Skip to main content
PCI DSS Level 1 Certified

Agent-Assisted Payments Your agent stays. The card number doesn't.

Agent-assisted payments keep your agent on the live call while the customer keys their card on their own phone. We mask the keypad tones before they reach the agent's audio or the call recording, so the conversation never breaks and the card data never lands anywhere it shouldn't. One keypress to start the capture. One green light when the gateway responds. PCI scope drops from SAQ D to SAQ A the moment you connect.

What an agent-assisted payment actually is

An agent-assisted payment is the ordinary phone payment your contact centre already runs, with one specific change: the customer enters their card details on their own keypad while the agent stays on the line throughout the call. The agent doesn't read digits back. They don't type anything into a terminal. They're right there in the conversation — confirming the amount, answering questions, reassuring a nervous caller — but the card data takes a different route. It travels from the customer's handset straight to our DTMF masking layer and on to your payment gateway. It never touches your agents, your recordings, your CRM, or your network. It's one of three approaches to take card payments over the phone safely — see the pillar guide for how it compares to IVR and outbound.

It's the middle option between two unworkable ones. Pure self-service IVR drops you out of PCI scope, but it also drops the customer the moment they need help — abandonment rates climb the second somebody passes a caller to "the machine". Pause-and-resume call recording leaves the card audio sitting in the agent's ear and on a quiet recording, which is still PCI cardholder data however carefully you handle it, and the compliance story falls over the first time an agent forgets to hit pause. Agent-assisted keeps the human in the call and keeps the card data out of it.

Who uses it? Any PCI-compliant contact centre where the agent needs to stay in the conversation through the transaction. That covers retail customer service teams taking phone orders, insurance call centres handling premiums and excesses, healthcare billing teams collecting patient charges, B2B account teams taking deposits on six-figure orders, charities running live donor pledges, and housing associations collecting service charges from residents who'd rather speak to a person. If your team is on the phone with the customer at the moment of payment, this is the route that lets them stay there safely. Tell us about your setupand we'll show you what it looks like on your phone system in under twenty minutes.

Agent-assisted payments in digital commerce and the wider payments industry

The phrase turns up in two adjacent places and means slightly different things in each, which is why the definitions you find online disagree with one another. In contact centres it means what we've just described — a live phone call where the agent stays present and the card is captured without them. In digital commerce it usually means an agent completing a purchase on the customer's behalf: the shopper is on the phone or in a chat window, the agent builds the basket, applies the discount, checks stock, and then has to collect payment for a checkout the shopper never touched. Different setting, same problem underneath. Somebody who works for you is driving the transaction, and the card has to reach the gateway without going through them.

As a category it belongs in payments rather than fintech. Agent-assisted payment isn't a lending, banking or wallet product. It's an acceptance channel — one of the routes a card can travel from a customer to your acquirer, sitting alongside a card machine in a shop, a web checkout, and an automated phone line. What marks it out from the others is a person who's accountable for the sale and deliberately excluded from the card data. That second half is the whole design goal. Anything that keeps a human in the conversation while routing the card around them qualifies. Anything that leaves them able to hear, see or write down the number doesn't, however it's marketed.

Paytia covers both settings on one platform. Phone calls run through DTMF masking or channel separation. Digital commerce runs through a virtual terminal the agent drives while the customer keys their card on their own handset, or through a payment link the agent sends mid-conversation and watches complete on screen. Same tokens, same gateway, same reporting, whichever way the customer got in touch.

How agent-assisted compares to the alternatives

There are three ways to take a card payment on a phone call. Two of them put you in full PCI scope. Only one keeps you out.

Risky

Agent reads the card aloud

The customer reads the card number out, the agent writes it down or types it into a terminal, everyone overhears it. The recording captures every digit. Notes, forms, and CRM fields end up holding card data.

PCI outcome: SAQ D. 329 controls. Every recording and workstation in scope. Not where you want to be.

Limited

Transfer to automated IVR

The agent puts the customer on hold, transfers them to an automated payment line, and hopes they come back. Fast for simple payments. Cold for anything that needs a person.

