Your Tenant Compliance Posture: The Toggle Map
The Compliance group in these docs is deep on individual surfaces — send gates, quiet hours, DNC, RND, STIR/SHAKEN, HIPAA, DSAR, opt-out, Sender-ID registration, KYC documents. This page is the map across all of them: which controls are yours to switch, where each switch lives, what the out-of-box default is, and the small set of surfaces the platform deliberately does not let you toggle. Read this once, then dive into the one or two deep pages your posture actually touches.The platform posture
Orbit’s compliance model has three commitments, and everything on the map below hangs off them:- Controls are tenant-owned. Compliance for your traffic is your responsibility. Orbit gives you the control surface — gates, windows, scrubs, registries, policy knobs — and enforces what you set. It does not mandate a posture for you, and it does not decide that a send is “compliant.” Several deep pages state this on their own surfaces (STIR/SHAKEN, SCIM, KYC documents, CPNI); this page is the statement for the group as a whole.
- Everything defaults open. Except for the hard asymmetries listed in What is not tenant-toggleable, every gate ships off / open: a new tenant’s sends are not held by quiet hours, not scrubbed against DNC or RND, and not blocked by an attestation floor, until you opt in. Where input can’t be resolved — a recipient timezone outside the US, an attestation lookup that errors — these controls fail open rather than blocking traffic. The posture you choose is additive: you tighten from an open default, you don’t loosen from a restrictive one.
- Orbit is the conduit and the ledger, not the compliance owner. Orbit carries your sends to the carriers, enforces the gates you set, and keeps the auditable record — consent decisions, suppression entries, certifications, traceback cases, scrub results. It never files with a regulator for you, never sends a customer notice for you, and never invents or auto-renews an identity document. The ledger reflects what you did; the decisions stay yours.
The posture map
One row per surface: where the toggle lives, how it defaults, how it behaves when inputs can’t be resolved, and the deep page to read before you flip it.
Two adjacent surfaces are read-only, not toggles: the org-wide
compliance-health scores and the
quiet-hours preview endpoint. They report
your posture; they never change it.
Three reference postures
Copy the posture closest to your traffic, then adjust. Each lists exactly which toggles to flip and which deep page documents the write.Posture A — US marketing SMS operator
You send A2P marketing SMS to US recipients under TCPA.- Quiet hours: enable the
smschannel on the org gate. Platform hours 08:00–21:00 recipient-local apply immediately; keepconsent_overrides_quiet_hours: true(the default) so permitted recipients stay reachable inside the window. See Quiet hours configuration. - Campaign fallback window: set it in Settings → Campaign limits
(or
PUT /campaigns/quiet-hours/settings) if your drip sends should use a tighter window than the platform default. - DNC scrub: turn on
dnc_sync_enabledso/compliance/dnc/checkand the suppression feed back your dialing decisions. Plan around the documented caveat: until a federal snapshot is synced, a number only on the FTC list reads back clear. See Send Gates. - Suppression: bulk-import any legacy opt-out list via
POST /compliance/suppression-list/importbefore your first send; phone rows default to scopeall, which also gates voice. - Sender ID / 10DLC: complete your brand and campaign registration (10DLC guide) — US long-code traffic without it degrades regardless of these gates.
- Emergency stop: know where it is before you need it —
POST /compliance/emergency-stop/activatehalts all outbound SMS, MMS, voice, and dialer traffic in one call. - Leave RND off unless you operate a re-consent program that needs the § 227 safe harbor reads.
Posture B — EU GDPR + APAC drip operator
You run drip campaigns to EU/APAC recipients under GDPR and local marketing rules. The full end-to-end walkthrough of this posture is Assembling a GDPR Posture End to End; the steps below are the map-level summary.- Campaign fallback window: set your local regime in Settings → Campaign limits (e.g. 22:00 → 07:00) so every drip or journey that lacks its own window sends inside it. This is the single highest- value toggle for this posture.
- Org gate per channel if you also want 1:1 traffic held —
enable per channel with your own
start_hour/end_hour. - Consent records: file per-channel consent through
POST /compliance/consentbefore campaign sends, with the GDPR lawful basis recorded. Consent coverage is 30% of the compliance-health score, and carriers read it. - DSAR: decide your intake path — operator-filed through
POST /compliance/dsar, the public self-service portal behind your privacy-policy link, or both. The SLA tracker applies per jurisdiction (gdpr30 days,pdpa30,lgpd15). - Processing register: document your Art.30 activities and run Art.35 DPIAs in the privacy register if your processing is high-risk.
- Preference center: configure one and sign per-contact links so GDPR delete/consent requests arrive structured instead of as support tickets.
