Three checks before a voice agent goes live, plus everything Sonora shipped in January.
͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ 

View in browser

Sonora Sonora

FEBRUARY 3, 2026

Sonora Shipped: January 2026

2026 is off to a fast start. This issue has an editorial on running AI voice agents safely, the changes that shipped in January, and a few reads and listens worth the time.

THE LEAD

Is that voice agent safe to run?

A dark card asking Is that voice agent safe to run? above a waveform, beside a pre-flight checklist reading tools scoped to the agent, keys kept out of prompts, guardrails on every turn

Voice agents are now trusted with tools, credentials, and live callers, and teams are turning them on faster than they are checking them. The most common failures are the same three: an agent that can call any tool the workspace has, tool credentials pasted into the system prompt, and no policy check between what the model says and what the caller hears.

Scope tools to the agent. A call can only invoke the tools on that agent’s allow-list.

Keep keys out of prompts. Store tool credentials as Connections and reference them by id.

Turn on Guardrails. Policies run as independent checks on every turn and can retry, escalate, or end the call.

Read the full article →

CHANGELOG

Shipped in January

Guardrails audit log – Every retry, escalate, and end decision is written to the call transcript with the policy name that triggered it.

Scoped tool permissions – Tools are allow-listed per agent configuration, and a call cannot invoke a tool outside its list.

Connections – Tool credentials are stored once and referenced by id from any agent configuration instead of living in the prompt.

Barge-in sensitivity – A low, medium, or high setting on the Ensemble API session controls how readily the agent yields when the caller talks over it.

Recording export – Call recordings can be delivered to an S3-compatible bucket of the workspace’s choosing.

See the full changelog →

Worth your time

Podcast: Turn-taking is a product decision – Episode 12 of the Sonora Signal podcast on why interruption handling belongs to the product team, not only the audio stack.

Read: Why your voice agent needs a kill switch – How to stop an agent mid-call and what should happen to the caller when you do.

Watch: Simulation tests, live – A recorded 20-minute session on writing simulation tests for Ensemble agents.

That’s January. See you next month.

Keep building,
The Sonora Team

P.S. Built something on Ensemble? Share it for a future issue.

What did you think of this issue?

Not my thing   Okay   Great
Sonora, 12 Harbor Mill, Brooklyn, NY 11201
Unsubscribe  |  Manage preferences