Documentation · Zoom Integration

LeadProof for Zoom Phone — Installation and User Guide

LeadProof Script Adherence & Call Coaching is an AI-powered call audit platform for insurance agencies that use Zoom Phone. This page walks you through installing LeadProof into your Zoom account, using it day-to-day, and removing it if needed.

LAST UPDATED · AUGUST 28, 2026

What LeadProof does

LeadProof monitors recorded calls made via Zoom Phone, automatically transcribes them, and scores each call against your agency's custom compliance script using AI. Each agent receives a secure email link to view their own audit feedback. Supervisors and Admins see aggregated compliance metrics in the LeadProof dashboard.

You provideLeadProof returns
Recorded Zoom Phone calls (automatic via webhook)Per-call compliance score (0–100%)
Your compliance script (set of required talking points)AI-generated coaching feedback in plain language
Agent roster (one-time setup)Trend analysis: who's on script, who's drifting
Compliance Evidence PDF reports for carriers and audits

Part 1 — How to install LeadProof

If something does not work during or after installation, jump to Troubleshooting — it covers the failures we see most often and what to check for each one.

Prerequisites

  • A Zoom Pro or Business subscription with Phone enabled
  • Cloud Recording enabled on your account (so recordings get sent to LeadProof)
  • Owner or Admin role on your Zoom account. LeadProof is an Admin-managed app: only an account administrator can authorize it, because the permissions it requests apply to the whole account rather than to a single user.
  • A LeadProof account (request access at sales@leadproof.app — invite-only during beta)

Installation steps

You start the installation from LeadProof, not from the Zoom App Marketplace listing. LeadProof needs to know which agency it is connecting your Zoom account to, so the authorization is initiated from inside your own signed-in workspace.

  1. Sign in to LeadProof at leadproof.app/login with your Admin account.
  2. Open Settings from the left sidebar, and scroll to the Integrations section. You will see a Zoom Phone card marked Not connected.
  3. Click "Connect Zoom".Your browser is sent to Zoom's authorization page.
  4. Zoom shows the consent screen listing exactly two permissions, and no others:
    • View phone users — reads your Zoom Phone directory so each recording is attributed to the right agent
    • View a call recording — downloads the audio file so it can be transcribed and scored

    Both are account-level, read-only permissions. Account level is deliberate and unavoidable: LeadProof audits the calls of your whole team, and account-scoped permissions are the only way Zoom exposes recordings across every user. Read-only is equally deliberate — LeadProof never creates, modifies, or deletes anything in your Zoom account, and requests no permission to write, to join or read meetings, to read calendars, or to manage users.

  5. Click "Allow". Zoom sends you back to LeadProof, and the Zoom Phone card now reads Connected, with Disconnect and Reconnect buttons in place of the original one.
  6. You're done.From this point forward, every Zoom Phone call recorded on your account is processed by LeadProof automatically. There is nothing to install on any agent's machine.

What happens on installation

  • Your Zoom OAuth access and refresh tokens are stored in LeadProof's database, encrypted at rest with AES-256-GCM.
  • A webhook subscription for phone.recording_completed is created — Zoom will notify LeadProof every time a call recording completes.
  • Your LeadProof org is provisioned with a default scoring threshold (85%) and an empty agent roster, ready for you to add agents.

Part 2 — How to use LeadProof

After installation, three steps to start getting audited calls:

Step A — Add your agents

  1. Log in to https://www.leadproof.app/login.
  2. Sidebar → Team.
  3. Click + Invite agent. Enter their name, email, and Zoom user ID (or upload a CSV with the bulk template).
  4. Agents do not need to log in to LeadProof. They receive audits via email links.

Step B — Configure your compliance script

  1. Sidebar → Scripts.
  2. Click + New script (or start from one of the built-in templates, if your agency has a script library enabled).
  3. Define required elements: things every agent must say or do during a call (e.g., "State that the call is recorded", "Confirm caller's identity", "Disclose TCPA notice").
  4. Activate the script. It becomes the default scoring criteria for all new calls.

Step C — Make calls as normal

Agents make calls from Zoom Phone the same way they always have. There is nothing for the agent to install or change. As long as Cloud Recording is enabled on your Zoom account, recordings flow to LeadProof automatically.

