# How To's

# IVR

# Five9 - IVR - Emergency Mode

The Importance of Secure Variable Management

In modern IVR systems, the way you manage data directly impacts security, compliance, and the quality of both customer and agent experiences. As you modularize your Five9 IVR scripts, understanding how to handle variables is essential for protecting sensitive information, ensuring PCI compliance, and enabling actionable reporting. Mastering variable usage is the foundation for building secure, flexible, and effective IVR solutions.



Key Terms for Secure and Effective IVR Scripting in Five9

Script Variable: A variable local to a specific script, used for temporary data storage and not visible in reports or to agents.

Call Variable: A global variable accessible across scripts, reportable, and can be marked as sensitive for secure data handling.

Input/Output Parameter: A setting that allows script variables to pass data between main and foreign scripts during execution.

PCI Compliance: Adherence to Payment Card Industry standards, requiring secure handling and masking of sensitive payment data in IVR systems.



Script Variables are used within a single script for temporary calculations or logic, as they are not reportable or visible to agents. Call Variables, however, are global, accessible across scripts, and can be used for data sharing and reporting, with options for sensitivity and visibility to agents.









Variable Properties and Use Cases

Script Variables (Scope and Limitations: Script Variables are confined to the script in which they are created. They are not accessible outside that script unless explicitly passed as input or output parameters. This makes them suitable for temporary logic or calculations that do not need to be tracked or reported. However, their limited scope means they should not be used for data that needs to be shared or retained beyond the script's execution. For example, a Script Variable might be used to store a temporary counter or a flag within a single IVR flow.



Call Variables (Global Scope and Reporting): Global Scope and Reporting: Call Variables are accessible across all scripts within the domain. They are created in the Admin Console and referenced in scripts using the [Group Name].[Variable Name] format. Because they are global, Call Variables are ideal for passing data between main and foreign scripts, and for capturing information that needs to be reported or displayed to agents. For instance, a Call Variable can be used to store a customer's payment status or rewards number, making this information available for reporting and agent screen-pops.



Data Masking for PCI: Call Variables can be marked as sensitive, which ensures that their values are masked in server logs and reports. This is a critical feature for maintaining PCI compliance when handling credit card numbers or other confidential data. Script Variables do not offer this level of masking and should never be used for sensitive information. Always use Call Variables with the sensitive flag enabled for any data that must be protected under PCI standards.



Agent and Reporting Visibility: Only Call Variables can be configured to display their values to agents or be included in reports. Script Variables are invisible to both agents and reporting tools. This distinction is crucial when designing IVR flows that require agents to see or act on collected data, or when you need to track outcomes for analytics and compliance. For example, displaying a payment status or rewards number to an agent is only possible if that data is stored in a Call Variable.

Understanding Data Flow Between Scripts

When working with multiple scripts, it's important to understand how data moves between them. Script Variables are passed explicitly as input or output parameters when one script calls another. This means you must specify which variables to share, ensuring controlled data flow.

In contrast, Call Variables are globally accessible throughout the call session. They do not require explicit passing and are automatically available to all scripts. This global scope makes Call Variables especially useful for securely handling sensitive data, such as when modularizing IVR flows for reporting and compliance purposes.

Introduction: Managing data flow between main and foreign scripts is essential for modular, secure and reportable IVR design

Define Variables in Admin Console
Start by identifying all the data points your IVR flow will need to capture or share. Create Call Variables in the Admin Console for any information that must be reported, displayed to agents, or handled securely (such as payment details). Group related variables for easier management.

Configure Script Variables as Input/Output
For temporary or script-specific data, define Script Variables within your IVR scripts. When passing data between main and foreign scripts, set these variables as input or output parameters in the relevant modules to control their flow explicitly.

Use Call Variables for Sensitive Data
Whenever you need to collect, store, or report sensitive or compliance-related data, use Call Variables marked as sensitive. This ensures data is masked in logs and reports, supporting PCI compliance and secure operations.

Test Data Flow and Visibility
After configuring your variables, thoroughly test the IVR scripts to confirm that data passes correctly between scripts. Check that sensitive data is masked where required and that agents can see only the appropriate information.

Validate in Reports and Agent Views
Finally, review reports and agent screen-pops to ensure all necessary data is captured, visible, and compliant with security standards. Adjust variable configurations as needed to align with business and compliance requirements.





Best Practices for Variable Management

Secure Data Collection: Always plan your variable usage before building scripts. Identify which data points are sensitive and require masking, and ensure these are stored in Call Variables marked as sensitive. Avoid using Script Variables for any information that could be considered confidential or that needs to be tracked beyond the script's execution. Regularly review your scripts to ensure that sensitive data is never stored in local variables or exposed in logs. Use input validation and data constraints to prevent accidental capture of unnecessary or risky information.