顧客保護型の解約・downgrade・pause・win-back を、利用権・cash・データまで閉じる
Technical Summary
Section titled “Technical Summary”- retention の前に exit integrity を測る。 顧客が選んだ
cancel / downgrade / pause / resume / export / delete / refundを、約束した時刻と条件どおりに完了できなければ、saved MRR や win-back 売上を読まない。迷わせた継続課金は retention ではない。 - 一つの
subscription_statusに潰さない。 顧客意思、更新予定、provider 契約、invoice / payment、利用権、refund / credit、account、export / deletion / retention、support case は別 state と別時計で持つ。Webhook は通知であり、利用権や銀行着金そのものではない。 - direct exit と optional option を同じボタン競争にしない。 退出経路は明確・到達可能・確認可能に保ち、pause、downgrade、support、discount は選択可能な別提案にする。提示しない群を作っても、取消可能性や必要表示を弱めない。
- provider ごとの差を entitlement policy で吸収する。 Stripe の period-end cancel と
pause_collection、Paddle のscheduled_change、Apple の auto-renew off、Google Play の canceled-but-entitled / pause / account hold は同じ意味ではない。provider の現在状態を再取得し、自社のaccess_untilを冪等に再計算する。 - primary は matured customer-safe contribution delta である。 同じ frozen eligible intent を分母に、settled cash から refund / fee / variable cost / offer / support / remediation を引く。ただし unexpected charge、early access loss、broken exit、data closeout failure、incident は平均利益で相殺しない。
- Codex / AI は分類・差分・draft・照合まで。 解約、返金、data deletion、live offer、顧客連絡を自律実行させない。この release の実行上限は
NEXT_LIFECYCLE_PROPOSAL_ONLY、live_action_authority = NONEである。
基準日: 2026-08-03
対象: Web app、subscription、mobile app、API / AI feature を一人または小規模で運用する technical founder
判断単位: seller × product / contract × route / jurisdiction × primary intent × frozen eligible cohort × assigned lifecycle revision × effective window × maturity rule
primary metric: matured_customer_safe_contribution_delta_per_eligible_intent
本章は product、billing、support、計測、運用の一般教材であり、個別の法務・税務・会計・決済助言ではない。B2C / B2B、地域、契約、store、決済 provider、商品、最低利用期間、返金、個人データ、会計・税・紛争保存に応じて専門家と確認する。
本文、運用パック、SQLite companion の顧客、subscription、intent、金額、offer、incident、review はすべて fully synthetic である。実績、save-rate benchmark、推奨 discount、普遍的な pause 期間、法的結論ではない。個人情報、payment credential、private contract、support 添付を公開物や生成 AI prompt に入れない。
Findings: churn 対策と正しい終了処理の間に空白がある
Section titled “Findings: churn 対策と正しい終了処理の間に空白がある”既存章は acquisition、pricing、retention、analytics、cash、migration を扱う。本章はそれらを置き換えず、intent → provider → entitlement → cash → data closeout → maturity → decision の接続だけを正本にする。
| 正本 | 既存章が受け持つこと | 本章が追加する接続 |
|---|---|---|
| 02章 | subscription economics、churn、LTV、unit economics | saved MRR を customer-safe cash contribution へ変換する |
| 03章 | friction、choice architecture、accessibility、dark pattern | direct exit と optional option、確認、取消、redress |
| 05章 | Webhook、冪等、billing、observability、incident | scheduled / effective / entitlement / cash / closeout の複数時計 |
| 06章 | privacy、terms、特商法、account deletion | subscription、account、data request、retention reason の分離 |
| 11章 | B2B authority、pilot、renewal、SLA | authorized requester、notice、commitment、data return の契約差 |
| 12章 | repeat value、AI cost、retention | 継続課金を repeat accepted value と取り違えない |
| 19章 | time zero、ITT、maturity、uncertainty | churn-selected cohort、offer assignment、exit harm の固有 gate |
| 21章 | invoice、refund、provider balance、bank cash | lifecycle cohort の settled cash / cost を一度だけ引き渡す |
| 23章 | price / package / terms、通知・同意、既存顧客移行 | downgrade / discount 後の exact offer、invoice、entitlement |
| 25章 | payment recovery、account compromise、appeal / restore | 自主退出と involuntary churn、正当な recovery を分母から分ける |
Definitions and scope
Section titled “Definitions and scope”intent、reason、state、outcome を同義語にしない
Section titled “intent、reason、state、outcome を同義語にしない”| 語 | この章での意味 | 単独では言えないこと |
|---|---|---|
PRIMARY INTENT |
顧客が今完了したい一つの action | churn reason、最適 offer、法的 authority |
REASON |
任意回答、support note、観測された文脈 | 真因、将来行動、discount eligibility |
SCHEDULED CHANGE |
period-end cancel / downgrade 等の将来予定 | 既に effective、返金済み、利用権失効 |
PROVIDER STATUS |
provider が持つ subscription / transaction state | 自社 app の認可、銀行現金、全 data closeout |
ENTITLEMENT |
product / feature / seat / data への利用権と期限 | invoice が支払済み、auto-renew が on |
REFUND / CREDIT |
現金返金、残高減額、invoice 調整等の別 ledger | subscription 終了、銀行着金、同じ principal の再控除 |
ACCOUNT CLOSE |
login / tenant / service account の閉鎖 | store subscription の停止、全データ即時消去 |
DATA CLOSEOUT |
export、削除、匿名化、保存理由・期限・access の処理 | subscription cancel と同時完了、無条件の全削除 |
RETAINED / REACTIVATED |
事前定義した期間の継続または再開 | repeat value、因果 uplift、利益、永続 retention |
MATURED |
predeclared follow-up と必要な照合が完了 | 将来の refund / dispute が絶対にない |
顧客の文を最初から churn score に変換しない。次の primary intent のどれを今求めているかを確認する。
