{
  "id": "CON-FLOW-METHOD-MATCH",
  "slug": "con-flow-method-match",
  "title": "The described opt-in method must match the evidence supplied",
  "statement": "The collection method described in the message flow must be consistent with the artifact and the website.",
  "rationale": "A mismatch between the description and the evidence reads to a reviewer as either carelessness or misdirection, and both get rejected. It also usually means one of your real collection surfaces is undocumented and therefore unaudited.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "campaign.message_flow + consent artifact",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Make the flow describe the same method the evidence shows. If you genuinely collect consent several ways, describe each one and attach evidence for each — partial evidence is what triggers the mismatch.",
  "example": "Consent is collected two ways: (1) the web form at acmecoffee.com/signup [screenshot attached], and (2) verbally at our counter using the attached script.",
  "catalogIds": [
    "CON-007"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-flow-method-match/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-flow-method-match.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
