The announcement post covered what the four vertical compliance packs are. This one is about the checklist they hand back — the sequence you actually walk between activating a pack and sending your first message, and which steps on it are automatic versus yours to complete. If you already activated a pack and the go-live list is sitting in your dashboard, this is the map for it.
What one activation returns
Activation is a single request from the pack's page under Settings → Compliance → Vertical Compliance Bundles. The response is the current state of everything it created, and the checklist travels inside that response. You get back the identifier of the draft compliance profile, the draft campaign rows it created, the agent identifier, the opt-in configuration, and the checklist itself — each step ordered, flagged as automatic or manual, and carrying a status of pending or done.
Automatic steps are the provisioning work: the pack completed them during the one call, and they arrive already marked done. Manual steps are the ones that remain — a human in your organization must act on them before go-live, and they stay pending until someone toggles them.
The reopen path matters in practice: if an earlier session activated a pack, the resume list on the bundles page reads your compliance profiles and shows every past activation with its current step count. Reopening does not re-provision anything — it pulls the recorded state straight back up, so the list survives reloads, browser refreshes, and handoffs between the compliance lead and the operator.
The order of the steps
The checklist order is not decorative. The draft profile is provisioned as a draft explicitly so that the review steps that follow have something to review; and sending stays blocked behind the same verification gates a hand-built setup would face until the profile passes review. Every pack appends the same five-step tail, and between activation and that tail each pack inserts one step of its own:
- Attach the required compliance documents — the business-registration and authorization documents the profile's use case requires.
- Submit the profile for verification — this starts the provider review; sending stays blocked until it is approved.
- Review the opt-in confirmation copy — confirm the seeded message names your brand and names the right help contact.
- Confirm the quiet-hours window — preview the dispatch window so sends land inside the allowed local hours for your recipients.
- Clear the pack's own step — the one entry that differs per vertical (below).
- Review and approve the campaign copy — read the seeded drafts, approve the wording, then schedule.
Why the shared steps are yours to clear
Opt-in confirmation copy, quiet-hours, and campaign wording are all settings under your control — the platform deliberately does not take that control away. A checklist step that looks like housekeeping is actually a consent question: does the confirmation message say what your brand promised at sign-up, does the dispatch window respect your recipients' local hours, does the draft copy say what you intend to send. Treating the list as a settings pass, not a compliance mandate, is the correct posture — and it is why the steps toggle independently instead of gating on one approve-all action. The shared tail exists so the pass is the same shape on every pack; the one step that changes per vertical is below.
The per-pack step
Healthcare (HIPAA-conscious patient messaging). The healthcare pack adds Sign a Business Associate Agreement (BAA) before the review steps. The BAA workflow lives under Compliance → BAA in the dashboard, and the checklist points at it because a BAA is the document a covered entity needs in place before patient messaging starts — the seeded appointment-reminder, refill, and follow-up drafts are written to keep PHI out of plain SMS, but the agreement step is the one no template can complete for you.
Fintech (KYC onboarding & account alerts). The fintech pack adds Confirm transactional vs marketing consent split. Its five drafts mix security and transaction alerts with onboarding messages, and the split matters: account and security alerts are transactional, while anything promotional requires explicit marketing consent. The step asks you to confirm your consent categories are mapped correctly before the onboarding or promotional copy goes out — a mapping you own, because only you know how your sign-up flow scopes consent.
E-commerce (order lifecycle & re-engagement). The e-commerce pack adds Separate marketing consent from order updates. Order confirmations and shipping updates are transactional and do not need marketing consent; the promotional offer draft does. The step exists so promotional sends only target contacts who opted in to marketing — the same consent-split discipline as the fintech step, focused where a store's traffic actually concentrates.
Payments & Collections (PCI-safe payment collection). The payments pack adds Confirm your hosted payment page is PCI-compliant. Every seeded draft sends a hosted payment link instead of collecting card details in the message, and the AI billing assistant is instructed to redirect anyone who pastes card numbers to the secure link. The checklist step asks you to confirm that the link target — your processor's hosted checkout — actually meets PCI-DSS, so a full card number, CVV, or expiry never travels over SMS or chat. What the payment link points at is your integration choice, so this one is also yours to clear.
None of these four steps is a platform mandate. They are your own settings and agreements, surfaced in a fixed order so nothing falls off the table between activation and launch.
Good-check / bad-check: what the toggle is for
Each manual step carries a simple contract: pending until a human clears it, done after. That contract is what makes the list useful as a shared runbook — a compliance lead can clear the BAA or the consent mapping while an operator clears the copy review, and both see the same live progress. A step marked done is the record that someone in your organization confirmed it; a step marked pending is the honest remainder. If a step is done but the underlying work was not — say the payment link routes to an unreviewed checkout page — the correct move is to toggle it back to pending, not to leave the badge green. The checklist is a record of your own decisions, and it stays accurate only if the toggles are.
Frequently asked questions
Does activating the pack send anything, or file anything with a carrier?
No. Activation creates drafts only: a draft compliance profile, draft campaigns, an opt-in flow configuration, and an agent row. Nothing is scheduled, submitted, or transmitted, and sending stays blocked until the profile passes verification — the same gates a hand-built setup faces.
What happens if I clear every manual step — is there a final approval?
No final gate. The checklist is your own record; the last manual step (approving campaign copy) is the last thing standing between the drafts and a scheduled send. Once the profile passes review and your steps are done, the campaigns are ready to schedule from the campaign pages.
Can two people work the same checklist?
Yes. Any activation already created appears in the resume list with its live step count, so the person who activated and the person who clears the remaining steps see the same list without re-activating anything.
Are the seeded campaign texts fixed, or can I rewrite them?
The seeded copy is a starting point. Review-and-approve means exactly that — edit the drafts until the wording is what you intend to send, then mark the copy-review step done.
Do the four per-pack steps differ in kind, or only in wording?
They differ in kind. Healthcare's step is a document (a BAA), fintech's and e-commerce's are a consent mapping, and payments' is an integration target (the hosted checkout). The reason each pack has its own step is that the one thing no template can finish is different per vertical — the shared tail is what every vertical has in common.