> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Assemble your tenant's compliance posture

> How compliance profiles, country rules, and vertical packs compose into one posture — which surfaces each profile opens, and the day-one order to activate them in.

# Assemble your tenant's compliance posture

Compliance in Orbit is not one switch — it is a set of small posture
surfaces that compose: **compliance profiles** (identity and business
verification for carriers and regulators), **country rules** (per-market
requirements a profile satisfies), and **vertical packs** (pre-wired
profiles + working copy for a traffic family). This page is the assembly
guide: what each piece does, which console surfaces it opens, how to
compose them, and the order to activate them on day one.

<Note>
  Posture is tenant-owned. Orbit gives you the control surface and
  defaults it open; you choose the posture, you file the registrations,
  and the go-live decision stays yours. See
  [Your Tenant Compliance Posture](/compliance/posture-overview).
</Note>

***

## The three ingredients

A posture is assembled from three kinds of building blocks. Each deep page
documents one block; this page orders them.

### 1. Compliance profiles — identity carriers trust

A **compliance profile** is a named, reusable packet of verified identity
and business data: legal entity, address, contact, and the documents that
prove them. You create one per use case and country, submit it, and reuse
it across every asset that asks for it — so a phone-number purchase, a
Sender-ID registration, and a brand verification never re-ask for the same
paperwork.

Console path: **Settings → Compliance → Profiles**.

Profiles follow a review lifecycle: `draft → pending_review → approved`
(or `rejected` / `partially_rejected`; `expired` when a carrier's validity
window lapses). Only an `approved` profile opens the gated surfaces
below. The full endpoint surface — create, edit, submit, resync, clone —
is documented in
[Compliance profiles API](/api-reference/endpoints/compliance).

### 2. Country rules — what each market demands

Every regulated destination declares what it requires: which use cases
need a profile, which documents, which sender types are allowed. The rules
are the checklist a profile is graded against — a US 10DLC brand
registration, a UK alphanumeric sender, a voice-carrier KYC entry each
name their own packet.

Read the per-country requirements before you create the profile:
[Country Compliance Requirements](/compliance/country-requirements).

### 3. Vertical packs — pre-wired profiles for a traffic family

A **vertical pack** is a shipped configuration for a named traffic family
(Payments & Collections, Healthcare, E-commerce, Fintech, and similar).
Each pack pre-wires: the compliance profile shape, working campaign copy
drafts, an opt-in flow, and a go-live checklist — so switching on a
vertical is a guided run instead of a blank form. A pack still submits the
profile for review itself; nothing sends until its checklist clears.

Console path: **Settings → Compliance → Vertical bundles**. Catalog,
preview, activation, and checklist endpoints are in
[Vertical Compliance Bundles](/compliance/vertical-bundles).

***

## Which surfaces open when a profile is approved

An approved profile is the key that opens a specific gated surface.
Until the right profile type clears review, the surface idles in a
pending state; once it clears, the surface becomes usable. Map the use
case to the console it feeds:

| Profile use case                               | Console surface it opens                                                                          | Pending gate                                    |
| ---------------------------------------------- | ------------------------------------------------------------------------------------------------- | ----------------------------------------------- |
| `phone_number_purchase`                        | **Numbers** — buy or port numbers into regulated markets                                          | Number idles at `pending_compliance`            |
| `sms_sender_id_alphanumeric`                   | **Settings → Compliance → Sender IDs** — alphanumeric senders in countries requiring registration | Country entry idles at `pending`                |
| `sms_10dlc_brand_us` / `sms_10dlc_campaign_us` | **Brand identity & trust** (Settings → Compliance → Brand identity) — US 10DLC brand + campaign   | Traffic degrades until brand + campaign approve |
| `sms_tfv_us`                                   | Toll-free SMS verification (US)                                                                   | Toll-free traffic blocked until verified        |
| `whatsapp_business_verification`               | **Channels → WhatsApp** — verified business display name                                          | Business name stays unverified                  |
| `rcs_brand_verification`                       | **Channels → RCS** — verified sender badge                                                        | RCS sends blocked until verified                |
| `email_domain_verification`                    | **Settings → Email** — verified sending domain                                                    | Domain sending blocked until verified           |
| `voice_carrier_kyc`                            | **Numbers / SIP trunks** — carrier KYC for voice origination                                      | Voice trunk idles pending KYC                   |

Two surfaces sit underneath the profiles and do not gate themselves:
**Country rules** is the checklist a profile is graded against (read it
before you create), and **Documents** (Settings → Compliance → Documents)
holds the uploaded identity files a profile references.

The pending-gate column uses the same statuses as
[Troubleshoot a pending number or Sender ID](/compliance/troubleshooting-pending-gated-surfaces) —
diagnose a stuck gate there.

***

## Compose: profiles × country rules × vertical packs

The three ingredients compose in one direction: pick the pack (or create
the profile directly), fill it against the country's checklist, submit,
and the gated surface opens when review approves.

| Your traffic family                                                          | First block to reach for                                                                                                        |
| ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
| Payments & Collections / Healthcare / E-commerce / Fintech (shipped catalog) | Activate the matching vertical pack — it pre-wires the profile shape and working copy                                           |
| Custom or unlisted family                                                    | Create a compliance profile directly (`other` use case if none of the labeled ones fit)                                         |
| Regulated destination country                                                | Read [Country Compliance Requirements](/compliance/country-requirements) first; the country rule names the exact packet to file |
| Several regulated markets at once                                            | Register per country — a profile is scoped to one use case + country, and assets reuse the approved one                         |

***

## Day-one activation order

Work this checklist in order the first time you assemble a posture; every
step names the console surface it runs on.

1. **Read your destination's country rules** — before you file anything,
   [Country Compliance Requirements](/compliance/country-requirements)
   tells you the exact packet the country demands.
2. **Create a compliance profile** (Settings → Compliance → Profiles) — or
   activate a matching vertical pack, which pre-wires the profile shape.
   Keep it `draft` until the data is complete.
3. **Submit for review** — the profile moves to `pending_review`; carrier
   review windows start now.
4. **Wire the gated surface** — once the profile approves, associate it
   with the surface that needs it (a number purchase, a Sender ID entry,
   a brand verification).
5. **Monitor renewals** — the Profiles list shows SLA and renewal hints so
   an expiring profile never silently locks its surface.

Start with one use case and one country; add more only when the first
approval returns.

***

## When a surface stays gated

A pending gate always traces back to one of the three ingredients: the
profile is still in review, the country's packet was not what the carrier
asked for, or a pack's go-live checklist has not cleared. The full
diagnosis walkthrough is
[Troubleshoot a pending number or Sender ID](/compliance/troubleshooting-pending-gated-surfaces) —
numbers stuck at `pending_compliance`, Sender IDs stuck at `pending`,
rejection reasons, and the re-submission path.

The [Posture FAQ](/compliance/posture-faq) answers the adjacent questions:
which surfaces fail open versus closed, and which approvals carry external
lead time.

***

## Related references

* [Your Tenant Compliance Posture: The Toggle Map](/compliance/posture-overview) — the full map of tenant-owned controls this assembly plugs into.
* [Vertical Compliance Bundles](/compliance/vertical-bundles) — the pack catalog, activation flow, and API surface.
* [Country Compliance Requirements](/compliance/country-requirements) — per-market packet demands.
* [Troubleshoot a pending number or Sender ID](/compliance/troubleshooting-pending-gated-surfaces) — de-gating diagnostics.
* [API Reference → Compliance](/api-reference/endpoints/compliance) — the compliance-profiles endpoint schemas.
