{
  "id": "OPS-127",
  "slug": "ops-127",
  "title": "UCaaS low-volume carries restrictions beyond the volume",
  "statement": "A UCaaS low-volume registration is limited to a low daily ceiling, a restricted throughput class, one number per human user, and no API or automated traffic.",
  "rationale": "The tier exists for individual humans typing messages, and the conditions enforce that rather than merely the volume — so a business that stays under the daily cap but sends through an API has still breached it. It is chosen for the low cost and the conditions are discovered afterwards.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "UCaaS traffic pattern against the tier conditions",
  "severity": "MEDIUM",
  "detectability": [
    "EXTERNAL_DATA"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "T-Mobile",
    "AT&T",
    "TCR"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Use this tier only for human-sent, one-number-per-person messaging. Register a standard campaign for anything automated, however low the volume. Done when no API traffic runs on a UCaaS registration.",
  "notes": "Tier conditions applied by the carriers. What the user has to confirm is that nothing automated touches the numbers on this tier — an integration somebody added later is the usual breach, and it is invisible in the volume figures.",
  "phase": "post",
  "automated": false,
  "attestation": {
    "question": "Does anything automated touch the numbers on your UCaaS low-volume registration?",
    "howToCheck": [
      "Look for API traffic, integrations and scheduled sends on those numbers — an integration somebody added later is the usual breach, and it is invisible in the volume figures.",
      "The tier requires human-sent messages, one number per person, no automation — staying under the daily cap is not sufficient.",
      "Register a standard campaign for anything automated, however low the volume."
    ],
    "failureLooksLike": "A business well under the daily ceiling has still breached the tier because it sends through an API. The tier was chosen for the price and the conditions were read afterwards."
  },
  "url": "https://ekas.io/rules/10dlc/operational/ops-127/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-127.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
