Skip to main content

Your Tenant Compliance Posture: The Toggle Map

The Compliance group in these docs is deep on individual surfaces — send gates, quiet hours, DNC, RND, STIR/SHAKEN, HIPAA, DSAR, opt-out, Sender-ID registration, KYC documents. This page is the map across all of them: which controls are yours to switch, where each switch lives, what the out-of-box default is, and the small set of surfaces the platform deliberately does not let you toggle. Read this once, then dive into the one or two deep pages your posture actually touches.
This page describes Orbit’s platform controls. It is not legal advice. Which laws apply to your traffic, and what posture is adequate, depends on where you and your recipients are and what you send. Confirm with qualified counsel.

Start here by topic

Eight regulatory postures cover nearly every new tenant’s first configuration pass. The order below is the recommended implementation sequence: sender identity and quiet hours first (they gate deliverability and call timing from the first send), privacy and voice identity next, then the healthcare, KYC, and opt-out layers a regulated or scaled operation adds. Configure the rows that match your traffic; skip the ones that don’t. Everything listed is a tenant-owned control — Orbit enforces what you set; the decisions stay yours. After the eight, the posture map below covers the remaining controls — DNC and RND scrubs, the emergency stop, fraud caps, and the read-only health signals — in the same one-row-per- surface format.

The platform posture

Orbit’s compliance model has three commitments, and everything on the map below hangs off them:
  1. Controls are tenant-owned. Compliance for your traffic is your responsibility. Orbit gives you the control surface — gates, windows, scrubs, registries, policy knobs — and enforces what you set. It does not mandate a posture for you, and it does not decide that a send is “compliant.” Several deep pages state this on their own surfaces (STIR/SHAKEN, SCIM, KYC documents, CPNI); this page is the statement for the group as a whole.
  2. Everything defaults open. Except for the hard asymmetries listed in What is not tenant-toggleable, every gate ships off / open: a new tenant’s sends are not held by quiet hours, not scrubbed against DNC or RND, and not blocked by an attestation floor, until you opt in. Where input can’t be resolved — a recipient timezone outside the US, an attestation lookup that errors — these controls fail open rather than blocking traffic. The posture you choose is additive: you tighten from an open default, you don’t loosen from a restrictive one.
  3. Orbit is the conduit and the ledger, not the compliance owner. Orbit carries your sends to the carriers, enforces the gates you set, and keeps the auditable record — consent decisions, suppression entries, certifications, traceback cases, scrub results. It never files with a regulator for you, never sends a customer notice for you, and never invents or auto-renews an identity document. The ledger reflects what you did; the decisions stay yours.

The posture map

One row per surface: where the toggle lives, how it defaults, how it behaves when inputs can’t be resolved, and the deep page to read before you flip it. Two adjacent surfaces are read-only, not toggles: the org-wide compliance-health scores and the quiet-hours preview endpoint. They report your posture; they never change it. A third read-only surface sits with the fraud controls: GET /api/v1/settings/compliance/voice-destination-blocks lists the automatic per-destination voice blocks the platform applied on a toll-fraud / Wangiri burst. The blocks themselves are enforcement, not a toggle — they are written by the anomaly sweep, enforce fail-closed on the outbound dial path, and expire on their own; this endpoint only makes the active list visible before a legitimate call to that number is rejected. The categories, time-bound semantics, and the dashboard panel behind that row are documented in Voice Destination Auto-Blocks.

Five reference postures

Copy the posture closest to your traffic, then adjust. Each lists exactly which toggles to flip and which deep page documents the write.