PCI outcome: SAQ A, but the call flow is jarring. You lose the ability to help mid-payment, and drop-off rates climb.

Recommended

Agent-assisted with DTMF masking

The agent stays on the call. The customer keys their card on their own handset. We mask the tones before they hit the recording or the agent's audio. Conversation never breaks; card data never arrives.

PCI outcome: SAQ A, 22 controls, full human experience. The one we're here for.

How an agent-assisted payment actually works on a call

Picture an ordinary call. A customer rings in, the agent picks up, they talk through whatever the customer needs — a new order, a renewal, a claim, a service-charge query. The conversation is unchanged from the way your team works today, right up to the moment of payment. At that point, the agent confirms the amount out loud, clicks "Take payment" in their dashboard, and tells the customer that they'll hear a short prompt and can tap their card details in on the keypad when they're ready. The agent stays right there with them.

What the agent sees: a progress panel inside whichever CRM or terminal they already use. The amount they entered. A counter showing digits arriving — sixteen for the card, four for expiry, three or four for the CVV. A live status — "awaiting card entry", "processing", "approved", or a clear decline reason if the gateway pushes one back. No card number, no truncated digits, nothing decodable. Just enough information to know the call is on track.

What the customer hears: the agent's voice the whole way through. They can ask "sorry, was that the long number or the security one?" and the agent can answer them in real time. They can pause to find their card. They can apologise for fumbling the keypad. None of it breaks anything — the audio path stays open both ways. The only thing that doesn't reach the agent's headset is the DTMF tones themselves. Every keypress is replaced with a flat, neutral sound before the audio leaves our network. Every digit sounds identical, so there's no way to reverse-engineer the card from the recording either.

Behind the scenes, the customer's keypresses arrive at our PCI DSS Level 1 environment over a secure SIP leg. The raw digits sit in encrypted memory just long enough to send to your acquirer. We never store them. As soon as the gateway responds, the agent's panel updates — approved with a transaction reference, or declined with a reason and a one-click option to try a different card. The whole capture takes twenty to thirty seconds in practice. The agent reads back the reference, schedules whatever's next, and the call carries on.

One detail worth pulling out: the masking happens upstream of the agent's device. It's not a piece of software running on their workstation, and it can't be disabled by an agent on a bad day. The agent's computer is literally on a different data path from the card digits. That's why this works as a control auditors trust — the protection is built into the technology, not into whether somebody remembered to hit pause.

How agents are kept away from card data

There are only four ways a card number reaches an agent on a payment call. They hear it read out. They see it on a screen. The recording captures it and somebody plays the recording back. Or they write it down — a notepad, a CRM free-text box, a spreadsheet somebody built years ago and nobody has looked at since. A payment channel is safe when all four are shut, and shut by the technology rather than by a rule that agents are asked to remember on a busy Friday.

Earshot closes first. The customer keys the card instead of speaking it, and every keypad tone is replaced with flat, identical audio before the call leaves our network. The agent hears the customer breathing, hesitating, asking whether it's the long number or the short one — everything except the digits. Because each replacement tone sounds the same as the last, there's nothing in the audio to decode afterwards. That shuts the recording route at the same time: your recorder captures the same flattened audio the agent heard, so recordings come out clean and stay usable for quality reviews and dispute handling with no redaction step bolted on.

The screen closes because we never send digits to it. The agent's panel carries the amount they typed, a count of how many digits have arrived, a live status, and the gateway's answer. No card number, no last four, no truncated fragment somebody could pair with a second call to rebuild the whole thing. The masking runs upstream of the agent's workstation, on a different data path entirely, so there's no local component for a curious agent to disable and no browser plugin to go wrong after a Windows update.

The notepad closes itself. There's no number to write down, so the habit dies with the process that created it. The one route left is social — the well-meaning agent who says "the keypad's playing up, just read it out and I'll type it in". For calls where you want that possibility removed rather than trained against, channel separationdrops the audio path during card entry, so the request physically can't be made.

