User GuideCallTrust Manager

CallTrust Manager — User Guide

This guide covers CallTrust Manager's day-to-day features from the perspective of the people who use them: Admins and Members. Each section describes what the feature is for, how to use it, and what each role can see or do.

CallTrust Manager helps your team detect whether your business phone numbers are being flagged as spam, track the evidence, and document a case to get a wrong label removed. It is a record-keeping and packet-building tool — it does not itself contact carriers or change how your numbers are labeled. The important caveats about that are called out in each section below, especially under Remediation.

Getting Started / Onboarding

How you sign in

CallTrust Manager has two roles:

  • Admin — full access, plus the extra Admin menu (Users, Audit Logs, Provider Integrations) and a few actions Members can't do (deleting numbers, approving/rejecting remediation, editing Business Profile settings).
  • Member — full access to the day-to-day workflow pages, but none of the Admin-only pages or actions.

There are two ways to get an account, depending on whether the app has been set up yet:

1. The very first person (becomes the Admin). The first person ever to use a fresh CallTrust Manager installation sets up the first account themselves. On the sign-in screen they'll see Create your account instead of Sign in; they enter a First Name, Last Name, email, and a password (8–128 characters) and click Create account. Both name fields are required — leaving either blank shows a field-level error, the same way an empty email or password does. This first account is automatically made an Admin. This one-time setup step is only available while no account exists yet — once any account exists, the registration form is gone, and anyone else who tries is told "An account already exists. Please sign in instead."

2. Everyone else (becomes a Member, automatically, via Google). After that first account exists, every other employee signs in with Continue with Google using their company Google account. As long as their email is on an allowed company domain (currently taxquotes.com and taxsolve.com), signing in for the first time automatically creates their account as a Member — there's no separate "invite" or "add user" step, and an Admin does not (and cannot) create the account by hand. If Google supplies a first and last name for that account, CallTrust Manager captures them automatically at that moment — nothing to type.

A Google account that is not on an allowed domain (a personal @gmail.com address, or an outside contractor) is refused with "This Google account isn't authorized for this app." There is no way to grant such a person access from inside the app — see "Changing who is allowed in" below.

Your avatar badge

Once you're signed in, the circle in the top-right corner of every page shows your initials — the first letter of your first name plus the first letter of your last name, uppercased. If no name is on file for your account (an account created before this feature existed, or a rare Google sign-in where Google didn't supply a name), it falls back to showing the first letter of your email address instead — never a generic placeholder.

Names are captured exactly once, at account creation — typed in, or auto-filled from Google — and there's no "edit my name" screen afterward. A later Google sign-in never overwrites a name already on file. An Admin/IT can run a one-off script to backfill older accounts that predate this feature.

Promoting, demoting, and deactivating people (Admins)

Once someone has an account, an Admin manages it from the Users page:

  • Make Admin / Make Member — promote a Member to Admin, or demote an Admin back to Member. A role change takes effect the next time that person signs in, not instantly mid-session.
  • Deactivate / Reactivate — block someone from signing in without deleting their account or history, and later restore access. Deactivation is not instant for someone already signed in — new sign-ins are blocked right away, but an existing session can keep working for up to about 5 minutes until the app re-checks it.

Changing who is allowed in

The list of allowed Google domains (today: taxquotes.com and taxsolve.com) is not something you change from any screen in the app — it is part of the server's configuration, and a change only takes effect after the application is restarted. If a new person needs access from a domain that isn't on the list, that's a server-configuration request, not something an Admin can do from the Users page.

Dashboard

What it's for: the landing page after sign-in, giving a one-glance overview of your numbers' health. Both Admins and Members see the same Dashboard.

What you see:

  • Summary cards: Total Numbers, Clean, Warning, Spam Risk (reputation rollups), Open Spam Reports, and Pending Remediation. Every card is clickable — it jumps to the matching filtered list (e.g. clicking Spam Risk opens Phone Numbers pre-filtered to that reputation).
  • A Top Risky Numbers table listing the highest advisory-risk numbers, with Label, Risk Score, Risk Level, and Reputation badge. Click a row to jump to that number on the Phone Numbers page.

The Risk Score and the Reputation badge are different signals. The Risk Score/Risk Level is the app's own internal advisory score computed from your caller-ID checklist, call analytics, and spam-report counts — it does not include carrier "spam" labels. The Reputation column reflects the carrier reputation observations you've recorded separately.

