{
  "id": "CMP-056",
  "slug": "cmp-056",
  "title": "An ISV registering for a customer must supply the customer's details",
  "statement": "Where an ISV or platform registers on behalf of a customer, the campaign must carry the customer's website and brand information, not the platform's.",
  "rationale": "This is the campaign-side twin of registering the wrong brand. The platform's own site is real and substantial, which makes it a tempting field value — and it means the entity being vetted is not the business whose messages will be sent, so the vetting proves nothing about the sender.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign fields + brand.website",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Populate every campaign field from the end customer: their website, their brand name, their opt-in surface. Your platform belongs on the CSP record only. Done when nothing in the campaign identifies the platform.",
  "example": "Website: acmecoffee.com (the customer) — not northstarplatform.io (the ISV).",
  "notes": "Catalog CMP-056 is conditional on the registration being on behalf of a third party. We hold no \"registered by an ISV\" fact, so the condition lives in the judgement criteria instead of the applicability tag — the rule only fires a finding when the content itself shows a platform.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-056/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-056.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
