Retention / Cancellation / Win-back Operating Pack
顧客が選んだ解約、downgrade、pause、resume、refund、account / data closeoutを、provider、利用権、cash、supportまで閉じてからoptionalなretention施策を判断するための14書式である。
共通相関キー: retention_lifecycle_contract_id
判断対象: one seller × product / contract × route / jurisdiction × primary intent × frozen eligible cohort × assigned lifecycle revision × effective window × maturity rule
primary metric: matured_customer_safe_contribution_delta_per_eligible_intent
実行上限: NEXT_LIFECYCLE_PROPOSAL_ONLY
live authority: NONE
このpackは一般的な運用雛形で、個別の法務・決済・税務・会計助言ではない。provider、store、B2C / B2B、地域、契約、最低期間、refund、personal data、会計・税・紛争保存をcurrent factsと専門家で確認する。
下の記入例はすべて fully synthetic である。実在顧客、provider ID、email、payment credential、private contract、support attachment、production thresholdを転記しない。real運用ではopaque ID、redacted evidence、権限制御された原本へのpointerを使う。
- このファイルを一decisionごとに複製し、Form 01でcontractを凍結する。
- Form 02〜10でcustomer intentと七つのstate planeを別々に記録する。
- Form 11〜12は事前定義したfollow-upが成熟するまで
NOT_DUE / MISSING / UNKNOWNを0にしない。 - Form 13のcustomer-harm / incident vetoをeconomicsで相殺しない。
- Form 14で独立reviewerがexact snapshotを確認し、proposalだけをhumanへ渡す。
- price、terms、provider、UI、entitlement、data policy、assignment、maturity、capの変更は新しい
contract_versionにする。
共通 vocabulary
Section titled “共通 vocabulary”primary_intent: CANCEL_RENEWAL | CANCEL_IMMEDIATE | DOWNGRADE | PAUSE | RESUME | REACTIVATE | EXPORT_DATA | DELETE_ACCOUNT | DELETE_DATA | REFUND_REQUEST | PAYMENT_RECOVERY | MARKETING_OPT_OUT
request_action: HONOR_CANCEL | SCHEDULE_CANCEL | DOWNGRADE | PAUSE | RESUME | REACTIVATE | EXPORT | DELETE_ACCOUNT | DELETE_DATA | REFUND | RECOVER_PAYMENT | NO_CHANGE
decision_state precedence: STOP_AND_REMEDIATE > PAUSE > UNKNOWN > FIX_LIFECYCLE > MAINTAIN > PROPOSE_BOUNDED_OPTION
evidence_status: NOT_DUE | OBSERVED | MISSING | UNKNOWN_LINK | DISPUTED | N/AForm 01 — Decision contract / scope freeze
Section titled “Form 01 — Decision contract / scope freeze”retention_lifecycle_contract_id:contract_version:environment: SYNTHETIC | TEST | REALcreated_at / frozen_at:
seller / product / contract revision:offer / terms / UI revision:provider / route / storefront:jurisdiction / customer_class: B2C | B2B | MIXED_NOT_ALLOWEDprimary_intent:
frozen eligible definition:eligibility entry occurs before option exposure / confirmation: YES | NOexclusions fixed before outcome:eligibility_start / eligibility_end:assignment_time_zero:reference_lifecycle_revision:candidate_lifecycle_revision:assignment_method:follow_up_end / maturity_rule_version:
intent_fulfillment_floor:direct_exit_reachability_floor:preconfirmation_failure_cap:unclassified_preconfirmation_cap:unexpected_charge_cap:early_access_loss_cap:data_closeout_floor:support_capacity_cap:source_freshness_cap:minimum_reconciliation_coverage:
provider_owner / entitlement_owner / cash_owner:data_owner / support_owner / incident_owner:independent_reviewer:rollback_artifact:customer_remedy_runbook:
authority_cap: NEXT_LIFECYCLE_PROPOSAL_ONLYlive_action_authority: NONEFreeze checklist:
- outcomeを見てからeligibility、arm、maturity、metric、capを変えない。
- voluntary exitとpayment recoveryを同じdenominatorにしない。
- direct exit、required notice / refund / exportをvariantにしない。
- seller / provider / route / storefront / jurisdictionが一意である。
-
contract_versionとすべてのartifact digestを結べる。 - proposal作成者とindependent reviewerが同一でない。
Form 02 — Current commercial / provider state snapshot
Section titled “Form 02 — Current commercial / provider state snapshot”retention_lifecycle_contract_id:snapshot_id / captured_at / as_of_recorded_at:source_checked_at / next_recheck_at:
contract: current_product / price / billing_period: minimum_term / renewal_rule / notice_rule: immediate_termination_rule: refund / credit / proration_rule: authoritative_document_ref / digest:
provider: provider_name / API_version / account_mode: current_subscription_status: auto_renew_state: scheduled_change / effective_at: current_period_start / current_period_end: next_billing_at / open_invoice_refs: pause_mechanism: TRUE_SUBSCRIPTION | COLLECTION_ONLY | STORE_PAUSE | NONE | UNKNOWN portal / self-service capabilities: authoritative_object_ref / observed_at:
local: local_subscription_state: entitlement_policy_revision: current_entitlements / access_until: mismatch_with_provider:
unknown / stale / conflict:owner / due_at:Do not infer:
- provider
active→ paid、entitled、bank cash received - period-end cancel → access revoked now、refund completed
- pause collection → true subscription pause
- account closed → store renewal stopped、data deleted
- API / Webhook success → customer-visible completion
Form 03 — Intent, target, actor authority intake
Section titled “Form 03 — Intent, target, actor authority intake”retention_lifecycle_contract_id:eligible_lifecycle_intent_id:lifecycle_request_id: N/A_UNTIL_CONFIRMEDcustomer_visible_case_ref:received_at / channel:
authenticated_actor_ref:actor_role / authority_basis:action_authority_matrix_revision:commercial / privacy / cash / provider approver refs as applicable:target_subscription_ref:target_account / tenant ref:target_data_scope if any:
raw_text_storage: NOT_STORED | REDACTED_POINTERprimary_intent:linked_request_ids:reason_status: NOT_ASKED | OPTIONAL_ANSWERED | DECLINEDreason_code / free_text_redaction:
ambiguity requiring human / customer clarification:vulnerability / accessibility / language support need:security / compromise signal:payment dispute signal:
eligible_intent_preconfirmation_state: ENTERED | REACHED_CONFIRMATION | WITHDRAWN | ABANDONED | FAILEDpreconfirmation_outcome / evidence:next_safe_action:owner / due_at:Intake gates:
- 一request一primary intent。複数actionはlinked requestに分けた。
- target subscription / account / data scopeを表示して確認する。
- requesterのauthorityをLLMやemail文面だけで決めない。
- refund request≠approval、data deletion request≠retention review completionとしてaction別authorityを確認した。
- cancel reasonは任意で、回答拒否でもdirect exitを続けられる。
- compromise / dispute / vulnerable-customer signalはoffer queueへ送らない。
Form 04 — Direct exit and accessibility evidence
Section titled “Form 04 — Direct exit and accessibility evidence”retention_lifecycle_contract_id:direct_exit_revision / rendered_artifact_sha256:route / device / locale / auth_state:tested_at / tester:
entry_point_visible_and_named: PASS | FAIL | UNKNOWNno_forced_survey_or_support_gate: PASS | FAIL | UNKNOWNkeyboard_complete: PASS | FAIL | UNKNOWNfocus_visible_and_not_obscured: PASS | FAIL | UNKNOWNtarget_size_and_spacing_review: PASS | FAIL | UNKNOWNlabels_and_errors_clear: PASS | FAIL | UNKNOWNauthentication_accessible: PASS | FAIL | UNKNOWNexact_target_shown: PASS | FAIL | UNKNOWNeffective_time_shown: PASS | FAIL | UNKNOWNremaining_access_shown: PASS | FAIL | UNKNOWNprice / next charge / proration shown: PASS | FAIL | UNKNOWNreview_or_correction_before_commit: PASS | FAIL | UNKNOWNreceipt / support fallback available: PASS | FAIL | UNKNOWN
joining_path_steps:exit_path_steps:material_asymmetry:frozen_eligible_intent_n:direct_action_rendered_x / n:confirmation_opportunity_x / n:confirmed_x / explicit_withdrawal_x / unclassified_abandonment_x / failure_x:failure_case_refs:remediation_owner / due_at:Direct exit parity:
- optional optionを拒否しても追加のstep、待機、再認証、電話を課さない。
- destructive / financial / data actionの最終確認はexact targetと結果を示す。
- cancel buttonだけでなくauth→confirm→receiptのprocessを検査した。
- support fallbackはexitの唯一経路ではなく、障害・例外時にcontactableである。
