コンテンツにスキップ

顧客保護型の解約・downgrade・pause・win-back を、利用権・cash・データまで閉じる

  • retention の前に exit integrity を測る。 顧客が選んだ cancel / downgrade / pause / resume / export / delete / refund を、約束した時刻と条件どおりに完了できなければ、saved MRR や win-back 売上を読まない。迷わせた継続課金は retention ではない。
  • 一つの subscription_status に潰さない。 顧客意思、更新予定、provider 契約、invoice / payment、利用権、refund / credit、account、export / deletion / retention、support case は別 state と別時計で持つ。Webhook は通知であり、利用権や銀行着金そのものではない。
  • direct exit と optional option を同じボタン競争にしない。 退出経路は明確・到達可能・確認可能に保ち、pause、downgrade、support、discount は選択可能な別提案にする。提示しない群を作っても、取消可能性や必要表示を弱めない。
  • provider ごとの差を entitlement policy で吸収する。 Stripe の period-end cancel と pause_collection、Paddle の scheduled_change、Apple の auto-renew off、Google Play の canceled-but-entitled / pause / account hold は同じ意味ではない。provider の現在状態を再取得し、自社の access_until を冪等に再計算する。
  • primary は matured customer-safe contribution delta である。 同じ frozen eligible intent を分母に、settled cash から refund / fee / variable cost / offer / support / remediation を引く。ただし unexpected charge、early access loss、broken exit、data closeout failure、incident は平均利益で相殺しない。
  • Codex / AI は分類・差分・draft・照合まで。 解約、返金、data deletion、live offer、顧客連絡を自律実行させない。この release の実行上限は NEXT_LIFECYCLE_PROPOSAL_ONLY、live_action_authority = NONE である。

基準日: 2026-08-03
対象: Web app、subscription、mobile app、API / AI feature を一人または小規模で運用する technical founder
判断単位: seller × product / contract × route / jurisdiction × primary intent × frozen eligible cohort × assigned lifecycle revision × effective window × maturity rule
primary metric: matured_customer_safe_contribution_delta_per_eligible_intent

本章は product、billing、support、計測、運用の一般教材であり、個別の法務・税務・会計・決済助言ではない。B2C / B2B、地域、契約、store、決済 provider、商品、最低利用期間、返金、個人データ、会計・税・紛争保存に応じて専門家と確認する。

本文、運用パック、SQLite companion の顧客、subscription、intent、金額、offer、incident、review はすべて fully synthetic である。実績、save-rate benchmark、推奨 discount、普遍的な pause 期間、法的結論ではない。個人情報、payment credential、private contract、support 添付を公開物や生成 AI prompt に入れない。

Findings: churn 対策と正しい終了処理の間に空白がある

Section titled “Findings: churn 対策と正しい終了処理の間に空白がある”

既存章は acquisition、pricing、retention、analytics、cash、migration を扱う。本章はそれらを置き換えず、intent → provider → entitlement → cash → data closeout → maturity → decision の接続だけを正本にする。

正本 既存章が受け持つこと 本章が追加する接続
02章 subscription economics、churn、LTV、unit economics saved MRR を customer-safe cash contribution へ変換する
03章 friction、choice architecture、accessibility、dark pattern direct exit と optional option、確認、取消、redress
05章 Webhook、冪等、billing、observability、incident scheduled / effective / entitlement / cash / closeout の複数時計
06章 privacy、terms、特商法、account deletion subscription、account、data request、retention reason の分離
11章 B2B authority、pilot、renewal、SLA authorized requester、notice、commitment、data return の契約差
12章 repeat value、AI cost、retention 継続課金を repeat accepted value と取り違えない
19章 time zero、ITT、maturity、uncertainty churn-selected cohort、offer assignment、exit harm の固有 gate
21章 invoice、refund、provider balance、bank cash lifecycle cohort の settled cash / cost を一度だけ引き渡す
23章 price / package / terms、通知・同意、既存顧客移行 downgrade / discount 後の exact offer、invoice、entitlement
25章 payment recovery、account compromise、appeal / restore 自主退出と involuntary churn、正当な recovery を分母から分ける

intent、reason、state、outcome を同義語にしない

Section titled “intent、reason、state、outcome を同義語にしない”
語 この章での意味 単独では言えないこと
PRIMARY INTENT 顧客が今完了したい一つの action churn reason、最適 offer、法的 authority
REASON 任意回答、support note、観測された文脈 真因、将来行動、discount eligibility
SCHEDULED CHANGE period-end cancel / downgrade 等の将来予定 既に effective、返金済み、利用権失効
PROVIDER STATUS provider が持つ subscription / transaction state 自社 app の認可、銀行現金、全 data closeout
ENTITLEMENT product / feature / seat / data への利用権と期限 invoice が支払済み、auto-renew が on
REFUND / CREDIT 現金返金、残高減額、invoice 調整等の別 ledger subscription 終了、銀行着金、同じ principal の再控除
ACCOUNT CLOSE login / tenant / service account の閉鎖 store subscription の停止、全データ即時消去
DATA CLOSEOUT export、削除、匿名化、保存理由・期限・access の処理 subscription cancel と同時完了、無条件の全削除
RETAINED / REACTIVATED 事前定義した期間の継続または再開 repeat value、因果 uplift、利益、永続 retention
MATURED predeclared follow-up と必要な照合が完了 将来の refund / dispute が絶対にない

