{
  "id": "CMP-076",
  "slug": "cmp-076",
  "title": "Message flow must state how to opt out",
  "statement": "The message-flow / CTA field must state how the consumer opts out.",
  "rationale": "The opt-out instruction is the single most important disclosure a consumer is given, and a flow that omits it is read as evidence that the surface omits it too. Reviewers treat the flow text as the record of what the consumer actually saw, so silence here is not neutral — it is a claim that nothing was said.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Include the STOP instruction inside the quoted disclosure. Done when the word STOP appears in the flow text and matches the opt-out keywords declared on the campaign. Put it in campaign.message_flow itself — this field is graded on its own text, not on what a reviewer would find by opening your site.",
  "example": "The disclosure beside the box reads \"Reply STOP to unsubscribe\"; STOP is honoured immediately and confirmed.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-076/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-076.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
