Skip to main content

Tenant posture audit map

A quarterly compliance review has a simple question to answer: which planes exist, who owns each one, and where do I sample the evidence that they are doing what I believe they do? The toggle inventory lists every switch; this page is the narrative underneath it — the map of planes and the audit trail each plane emits. Read this once before a review, then use the toggle page for the live setting and the Compliance Health Scores page for the current signal.
This page describes Orbit’s platform controls. It is not legal advice. Which laws apply to your traffic, and what posture is adequate, depends on where you and your recipients are and what you send. Confirm with qualified counsel.

1. The three planes

Every gate a send traverses belongs to exactly one of three planes. The planes differ in who owns the switch — and that distinction decides which plane a review treats as “verify the default” versus “sample the configuration.”

Plane A — federal asymmetry (platform-owned)

Two surfaces carry no tenant toggle, because the statute or recipient protection forbids an open default:
  • TCPA federal voice window. Campaign and dialer voice to US (+1) recipients outside the 8 AM–9 PM recipient-local window hard-blocks with 422 TCPA_FEDERAL_DIALING_WINDOW_BLOCKED, and a timezone-unresolved US recipient blocks fail-closed. State mini-TCPA overlays (Florida’s Sunday ban, Mississippi’s close, the Oklahoma/Louisiana/Alabama/Arkansas/ West Virginia windows) intersect on top, most-restrictive-wins.
  • Emergency-routing rail. A recipient-side protection path with the same no-toggle posture as the federal window — the exact rail, like the window, exists precisely so that no tenant decision can weaken it.
A review samples Plane A differently: there is nothing to configure, so the question is “confirm the rails still hold” — one row verified, not a configuration sampled.

Plane B — tenant opt-in gates (tenant-owned)

The tail of the send chain, each defaulting open until you opt in:
  • Quiet hours — per-channel windows you set on the org gate.
  • DNC / RND safe-harbor — the federal scrub and the Reassigned Numbers Database reads that back the § 227 safe-harbor.
  • STIR attestation floors — the minimum-attestation policy per inbound DID, and the delegate-certificate ceiling (B, never A) on outbound.
  • Channel rate overrides — per-channel throughput ceilings below the platform default.
  • DNO (do-not-originate) — the inbound-origin block list posture.
For Plane B the review samples configuration: which gates are enabled, and do the settings match the policy the review expects? The toggle inventory is the live map of where each switch sits and how it defaults.

Plane C — always-on hygiene (no audit checkpoint to miss)

The chain every send walks regardless of any toggle:
  • Suppression scope — opt-outs entered through STOP, the Consent API, the preference center, or bulk import are fail-closed for entries that exist; phone rows defaulting to scope all gate voice and dialer too.
  • Wallet / frequency chain — the billing pause flags and the per-contact frequency caps that compose the send-admission path.
Hygiene planes are not optional, so a review does not “sample the configuration” — it checks that the chain runs at all, then looks at the evidence the chain produced.

2. Fail-closed vs fail-open, per plane

The review’s first question on any plane is what happens when the input cannot be resolved — that default decides whether a failure hides a send or blocks one. Ownership matches the default: Plane A rails are platform-owned (you cannot flip them), Plane B gates are yours to flip from an open default, and Plane C is the path itself, not a knob. The per-surface defaults are the rows on the toggle map; this page is the shape of the map, not the table.

3. Worked flow: new campaign to US +1 recipients

Walk the gates a send traverses, in the order the send walks them. A U.S. (+1) SMS campaign with consent shown in the list:
  1. Country rules. The destination resolves against your outbound country allowlist — unset, it is fail-open; once set, an off-list destination rejects 422 COUNTRY_NOT_ALLOWED. See Fraud Shield.
  2. Registration. For US long-code traffic, the 10DLC brand and campaign registration gates before delivery; toll-free verification is the toll-free analog. See Sender-ID Registration.
  3. Quiet-hours resolution. If you enabled the channel on the org gate with a window, the contact’s timezone resolves; unresolved (or non-US) recipients pass under your configured skip policy — Quiet hours configuration.
  4. DNC. If the scrub is on, the number checks the synced federal list; with no snapshot it returns 403 DNC_SYNC_NOT_ENABLED. See DNC Scrubbing.
  5. RND. If the scrub is on, the Reassigned Numbers verdict backs the safe-harbor read; unenabled, verdicts degrade to no_data. See Send Gates.
  6. Suppression scope. Phone suppression entries — entered from STOP, the Consent API, the preference center, or import — drop the send before dispatch; scope all gates voice and dialer too. See Opt-Out & Suppression Lists.
  7. Wallet / frequency. The org’s outbound pause flags and your per-contact frequency caps admit or gate the send. See Wallets, credits, and charges and Frequency caps.
Voice campaigns add the layer above all of this: the TCPA federal window (Plane A) sits before the tenant gates, and an unresolved US recipient timezone blocks fail-closed. The full chain is in Send Gates.

4. Where the evidence lands

Three stores produce audit evidence; a quarterly review samples a different slice from each.

Evidence binder

The evidence binder rolls your audit chain into a framework-mapped pack (SOC 2, ISO 27001, GDPR, HIPAA) with one download to hand to an auditor. A review samples: the binder’s own generation history and the sections the framework’s controls cover — consent-posture evidence, access reviews, retention posture, breach counts.

Audit log

Every tenant-owned write — a toggle flip on Plane B, a suppression import, a posture justification — lands in the org audit log with its actor, timestamp, and old/new values. A review samples: a slice of the toggle flips since the last review, checking each one had an owner and a justification. The unknown-consent and posture-FAQ pages note which writes demand a recorded lawful basis.

Compliance-health snapshot

Compliance Health Scores blend consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections into a 0–100 score per organization, sender, and campaign. A review samples: the organization score over the quarter’s window and the worst rows on the sender table — the early-warning read, never a blocker. The rule of thumb: the binder is your external artifact, the audit log is your internal trail, and the health snapshot is your early-warning signal. Sample all three; any one alone misses part of the posture.

5. Guardrail: no platform-mandated bars

Apart from the two federal asymmetries in Plane A, no platform mandate sits on top of your posture. The default-open / fail-open model means the platform never decides that a send is compliant on your behalf — it enforces what you set and keeps the ledger. This is the framing that keeps a posture readable:
  • What stays tenant-owned, by design. Apart from the named Plane A rails, every gate in the compliance group is yours to flip from an open default. The Posture FAQ says this plainly: a short, deliberate asymmetry list, and everything else tenant-owned.
  • The asymmetry list is short on purpose. The two rails above — the TCPA federal voice window and the emergency-routing rail — are the complete set. No fourth bar exists; the absence of more defaults-open exceptions is the posture model’s point.
That split is what makes the map above usable: verify the two rails, sample the tenant gates, and rely on the hygiene chain. A review that samples anything else is sampling the wrong plane.