顧客の文を最初から churn score に変換しない。次の primary intent のどれを今求めているかを確認する。

CANCEL_RENEWAL | CANCEL_IMMEDIATE | DOWNGRADE | PAUSE | RESUME
REACTIVATE | EXPORT_DATA | DELETE_ACCOUNT | DELETE_DATA
REFUND_REQUEST | PAYMENT_RECOVERY | MARKETING_OPT_OUT

一つの request は一つの primary intent を持つ。たとえば「解約してデータも消したい」は、subscription cancel と account / data closeout を別 request に分け、共通の customer-visible case reference で結ぶ。片方の成功をもう片方の成功にしない。

plane minimum state authoritative evidence
customer authority / intent requested、confirmed、withdrawn、disputed authenticated actor、role、exact choice、confirmation revision
commercial renewal renew on/off、notice、commitment、scheduled change current contract / offer / terms、effective rule
provider subscription active、trialing、past_due、paused、canceled、expired 等 current provider object / transaction / renewal info
invoice / payment / adjustment open、paid、retry、hold、refund pending/paid/failed、credit invoice / transaction / adjustment + bank / provider reconciliation
entitlement current product / seats / feature、access_until、revoked local authorization ledger + provider / contract policy
account / data login open/closed、export due/delivered、delete due/completed、retained class identity receipt、data job、retention schedule / reason / access
communication / support notice due/sent/delivered、case open/resolved、appeal rendered message revision、delivery、case / remedy receipt

active、canceled、paused の一語から他 plane を埋めない。provider status は自社の entitlement 判定への入力であり、認可判定そのものではない。

retention_lifecycle_contract_id / contract_version:
seller / product / contract / offer revision:
route / provider / storefront / jurisdiction / customer class:
primary intent / authorized actor / confirmation revision:
direct exit path / accessibility review / support fallback:
reference lifecycle / candidate optional intervention / assignment:
eligibility freeze / time zero / effective rule / follow-up / maturity:
intent fulfillment floor / unexpected charge cap / early access loss cap:
data closeout floor / support capacity cap / incident veto:
economics components / FX / internal time cost / reconciliation threshold:
provider owner / entitlement owner / cash owner / data owner / support owner:
rollback / remedy / source checked_at / independent reviewer:
authority_cap: NEXT_LIFECYCLE_PROPOSAL_ONLY
live_action_authority: NONE

contract ID は join key であって合法性や安全性を作らない。provider、store policy、terms、offer、effective rule、entitlement policy、data retention、assignment、maturity、cap、owner のどれかを変えたら version を上げ、古い承認を継承しない。

eligibility grain と confirmed request を分ける

Section titled “eligibility grain と confirmed request を分ける”
eligible_lifecycle_intent_id
= one authenticated actor
× one target subscription / account / data scope
× first eligible entry into the lifecycle path
× before option assignment or outcome
lifecycle_request_id
= one authenticated actor
× one target subscription / account / data scope
× one primary intent
× one exact confirmed choice revision

eligible_lifecycle_intent_id はconfirmation前のerror、loop、forced support、accessibility failure、unclassified abandonmentを分母に残すspineである。confirmationに到達した対象だけをeligibleにしない。lifecycle_request_id はexact choice確認後に作り、両者を一対一または明示したlinked relationで結ぶ。

単なるsettings page view、survey start、support message、Webhook eventをintent / request件数へ増幅しない。eligibility入口はpredeclaredなauthenticated action(例: direct exit entry)に固定する。retryはeligible_lifecycle_intent_id + attempt_sequence、confirmation後はlifecycle_request_id + attempt_sequenceで結び、同じ顧客が複数subscriptionを持つときは対象を明示する。

Methodology: direct exit を基盤、option を別の実験にする

Section titled “Methodology: direct exit を基盤、option を別の実験にする”
authenticated intent intake
→ exact target / authority / current terms を表示
→ direct requested action と optional alternative を並列に保持
→ customer confirms one exact action
→ provider command with idempotency key
→ current provider state reread
→ entitlement / invoice / data jobs derived separately
→ customer-visible receipt with effective time and remaining obligations
→ reconciliation / remedy / maturity

