Quick answer: agent-assisted payments keep a live agent on the call while the caller types their card number on their phone keypad. The digits route directly to the payment gateway, the agent sees only masked progress on screen, and the card number never enters your phone system, call recordings or agent desktops. The conversation keeps going, the recording keeps running, and the systems that used to carry card data no longer do.
Agent-assisted payment capture is one of the established patterns for PCI compliant phone payments, and it is the one built for a specific moment: the payment that happens inside a conversation. This guide covers why the pattern exists, how it works for the agent and the caller, how it compares to the alternatives, what to do when a payment fails mid-call, and what changes when the "agent" is an AI.
Why agent-assisted payments exist
Payments don't arrive on a call as standalone events. They arrive at the end of something else: a dispute gets resolved and the balance is due, a renewal call turns into an upgrade, an agent talks a caller through their options and they agree an amount. The payment is the last step of a conversation that a person just did the work to get right.
The traditional ways of taking that payment break the moment. Transfer the caller to an automated line and some of them don't survive the transfer: they get lost in the menu, mistype a reference, or hang up and mean to call back. Send them away to pay online and the payment leaves the call entirely, along with any certainty it will complete. Either way, the person who built the agreement is gone at the exact point the caller is ready to pay.
The old alternative, keeping the agent on and having the caller read their card number aloud, solves the completion problem and creates a compliance one. The agent hears the number, the recording captures it, and the phone system carries it, which pulls all of them into PCI DSS scope.
Agent-assisted payments exist to resolve that tension. The pattern keeps the conversation and removes the card data. The agent who agreed the amount stays on the line to the confirmation; the card number goes somewhere your systems never see.
How an agent-assisted payment works
The agent's side
The agent triggers the capture. When the caller is ready to pay, the agent starts the secure payment step from their screen, with the amount already agreed on the call.
The caller enters their card on the keypad. The keypad tones route directly to the payment gateway rather than through the agent's audio path.
The agent sees masked progress. Their screen shows that digits are arriving, masked, not the digits themselves. The agent stays on the line and keeps talking: they can reassure the caller, answer questions, or prompt them if they stall on the expiration date.
The confirmation lands in the agent's screen. Approved or declined, with a tokenized reference. The agent confirms the result to the caller and the conversation carries on, to a receipt, a follow-up, or a goodbye.
The mechanics underneath (how the tones are intercepted, and the difference between clamping, masking and suppression) are covered in our guide to DTMF payment capture. For the buyer's purposes, the important property is the outcome: the agent participates in the payment without ever having access to the card.
The caller's side
From the caller's seat, the experience is close to invisible. Nobody asks them to read a card number to a stranger. Nobody transfers them to a robot. They type their card into their own phone, the way they'd type a PIN at an ATM, while the person they were just talking to stays with them. If they hesitate or mistype, the agent is right there.
And because the card number never enters the call audio, the recording can keep running through the whole payment. Quality monitoring and dispute evidence stay intact, with no gap in the recording and no card data in it.
Agent-assisted payments vs the alternatives
Three other patterns compete for the same job. Each has a place; the differences matter.
Versus IVR payments. An IVR payment is fully automated: the caller pays through a keypad flow with no agent on the line. It's the right tool for high-volume, routine payments (bills, balances, renewals), and the wrong one for payments that need a human first. If the amount had to be negotiated, explained or agreed, an IVR can't do that part, and transferring a caller into one after the conversation risks losing them at the handoff.
Versus pause-and-resume recording. In this pattern the agent pauses the call recording while the caller reads their card number aloud, then resumes it. The pattern is workable and widely deployed. Its weakness is operational: the protection depends on the pause happening on every call, and a missed pause means a recording with a card number in it. The spoken number also still travels through your phone system and your agent's ears, so those stay in scope even when the pause works perfectly. The critique here is of the operating model, not any particular product: a control that relies on a human action repeating correctly on every call is a fragile control.
Versus a virtual terminal. With a virtual terminal, the caller reads the card aloud and the agent types it into a payment screen. It's the simplest thing to set up and the heaviest to live with: the agent hears and handles the card, the workstation processes it, and the desktop, its network and the people using it all sit inside PCI DSS scope.