This is where agent-assisted parts company with pause-and-resume recording. Pausing the recorder shuts one of the four routes and leaves the other three open — the agent still hears the number, still types it somewhere, and still might write it down. Auditors know that, which is why pause-and-resume rarely buys the scope reduction people expect from it.

The three technical methods behind agent-assisted

Agent-assisted is a use case, not a single technology. There are three different technical approaches that deliver it, and they're not interchangeable. Most contact centres pick one as a default and use a second for the calls where it fits better.

DTMF masking

The most widely deployed approach, and what we run by default. The agent and customer stay audibly connected throughout. As the customer taps their card on the keypad, every DTMF tone is intercepted at the network layer, decoded into a digit, and routed straight to the payment gateway. The agent hears a flat replacement tone in place of each press. Conversation continues. Rapport doesn't break. The strength of DTMF masking is the customer experience — a nervous caller can ask "is that going through?" mid-entry and the agent can answer. The trade-off is that the live voice path has to stay connected, which means the masking has to handle the audio stream in real time. We do that at our network edge, which is why the agent's workstation never sees the card data.

Channel separation

Channel separation takes a stricter line for the calls where audit-proof security matters more than conversational warmth. During the card-entry window, the audio between agent and customer is disconnected entirely. The customer hears a recorded prompt asking them to enter their card. The agent hears hold music and watches the same progress panel. When the gateway confirms, both sides are reconnected and the call picks up where it left off. The advantage is that the agent physically can't prompt the customer to read a card aloud — the audio path isn't there to carry the request — so the social-engineering risk drops to near zero. The trade-off is that the customer can't ask questions mid-entry. Experienced callers don't mind. Nervous ones can find it cold. We deliberately offer both methods so you can match the technique to the call type. Channel separation has its own page if you want the deeper view.

Conference-pay IVR

The third option conferences the customer into a separate IVR for the payment step. The agent stays on the line but the customer is temporarily routed to a secure IVR system to enter their card. When the IVR confirms the payment, the customer is brought back to the agent and the call continues. It works, and the card data stays out of your systems, but customers tend to find the handover clunky — there's a clear "you're being passed to a machine now" moment that some abandon at. It's also more complex to integrate because you're coordinating two voice platforms instead of one. We'll deploy it where a contact centre already has an IVR estate they want to keep using, but it's rarely the default we'd pick.

The short version: DTMF masking wins when the human connection matters most, channel separation wins when audit-proof security matters most, and conference-pay IVR wins when minimal integration work matters most. We've put a side-by-side breakdown of the two we recommend on our DTMF masking vs channel separation page— worth a read if you're choosing between them.

What this does to your PCI DSS scope

A contact centre that takes phone payments without protection sits inside the full PCI DSS cardholder data environment. Agents hear the numbers, so the audio channel is in scope. Recordings capture the tones, so the recording platform is in scope. Agents type the numbers into a form, so the workstation, the network, the CRM, and anything downstream is in scope. The self-assessment is SAQ D — 329 controls covering network security, access management, encryption, vulnerability scans, key management, logging, and the rest. It's the biggest tier the PCI Council publishes, and it's designed for environments that actively store, process, or transmit card data.

Agent-assisted with DTMF masking, running through a PCI DSS Level 1 provider, typically drops the self-assessment to SAQ A — 22 controls. That's a 93% reduction in requirement count, and the remaining controls are mostly about documenting your relationship with us rather than running infrastructure. Your call recordings come out card-data free, so you can review and archive them without redaction. Your agents drop out of mandatory annual PCI training. Your network drops out of the cardholder data environment. Your QSA conversation moves from "walk me through every control" to "here's the Attestation of Compliance from your service provider".

The cost side follows the control count. Contact centres we work with typically report a 75% reduction in ongoing PCI spend — that's staff time on compliance work, quarterly ASV scans, annual penetration tests, QSA fees, remediation, and training, combined. The bigger benefit is one nobody puts on a spreadsheet: phone payments stop being a board-level audit risk. The blast radius of a single agent mistake collapses from "reportable data incident" to "the customer tried a wrong digit".