安全な cancellation flow は「offer を見せない」ことではない。次を同時に満たすことである。

  • direct exit は常に識別でき、keyboard、focus、label、error、review / correction を含む end-to-end process として到達できる。
  • option は NO THANKS / CONTINUE EXIT を持ち、拒否で不利益や再入力を増やさない。
  • countdown、false scarcity、選択済み add-on、曖昧な二重否定、support だけの隠れた経路を使わない。
  • discount、pause、downgrade の price、期間、終了後 price、自動更新、利用権、次回請求を action 前に示す。
  • 顧客が cancel を選んだ後、survey 回答や担当者との交渉を完了条件にしない。reason は任意で別 evidence にする。
  • 法定・契約上必要な notice、refund、export、withdrawal を experiment の variant にしない。

WCAG 2.2は keyboard、focus、target size、labels / errors、認証支援、法的・金銭的・データ変更の review / correction 等を扱う。適合は cancel button 一個でなく、認証からreceiptまでの process 全体で確認する。W3C Ethical Web Principlesは利用者の主体性・透明性・privacy と manipulative design の抑制を高位原則として示すが、法律や適合規格そのものではない。

append-only event spine と as-of snapshot

Section titled “append-only event spine と as-of snapshot”
ELIGIBLE_INTENT_FROZEN
→ AUTHORITY_AND_TARGET_VERIFIED
→ EXACT_CHOICE_CONFIRMED
→ PROVIDER_COMMAND_REQUESTED / ACCEPTED / FAILED
→ PROVIDER_CURRENT_STATE_OBSERVED
→ ENTITLEMENT_DERIVED / APPLIED / VERIFIED
→ INVOICE / REFUND / CREDIT / CASH RECONCILED
→ EXPORT / DELETION / RETENTION CLOSEOUT
→ VALUE / SUPPORT / COST FOLLOW-UP
→ MATURITY_SNAPSHOT
→ INDEPENDENT REVIEW
→ LIFECYCLE DECISION

event は occurred_at / effective_at / observed_at / recorded_at を分ける。period-end cancel は requested と effective が違い、refund requested と funds returned も違う。snapshot は recorded_at <= cutoff の revision だけを読み、後から届いた backdated event で過去判断を黙って書き換えない。late evidence は新しい snapshot で再評価する。

Webhook は署名確認、event ID dedupe、非同期 retry、object 再取得、transition validation、business idempotency を経る。provider command の HTTP 2xx や event 受信は、local entitlement、receipt delivery、bank cash の完了証拠ではない。

scheduled、effective、verified を別時計にする

Section titled “scheduled、effective、verified を別時計にする”
action scheduled evidence effective evidence closeout evidence
period-end cancel renewal off / scheduled change provider ended at period end no unexpected renewal + correct access end
immediate cancel accepted immediate termination provider terminal state access / invoice / refund / remedy reconciled
downgrade target price / product + effective rule target subscription current entitlement and invoice match disclosed preview
pause exact pause mechanism + start / resume rule provider / local paused state invoice and access follow chosen policy
resume / reactivate target offer and billing start provider active / new transaction payment and entitlement verified
refund adjustment requested / approved provider refund completed original rail / bank outcome and principal exclusivity
data deletion scope / due / retention exception job completed per class retained-data notice, access restriction, expiry

missing、not due、pending、late、failed、disputed、unknown link を0や成功へ変換しない。

Provider reality: 四つの billing model を一つにしない

Section titled “Provider reality: 四つの billing model を一つにしない”

Provider feature、plan、API version、storefront、policy は変わる。以下は2026-08-03時点の一次資料を設計境界として整理したものであり、実装時に current account / docs / sandbox で再確認する。

provider cancel / change pause / recovery 実装時の非推論ルール
Stripe cancel_at_period_end=true は期間末まで継続し、実終了前なら撤回可能。設定時は updated、実終了時は deleted。即時 cancel 後の再開は新規 subscription 真の subscription pause は cited state では Private Preview。pause_collection は invoice を生成し subscription は active のまま cancel から refund、未請求 usage、pending invoice item、open invoice、entitlement を推論しない
Paddle period-end cancel は scheduled_change を持ち active のまま、期日に canceled。API は immediate も選択でき、canceled は terminal period-end / immediate pause、resume billing mode がある。paused 中の access は seller policy。portal self-service pause の可否は current feature を確認 status、scheduled change、transaction、refund / credit、access を別にする
Apple App Store auto-renew off 後も原則 current period end まで利用。upgrade / crossgrade / downgrade の effective timing が異なる grace、billing retry、win-back eligibility がある。一般的な subscription pause と download pause を混同しない notification、renewal state、transaction、family sharing、refund / revoke を再取得して entitlement を判断
Google Play SUBSCRIPTION_CANCELED 後も expiryTime まで entitlement を維持。cancel type、restore、revoke は別 pause は対応 plan / setting で period end 後に発効。grace 中は access、account hold 中は停止。RTDN 後に API reread canceled を即時 revoke にせず、日数を hard-code せず、new purchase token を local account と結ぶ

