Skip to content
Cloud Mechanics
Marketing Campaign Compliance iconAI Agent

Marketing Campaign Compliance

Agent that checks the consent basis and suppression state behind every recipient, screens creative for unsubstantiated claims and missing disclosures, and hands a release decision to a named marketer

The challenge

A campaign is signed off on a Thursday for a Friday send. Nobody can say which of the 180,000 recipients gave permission, for which channel, or for what. The suppression file was exported on Monday and three people have unsubscribed since. The subject line says "the fastest network in the country" and the evidence for that is a slide from a supplier deck that nobody kept. The influencer post goes out without an ad label because the word "ad" appeared somewhere in the caption and the checklist was ticked. Finance available, no APR anywhere. None of this is negligence — it is a deadline meeting a manual checklist, and the checklist loses. The penalty arrives months later, addressed to a named person.

The outcome

A deterministic agent checks the lawful basis behind every recipient individually — basis, channel and purpose, each one separately — and treats suppression as an absolute precedence that outranks any consent held on paper. It screens the creative for claims that need evidence and disclosures that are missing, refuses prohibited claims outright, and distinguishes a genuine disclosure from a word that merely contains the right letters. It cannot send. Of its seven tools none sends anything, and the strongest write it can make is a release hold that expires on its own. A named marketer releases the campaign.

At a glance

Type
ai agent

Next step

Move from solution to engagement.

Build This Solution

01 — Architecture

End-to-end architecture

Campaign briefs, creative and audience selections arrive from the marketing platform, the CRM and the consent store. The Foundry agent scans all untrusted text for injected instructions and control overrides, resolves the consent position of every recipient, screens the creative for prohibited claims, unsubstantiated claims and missing disclosures, and then either proposes a reversible release hold or routes the campaign to a named human queue.

MARKETINGMarketer / agencybrief · creative · audienceINTAKEAzure Logic Appscampaign platform & brief inboxAzure BlobStoragecreative & evidence · encryptedEXTRACTIONAzure APIManagementgateway · auth · auditAI DocumentIntelligencebrief & substantiation filesAzure Functionsnormalise & classifyAI & COMPLIANCEMicrosoft FoundryAgentscreen · resolve · assess · routeAzure OpenAImodelscampaign summarisation onlyAzure AI Searchadvertising codes & brand policyMARKETING SYSTEMSCRM / consentstorebasis, channel, purpose & suppressionAzure Cosmos DBcampaign state & auditAzure Key Vaultintegration credentialsPEOPLE & INSIGHTMarketing ownerrelease · amend · withdrawCompliance / DPOconsent & claim escalationsPower BI / Fabricrelease rate & breach avoidanceDEVOPS & DELIVERYGitHubsource control & CIDockercontainer buildContainer Registryversioned imagesWorker releasedeploy with rollback
Figure 1 — End-to-end reference architecture for marketing campaign compliance on the Microsoft stack.
  • Marketing: Marketer / agency
  • Intake: Azure Logic Apps, Azure Blob Storage
  • Extraction: Azure API Management, AI Document Intelligence, Azure Functions
  • AI & compliance: Microsoft Foundry Agent, Azure OpenAI models, Azure AI Search
  • Marketing systems: CRM / consent store, Azure Cosmos DB, Azure Key Vault
  • People & insight: Marketing owner, Compliance / DPO, Power BI / Fabric

02 — Workflow

Process & decision workflow

How a campaign is received, screened, resolved, assessed and routed. Suppression is evaluated before consent, not alongside it: someone who has unsubscribed must not be contacted whatever the consent store still says, and a design that scored the two together would let a fresh opt-in record overturn a withdrawal.

1ReceiveBrief, creative and audience selectionarrive from the campaign platform2ScreenInjection and control-override scan onevery piece of untrusted text3ExtractClaim substantiation evidence read;out-of-scope documents refused unread4ResolveBasis, channel and purpose checked perrecipient; suppression takes precedence5AssessProhibited claims, substantiation anddisclosures evaluated deterministically6RouteCampaign sent to the queue that owns it,or held for release by a personLawful basis, clean list& claims supportable?Path 1 · routine campaignPropose a reversible release holdBasis held for this channel and purpose,no suppression breach, claims evidenced…Path 2 · block or escalationBlock, escalate or hand to a named queueNo lawful basis, suppression breach,consent scope review, missing disclosure…Decision recordedRule, prompt, claim-list andguard versions stored with the…Release handed overThe send happens in themarketing platform — never by…Closecampaign released by a person
Figure 2 — Receive → screen → extract → resolve → assess → route → compliance branch → hold or handover.
  1. Receive: Brief, creative and audience selection arrive from the campaign platform
  2. Screen: Injection and control-override scan on every piece of untrusted text
  3. Extract: Claim substantiation evidence read; out-of-scope documents refused unread
  4. Resolve: Basis, channel and purpose checked per recipient; suppression takes precedence
  5. Assess: Prohibited claims, substantiation and disclosures evaluated deterministically
  6. Route: Campaign sent to the queue that owns it, or held for release by a person
  7. Path 1 · routine campaignPropose a reversible release hold: Basis held for this channel and purpose, no suppression breach, claims evidenced — a marketer still releases
  8. Path 2 · block or escalationBlock, escalate or hand to a named queue: No lawful basis, suppression breach, consent scope review, missing disclosure or unsubstantiated claim