CANCEL_RENEWAL | CANCEL_IMMEDIATE | DOWNGRADE | PAUSE | RESUMEREACTIVATE | EXPORT_DATA | DELETE_ACCOUNT | DELETE_DATAREFUND_REQUEST | PAYMENT_RECOVERY | MARKETING_OPT_OUT一つの request は一つの primary intent を持つ。たとえば「解約してデータも消したい」は、subscription cancel と account / data closeout を別 request に分け、共通の customer-visible case reference で結ぶ。片方の成功をもう片方の成功にしない。
seven-plane lifecycle state
Section titled “seven-plane lifecycle state”| plane | minimum state | authoritative evidence |
|---|---|---|
| customer authority / intent | requested、confirmed、withdrawn、disputed | authenticated actor、role、exact choice、confirmation revision |
| commercial renewal | renew on/off、notice、commitment、scheduled change | current contract / offer / terms、effective rule |
| provider subscription | active、trialing、past_due、paused、canceled、expired 等 | current provider object / transaction / renewal info |
| invoice / payment / adjustment | open、paid、retry、hold、refund pending/paid/failed、credit | invoice / transaction / adjustment + bank / provider reconciliation |
| entitlement | current product / seats / feature、access_until、revoked |
local authorization ledger + provider / contract policy |
| account / data | login open/closed、export due/delivered、delete due/completed、retained class | identity receipt、data job、retention schedule / reason / access |
| communication / support | notice due/sent/delivered、case open/resolved、appeal | rendered message revision、delivery、case / remedy receipt |
active、canceled、paused の一語から他 plane を埋めない。provider status は自社の entitlement 判定への入力であり、認可判定そのものではない。
exact lifecycle contract
Section titled “exact lifecycle contract”retention_lifecycle_contract_id / contract_version:seller / product / contract / offer revision:route / provider / storefront / jurisdiction / customer class:
primary intent / authorized actor / confirmation revision:direct exit path / accessibility review / support fallback:reference lifecycle / candidate optional intervention / assignment:eligibility freeze / time zero / effective rule / follow-up / maturity:
intent fulfillment floor / unexpected charge cap / early access loss cap:data closeout floor / support capacity cap / incident veto:economics components / FX / internal time cost / reconciliation threshold:
provider owner / entitlement owner / cash owner / data owner / support owner:rollback / remedy / source checked_at / independent reviewer:authority_cap: NEXT_LIFECYCLE_PROPOSAL_ONLYlive_action_authority: NONEcontract ID は join key であって合法性や安全性を作らない。provider、store policy、terms、offer、effective rule、entitlement policy、data retention、assignment、maturity、cap、owner のどれかを変えたら version を上げ、古い承認を継承しない。
eligibility grain と confirmed request を分ける
Section titled “eligibility grain と confirmed request を分ける”eligible_lifecycle_intent_id= one authenticated actor × one target subscription / account / data scope × first eligible entry into the lifecycle path × before option assignment or outcome
lifecycle_request_id= one authenticated actor × one target subscription / account / data scope × one primary intent × one exact confirmed choice revisioneligible_lifecycle_intent_id はconfirmation前のerror、loop、forced support、accessibility failure、unclassified abandonmentを分母に残すspineである。confirmationに到達した対象だけをeligibleにしない。lifecycle_request_id はexact choice確認後に作り、両者を一対一または明示したlinked relationで結ぶ。
単なるsettings page view、survey start、support message、Webhook eventをintent / request件数へ増幅しない。eligibility入口はpredeclaredなauthenticated action(例: direct exit entry)に固定する。retryはeligible_lifecycle_intent_id + attempt_sequence、confirmation後はlifecycle_request_id + attempt_sequenceで結び、同じ顧客が複数subscriptionを持つときは対象を明示する。
Methodology: direct exit を基盤、option を別の実験にする
Section titled “Methodology: direct exit を基盤、option を別の実験にする”exit architecture
Section titled “exit architecture”authenticated intent intake→ exact target / authority / current terms を表示→ direct requested action と optional alternative を並列に保持→ customer confirms one exact action→ provider command with idempotency key→ current provider state reread→ entitlement / invoice / data jobs derived separately→ customer-visible receipt with effective time and remaining obligations→ reconciliation / remedy / maturity安全な cancellation flow は「offer を見せない」ことではない。次を同時に満たすことである。
- direct exit は常に識別でき、keyboard、focus、label、error、review / correction を含む end-to-end process として到達できる。
- option は
NO THANKS / CONTINUE EXITを持ち、拒否で不利益や再入力を増やさない。 - countdown、false scarcity、選択済み add-on、曖昧な二重否定、support だけの隠れた経路を使わない。
- discount、pause、downgrade の price、期間、終了後 price、自動更新、利用権、次回請求を action 前に示す。
