
There Is No Warm-Up That Ends in a Cold Instagram DM
Engaging with someone before messaging them does not create permission. The API has no path to a stranger, and warming up is not a loophole in it.
Compliance4 min read
Writing
Every compliance post, newest first.

Engaging with someone before messaging them does not create permission. The API has no path to a stranger, and warming up is not a loophole in it.
Compliance4 min read

Compliance
A bot that asserts a payment succeeded, failed or is pending is the exact shape the scams on this channel use. Here is why, and what a message can honestly do instead.
5 min read

Compliance
Policy documents describe rules. Complaints come from a person's thumb moving. Here are the moments that move it, written from the recipient's side of the thread.
5 min read

Compliance
A citizen cannot choose another provider, which changes every trade-off. What a public body can safely automate, and what it must never touch.
5 min read

Compliance
The rating on a business number is not a score for your writing. It is a summary of how recipients reacted, which means it is a lagging report on your list.
5 min read

Compliance
A bought list is not an opt-in and a tick box buried in checkout is barely one. What consent has to look like on a channel that sits beside family chats.
5 min read

Compliance
GDPR is not DPDP with different words. Where the two diverge for a messaging channel, and which parts of the problem software can genuinely help with.
4 min read

Compliance
Restrictions on this channel are usually earned by message quality rather than by volume. What actually triggers them, and what a tool can and cannot do about it.
4 min read

Compliance
Sending the ask is the easy part. What destroys the data — and in places the legality — is paying for answers or routing unhappy customers away from the public form.
5 min read

Compliance
Before any question about obligations, a simpler one: what data does this channel generate, who ends up with a copy, and how much of it did you choose to collect?
4 min read

Compliance
The rules for this channel live in several documents owned by different parties and they all change. A map of what governs what, and a routine for staying current.
5 min read

Compliance
One is a feature of Meta's free Business app that lives on a single phone. The other is template sending on the Business Platform. People shop for one and buy the other.
5 min read

Compliance
A customer's number and their messages are personal data. What that obligation actually lands on, and why no tool can sell you compliance.
5 min read

Compliance
A clinic can automate the front desk and nothing beyond it. The harder discipline is what a template is allowed to contain, because it appears on a lock screen.
5 min read

Compliance
A buyer can verify Meta API compliance before signing up. What to ask, what the permissions screen should say, and the one test that settles it in a minute.
6 min read

Compliance
Bans are rare. Graded restrictions are not. What actually trips one, how to tell a platform throttle from your own tool refusing, and what recovery really involves.
6 min read

Compliance
Every DM a broker gets is really one question, and it is the one question a bot must not answer. Here is what to send instead, and why the stakes are different.
5 min read

Compliance
A law practice usually cannot answer a legal question in a DM at all. So the build is mostly a refusal list, a routing reply, and a consultation link that works.
5 min read

Compliance
Somebody just sent you their portfolio screenshot and asked what to do with it. Suitability is the whole job, and a keyword match has not done any of it.
5 min read

Compliance
A symptom in an Instagram DM is a clinical question wearing casual clothes. No automation should answer one, and the build for a clinic starts by making sure it never can.
6 min read

Compliance
Three questions make up most of a dealership inbox, and an automation should refuse all three. The argument for why, and what is left once you accept it.
5 min read

Compliance
We do not track affiliate links, clicks or commissions — none of it. What this post is really about is the disclosure that has to be inside the message itself.
5 min read

Compliance
The inbox does not respect the line between coaching and clinical care, so the automation has to. What a non-clinical account must never send, and who reads the rest.
6 min read

Compliance
A Reel that travels is a load event. What actually happens to your automation during a spike, and the preparation that has to be done before it starts.
5 min read

Compliance
Every enquiry is a parent asking about a minor, and the obvious qualifying question — name, age, class, school — is the one a DM automation must never ask.
6 min read

Compliance
A CA inbox in filing season is deadlines, document lists, and people trying to send you their PAN. Only one of those three is safe to automate. Here is the split.
5 min read

Compliance
A charity account receives messages from people offering help and from people who need it. Telling those two apart before you automate anything is the entire job.
5 min read

Compliance
A skincare inbox is full of questions that look like product questions and are actually health questions. That line is where a beauty automation lives or dies.
5 min read