PCI DSS 4.0, mandatory since March 2025, tightens the scoping rules — you have to actively demonstrate that systems are out of scope, not just assume they are. That makes agent-assisted more valuable, not less. You can point at the network diagram, point at our Attestation of Compliance, and show the QSA exactly why the card data never enters your environment. Pause-and-resume can't tell that story cleanly, because the audio still touches the agent. Agent-assisted can.

PCI DSS Level 1 Service Provider certification

PCI DSS Level 1

Our scope becomes yours the moment your card data takes our route. The work, the audit, and the evidence sit with us.

AreaWithout PaytiaWith Paytia
Self-assessmentSAQ D (329 controls)SAQ A (22 controls)
Network in scopeMost of your stackNone
Call recordingsRedact, pause-and-resume, or isolateCard-data free
Agent trainingMandatory and recurringNone required
Audit evidenceEvery touchpointProof of integration only

What enterprises get out of agent-assisted payments

Small teams buy agent-assisted payments to get out of SAQ D. Large ones buy it for reasons that only show up above a certain headcount, and the compliance saving is often the least interesting of them by the time the project lands.

The first is consistency across sites and working patterns. A hundred agents split between two offices, a home-working rota and an outsourced overflow partner is four different control environments if the protection lives in local process. Move the capture onto a shared service and it's one. That's exactly what Insure and Go did across their office and home-based staff — one capture service, identical behaviour wherever the agent sat. It also changes hiring: once card exposure stops being a property of the room the agent is in, you can recruit anywhere and let people work from home without rewriting the compliance story.

The second is what happens to call recordings. Large operations record everything and rely on those recordings for quality scoring, complaint handling, dispute evidence and regulated-sale verification. Card audio in the recording turns the whole archive into cardholder data, which means restricted access, retention headaches, and a redaction pipeline somebody has to run and prove works. Clean recordings remove that entire workstream and give the quality team its library back.

The third is the shape of the audit. Instead of evidencing controls across every desktop, network segment and recording server, you evidence one integration and hand over a service provider's Attestation of Compliance. Under PCI DSS 4.0 you have to actively show that systems are out of scope, and a network diagram where card data never crosses your boundary is a far easier thing to show than a set of procedures agents are trusted to follow.

The fourth is control at the group level. Multi-store IDs let a group run several brands or trading entities through one platform with separate reporting. Country, currency and card-type restrictions are set centrally rather than argued about per team. Address verification is on or off by policy, not by whoever configured the last terminal. Our enterprise contact centre pagecovers the operating model in more depth if that's the size of estate you're working with.

The cost case, and where the money actually comes back

Let's be straight about one thing first. Agent-assisted payments keep the agent on the call, so they don't deliver the labour saving that a fully automated payment line does — an IVR payment that runs without a human costs pennies in platform and gateway fees, while a phone payment with a person attached runs a few pounds once you load in agent time, supervision, training and the infrastructure that has to sit around somebody handling card data. If your calls are routine enough to automate, automate them. The savings below are for the calls that genuinely need a person.

The largest line is compliance run cost. Contact centres we work with typically report around a 75% reduction in ongoing PCI spend once card data stops entering their environment. That figure is made up of quarterly scans and penetration tests on systems that leave scope, QSA days that shrink with the control count, remediation work that stops appearing, and the staff hours that used to go into evidence gathering every year. None of it is a one-off. It comes back every twelve months.

The second is handling time, and it's the one finance teams underestimate. The old loop — read the number back, type it in, check it, apologise, re-read it — takes far longer than most people think when they price it. Warby Parker cut average call handling time by 35% after their reps stopped doing it, and the saving showed up inside the first month. At Total Tiles the same change lifted daily order throughput from 25-30 to 45-50 within a week of go-live, because the payment step had been the bottleneck holding up everything else in the order process.

The third is training and turnover. Annual PCI training for every agent who touches card data disappears, and so does the induction time for each new starter — which matters most in exactly the operations that churn hardest. Twenty to thirty minutes on the new button replaces it.

