{
  "id": "CMP-072",
  "slug": "cmp-072",
  "title": "Message flow must state the message types",
  "statement": "The message-flow / CTA field must state the message types the subscriber will receive.",
  "rationale": "Consent is scoped to what was disclosed, so the flow has to record what the consumer was told they would get. A flow that describes the mechanics of ticking a box without saying what arrives afterwards documents an opt-in to nothing in particular, and leaves a reviewer no way to check the samples against the consent.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Name the categories you actually send — \"order and delivery updates plus weekly promotional offers\" — instead of \"messages\". Done when a reader can predict, from the flow alone, what will land on the subscriber's phone. Put it in campaign.message_flow itself — this field is graded on its own text, not on what a reviewer would find by opening your site.",
  "example": "Subscribers receive order and delivery updates plus weekly promotional offers from Acme Coffee.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-072/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-072.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
