> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit a compliance profile for review

> Submit a completed compliance profile to the carriers/platforms its use case requires, fanning out one submission per provider and country. Validates first that the profile is complete and its use case is supported (returns 422 with the missing items otherwise). Submission is idempotent — a profile already in review is not re-sent. Moves the profile to pending_review and returns the per-provider submission rows. Owner/admin/developer only.



## OpenAPI

````yaml /openapi.yaml post /api/v1/compliance/compliance-profiles/{id}/submit
openapi: 3.1.0
info:
  title: Devotel CPaaS API
  description: Orbit by Devotel — Communications Platform as a Service API
  version: 1.0.0
  contact:
    name: Devotel
    url: https://devotel.io
    email: support@devotel.io
  license:
    name: Proprietary
servers:
  - url: https://api.orbit.devotel.io
    description: Production
security:
  - Bearer: []
  - ApiKey: []
tags:
  - name: Messages
    description: >-
      Send and manage messages across all channels (SMS, WhatsApp, RCS, Email,
      Viber, etc.)
  - name: Fax
    description: >-
      List and track fax (MMS/T.38) transmissions on Telnyx-backed fax numbers
      (sending flows through the Messaging API)
  - name: Agents
    description: AI agent creation, configuration, and execution
  - name: Voice
    description: Voice calls, IVR, conferencing, and SIP trunking
  - name: OnCall
    description: On-call rotations and escalation policy planning for incident alerting
  - name: Webhooks
    description: Webhook endpoint management and delivery logs
  - name: Numbers
    description: Phone number search, provisioning, and configuration
  - name: Brand Identity
    description: >-
      Unified cross-channel brand trust posture (10DLC, toll-free, WhatsApp,
      RCS, branded calling, number KYC)
  - name: Contacts
    description: Contact management, segmentation, and lifecycle tracking
  - name: Campaigns
    description: Marketing campaign orchestration and analytics
  - name: Flows
    description: Automation flow builder and execution engine
  - name: Templates
    description: Message template management and approval workflows
  - name: Settings
    description: Organization, channel, and user preference settings
  - name: Verify
    description: OTP generation and verification across channels
  - name: Push
    description: Push notification delivery via FCM and APNs
  - name: Integrations
    description: Third-party service connections and OAuth management
  - name: CDP
    description: >-
      Customer Data Platform — activation surface (CRM object sync, streaming
      destinations, ad-audience activation)
  - name: Files
    description: >-
      Server-to-server media upload, listing, retrieval, and deletion
      (signed-URL backed)
  - name: Commerce
    description: >-
      Omnichannel conversational-commerce — persistent cart + checkout state
      machine, channel-agnostic hosted pay-by-link, native WhatsApp checkout,
      and AP2-style agent payment mandates.
  - name: Sync
    description: >-
      Real-time shared-state primitive (Twilio Sync parity) — Documents, Maps,
      Lists, and ephemeral Streams, with change events relayed over the
      /api/v1/ws/sync WebSocket gateway
  - name: Risk
    description: >-
      Unified cross-channel Trust & Fraud risk scoring — fuses SMS-pumping,
      URL-reputation, Verify Fraud Guard, and Voice Biometrics signals into one
      composite verdict queryable before a send or a call.
  - name: Orby
    description: >-
      In-dashboard Orby operator assistant: streamed assistant turns,
      conversation threads, product knowledge-base search, and the tool-action
      approval gate. Available to signed-in operators only (dashboard session
      auth — API-key requests are rejected).
paths:
  /api/v1/compliance/compliance-profiles/{id}/submit:
    post:
      tags:
        - Compliance
      summary: Submit a compliance profile for review
      description: >-
        Submit a completed compliance profile to the carriers/platforms its use
        case requires, fanning out one submission per provider and country.
        Validates first that the profile is complete and its use case is
        supported (returns 422 with the missing items otherwise). Submission is
        idempotent — a profile already in review is not re-sent. Moves the
        profile to pending_review and returns the per-provider submission rows.
        Owner/admin/developer only.
      parameters:
        - schema:
            type: string
          in: path
          name: id
          required: true
      responses:
        '200':
          description: The per-provider carrier submissions created for the profile.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      submissions:
                        type: array
                        items:
                          $ref: '#/components/schemas/ComplianceProfileSubmission'
                  meta:
                    $ref: '#/components/schemas/ResponseMeta'
              example:
                data:
                  submissions:
                    - id: csub_8x7y6z5w4v3u
                      profile_id: cprof_7h3k9m2p4q1w
                      provider: tcr_us
                      country_code: US
                      provider_bundle_id: BRAND-A1B2C3
                      status: pending_review
                      rejected_reason: null
                      submitted_at: '2026-08-07T12:00:00.000Z'
                      verified_at: null
                      last_synced_at: '2026-08-07T12:00:00.000Z'
                      created_at: '2026-08-07T12:00:00.000Z'
                      updated_at: '2026-08-07T12:00:00.000Z'
                meta:
                  request_id: req_1a2b3c4d5e6f
                  timestamp: '2026-08-07T12:00:00.000Z'
components:
  schemas:
    ComplianceProfileSubmission:
      type: object
      description: >-
        One carrier-side submission for a compliance profile — a single
        (provider × country) bundle and its current verification status.
      properties:
        id:
          type: string
        profile_id:
          type: string
        provider:
          type: string
          description: >-
            The carrier / platform this bundle was submitted to (e.g. telnyx,
            didww, tcr_us, meta_wa, dotgo_rcs).
        country_code:
          type: string
          nullable: true
          description: >-
            The country this bundle covers, or null for a country-agnostic
            submission.
        provider_bundle_id:
          type: string
          nullable: true
          description: The carrier-side identifier for this bundle, once created.
        status:
          type: string
          enum:
            - pending
            - pending_review
            - verified
            - approved
            - rejected
        rejected_reason:
          type: string
          nullable: true
        submitted_at:
          type: string
          format: date-time
          nullable: true
        verified_at:
          type: string
          format: date-time
          nullable: true
        last_synced_at:
          type: string
          format: date-time
          nullable: true
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    ResponseMeta:
      type: object
      required:
        - request_id
        - timestamp
      additionalProperties: false
      properties:
        request_id:
          type: string
          description: Unique request identifier (also returned as X-Request-Id header)
        timestamp:
          type: string
          format: date-time
        docs_url:
          type: string
          format: uri
          nullable: true
  securitySchemes:
    Bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Dashboard JWT token from Clerk
    ApiKey:
      type: apiKey
      name: X-API-Key
      in: header
      description: Server-to-server API key (dv_live_sk_*)

````