The two instruments
Call Analytics (TAC > user > Meetings & calls): per-call forensics — every leg, every stream, per-direction jitter/loss/RTT graphs, device and network metadata, connectivity type (direct/relay/TCP). The support-desk tool: one user, one bad call, minutes to verdict. The two support-engineer roles exist precisely to grant this without admin writes.
CQD (Call Quality Dashboard): the fleet view — every call's telemetry, aggregated and sliceable (building, subnet, device, capture device, transport, VPN flag). The engineering tool: is Building 4 worse than the estate? Did the firewall change on the 12th move the TCP-fallback share? Its power multiplies with building/subnet data uploads — the tenant file that maps subnets to places; without it CQD is a good chart with amnesia about geography.
The triage ladder (run it in order)
- One complaint → Call Analytics on that call: which STREAM degraded, which DIRECTION, what transport? 70% of tickets end here (device, Wi-Fi, VPN, TCP fallback — all visible).
- A pattern claim ("mornings are bad") → CQD filtered to the population/ time: is poor-call % actually elevated? Against which dimension?
- A location claim → CQD by subnet/building (needs the upload): one subnet red = network path; all subnets red = something shared (egress, proxy).
- A change claim ("since last week") → CQD trend + the serv365 drift log for the same window: config changed? Microsoft advisory? Firewall ticket? The correlation IS the Pulse thesis — quality curves and change events on one timeline.
Reading the numbers like a grown-up
- Poor-call classification is composite (loss/jitter/RTT thresholds) — track the PERCENTAGE trend, not single-call absolutes.
- Transport is the loudest signal: TCP share rising = UDP being denied somewhere; VPN-flagged share rising = split-tunnel decay.
- Wired vs Wi-Fi split, capture-device names (that one USB dock…), and inside/ outside-corp flags each separate a class of cause in one filter.
What to watch (proofs)
- Standing weekly: CQD poor-call % trend, transport mix, top-5 worst subnets — fifteen minutes that pre-empts the quarterly crisis.
- Per ticket: the Call Analytics permalink attached to the ticket — closure with the graph, not with 'seems fine now'.
- Upload freshness: building data last-updated — an office move without a CQD upload update silently un-maps a site (geography lies until refreshed).
- The correlation habit: any CQD inflection date vs the drift/MC timeline — serv365's verdict/drift feed is the missing 'what changed' column CQD lacks.