{
  "id": "OPS-233",
  "slug": "ops-233",
  "title": "A spoken consent record must name the agent who took it",
  "statement": "Every consent record must carry the identifier of the agent who read the consent script.",
  "rationale": "A verbal opt-in has no artifact the consumer touched, so the whole evidentiary weight sits on the call. Naming the agent is what makes the record investigable: it is how a brand finds out that one agent has been paraphrasing the script, and how it shows a regulator that it looked. Contact centres omit it because the CRM records the account owner rather than whoever was on the call.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.message_flow + privacy policy",
  "severity": "MEDIUM",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "FTC",
    "practice"
  ],
  "applicability": {
    "consentMethods": [
      "verbal_live"
    ]
  },
  "applicabilityText": "Applies when consent was collected by live verbal.",
  "universal": false,
  "remediation": "Store the agent identifier — the login, extension or badge number of the person who read the script — on each verbal consent record. Done when any consent record names a specific person, not a team or a queue.",
  "example": "Verbal opt-ins store agent_id: acme-cs-0142 with the call UCID and the script version read.",
  "notes": "Registration-side twin: we judge whether the programme describes storing the field, never whether the stored record exists.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-233/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-233.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
