{
  "id": "POL-243",
  "slug": "pol-243",
  "title": "Mark every unverified variable and block export until it is resolved",
  "statement": "Every unverified variable in a generated draft must be visibly marked, and export must be blocked until each is resolved.",
  "rationale": "The alternative to marking is guessing, and a guessed retention period ships as a fact — so the marker is what keeps POL-242 enforceable rather than aspirational. The published-document version of this failure is trivially detectable and embarrassingly common: a live policy with {{COMPANY_NAME}} still in it, which is what happens when a draft is exported past its own placeholders.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "draft policy placeholder tokens",
  "severity": "HIGH",
  "detectability": [
    "HUMAN"
  ],
  "failureClass": "TERMINAL_ARTIFACT",
  "artifact": "privacy_policy",
  "authorities": [
    "TCR"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Leave every unconfirmed value as a visible token rather than a plausible default, and resolve each before publishing. Done when a search of the draft for \"{\" and \"[\" returns nothing.",
  "notes": "The publication-side twin is POL-156, which fails a live page carrying tokens; this is the gate before that page exists. We hold no draft, so the user owns it: do not publish a generated document until every marked variable has been replaced with a value somebody confirmed.",
  "phase": "approval",
  "automated": false,
  "attestation": {
    "question": "Does a search of this draft for \"{\" and \"[\" return nothing?",
    "howToCheck": [
      "Search the draft for both characters before publishing.",
      "Resolve each marked variable with a value somebody confirmed, rather than a plausible default.",
      "Do not publish while any marker remains."
    ],
    "failureLooksLike": "A live policy with {{COMPANY_NAME}} still in it — trivially detectable, embarrassingly common, and what happens when a draft is exported past its own placeholders."
  },
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-243/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-243.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