- 顧客が cancel を選んだ後、survey 回答や担当者との交渉を完了条件にしない。reason は任意で別 evidence にする。
- 法定・契約上必要な notice、refund、export、withdrawal を experiment の variant にしない。
WCAG 2.2は keyboard、focus、target size、labels / errors、認証支援、法的・金銭的・データ変更の review / correction 等を扱う。適合は cancel button 一個でなく、認証からreceiptまでの process 全体で確認する。W3C Ethical Web Principlesは利用者の主体性・透明性・privacy と manipulative design の抑制を高位原則として示すが、法律や適合規格そのものではない。
append-only event spine と as-of snapshot
Section titled “append-only event spine と as-of snapshot”ELIGIBLE_INTENT_FROZEN→ AUTHORITY_AND_TARGET_VERIFIED→ EXACT_CHOICE_CONFIRMED→ PROVIDER_COMMAND_REQUESTED / ACCEPTED / FAILED→ PROVIDER_CURRENT_STATE_OBSERVED→ ENTITLEMENT_DERIVED / APPLIED / VERIFIED→ INVOICE / REFUND / CREDIT / CASH RECONCILED→ EXPORT / DELETION / RETENTION CLOSEOUT→ VALUE / SUPPORT / COST FOLLOW-UP→ MATURITY_SNAPSHOT→ INDEPENDENT REVIEW→ LIFECYCLE DECISIONevent は occurred_at / effective_at / observed_at / recorded_at を分ける。period-end cancel は requested と effective が違い、refund requested と funds returned も違う。snapshot は recorded_at <= cutoff の revision だけを読み、後から届いた backdated event で過去判断を黙って書き換えない。late evidence は新しい snapshot で再評価する。
Webhook は署名確認、event ID dedupe、非同期 retry、object 再取得、transition validation、business idempotency を経る。provider command の HTTP 2xx や event 受信は、local entitlement、receipt delivery、bank cash の完了証拠ではない。
scheduled、effective、verified を別時計にする
Section titled “scheduled、effective、verified を別時計にする”| action | scheduled evidence | effective evidence | closeout evidence |
|---|---|---|---|
| period-end cancel | renewal off / scheduled change | provider ended at period end | no unexpected renewal + correct access end |
| immediate cancel | accepted immediate termination | provider terminal state | access / invoice / refund / remedy reconciled |
| downgrade | target price / product + effective rule | target subscription current | entitlement and invoice match disclosed preview |
| pause | exact pause mechanism + start / resume rule | provider / local paused state | invoice and access follow chosen policy |
| resume / reactivate | target offer and billing start | provider active / new transaction | payment and entitlement verified |
| refund | adjustment requested / approved | provider refund completed | original rail / bank outcome and principal exclusivity |
| data deletion | scope / due / retention exception | job completed per class | retained-data notice, access restriction, expiry |
missing、not due、pending、late、failed、disputed、unknown link を0や成功へ変換しない。
Provider reality: 四つの billing model を一つにしない
Section titled “Provider reality: 四つの billing model を一つにしない”Provider feature、plan、API version、storefront、policy は変わる。以下は2026-08-03時点の一次資料を設計境界として整理したものであり、実装時に current account / docs / sandbox で再確認する。
| provider | cancel / change | pause / recovery | 実装時の非推論ルール |
|---|---|---|---|
| Stripe | cancel_at_period_end=true は期間末まで継続し、実終了前なら撤回可能。設定時は updated、実終了時は deleted。即時 cancel 後の再開は新規 subscription |
真の subscription pause は cited state では Private Preview。pause_collection は invoice を生成し subscription は active のまま |
cancel から refund、未請求 usage、pending invoice item、open invoice、entitlement を推論しない |
| Paddle | period-end cancel は scheduled_change を持ち active のまま、期日に canceled。API は immediate も選択でき、canceled は terminal |
period-end / immediate pause、resume billing mode がある。paused 中の access は seller policy。portal self-service pause の可否は current feature を確認 | status、scheduled change、transaction、refund / credit、access を別にする |
| Apple App Store | auto-renew off 後も原則 current period end まで利用。upgrade / crossgrade / downgrade の effective timing が異なる | grace、billing retry、win-back eligibility がある。一般的な subscription pause と download pause を混同しない | notification、renewal state、transaction、family sharing、refund / revoke を再取得して entitlement を判断 |
| Google Play | SUBSCRIPTION_CANCELED 後も expiryTime まで entitlement を維持。cancel type、restore、revoke は別 |
pause は対応 plan / setting で period end 後に発効。grace 中は access、account hold 中は停止。RTDN 後に API reread | canceled を即時 revoke にせず、日数を hard-code せず、new purchase token を local account と結ぶ |
Stripe
Section titled “Stripe”Stripe の cancellationは即時、期間末、指定時刻と、その後の invoice item / metered usage / refund・proration の関係を分ける。Customer Portalは cancellation、period-end resume、同一 Product 内の Price change、reason 等を構成でき、cancellation pageでは任意の coupon 提示も扱う。feature があることは公正な設計、利益、因果 save を保証しない。
Pause a subscriptionの真の pause と、pause payment collectionを同じ paused=true にしない。後者は invoice を生成し、subscription status が active のままになり得る。Webhook guidanceを入口に current object を再取得し、access_until と invoice / adjustment を再計算する。