Posture A — US marketing SMS operator

You send A2P marketing SMS to US recipients under TCPA.
  1. Quiet hours: enable the sms channel on the org gate. Platform hours 08:00–21:00 recipient-local apply immediately; keep consent_overrides_quiet_hours: true (the default) so permitted recipients stay reachable inside the window. See Quiet hours configuration.
  2. Campaign fallback window: set it in Settings → Campaign limits (or PUT /campaigns/quiet-hours/settings) if your drip sends should use a tighter window than the platform default.
  3. DNC scrub: turn on dnc_sync_enabled so /compliance/dnc/check and the suppression feed back your dialing decisions. Plan around the documented caveat: until a federal snapshot is synced, a number only on the FTC list reads back clear. See Send Gates.
  4. Suppression: bulk-import any legacy opt-out list via POST /compliance/suppression-list/import before your first send; phone rows default to scope all, which also gates voice.
  5. Sender ID / 10DLC: complete your brand and campaign registration (10DLC guide) — US long-code traffic without it degrades regardless of these gates.
  6. Emergency stop: know where it is before you need it — POST /compliance/emergency-stop/activate halts all outbound SMS, MMS, voice, and dialer traffic in one call.
  7. Leave RND off unless you operate a re-consent program that needs the § 227 safe harbor reads.

Posture B — EU GDPR + APAC drip operator

You run drip campaigns to EU/APAC recipients under GDPR and local marketing rules. The full end-to-end walkthrough of this posture is Assembling a GDPR Posture End to End; the steps below are the map-level summary.
  1. Campaign fallback window: set your local regime in Settings → Campaign limits (e.g. 22:00 → 07:00) so every drip or journey that lacks its own window sends inside it. This is the single highest- value toggle for this posture.
  2. Org gate per channel if you also want 1:1 traffic held — enable per channel with your own start_hour / end_hour.
  3. Consent records: file per-channel consent through POST /compliance/consent before campaign sends, with the GDPR lawful basis recorded. Consent coverage is 30% of the compliance-health score, and carriers read it.
  4. DSAR: decide your intake path — operator-filed through POST /compliance/dsar, the public self-service portal behind your privacy-policy link, or both. The SLA tracker applies per jurisdiction (gdpr 30 days, pdpa 30, lgpd 15).
  5. Processing register: document your Art.30 activities and run Art.35 DPIAs in the privacy register if your processing is high-risk.
  6. Preference center: configure one and sign per-contact links so GDPR delete/consent requests arrive structured instead of as support tickets.

Posture C — US voice dialer operator

You run outbound voice campaigns and ad-hoc dialing to US recipients.
  1. Accept the hard rails first. Campaign and dialer voice outside the 8 AM–9 PM recipient-local federal window is always blocked (422 TCPA_FEDERAL_DIALING_WINDOW_BLOCKED), a timezone-unresolved US recipient is blocked fail-closed, and stricter state overlays (Florida’s Sunday ban, Oklahoma/Mississippi windows, and the other mini-TCPA states) sit on top. No toggle relaxes any of this — see What is not tenant-toggleable.
  2. Ad-hoc 1:1 dialing: decide whether the dashboard soft-dials stay advisory (the default) or become hard holds — enable the voice channel on the org gate for the latter.
  3. Suppression: phone-scoped opt-outs gate voice and dialer traffic; import your DNC list and wire STOP handling before the first campaign.
  4. STIR/SHAKEN: run your traffic from numbers your org owns — the only path to full (A) attestation. Register delegate certificates for external caller IDs you legitimately control to raise them C → B, and set the attestation policy plus the inbound floor per DID. All in STIR/SHAKEN.
  5. RMD: create and submit your Robocall Mitigation Database filing through POST /compliance/rmd before originating voice; keep the recertification deadline on your calendar. The full lifecycle — submit, certify, remediate, resolve, withdraw, and the opt-in call-time guard — is in RMD Registration.
  6. Emergency stop: the same kill switch covers voice — one call halts dialer traffic mid-incident.

