Scoped as the CISO half of minutes #79 decision 3's gate. TCPA is the wrong statute for this channel -- it covers calls/texts/fax, not email -- and does not belong in the checklist at all. CAN-SPAM (15 U.S.C. Sec.7701 et seq.) and NY GBL Sec.349/350 are the two live obligations, and for a 33-target B2B one-time batch with mandatory per-message human approval, both close with a short footer/process checklist. The remaining blocker is mechanical, not legal: an undischarged #47 (no formed entity) means there is no compliant physical address to put in the required footer. #47 stays blocking for that concrete reason, not just as a formality. growth-ops.md's boundary #1 ("cannot send anything, ever") is a structural, board-set boundary -- CISO can scope the legal gate but not waive the charter change.
Findings
CAN-SPAM's physical-address requirement is currently unsatisfiable. BUSINESS_MODEL.md Gate B table (#47 open, entity status "Unknown") -- no entity means no registered business address; the only address available today is the owner's personal one. Blast radius: omitting the address is an FTC violation (up to $53,088/email, 2025 schedule, assessed per message); using the owner's home address is a personal safety/OPSEC exposure. Fix: a CMRA/PO Box or registered-agent address resolves this specific sub-piece even before the rest of #47 closes.
growth-ops is structurally send-incapable by design, and that's the load-bearing safety mechanism today. .claude/agents/growth-ops.md:54-56 -- "You cannot send anything, to anyone, ever... You draft; a human transmits." Blast radius of removing it without a compensating control: an SMTP-capable agent with no per-message gate can batch-send to all 33 at once. Fix: any charter change is a board decision, must pair the grant with mandatory per-recipient human click-to-send (no autosend, no batch job).
Target list has no email addresses yet; sourcing them is where CAN-SPAM's harvesting exposure lives. growth/westchester-target-list.md -- 33 rows verified for name/phone/address only, zero email column. Low risk if hand-copied from each business's own public listing; becomes aggravated-violation exposure under 15 U.S.C. Sec.7704(b) if scraped or purchased. Fix: one sourcing rule -- manual, one at a time, from published contact info only.
No suppression-list mechanism exists. A second email to an opted-out business is its own violation. Fix: growth/suppression-list.md, checked before every send.
NY GBL Sec.349/350 is a weak fit -- "consumer-oriented" conduct required, B2B-to-B2B is a stretch. No NY-specific commercial-email statute reaches plain B2B email. Practical exposure reduces to "don't make false/misleading claims," already required by growth-ops.md boundaries #3/#4.
Could not verify
Whether #47's in-progress ToS/Privacy/AUP work already reserves a compliant mailing address (owner-only); primary NY case law on Sec.349's B2B applicability (secondary sources only).
Recommendation
TCPA: drop from the gate -- does not apply to email.
NY UDAP: no action beyond growth-ops.md's existing honesty boundaries.
Add growth/suppression-list.md + a manual-sourcing rule to growth-ops.md.
Resolve#47's address sub-piece specifically -- a CMRA/PO Box unblocks the CAN-SPAM footer even before the rest of #47 closes. Owner: confirm whether that partial close is acceptable.
Draft a charter amendment to growth-ops.md granting bounded send capability (per-message human approval, one-time batch not a drip, opt-out honored within 10 business days) once #4 is answered.
Needs a CEO ruling
Whether #47 can partial-close (address only) to unblock this channel, or must close in full first.
Whether the board wants to formally amend growth-ops.md boundary #1.
Whether cold email can close #66/GOALS.md's kill criterion at all -- GOALS.md (minutes #79 decision 5, restated #146) is explicit that email/DM never counts as a qualifying conversation, only live two-way (phone/video/walk-in). A compliant cold-email channel is legally buildable, but it cannot by itself satisfy the 12-conversation count -- it can only generate leads that still need a live call to count.
Bottom line
Fast, closeable checklist -- not an open-ended legal question. The real blocker is mechanical (no compliant mailing address until #47's entity/address sub-piece resolves), not legal complexity.
