Marketing Campaign Compliance
Agent that checks the consent basis and suppression state behind every recipient, screens creative for unsubstantiated claims and missing disclosures, and hands a release decision to a named marketer
The challenge
A campaign is signed off on a Thursday for a Friday send. Nobody can say which of the 180,000 recipients gave permission, for which channel, or for what. The suppression file was exported on Monday and three people have unsubscribed since. The subject line says "the fastest network in the country" and the evidence for that is a slide from a supplier deck that nobody kept. The influencer post goes out without an ad label because the word "ad" appeared somewhere in the caption and the checklist was ticked. Finance available, no APR anywhere. None of this is negligence — it is a deadline meeting a manual checklist, and the checklist loses. The penalty arrives months later, addressed to a named person.
The outcome
A deterministic agent checks the lawful basis behind every recipient individually — basis, channel and purpose, each one separately — and treats suppression as an absolute precedence that outranks any consent held on paper. It screens the creative for claims that need evidence and disclosures that are missing, refuses prohibited claims outright, and distinguishes a genuine disclosure from a word that merely contains the right letters. It cannot send. Of its seven tools none sends anything, and the strongest write it can make is a release hold that expires on its own. A named marketer releases the campaign.
01 — Architecture
End-to-end architecture
Campaign briefs, creative and audience selections arrive from the marketing platform, the CRM and the consent store. The Foundry agent scans all untrusted text for injected instructions and control overrides, resolves the consent position of every recipient, screens the creative for prohibited claims, unsubstantiated claims and missing disclosures, and then either proposes a reversible release hold or routes the campaign to a named human queue.
- Marketing: Marketer / agency
- Intake: Azure Logic Apps, Azure Blob Storage
- Extraction: Azure API Management, AI Document Intelligence, Azure Functions
- AI & compliance: Microsoft Foundry Agent, Azure OpenAI models, Azure AI Search
- Marketing systems: CRM / consent store, Azure Cosmos DB, Azure Key Vault
- People & insight: Marketing owner, Compliance / DPO, Power BI / Fabric
02 — Workflow
Process & decision workflow
How a campaign is received, screened, resolved, assessed and routed. Suppression is evaluated before consent, not alongside it: someone who has unsubscribed must not be contacted whatever the consent store still says, and a design that scored the two together would let a fresh opt-in record overturn a withdrawal.
- Receive: Brief, creative and audience selection arrive from the campaign platform
- Screen: Injection and control-override scan on every piece of untrusted text
- Extract: Claim substantiation evidence read; out-of-scope documents refused unread
- Resolve: Basis, channel and purpose checked per recipient; suppression takes precedence
- Assess: Prohibited claims, substantiation and disclosures evaluated deterministically
- Route: Campaign sent to the queue that owns it, or held for release by a person
- Path 1 · routine campaign — Propose a reversible release hold: Basis held for this channel and purpose, no suppression breach, claims evidenced — a marketer still releases
- Path 2 · block or escalation — Block, escalate or hand to a named queue: No lawful basis, suppression breach, consent scope review, missing disclosure or unsubstantiated claim
03 — Components
Key Microsoft components
Clearing a campaign needs a trustworthy consent position, deterministic claim and disclosure rules, and an audit trail that stands up to a regulator months after the send — all on the Microsoft stack.
Azure Logic AppsCampaign platform, brief inbox and audience export watchers.
Azure Blob StorageCreative, briefs and claim substantiation evidence, encrypted and access-logged.
Azure AI Document IntelligenceReads briefs and substantiation files into structured JSON.
Microsoft Foundry Agent ServiceScreening, consent resolution, claim assessment and routing orchestration with tools.
Azure OpenAI modelsDrafts the campaign summary. It does not make the release decision.
Azure AI SearchGrounded retrieval across advertising codes, brand policy and prior rulings.
Azure FunctionsAudience normalisation, per-recipient consent evaluation and queue routing.
Azure API ManagementSecure gateway for CRM, consent store and campaign platform APIs.
Azure SQLConsent records, suppression lists and campaign history.
Azure Cosmos DBCampaign state, retries and per-campaign audit history.
Azure Key VaultCRM and campaign platform integration credentials.
Azure Communication ServicesReviewer notifications, sent to staff rather than to the audience.
Azure Container AppsContainerised assessment and evaluation workers.
Power BI / Microsoft FabricRelease rate, escalation mix and avoided-breach dashboards.
