The consent record must say which act gave consent

The requirementstatement

Every consent record must carry the confirmation method used — a ticked box, a click, or a replied keyword.

Severityseverity
MediumMEDIUMUsually survives review, but lowers your trust score or invites a manual look you would rather avoid.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
campaign.message_flow + privacy policy
Where it liveslayer
OperationalOPERATIONAL
How Ekas settles itdetectability
AI · formAI_FORM
A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
What the fix involvesfailureClass
Fix the fieldRETRY_FIELD
A better value in the form fixes it. Ekas can rewrite it and re-check.
Who requires itauthorities
CTIAmytcrplus
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

Two records can agree on number, timestamp and campaign and still describe completely different events: one consumer ticked an unchecked box, another replied YES to a text, a third was added by an agent. Those are not equally strong evidence, and a record that does not say which act happened cannot be graded — which is exactly the moment, months later, when it needs to be.

How to fix itremediation

Store the specific act on each record — checkbox, button click, SMS reply, keypress, agent entry — rather than a boolean. Done when reading one record tells you what the consumer physically did.

A compliant exampleexample

Each opt-in stores confirmation_method: checkbox_ticked (or sms_reply_yes for double opt-ins).

Notesnotes

Registration-side twin: we judge whether the programme describes storing the field, never whether the stored record exists.

Rules you will hit next

6 other rules read campaign.message_flow + privacy policy. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.

All operational rules

OPS-209 is one of 139 operational rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.