## Position
Scoped as the CISO half of minutes #79 decision 3's gate. TCPA is the wrong statute for this channel -- it covers calls/texts/fax, not email -- and does not belong in the checklist at all. CAN-SPAM (15 U.S.C. Sec.7701 et seq.) and NY GBL Sec.349/350 are the two live obligations, and for a 33-target B2B one-time batch with mandatory per-message human approval, both close with a short footer/process checklist. The remaining blocker is mechanical, not legal: an undischarged #47 (no formed entity) means there is no compliant physical address to put in the required footer. #47 stays blocking for that concrete reason, not just as a formality. growth-ops.md's boundary #1 ("cannot send anything, ever") is a structural, board-set boundary -- CISO can scope the legal gate but not waive the charter change.
## Findings
1. CAN-SPAM's physical-address requirement is currently unsatisfiable. `BUSINESS_MODEL.md` Gate B table (#47 open, entity status "Unknown") -- no entity means no registered business address; the only address available today is the owner's personal one. Blast radius: omitting the address is an FTC violation (up to $53,088/email, 2025 schedule, assessed per message); using the owner's home address is a personal safety/OPSEC exposure. Fix: a CMRA/PO Box or registered-agent address resolves this specific sub-piece even before the rest of #47 closes.
2. growth-ops is structurally send-incapable by design, and that's the load-bearing safety mechanism today. `.claude/agents/growth-ops.md:54-56` -- "You cannot send anything, to anyone, ever... You draft; a human transmits." Blast radius of removing it without a compensating control: an SMTP-capable agent with no per-message gate can batch-send to all 33 at once. Fix: any charter change is a board decision, must pair the grant with mandatory per-recipient human click-to-send (no autosend, no batch job).
3. Target list has no email addresses yet; sourcing them is where CAN-SPAM's harvesting exposure lives. `growth/westchester-target-list.md` -- 33 rows verified for name/phone/address only, zero email column. Low risk if hand-copied from each business's own public listing; becomes aggravated-violation exposure under 15 U.S.C. Sec.7704(b) if scraped or purchased. Fix: one sourcing rule -- manual, one at a time, from published contact info only.
4. No suppression-list mechanism exists. A second email to an opted-out business is its own violation. Fix: `growth/suppression-list.md`, checked before every send.
5. NY GBL Sec.349/350 is a weak fit -- "consumer-oriented" conduct required, B2B-to-B2B is a stretch. No NY-specific commercial-email statute reaches plain B2B email. Practical exposure reduces to "don't make false/misleading claims," already required by growth-ops.md boundaries #3/#4.
## Could not verify
Whether #47's in-progress ToS/Privacy/AUP work already reserves a compliant mailing address (owner-only); primary NY case law on Sec.349's B2B applicability (secondary sources only).
## Recommendation
1. TCPA: drop from the gate -- does not apply to email.
2. NY UDAP: no action beyond growth-ops.md's existing honesty boundaries.
3. Add `growth/suppression-list.md` + a manual-sourcing rule to growth-ops.md.
4. Resolve #47's address sub-piece specifically -- a CMRA/PO Box unblocks the CAN-SPAM footer even before the rest of #47 closes. Owner: confirm whether that partial close is acceptable.
5. Draft a charter amendment to growth-ops.md granting bounded send capability (per-message human approval, one-time batch not a drip, opt-out honored within 10 business days) once #4 is answered.
## Needs a CEO ruling
- Whether #47 can partial-close (address only) to unblock this channel, or must close in full first.
- Whether the board wants to formally amend growth-ops.md boundary #1.
- **Whether cold email can close #66/GOALS.md's kill criterion at all** -- GOALS.md (minutes #79 decision 5, restated #146) is explicit that email/DM never counts as a qualifying conversation, only live two-way (phone/video/walk-in). A compliant cold-email channel is legally buildable, but it cannot by itself satisfy the 12-conversation count -- it can only generate leads that still need a live call to count.
## Bottom line
Fast, closeable checklist -- not an open-ended legal question. The real blocker is mechanical (no compliant mailing address until #47's entity/address sub-piece resolves), not legal complexity.
logan
added the role:ciso label 2026-09-13 21:40:31 -04:00
Owner ruling, 2026-09-13: PO box accepted as the CAN-SPAM footer address (1350 E. Main St. Ste. 24, Shrub Oak, NY 10588) — resolves finding #1's address blocker without waiting on the rest of #47. growth-ops.md amended to grant bounded email-draft-to-outbox capability per the review's recommendation #2/#5 (no Bash/network added, no autosend, no batch — a human sends each one from their own mail client). growth/suppression-list.md and growth/outbox/ created.