04 — AI
What the agent consumes
The capabilities the agent applies to every campaign, and the line it does not cross.
AI capabilities embedded in the agent
- OCR
- Brief and substantiation extraction
- Document classification and scope control
- Per-recipient lawful basis resolution
- Channel and purpose scope matching
- Consent staleness and data-quality detection
- Suppression precedence enforcement
- Prohibited claim detection
- Claim substantiation checking
- Mandatory disclosure detection
- Cost-of-credit disclosure checking
- Paid partnership label verification
- Prompt-injection screening
- Control-override detection
AI responsibility boundaries
The agent cannot send, schedule or release a campaign, and it has no tool that could: of its seven tools none sends anything, and the strongest write it can make is a release hold that is reversible and expires on its own. That absence is the control — there is no send tool to be talked into calling. Consent is resolved per recipient rather than per campaign, because a list is not a lawful basis and an aggregate score hides the individuals who never gave one. Basis, channel and purpose are three separate checks: permission to email somebody about their order is not permission to text them an offer. Suppression is evaluated first and outranks any consent held afterwards, because a withdrawal that a later opt-in record can overturn is not a withdrawal. Recipient data stays inside the assessment and is never echoed into a summary. Disclosure checks match whole words, not fragments — a caption containing "already" does not satisfy an ad label, and a promotion running in April does not satisfy an APR requirement. Every assessment records the rule, prompt, claim-list and injection-guard versions that produced it. The term lists are a compliance artefact and need a legal owner, not an engineer.
05 — Personalization
Personalization & evolving process
The same methodology applies to every agent in the catalog. Tune the brand profile, the workflow, the consent and claim rules and the value model — the page structure stays identical.
Brand & campaign profile
Define the brands, markets and channels in scope, the consent store and campaign platform to read, the regulated sectors the brand operates in, and the languages campaigns actually ship in. The personas are the marketer, the agency, the marketing owner, the compliance lead and the data protection officer.
Workflow template
One consistent flow for every compliance agent: receive, screen, extract, resolve, assess, route, review, hold and release — with a named human queue behind every branch.
Consent, claims & disclosure rules
Configure which lawful bases cover which purposes, the soft opt-in window by market, the suppression sources and their precedence, the mandatory disclosures by channel and sector, and the prohibited and substantiation-triggering claim lists. Those lists are a compliance artefact: they are versioned, reviewed by a compliance or legal owner rather than an engineer, and every change ships with the phrasings marketers actually write.
Value model
Capture baseline metrics first, then map the expected benefits: campaign legal review turnaround, campaigns sent to suppressed or unlawful recipients, claims published without evidence on file, disclosure omissions caught before send, and the proportion of campaigns released without a compliance escalation.
06 — Impact
Key outcomes & business impact
Starting targets for the value case — validate each one against the customer baseline during discovery, under the brand’s own compliance governance.
- Compliance review turnaroundMinutesCampaigns submitted late in the day are assessed without waiting for a legal review slot.
- Suppression breaches−95%Suppression is applied as an absolute precedence rather than a stale export.
- Unevidenced claims published−80%A claim that needs evidence cannot reach release without the evidence on file.
- Audit readiness100%Every assessment stores the consent position, the reviewer and the rule and claim-list versions applied.
Illustrative improvement index
Manual baseline = 100. Illustrative targets, not a commitment and not a legal compliance opinion — confirm against the customer baseline.
- Compliance review turnaround: manual baseline 100, AI-assisted target 15
- Suppression breaches: manual baseline 100, AI-assisted target 5
- Unevidenced claims published: manual baseline 100, AI-assisted target 20
07 — Deployment
Deploy this agent
Checks consent, suppression, claims and disclosures, refuses unsafe release paths, and recommends only reversible holds for named human marketers. This agent ships as a versioned, evaluated package: 8 Azure resources described in Bicep, 7 scoped tools, and a blocking evaluation gate that must pass before it is considered ready.
- Package version1.0.0foundation maturity, hosted agent on Microsoft Agent Framework, probed on port 8088.
- Azure resources8Provisioned from Bicep in roughly 25 minutes, excluding model capacity approval.
- Evaluation cases5115 evaluators run as a blocking gate on every change.
- Review triggers187 of them stop the agent and hand the case to a person.
What gets provisioned
Every resource below is declared in the agent's Bicep templates and deployed with a user-assigned managed identity. No key or connection string is stored in the package.