The fourth is licensing that follows demand. All Clear Travel Insurance scale agent seats up and down against active usage, worth roughly 45% during off-peak travel periods when their booking volumes fall away. Whether per-seat or per-transaction pricing suits you depends on how much your headcount swings through the year — our guide to choosing your charging modelworks through both. Bring your call volumes and average ticket to a scoping call and we'll quote against real numbers rather than a rate card.

Real outcomes from contact centres running this

Compliance is what gets contact centres into the conversation. The numbers we hear back six months later are usually different — handle times, throughput, hours of admin recovered, staff working from home without dropping the PCI story.

Warby Parker brought us in to fix the PCI picture on their phone order line. The side effect was a 35% reduction in average call handling time once their reps stopped cycling through the old pause-read-type-confirm loop on every call. Their customers entered their own details on the keypad while the rep stayed on the line, and the time savings landed inside the first month.

Total Tilesmoved to us when COVID broke their in-office phone-order workflow. Within a week of go-live, daily order throughput went from 25-30 to 45-50 — an 80% lift. The payment step itself wasn't what unlocked the volume; removing it as the bottleneck on the rest of the order process was.

Insure and Go run a travel insurance call centre on Digi-desk by Citrus and needed agents to handle premiums, mid-term changes, and emergency claim payments without exposing card data — across both their office and home-working staff. We deployed a common capture service across all their agent locations. The result was a 75% reduction in PCI scope, a 40% lift in agent efficiency, and the same payment experience regardless of where the agent was working from.

All Clear Travel Insurance, the sister operation, got the same 75% scope reduction and layered our flexible licensing on top. They scale agent seats up and down based on active usage, which is worth roughly 45% during off-peak travel periods when their booking volumes drop and they don't need the same number of seats covered.

The pattern across all four is the same: scope shrinks, handle time drops, staff time comes back, and the customer experience improves rather than degrades. That's what agent-assisted looks like when it's working — and it's why we've never had a contact centre go back to the old way.

Softphones, CCaaS platforms, and why nobody needs a card reader

A card reader is a card-present device. It exists to read a chip or a contactless antenna with the card physically in front of it. A telephone payment is card-not-present by definition — the customer is at home with the card in their hand and your agent is somewhere else entirely — so a reader on the agent's desk would have nothing to read. Buying one for a phone team is a category error, and an expensive one once you count the estate management that comes with a few hundred devices. The card details arrive as keypad tones from the customer's own handset. All the security work happens on the line, not on the desk.

That's also why softphones are fine. We sit on the SIP path, not on the agent's audio device, so what they wear or click doesn't change the security model. A browser-based softphone, a desktop client, a USB handset, a headset plugged into a laptop, a hot-desking agent who logs into a different machine each morning — all the same to us, because none of them are ever on the path the card digits take. There's nothing to install on the agent's computer and nothing to keep patched. The virtual terminal runs in the browser they already have open.

On the platform side, we've built and tested integrations with Genesys, NICE CXone, Five9, Talkdesk, Amazon Connect, RingCentral, 8x8, Vonage, Mitel, Aircall, 3CX, ContactOne, Zoom and Microsoft Teams, plus on-premise estates on Avaya, Cisco and Mitel where we join at the SIP trunk and leave core telephony alone. Smaller teams without SIP can forward an analogue line instead, or use dedicated agent phone numbers and skip platform integration entirely. Our telephony partner pages set out how each one connects.

A question we get a lot is which CCaaS provider supplies compliant capture with masking built in. It's the wrong question to lead with. Your contact centre platform doesn't need to offer card capture, and you shouldn't pick one on that basis — the masking happens on a separate SIP leg operated by a PCI DSS Level 1 service provider, which is what gives you the scope reduction in the first place. Capture built into a platform that isn't itself certified at Level 1 leaves the card data in your environment and leaves you holding the audit. Pick the CCaaS platform your operation actually needs, then put the payment leg beside it.

Where this fits in your stack

Most contact centres we talk to worry about integration before they worry about anything else, usually because they've been burned by enterprise software projects before. The honest answer is that agent-assisted payments don't need a platform migration. We plug into whatever telephony you're already using.