What the agent receives

After each audited call, the agent receives an email titled "Your call coaching feedback is ready" with a magic-link button. The link grants 30-day read-only access to:

  • Their own compliance score
  • AI-generated coaching paragraph in plain language (Spanish or English depending on the call language)
  • Breakdown of script elements: HIT vs MISSED, with reasoning per element
  • Recording playback (if Cloud Recording stored it)

What the Admin sees in the dashboard

Dashboard areaWhat it shows
Dashboard (home)Compliance Rate (org-wide, 7-day trend), audit volume vs monthly quota, urgent flags
TeamAll agents, their compliance scores, trend indicators, "At risk" status
LeaderboardTop performers this week / month / quarter
ScriptsYour active compliance scripts and version history
EvidenceGenerate audit-grade PDF reports for carriers, legal counsel, or compliance audits
SettingsBilling, integrations, threshold configuration

Reading an audit

When you click into an individual audit:

  • Compliance Score (large number, 0–100%, color-coded green/amber/red)
  • Conversational Score (secondary metric for tone, pace, clarity)
  • AI Feedback paragraph — written explanation of what went well and what to improve
  • Script Elements table — each required element with HIT/MISSED status and reasoning
  • Recording player — listen to the audio inline
  • Transcript viewer — full Deepgram transcript with timestamps

Part 3 — How to uninstall LeadProof

From Zoom (revoke access)

  1. Sign in to https://marketplace.zoom.us.
  2. Top right → Manage Added Apps.
  3. Find "LeadProof Script Adherence & Call Coaching" in the list.
  4. Click Remove. Confirm.

Zoom will:

  • Invalidate the access and refresh tokens immediately
  • Notify LeadProof via a removal webhook
  • Stop sending recording webhooks to LeadProof

LeadProof will:

  • Clear the encrypted tokens from your org row in the database
  • Mark the integration as "Disconnected" in your LeadProof Settings page
  • Stop processing new recordings
  • Delete the Zoom-derived content we hold for your organization — the recording audio and the transcripts — and verify the deletion before confirming it to Zoom

What happens to your existing data

  • Recording audio files are deleted as soon as Zoom notifies us that you removed the app. You do not have to ask, and there is no waiting period.
  • Transcripts are deleted with the audio: word for word, they are what was said on your Zoom calls.
  • Links to your Zoom recordings are cleared from our call records.
  • The deletion is verified, not assumed: we re-count your recording storage and every affected table afterwards, and if anything survives we do not report the deletion as complete to Zoom — we fail loudly and retry instead.
  • Audit results and scores already generated are retained — they are your compliance record and you keep access to them. To be exact rather than flattering: each audit carries short verbatim quotes (a dozen words or fewer) as the evidence for what it marks covered, because a score with no evidence is not a compliance record. The audio and the full transcript are gone; those fragments stay inside your own audits, alongside the identifiers that attribute each one to a call and a caller.
  • Agent roster and scripts remain in your LeadProof org so you can reinstall later without losing setup.

To fully delete your LeadProof org (after uninstall)

Email support@leadproof.app with the subject "Delete org" and the email of any Admin user. We will purge all org data within 7 business days and email confirmation, per our Privacy Policy.


Troubleshooting

The app is installed, but no calls arrive in LeadProof

The most common cause is that call recording is not enabled at the account level. Zoom exposes this setting in two different places and only one of them applies:

  • Admin → Account Management → Account Settings → Zoom Phone tab → Automatic Call Recording. This is the one LeadProof depends on.
  • ❌ Personal Phone → Settings. An individual user does not see the account-wide recording option here, so checking it proves nothing.

Also confirm the recording direction covers what you expect — Inbound and Outbound — and that the agent is not paused in LeadProof → Team → Agent settings.

There are recordings in Zoom, but LeadProof shows nothing for them

LeadProof only processes calls recorded after the integration was installed. It does not backfill history, by design: we do not reach into recordings your agents made before you granted access. If a call is newer than the install and still missing, contact support with the call time and the extension.

Only one side of the conversation is being audited

Check whether single-sided recordingis enabled in your Zoom Phone recording settings. In Zoom's own words, it "captures only the Zoom Phone user's audio", and when a call with single-sided recording begins, "disclaimer or consent prompts are not played to any participants".

That has two consequences: the audit only ever sees your agent's half of the call, and the other party is never notified that recording started. Turn it off if you want both sides scored and the consent prompt played.

I disconnected LeadProof, but Zoom still lists the app

There are two removal paths and they do different things:

  • Disconnect inside LeadProof (Settings → Integrations) revokes the access token at Zoom and deletes our stored credentials. The app entry may still be visible in your Zoom account until you remove it there.
  • Remove from the Zoom Marketplace revokes the grant and notifies us, which triggers deletion of the credentials on our side. See Part 3 — How to uninstall for what happens to your data.

Doing both is safe and is the cleanest end state.

Still stuck

Contact us at support@leadproof.app. Response times and hours are listed under Support. Including the account number, the extension and the approximate call time makes a missing-call report much faster to trace.