Stripe の cancellationは即時、期間末、指定時刻と、その後の invoice item / metered usage / refund・proration の関係を分ける。Customer Portalは cancellation、period-end resume、同一 Product 内の Price change、reason 等を構成でき、cancellation pageでは任意の coupon 提示も扱う。feature があることは公正な設計、利益、因果 save を保証しない。

Pause a subscriptionの真の pause と、pause payment collectionを同じ paused=true にしない。後者は invoice を生成し、subscription status が active のままになり得る。Webhook guidanceを入口に current object を再取得し、access_until と invoice / adjustment を再計算する。

Paddle cancelは immediate と next billing period、terminal canceled、scheduled_change を区別する。Pause / resumeは timing と billing mode を持ち、paused 中の limited access は自社判断である。Upgrade / downgradeは item replacement と proration mode を必要とし、preview は確認材料であって最終請求や顧客同意そのものではない。

Webhook だけでなくsubscription APIを再取得する。refund と credit は別 adjustment であり、live refund が pending approval になり得るため、requested を returned cash としない。

Apple auto-renewable subscriptionsでは system management UI、renewal、grace、offer、win-back 等を扱う。auto-renew off は通常、current paid period の即時剥奪ではない。server notification 一件でなく、App Store Server APIと latest transaction / renewal info を確認する。

Billing Grace Periodは設定日数と実際の subscription duration による差があり、設定反映にも時間があり得る。固定日数を entitlement code に埋め込まない。Win-back offerの eligibility は、表示・転換・利益・marketing consent の証明ではない。

Apple のaccount deletion guidanceは in-app initiation 等を扱う一方、subscription billing の cancel は別途必要と明示する。account を閉じた local boolean から store renewal を止めたと推論しない。

Google Play subscription lifecycleは voluntary cancellation 後も expiry まで entitlement を維持し、RTDN 後に purchases.subscriptionsv2.get で current state を取得するよう示す。pause、grace、account hold、restore、resubscribe の token / timing は別である。

Cancel APIの stop-renewals と stop-payments、revoke APIの即時 entitlement 剥奪・refund context を同じ cancel command にしない。plan changeは replacement mode が timing / proration を決めるため、「downgradeなら必ずperiod-end」という自社仮定を provider fact にしない。

Google Play account deletion policyは、対象appにin-appの削除開始経路と外部web request pathを求め、associated data、providerへの伝播、retained-data disclosureを扱う。Google Play subscription cancellationとは別actionとして実装し、subscription停止だけをaccount/data deletion完了にしない。

Subscription、account、data、refund を別の完了条件にする

Section titled “Subscription、account、data、refund を別の完了条件にする”
顧客の言葉 作る request 完了に必要な証拠 自動で行わないこと
「更新を止めたい」 CANCEL_RENEWAL renewal off / scheduled end、receipt、remaining access immediate revoke、refund、account delete
「今すぐ使えなくして返金して」 cancel + refund の linked requests authority、effective cancel、access、adjustment、cash status refund 要求を承認済みにする
「安いplanへ」 DOWNGRADE exact target、price、timing、invoice / entitlement 全item削除、silent proration
「しばらく休みたい」 PAUSE provider capability、start、resume rule、access / invoice payment collection pauseをtrue pause扱い
「アカウントを消したい」 account close + subscription check + data requests store / PSP renewal、login close、data classごとのreceipt account flagだけで完了通知
「データを全部ください」 EXPORT_DATA scope、identity、format、delivery / exception 日本法上の一般的全データ portability を約束
「請求がおかしい」 disputed lifecycle + refund / support case invoice、consent、effective rule、remedy retention offer、自動dunning

日本の個人情報保護法ガイドライン(通則編)では、開示、訂正等、利用停止等、不要となった個人データの消去努力、保存理由や例外をそれぞれ適用事実に照らして扱う。account close = all data delete now でも 会計に必要 = 全データ永久保存 でもない。data class ごとに purpose、legal / dispute / security reason、access、retention end、delete / anonymize receipt を持つ。2026年7月17日公布の改正法は主要部分が未施行で、施行日・政令・規則・経過措置を追跡する。

EU対象市場ではGDPRのArticle 3に照らし、EU内establishment、EU所在者へのgoods / services offering、behavior monitoring等のterritorial scopeを確認してから、access、erasure、portability、storage limitationと、それぞれの根拠・範囲・例外をcurrent factsで扱う。portabilityやerasureを、推論を含む全データの無条件・即時処理へ広げない。

