{
  "id": "BRD-164",
  "slug": "brd-164",
  "title": "The named contact must be authorised to act for the business",
  "statement": "The brand contact must be an authorised representative of the business, not a generic, third-party or aggregator name.",
  "rationale": "This person is treated as the party who attested to the registration, so the name matters when a carrier asks who authorised the programme. A vendor's account manager or a shared \"Marketing Team\" entry means nobody at the business did — and that is a materially different answer from the one the registration implies.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "brand.authorized_rep",
  "severity": "HIGH",
  "detectability": [
    "HUMAN"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "AWS",
    "Bandwidth",
    "HighLevel",
    "CTIA"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30972",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Name someone employed by the business with authority to commit it — an owner, an officer, or the manager who owns the messaging programme. Get their agreement before naming them, because they may be contacted about it.",
  "notes": "Nothing on the form shows whether the named person works for the business. What the user has to do is confirm the person is a real employee with authority and knows they have been named — a reviewer who calls the business and finds nobody by that name treats the whole registration as unverified.",
  "phase": "approval",
  "automated": false,
  "attestation": {
    "question": "Does the named representative work for the business, have authority to commit it, and know they have been named?",
    "howToCheck": [
      "Confirm the person is a real employee — an owner, an officer, or the manager who owns the messaging programme.",
      "Tell them they have been named and that they may be contacted about it.",
      "Rule out the two substitutes: a vendor's account manager, and a generic entry like \"Marketing Team\"."
    ],
    "failureLooksLike": "A reviewer calls the business and finds nobody by that name. The registration implies somebody at the business attested to it, and nobody did."
  },
  "url": "https://ekas.io/rules/10dlc/brand/brd-164/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-164.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
