> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Tenant posture audit map — planes, ownership, and where the evidence lands

> The mental model behind your quarterly compliance review: the three planes every send traverses (federal asymmetries, tenant opt-in gates, always-on hygiene), who owns each toggle, and which of the three evidence stores to sample.

# Tenant posture audit map

A quarterly compliance review has a simple question to answer: which
planes exist, who owns each one, and where do I sample the evidence that
they are doing what I believe they do? The
[toggle inventory](/compliance/posture-overview) lists every switch; this
page is the narrative underneath it — the map of planes and the audit
trail each plane emits. Read this once before a review, then use the
toggle page for the live setting and the
[Compliance Health Scores](/compliance/compliance-health) page for the
current signal.

<Warning>
  This page describes Orbit's platform controls. It is **not legal
  advice.** Which laws apply to your traffic, and what posture is
  adequate, depends on where you and your recipients are and what you
  send. Confirm with qualified counsel.
</Warning>

***

## 1. The three planes

Every gate a send traverses belongs to exactly one of three planes. The
planes differ in who owns the switch — and that distinction decides which
plane a review treats as "verify the default" versus "sample the
configuration."

### Plane A — federal asymmetry (platform-owned)

Two surfaces carry no tenant toggle, because the statute or recipient
protection forbids an open default:

* **TCPA federal voice window.** Campaign and dialer voice to US (+1)
  recipients outside the 8 AM–9 PM recipient-local window hard-blocks with
  `422 TCPA_FEDERAL_DIALING_WINDOW_BLOCKED`, and a timezone-unresolved US
  recipient blocks fail-closed. State mini-TCPA overlays (Florida's
  Sunday ban, Mississippi's close, the Oklahoma/Louisiana/Alabama/Arkansas/
  West Virginia windows) intersect on top, most-restrictive-wins.
* **Emergency-routing rail.** A recipient-side protection path with the
  same no-toggle posture as the federal window — the exact rail, like the
  window, exists precisely so that no tenant decision can weaken it.

A review samples Plane A differently: there is nothing to configure, so
the question is "confirm the rails still hold" — one row verified, not a
configuration sampled.

### Plane B — tenant opt-in gates (tenant-owned)

The tail of the send chain, each defaulting open until you opt in:

* **Quiet hours** — per-channel windows you set on the org gate.
* **DNC / RND safe-harbor** — the federal scrub and the Reassigned
  Numbers Database reads that back the § 227 safe-harbor.
* **STIR attestation floors** — the minimum-attestation policy per inbound
  DID, and the delegate-certificate ceiling (B, never A) on outbound.
* **Channel rate overrides** — per-channel throughput ceilings below the
  platform default.
* **DNO (do-not-originate)** — the inbound-origin block list posture.

For Plane B the review samples configuration: which gates are enabled,
and do the settings match the policy the review expects? The
[toggle inventory](/compliance/posture-overview) is the live map of
where each switch sits and how it defaults.

### Plane C — always-on hygiene (no audit checkpoint to miss)

The chain every send walks regardless of any toggle:

* **Suppression scope** — opt-outs entered through STOP, the Consent API,
  the preference center, or bulk import are fail-closed for entries that
  exist; phone rows defaulting to scope `all` gate voice and dialer too.
* **Wallet / frequency chain** — the billing pause flags and the
  per-contact frequency caps that compose the send-admission path.

Hygiene planes are not optional, so a review does not "sample the
configuration" — it checks that the chain runs at all, then looks at the
evidence the chain produced.

***

## 2. Fail-closed vs fail-open, per plane

The review's first question on any plane is *what happens when the input
cannot be resolved* — that default decides whether a failure hides a send
or blocks one.

| Plane                       | Default                                                                                                          | Why it matters to the review                                                            |
| --------------------------- | ---------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
| **A — federal asymmetry**   | **Fail-closed.** A timezone-unresolved US voice recipient blocks.                                                | A blocker you cannot relax; the review confirms it fires.                               |
| **B — tenant opt-in gates** | **Fail-open** (voice federal window excepted). Unresolved inputs pass rather than block traffic.                 | A control that "looks quiet" may be off, not working — the review reads the toggle map. |
| **C — hygiene**             | **Fail-closed for existing suppression entries**; the wallet gate engages only when balance or flags require it. | Suppression and wallet are the admission path, not a posture choice.                    |

Ownership matches the default: Plane A rails are platform-owned (you
cannot flip them), Plane B gates are yours to flip from an open default,
and Plane C is the path itself, not a knob. The per-surface defaults are
the rows on [the toggle map](/compliance/posture-overview); this page is
the shape of the map, not the table.