Part 4 — Architecture overview

For Zoom Marketplace reviewers and security-conscious admins, here is the data flow:

┌──────────────────────────────────────────────────────────────┐
│              CUSTOMER ZOOM ACCOUNT                           │
│                                                              │
│  Phone call recorded → phone.recording_completed event       │
└──────────────────────────┬───────────────────────────────────┘
                           │ webhook signed with HMAC SHA-256
                           ▼
┌──────────────────────────────────────────────────────────────┐
│         LEADPROOF BACKEND (Vercel)                           │
│                                                              │
│  1. Verify HMAC signature                                    │
│  2. Look up agent by zoom_user_id                            │
│  3. Insert call row (status: pending)                        │
│  4. Trigger audit pipeline async                             │
└─────┬──────────┬──────────┬──────────┬───────────────────────┘
      │          │          │          │
      ▼          ▼          ▼          ▼
   Deepgram   Claude    Supabase     Postgres (Supabase)
   (transcribe) (score)  Storage      (RLS multi-tenant,
                         (audio,      AES-256 encrypted
                          private)     at rest)
      │
      ▼
   Email via Resend (magic link to agent)

Security highlights

  • TLS 1.2+ on all connections (enforced by Vercel edge)
  • HMAC SHA-256 signature verification on every Zoom webhook before any processing
  • AES-256-GCM encryption at rest for OAuth tokens
  • Row-Level Security in Postgres ensures cross-org data isolation
  • Least-privilege OAuth scopes— four permissions, all read-only, each mapped to a specific endpoint we call. They are account-level ("admin") because auditing a whole team requires it, but none of them can write, modify, or delete anything, and we request nothing for meetings, calendars, or user management
  • PII handling — only the call transcript is sent to the LLM for scoring, under enterprise no-training terms; raw audio stays in our infrastructure. Your plan defines how long we retain recordings, and deletion on request is verified across every table and your recording storage — see our security and data trust page

Part 5 — Frequently asked questions

Does LeadProof join my Zoom calls or meetings?

No. LeadProof only processes calls after they are completed and recorded. We do not join meetings, do not have RTMS access, and do not consume any bot-attendee resources.

Does LeadProof see calls made before the integration was installed?

No. Only calls recorded after you authorize the app are sent to LeadProof. Historical calls in your Zoom account are not retroactively accessible.

Can I exclude certain agents or numbers from being audited?

Yes. In LeadProof → Team → Agent settings, you can pause auditing per agent. Calls from paused agents are still received via webhook but stored as status: filtered_out and never scored.

How long does scoring take?

Typical pipeline latency from call hangup to audit ready: 3–8 minutes(depending on call length and queue depth). Agents receive their feedback email within 10 minutes for >95% of audits.

Is my agency's call data shared with other LeadProof customers?

No. Row-Level Security policies in our Postgres database enforce strict org isolation. Every query is scoped to the calling user's org_id. We have not had a breach of customer data. We run a full internal security review every 60 days — including our own intrusion testing — and each one is written up with its findings and their fixes. We do not commission third-party penetration tests, and we would rather tell you that than let you assume otherwise.

Where are recordings stored?

In Supabase Storage, on AWS us-west-2 (United States), in a private bucket restricted to audio files. Encryption at rest is enabled at the bucket level, and access is scoped per organization. How long we retain recordings is set by your plan; deletion on request removes the audio, the transcript, and every derived record, and the job verifies itself afterwards. See our security and data trust page for the retention table and the full sub-processor list.

Can I export my audit data?

Yes. On the Dashboard, use Export for your audit history as CSV. For a formal, audit-grade PDF over a specific date range, use Evidence in the sidebar.

What's the difference between LeadProof and a CRM?

LeadProof scores call quality against your compliance script. A CRM tracks call outcomes(was the sale closed). The two are complementary: CRMs measure "did we sell" — LeadProof measures "did we sell properly". Most agencies run both side-by-side.


Part 6 — Support and contact

ChannelWhen to use
support@leadproof.appGeneral questions, troubleshooting, feature requests
jron@leadproof.appSales, partnership, pilot conversations
alerts@leadproof.app(Outbound from LeadProof) — system-generated alerts to your team

Hours of operation: Monday to Friday, 9:00 AM to 6:00 PM US Eastern Time, excluding US federal holidays.

First response SLA: 4 business hours for support requests, 1 hour for production-impacting incidents. Requests received outside business hours are answered on the next business day.

How to open a support request: email support@leadproof.app with your organization name and, when relevant, the call date and agent involved. There is no separate ticket portal or phone support line — email is the single support channel, and it is monitored during the hours above. This guide is the knowledge base; the troubleshooting and FAQ sections resolve the most common issues without contacting us.