Run a quarterly compliance posture review
Your posture was set deliberately once — at launch, market by market, through the first-run configuration guide. This runbook is the recurring half of that discipline: a four-check quarterly review that re-verifies the per-control surfaces after a quarter of traffic, and closes with evidence. It assumes the controls are set; it asks whether they are still set correctly.Every control re-verified here is tenant-owned. Orbit provides the
surfaces and defaults them open; you configure them and you own the
posture. This page is an operational runbook, not legal advice —
confirm which obligations apply to your traffic with counsel.
Why posture decays between audits
Compliance configuration behaves like a garden, not a vault. The toggles you set at launch are point-in-time decisions, and four forces move them without touching a toggle:- Traffic drift. You launched with one SMS campaign; by Q3 you run WhatsApp, a dialer, and a reactivation flow a teammate added. A 12,000-recipient import quietly lowers consent coverage from 98% to 81% — and the first place that registers is not a carrier throttle, it is your compliance-health score.
- Jurisdiction drift. A US SMS program expands to Brazil (LGPD, a 15-day DSAR clock) and the UK. Each market re-asks the consent, disclosure, and announcement questions you last answered at launch.
- Consent staleness. Captured consent ages — the
valid_untilon a receipt expires, theconsent_text_versionon an old CSV import no longer matches the policy page a new contact actually saw, and a proof URL nobody archived is a proof you cannot produce. - DSAR pipeline decay. An intake portal nobody filed through, an OTP sender no one configured, an export link that expired before anyone downloaded it. The time to find a broken fulfilment path is a drill, not a live request with a statutory clock running.
The quarterly cadence — four checks
An hour-ish per quarter for a single-market tenant; wider portfolios budget proportionally. Run the checks in order — each one narrows the next.Check 1 — Read the health score (15 minutes)
Open the compliance-health score per organization, sender, and campaign, with the window set to the quarter. The score blends four signals — consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections — and none of them gates a send; a low score is advisory until you act on it. That is the point of the review: it is the early-warning read before a carrier throttle or a rejection spike becomes the message. Flag for Check 2:consent_coveragesliding fromoktowardwarnwhile volume grows — a list import or capture path that never wrote consent records.- Opt-out velocity climbing on a specific sender or campaign — wording, frequency, or audience drift worth fixing before the carrier notices.
Check 2 — Re-verify consent and channel coverage (30 minutes)
The correct-at-launch pairing decays in specific, checkable places. Work down the list against the markets and channels you actually ran this quarter:- Consent records and receipts — confirm capture points still write consent on every collection path, and that the channel mix you now run is covered by the records you hold. For HIPAA-adjacent audiences, confirm the BAA is signed and current. Reference: Consent Management & Receipts.
- Recording announcement coverage — list the jurisdictions you placed or received calls in this quarter (call logs group by destination), then compare the announcement pairing saved in Voice → Calls → Recording settings —
settings.recording.{eligibility_mode, consent_announcement_mode}— against the strictest of them. Dialing into an all-party-consent jurisdiction withannounce_callerset, or auto-recording withconsent_announcement_mode: none(an in-app warning Orbit surfaces — this check is where a dismissed warning gets caught), is exactly the drift this audit exists to find. Reference: Call Recording Consent. - Time-window gates — re-read your quiet hours per channel against current sending patterns, and the US state calling windows against the states you actually dialed. A seasonal override set for one campaign and never lifted is a six-month posture change nobody decided on.
- STIR/SHAKEN attestation — review the per-number attestation posture of your outbound voice in Attestation posture, not only at onboarding. Numbers provisioned mid-quarter inherit posture separately.
- Suppression enforcement — confirm opt-out suppression is still enforced, end to end, by running a pre-send check on a sample known-suppressed contact and watching it hold. Reference: Opt-Out & Suppression Lists.
Check 3 — Exercise the DSAR pipeline (15 minutes)
The failure this check catches is not a late request — it is a pipeline you never exercised, discovered live. Once a quarter, against the DSAR surface:- File one request against your own contact record — the fire drill. Verify it enters the operator queue alongside real traffic and that the portal path (or operator intake) marks verification the way you expect.
- Read the SLA snapshot. Per-request
days_remainingand severity tier are scaled to each jurisdiction’s deadline — GDPR 30 days, CCPA/CPRA 45, LGPD 15. Anything breached, or anapproachingcount that keeps growing, is a staffing problem surfacing a quarter early. - Download one export. Signed export links expire — open one, confirm the file contains what you would actually hand a data subject, and confirm your team knows where the row counts per table are described.
- Re-set the jurisdiction mix at intake. If you launched GDPR-only and now market into California or Brazil, requests arriving under the wrong
applicable_jurisdictiongrade against the wrong clock. Intake accuracy is part of the review.
Check 4 — Close with evidence (10 minutes)
End the quarter provable, not just done:- Archive the quarter’s consent and suppression exports — both of them, at
status=allso revoked rows are preserved and the file proves re-permissioning, not just the active blocklist. - Generate a binder — Settings → Compliance → Binder, pick the framework your auditor or buyer asks for (SOC 2 for procurement, GDPR for the privacy file), and the format. The walkthrough is in Assemble and seal an evidence binder; the framework tables in the binder reference. A quarterly generation builds the habit and a comparable archive: two generations over the same data are byte-identical and carry a SHA-256 checksum, so quarter-over-quarter diffs are mechanical and a tamper-flagged generation surfaces while there is still time to investigate.
Override file + sign-off
Overrides are legitimate posture — a seasonal window lift, a manual-only recording designation, a dialer exemption — as long as someone can name its expiry. Keep them out of memory and in one file; the review then costs minutes.- Health score reviewed per org, sender, and campaign; findings logged
- Overrides above re-confirmed or reverted
- Consent coverage confirmed for every capture path and channel in use
- Recording
eligibility_mode×consent_announcement_modepairing confirmed against the quarter’s actual call destinations - Quiet hours and state calling windows confirmed against actual traffic
- Attestation posture reviewed on numbers provisioned this quarter
- Suppression enforcement verified on a known-suppressed sample contact
- DSAR fire drill filed, SLA snapshot clean, one export downloaded
- Consent and suppression exports archived for the quarter
- Binder generated and checksum recorded
Related
- Compliance posture overview — the per-control surfaces this cadence re-verifies
- First-run tenant posture — the launch-time counterpart; run it once per market, run this review every quarter
- Assemble and seal an evidence binder — the binder walkthrough, incl. gated-surface verdicts
- Compliance posture FAQ — the tenant-owned-controls mental model