Guardivia

A2P Revenue Assurance

How can an MNO establish an A2P traffic baseline before deploying a firewall?

Reviewed 2026-09-12 by the Guardivia QoS Engineering Team

In short

Run the platform in monitoring mode for a full traffic cycle — at least four to six weeks — recording classification, senders, routes, volumes, delivery rates and timing without enforcing anything. That record is what later proves which volume changes were recovered bypass and which were over-blocking.

Why the baseline is non-negotiable

Every question an operator will ask after go-live depends on it. Did volume fall because bypass stopped or because we blocked a bank? Did revenue rise because of the firewall or because of a seasonal peak? Which aggregators were already compliant?

Without a baseline, none of these can be answered, and the usual outcome is that controls are relaxed indiscriminately the first time an enterprise complains.

What to record

The baseline needs enough dimensions to support later attribution:

  • Total volume by classification — A2P, P2P, P2A, M2P — and by purpose within A2P
  • Volume by route, interconnect partner and Global Title
  • Volume by Sender ID and by submitting account, with registry status recorded
  • Delivery rates and latency per route and destination operator
  • Timing distribution across hour of day and day of week
  • Destination-range distribution, which is what makes later AIT detection possible

How long to observe

Four to six weeks is the practical minimum. Messaging traffic has weekly cycles, monthly billing-driven peaks and payday effects, and a two-week sample will misrepresent all three.

Where a market has strong seasonal patterns — religious holidays, retail events, academic terms — it is worth either extending the period or explicitly noting which effects the baseline does not capture.

Baseline as an asset, not a phase

The baseline should not be a one-off document filed after go-live. It becomes the reference the platform continues to compare against, and it is refreshed as legitimate traffic patterns evolve.

In Guardivia's deployment sequence this is explicit: monitoring-mode operation and traffic baselining are distinct steps before controlled production activation, and the baselines the platform builds are what its classifiers later score deviations against.

Discuss this with the engineers who build the platform

Questions about how this applies to your network go straight to the QoS Engineering Team.