Skip to main content

Your Tenant Compliance Posture: The Toggle Map

The Compliance group in these docs is deep on individual surfaces — send gates, quiet hours, DNC, RND, STIR/SHAKEN, HIPAA, DSAR, opt-out, Sender-ID registration, KYC documents. This page is the map across all of them: which controls are yours to switch, where each switch lives, what the out-of-box default is, and the small set of surfaces the platform deliberately does not let you toggle. Read this once, then dive into the one or two deep pages your posture actually touches.
This page describes Orbit’s platform controls. It is not legal advice. Which laws apply to your traffic, and what posture is adequate, depends on where you and your recipients are and what you send. Confirm with qualified counsel.

The platform posture

Orbit’s compliance model has three commitments, and everything on the map below hangs off them:
  1. Controls are tenant-owned. Compliance for your traffic is your responsibility. Orbit gives you the control surface — gates, windows, scrubs, registries, policy knobs — and enforces what you set. It does not mandate a posture for you, and it does not decide that a send is “compliant.” Several deep pages state this on their own surfaces (STIR/SHAKEN, SCIM, KYC documents, CPNI); this page is the statement for the group as a whole.
  2. Everything defaults open. Except for the hard asymmetries listed in What is not tenant-toggleable, every gate ships off / open: a new tenant’s sends are not held by quiet hours, not scrubbed against DNC or RND, and not blocked by an attestation floor, until you opt in. Where input can’t be resolved — a recipient timezone outside the US, an attestation lookup that errors — these controls fail open rather than blocking traffic. The posture you choose is additive: you tighten from an open default, you don’t loosen from a restrictive one.
  3. Orbit is the conduit and the ledger, not the compliance owner. Orbit carries your sends to the carriers, enforces the gates you set, and keeps the auditable record — consent decisions, suppression entries, certifications, traceback cases, scrub results. It never files with a regulator for you, never sends a customer notice for you, and never invents or auto-renews an identity document. The ledger reflects what you did; the decisions stay yours.

The posture map

One row per surface: where the toggle lives, how it defaults, how it behaves when inputs can’t be resolved, and the deep page to read before you flip it. Two adjacent surfaces are read-only, not toggles: the org-wide compliance-health scores and the quiet-hours preview endpoint. They report your posture; they never change it.

Three reference postures

Copy the posture closest to your traffic, then adjust. Each lists exactly which toggles to flip and which deep page documents the write.

Posture A — US marketing SMS operator

You send A2P marketing SMS to US recipients under TCPA.
  1. Quiet hours: enable the sms channel on the org gate. Platform hours 08:00–21:00 recipient-local apply immediately; keep consent_overrides_quiet_hours: true (the default) so permitted recipients stay reachable inside the window. See Quiet hours configuration.
  2. Campaign fallback window: set it in Settings → Campaign limits (or PUT /campaigns/quiet-hours/settings) if your drip sends should use a tighter window than the platform default.
  3. DNC scrub: turn on dnc_sync_enabled so /compliance/dnc/check and the suppression feed back your dialing decisions. Plan around the documented caveat: until a federal snapshot is synced, a number only on the FTC list reads back clear. See Send Gates.
  4. Suppression: bulk-import any legacy opt-out list via POST /compliance/suppression-list/import before your first send; phone rows default to scope all, which also gates voice.
  5. Sender ID / 10DLC: complete your brand and campaign registration (10DLC guide) — US long-code traffic without it degrades regardless of these gates.
  6. Emergency stop: know where it is before you need it — POST /compliance/emergency-stop/activate halts all outbound SMS, MMS, voice, and dialer traffic in one call.
  7. Leave RND off unless you operate a re-consent program that needs the § 227 safe harbor reads.

Posture B — EU GDPR + APAC drip operator

You run drip campaigns to EU/APAC recipients under GDPR and local marketing rules. The full end-to-end walkthrough of this posture is Assembling a GDPR Posture End to End; the steps below are the map-level summary.
  1. Campaign fallback window: set your local regime in Settings → Campaign limits (e.g. 22:00 → 07:00) so every drip or journey that lacks its own window sends inside it. This is the single highest- value toggle for this posture.
  2. Org gate per channel if you also want 1:1 traffic held — enable per channel with your own start_hour / end_hour.
  3. Consent records: file per-channel consent through POST /compliance/consent before campaign sends, with the GDPR lawful basis recorded. Consent coverage is 30% of the compliance-health score, and carriers read it.
  4. DSAR: decide your intake path — operator-filed through POST /compliance/dsar, the public self-service portal behind your privacy-policy link, or both. The SLA tracker applies per jurisdiction (gdpr 30 days, pdpa 30, lgpd 15).
  5. Processing register: document your Art.30 activities and run Art.35 DPIAs in the privacy register if your processing is high-risk.
  6. Preference center: configure one and sign per-contact links so GDPR delete/consent requests arrive structured instead of as support tickets.