A number can show a low Risk Score (looks healthy) and still carry a Warning or Spam Risk reputation badge, or vice-versa. Watch both columns, not just one.

Phone Numbers

What it's for: the master list of every outbound number you're tracking — the starting point for everything else; most other pages let you pick one of these numbers to work on.

  • A searchable, filterable table: Number, Label, Department, Status (Active/Inactive), Risk (level + score, e.g. "Low · 90"), Reputation, Created. Filter by Status, Risk Level, and Reputation; search by number/label/department; sort any column.
  • + Add Number opens a form. The Number must be E.164 format — a leading + and 1–15 digits, e.g. +13105550100. Optional Label, Department, Provider, Status, Notes. Both roles can add/edit numbers.
  • Edit reopens that form. Delete is Admin-only — permanent, and also removes the number's checklist, reputation history, spam reports, remediation requests, and call analytics. No undo.

The advisory Risk Score does not include carrier spam labels. It starts at 100 and subtracts points for things within your control: an incomplete caller-ID checklist, poor call-analytics figures (low answer rate, high short-call rate, high complaint rate, after-hours calls), and 3+ open spam reports. Higher is healthier: 80–100 = Low, 50–79 = Medium, 0–49 = High.

A number can be actively labeled "Spam Likely" by a carrier and still show a good Low-risk score, because the score never looks at carrier reputation data — that's why the Reputation column exists separately.

Risk History (per number)

Each row has a Risk History button (both roles) showing a history of risk-score snapshots over time.

  • Each snapshot shows date/time, score, Risk Level, and a reason badge: Scheduled (automatic daily snapshot), Manual, or PreRemediation/PostRemediation (captured automatically around a remediation submission/decision).
  • Filter by Reason or a From/To date range. Capture Snapshot Now records a Manual snapshot immediately.

The Capture Daily Snapshots button on the main page (Admin-only) triggers the daily-batch snapshot on demand for every active number.

Number Control Center

Per-number drill-down · both roles

What it's for: a single page pulling together everything CallTrust Manager knows about one phone number — identity, advisory risk, carrier reputation, remediation, call behavior, risk history, and Caller ID/CNAM setup — plus a combined history feed, so you don't have to visit six separate pages.

How to get there: on the Phone Numbers page, click anywhere on a number's row (not the Edit/Risk History/Delete buttons). Opens /phone-numbers/{id}. Click ← Back to Phone Numbers to return.

It's read-only. "This page consolidates existing data — it is read-only; use each card's link to make changes." Every card links to the existing page where the real editing happens, pre-filtered to this number.

The header band shows the number, Label, Department, and three badges: Active/Inactive, Risk: [level] · [score], and Reputation: [status].

The cards, in order:

  1. Identity & Inventory — the number's Number, Label, Department, Provider, Status, Created date, and Notes. Links to Edit → on Phone Numbers.
  2. Reputation — rolled-up status badge plus the latest observation per carrier (status, spam-label text, Source, checked date). Links to Reputation →.
  3. Registration & Remediation — most recent remediation request (Target, Status, dates, count of open requests) plus a Voice Integrity Registration area showing "Registration: [status]" when the most recent request targets Twilio and has a vendor status on file. Links to Remediation →.
  4. Call Behavior — most recent call-analytics entry ("Latest") and the one before it ("Previous") for comparison. Links to Call Analytics →.
  5. Risk History — a compact list of recent snapshots. Links back to the Phone Numbers list (Risk History is a pop-up there, not its own page).
  6. Caller ID / CNAM — checklist completion % and CNAM display name. Links to Caller ID →.
  7. Activity Timeline — a full-width card at the bottom (see below).

The Activity Timeline is not an audit trail. It's a combined, newest-first feed assembled from existing records (reputation observations, spam reports, remediation requests, risk snapshots, call-analytics entries), paged 20 per page. It shows what happened and when, but not who did it — for that, Admins use the Audit Logs page.

A note on Twilio data: the only Twilio-derived data on this page is the Voice Integrity "Registration: [status]" line, shown only when the most recent remediation request targets Twilio with a vendor status on file. There is no live, continuous Twilio reputation monitoring here — everything else reflects data your team entered manually (plus the optional, opt-in Nomorobo-via-Twilio check described under Reputation).