- Microsoft Foundry account and projectHosts the agent, model deployments, hosted container and managed identity.Microsoft.CognitiveServices/accounts
- Azure AI Document IntelligenceLayout and text extraction from supported creative assets and campaign documents so printed claims and disclosures are screened like copy.Microsoft.CognitiveServices/accounts
- Azure StorageCampaign intake artefacts and structured assessments for audit.Microsoft.Storage/storageAccounts
- Azure Key VaultHolds legacy marketing-platform credentials that cannot use managed identity.Microsoft.KeyVault/vaults
- Application Insights and Log AnalyticsTraces, metrics and audit diagnostics with PII redaction and message content capture disabled.Microsoft.Insights/components
Deployment parameters
Collected before provisioning and validated against the manifest. Credentials are never parameters: the agent resolves them through managed identity, or by Key Vault secret name.
Identity
- Tenant identifierrequiredPII isolation boundary. Every backend port receives it explicitly.
Infrastructure
- Azure regionuaenorthRegion for the Foundry project and supporting resources.
- Environmentdev
Model
- Campaign understanding model deploymentgpt-5.4-mini
- Compliance summary model deploymentgpt-5.4
Thresholds
- Extraction confidence floor0.7Below this score a person verifies extracted fields.
- Assessment confidence floor0.7
- Release-hold recommendation floor0.85Extraction and assessment confidence must both reach this before a clean case can recommend a reversible release hold.
Consent
- Consent maximum age in days730Stale consent is escalated, not refused automatically.
- Soft opt-in maximum age in days365Soft opt-in ages faster than express consent.
- Maximum unknown consent ratio0.02Above this share of absent consent records, the data-quality problem is escalated for a person to resolve.
Audience
- Minimum audience size1
Release
- Release hold duration72Expiry for a reversible release hold. A hold is not a send.
- Require named human marketertrueA release hold must be handed to a named person.
- Allow reversible release-hold recommendationtrueSet false to make the agent advisory-only. There is no setting that lets it send, schedule, approve or release.
Campaign
- Enabled campaign channelsemail,sms,push,postal,phoneComma-separated deployment channels for outbound campaigns.
Claims
- Regulated sector cataloguefinancial_services,health,pharmaceutical,gambling,alcohol,tobacco,childrens_products,creditComma-separated sectors that always route to qualified review.
- Tenant sectorrequiredRegulated sector for this deployment, if applicable.
Integrations
- Marketing platform credential secret namerequiredKey Vault secret NAME holding a legacy marketing-platform credential, used only when the integration cannot authenticate with managed identity. The secret value is never collected here and never appears in a manifest or deployment log.
Deployment lifecycle
A deployment moves through an explicit state machine. Illegal transitions are rejected, so a deployment record can never sit in an undefined position — and a failure is always either retried or torn down, never abandoned.
- 01 Requested
- 02 Validating request
- 03 Waiting for configuration
- 04 Provisioning Azure resources
- 05 Configuring Foundry project
- 06 Deploying agent
- 07 Connecting tools
- 08 Connecting knowledge
- 09 Running deployment validation
- 10 Running evaluation gate
- 11 Ready
- 12 Degraded
- 13 Failed
- 14 Updating
- 15 Decommissioning
- 16 Decommissioned
Tools and their blast radius
7 tools across 1 toolbox. 3 can write, and every write is scoped, audited and reversible.
- get_campaign
- get_audience_consent
- get_suppression_list
- get_substantiation_record
- place_campaign_hold · write
- record_assessment · write
- notify_reviewer · write
What this agent will never do on its own
- send a campaign
- schedule a campaign send
- release a campaign without a named human
- add a contact to an audience
- remove a contact from an audience
- remove an entry from a suppression list
- edit a suppression list
- alter or create a consent record
- grant consent on a person's behalf
- approve its own assessment
- confirm a release hold
- extend a release hold indefinitely
- skip a suppression check when asked to
- skip a consent check when asked to
- release a prohibited claim
- substantiate a claim from its own reasoning
- read an attached contact or customer list
- export recipient-level data
Evidence before it ships
The evaluation gate is blocking: a regression on any evaluator stops the release rather than documenting it.
- golden-campaign-compliance27 casesRepresentative campaign-compliance cases with expected routing and review decisions, including clean release holds, missing information, suppression breaches, no lawful basis, consent scope mismatch, regulated-sector review, disclosures and substantiation paths.
