{
  "id": "CMP-085",
  "slug": "cmp-085",
  "title": "Message flow must state how consent is recorded",
  "statement": "The message-flow / CTA field must state how consent is recorded once given.",
  "rationale": "The record is what you rely on when a complaint arrives, and reviewers read its absence as evidence that nothing is retained. Storing only \"opted in: true\" leaves you unable to show WHAT was agreed to, which is the question every TCPA complaint turns on.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "State the fields you keep: number, timestamp, the disclosure version shown, and the session or agent identity. Done when the flow shows you could reproduce what a given subscriber saw on the day they agreed. Put it in campaign.message_flow itself — this field is graded on its own text, not on what a reviewer would find by opening your site.",
  "example": "Each opt-in is stored with the phone number, timestamp, the disclosure version shown, and the checkout session id.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-085/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-085.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
