Skip to content

Outbound Dialing Permissions

Outbound Dialing Permissions let you control which destinations can be dialed, and by whom, independently of your routing configuration. They act as a policy layer over Outbound Routes: a rule can block a number pattern outright, explicitly allow it, or require the caller to enter an authorization code before the call proceeds. Administrators use this to curb toll fraud and abuse - for example blocking international or premium-rate numbers for most extensions, while permitting them from a few authorized phones or behind a PIN.

Each rule matches on the destination being dialed and, optionally, on the origination (the caller). If no origination pattern is given, the rule applies to everyone.

Dialing Permissions checking is disabled by default to avoid any overhead. Use the Enable Checking button above the grid, or set the Global Dialplan Variable TL_CHECK_DIALING_PERMISSIONS to 1 by hand. Removing this variable or setting TL_CHECK_DIALING_PERMISSIONS to 0 will disable checking of Dialing Permissions. The variable is global, so the button appears only for administrators who can edit Dialplan Variables.

Outbound Dialing Permissions can be also set on a tenant level. System-wide permissions have higher priority. Calls are checked against the Tenant level permissions only if they pass the system-wide Outbound Dialing Permissions check.

Create/Edit Dialing Permissions

Here you can enter one or more Destination Patterns (separated by commas) and optionally one or more Origination Patterns (also separated by commas) following standard dialplan pattern rules. The “Action” will apply to calls made to destinations matching “Destination Patterns” by either all callers (if no “Origination Patterns” are specified) or the endpoints matching Origination Patterns.

Description. Specify a short description.

Origination Pattern(s). If omitted, will apply the rule to all outbound calls. A number or a pattern for outbound call caller id number matching. Accepts multiple values separated by a comma. If the first character is _ it means that whatever follows is to be treated as a pattern.

Destination Pattern(s). A number or a pattern for matching the outbound call number. Accepts multiple values separated by a comma. If the first character is _ it means that whatever follows is to be treated as a pattern.

Action. Defines what to do with the call if the conditions defined by patterns are met.

Possible actions are:

  • Deny. This will reject the call.
  • Allow. Proceed with the call.
  • Require Authorization Code. Request caller to enter a short numeric code.

Authorization Code. Code to authorize calls matching this pattern. Shown only when the Action is Require Authorization Code. Callers who enter the correct code are allowed to complete the call.

Pattern matching

Patterns follow standard dialplan rules. A plain value (for example 14155551234) matches that exact number. Prefix a value with an underscore (_) to treat the rest as a pattern:

  • X matches any digit 0-9
  • Z matches any digit 1-9
  • N matches any digit 2-9
  • [13-5] matches any single digit listed in the brackets
  • . matches one or more remaining characters

For example, _9011. matches any number the user dials with a 9011 international prefix, and _1900NXXXXXX matches US premium-rate 1-900 numbers.

Examples

  • Block international dialing for everyone. Destination Pattern _9011., no Origination Pattern, Action Deny. (Adjust the prefix to match how your users reach international dialing.)
  • Allow international only from the front desk. Add a second rule with the same destination but Origination Pattern set to the front-desk caller ID, Action Allow. Because tenant rules are only consulted after the system-wide check passes, and more specific allow rules can carve out exceptions, order your policy from broad deny to specific allow.
  • Require a PIN for premium-rate numbers. Destination Pattern _1900NXXXXXX, Action Require Authorization Code, with an Authorization Code your finance team controls.

Best practices

  • Enable checking deliberately. Permissions checking is off by default; set TL_CHECK_DIALING_PERMISSIONS to 1 (see the note above) only after you have defined your rules, so you don’t accidentally block all outbound calls with an empty or incomplete policy.
  • Test with a non-critical extension first before rolling a deny policy out tenant-wide.
  • Default to deny for high-risk destinations (international, premium-rate, directory-assistance) and explicitly allow the specific extensions that need them - this is far safer than trying to enumerate every bad number.
  • Prefer authorization codes over outright allow for occasional legitimate use of expensive destinations, so usage is gated without hard-coding which phones can dial.
  • Remember origination matches on the outbound caller ID, so keep extension caller IDs consistent for the rules to behave predictably.