Your Tenant Compliance Posture: The Toggle Map
The Compliance group in these docs is deep on individual surfaces — send gates, quiet hours, DNC, RND, STIR/SHAKEN, HIPAA, DSAR, opt-out, Sender-ID registration, KYC documents. This page is the map across all of them: which controls are yours to switch, where each switch lives, what the out-of-box default is, and the small set of surfaces the platform deliberately does not let you toggle. Read this once, then dive into the one or two deep pages your posture actually touches.Start here by topic
Eight regulatory postures cover nearly every new tenant’s first configuration pass. The order below is the recommended implementation sequence: sender identity and quiet hours first (they gate deliverability and call timing from the first send), privacy and voice identity next, then the healthcare, KYC, and opt-out layers a regulated or scaled operation adds. Configure the rows that match your traffic; skip the ones that don’t. Everything listed is a tenant-owned control — Orbit enforces what you set; the decisions stay yours.
After the eight, the posture map below covers the
remaining controls — DNC and RND scrubs, the emergency stop, fraud
caps, and the read-only health signals — in the same one-row-per-
surface format.
The platform posture
Orbit’s compliance model has three commitments, and everything on the map below hangs off them:- Controls are tenant-owned. Compliance for your traffic is your responsibility. Orbit gives you the control surface — gates, windows, scrubs, registries, policy knobs — and enforces what you set. It does not mandate a posture for you, and it does not decide that a send is “compliant.” Several deep pages state this on their own surfaces (STIR/SHAKEN, SCIM, KYC documents, CPNI); this page is the statement for the group as a whole.
- Everything defaults open. Except for the hard asymmetries listed in What is not tenant-toggleable, every gate ships off / open: a new tenant’s sends are not held by quiet hours, not scrubbed against DNC or RND, and not blocked by an attestation floor, until you opt in. Where input can’t be resolved — a recipient timezone outside the US, an attestation lookup that errors — these controls fail open rather than blocking traffic. The posture you choose is additive: you tighten from an open default, you don’t loosen from a restrictive one.
- Orbit is the conduit and the ledger, not the compliance owner. Orbit carries your sends to the carriers, enforces the gates you set, and keeps the auditable record — consent decisions, suppression entries, certifications, traceback cases, scrub results. It never files with a regulator for you, never sends a customer notice for you, and never invents or auto-renews an identity document. The ledger reflects what you did; the decisions stay yours.
The posture map
One row per surface: where the toggle lives, how it defaults, how it behaves when inputs can’t be resolved, and the deep page to read before you flip it.
Two adjacent surfaces are read-only, not toggles: the org-wide
compliance-health scores and the
quiet-hours preview endpoint. They report
your posture; they never change it. A third read-only surface sits
with the fraud controls:
GET /api/v1/settings/compliance/voice-destination-blocks lists the
automatic per-destination voice blocks the platform applied on a
toll-fraud / Wangiri burst. The blocks themselves are enforcement,
not a toggle — they are written by the anomaly sweep, enforce
fail-closed on the outbound dial path, and expire on their own;
this endpoint only makes the active list visible before a legitimate
call to that number is rejected. The categories, time-bound
semantics, and the dashboard panel behind that row are documented
in Voice Destination Auto-Blocks.
Five reference postures
Copy the posture closest to your traffic, then adjust. Each lists exactly which toggles to flip and which deep page documents the write.Posture A — US marketing SMS operator
You send A2P marketing SMS to US recipients under TCPA.- Quiet hours: enable the
smschannel on the org gate. Platform hours 08:00–21:00 recipient-local apply immediately; keepconsent_overrides_quiet_hours: true(the default) so permitted recipients stay reachable inside the window. See Quiet hours configuration. - Campaign fallback window: set it in Settings → Campaign limits
(or
PUT /campaigns/quiet-hours/settings) if your drip sends should use a tighter window than the platform default. - DNC scrub: turn on
dnc_sync_enabledso/compliance/dnc/checkand the suppression feed back your dialing decisions. Plan around the documented caveat: until a federal snapshot is synced, a number only on the FTC list reads back clear. See Send Gates. - Suppression: bulk-import any legacy opt-out list via
POST /compliance/suppression-list/importbefore your first send; phone rows default to scopeall, which also gates voice. - Sender ID / 10DLC: complete your brand and campaign registration (10DLC guide) — US long-code traffic without it degrades regardless of these gates.
