{
  "id": "OPS-292",
  "slug": "ops-292",
  "title": "Evidence screenshots must say when and where they were taken",
  "statement": "Every submitted evidence image must carry its capture timestamp, the source URL, and enough provenance to tie it to the live surface.",
  "rationale": "A screenshot with no provenance is a picture of a form, and a reviewer cannot tell whether it is the live page, a staging build, or a mock-up made for the submission — so the cautious ones reject it and the rest approve something they did not verify. Adding the URL and the date costs one line in the upload and turns the image into evidence, which is the difference the brand is actually being asked for.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.consent_artifact[]",
  "severity": "MEDIUM",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "CTIA",
    "researcher recommendation"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Capture the browser address bar in the screenshot, or caption each image with the full URL and the capture date where the surface is not a web page. Done when the image alone tells a reviewer which page it is and when it was taken.",
  "example": "Screenshot filename optin-signup-2026-03-04.png, captioned \"https://acmecoffee.com/signup — captured 4 March 2026, 1440×900\", with the address bar visible in the image.",
  "pitfalls": [
    "Cropping to the consent block removes the address bar, which is usually the only provenance the image had."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-292/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-292.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
