{
  "id": "CON-ART-002",
  "slug": "con-art-002",
  "title": "The consent artifact must actually show a consent surface",
  "statement": "The attached artifact must depict the point of consent collection, not an unrelated page, logo, or product screen.",
  "rationale": "The most common evidence failure is not a missing screenshot but the wrong one — a homepage, a logo, or a dashboard. Reviewers read that as an attempt to satisfy the requirement without meeting it, and it costs more credibility than attaching nothing. Catching it before submission avoids a rejection that is embarrassing as well as expensive.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "consent artifact",
  "severity": "BLOCKING",
  "detectability": [
    "VISION"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Replace the attachment with an image of the actual screen or form where the customer gives consent. Three things must appear together in one frame: the phone-number field, the control they act on (checkbox, toggle, or signature line), and the disclosure text beside it.",
  "pitfalls": [
    "A screenshot of the confirmation page after signup shows the outcome, not the consent — capture the form itself."
  ],
  "catalogIds": [
    "CON-028"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-art-002/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-art-002.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