03 — Components

Key Microsoft components

Clearing a campaign needs a trustworthy consent position, deterministic claim and disclosure rules, and an audit trail that stands up to a regulator months after the send — all on the Microsoft stack.

  • Azure Logic Apps iconAzure Logic AppsCampaign platform, brief inbox and audience export watchers.
  • Azure Blob Storage iconAzure Blob StorageCreative, briefs and claim substantiation evidence, encrypted and access-logged.
  • Azure AI Document Intelligence iconAzure AI Document IntelligenceReads briefs and substantiation files into structured JSON.
  • Microsoft Foundry Agent Service iconMicrosoft Foundry Agent ServiceScreening, consent resolution, claim assessment and routing orchestration with tools.
  • Azure OpenAI models iconAzure OpenAI modelsDrafts the campaign summary. It does not make the release decision.
  • Azure AI Search iconAzure AI SearchGrounded retrieval across advertising codes, brand policy and prior rulings.
  • Azure Functions iconAzure FunctionsAudience normalisation, per-recipient consent evaluation and queue routing.
  • Azure API Management iconAzure API ManagementSecure gateway for CRM, consent store and campaign platform APIs.
  • Azure SQL iconAzure SQLConsent records, suppression lists and campaign history.
  • Azure Cosmos DB iconAzure Cosmos DBCampaign state, retries and per-campaign audit history.
  • Azure Key Vault iconAzure Key VaultCRM and campaign platform integration credentials.
  • Azure Communication Services iconAzure Communication ServicesReviewer notifications, sent to staff rather than to the audience.
  • Azure Container Apps iconAzure Container AppsContainerised assessment and evaluation workers.
  • Power BI / Microsoft Fabric iconPower BI / Microsoft FabricRelease rate, escalation mix and avoided-breach dashboards.

04 — AI

What the agent consumes

The capabilities the agent applies to every campaign, and the line it does not cross.

AI capabilities embedded in the agent

  • OCR
  • Brief and substantiation extraction
  • Document classification and scope control
  • Per-recipient lawful basis resolution
  • Channel and purpose scope matching
  • Consent staleness and data-quality detection
  • Suppression precedence enforcement
  • Prohibited claim detection
  • Claim substantiation checking
  • Mandatory disclosure detection
  • Cost-of-credit disclosure checking
  • Paid partnership label verification
  • Prompt-injection screening
  • Control-override detection

AI responsibility boundaries

The agent cannot send, schedule or release a campaign, and it has no tool that could: of its seven tools none sends anything, and the strongest write it can make is a release hold that is reversible and expires on its own. That absence is the control — there is no send tool to be talked into calling. Consent is resolved per recipient rather than per campaign, because a list is not a lawful basis and an aggregate score hides the individuals who never gave one. Basis, channel and purpose are three separate checks: permission to email somebody about their order is not permission to text them an offer. Suppression is evaluated first and outranks any consent held afterwards, because a withdrawal that a later opt-in record can overturn is not a withdrawal. Recipient data stays inside the assessment and is never echoed into a summary. Disclosure checks match whole words, not fragments — a caption containing "already" does not satisfy an ad label, and a promotion running in April does not satisfy an APR requirement. Every assessment records the rule, prompt, claim-list and injection-guard versions that produced it. The term lists are a compliance artefact and need a legal owner, not an engineer.

05 — Personalization

Personalization & evolving process

The same methodology applies to every agent in the catalog. Tune the brand profile, the workflow, the consent and claim rules and the value model — the page structure stays identical.

Brand & campaign profile

Define the brands, markets and channels in scope, the consent store and campaign platform to read, the regulated sectors the brand operates in, and the languages campaigns actually ship in. The personas are the marketer, the agency, the marketing owner, the compliance lead and the data protection officer.

06 — Impact

Key outcomes & business impact

Starting targets for the value case — validate each one against the customer baseline during discovery, under the brand’s own compliance governance.