Email is a top-of-funnel channel only — GOALS.md/minutes #79's rule that only live two-way conversation counts toward #66's 12 is unchanged and restated in growth-ops.md.
Remaining open question (mechanism, not policy): whether sending is manual copy-paste from the owner's own email client (zero setup, works today) or an actual SMTP relay account for automation — owner to decide, separate from this ruling.
**Owner ruling, 2026-09-13**: PO box accepted as the CAN-SPAM footer address (1350 E. Main St. Ste. 24, Shrub Oak, NY 10588) — resolves finding #1's address blocker without waiting on the rest of #47. growth-ops.md amended to grant bounded email-draft-to-outbox capability per the review's recommendation #2/#5 (no Bash/network added, no autosend, no batch — a human sends each one from their own mail client). `growth/suppression-list.md` and `growth/outbox/` created.
Email is a top-of-funnel channel only — GOALS.md/minutes #79's rule that only live two-way conversation counts toward #66's 12 is unchanged and restated in growth-ops.md.
Remaining open question (mechanism, not policy): whether sending is manual copy-paste from the owner's own email client (zero setup, works today) or an actual SMTP relay account for automation — owner to decide, separate from this ruling.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Position
Scoped as the CISO half of minutes #79 decision 3's gate. TCPA is the wrong statute for this channel -- it covers calls/texts/fax, not email -- and does not belong in the checklist at all. CAN-SPAM (15 U.S.C. Sec.7701 et seq.) and NY GBL Sec.349/350 are the two live obligations, and for a 33-target B2B one-time batch with mandatory per-message human approval, both close with a short footer/process checklist. The remaining blocker is mechanical, not legal: an undischarged #47 (no formed entity) means there is no compliant physical address to put in the required footer. #47 stays blocking for that concrete reason, not just as a formality. growth-ops.md's boundary #1 ("cannot send anything, ever") is a structural, board-set boundary -- CISO can scope the legal gate but not waive the charter change.
Findings
BUSINESS_MODEL.mdGate B table (#47 open, entity status "Unknown") -- no entity means no registered business address; the only address available today is the owner's personal one. Blast radius: omitting the address is an FTC violation (up to $53,088/email, 2025 schedule, assessed per message); using the owner's home address is a personal safety/OPSEC exposure. Fix: a CMRA/PO Box or registered-agent address resolves this specific sub-piece even before the rest of #47 closes..claude/agents/growth-ops.md:54-56-- "You cannot send anything, to anyone, ever... You draft; a human transmits." Blast radius of removing it without a compensating control: an SMTP-capable agent with no per-message gate can batch-send to all 33 at once. Fix: any charter change is a board decision, must pair the grant with mandatory per-recipient human click-to-send (no autosend, no batch job).growth/westchester-target-list.md-- 33 rows verified for name/phone/address only, zero email column. Low risk if hand-copied from each business's own public listing; becomes aggravated-violation exposure under 15 U.S.C. Sec.7704(b) if scraped or purchased. Fix: one sourcing rule -- manual, one at a time, from published contact info only.growth/suppression-list.md, checked before every send.Could not verify
Whether #47's in-progress ToS/Privacy/AUP work already reserves a compliant mailing address (owner-only); primary NY case law on Sec.349's B2B applicability (secondary sources only).
Recommendation
growth/suppression-list.md+ a manual-sourcing rule to growth-ops.md.Needs a CEO ruling
Bottom line
Fast, closeable checklist -- not an open-ended legal question. The real blocker is mechanical (no compliant mailing address until #47's entity/address sub-piece resolves), not legal complexity.
Owner ruling, 2026-09-13: PO box accepted as the CAN-SPAM footer address (1350 E. Main St. Ste. 24, Shrub Oak, NY 10588) — resolves finding #1's address blocker without waiting on the rest of #47. growth-ops.md amended to grant bounded email-draft-to-outbox capability per the review's recommendation #2/#5 (no Bash/network added, no autosend, no batch — a human sends each one from their own mail client).
growth/suppression-list.mdandgrowth/outbox/created.Email is a top-of-funnel channel only — GOALS.md/minutes #79's rule that only live two-way conversation counts toward #66's 12 is unchanged and restated in growth-ops.md.
Remaining open question (mechanism, not policy): whether sending is manual copy-paste from the owner's own email client (zero setup, works today) or an actual SMTP relay account for automation — owner to decide, separate from this ruling.