Shipped digest
GPT-6 Astra passed
- Tokens
- 79,653
- Cost
- $0.77
Write the January 2026 issue of Sonora Shipped, the monthly email from Sonora, the voice-agent platform behind Sonora Ensemble. Recipients are developers and product teams who opted in. The issue goes out February 3, 2026 and can be viewed in the browser at https://sonora-email.s3.amazonaws.com/shipped/2026-01
Opening: 2026 is off to a fast start. This issue has an editorial on running AI voice agents safely, the changes that shipped in January, and a few reads and listens worth the time.
Lead article, titled "Is that voice agent safe to run?": Voice agents are now trusted with tools, credentials, and live callers, and teams are turning them on faster than they are checking them. The most common failures are the same three: an agent that can call any tool the workspace has, tool credentials pasted into the system prompt, and no policy check between what the model says and what the caller hears. The article lays out three checks to run before an agent goes live. Scope tools to the agent so a call can only invoke the tools on that agent's allow-list. Keep keys out of prompts by storing tool credentials as Connections and referencing them by id. Turn on Guardrails so policies run as independent checks on every turn and can retry, escalate, or end the call. Full article: https://sonora-email.s3.amazonaws.com/blog/running-voice-agents-safely
Shipped in January, five changes in this order, each with a one-line description and a link:
- Guardrails audit log: every retry, escalate, and end decision is written to the call transcript with the policy name that triggered it. https://sonora-email.s3.amazonaws.com/docs/guardrails/audit-log
- Scoped tool permissions: tools are allow-listed per agent configuration, and a call cannot invoke a tool outside its list. https://sonora-email.s3.amazonaws.com/docs/tools/permissions
- Connections: tool credentials are stored once and referenced by id from any agent configuration instead of living in the prompt. https://sonora-email.s3.amazonaws.com/docs/connections
- Barge-in sensitivity: a low, medium, or high setting on the Ensemble API session controls how readily the agent yields when the caller talks over it. https://sonora-email.s3.amazonaws.com/changelog/2026-01
- Recording export: call recordings can be delivered to an S3-compatible bucket of the workspace's choosing. https://sonora-email.s3.amazonaws.com/docs/recordings/export
The full changelog is at https://sonora-email.s3.amazonaws.com/changelog/2026-01
Worth your time, three items:
- Podcast: Turn-taking is a product decision. Episode 12 of the Sonora Signal podcast on why interruption handling belongs to the product team, not only the audio stack. https://sonora-email.s3.amazonaws.com/learn/podcast/turn-taking
- Read: Why your voice agent needs a kill switch. How to stop an agent mid-call and what should happen to the caller when you do. https://sonora-email.s3.amazonaws.com/blog/voice-agent-kill-switch
- Watch: Simulation tests, live. A recorded 20-minute session on writing simulation tests for Ensemble agents. https://sonora-email.s3.amazonaws.com/learn/simulation-tests-live
Sign-off from The Sonora Team, with a postscript inviting readers who built something on Ensemble to share it for a future issue at https://sonora-email.s3.amazonaws.com/community/showcase/submit
Feedback vote, "What did you think of this issue?", with three linked options: Not my thing (https://sonora-email.s3.amazonaws.com/feedback/not-my-thing), Okay (https://sonora-email.s3.amazonaws.com/feedback/okay), Great (https://sonora-email.s3.amazonaws.com/feedback/great)
Reference artwork: assets.illustrations.safetyHero for the lead article.
The footer gives the postal address and links to https://sonora-email.s3.amazonaws.com/unsubscribe and https://sonora-email.s3.amazonaws.com/preferences
Dark mode should be supported.
Use /world/sonora-email for brand chrome and CSS. Use the absolute HTTPS URLs from tokens.json; do not use /world/ paths as image src.
Leave the HTML in output/email.html, a plain-text version in output/email.txt, and the subject in output/meta.json as {"subject": "..."}. Don't include From, To, or Date headers.