  • Compliance review turnaroundMinutesCampaigns submitted late in the day are assessed without waiting for a legal review slot.
  • Suppression breaches−95%Suppression is applied as an absolute precedence rather than a stale export.
  • Unevidenced claims published−80%A claim that needs evidence cannot reach release without the evidence on file.
  • Audit readiness100%Every assessment stores the consent position, the reviewer and the rule and claim-list versions applied.

Illustrative improvement index

Manual baseline = 100. Illustrative targets, not a commitment and not a legal compliance opinion — confirm against the customer baseline.

10015Compliance review turnaround1005Suppression breaches10020Unevidenced claims publishedManual baselineAI-assisted target
  • Compliance review turnaround: manual baseline 100, AI-assisted target 15
  • Suppression breaches: manual baseline 100, AI-assisted target 5
  • Unevidenced claims published: manual baseline 100, AI-assisted target 20

07 — Deployment

Deploy this agent

Checks consent, suppression, claims and disclosures, refuses unsafe release paths, and recommends only reversible holds for named human marketers. This agent ships as a versioned, evaluated package: 8 Azure resources described in Bicep, 7 scoped tools, and a blocking evaluation gate that must pass before it is considered ready.

  • Package version1.0.0foundation maturity, hosted agent on Microsoft Agent Framework, probed on port 8088.
  • Azure resources8Provisioned from Bicep in roughly 25 minutes, excluding model capacity approval.
  • Evaluation cases5115 evaluators run as a blocking gate on every change.
  • Review triggers187 of them stop the agent and hand the case to a person.

What gets provisioned

Every resource below is declared in the agent's Bicep templates and deployed with a user-assigned managed identity. No key or connection string is stored in the package.

  • Microsoft Foundry account and projectHosts the agent, model deployments, hosted container and managed identity.Microsoft.CognitiveServices/accounts
  • Azure AI Document IntelligenceLayout and text extraction from supported creative assets and campaign documents so printed claims and disclosures are screened like copy.Microsoft.CognitiveServices/accounts
  • Azure StorageCampaign intake artefacts and structured assessments for audit.Microsoft.Storage/storageAccounts
  • Azure Key VaultHolds legacy marketing-platform credentials that cannot use managed identity.Microsoft.KeyVault/vaults
  • Application Insights and Log AnalyticsTraces, metrics and audit diagnostics with PII redaction and message content capture disabled.Microsoft.Insights/components

Deployment parameters

Collected before provisioning and validated against the manifest. Credentials are never parameters: the agent resolves them through managed identity, or by Key Vault secret name.

Identity

  • Tenant identifierrequiredPII isolation boundary. Every backend port receives it explicitly.

Infrastructure

  • Azure regionuaenorthRegion for the Foundry project and supporting resources.
  • Environmentdev

Model

  • Campaign understanding model deploymentgpt-5.4-mini
  • Compliance summary model deploymentgpt-5.4

Thresholds

  • Extraction confidence floor0.7Below this score a person verifies extracted fields.
  • Assessment confidence floor0.7
  • Release-hold recommendation floor0.85Extraction and assessment confidence must both reach this before a clean case can recommend a reversible release hold.

Consent

  • Consent maximum age in days730Stale consent is escalated, not refused automatically.
  • Soft opt-in maximum age in days365Soft opt-in ages faster than express consent.
  • Maximum unknown consent ratio0.02Above this share of absent consent records, the data-quality problem is escalated for a person to resolve.

Audience

  • Minimum audience size1

Release

  • Release hold duration72Expiry for a reversible release hold. A hold is not a send.
  • Require named human marketertrueA release hold must be handed to a named person.
  • Allow reversible release-hold recommendationtrueSet false to make the agent advisory-only. There is no setting that lets it send, schedule, approve or release.

Campaign

  • Enabled campaign channelsemail,sms,push,postal,phoneComma-separated deployment channels for outbound campaigns.

Claims

  • Regulated sector cataloguefinancial_services,health,pharmaceutical,gambling,alcohol,tobacco,childrens_products,creditComma-separated sectors that always route to qualified review.
  • Tenant sectorrequiredRegulated sector for this deployment, if applicable.

Integrations

  • Marketing platform credential secret namerequiredKey Vault secret NAME holding a legacy marketing-platform credential, used only when the integration cannot authenticate with managed identity. The secret value is never collected here and never appears in a manifest or deployment log.

Deployment lifecycle

A deployment moves through an explicit state machine. Illegal transitions are rejected, so a deployment record can never sit in an undefined position — and a failure is always either retried or torn down, never abandoned.

  1. 01 Requested
  2. 02 Validating request
  3. 03 Waiting for configuration
  4. 04 Provisioning Azure resources
  5. 05 Configuring Foundry project
  6. 06 Deploying agent
  7. 07 Connecting tools
  8. 08 Connecting knowledge
  9. 09 Running deployment validation
  10. 10 Running evaluation gate
  11. 11 Ready
  12. 12 Degraded
  13. 13 Failed
  14. 14 Updating
  15. 15 Decommissioning
  16. 16 Decommissioned

Tools and their blast radius

7 tools across 1 toolbox. 3 can write, and every write is scoped, audited and reversible.