On the cloud side we integrate with Genesys, Five9, NICE CXone, Mitel CX, Aircall, 3CX, RingCentral, ContactOne, Amazon Connect, Talkdesk, and most other SIP-based contact centre platforms. For on-premise PBX — Avaya, Cisco, Mitel — we integrate at the SIP trunk so we don't need to touch your core telephony. For cloud contact-centre suites that already ship native payment-capture integrations, we slot alongside their workflow rather than replacing it. If you're on something unusual we'll tell you honestly on the discovery call whether the integration is straightforward.

On the gateway side we work with the UK's major acquirers and processors — Worldpay, Barclaycard, Stripe, Adyen, Trust Payments, Elavon, Global Payments, and a long list of others. We tokenise the card on first capture so the same flow supports one-off payments, recurring billing, instalments, and follow-up charges without re-prompting the customer. Refunds run through the same Paytia terminal so your agents never need to log into a gateway dashboard separately.

On the agent side, nothing visible changes except a new button. The Paytia console is browser-based and works on whatever the agent already uses — Windows, macOS, Chromebook, thin client, it doesn't matter. The softphone stays the same. The CRM stays the same. We embed the capture into Salesforce, HubSpot, Zoho, Microsoft Dynamics, Zendesk, Freshdesk, and most sector-specific systems (claims, booking, property management). Training is twenty to thirty minutes per agent. Most of that is showing them the new button — the payment flow itself is simpler than what they were doing before.

Multi-site or multi-country deployments take two to four weeks. We've never had one take longer than six, and on the longer ones the lift is procurement and change management rather than technical integration. We work with your operations lead for an hour to understand the call flow, provision the platform, run a parallel test for a day or two, and flip traffic over. For a deeper look at the picture across a contact centre, our guide to secure payments in contact centres covers the operational side. Book a demoand we'll run it against the same phone system and gateway you already use.

How long setup and agent training actually take

The fear behind this question is usually a previous project — a payments or telephony programme that ate six months, needed a systems integrator, and left the floor learning new software while call volumes carried on regardless. Agent-assisted capture isn't that shape of work, because almost none of it happens on your side.

What we need from you is small and specific. An hour with whoever knows your call flow, so we understand where in the conversation the payment sits and what the agent needs to see when it finishes. Your gateway credentials, so the money lands with the acquirer you already use rather than a new one. A telephony contact for the SIP connection, which is typically a configuration change on your side and not a purchase. Then the settings you want enforced — which countries and currencies you trade in, which card types you accept, whether address verification is required, which fields the agent must complete before a capture can start.

After that it's us. We provision the platform, build the flow, and run it in parallel with your live traffic for a day or two so you can watch real captures complete before anything switches over. Multi-site or multi-country deployments take two to four weeks, and we've not had one run past six. On the longer ones the delay is nearly always procurement sign-off or a change window, not integration.

Agent training is twenty to thirty minutes, and most of that is showing people the button. There's no software to install, no new application to sit alongside the CRM, and no script to memorise — the agent confirms the amount out loud, clicks to start the capture, and tells the customer to key their card when they're ready. Supervisors usually need a second session on the reporting side. What we tell operations leads to plan for isn't training time, it's the fortnight afterwards when experienced agents keep reaching for the old habit of asking for the number. That fades quickly, because the new way is less work.

Running agent-assisted and self-service from the same setup

Very few businesses want only one payment channel. The call that needs a person today is the same customer who'll happily pay an identical bill through an automated line next quarter, and forcing everyone down one route costs you either agent hours or completed payments. Both models run on the same Paytia platform, against the same gateway, with the same tokens and one reporting view — so the choice is an operational one rather than a procurement one.

The pattern most contact centres settle on is straightforward. Routine, predictable payments go to the automated line, which also covers evenings and weekends when nobody's on the desk. Anything with a conversation attached — a dispute, a renewal, a part payment, a customer who needs reassurance — stays with an agent and uses agent-assisted capture. If a caller drops out of the automated flow, they land with an agent who can finish the payment on the same call rather than sending them back to the start. Our guide to self-service versus agent-assisted works through where the line sits.