Paddle
Section titled “Paddle”Paddle cancelは immediate と next billing period、terminal canceled、scheduled_change を区別する。Pause / resumeは timing と billing mode を持ち、paused 中の limited access は自社判断である。Upgrade / downgradeは item replacement と proration mode を必要とし、preview は確認材料であって最終請求や顧客同意そのものではない。
Webhook だけでなくsubscription APIを再取得する。refund と credit は別 adjustment であり、live refund が pending approval になり得るため、requested を returned cash としない。
Apple App Store
Section titled “Apple App Store”Apple auto-renewable subscriptionsでは system management UI、renewal、grace、offer、win-back 等を扱う。auto-renew off は通常、current paid period の即時剥奪ではない。server notification 一件でなく、App Store Server APIと latest transaction / renewal info を確認する。
Billing Grace Periodは設定日数と実際の subscription duration による差があり、設定反映にも時間があり得る。固定日数を entitlement code に埋め込まない。Win-back offerの eligibility は、表示・転換・利益・marketing consent の証明ではない。
Apple のaccount deletion guidanceは in-app initiation 等を扱う一方、subscription billing の cancel は別途必要と明示する。account を閉じた local boolean から store renewal を止めたと推論しない。
Google Play
Section titled “Google Play”Google Play subscription lifecycleは voluntary cancellation 後も expiry まで entitlement を維持し、RTDN 後に purchases.subscriptionsv2.get で current state を取得するよう示す。pause、grace、account hold、restore、resubscribe の token / timing は別である。
Cancel APIの stop-renewals と stop-payments、revoke APIの即時 entitlement 剥奪・refund context を同じ cancel command にしない。plan changeは replacement mode が timing / proration を決めるため、「downgradeなら必ずperiod-end」という自社仮定を provider fact にしない。
Google Play account deletion policyは、対象appにin-appの削除開始経路と外部web request pathを求め、associated data、providerへの伝播、retained-data disclosureを扱う。Google Play subscription cancellationとは別actionとして実装し、subscription停止だけをaccount/data deletion完了にしない。
Subscription、account、data、refund を別の完了条件にする
Section titled “Subscription、account、data、refund を別の完了条件にする”separation matrix
Section titled “separation matrix”| 顧客の言葉 | 作る request | 完了に必要な証拠 | 自動で行わないこと |
|---|---|---|---|
| 「更新を止めたい」 | CANCEL_RENEWAL |
renewal off / scheduled end、receipt、remaining access | immediate revoke、refund、account delete |
| 「今すぐ使えなくして返金して」 | cancel + refund の linked requests | authority、effective cancel、access、adjustment、cash status | refund 要求を承認済みにする |
| 「安いplanへ」 | DOWNGRADE |
exact target、price、timing、invoice / entitlement | 全item削除、silent proration |
| 「しばらく休みたい」 | PAUSE |
provider capability、start、resume rule、access / invoice | payment collection pauseをtrue pause扱い |
| 「アカウントを消したい」 | account close + subscription check + data requests | store / PSP renewal、login close、data classごとのreceipt | account flagだけで完了通知 |
| 「データを全部ください」 | EXPORT_DATA |
scope、identity、format、delivery / exception | 日本法上の一般的全データ portability を約束 |
| 「請求がおかしい」 | disputed lifecycle + refund / support case | invoice、consent、effective rule、remedy | retention offer、自動dunning |
日本の個人情報保護法ガイドライン(通則編)では、開示、訂正等、利用停止等、不要となった個人データの消去努力、保存理由や例外をそれぞれ適用事実に照らして扱う。account close = all data delete now でも 会計に必要 = 全データ永久保存 でもない。data class ごとに purpose、legal / dispute / security reason、access、retention end、delete / anonymize receipt を持つ。2026年7月17日公布の改正法は主要部分が未施行で、施行日・政令・規則・経過措置を追跡する。
EU対象市場ではGDPRのArticle 3に照らし、EU内establishment、EU所在者へのgoods / services offering、behavior monitoring等のterritorial scopeを確認してから、access、erasure、portability、storage limitationと、それぞれの根拠・範囲・例外をcurrent factsで扱う。portabilityやerasureを、推論を含む全データの無条件・即時処理へ広げない。
consumer / contract boundary
Section titled “consumer / contract boundary”日本の特定商取引法と消費者庁の通信販売ガイドは、対象取引の最終確認画面で数量、価格・支払、提供時期、申込期間、撤回・解除条件等を一覧的に示し、容易な確認・訂正を可能にする枠組みを持つ。チャット / SNS 型申込でも最終確認規律が問題になり得る。適用除外やB2B該当性があるため、全SaaSへ同じ結論を広げない。
通信販売には特定商取引法上の一般的なクーリング・オフ規定はない。返品特約や商品・特定権利の法定返品等を別に確認し、それらを純粋なSaaSの一律解約権にしない。解約料も常に無効ではなく、消費者契約法上の平均的損害、解除時期、算定根拠等を個別に確認する。
EUのConsumer Rights Directive上の対象遠隔契約のwithdrawalと、将来更新を止めるordinary cancellationは別である。Directive (EU) 2023/2673では加盟国の適用開始が2026-06-19とされるが、online withdrawal functionは法定withdrawal rightがある対象契約と期間に関するもので、全subscriptionの常時one-click cancellationと同義ではない。対象国の実施法を確認する。
action-specific authority matrix
Section titled “action-specific authority matrix”| action | customer / requesterが決めること | provider / operatorが確認・承認すること | 単独でauthorityにしないもの |
|---|---|---|---|
| cancel renewal / downgrade / pause / resume | authenticated actorがexact target・timing・termsを確認 | contract / tenant role、provider capability、idempotent execution | email文面、LLM intent、support reason |
