---
title: Storage destination
description: "Choose which storage bucket an agent uses for recordings and transcripts: the company default, or a bucket connected under Settings, Storage."
---

**Storage destination** in the **Privacy** card under **Advanced** picks the bucket
where an agent's recordings and transcripts are written. **Company default** uses
the organisation-wide setting from **Settings**, **Storage**; any other entry is a
storage connection you added there, so one agent's data can live in its own bucket.

:::note[Bring your own storage]
Callab writes to Amazon S3 and any S3-compatible provider: Cloudflare R2, Backblaze
B2, Wasabi, DigitalOcean Spaces, MinIO. Connect one under **Settings**, **Storage**
first; until then the list holds **Company default** only.
:::

![The Storage destination selector.](/media/build/storage-destination-select.webp)

## Prerequisites

- A storage connection under **Settings**, **Storage**, added with **Add Storage**:
  endpoint URL, display name, access key, secret, bucket, optional region and path
  prefix, tested with **Test Credentials**. See [Storage](/account/storage).
- Permission to edit the agent.

## Configuring it

1. Open the agent and choose **Advanced** under **Build**.
2. In **Privacy**, open **Storage destination**.
3. Pick **Company default** or a named connection.
4. **Save**.

## Reference

| Option | Default | What it does |
|---|---|---|
| **Company default** | Yes | Uses your organisation-wide storage setting. With no connection added, that is Callab's own storage |
| A named connection | | Listed as the connection name with its bucket in brackets. Writes this agent's recordings and transcripts to that bucket, under the connection's path prefix |

## Why a per-agent destination

- A client or department that must hold its own recordings gets its own bucket and
  credentials.
- Data residency: an agent serving one region writes to a bucket in that region.
- Retention on your terms: lifecycle rules on the bucket decide how long recordings
  live.

## Behaviour and limits

- The destination applies to new conversations after the save. Existing files are
  not moved.
- The dashboard still plays and links recordings from the bucket; the **Download**
  link on a call points at the stored file.
- If the credentials stop working, recordings fail to upload for that agent. Watch
  for calls with no recording under **Call Logs** after rotating keys, and use
  **Test Credentials** under **Settings**, **Storage** after any change.
- Credentials are encrypted at rest; the secret key is never shown again after it
  is saved.
- [Data retention](/build/privacy/data-retention) still applies: with **Opt-Out of
  Data Storage** nothing is written to any destination, and the **Storage
  destination** field is hidden.

## Verify

Run a **Call** test, then check the bucket: a new recording appears under the
connection's path prefix, and the call's page under **Call Logs** plays it.

## Related

- [Storage](/account/storage)
- [Data retention](/build/privacy/data-retention)
- [PII redaction](/build/privacy/pii-redaction)
- [Call details](/operate/call-details)