Caller ID / CNAM Checklist

What it's for: tracks, per number, whether you've completed the basic "look legitimate to carriers" setup steps. A more complete checklist improves the advisory Risk Score. Both roles can view and edit.

  1. Pick a number from the Phone number dropdown. (If no checklist exists yet: "No checklist yet — saving creates one.")
  2. Tick the five checklist items: CNAM configured, Listed on business website, Voicemail configured, Opt-out available, STIR/SHAKEN enabled.
  3. If CNAM is configured, enter the CNAM display name (carrier maximum 15 characters).
  4. Add optional Notes, then click Save checklist.

A progress bar shows completion as X/5 — N% complete (each item worth 20%). "Completion percentage feeds the advisory Risk Score; it is guidance, not a carrier guarantee."

Reputation

What it's for: where you record and review what carriers actually think of each number — including whether a carrier has applied a spam label. This is the carrier-facing signal the advisory Risk Score deliberately ignores. Both roles can view and add observations.

  • A table: Number, Carrier, Reputation (Clean/Warning/SpamRisk/Unknown), Spam Label, Checked date/time, Source (Manual or a provider), and the number's current Risk for context.
  • Filter by Search, Phone number, Carrier, Reputation status. Clicking a row also selects that number in the Phone number filter, same as picking it from the dropdown.
  • + Add Reputation — the primary, unchanged manual-entry flow.
  • Check via Telnyx — appears only if an Admin has enabled a Telnyx credential; requires a selected number. Returns sample/placeholder data in this release, not a live lookup.
  • Fetch Nomorobo score (Twilio) — optional, opt-in automated datapoint (see below).

Why this page matters: a carrier spam label shows up here and is not reflected in the Risk Score. A number with a great Risk Score can still carry a "Spam Likely" label — check this page (and the Dashboard's Reputation column) regularly.

Optional: Fetch Nomorobo score (Twilio)

One automated, third-party spam-analytics datapoint from Twilio Lookup + the Twilio Marketplace Nomorobo Spam Score add-on — a yes/no signal, not a carrier verdict, and not a replacement for manual entry. It doesn't run on a schedule; you fetch it per number, same as Check via Telnyx.

  1. Open Reputation and select a number in the Phone number filter.
  2. If an Admin has configured/enabled a Twilio credential (and the tenant's Twilio integration is on), Fetch Nomorobo score (Twilio) appears next to Check via Telnyx.
  3. Click it — the label changes to "Fetching…".
  4. On success, a row is added: look for Combined in Carrier and Twilio in Source. "Likely a robocall" shows as Reputation: SpamRisk with Spam Label "Nomorobo: likely robocall"; otherwise Clean.

It participates in the number's reputation history exactly like any other row — if it's the most severe result, it drives the rolled-up Reputation badge everywhere, and can trigger the same spam-label alert email a manual entry would.

If the Nomorobo add-on isn't installed/available on the Twilio side, the fetch fails gracefully with an inline message — nothing crashes, no row is added, and the rest of the page is unaffected.

Turning it on is a two-part, out-of-band setup: an Admin enables a Twilio credential on Provider Integrations, the tenant-level Twilio integration is turned on (off by default), and the Nomorobo add-on is installed in the Twilio Console (billed per lookup, separate from Twilio registration for Remediation).

Spam Reports

What it's for: a backlog of individual spam complaints against your numbers. A number with 3 or more open spam reports has its advisory Risk Score reduced. Both roles can log and resolve reports.

  • Table: Number, Reported date/time, Channel, Carrier, Description, Status (Open/Resolved).
  • Filter by Search, Phone number, Carrier, Status, and a Reported from/to date range.
  • + Report logs a new complaint. Edit updates a report; Resolve (Open reports only) marks it handled, removing it from the open count that affects the Risk Score.

Remediation

What it's for: build a documented case ("packet") arguing that a spam label is wrong, track it through a review workflow, and export it to send to a carrier or analytics vendor.

What "Submit" actually does — read this first. Submitting a remediation request does NOT send anything to any carrier, registry, or vendor. Clicking Submit only changes the request's status inside CallTrust Manager (Draft → Submitted) and freezes a snapshot of the packet. Nothing leaves the app.