| refund / credit | customerはrequest / disputeと希望scopeを示す | policy / contract / law、amount、principal group、provider approval、cash status | refund request、cancel成功、model confidence |
| account close | authorized ownerがexact account / tenant scopeを確認 | shared resource、admin succession、store / PSP renewal、security hold | login disable、subscription cancel |
| export / delete data | verified requesterがscope / deliveryを示す | data subject / representative authority、data class、retention reason / exception、processor closeout | account close、generic consent、全data即時delete assumption |
| customer message / win-back | customer choice、marketing opt-out、channel preference | current consent / contract、suppression、frequency、rendered claims | provider eligibility、high LTV、past acceptance |
| experiment / live option launch | 対象顧客のexit rightsは固定 | accountable humanがexact cohort、artifact、cap、rollbackを別changeで承認 | SQL decision、eval pass、proposal author |
同じhuman approvalを万能鍵にしない。requester identity、action authority、commercial / privacy / cash owner、provider permissionをactionごとに結び、refund requestをrefund approval、data deletion requestをretention exceptionなしの即時消去へ昇格させない。
米国ではROSCAが対象 online negative-option transaction に material terms の明瞭表示、express informed consent、recurring charge を止める simple mechanism を求める。州・媒体・sector rules は別である。FTC のNegative Option Rule current pageと2026 ANPRMでは2024 amended ruleがvacatedされた現在地を確認できるため、それを施行中の世界共通 click-to-cancel rule として引用しない。
Voluntary exit と involuntary churn を混ぜない
Section titled “Voluntary exit と involuntary churn を混ぜない”| lane | time zero | primary outcome | owner / remedy |
|---|---|---|---|
| voluntary | authenticated cancel / downgrade / pause intent | exact choice fulfilled by promised time | product / billing / support |
| payment recovery | failed renewal / grace / retry state | authorized payment recovered without duplicate / surprise charge | billing / cash / support |
| account compromise | reviewed compromise signal / owner report | victim-safe access and billing restored | security / support |
| provider outage | observed provider / webhook / entitlement incident | state reconciled and customer harm remediated | engineering / provider owner |
| contract non-renewal | notice / term boundary | agreed offboarding, access, data return, final invoice | commercial / legal / data owner |
payment failure を「解約意向」、voluntary cancel を「支払失敗」として同じ dunning / offer queue に入れない。grace 中、account hold、past_due、unpaid、paused は provider ごとの意味を current object と policy から読む。compromised account には coupon ではなく session containment、identity recovery、refund / entitlement remedy が先である。
Options: 何を提案でき、何を証拠にしないか
Section titled “Options: 何を提案でき、何を証拠にしないか”| option | 提示前の必須条件 | 成功と数えないもの |
|---|---|---|
| direct cancel | target、effective time、remaining access、invoice / refund boundary | button click、API 2xx、survey完了 |
| downgrade | exact product / price / seats、timing、proration、lost feature | preview、選択画面表示 |
| pause | true mechanism、billing / access、start / resume、unsupported fallback | pause_collection、support promise |
| support fix | exact incident / issue、response due、exit remains available | ticket作成、謝罪mail |
| bounded discount | eligibility、duration、post-discount price、renewal、margin cap | coupon表示、acceptance、初回authorization |
| win-back | expired / eligible state、channel consent、new terms、new entitlement | provider eligibility、message delivered |
| payment recovery | amount、invoice、retry / consent、grace / access | retry scheduled、provider active |
reason code は product discovery の入口であり、個々の顧客を心理的に最適化する命令ではない。少数の自由記述を「価格が原因 42%」のような母集団推定へ広げず、x/n、multiple choice design、missing / optional、support context、cohort を残す。
win-back は exit を遅らせるためではなく、終了後の適格な顧客へ新しい価値提案を届ける別 journey である。unsubscribe / marketing opt-out、storefront eligibility、contract / consent、frequency cap、support suppression を持ち、reactivation 後の repeat accepted value と matured contribution を追う。
AI / Codex-assisted lifecycle operations
Section titled “AI / Codex-assisted lifecycle operations”任せられること
Section titled “任せられること”- redacted text から primary intent 候補と不足情報を structured output で提案する
- provider / local / invoice / entitlement / data state の差分と missing join を列挙する
- current terms、price、effective time、remaining access から確認画面・receipt draft を作る
- synthetic fixtures、idempotency、event order、reconciliation、accessibility regression を検査する
- reason taxonomy、support queue、matured cohort、cost readout を人のreview用に整形する
NEXT_LIFECYCLE_PROPOSAL_ONLYのdecision packetを作る
任せないこと
Section titled “任せないこと”- 曖昧な会話から無確認で cancel / retain / refund / delete を選ぶ