日本の特定商取引法と消費者庁の通信販売ガイドは、対象取引の最終確認画面で数量、価格・支払、提供時期、申込期間、撤回・解除条件等を一覧的に示し、容易な確認・訂正を可能にする枠組みを持つ。チャット / SNS 型申込でも最終確認規律が問題になり得る。適用除外やB2B該当性があるため、全SaaSへ同じ結論を広げない。

通信販売には特定商取引法上の一般的なクーリング・オフ規定はない。返品特約や商品・特定権利の法定返品等を別に確認し、それらを純粋なSaaSの一律解約権にしない。解約料も常に無効ではなく、消費者契約法上の平均的損害、解除時期、算定根拠等を個別に確認する。

EUのConsumer Rights Directive上の対象遠隔契約のwithdrawalと、将来更新を止めるordinary cancellationは別である。Directive (EU) 2023/2673では加盟国の適用開始が2026-06-19とされるが、online withdrawal functionは法定withdrawal rightがある対象契約と期間に関するもので、全subscriptionの常時one-click cancellationと同義ではない。対象国の実施法を確認する。

action customer / requesterが決めること provider / operatorが確認・承認すること 単独でauthorityにしないもの
cancel renewal / downgrade / pause / resume authenticated actorがexact target・timing・termsを確認 contract / tenant role、provider capability、idempotent execution email文面、LLM intent、support reason
refund / credit customerはrequest / disputeと希望scopeを示す policy / contract / law、amount、principal group、provider approval、cash status refund request、cancel成功、model confidence
account close authorized ownerがexact account / tenant scopeを確認 shared resource、admin succession、store / PSP renewal、security hold login disable、subscription cancel
export / delete data verified requesterがscope / deliveryを示す data subject / representative authority、data class、retention reason / exception、processor closeout account close、generic consent、全data即時delete assumption
customer message / win-back customer choice、marketing opt-out、channel preference current consent / contract、suppression、frequency、rendered claims provider eligibility、high LTV、past acceptance
experiment / live option launch 対象顧客のexit rightsは固定 accountable humanがexact cohort、artifact、cap、rollbackを別changeで承認 SQL decision、eval pass、proposal author

同じhuman approvalを万能鍵にしない。requester identity、action authority、commercial / privacy / cash owner、provider permissionをactionごとに結び、refund requestをrefund approval、data deletion requestをretention exceptionなしの即時消去へ昇格させない。

米国ではROSCAが対象 online negative-option transaction に material terms の明瞭表示、express informed consent、recurring charge を止める simple mechanism を求める。州・媒体・sector rules は別である。FTC のNegative Option Rule current pageと2026 ANPRMでは2024 amended ruleがvacatedされた現在地を確認できるため、それを施行中の世界共通 click-to-cancel rule として引用しない。

Voluntary exit と involuntary churn を混ぜない

Section titled “Voluntary exit と involuntary churn を混ぜない”
lane time zero primary outcome owner / remedy
voluntary authenticated cancel / downgrade / pause intent exact choice fulfilled by promised time product / billing / support
payment recovery failed renewal / grace / retry state authorized payment recovered without duplicate / surprise charge billing / cash / support
account compromise reviewed compromise signal / owner report victim-safe access and billing restored security / support
provider outage observed provider / webhook / entitlement incident state reconciled and customer harm remediated engineering / provider owner
contract non-renewal notice / term boundary agreed offboarding, access, data return, final invoice commercial / legal / data owner

payment failure を「解約意向」、voluntary cancel を「支払失敗」として同じ dunning / offer queue に入れない。grace 中、account hold、past_due、unpaid、paused は provider ごとの意味を current object と policy から読む。compromised account には coupon ではなく session containment、identity recovery、refund / entitlement remedy が先である。

Options: 何を提案でき、何を証拠にしないか

Section titled “Options: 何を提案でき、何を証拠にしないか”
option 提示前の必須条件 成功と数えないもの
direct cancel target、effective time、remaining access、invoice / refund boundary button click、API 2xx、survey完了
downgrade exact product / price / seats、timing、proration、lost feature preview、選択画面表示
pause true mechanism、billing / access、start / resume、unsupported fallback pause_collection、support promise
support fix exact incident / issue、response due、exit remains available ticket作成、謝罪mail
bounded discount eligibility、duration、post-discount price、renewal、margin cap coupon表示、acceptance、初回authorization
win-back expired / eligible state、channel consent、new terms、new entitlement provider eligibility、message delivered
payment recovery amount、invoice、retry / consent、grace / access retry scheduled、provider active

reason code は product discovery の入口であり、個々の顧客を心理的に最適化する命令ではない。少数の自由記述を「価格が原因 42%」のような母集団推定へ広げず、x/n、multiple choice design、missing / optional、support context、cohort を残す。

win-back は exit を遅らせるためではなく、終了後の適格な顧客へ新しい価値提案を届ける別 journey である。unsubscribe / marketing opt-out、storefront eligibility、contract / consent、frequency cap、support suppression を持ち、reactivation 後の repeat accepted value と matured contribution を追う。