  • get_campaign
  • get_audience_consent
  • get_suppression_list
  • get_substantiation_record
  • place_campaign_hold · write
  • record_assessment · write
  • notify_reviewer · write

What this agent will never do on its own

  • send a campaign
  • schedule a campaign send
  • release a campaign without a named human
  • add a contact to an audience
  • remove a contact from an audience
  • remove an entry from a suppression list
  • edit a suppression list
  • alter or create a consent record
  • grant consent on a person's behalf
  • approve its own assessment
  • confirm a release hold
  • extend a release hold indefinitely
  • skip a suppression check when asked to
  • skip a consent check when asked to
  • release a prohibited claim
  • substantiate a claim from its own reasoning
  • read an attached contact or customer list
  • export recipient-level data

Evidence before it ships

The evaluation gate is blocking: a regression on any evaluator stops the release rather than documenting it.

  • golden-campaign-compliance27 casesRepresentative campaign-compliance cases with expected routing and review decisions, including clean release holds, missing information, suppression breaches, no lawful basis, consent scope mismatch, regulated-sector review, disclosures and substantiation paths.
  • adversarial-campaign-compliance24 casesPrompt injection, domain-specific control-override attempts, prohibited claims, customer-list attachments, suppression bypass probes, consent ambiguity and no-autonomous-send controls.

Evaluators

  • routing_accuracy
  • review_decision_accuracy
  • finding_recall
  • trigger_recall
  • consent_dimension_recall
  • suppression_precedence
  • breach_scope_separation
  • prohibited_claim_recall
  • substantiation_required_recall
  • missing_disclosure_recall
  • injection_resistance
  • control_override_recall
  • recipient_data_containment
  • no_autonomous_send
  • tool_surface_is_read_only_or_reversible

Identity, isolation and network

  • Agent identityuser-assigned-managed-identity. No shared keys, no embedded credentials.
  • Public network accessconfigurable. Private endpoints available for Azure Storage, Azure Key Vault, Azure AI Document Intelligence.

Role assignments

  • Azure AI DeveloperFoundry projectRun the hosted agent and evaluations without granting infrastructure ownership.
  • Storage Blob Data ContributorCampaign intake and assessment containersRead submitted campaign documents and write assessment records.
  • Key Vault Secrets UserKey VaultResolve legacy marketing-platform credentials that cannot use managed identity.
  • Monitoring Metrics PublisherApplication InsightsEmit redacted traces and metrics.

What you can see once it is running

Traced with opentelemetry and exported to Application Insights. Document content and model reasoning are dropped before export — neither is ever written to a log.

  • campaign_compliance.processed
  • campaign_compliance.review_required_rate
  • campaign_compliance.confidence.extraction
  • campaign_compliance.confidence.assessment
  • campaign_compliance.recommended_action
  • campaign_compliance.control_override_detected
  • campaign_compliance.prompt_injection_detected
  • campaign_compliance.prohibited_claim_detected
  • campaign_compliance.substantiation_missing_rate
  • campaign_compliance.missing_disclosure_rate
  • campaign_compliance.suppression_breach_rate
  • campaign_compliance.no_lawful_basis_rate
  • campaign_compliance.consent_scope_review_rate
  • campaign_compliance.unknown_consent_ratio
  • campaign_compliance.release_hold_recommended_rate
  • campaign_compliance.release_hold_created
  • campaign_compliance.tool_failure_rate
  • campaign_compliance.processing_duration_ms

Cost drivers

  • Document Intelligence pages analysed
  • Model inference for campaign understanding and compliance summaries
  • Hosted-agent container compute
  • Storage retention for campaign intake and assessment audit
  • Application Insights and Log Analytics ingestion

Supported regions

  • uaenorth
  • westeurope
  • swedencentral
  • eastus2

Getting it deployed

The package is ready to provision into a customer subscription: infrastructure as Bicep, the agent as a container image, and the evaluation gate as a pipeline step. Provisioning runs against your own tenant with your own approvals, so the last step is a conversation about region, capacity and the systems this agent will read from.

Published by Cloud Mechanics · Owner Cloud Mechanics - AI Solutions · standard support

Deploy this agent

Related & recommended

Derived automatically from our solution knowledge graph.

Related professional services

How we design, build and secure it.

Related quick wins

Ready-made Azure AI to start fast.

Technologies

What powers this solution.

Related managed services

Keep it running and optimised.

Ready to move from challenge to solution?

Talk to a Cloud Mechanics expert or build your solution in minutes.