Agent-assisted capture | IVR payment | Pause-and-resume | Virtual terminal | |
|---|---|---|---|---|
Agent on the call | Yes | No | Yes | Yes |
Agent hears or sees the card | No | No | Yes (hears) | Yes (hears and types) |
Recording runs throughout | Yes | Yes | No (must pause) | No (captures spoken card data) |
Card data enters your systems | No | No | Yes (spoken) | Yes (spoken and typed) |
Best for | Payments inside conversations | High-volume routine payments | Legacy operations | Very low volume, accepted scope |
When the payment goes wrong mid-call
Live-call payments fail in predictable ways, and the recoveries are worth designing in advance, because the compliant answer is never "just read me the number".
The call drops mid-payment. The caller was two digits from done and the line went. Rather than hoping they call back and queue again, send a payment link by SMS or email: they finish the payment on their own device, against the same amount the agent already set up.
The caller has no card to hand. The card is in another room, expired, or they'd simply rather not use one. Take a bank payment on the same call instead. See ACH and bank payments over the phone.
An operation that treats these as designed paths rather than exceptions collects more of the payments it has already earned on the call.
When the agent isn't human
The "agent" in agent-assisted no longer has to be a person. The same secure capture pattern works when an AI voice agent is running the call: the AI handles the conversation, invokes the secure payment step when the caller is ready, and receives only the result, so card data never reaches the AI platform, its transcripts or its recordings. The compliance logic is identical; the thing being kept away from the card just happens to be a model instead of a person. If your roadmap includes automated voice, it's worth choosing a capture approach that supports both from the start. See AI voice agents and PCI compliant payments.
How Shuttle handles agent-assisted payments
Shuttle provides agent-assisted capture as part of one payment layer across voice, links and bank payments:
It runs on Twilio's voice infrastructure. Shuttle is Twilio's chosen provider to enable Twilio Pay for many payment gateways.
Card details are tokenized with the payment gateway itself. Shuttle holds no card vault of its own, so the capture doesn't create a new place where card data accumulates.
Your gateway, not ours. Shuttle works with 40+ payment gateways, so agent-assisted payments settle through the merchant account you already have. Voice capture works on many supported gateways; payment links cover the rest.
The recoveries are built in. Payment links by SMS or email for the dropped call, bank payments for the caller without a card, so a failed card moment doesn't become a lost payment.
Multi-client routing. If you collect for many clients, each with their own merchant account (answering services, billing services, collections servicers), every payment routes to the right client's account automatically. See taking payments on behalf of your clients.
Agent-assisted payments FAQ
What are agent-assisted payments?
Agent-assisted payments are card payments taken on a live call where the caller enters their card number on their phone keypad instead of reading it aloud. The agent stays on the call throughout, the digits route directly to the payment gateway, and the card number stays out of the phone system, the recording and the agent's screen.
Does the agent hear the card number?
No. The caller types the number rather than speaking it, and the keypad tones are kept out of the agent's audio path. The agent's screen shows masked progress, enough to see the caller is entering digits, never the digits themselves.
Does agent-assisted capture work with call recording?
Yes, and that's one of its main advantages. Because the card number never enters the call audio, the recording can run through the entire payment without capturing card data. There's no pause to remember and no gap in the recording.
What does it do to our PCI scope?
Implemented correctly, agent-assisted capture keeps card data out of your phone system, call recordings and agent desktops, which typically takes those systems out of PCI DSS scope and supports the lighter self-assessment routes. Where your operation lands exactly depends on the details of your environment, so confirm your SAQ level with your acquirer or assessor.
Can an AI agent take the payment instead of a human?
Yes. The same secure capture works when an AI voice agent is on the call: the AI triggers the payment step and receives only the result, so card data never reaches the AI platform or its transcripts. See AI voice agents and PCI compliant payments.
Do we have to change payment providers?
Not with a gateway-agnostic capture layer. Shuttle works with 40+ payment gateways, so agent-assisted payments settle through your existing merchant account rather than forcing a switch. Voice capture works on many supported gateways; payment links cover the rest.
Related reading
PCI Compliant Phone Payments: How to Take Card Payments Over the Phone
DTMF Payment Processing: PCI Compliant Capture, Clamping & Masking
Virtual Terminal Payments: PCI Rules and Secure Alternatives
Taking payments on live calls without the card data? Talk to us. If you'd rather explore the technical side first, docs.shuttleglobal.com covers the flows, with sandbox accounts available for testing.