***

## 3. Worked flow: new campaign to US +1 recipients

Walk the gates a send traverses, in the order the send walks them. A
U.S. (+1) SMS campaign with consent shown in the list:

1. **Country rules.** The destination resolves against your outbound
   country allowlist — unset, it is fail-open; once set, an off-list
   destination rejects `422 COUNTRY_NOT_ALLOWED`. See
   [Fraud Shield](/compliance/fraud-shield).
2. **Registration.** For US long-code traffic, the 10DLC brand and
   campaign registration gates before delivery; toll-free verification is
   the toll-free analog. See
   [Sender-ID Registration](/compliance/sender-id-registration).
3. **Quiet-hours resolution.** If you enabled the channel on the org gate
   with a window, the contact's timezone resolves; unresolved (or non-US)
   recipients pass under your configured skip policy —
   [Quiet hours configuration](/guides/quiet-hours-configuration).
4. **DNC.** If the scrub is on, the number checks the synced federal list;
   with no snapshot it returns `403 DNC_SYNC_NOT_ENABLED`. See
   [DNC Scrubbing](/compliance/dnc-scrub).
5. **RND.** If the scrub is on, the Reassigned Numbers verdict backs the
   safe-harbor read; unenabled, verdicts degrade to `no_data`. See
   [Send Gates](/compliance/send-gates).
6. **Suppression scope.** Phone suppression entries — entered from STOP,
   the Consent API, the preference center, or import — drop the send
   before dispatch; scope `all` gates voice and dialer too. See
   [Opt-Out & Suppression Lists](/compliance/opt-out-suppression).
7. **Wallet / frequency.** The org's outbound pause flags and your
   per-contact frequency caps admit or gate the send. See
   [Wallets, credits, and charges](/concepts/wallets-credits-and-charges)
   and [Frequency caps](/guides/frequency-caps).

Voice campaigns add the layer above all of this: the TCPA federal window
(Plane A) sits before the tenant gates, and an unresolved US recipient
timezone blocks fail-closed. The full chain is in
[Send Gates](/compliance/send-gates).

***

## 4. Where the evidence lands

Three stores produce audit evidence; a quarterly review samples a
different slice from each.

### Evidence binder

The [evidence binder](/compliance/evidence-binder) rolls your audit chain
into a framework-mapped pack (SOC 2, ISO 27001, GDPR, HIPAA) with one
download to hand to an auditor. A review samples: the binder's own
generation history and the sections the framework's controls cover —
consent-posture evidence, access reviews, retention posture, breach
counts.

### Audit log

Every tenant-owned write — a toggle flip on Plane B, a suppression import,
a posture justification — lands in the org audit log with its actor,
timestamp, and old/new values. A review samples: a slice of the toggle
flips since the last review, checking each one had an owner and a
justification. The unknown-consent and posture-FAQ pages note which
writes demand a recorded lawful basis.

### Compliance-health snapshot

[Compliance Health Scores](/compliance/compliance-health) blend consent
coverage, opt-out velocity, STOP-reply rate, and carrier rejections into
a 0–100 score per organization, sender, and campaign. A review samples:
the organization score over the quarter's window and the worst rows on
the sender table — the early-warning read, never a blocker.

The rule of thumb: the binder is your external artifact, the audit log is
your internal trail, and the health snapshot is your early-warning
signal. Sample all three; any one alone misses part of the posture.

***

## 5. Guardrail: no platform-mandated bars

Apart from the two federal asymmetries in Plane A, **no platform mandate
sits on top of your posture.** The default-open / fail-open model means
the platform never decides that a send is compliant on your behalf — it
enforces what you set and keeps the ledger.

This is the framing that keeps a posture readable:

* **What stays tenant-owned, by design.** Apart from the named Plane A
  rails, every gate in the compliance group is yours to flip from an open
  default. The [Posture FAQ](/compliance/posture-faq) says this plainly:
  a short, deliberate asymmetry list, and everything else tenant-owned.
* **The asymmetry list is short on purpose.** The two rails above — the
  TCPA federal voice window and the emergency-routing rail — are the
  complete set. No fourth bar exists; the absence of more defaults-open
  exceptions is the posture model's point.

That split is what makes the map above usable: **verify the two rails,
sample the tenant gates, and rely on the hygiene chain.** A review that
samples anything else is sampling the wrong plane.

***

## Related references

* [Your Tenant Compliance Posture: The Toggle Map](/compliance/posture-overview) —
  the live inventory of every switch; this page is the narrative
  underneath that inventory.
* [Compliance Health Scores](/compliance/compliance-health) — the
  early-warning snapshot a quarterly review samples.
* [Compliance evidence binder](/compliance/evidence-binder) — the
  framework-mapped pack a review hands to an auditor.
* [Send Gates](/compliance/send-gates) — the full gate chain this map
  traverses.
* [Posture FAQ](/compliance/posture-faq) — the operator questions behind
  the planes, including the no-platform-mandate framing.