Posture D — Regulated-healthcare sender

You send patient-adjacent traffic under HIPAA, with an executed BAA, and your data-handling rules say message bodies never leave your tenancy for an AI hop. Every write below is owner-only, and every one lands in the org audit log.
  1. BAA + HIPAA mode first. Execute the BAA, then enable HIPAA mode (PUT /api/v1/settings/hipaa; HIPAA). Until the BAA is executed the mode refuses to enable and PHI sends are rejected 422 HIPAA_BAA_REQUIRED — fail-closed toward PHI. Set your PHI retention window in the same pass. The full walkthrough is HIPAA onboarding: from BAA to audit-ready.
  2. Close the inbox AI gates. PATCH /api/v1/settings/compliance/inbox-ai-privacy with auto_categorize: false and auto_summarize: false. Both default on and ship inbound message bodies (categorize) and close-time summaries (summarize) to a third-party LLM — this is the one posture where the platform default is the wrong day-0 state and you deliberately tighten from it. Verify with GET /api/v1/settings/compliance/inbox-ai-privacy → both fields false.
  3. Leave AI-turn audit off unless your policy requires it. Off is the default and the fail-safe direction. If your audit policy requires verbatim records, PUT /api/v1/settings/compliance/ai-turn-audit with enabled: true persists every AI turn — system prompt, user prompt, and response — to your tenant audit table. Treat that as a multi-year verbatim PII surface: enable it only per written policy, and pair it with a retention decision. Verify with GET /api/v1/settings/compliance/ai-turn-audit. Decide explicitly: verbatim audit is a deliberate, policy-backed choice, not a leftover. “Off by accident” and “on by accident” are both findings in a HIPAA review.
  4. Refuse unknown-consent marketing. Keep unknown_marketing_policy at the default refuse — a marketing gate never widens onto PHI-adjacent contacts whose consent was never recorded. Verify with GET /api/v1/settings/compliance/unknown-marketing-policy → refuse. If you ever relax it, the PATCH demands a justification and a lawful basis and writes both to the audit log.
  5. Consent default policy: if your CDP destinations fan out to analytics, switch PATCH /api/v1/settings/compliance/consent-default-policy to deny_on_missing so a contact with no consent ledger row is never reached by a destination fanout. This flips the consent-default from fail-open to fail-closed; universal legal gates (revoked consent, erasure) apply regardless of the setting.

Posture E — US-only high-volume sender

You ship US-only traffic at volume, and your fraud envelope must match your footprint: no destinations outside the US, hard velocity and spend ceilings, and inbound origins outside the US dropped before they hit the inbox. Every write is owner-only.
  1. Narrow the outbound country allowlist. PUT /api/v1/settings/compliance/country-allowlist with allowed_countries: ["US"] and allow_all_countries: false. While the allowlist is empty the control is fail-open — nothing is country-gated. The moment you set it, it is fail-closed by design: ["US"] rejects any non-US phone destination with 422 COUNTRY_NOT_ALLOWED on SMS, the messaging channels, and voice alike. Leave allow_all_countries at false — setting it to true is the explicit send-anywhere posture and defeats the rail. Verify with GET /api/v1/settings/compliance/country-allowlist.
  2. Set per-channel fraud caps. PUT /api/v1/settings/compliance/fraud-caps with per-channel velocity (max_per_min) and daily-spend (max_daily_spend_cents) ceilings sized to your real traffic, plus the voice block (max_calls_per_min, max_daily_spend_cents — and a per-destination-country calls/min map if you want a hard 0 on a country you never dial). The response echoes the platform floor per channel; your override can only lower the envelope, never raise it past the floor. This converts spend anomalies from a report into a hard refusal. Verify with GET /api/v1/settings/compliance/fraud-caps — each channel’s override appears next to its floor.
  3. Optionally tighten throughput per channel. If your senders are provisioned for a steady rate, PUT /api/v1/settings/compliance/channel-rate-overrides caps the per-minute send rate per channel below the platform default, so a runaway campaign or a compromised key cannot spike your throughput. Verify with GET /api/v1/settings/compliance/channel-rate-overrides.
  4. Block inbound origins outside the US. PUT /api/v1/settings/compliance/inbound-country-gate with inbound_country_mode: "block" and inbound_allowed_countries: ["US"] (or the inverse — inbound_blocked_countries for a deny-list). Origins outside the allowed set are dropped before they reach the inbox. Start with flag if you want to observe first: flag-mode records without dropping, and off leaves the gate inert. Origin is resolved from the sender’s phone number — non-phone senders resolve to no country and are not gated. Verify with GET /api/v1/settings/compliance/inbound-country-gate.
  5. Layer the US-marketing posture. For the messaging side, every toggle in Posture A applies unchanged — quiet hours, DNC scrub, suppression imports, sender registration, and the emergency stop.
  6. Watch the read-only surfaces. Check GET /api/v1/settings/compliance/voice-destination-blocks during a fraud wave — it lists the automatic per-destination voice blocks the anomaly sweep applied, so you can tell a platform fraud block from your own country allowlist before calling support.

