{
  "id": "CMP-082",
  "slug": "cmp-082",
  "title": "Message flow must state where the opt-in occurs",
  "statement": "The message-flow / CTA field must state where on the site, app, or premises the opt-in happens.",
  "rationale": "Reviewers verify by going and looking, so the flow must tell them where to go, described from the consumer's point of view rather than in internal system terms. \"On the checkout page after entering delivery details\" is findable; \"via our CDP integration\" is not, and an unfindable opt-in is treated as an unverifiable one.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Give the URL or the physical place, plus the position on the page. Done when someone holding only the flow text could navigate to the control and see it. Put it in campaign.message_flow itself — this field is graded on its own text, not on what a reviewer would find by opening your site.",
  "example": "Opt-in happens on the checkout page at https://acmecoffee.com/checkout, in the block beneath the delivery address fields.",
  "catalogIds": [
    "CON-006"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-082/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-082.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
