{
  "id": "BRD-246",
  "slug": "brd-246",
  "title": "A political token is used once and once only",
  "statement": "Each Campaign Verify token is single-use and unique to one brand and CSP; a second use requires a reissue or a fresh political vet.",
  "rationale": "Standard vetting tokens can be spread across duplicate brand instances (BRD-218) and political ones cannot, so an operator who learned the first behaviour applies it to the second and the reuse is refused. Getting another token is not a self-service action — it means going back to Campaign Verify — which is why this costs days rather than minutes.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "the Campaign Verify token",
  "severity": "BLOCKING",
  "detectability": [
    "EXTERNAL_DATA"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "Twilio",
    "TCR"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "21722",
      "remediable": true
    },
    {
      "provider": "TCR",
      "code": "543",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Use each token on exactly one brand at one CSP. Where the same organisation registers through two providers, request a second token from Campaign Verify rather than importing the first one twice — and request it before you need it.",
  "notes": "Absorbs OPS-320, which contrasts single-use political tokens with the multi-use standard tokens in BRD-218. Whether a token has already been consumed is registry state we cannot see. What the user has to track is which brand each token went to, because the refusal on the second import does not say where the first one was used.",
  "catalogIds": [
    "OPS-320"
  ],
  "phase": "approval",
  "automated": false,
  "attestation": {
    "question": "Has this Campaign Verify token been used on any other brand or at any other CSP?",
    "howToCheck": [
      "Keep a record of which brand each token went to. The refusal on a second import does not say where the first one was used.",
      "Registering the same organisation through two providers means requesting a second token from Campaign Verify — before you need it, since it is not self-service."
    ],
    "failureLooksLike": "Standard vetting tokens can be spread across duplicate brand instances, so an operator applies the same habit to a political one. The reuse is refused and getting another costs days."
  },
  "url": "https://ekas.io/rules/10dlc/brand/brd-246/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-246.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