The same platform reaches beyond the phone. An agent can send a payment link mid-conversation and watch it complete, drive a web checkout for a customer who'd rather pay online, or start a capture from your own application through our API and pick up the result on a webhook. Because the card is tokenised on first capture, a customer who paid once with an agent can be billed again on a schedule without another call — useful for instalments, renewals and recurring payments.

Every one of those routes keeps card data out of your environment, so adding a channel doesn't reopen the scope question you closed when you started. That's the practical reason to buy the platform rather than the point solution: the second channel costs a configuration conversation, not another compliance project. If phone orders are your main volume, our MOTO payments page covers the card-not-present picture across the whole channel.

What the agent actually works with

Both capture modes keep the card out of your business and drop the acceptance channel to SAQ A. What differs day to day is how much control the team has over the call, the form and what you are willing to accept.

The agent's screen

  • A web-based virtual terminal — no software to install
  • Show, hide or require individual fields
  • CRM autofill of customer details
  • Multi-store ID support for multi-brand teams

Trade controls

  • Cardholder address verification
  • Restrict to the countries you trade in
  • Restrict to the currencies you trade in
  • Choose which card types and brands you accept

Telephony and integration

  • Digital SIP, or a simple analogue forward
  • Works with any CCaaS or PBX
  • Dedicated agent phone numbers
  • API to start a payment from your own application
  • Webhook callbacks on completion

On the call itself

  • Choice of voice language and gender for the prompts
  • Press * to reconnect the agent mid-flow
  • Full transcript and status logging
  • Immediate charge, reserve, pre-auth or capture to token

Frequently asked questions

What is an agent-assisted payment?+

An agent-assisted payment is a card payment taken during a live phone call, with the agent on the line the whole time, but where the agent never sees or hears the card number. The customer keys their card on their own phone keypad, the keypad tones are masked before they reach the agent's audio or your call recording, and the card goes straight to your payment gateway. The agent stays in the conversation — they can answer questions, confirm the amount, cross-sell, close the deal — but they're never the route the card data takes.

How is agent-assisted different from IVR?+

IVR (Interactive Voice Response) is fully automated — the customer calls a number, a recorded voice walks them through, no human involved. That's fine for routine, low-value, high-volume payments, but it's a poor fit anywhere the customer needs help or the call has commercial substance. Agent-assisted keeps the human in the loop. Your agent stays on the call through the payment step, which means they can handle anything unusual — a wrong digit, a confused customer, a follow-up question, an upsell — without the call going cold. Same PCI protection either way; different conversation.

Why not just have the agent take the card number down?+

Because that puts you in full PCI DSS scope — SAQ D, 329 controls, annual QSA audit, mandatory staff training, secure rooms, paper shredding, the works. It also puts the card data in your call recording, your agent's ear, your CRM notes, sometimes a Post-it. Any one of those becoming compromised is a reportable incident. Agent-assisted with DTMF masking removes every one of those touchpoints while keeping the agent where they're useful — on the call.

Does the agent know if the payment was successful?+

Yes — immediately. A status panel in the agent dashboard shows the capture progressing in real time (digits entered, awaiting gateway, approved or declined), and the agent gets a clear approved/declined signal the moment the gateway responds. They can immediately pick the conversation back up — confirm the reference number, send the receipt, schedule the next payment, whatever the next step is.

Which phone systems does this work with?+

Anything modern — traditional PBX, SIP trunks, and major CCaaS platforms. We integrate at the SIP or API layer and don't need on-premise hardware on your side. The complex work is on our side, not yours.

What do agents need to learn?+

Almost nothing. The agent sees a button in whatever dashboard they already use — a CRM, a bespoke tool, the browser-based Paytia console. They click it, enter the amount, and tell the customer to key their card. Everything else runs on its own. No scripts to memorise, no new software to master, no handoff to a payment team. The payment step becomes the same shape of task as asking for a postcode.

Does it work for MOTO payments?+

Yes. Agent-assisted payments with DTMF masking are built for card-not-present telephone orders — which is what MOTO is. We tokenise the card on first capture so the same flow supports one-off payments, recurring billing, instalments, and follow-up charges. See our MOTO payments page for the broader card-not-present picture.

