Updated Jul 2026
How compliance review actually works
When you select Analyze on a pending post, PostSignoff checks the post’s text against a set of marketing rules chosen for your brand. This page explains what that check is actually doing, where it stops, and why the workflow around it treats your judgment, not the checker’s, as the thing that counts. For the click-by-click mechanics, see Run a compliance check before approving.
A pack is a ruleset for an industry
Compliance review is configured per brand. When you turn on Enable compliance review before approval, you choose a compliance pack: a set of rules built around one industry’s marketing regulations. The pack documented today is Medicare (CMS marketing rules), and it’s also the default that applies when the pack list can’t be loaded. A brand can add its own custom rules on top of whichever pack it uses.
A pack isn’t a legal opinion. It’s a codified reading of a rulebook, applied the same way to every post your brand produces.
What the check reads
The analysis takes the post’s current text as its input: the body, the sign-off, and the hashtags. All of it is text.
That boundary matters as much as anything inside it. The checker never sees an attached image or video, the landing page a link points to, or whatever happens in the comments after publishing. If a claim lives in a screenshot or on the page you’re linking to, the check can’t catch it. Your own review still has to.
How findings are graded
Every finding carries a severity: info, warning, or high, shown as
a small colored label. The scale runs the way the names suggest. An
info finding is context worth seeing. A warning points at wording
that likely needs attention. high marks what the checker treats as most
serious.
Severity tells you where to spend attention first. It doesn’t change what you’re allowed to do: any unresolved finding, whatever its level, has to be either fixed in the content or acknowledged before the post can approve. Beyond the label, a finding can quote the exact flagged phrase, offer a suggestion, or, for a missing required disclaimer, come with an Insert disclaimer button that adds the text for you.
Why some findings cite a regulation and some don’t
A citation appears when the rule behind a finding is grounded in a
specific regulation. The required TPMO disclaimer under Medicare
marketing rules, for instance, cites 42 CFR §422.2267(e)(41). Rules
that don’t trace back to one citable clause, your brand’s custom rules
among them, don’t carry a citation. That doesn’t make the finding less
worth reading. It means the rule’s authority is the pack or your own
brand configuration rather than a single line of regulation you can look
up.
Assistance, not certification
Every result, clean pass or not, carries the same line: “This is review assistance, not a compliance certification.” That sentence is an honest description of the design.
The checker’s job is to narrow the field. It reads every post the same way, every time, and surfaces the wording a trained reviewer would want to look at. What it can’t do is make the call. Whether a flagged phrase is acceptable in context is a judgment, and the workflow keeps that judgment with you. Compliance review is designed to support your supervision process. It doesn’t replace it, and it doesn’t guarantee compliance with any regulation.
That’s also why acknowledgement is recorded instead of quietly skipped. When you approve a post with unresolved findings, PostSignoff writes down who acknowledged them, when, and a fingerprint of the exact wording, sign-off, and hashtags that were on the table. The human decision is the supervision event, so the human decision is what goes on record. Bulk actions never make it for you. A post with open findings is skipped until someone opens it and decides.
Why an edit resets the analysis
An analysis result describes one exact piece of text. Change anything, even a hashtag, and the result now describes text that no longer exists. So PostSignoff clears it, and Approve stays disabled until the new text has been analyzed. Saving an edit re-runs the check for you automatically. Restoring an old version doesn’t.
The same principle shapes the record. Each analysis creates its own review entry, permanently tied to the wording it checked, so a post’s compliance history is a series of exact-text snapshots rather than one status that gets overwritten. If it ever matters what was reviewed and what was approved, the answer isn’t ambiguous. See Keep an audit trail of what went out for where that record surfaces.