{
  "id": "CMP-079",
  "slug": "cmp-079",
  "title": "Message flow must describe the consumer-facing opt-in action",
  "statement": "The message-flow / CTA field must state how the consumer is told about the programme and what they do to join.",
  "rationale": "The flow must describe the experience, not the plumbing: what the consumer sees, and the specific action they take. This is what lets a reviewer decide the action was affirmative rather than passive — the difference between a box someone ticked and a form someone submitted while consent was assumed.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Describe the control the consumer sees, its label, and the action they take on it. Done when the text names a deliberate act — ticking, texting, signing, saying yes. Put it in campaign.message_flow itself — this field is graded on its own text, not on what a reviewer would find by opening your site.",
  "example": "Beneath the delivery fields the customer sees an unchecked box labelled \"Text me offers\" with the disclosure printed beside it, and ticks it before placing the order.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-079/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-079.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