- live subscription、invoice、entitlement、account、data、marketing consent を変更する
- private contract、本人確認資料、payment credential、raw support attachmentをpromptへ入れる
- provider stateから法的権利、本人authority、refund eligibilityを確定する
- high-value顧客だけexitを難しくする、vulnerable customerをdiscountへ誘導する
- eval passやmodel confidenceをhuman approval / customer confirmationの代替にする
OpenAI の agent guideは layered guardrails、tool risk、failure threshold、高リスク・不可逆 action への human intervention を説明し、cancel order、large refund、payment を例に挙げる。Evaluation best practicesに沿って representative case、edge case、continuous eval を持っても、それは live action authority ではない。
顧客文、添付、provider response、retrieved terms は untrusted input とする。OWASP LLM Prompt Injection PreventionとAI Agent Securityを使い、read-only tool、least privilege、structured output、parameter-bound human approval、idempotency、audit trail、timeout、fail closed を置く。agentには proposal tool と execution tool を同時に与えない。
Measurement: safety gate の後だけ economics を読む
Section titled “Measurement: safety gate の後だけ economics を読む”customer-safety gates
Section titled “customer-safety gates”direct_exit_reachability_rate= frozen eligible lifecycle intents shown an enabled direct action and able to reach exact confirmation without a forced survey, support diversion, loop, or error / all frozen eligible lifecycle intents
preconfirmation_failure_rate= frozen eligible lifecycle intents with a technical, accessibility, wrong-target, forced-diversion, or policy failure before confirmation / all frozen eligible lifecycle intents
intent_fulfillment_rate= mature confirmed requests completed exactly as confirmed and by promised due time / all mature confirmed requests
unexpected_charge_rate= mature requests with a post-effective undisclosed or unauthorized charge / mature confirmed requests that could incur a charge
early_access_loss_rate= requests losing paid / committed access before the disclosed end / requests with remaining entitlement
data_closeout_completion_rate= due exports / deletions / retained-data notices completed / all due data-closeout obligationseligible→direct action rendered→confirmation opportunity→confirmed / explicit withdrawal / unclassified abandonment / failure→fulfilled のarm別funnelを残す。abandonmentを自動的にfailureやretainedへせず、unclassified / missingがcapを超えればUNKNOWNにする。必ずabsolute x/n とfailure caseを併記する。confirmation mail sent、provider API 2xx、portal redirect、Webhook delivered、scheduled change、local flagは、exact outcomeの検証なしにnumeratorへ入れない。
primary economic readout
Section titled “primary economic readout”matured_customer_safe_contribution= settled recurring cash attributable to the follow-up window - refund and credit actually applied - PSP / store / MoR fee - indirect tax collected for others - variable infra / AI / data / notification cost - offer / discount cost - support and founder time at declared internal cost - migration / remediation / unexpected-charge cost
delta_per_eligible_intent= candidate contribution / candidate frozen eligible intents - reference contribution / reference frozen eligible intents不均等割付やcluster / stratified designはpredeclared weightingとanalysis unitを使い、candidate件数だけでtotal differenceを割らない。voluntary / involuntary、new / existing、B2B / B2C、provider / route、intent classを混ぜない。settled cashをinvoice、authorization、provider balanceと取り違えず、refund / credit / chargebackのprincipalを二重控除しない。continued paymentとrepeated accepted valueを別driverにする。
fully synthetic arithmetic example
Section titled “fully synthetic arithmetic example”これは算術とdecision contractを検査する架空例であり、20件、金額、14日、差分は実績・期待値・推奨値ではない。両armに20件ずつfrozen eligible intentがあり、全件がmatured、safety gate合格、cash / cost照合済みと仮定する。
| component | reference | candidate | candidate - reference |
|---|---|---|---|
| frozen eligible / matured intents | 20 / 20 | 20 / 20 | 0 |
| direct exit reached / pre-confirmation failure | 20 / 0 | 20 / 0 | 0 |
| settled follow-up recurring cash | ¥160,000 | ¥205,000 | +¥45,000 |
| refund / credit | -¥8,000 | -¥10,000 | -¥2,000 |
| PSP / store / MoR fee | -¥12,000 | -¥15,000 | -¥3,000 |
| variable infra / AI / notification | -¥20,000 | -¥24,000 | -¥4,000 |
| offer / discount | ¥0 | -¥18,000 | -¥18,000 |
| support / founder time | -¥32,000 | -¥30,000 | +¥2,000 |
| remediation / unexpected charge | ¥0 | ¥0 | ¥0 |
| matured customer-safe contribution | ¥88,000 | ¥108,000 | +¥20,000 |
| contribution per eligible intent | ¥4,400 | ¥5,400 | +¥1,000 |
candidate の利益が高くても、unexpected charge 一件、paid access の早期剥奪、broken exit、unresolved data closeout、active incident、live authority 昇格を相殺しない。この例は option が差分を原因として作った証拠でもない。
