Somewhere in your roadmap there is a line that says "record the meeting." It looks like a feature. It is also a promise you are making to every person who ever joins a call with one of your users, most of whom never signed your terms of service. Getting that promise right is a design problem, and it is much cheaper to solve before launch than after.
Two kinds of consent rules
Recording rules split roughly into two families. In some jurisdictions, one participant's consent is enough, and the person doing the recording counts. In others, every participant on the call has to know and agree. Your users are spread across both, their meeting guests are spread across both, and a single call can span both at once. None of this is legal advice, and you should talk to counsel about the markets you serve. But the engineering conclusion does not require a law degree: you cannot know at join time which rules apply, so build for the strictest room.
Building for the strictest room means treating notice as a hard requirement of the recording path, not a setting buried three menus deep. If your architecture makes silent capture possible, someone will eventually use it that way, and you will own the outcome.
Say it three times
Good recording products announce themselves at three moments, because participants arrive through different doors. Someone who accepted the invite a week early, someone who clicked the link two minutes late, and someone dialing in from a phone all need a chance to find out.
- In the invite. If the event was created knowing it would be recorded, the description should say so before anyone joins.
- In the roster. The recorder joins as a visible participant with a clear display name, where anyone glancing at the participant list can see it.
- In the meeting. An announcement when the bot joins, spoken or posted in chat, catches everyone who skipped the invite and never checks the roster.
Redundancy is the point. Any single notice can be missed. All three together make "I didn't know" an unlikely outcome instead of a likely one.
Your job and the host's job
You cannot obtain consent on behalf of your users' guests. The host chooses to record, and the host carries the human obligation to inform the people in the room. What you control is whether the honest path is the default path. Ship notice on by default. Make the bot impossible to hide. Give hosts a one-line way to explain what happens to the recording and how long it lives.
Draw the line explicitly in your docs. Your product provides the notice mechanisms; the host is responsible for using them and for complying with whatever rules govern their calls. Vague ownership here turns into support tickets at best and disputes at worst.
Silent recording is a decision, and a bad one
Every recording product gets the request eventually: can the bot join invisibly, or capture without joining at all. The pitch is always the same: sales calls where a prospect might object, interviews where the notice feels awkward. Decline. A hidden recorder converts a product feature into a covert surveillance tool, and the discovery is never private. One screenshot of an unannounced transcript travels further than any launch post.
There is also a practical floor. The meeting platforms keep adding recording indicators of their own, and a product built on staying hidden is built on a shrinking gap. Visible recording does not have that problem.
Defaults are the policy
Most hosts never change settings, so whatever you ship is what happens in the world. Default the bot to visible. Default the announcement to on. Give the display name a default that carries the product's brand, not a fake human name. Horato's recorder works this way out of the box: it joins as a visible participant whose display name defaults to the tenant's brand, because a recorder people can see is the only kind worth shipping.