What are the benefits of agent-assisted payments for an enterprise?+

Four things show up above a certain size. One control environment instead of one per site, so office, home-working and outsourced agents all behave identically — which also lets you hire wherever you want. Call recordings that stay clean, so the quality and complaints teams keep their archive without a redaction pipeline sitting in front of it. An audit that turns into one integration plus a service provider's Attestation of Compliance rather than evidence gathered from every desktop and network segment. And group-level control of countries, currencies, card types and address verification, set centrally instead of configured per team.

Where do the cost savings from agent-led payment flows actually come from?+

Mostly from four places. Compliance run cost falls the most — contact centres we work with typically report around a 75% reduction in ongoing PCI spend, covering scans, penetration tests, QSA days, remediation and the staff hours that went into evidence every year. Call handling time drops because the read-back-and-retype loop disappears; Warby Parker measured 35%. Annual PCI training for agents goes away, along with the induction time for each new starter. And per-seat licensing that flexes with demand cuts spend in quieter months — All Clear save roughly 45% off-peak.

How much setup work and agent training does this need?+

Very little on your side. We need an hour with whoever knows your call flow, your existing gateway credentials, a telephony contact for the SIP connection, and your trading rules — countries, currencies, card types, whether address verification is required. We build and provision everything else, then run it in parallel with live traffic for a day or two before switching over. Multi-site or multi-country deployments take two to four weeks. Agent training is twenty to thirty minutes, and there's nothing to install.

Can agents take payments on a softphone without a separate card reader?+

Yes, and a card reader would have nothing to do here anyway — a reader is for card-present transactions where the card is physically in front of the device. A telephone payment is card-not-present: the customer keys their own card on their own handset. We sit on the SIP path rather than the agent's audio device, so browser softphones, desktop clients, USB handsets, headsets and hot-desking all work the same way. Nothing gets installed on the agent's machine.

Which CCaaS platforms support PCI DSS compliant capture with masking?+

It's worth turning that question around. Your contact centre platform doesn't need to supply card capture, and choosing one on that basis is a mistake — the masking runs on a separate SIP leg operated by a PCI DSS Level 1 service provider, and that separation is what produces the scope reduction. Capture built into a platform that isn't certified at Level 1 keeps card data in your environment. We've built and tested integrations with Genesys, NICE CXone, Five9, Talkdesk, Amazon Connect, RingCentral, 8x8, Vonage, Mitel, Aircall, 3CX, ContactOne, Zoom and Microsoft Teams, plus on-premise Avaya and Cisco estates at the SIP trunk.

Can we run agent-assisted and self-service payments on the same platform?+

Yes, and most of our contact centre customers do. Routine, predictable payments go to the automated line, which also covers evenings and weekends. Anything with a conversation attached stays with an agent. Both run on the same platform, the same gateway and the same tokens, with one reporting view, so a caller who drops out of the automated flow can be finished off by an agent on the same call rather than starting again.

Can an agent complete a web checkout on the customer's behalf?+

Yes. Where the customer would rather pay online than key digits on a call, the agent can send a payment link mid-conversation and watch it complete on their screen, or drive our browser-based virtual terminal while the customer enters their card themselves. You can also start a capture from your own application through our API and receive the result on a webhook. Every route keeps the card out of your environment, so adding one doesn't reopen the compliance question.

The Paytia solution provides our customers with a convenient and secure way to make payments. It enables us to keep card data out of our environment and off our systems altogether.

CAS

Read the case study →

Used by British American Tobacco · Howard Kennedy · CITB · Clinical Partners · Trinity Hall College

Since 2016

Building secure payments

PCI DSS Level 1

Highest certification

99.99%

Platform uptime

£400M+

Transactions processed

Keep the agent. Lose the card data.

We'll demo it against the same phone system and gateway you already use.

PCI DSS Level 1
Cyber Essentials Plus

Trusted by law firms, insurers, healthcare providers and regulated businesses worldwide. Learn more about Paytia