  • redacted text から primary intent 候補と不足情報を structured output で提案する
  • provider / local / invoice / entitlement / data state の差分と missing join を列挙する
  • current terms、price、effective time、remaining access から確認画面・receipt draft を作る
  • synthetic fixtures、idempotency、event order、reconciliation、accessibility regression を検査する
  • reason taxonomy、support queue、matured cohort、cost readout を人のreview用に整形する
  • NEXT_LIFECYCLE_PROPOSAL_ONLY のdecision packetを作る
  • 曖昧な会話から無確認で cancel / retain / refund / delete を選ぶ
  • live subscription、invoice、entitlement、account、data、marketing consent を変更する
  • private contract、本人確認資料、payment credential、raw support attachmentをpromptへ入れる
  • provider stateから法的権利、本人authority、refund eligibilityを確定する
  • high-value顧客だけexitを難しくする、vulnerable customerをdiscountへ誘導する
  • eval passやmodel confidenceをhuman approval / customer confirmationの代替にする

OpenAI の agent guideは layered guardrails、tool risk、failure threshold、高リスク・不可逆 action への human intervention を説明し、cancel order、large refund、payment を例に挙げる。Evaluation best practicesに沿って representative case、edge case、continuous eval を持っても、それは live action authority ではない。

顧客文、添付、provider response、retrieved terms は untrusted input とする。OWASP LLM Prompt Injection PreventionとAI Agent Securityを使い、read-only tool、least privilege、structured output、parameter-bound human approval、idempotency、audit trail、timeout、fail closed を置く。agentには proposal tool と execution tool を同時に与えない。

Measurement: safety gate の後だけ economics を読む

Section titled “Measurement: safety gate の後だけ economics を読む”
direct_exit_reachability_rate
= frozen eligible lifecycle intents shown an enabled direct action and able to reach
exact confirmation without a forced survey, support diversion, loop, or error
/ all frozen eligible lifecycle intents
preconfirmation_failure_rate
= frozen eligible lifecycle intents with a technical, accessibility, wrong-target,
forced-diversion, or policy failure before confirmation
/ all frozen eligible lifecycle intents
intent_fulfillment_rate
= mature confirmed requests completed exactly as confirmed and by promised due time
/ all mature confirmed requests
unexpected_charge_rate
= mature requests with a post-effective undisclosed or unauthorized charge
/ mature confirmed requests that could incur a charge
early_access_loss_rate
= requests losing paid / committed access before the disclosed end
/ requests with remaining entitlement
data_closeout_completion_rate
= due exports / deletions / retained-data notices completed
/ all due data-closeout obligations

eligible→direct action rendered→confirmation opportunity→confirmed / explicit withdrawal / unclassified abandonment / failure→fulfilled のarm別funnelを残す。abandonmentを自動的にfailureやretainedへせず、unclassified / missingがcapを超えればUNKNOWNにする。必ずabsolute x/n とfailure caseを併記する。confirmation mail sent、provider API 2xx、portal redirect、Webhook delivered、scheduled change、local flagは、exact outcomeの検証なしにnumeratorへ入れない。

matured_customer_safe_contribution
= settled recurring cash attributable to the follow-up window
- refund and credit actually applied
- PSP / store / MoR fee
- indirect tax collected for others
- variable infra / AI / data / notification cost
- offer / discount cost
- support and founder time at declared internal cost
- migration / remediation / unexpected-charge cost
delta_per_eligible_intent
= candidate contribution / candidate frozen eligible intents
- reference contribution / reference frozen eligible intents

不均等割付やcluster / stratified designはpredeclared weightingとanalysis unitを使い、candidate件数だけでtotal differenceを割らない。voluntary / involuntary、new / existing、B2B / B2C、provider / route、intent classを混ぜない。settled cashをinvoice、authorization、provider balanceと取り違えず、refund / credit / chargebackのprincipalを二重控除しない。continued paymentとrepeated accepted valueを別driverにする。