Compliance
An academy inbox holds adults enquiring about children and children enquiring about themselves. The automation cannot tell them apart, so build as though it never can.
5 min read

Compliance
A multi-practitioner clinic has one inbox and no author. Before automating anything, decide who signs off the wording, who can change it, and who reads what got blocked.
6 min read

Compliance
A school or university inbox is full of prospective students, anxious parents and agents, and you cannot tell them apart. What that rules out automating, and why.
6 min read

Compliance
Tag spam, hashtags and repeat entries make a giveaway comment section hostile to keyword matching. What actually collides, and the reply you must never automate.
5 min read

Compliance
Automation gets accounts restricted when it signs in as you. On the official API it does not. The difference, and how to tell in thirty seconds.
5 min read

Compliance
The two windows, what the official API will and will not let a business send, and the behaviours that get accounts restricted. Written without the scare tactics.
5 min read

Compliance
People in distress message therapists. On a therapy account the safe posture is inverted: automate almost nothing, fire on almost nothing, and get out of the way fast.
6 min read

Compliance
A spa inbox is full of questions that sound like service questions and are actually health questions. Those are the ones a template must be built to refuse.
5 min read

Compliance
Most incidents are not clever attacks on a vendor. They are a shared login, a stale freelancer and a token nobody revoked. What to fix, in the order it matters.
5 min read

Compliance
A page that publishes about anxiety is not a service, but the people who message it do not know that. The gap between what you publish and who replies is the whole risk.
6 min read

Compliance
A life coach is not a therapist, and the person messaging at 2am does not always know that. What that means for what an automation is allowed to send, and when.
6 min read

Compliance
A yoga studio, a nutritionist and a supplement brand receive the same DMs a clinic does, with none of a clinic's guardrails. Three things that must never be automated.
6 min read

Compliance
One inbox, several advisers, and every reply going out in the firm's name. The hard part is not writing templates. It is who approved them and who reads the thread.
6 min read

Compliance
Automation can ask everybody the same way at the same moment. What it must never do is choose who gets asked — filtering for happy customers is a dark pattern with teeth.
5 min read

Compliance
The privacy duties that land on the business running the automation, not the vendor: notice, purpose, retention, who on your team can read a DM, and requests.
5 min read

Compliance
A chiropractic inbox fills up with strangers describing their own pain. That is a clinical question wearing an enquiry's clothes, and a template must not answer it.
6 min read

Compliance
A non-engineer guide to the permission map every compliant vendor shares: what can be sent, to whom, inside which clock, and what no approval will ever allow.
5 min read

Compliance
What the official API permits, what it refuses, what every tool in this category can and cannot do, and how to tell a compliant one from the other kind.
4 min read

Compliance
Collecting a testimonial is easy. The obligations that come with it are the post: explicit consent, the words unedited, and a record of what was agreed to.
6 min read

Compliance
A follow is not a message, so it opens no window and triggers nothing. What the tools promising welcome DMs are actually doing, and what works instead.
5 min read

Compliance
What the Messaging API needs, which scopes do what, how the 24 hour window really works, and the four setup mistakes that cost people a week.
5 min read

Compliance
A wellness brand is not a clinic, and that makes its inbox harder, not easier. Two absolute rules, and the narrow set of messages a template may answer.
6 min read

Compliance
A treatment reel that performs fills your DMs with symptoms, outcome questions and price requests. Three sentences a healthcare account must never send automatically.
6 min read

Compliance
Instagram DMs are a private channel people use to talk to a person. Where disclosure is owed, what a comment consents to, and uses that are wrong even when permitted.
5 min read

Compliance
Admissions enquiries are high-stakes, often regulated, and frequently come from minors or their parents. What a school can safely automate is a short list.
6 min read

Compliance
A comment becomes rows in a database. Which rows, who can read them, how long they stay, and what happens when the person asks for a copy or a deletion.
5 min read

Compliance
You cannot message someone who has not messaged you. No plan, no workaround, no permission. What the tools selling it are really doing, and what generates inbound instead.
5 min read

Compliance
We cannot recover an Instagram account and neither can any other tool — only Meta can. What our side shows when something breaks, and how to tell the two problems apart.
5 min read

Compliance
A follow is not a message, so the Instagram API gives you no way to DM new followers. Why that rule exists, what the tools selling it do, and what works.
4 min read
Prefer a feed? RSS.