- Emergency stop: know where it is before you need it —
POST /compliance/emergency-stop/activatehalts all outbound SMS, MMS, voice, and dialer traffic in one call. - Leave RND off unless you operate a re-consent program that needs the § 227 safe harbor reads.
Posture B — EU GDPR + APAC drip operator
You run drip campaigns to EU/APAC recipients under GDPR and local marketing rules. The full end-to-end walkthrough of this posture is Assembling a GDPR Posture End to End; the steps below are the map-level summary.- Campaign fallback window: set your local regime in Settings → Campaign limits (e.g. 22:00 → 07:00) so every drip or journey that lacks its own window sends inside it. This is the single highest- value toggle for this posture.
- Org gate per channel if you also want 1:1 traffic held —
enable per channel with your own
start_hour/end_hour. - Consent records: file per-channel consent through
POST /compliance/consentbefore campaign sends, with the GDPR lawful basis recorded. Consent coverage is 30% of the compliance-health score, and carriers read it. - DSAR: decide your intake path — operator-filed through
POST /compliance/dsar, the public self-service portal behind your privacy-policy link, or both. The SLA tracker applies per jurisdiction (gdpr30 days,pdpa30,lgpd15). - Processing register: document your Art.30 activities and run Art.35 DPIAs in the privacy register if your processing is high-risk.
- Preference center: configure one and sign per-contact links so GDPR delete/consent requests arrive structured instead of as support tickets.
Posture C — US voice dialer operator
You run outbound voice campaigns and ad-hoc dialing to US recipients.- Accept the hard rails first. Campaign and dialer voice outside
the 8 AM–9 PM recipient-local federal window is always blocked
(
422 TCPA_FEDERAL_DIALING_WINDOW_BLOCKED), a timezone-unresolved US recipient is blocked fail-closed, and stricter state overlays (Florida’s Sunday ban, Oklahoma/Mississippi windows, and the other mini-TCPA states) sit on top. No toggle relaxes any of this — see What is not tenant-toggleable. - Ad-hoc 1:1 dialing: decide whether the dashboard soft-dials stay
advisory (the default) or become hard holds — enable the
voicechannel on the org gate for the latter. - Suppression: phone-scoped opt-outs gate voice and dialer traffic; import your DNC list and wire STOP handling before the first campaign.
- STIR/SHAKEN: run your traffic from numbers your org owns — the only path to full (A) attestation. Register delegate certificates for external caller IDs you legitimately control to raise them C → B, and set the attestation policy plus the inbound floor per DID. All in STIR/SHAKEN.
- RMD: create and submit your Robocall Mitigation Database filing
through
POST /compliance/rmdbefore originating voice; keep the recertification deadline on your calendar. The full lifecycle — submit, certify, remediate, resolve, withdraw, and the opt-in call-time guard — is in RMD Registration. - Emergency stop: the same kill switch covers voice — one call halts dialer traffic mid-incident.
Posture D — Regulated-healthcare sender
You send patient-adjacent traffic under HIPAA, with an executed BAA, and your data-handling rules say message bodies never leave your tenancy for an AI hop. Every write below is owner-only, and every one lands in the org audit log.-
BAA + HIPAA mode first. Execute the BAA, then enable HIPAA
mode (
PUT /api/v1/settings/hipaa; HIPAA). Until the BAA is executed the mode refuses to enable and PHI sends are rejected422 HIPAA_BAA_REQUIRED— fail-closed toward PHI. Set your PHI retention window in the same pass. The full walkthrough is HIPAA onboarding: from BAA to audit-ready. -
Close the inbox AI gates.