これは算術とdecision contractを検査する架空例であり、20件、金額、14日、差分は実績・期待値・推奨値ではない。両armに20件ずつfrozen eligible intentがあり、全件がmatured、safety gate合格、cash / cost照合済みと仮定する。

component reference candidate candidate - reference
frozen eligible / matured intents 20 / 20 20 / 20 0
direct exit reached / pre-confirmation failure 20 / 0 20 / 0 0
settled follow-up recurring cash ¥160,000 ¥205,000 +¥45,000
refund / credit -¥8,000 -¥10,000 -¥2,000
PSP / store / MoR fee -¥12,000 -¥15,000 -¥3,000
variable infra / AI / notification -¥20,000 -¥24,000 -¥4,000
offer / discount ¥0 -¥18,000 -¥18,000
support / founder time -¥32,000 -¥30,000 +¥2,000
remediation / unexpected charge ¥0 ¥0 ¥0
matured customer-safe contribution ¥88,000 ¥108,000 +¥20,000
contribution per eligible intent ¥4,400 ¥5,400 +¥1,000

candidate の利益が高くても、unexpected charge 一件、paid access の早期剥奪、broken exit、unresolved data closeout、active incident、live authority 昇格を相殺しない。この例は option が差分を原因として作った証拠でもない。

claim 必要な設計 言えること
descriptive frozen request spine、maturity、reconciliation intent fulfillment、x/n、cash、cost、reason distribution
association time zero とcohort差を明示 offer accepted / reactivated群との関連。selectionを残す
causal candidate direct exitは全arm同一、optional optionだけpredeclared assignment、ITT、integrity exact population / window のbounded effect candidate
scale decision causal evidence + safety / capacity / cash + rollback 次versionを提案できる。live authorityではない

cancel できるか、required notice / refund / exportを受けられるか、unauthorized chargeを避けられるかをrandomizeしない。treatmentをoffer clickedやcoupon acceptedに後付けせずoriginal assignmentで読む。小標本はx/n、absolute difference、uncertainty、missingness、late eventsを示し、短期saveからannual LTVを外挿しない。

STOP_AND_REMEDIATE
> PAUSE
> UNKNOWN
> FIX_LIFECYCLE
> MAINTAIN
> PROPOSE_BOUNDED_OPTION
state 代表条件 work order
STOP_AND_REMEDIATE unexpected / unauthorized charge、broken cancellation、early access loss、account/subscription混同、privacy/security incident、live authority STOP_AND_REMEDIATE_CUSTOMER_HARM。影響顧客、charge、access、dataを人が修復
PAUSE incident未封じ込め、provider / policy / terms source stale、新assignmentを安全に受けられない PAUSE_NEW_ASSIGNMENT。current customer obligationを優先
UNKNOWN maturity、authoritative state、join、cash、data closeout、signature不足 COLLECT_MISSING_EVIDENCE。missingを0にしない
FIX_LIFECYCLE direct exit / accessibility / fulfillment / support capacity cap違反、成熟後delta負 FIX_LIFECYCLE_BEFORE_OPTIONS
MAINTAIN current pathはsafeでchangeを支持するdecision-relevant evidenceなし MAINTAIN_CURRENT_LIFECYCLE
PROPOSE_BOUNDED_OPTION 全gate合格、exact snapshot review、positive bounded evidence、proposal-only PROPOSE_NEXT_LIFECYCLE_VERSION

positive stateでもauthority_cap = NEXT_LIFECYCLE_PROPOSAL_ONLY、live_action_authority = NONEである。provider cancel / pause / resume、refund / credit、entitlement change、account close、data delete、customer message、offer launch、experiment assignmentは、上のaction-specific matrixに従うexact customer/requester authorityと、必要なoperator / policy / provider approvalを別receiptで満たす。どちらか一方を万能な代替にしない。

day action exit evidence
0 contract、intent、provider / route、direct exit、reference / candidate、caps、maturityを凍結 version、owner、authority、rollback
1 current terms / offer / provider capability snapshot source URL、checked_at、account / plan caveat
2 seven-plane schema と request / retry identity no boolean collapse、FK / append-only
3 cancel / downgrade / pause / refund / deletionのsynthetic happy paths scheduled / effective / verified clocks
4 unexpected charge、early access loss、wrong target、duplicate command idempotency、STOP receipts、remedy owner
5 Webhook duplicate / reverse / stale / missed delivery current object reread、reconciliation
6 Stripe / Paddle / Apple / Google mapping review provider-specific transition table
7 keyboard、focus、label、error、confirmation、support fallback end-to-end accessibility evidence
8 voluntary / involuntary / compromise lane split separate denominator / owner
9 export / deletion / retained-data closeout data class、due、reason、receipt
10 optional offer assignment と direct-exit parity ITT spine、no coercive variant
11 cash / refund / fee / offer / support / remediation rollup principal exclusivity、bank / provider join
12 maturity snapshot、missing / late correction frozen cutoff、新snapshot rule
13 14decision fixture とmutation probe precedence、authority、immutability
14 independent review とbounded proposal exact SHA、signature ref、NONE authority

実データへ進む前に、retention / cancellation / win-back packを複製し、fully synthetic SQLite companionを実行する。rehearsal はschema、算術、state、handoffを検査するだけで、顧客の支払意思、法的充足、provider本番信頼性、retention upliftを証明しない。