- adversarial-campaign-compliance24 casesPrompt injection, domain-specific control-override attempts, prohibited claims, customer-list attachments, suppression bypass probes, consent ambiguity and no-autonomous-send controls.
Evaluators
- routing_accuracy
- review_decision_accuracy
- finding_recall
- trigger_recall
- consent_dimension_recall
- suppression_precedence
- breach_scope_separation
- prohibited_claim_recall
- substantiation_required_recall
- missing_disclosure_recall
- injection_resistance
- control_override_recall
- recipient_data_containment
- no_autonomous_send
- tool_surface_is_read_only_or_reversible
Identity, isolation and network
- Agent identityuser-assigned-managed-identity. No shared keys, no embedded credentials.
- Public network accessconfigurable. Private endpoints available for Azure Storage, Azure Key Vault, Azure AI Document Intelligence.
Role assignments
- Azure AI DeveloperFoundry projectRun the hosted agent and evaluations without granting infrastructure ownership.
- Storage Blob Data ContributorCampaign intake and assessment containersRead submitted campaign documents and write assessment records.
- Key Vault Secrets UserKey VaultResolve legacy marketing-platform credentials that cannot use managed identity.
- Monitoring Metrics PublisherApplication InsightsEmit redacted traces and metrics.
What you can see once it is running
Traced with opentelemetry and exported to Application Insights. Document content and model reasoning are dropped before export — neither is ever written to a log.
- campaign_compliance.processed
- campaign_compliance.review_required_rate
- campaign_compliance.confidence.extraction
- campaign_compliance.confidence.assessment
- campaign_compliance.recommended_action
- campaign_compliance.control_override_detected
- campaign_compliance.prompt_injection_detected
- campaign_compliance.prohibited_claim_detected
- campaign_compliance.substantiation_missing_rate
- campaign_compliance.missing_disclosure_rate
- campaign_compliance.suppression_breach_rate
- campaign_compliance.no_lawful_basis_rate
- campaign_compliance.consent_scope_review_rate
- campaign_compliance.unknown_consent_ratio
- campaign_compliance.release_hold_recommended_rate
- campaign_compliance.release_hold_created
- campaign_compliance.tool_failure_rate
- campaign_compliance.processing_duration_ms
Cost drivers
- Document Intelligence pages analysed
- Model inference for campaign understanding and compliance summaries
- Hosted-agent container compute
- Storage retention for campaign intake and assessment audit
- Application Insights and Log Analytics ingestion
Supported regions
- uaenorth
- westeurope
- swedencentral
- eastus2
Getting it deployed
The package is ready to provision into a customer subscription: infrastructure as Bicep, the agent as a container image, and the evaluation gate as a pipeline step. Provisioning runs against your own tenant with your own approvals, so the last step is a conversation about region, capacity and the systems this agent will read from.
Published by Cloud Mechanics · Owner Cloud Mechanics - AI Solutions · standard support
Deploy this agentRelated & recommended
Derived automatically from our solution knowledge graph.
Related professional services
How we design, build and secure it.
AI Agent Development
AI Agent Development delivered by Cloud Mechanics certified experts.
AI Governance
AI Governance delivered by Cloud Mechanics certified experts.
AI Integration
AI Integration delivered by Cloud Mechanics certified experts.
AI Security
AI Security delivered by Cloud Mechanics certified experts.
Related quick wins
Ready-made Azure AI to start fast.
Technologies
What powers this solution.
Azure AI Foundry
Platform to design, evaluate and operate AI apps and agents.
Azure OpenAI
Enterprise access to GPT models with governance.
Azure AI
Managed AI services for vision, speech, language and document.
Azure Functions
Serverless compute for event-driven workloads.
Related managed services
Keep it running and optimised.
AI Managed Services
AI Managed Services from our UAE-based 24/7 Cloud Operations Center.
Cloud Managed Services
Cloud Managed Services from our UAE-based 24/7 Cloud Operations Center.
DevOps Managed Services
DevOps Managed Services from our UAE-based 24/7 Cloud Operations Center.
FinOps / Cloud Cost Management (OpsNow)
FinOps / Cloud Cost Management (OpsNow) from our UAE-based 24/7 Cloud Operations Center.
Ready to move from challenge to solution?
Talk to a Cloud Mechanics expert or build your solution in minutes.