claim ladder
Section titled “claim ladder”| claim | 必要な設計 | 言えること |
|---|---|---|
| descriptive | frozen request spine、maturity、reconciliation | intent fulfillment、x/n、cash、cost、reason distribution |
| association | time zero とcohort差を明示 | offer accepted / reactivated群との関連。selectionを残す |
| causal candidate | direct exitは全arm同一、optional optionだけpredeclared assignment、ITT、integrity | exact population / window のbounded effect candidate |
| scale decision | causal evidence + safety / capacity / cash + rollback | 次versionを提案できる。live authorityではない |
cancel できるか、required notice / refund / exportを受けられるか、unauthorized chargeを避けられるかをrandomizeしない。treatmentをoffer clickedやcoupon acceptedに後付けせずoriginal assignmentで読む。小標本はx/n、absolute difference、uncertainty、missingness、late eventsを示し、短期saveからannual LTVを外挿しない。
Decision state と authority
Section titled “Decision state と authority”STOP_AND_REMEDIATE> PAUSE> UNKNOWN> FIX_LIFECYCLE> MAINTAIN> PROPOSE_BOUNDED_OPTION| state | 代表条件 | work order |
|---|---|---|
STOP_AND_REMEDIATE |
unexpected / unauthorized charge、broken cancellation、early access loss、account/subscription混同、privacy/security incident、live authority | STOP_AND_REMEDIATE_CUSTOMER_HARM。影響顧客、charge、access、dataを人が修復 |
PAUSE |
incident未封じ込め、provider / policy / terms source stale、新assignmentを安全に受けられない | PAUSE_NEW_ASSIGNMENT。current customer obligationを優先 |
UNKNOWN |
maturity、authoritative state、join、cash、data closeout、signature不足 | COLLECT_MISSING_EVIDENCE。missingを0にしない |
FIX_LIFECYCLE |
direct exit / accessibility / fulfillment / support capacity cap違反、成熟後delta負 | FIX_LIFECYCLE_BEFORE_OPTIONS |
MAINTAIN |
current pathはsafeでchangeを支持するdecision-relevant evidenceなし | MAINTAIN_CURRENT_LIFECYCLE |
PROPOSE_BOUNDED_OPTION |
全gate合格、exact snapshot review、positive bounded evidence、proposal-only | PROPOSE_NEXT_LIFECYCLE_VERSION |
positive stateでもauthority_cap = NEXT_LIFECYCLE_PROPOSAL_ONLY、live_action_authority = NONEである。provider cancel / pause / resume、refund / credit、entitlement change、account close、data delete、customer message、offer launch、experiment assignmentは、上のaction-specific matrixに従うexact customer/requester authorityと、必要なoperator / policy / provider approvalを別receiptで満たす。どちらか一方を万能な代替にしない。
14-day fully synthetic rehearsal
Section titled “14-day fully synthetic rehearsal”| day | action | exit evidence |
|---|---|---|
| 0 | contract、intent、provider / route、direct exit、reference / candidate、caps、maturityを凍結 | version、owner、authority、rollback |
| 1 | current terms / offer / provider capability snapshot | source URL、checked_at、account / plan caveat |
| 2 | seven-plane schema と request / retry identity | no boolean collapse、FK / append-only |
| 3 | cancel / downgrade / pause / refund / deletionのsynthetic happy paths | scheduled / effective / verified clocks |
| 4 | unexpected charge、early access loss、wrong target、duplicate command | idempotency、STOP receipts、remedy owner |
| 5 | Webhook duplicate / reverse / stale / missed delivery | current object reread、reconciliation |
| 6 | Stripe / Paddle / Apple / Google mapping review | provider-specific transition table |
| 7 | keyboard、focus、label、error、confirmation、support fallback | end-to-end accessibility evidence |
| 8 | voluntary / involuntary / compromise lane split | separate denominator / owner |
| 9 | export / deletion / retained-data closeout | data class、due、reason、receipt |
| 10 | optional offer assignment と direct-exit parity | ITT spine、no coercive variant |
| 11 | cash / refund / fee / offer / support / remediation rollup | principal exclusivity、bank / provider join |
| 12 | maturity snapshot、missing / late correction | frozen cutoff、新snapshot rule |
| 13 | 14decision fixture とmutation probe | precedence、authority、immutability |
| 14 | independent review とbounded proposal | exact SHA、signature ref、NONE authority |
実データへ進む前に、retention / cancellation / win-back packを複製し、fully synthetic SQLite companionを実行する。rehearsal はschema、算術、state、handoffを検査するだけで、顧客の支払意思、法的充足、provider本番信頼性、retention upliftを証明しない。
Codex handoff contract
Section titled “Codex handoff contract”You may:- inspect redacted lifecycle events, schemas, provider docs and synthetic fixtures;- draft state mappings, UI copy, receipts, reconciliation queries and tests;- compute matured customer-safe contribution from approved components;- flag missing, stale, wrong-target, early-access, unexpected-charge, duplicate-principal, unresolved-closeout and authority failures;- produce NEXT_LIFECYCLE_PROPOSAL_ONLY.