What is not tenant-toggleable

A short list, on purpose. These are the surfaces where an open default or a tenant opt-out would be wrong — either the statute forbids it, or the control exists to protect the recipient and the platform alike.
  • Campaign and dialer voice federal window. The TCPA 8 AM–9 PM recipient-local dialing window (47 U.S.C. § 227(b)(1)(B)) hard-blocks all automated and bulk outbound voice to US (+1) recipients, and accepts no tenant toggle: no per-organization bypass, no start_hour/end_hour knob on the federal window, no fail-open on a timezone-unresolved recipient. Ad-hoc 1:1 dashboard dialing is advisory-unless-enabled (a tenant control — flip voice on the org gate to harden it); the campaign/dialer path never is. Carriers and the statute assess 500–500–1,500 per violating call, so the rail is platform-level. See the US-voice note in Send Gates and the enforcement table in Quiet hours configuration.
  • State mini-TCPA overlays. Stricter state windows and day bans (Florida’s Sunday prohibition, Mississippi’s 7:30 PM close, Oklahoma/Louisiana/Alabama/West Virginia overlays) intersect with the federal window on the most-restrictive-wins rule. They carry no tenant toggle either — a state statutory window is not yours to relax. Block reasons surface as outside_state_window or state_blocked_day so you can separate state-driven holds from federal ones in reporting.
  • Emergency-stop scope. The kill switch is defined by what it halts — outbound SMS, MMS, voice, and dialer campaign traffic. Its carve-out is fixed, not configurable: transactional Verify/OTP sends and email are never gated by it, because a login code must still reach a contact mid-incident. You cannot widen the stop to those paths through the switch — if you need them paused, disable the Verify profile or email sender directly. See Send Gates → Emergency stop.
  • The delegate-certificate A ceiling. A delegate certificate raises an external number from C to B only — never to A. A attestation is reserved for numbers owned through Orbit, and this ceiling is deliberately not a setting: treating a self-registered artifact as full attestation would let anyone spoof it for arbitrary numbers. See STIR/SHAKEN.
  • Wholesale signing authority. Orbit signals the attestation level; the Devotel-operated softswitch signs the PASSporT on-net, and it will never sign higher than what the platform attests. There is no tenant-side “sign at A anyway.”
Nothing else on this surface is platform-mandated. The absence of a fourth hard rail is the point of the posture model: defaults open, tenant-owned, with these documented asymmetries.

Read the signals, don’t guess

Two read-only surfaces report the posture you actually have — use them before and after you change a toggle, not as a substitute for one.
  • Compliance health (GET /compliance/health, plus /health/numbers and /health/campaigns) blends consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections into a 0–100 score per organization, sender, and campaign, with a warnings array of ranked fixes. It never blocks a send; it tells you which sender is about to be throttled before the traffic degrades. Start with the list endpoints — they order worst first. See Compliance Health Scores.
  • Quiet-hours preview (GET /compliance/quiet-hours/preview) answers “would this send, to this recipient, be held right now — and if so until when?” with the resolved window and next_allowed_at. Check it before a rollout, and use it to schedule around a window rather than retrying into it. See Quiet-Hours Preview for the response contract, and Send Gates for the full gate stack.
Read the health score and the preview together with the map above: the map tells you which switch to flip, the signals tell you whether the flip did what you intended.