You may:
- inspect redacted lifecycle events, schemas, provider docs and synthetic fixtures;
- draft state mappings, UI copy, receipts, reconciliation queries and tests;
- compute matured customer-safe contribution from approved components;
- flag missing, stale, wrong-target, early-access, unexpected-charge,
duplicate-principal, unresolved-closeout and authority failures;
- produce NEXT_LIFECYCLE_PROPOSAL_ONLY.
You must not:
- ingest payment credentials, secrets, identity documents, private contracts,
raw support attachments or unnecessary personal data;
- infer legal rights, actor authority, refund eligibility or customer intent;
- mutate live subscriptions, invoices, entitlements, accounts, data, consent,
offers, messages or experiment assignments;
- treat webhook receipt, API 2xx, provider status or eval pass as completion;
- exceed live_action_authority = NONE.

repository では contract、provider mapping、UI revision、terms / offer、event schema、test、accessibility、rollback、decision snapshot を同じ change ID へ結ぶ。source checked_at、provider API version、artifact SHA、reviewer、signature refがずれたら UNKNOWN または PAUSE に戻す。

  • cancellation reason は低いvalue、budget、seasonality、組織変更、support failure、競合、事業終了等の入口であり、lifecycle optionがroot causeとは限らない。
  • churn / win-back cohortはsignal後に選ばれている。全active customerとの単純比較やaccepted-offer群だけの比較から因果効果を主張しない。
  • provider feature、status、retry、grace、pause、proration、refund、API、store policyは変わる。docsだけでなくcurrent account / sandbox / test clock / authoritative readで確認する。
  • B2B authority、minimum term、notice、early termination、data return、seat、invoice、renewalはcontract-specificである。consumer UIをそのまま適用しない。
  • 日本、EU、米国連邦・州、store policyは同じ規則ではない。withdrawal、ordinary cancellation、account deletion、data erasureを分ける。
  • data deletionと会計・税・security・fraud・dispute・legal retentionは衝突し得る。data class、purpose、access、reason、expiryをreviewする。
  • 14日でrenewal、refund、chargeback、win-backが成熟しないことがある。期間を延長するか historical cohort を使い、UNKNOWN のまま止める。
  • support / founder time、lost contribution、future repeat valueには不確実性がある。宣言したinternal rate、range、sensitivityを示し、無料扱いしない。
  • SQLite companionはsynthetic row、constraint、query、expected decisionを検査する。本番storageのappend-only耐久性、cryptographic identity / signature、provider API、法律、顧客結果を証明しない。
  • chart は掲載しない。実測時系列や分布がなく、synthetic count の図示はbenchmarkや経験的傾向を暗示するため、exact mappingと算術表を使う。
  1. 今週、一つのproduct / provider / routeと、一つのprimary intentだけを選ぶ。
  2. 顧客意思、commercial renewal、provider、invoice、entitlement、account/data、supportを別stateにする。
  3. direct exitをend-to-endでkeyboard / focus / confirmation / receiptまで検査し、optionより先に直す。
  4. provider command後にcurrent objectを再取得し、entitlementとinvoiceを冪等に再導出する。
  5. subscription cancel、account close、data deletion、refundをlinked requestとして分離する。
  6. voluntary exit、payment recovery、compromise、provider incidentを別denominator / ownerにする。
  7. optional optionだけをbounded assignmentし、全armのexit rightsとrequired noticeを同じにする。
  8. safety gate合格後にだけmatured customer-safe contributionを読み、proposal-onlyでhumanへ渡す。
  • 顧客が「解約」と言ったとき、renewal stop、immediate revoke、refund、account deleteのどれを確認しているか。
  • providerのscheduled stateとlocal access_untilが食い違ったとき、どちらを止め、誰が何分で修復するか。
  • cancel後に発生し得るusage、open invoice、proration、refund、creditを事前に正確に表示できるか。
  • account deletion前にstore / PSP subscriptionの継続を検知できるか。
  • data classごとのexport、delete、retain reason、access、expiry、customer noticeがあるか。
  • pauseはtrue subscription pauseか、collection pauseか、単なるsupport promiseか。
  • direct exitを使った群だけ、support負荷や再入力、accessibility failureが増えていないか。
  • saved customerはrepeat accepted valueを得たか、それとも支払いだけが残ったか。
  • optional offerを外してもreferenceより良いのか。offer cost、support、refundを引いたか。
  • next lifecycle versionが失敗したとき、exact config / UI / policyを誰が戻し、顧客harmをどうremedyするか。

この問いへ証拠付きで答えられない場合、必要なのは高度な churn model ではない。まず direct exit、state separation、current-state reconciliation、customer-visible receipt、data closeout、proposal-only authority を整える。