You must not:- ingest payment credentials, secrets, identity documents, private contracts, raw support attachments or unnecessary personal data;- infer legal rights, actor authority, refund eligibility or customer intent;- mutate live subscriptions, invoices, entitlements, accounts, data, consent, offers, messages or experiment assignments;- treat webhook receipt, API 2xx, provider status or eval pass as completion;- exceed live_action_authority = NONE.repository では contract、provider mapping、UI revision、terms / offer、event schema、test、accessibility、rollback、decision snapshot を同じ change ID へ結ぶ。source checked_at、provider API version、artifact SHA、reviewer、signature refがずれたら UNKNOWN または PAUSE に戻す。
Limitations and robustness
Section titled “Limitations and robustness”- cancellation reason は低いvalue、budget、seasonality、組織変更、support failure、競合、事業終了等の入口であり、lifecycle optionがroot causeとは限らない。
- churn / win-back cohortはsignal後に選ばれている。全active customerとの単純比較やaccepted-offer群だけの比較から因果効果を主張しない。
- provider feature、status、retry、grace、pause、proration、refund、API、store policyは変わる。docsだけでなくcurrent account / sandbox / test clock / authoritative readで確認する。
- B2B authority、minimum term、notice、early termination、data return、seat、invoice、renewalはcontract-specificである。consumer UIをそのまま適用しない。
- 日本、EU、米国連邦・州、store policyは同じ規則ではない。withdrawal、ordinary cancellation、account deletion、data erasureを分ける。
- data deletionと会計・税・security・fraud・dispute・legal retentionは衝突し得る。data class、purpose、access、reason、expiryをreviewする。
- 14日でrenewal、refund、chargeback、win-backが成熟しないことがある。期間を延長するか historical cohort を使い、
UNKNOWNのまま止める。 - support / founder time、lost contribution、future repeat valueには不確実性がある。宣言したinternal rate、range、sensitivityを示し、無料扱いしない。
- SQLite companionはsynthetic row、constraint、query、expected decisionを検査する。本番storageのappend-only耐久性、cryptographic identity / signature、provider API、法律、顧客結果を証明しない。
- chart は掲載しない。実測時系列や分布がなく、synthetic count の図示はbenchmarkや経験的傾向を暗示するため、exact mappingと算術表を使う。
Recommendations
Section titled “Recommendations”- 今週、一つのproduct / provider / routeと、一つのprimary intentだけを選ぶ。
- 顧客意思、commercial renewal、provider、invoice、entitlement、account/data、supportを別stateにする。
- direct exitをend-to-endでkeyboard / focus / confirmation / receiptまで検査し、optionより先に直す。
- provider command後にcurrent objectを再取得し、entitlementとinvoiceを冪等に再導出する。
- subscription cancel、account close、data deletion、refundをlinked requestとして分離する。
- voluntary exit、payment recovery、compromise、provider incidentを別denominator / ownerにする。
- optional optionだけをbounded assignmentし、全armのexit rightsとrequired noticeを同じにする。
- safety gate合格後にだけmatured customer-safe contributionを読み、proposal-onlyでhumanへ渡す。
Further questions
Section titled “Further questions”- 顧客が「解約」と言ったとき、renewal stop、immediate revoke、refund、account deleteのどれを確認しているか。
- providerのscheduled stateとlocal
access_untilが食い違ったとき、どちらを止め、誰が何分で修復するか。 - cancel後に発生し得るusage、open invoice、proration、refund、creditを事前に正確に表示できるか。
- account deletion前にstore / PSP subscriptionの継続を検知できるか。
- data classごとのexport、delete、retain reason、access、expiry、customer noticeがあるか。
- pauseはtrue subscription pauseか、collection pauseか、単なるsupport promiseか。
- direct exitを使った群だけ、support負荷や再入力、accessibility failureが増えていないか。
- saved customerはrepeat accepted valueを得たか、それとも支払いだけが残ったか。
- optional offerを外してもreferenceより良いのか。offer cost、support、refundを引いたか。
- next lifecycle versionが失敗したとき、exact config / UI / policyを誰が戻し、顧客harmをどうremedyするか。
この問いへ証拠付きで答えられない場合、必要なのは高度な churn model ではない。まず direct exit、state separation、current-state reconciliation、customer-visible receipt、data closeout、proposal-only authority を整える。