To get a label reviewed, you take the exported packet and submit it yourself, outside the app — e.g. the Free Caller Registry (freecallerregistry.com), a specific vendor's dispute portal (Hiya, TNS, First Orion), or the carrier's own dispute form. The app doesn't track your case number with them, and removal is not guaranteed.

The workflow:

  1. Create a request (Draft). + New Request: pick the number, enter a Target (e.g. "Hiya") and a Reason. Both roles can do this.
  2. Export the packet. Export downloads remediation-<id>.txt, assembled from your Business Profile, the number's info, its checklist, latest call analytics, current Risk Score, and your reason — ending with a "removal is not guaranteed" disclaimer. Exportable at any status.
  3. Submit (Draft → Submitted). Locks the request and captures the packet snapshot; for most targets, nothing is transmitted. Target "Twilio" is the one exception (see below). Both roles can submit.
  4. Decide (Submitted → Approved/Rejected)Admin only. Once a carrier/vendor responds (or you otherwise close the case), an Admin marks Approve or Reject, optionally with decision notes.

Filter the list by status, including a combined Pending option (Draft + Submitted together) — the Dashboard's Pending Remediation card links here pre-filtered that way.

The one exception: a Target of "Twilio" drives a real registration

Typing Twilio into Target (any case) makes Submit do more — this is now live, no longer gated behind a go-live step:

  • CallTrust Manager calls Twilio's Trust Hub API and registers the number for Voice Integrity, Twilio's program for branding a number with major US carrier analytics engines. This really does leave the app, unlike every other Target.
  • On success, the row grows a "Registration: [status]" line (e.g. "pending-review") with the Trust Product SID in a tooltip. This is separate from the request's own Draft/Submitted/Approved/Rejected status.
  • If the Twilio call fails, Submit still succeeds — the request still moves to Submitted; the Registration line shows a failure status instead.
  • Every other Target keeps the manual export-packet flow exactly as described above.
  • The disclaimer still applies — registering with Voice Integrity reduces mislabeling risk, but is not a guarantee.

Behind the scenes this still relies on a Twilio credential configured on Provider Integrations — an Admin sets that up once, the same as for any other provider.

Keeping a Twilio registration status current: the Refresh button

A Refresh button pulls Twilio's current status on demand. It appears next to the Registration line only when all of these are true:

  • Target is "Twilio" (case-insensitive, trimmed match).
  • Status is Submitted (Draft/Approved/Rejected never show it).
  • A registration was actually recorded (a stored Trust Product SID from a prior successful Submit).

Click Refresh (both roles) — the label changes to "Refreshing…". On success, the Registration line updates live; nothing about the request's Draft/Submitted/Approved/Rejected decision changes. If Twilio is temporarily unreachable, a banner reads "Could not reach Twilio right now — please try again shortly," and the last-known status is left untouched.

Automated Reputation Sweep

Optional · off by default · turned on by your server operator

What it's for: automates the two most repetitive parts of the spam-label workflow — running a reputation check on every number, and keeping submitted Twilio requests' outcomes up to date — so nobody has to click through numbers one at a time. Both pieces are off by default and are switched on as a server-configuration setting, not from any screen in the app, because every automated check is billed by Twilio per query.

The reputation sweep

When enabled, a scheduled job checks every Active phone number through the same check the Fetch Nomorobo score button runs — same results, same history rows, just without anyone clicking.

  • Each run appends a new history row to every checked number (Source: Twilio), exactly like a manual check.
  • If a check finds a spam label on a number that wasn't already flagged: Admins get the usual "Spam label detected" alert email, and a Draft remediation request is created automatically, with a reason like "Automated: Twilio/Nomorobo reported 'Spam Likely' on ..." — that wording is how you tell an automated draft from one a person wrote.
  • The alert email links straight to that draft, one click from Submit.
  • Numbers already flagged don't re-alert or get a duplicate draft — a number with an open (Draft or Submitted) request never gets a second one.

A person still submits. The sweep never sends anything to Twilio's Trust Hub on its own — the draft sits in the Remediation list until someone reviews it and clicks Submit, exactly like a request a person created by hand.

The vendor-status sync and auto-decisions

A second, separate scheduled job does what the Refresh button does — asks Twilio for the current review status — for every submitted Twilio request, on a schedule, and acts on final outcomes:

  • Twilio reports twilio-approved → the request is automatically marked Approved.
  • Twilio reports twilio-rejected → automatically marked Rejected.
  • The decision note reads like "Automatic decision from Twilio vendor status 'twilio-approved' on ..." — again, that's how you spot an automatic decision.
  • Admins get an email for every automatic decision.
  • In-between statuses (pending review, in review) just update the Vendor status shown on the request — no decision is made, and a request whose original registration failed is always left for a person to look at.

