{
  "id": "OPS-204",
  "slug": "ops-204",
  "title": "Verbal consent records must substitute a call identifier for the IP address",
  "statement": "Where consent was verbal or via IVR, a call identifier must replace the IP-address field in the consent record.",
  "rationale": "The IP field is meaningless for phone consent, and leaving it empty produces a record that looks incomplete rather than method-appropriate. A call ID, recording ID, or agent identifier is the equivalent evidence and is what a reviewer expects for that method.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.message_flow",
  "severity": "MEDIUM",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "CTIA",
    "FCC"
  ],
  "applicability": {
    "consentMethods": [
      "verbal_live",
      "verbal_ivr"
    ]
  },
  "applicabilityText": "Applies when consent was collected by live verbal and IVR.",
  "universal": false,
  "remediation": "Store a call ID, recording ID, or agent extension on verbal consent records in place of the IP address, and say so in the message flow.",
  "example": "Verbal opt-ins store the call UCID, the agent ID, and the script version read, in place of an IP address.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-204/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-204.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