Posture C — US voice dialer operator

You run outbound voice campaigns and ad-hoc dialing to US recipients.
  1. Accept the hard rails first. Campaign and dialer voice outside the 8 AM–9 PM recipient-local federal window is always blocked (422 TCPA_FEDERAL_DIALING_WINDOW_BLOCKED), a timezone-unresolved US recipient is blocked fail-closed, and stricter state overlays (Florida’s Sunday ban, Oklahoma/Mississippi windows, and the other mini-TCPA states) sit on top. No toggle relaxes any of this — see What is not tenant-toggleable.
  2. Ad-hoc 1:1 dialing: decide whether the dashboard soft-dials stay advisory (the default) or become hard holds — enable the voice channel on the org gate for the latter.
  3. Suppression: phone-scoped opt-outs gate voice and dialer traffic; import your DNC list and wire STOP handling before the first campaign.
  4. STIR/SHAKEN: run your traffic from numbers your org owns — the only path to full (A) attestation. Register delegate certificates for external caller IDs you legitimately control to raise them C → B, and set the attestation policy plus the inbound floor per DID. All in STIR/SHAKEN.
  5. RMD: create and submit your Robocall Mitigation Database filing through POST /compliance/rmd before originating voice; keep the recertification deadline on your calendar. The full lifecycle — submit, certify, remediate, resolve, withdraw, and the opt-in call-time guard — is in RMD Registration.
  6. Emergency stop: the same kill switch covers voice — one call halts dialer traffic mid-incident.

What is not tenant-toggleable

A short list, on purpose. These are the surfaces where an open default or a tenant opt-out would be wrong — either the statute forbids it, or the control exists to protect the recipient and the platform alike.
  • Campaign and dialer voice federal window. The TCPA 8 AM–9 PM recipient-local dialing window (47 U.S.C. § 227(b)(1)(B)) hard-blocks all automated and bulk outbound voice to US (+1) recipients, and accepts no tenant toggle: no per-organization bypass, no start_hour/end_hour knob on the federal window, no fail-open on a timezone-unresolved recipient. Ad-hoc 1:1 dashboard dialing is advisory-unless-enabled (a tenant control — flip voice on the org gate to harden it); the campaign/dialer path never is. Carriers and the statute assess 500500–1,500 per violating call, so the rail is platform-level. See the US-voice note in Send Gates and the enforcement table in Quiet hours configuration.
  • State mini-TCPA overlays. Stricter state windows and day bans (Florida’s Sunday prohibition, Mississippi’s 7:30 PM close, Oklahoma/Louisiana/Alabama/West Virginia overlays) intersect with the federal window on the most-restrictive-wins rule. They carry no tenant toggle either — a state statutory window is not yours to relax. Block reasons surface as outside_state_window or state_blocked_day so you can separate state-driven holds from federal ones in reporting.
  • Emergency-stop scope. The kill switch is defined by what it halts — outbound SMS, MMS, voice, and dialer campaign traffic. Its carve-out is fixed, not configurable: transactional Verify/OTP sends and email are never gated by it, because a login code must still reach a contact mid-incident. You cannot widen the stop to those paths through the switch — if you need them paused, disable the Verify profile or email sender directly. See Send Gates → Emergency stop.
  • The delegate-certificate A ceiling. A delegate certificate raises an external number from C to B only — never to A. A attestation is reserved for numbers owned through Orbit, and this ceiling is deliberately not a setting: treating a self-registered artifact as full attestation would let anyone spoof it for arbitrary numbers. See STIR/SHAKEN.
  • Wholesale signing authority. Orbit signals the attestation level; the Devotel-operated softswitch signs the PASSporT on-net, and it will never sign higher than what the platform attests. There is no tenant-side “sign at A anyway.”
Nothing else on this surface is platform-mandated. The absence of a fourth hard rail is the point of the posture model: defaults open, tenant-owned, with these documented asymmetries.

Read the signals, don’t guess

Two read-only surfaces report the posture you actually have — use them before and after you change a toggle, not as a substitute for one.
  • Compliance health (GET /compliance/health, plus /health/numbers and /health/campaigns) blends consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections into a 0–100 score per organization, sender, and campaign, with a warnings array of ranked fixes. It never blocks a send; it tells you which sender is about to be throttled before the traffic degrades. Start with the list endpoints — they order worst first. See Compliance Health Scores.
  • Quiet-hours preview (GET /compliance/quiet-hours/preview) answers “would this send, to this recipient, be held right now — and if so until when?” with the resolved window and next_allowed_at. Check it before a rollout, and use it to schedule around a window rather than retrying into it. See Send Gates.
Read the health score and the preview together with the map above: the map tells you which switch to flip, the signals tell you whether the flip did what you intended.