Where to see what the automation did

  • Remediation — automated drafts and decisions look like any other request; their reason/decision-note text marks them as automated.
  • Reputation — sweep checks appear as ordinary Twilio-source history rows.
  • Audit Logs Admin — every run logs a summary entry: ReputationSweep.Executed and VendorStatusSync.Executed, recorded under the user system.
  • /hangfire Admin — the jobs appear in Recurring Jobs as nightly-reputation-sweep and vendor-status-sync, next to daily-risk-snapshot.

Good to know: only Twilio is swept — the sample Telnyx integration and the other remediation targets (Hiya, TNS, First Orion) are untouched. Numbers already flagged before the automation was first turned on don't get drafts created retroactively; use the normal Remediation workflow for those. And since checks are billed by Twilio per number per run, cadence (nightly vs. weekly) is a cost decision your server operator makes.

Call Analytics

What it's for: record, per number per day, the raw calling figures that help explain and drive the advisory Risk Score. Entered by hand — the app does not pull them automatically. Both roles can add and edit entries.

  • One row per number per day: Date, Phone Number, Total, Answered, Short, Complaints, Outside Hrs, plus computed Answer Rate, Short-Call Rate, Complaint Rate.
  • Filter by Phone number and a From/To date range. + Add Entry / Edit.

The most recent row for a number feeds the Risk Score: a low answer rate (<20%), high short-call rate (>40%), high complaint rate (>2%), or any after-hours calls each subtract points.

Settings (Business Profile)

What it's for: your organization's Business Profile — shared company details that pre-fill remediation packets. One profile per tenant. Unrelated to sign-in/passwords/access (see Getting Started).

Who can edit: Admins edit and save; Members see read-only fields ("Read-only — contact an admin to change these settings").

  • Business Name (required), optional Website, Contact Email, Contact Phone — appear at the top of every remediation packet.
  • Default Call Purpose, Default Opt-Out Process, Default Sample Script — free text.
  • Time Zone (IANA ID), Business Hours Start/End, Business Days — define "business hours" for the after-hours figure in Call Analytics.

Provider Integrations

Admin configures · both roles use the check

Lets an Admin store credentials for outside reputation-check vendors (Telnyx, Twilio, Hiya, First Orion, TNS) and lets any signed-in user run a check against a number, directly from the Reputation page.

Where: Admins see Provider Integrations in the Admin nav section, at /admin/provider-integrations. Members can't reach it (403 on direct API access).

Telnyx is a sample integration, off by default in production. Five providers can be configured, but none queries a real carrier today. Telnyx is the only one with any check behind it, and that check returns fixed placeholder results — not a live lookup. The other four do nothing yet.

Do not rely on a provider check as evidence a number is or isn't spam-labeled — enter real carrier observations by hand via + Add Reputation instead.

How an Admin configures a provider credential

  1. Open Provider Integrations from the sidebar.
  2. The Provider Credentials table lists existing credentials: Provider, Display Name, Enabled, Last Connected, Last Sync Status.
  3. Click + Add Credential.
  4. Fill in Provider (dropdown of the five), Display Name (required, up to 100 chars), API Key (required, masked), API Secret (optional, masked), and Enabled (checked by default — must be enabled to appear on the Reputation page).
  5. Click Add Credential to save.

Editing: Provider becomes read-only after creation (delete and re-add to switch). Key/secret fields show a placeholder; leaving them blank keeps the existing value. Deleting: requires confirmation and immediately removes the "Check via…" button for all users. Duplicates: only one credential per provider per tenant.

How any user runs a reputation check via a provider

  1. Open Reputation, select a number in the Phone number filter.
  2. If a Telnyx credential is configured and enabled, Check via Telnyx appears next to + Add Reputation.
  3. Click it (label changes to "Checking…"). On success, a confirmation message appears and new Telnyx-sourced rows appear in the table (Source = Telnyx) — remember, these are sample data.
ActionAdminMember
View Provider Integrations pageYesNo
Add / edit / delete credentialsYesNo
View stored keys/secrets in plaintextNo (nobody can)No
See "Check via Telnyx" (once configured)YesYes
Run a Telnyx reputation checkYesYes
Use "Check via…" for Twilio/Hiya/FirstOrion/TNSNo — not built yetNo — not built yet

Users

Admin only

Where an Admin manages access: role (Admin/Member) and whether an account is active. Found at /admin/users. The table lists Email, Role, Sign-in Methods, Status, Created.

