{
  "id": "CMP-084",
  "slug": "cmp-084",
  "title": "Message flow must state who opts in and when",
  "statement": "The message-flow / CTA field must state who is opting in and at what moment.",
  "rationale": "Which customers, at which point in their journey, is what determines whether the consent scope matches the messages sent. A flow that never says who is subscribing cannot be checked against the samples, and it is the field where list-purchase and scraped-number programmes give themselves away.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Name the audience and the moment: which customers, at which step. Done when the flow makes clear that only people who took the action are on the list. Put it in campaign.message_flow itself — this field is graded on its own text, not on what a reviewer would find by opening your site.",
  "example": "Customers opt in during checkout, after entering delivery details and before placing the order; only customers who tick the box are subscribed.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-084/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-084.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
