{
  "id": "CMP-060",
  "slug": "cmp-060",
  "title": "Every opt-in method in use must be listed in the message flow",
  "statement": "All opt-in methods actually in use must be described inside the single message-flow field.",
  "rationale": "There is one flow field and it has to cover every collection surface, because an undescribed method is an unaudited one. Brands routinely describe only their web form while also collecting consent verbally at a counter, which leaves the larger half of their list undocumented — and it is the undocumented half that generates the complaints.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "List every method you actually use in campaign.message_flow, each in its own paragraph. If you collect consent three ways, the field describes three flows. Done when the methods described match the methods you could be audited on.",
  "example": "Consent is collected three ways: (1) the checkout box at acmecoffee.com/checkout [screenshot attached]; (2) verbally at our counter using the attached script; (3) by texting JOIN to 55512 from our in-store signage [photo attached].",
  "pitfalls": [
    "Dropping a method from the flow does not remove the obligation — it removes the evidence that you meet it."
  ],
  "catalogIds": [
    "CON-003",
    "CON-004"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-060/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-060.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