Deactivating a user

  1. Open Users, find the user's row.
  2. Click Deactivate (shown only for currently active users).
  3. Confirm in the dialog: "Deactivate [email]? They will be signed out and blocked from signing in."
  4. On success, the Status badge changes to Inactive and the row is dimmed.

You can't deactivate the tenant's last active Admin. The dialog shows an error: "Cannot deactivate the last remaining active Admin. Activate or promote another Admin first."

Reactivating a user

Click Reactivate on an Inactive user's row, confirm, and they can sign in again immediately.

Deactivation isn't instant for an active session

New sign-ins are blocked immediately, but an already-signed-in session can keep working for up to about 5 minutes until the app's next periodic re-check. There's no button to force an immediate cutoff.

ActionAdminMember
View the Users pageYesNo
Deactivate / Reactivate a userYesNo
Change a user's roleYesNo
Deactivate the last active AdminNo — blockedN/A

Audit Logs

Admin only

What it's for: a read-only trail of significant actions — creates/edits/deletes, state changes (e.g. submitting a remediation request), sign-ins, role and activation changes. Found at /admin/audit-logs.

  • A newest-first table: Timestamp, User, Action (e.g. PhoneNumber.Created, Remediation.Submitted), Entity, Details (expandable), IP Address.
  • Filters: User, Action (by module, e.g. Reputation.*, Remediation.*), and a From/To date range.

Nothing here is editable or deletable — it's the place to reconstruct what happened to a number, report, or account.

Background Jobs (Daily Risk Snapshot)

CallTrust Manager automatically records a risk-score snapshot for every active phone number once a day, keeping Risk History populated with a "Scheduled" data point daily without anyone having to run it.

Looking for the reputation-check and remediation-decision automations instead? See Automated Reputation Sweep — they're two separate, optional jobs alongside this one.

What the daily job does

  • Once a day, snapshots every Active number, filed under reason Scheduled.
  • Idempotent per day (UTC) — won't create a duplicate if one already exists today.
  • Runs on its own, at a fixed time (6:00 AM UTC), every day.

Checking the job itself is running

Admin only — a separate, direct-URL tool, not linked from the app's navigation:

/hangfire

Append this to your CallTrust Manager URL. Members and signed-out users are refused access. The Recurring Jobs section lists daily-risk-snapshot with its schedule and next run time; the Jobs history shows past runs.

This page is a general-purpose job-scheduler tool (Hangfire), not a custom CallTrust screen — the daily-risk-snapshot job name is what to look for.

New-user welcome email (Google sign-in)

When someone signs in with Google for the first time and their account is auto-provisioned, CallTrust Manager automatically sends a welcome email in the background, the same way as the daily snapshot job — a slow or failed send doesn't hold up sign-in. If a send fails, an Admin can check /hangfire's Jobs history; there's no in-app indicator otherwise.

Risk & Status Glossary

The badges and statuses that show up across Phone Numbers, Reputation, and Remediation.

StatusWhere you'll see itMeaning
LowPhone Numbers · DashboardAdvisory Risk Score of 80–100.
MediumPhone Numbers · DashboardAdvisory Risk Score of 50–79.
HighPhone Numbers · DashboardAdvisory Risk Score of 0–49.
CleanReputation · DashboardNo spam label recorded from any carrier or source.
WarningReputation · DashboardA mild risk flag on file, short of a full spam label.
Spam RiskReputation · DashboardA "Spam Likely"-type label is on file for this number.
DraftRemediationRequest created, fully editable, not yet submitted.
SubmittedRemediationPacket snapshot frozen. Nothing is sent to a carrier automatically (Twilio target aside).
Approved / RejectedRemediationYour own recorded decision about how the case turned out.
"Automated: ..."Remediation reason textA Draft created by the reputation sweep, not a person — see Automated Reputation Sweep.
"Automatic decision from ..."Remediation decision noteAn Approve/Reject decided by the vendor-status sync, not an Admin.