{
  "id": "OPS-058",
  "slug": "ops-058",
  "title": "Re-read the inbound log for opt-outs the handler missed",
  "statement": "Inbound message logs must be reviewed on a schedule for revocations the keyword handler did not catch, and those subscriptions terminated.",
  "rationale": "No intent classifier catches everything, so the question is not whether some revocations are missed but whether anybody ever finds out. A scheduled sweep converts a silent miss into a caught one — and finding three a month is a working programme, while finding none usually means nobody is looking rather than that the handler is perfect.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "inbound log review",
  "severity": "HIGH",
  "detectability": [
    "UNDETECTABLE_PRE_SUBMISSION"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Schedule a review of inbound messages that produced no keyword match, suppress anything that reads as a revocation, and record when the review ran. Done when the review has a date, an owner and a finding count each time.",
  "example": "Weekly: export unmatched inbound messages, review, suppress, record \"reviewed 2026-03-06, 4 revocations found\".",
  "notes": "A recurring job over data we never see. What the user has to do is own the schedule and keep its output — the review record is what shows a missed revocation was an exception rather than the norm.",
  "phase": "post",
  "automated": false,
  "attestation": {
    "question": "Does the review of unmatched inbound messages have a date, an owner and a finding count each time it runs?",
    "howToCheck": [
      "Schedule the sweep over inbound messages that produced no keyword match.",
      "Suppress anything that reads as a revocation, and record when the review ran and what it found.",
      "Finding three a month is a working programme. Finding none usually means nobody is looking."
    ],
    "failureLooksLike": "No classifier catches everything, so the question is whether anybody ever finds out. Without the review record, a missed revocation looks like the norm rather than an exception."
  },
  "url": "https://ekas.io/rules/10dlc/operational/ops-058/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-058.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