PATCH /api/v1/settings/compliance/inbox-ai-privacywithauto_categorize: falseandauto_summarize: false. Both default on and ship inbound message bodies (categorize) and close-time summaries (summarize) to a third-party LLM — this is the one posture where the platform default is the wrong day-0 state and you deliberately tighten from it. Verify withGET /api/v1/settings/compliance/inbox-ai-privacy→ both fieldsfalse. -
Leave AI-turn audit off unless your policy requires it. Off is
the default and the fail-safe direction. If your audit policy
requires verbatim records,
PUT /api/v1/settings/compliance/ai-turn-auditwithenabled: truepersists every AI turn — system prompt, user prompt, and response — to your tenant audit table. Treat that as a multi-year verbatim PII surface: enable it only per written policy, and pair it with a retention decision. Verify withGET /api/v1/settings/compliance/ai-turn-audit. Decide explicitly: verbatim audit is a deliberate, policy-backed choice, not a leftover. “Off by accident” and “on by accident” are both findings in a HIPAA review. -
Refuse unknown-consent marketing. Keep
unknown_marketing_policyat the defaultrefuse— a marketing gate never widens onto PHI-adjacent contacts whose consent was never recorded. Verify withGET /api/v1/settings/compliance/unknown-marketing-policy→refuse. If you ever relax it, thePATCHdemands a justification and a lawful basis and writes both to the audit log. -
Consent default policy: if your CDP destinations fan out to
analytics, switch
PATCH /api/v1/settings/compliance/consent-default-policytodeny_on_missingso a contact with no consent ledger row is never reached by a destination fanout. This flips the consent-default from fail-open to fail-closed; universal legal gates (revoked consent, erasure) apply regardless of the setting.
Posture E — US-only high-volume sender
You ship US-only traffic at volume, and your fraud envelope must match your footprint: no destinations outside the US, hard velocity and spend ceilings, and inbound origins outside the US dropped before they hit the inbox. Every write is owner-only.- Narrow the outbound country allowlist.
PUT /api/v1/settings/compliance/country-allowlistwithallowed_countries: ["US"]andallow_all_countries: false. While the allowlist is empty the control is fail-open — nothing is country-gated. The moment you set it, it is fail-closed by design:["US"]rejects any non-US phone destination with422 COUNTRY_NOT_ALLOWEDon SMS, the messaging channels, and voice alike. Leaveallow_all_countriesatfalse— setting it totrueis the explicit send-anywhere posture and defeats the rail. Verify withGET /api/v1/settings/compliance/country-allowlist. - Set per-channel fraud caps.
PUT /api/v1/settings/compliance/fraud-capswith per-channel velocity (max_per_min) and daily-spend (max_daily_spend_cents) ceilings sized to your real traffic, plus the voice block (max_calls_per_min,max_daily_spend_cents— and a per-destination-country calls/min map if you want a hard0on a country you never dial). The response echoes the platform floor per channel; your override can only lower the envelope, never raise it past the floor. This converts spend anomalies from a report into a hard refusal. Verify withGET /api/v1/settings/compliance/fraud-caps— each channel’s override appears next to its floor. - Optionally tighten throughput per channel. If your senders are
provisioned for a steady rate,
PUT /api/v1/settings/compliance/channel-rate-overridescaps the per-minute send rate per channel below the platform default, so a runaway campaign or a compromised key cannot spike your throughput. Verify withGET /api/v1/settings/compliance/channel-rate-overrides. - Block inbound origins outside the US.
PUT /api/v1/settings/compliance/inbound-country-gatewithinbound_country_mode: "block"andinbound_allowed_countries: ["US"](or the inverse —inbound_blocked_countriesfor a deny-list). Origins outside the allowed set are dropped before they reach the inbox. Start withflagif you want to observe first: flag-mode records without dropping, andoffleaves the gate inert. Origin is resolved from the sender’s phone number — non-phone senders resolve to no country and are not gated. Verify withGET /api/v1/settings/compliance/inbound-country-gate. - Layer the US-marketing posture. For the messaging side, every toggle in Posture A applies unchanged — quiet hours, DNC scrub, suppression imports, sender registration, and the emergency stop.
- Watch the read-only surfaces. Check
GET /api/v1/settings/compliance/voice-destination-blocksduring a fraud wave — it lists the automatic per-destination voice blocks the anomaly sweep applied, so you can tell a platform fraud block from your own country allowlist before calling support.