Posture C — US voice dialer operator
You run outbound voice campaigns and ad-hoc dialing to US recipients.- Accept the hard rails first. Campaign and dialer voice outside
the 8 AM–9 PM recipient-local federal window is always blocked
(
422 TCPA_FEDERAL_DIALING_WINDOW_BLOCKED), a timezone-unresolved US recipient is blocked fail-closed, and stricter state overlays (Florida’s Sunday ban, Oklahoma/Mississippi windows, and the other mini-TCPA states) sit on top. No toggle relaxes any of this — see What is not tenant-toggleable. - Ad-hoc 1:1 dialing: decide whether the dashboard soft-dials stay
advisory (the default) or become hard holds — enable the
voicechannel on the org gate for the latter. - Suppression: phone-scoped opt-outs gate voice and dialer traffic; import your DNC list and wire STOP handling before the first campaign.
- STIR/SHAKEN: run your traffic from numbers your org owns — the only path to full (A) attestation. Register delegate certificates for external caller IDs you legitimately control to raise them C → B, and set the attestation policy plus the inbound floor per DID. All in STIR/SHAKEN.
- RMD: create and submit your Robocall Mitigation Database filing
through
POST /compliance/rmdbefore originating voice; keep the recertification deadline on your calendar. The full lifecycle — submit, certify, remediate, resolve, withdraw, and the opt-in call-time guard — is in RMD Registration. - Emergency stop: the same kill switch covers voice — one call halts dialer traffic mid-incident.
What is not tenant-toggleable
A short list, on purpose. These are the surfaces where an open default or a tenant opt-out would be wrong — either the statute forbids it, or the control exists to protect the recipient and the platform alike.- Campaign and dialer voice federal window. The TCPA 8 AM–9 PM
recipient-local dialing window (47 U.S.C. § 227(b)(1)(B)) hard-blocks
all automated and bulk outbound voice to US (+1) recipients, and
accepts no tenant toggle: no per-organization bypass, no
start_hour/end_hourknob on the federal window, no fail-open on a timezone-unresolved recipient. Ad-hoc 1:1 dashboard dialing is advisory-unless-enabled (a tenant control — flipvoiceon the org gate to harden it); the campaign/dialer path never is. Carriers and the statute assess 1,500 per violating call, so the rail is platform-level. See the US-voice note in Send Gates and the enforcement table in Quiet hours configuration. - State mini-TCPA overlays. Stricter state windows and day bans
(Florida’s Sunday prohibition, Mississippi’s 7:30 PM close,
Oklahoma/Louisiana/Alabama/West Virginia overlays) intersect with the
federal window on the most-restrictive-wins rule. They carry no
tenant toggle either — a state statutory window is not yours to
relax. Block reasons surface as
outside_state_windoworstate_blocked_dayso you can separate state-driven holds from federal ones in reporting. - Emergency-stop scope. The kill switch is defined by what it halts — outbound SMS, MMS, voice, and dialer campaign traffic. Its carve-out is fixed, not configurable: transactional Verify/OTP sends and email are never gated by it, because a login code must still reach a contact mid-incident. You cannot widen the stop to those paths through the switch — if you need them paused, disable the Verify profile or email sender directly. See Send Gates → Emergency stop.
- The delegate-certificate A ceiling. A delegate certificate raises an external number from C to B only — never to A. A attestation is reserved for numbers owned through Orbit, and this ceiling is deliberately not a setting: treating a self-registered artifact as full attestation would let anyone spoof it for arbitrary numbers. See STIR/SHAKEN.
- Wholesale signing authority. Orbit signals the attestation level; the Devotel-operated softswitch signs the PASSporT on-net, and it will never sign higher than what the platform attests. There is no tenant-side “sign at A anyway.”
Read the signals, don’t guess
Two read-only surfaces report the posture you actually have — use them before and after you change a toggle, not as a substitute for one.- Compliance health (
GET /compliance/health, plus/health/numbersand/health/campaigns) blends consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections into a 0–100 score per organization, sender, and campaign, with awarningsarray of ranked fixes. It never blocks a send; it tells you which sender is about to be throttled before the traffic degrades. Start with the list endpoints — they order worst first. See Compliance Health Scores. - Quiet-hours preview (
GET /compliance/quiet-hours/preview) answers “would this send, to this recipient, be held right now — and if so until when?” with the resolved window andnext_allowed_at. Check it before a rollout, and use it to schedule around a window rather than retrying into it. See Send Gates.
Related references
- Compliance Posture FAQ — the operator questions behind the map: why an enabled toggle may not be blocking yet, which controls fail open versus closed, and which approvals carry external lead time.
- Configure Your Tenant’s Posture Before the First Send — the guided runbook: this map’s toggles flipped in day-one order, with defaults and consequences for each.
- Assembling a GDPR Posture End to End — the full walkthrough behind Posture B.
- Send Gates — the full gate stack this page maps.
- Quiet hours configuration — the two quiet-hours knobs and their carve-outs.
- Compliance Health Scores — the read-only early-warning layer.
- Opt-Out & Suppression Lists — the suppression layer the gates read.
- STIR/SHAKEN attestation — voice caller-identity posture.
- API Reference → Compliance — full request/response schemas for every endpoint named here.