What is not tenant-toggleable
A short list, on purpose. These are the surfaces where an open default or a tenant opt-out would be wrong — either the statute forbids it, or the control exists to protect the recipient and the platform alike.- Campaign and dialer voice federal window. The TCPA 8 AM–9 PM
recipient-local dialing window (47 U.S.C. § 227(b)(1)(B)) hard-blocks
all automated and bulk outbound voice to US (+1) recipients, and
accepts no tenant toggle: no per-organization bypass, no
start_hour/end_hourknob on the federal window, no fail-open on a timezone-unresolved recipient. Ad-hoc 1:1 dashboard dialing is advisory-unless-enabled (a tenant control — flipvoiceon the org gate to harden it); the campaign/dialer path never is. Carriers and the statute assess 1,500 per violating call, so the rail is platform-level. See the US-voice note in Send Gates and the enforcement table in Quiet hours configuration. - State mini-TCPA overlays. Stricter state windows and day bans
(Florida’s Sunday prohibition, Mississippi’s 7:30 PM close,
Oklahoma/Louisiana/Alabama/West Virginia overlays) intersect with the
federal window on the most-restrictive-wins rule. They carry no
tenant toggle either — a state statutory window is not yours to
relax. Block reasons surface as
outside_state_windoworstate_blocked_dayso you can separate state-driven holds from federal ones in reporting. - Emergency-stop scope. The kill switch is defined by what it halts — outbound SMS, MMS, voice, and dialer campaign traffic. Its carve-out is fixed, not configurable: transactional Verify/OTP sends and email are never gated by it, because a login code must still reach a contact mid-incident. You cannot widen the stop to those paths through the switch — if you need them paused, disable the Verify profile or email sender directly. See Send Gates → Emergency stop.
- The delegate-certificate A ceiling. A delegate certificate raises an external number from C to B only — never to A. A attestation is reserved for numbers owned through Orbit, and this ceiling is deliberately not a setting: treating a self-registered artifact as full attestation would let anyone spoof it for arbitrary numbers. See STIR/SHAKEN.
- Wholesale signing authority. Orbit signals the attestation level; the Devotel-operated softswitch signs the PASSporT on-net, and it will never sign higher than what the platform attests. There is no tenant-side “sign at A anyway.”
Read the signals, don’t guess
Two read-only surfaces report the posture you actually have — use them before and after you change a toggle, not as a substitute for one.- Compliance health (
GET /compliance/health, plus/health/numbersand/health/campaigns) blends consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections into a 0–100 score per organization, sender, and campaign, with awarningsarray of ranked fixes. It never blocks a send; it tells you which sender is about to be throttled before the traffic degrades. Start with the list endpoints — they order worst first. See Compliance Health Scores. - Quiet-hours preview (
GET /compliance/quiet-hours/preview) answers “would this send, to this recipient, be held right now — and if so until when?” with the resolved window andnext_allowed_at. Check it before a rollout, and use it to schedule around a window rather than retrying into it. See Quiet-Hours Preview for the response contract, and Send Gates for the full gate stack.
Related references
- Compliance endpoint permissions: the role matrix —
one central table of which workspace role each high-traffic compliance
endpoint’s reads and writes need, and how to read a
403when the gate refuses. - Compliance Posture FAQ — the operator questions behind the map: why an enabled toggle may not be blocking yet, which controls fail open versus closed, and which approvals carry external lead time.
- Compliance Approval Timelines & Trigger Runbooks — the platform-paced vs external-paced timeline table behind every approval row, and the trigger-event runbook routes (flagged campaign, country-rules refresh, BAA expiry).
- Configure Your Tenant’s Posture Before the First Send — the guided runbook: this map’s toggles flipped in day-one order, with defaults and consequences for each.
- Assembling a GDPR Posture End to End — the full walkthrough behind Posture B.
- Assemble a Shared Compliance Profile Across Gated Surfaces — the shared-packet pattern this map’s KYC row plugs into — reuse, attach-by-id, rotation, and expiry alerts.
- Send Gates — the full gate stack this page maps.
- Quiet hours configuration — the two quiet-hours knobs and their carve-outs.
- Compliance Health Scores — the read-only early-warning layer.
- Opt-Out & Suppression Lists — the suppression layer the gates read.
- Fraud Shield — the fraud-enforcement controls behind the country allowlist, inbound gate, caps, and rate-override rows.
- Consent Management — the consent ledger the two consent-policy rows gate on.
- Consent Posture: The Unknown-Consent Policies — the concept page behind the two consent-policy rows: what each knob resolves, when to loosen, and what the audit trail records.
- AI Turn Audit — the verbatim AI-decision evidence chain behind SOC2 / HIPAA / FINRA export and the GDPR Art-22 § 3 human-override path.
- STIR/SHAKEN attestation — voice caller-identity posture.
- API Reference → Compliance — full request/response schemas for every endpoint named here.