Form 05 — Optional option policy and assignment
Section titled “Form 05 — Optional option policy and assignment”retention_lifecycle_contract_id:option_policy_revision:option_type: NONE | DOWNGRADE | PAUSE | SUPPORT_FIX | DISCOUNT | WIN_BACKoption_id / exact offer revision:
eligible intent / product / route:eligibility_basis known before outcome:exclusions:price / discount / duration:post_option_price / renewal behavior:effective time / remaining access:pause start / resume rule if applicable:support SLA / owner if applicable:frequency cap / cooldown:marketing consent / suppression rule:margin / cash / support capacity cap:
assignment_method:assignment_unit / time_zero:reference experience:candidate experience:direct_exit_identical_across_arms: YES | NO | UNKNOWNrequired_rights_identical_across_arms: YES | NO | UNKNOWNassignment_receipt_ref:
prohibited_segments / reasons:rollback / expiry:reviewer:Never count as option success:
- display、eligibility、click、coupon generation、support ticket creation
- cancel delay、forced survey、missing receipt、unexpected charge
- customer selected after being denied the direct action
- reactivation without later entitlement / value / cash maturity
Form 06 — Customer choice and confirmation receipt
Section titled “Form 06 — Customer choice and confirmation receipt”retention_lifecycle_contract_id:eligible_lifecycle_intent_id:lifecycle_request_id:confirmation_revision / confirmed_at:
authenticated_actor_ref / target_ref:primary_intent:chosen_action:optional_offer_shown / accepted / declined:
exact_product / price / billing_period:effective_at or scheduled_for:remaining_access_until:next_charge amount / date / condition:proration / refund / credit disclosure:features / seats lost or retained:data / account implications shown:withdraw / correction path:
customer_confirmation_receipt_ref:receipt_delivery_status / delivered_at:idempotency_key:support_case_ref:Confirmation gates:
-
yesだけでなく何に同意したかをversionで保存した。 - display priceとprovider command parameterが同じartifactへ結ばれる。
- scheduled actionはeffective前のwithdraw / resume可否を示す。
- account / data / refundをsubscription actionへ暗黙に含めない。
- receiptにはstatusではなく次に何がいつ起こるかを示す。
Form 07 — Provider execution and current-state reconciliation
Section titled “Form 07 — Provider execution and current-state reconciliation”retention_lifecycle_contract_id:lifecycle_request_id:provider_command_id / attempt_sequence:provider / API_version / mode:command_type / exact parameters digest:requested_at / accepted_at / failed_at:idempotency_key / provider_event_ids:
webhook_signature_result:duplicate / reverse_order / retry handling:current_object_reread_at:current_subscription_status:auto_renew / scheduled_change:effective_at / period_end:invoice / transaction refs:refund / adjustment refs:
expected_transition:observed_transition:mismatch / stale / unknown:reconciliation_status: PASS | FAIL | UNKNOWNowner / due_at / retry_policy:Provider-specific review:
- Stripe: cancel、
cancel_at_period_end、true pause、pause_collectionを分けた。 - Paddle: statusと
scheduled_change、pause / resume billing modeを分けた。 - Apple: renewal state、latest transaction、grace / retry、refund / revokeを分けた。
- Google: canceled-but-entitled、expiry、pause、grace、hold、revokeを分けた。
- Webhook後にauthoritative current stateを再取得した。
Form 08 — Entitlement and access closeout
Section titled “Form 08 — Entitlement and access closeout”retention_lifecycle_contract_id:lifecycle_request_id:entitlement_policy_revision:
commercial_effective_at:provider_effective_at:expected_access_start / access_until:products / features / seats / export-only access:grace / hold / limited-access rule:
derivation_input_refs:derived_at / applied_at / verified_at:local_entitlement_before:local_entitlement_after:authorization_cache_invalidated_at:
early_access_loss: YES | NO | UNKNOWNlate_access_retention: YES | NO | UNKNOWNcross-tenant / wrong-target effect: YES | NO | UNKNOWNcustomer_observed_result:remedy / restore receipt:owner / due_at:Entitlement gates:
-
provider statusを直接authorization middlewareのbooleanにしない。 - paid / committed periodの早期剥奪をSTOPとして扱う。
- downgrade / pauseのlimited accessをexact feature / seatで表す。
- cache / token / offline accessもcloseout対象に含める。
- restoreはcommandでなくverified access receiptまで追う。
Form 09 — Invoice, refund, credit, provider and bank cash
Section titled “Form 09 — Invoice, refund, credit, provider and bank cash”retention_lifecycle_contract_id:lifecycle_request_id:currency / FX evidence if normalized:
invoice_refs / open_items:usage_cutoff / pending_invoice_items:proration_preview_ref / actual_invoice_ref:next_charge_expected / actual:unexpected_charge: YES | NO | UNKNOWN
adjustment_type: NONE | REFUND | CREDIT | VOID | CHARGEBACK | OTHERprincipal_group_id:requested / approved / pending / completed / failed amounts:provider_transaction_ref:original_payment_rail:provider_balance_effect:bank_cash_effect / observed_at:
fee / indirect_tax / provider_cost:principal_exclusivity_result: PASS | FAIL | UNKNOWNreconciliation_result: PASS | FAIL | UNKNOWNcustomer_remedy_ref:cash_owner / due_at:Cash gates:
- cancelはrefundを自動的に意味しない。
- refund requested / approved / completed / bank outcomeを分ける。
- creditとcash refundを同一視しない。
- refund、chargeback、write-offを同じprincipal groupで二重控除しない。
- authorization、invoice、provider balance、payout initiationをbank cashと呼ばない。
Form 10 — Account, export, deletion, retention closeout
Section titled “Form 10 — Account, export, deletion, retention closeout”retention_lifecycle_contract_id:customer_visible_case_ref:linked_request_ids:
subscription_cancel_status:store / PSP renewal check:account_login_status:tenant / shared-resource ownership review:
export_request_scope / due_at:export_format / delivery_method:export_status / delivered_at / exception:
data_class_rows: - data_class: action: DELETE | ANONYMIZE | RETAIN | RETURN | N/A purpose / lawful_or_contractual_reason: access_role: retention_end / review_at: processor / subprocessor closeout: completed_at / receipt_ref:
customer retained-data notice revision / delivered_at:deletion / export appeal path:data_closeout_status: PASS | FAIL | NOT_DUE | UNKNOWNdata_owner / due_at:Data gates:
- account close、subscription cancel、store renewal、data deletionを別checkにした。
- shared tenant / legal hold / accounting / tax / security / dispute dataをclass別にreviewした。
- retainを永久保存や全access継続にしない。
- processor / subprocessorのcloseoutとreceiptを追う。
- public log / promptへpersonal dataやprivate evidenceを複製しない。
Form 11 — Value, reactivation and maturity spine
Section titled “Form 11 — Value, reactivation and maturity spine”retention_lifecycle_contract_id:lifecycle_request_id:assignment_arm:primary_intent / voluntary_or_involuntary:time_zero / follow_up_end:maturity_rule_version:
scheduled_outcomes: intent_effective_due_at: entitlement_verify_due_at: invoice / adjustment_due_at: data_closeout_due_at: repeat_value_observation_due_at: cash / refund maturity_due_at:
observed: exact_intent_fulfilled / at: repeated_accepted_value_units: reactivated / at / new_terms_ref: churned_or_expired / at: support_rescue / at: late refund / dispute / correction:
maturity_status: NOT_DUE | MATURED | MISSING | UNKNOWNmissing_or_late_evidence:exclusion_after_assignment: PROHIBITEDowner / next_snapshot_at:Maturity gates:
- continued paymentとrepeat accepted valueを別driverにした。
- win-back eligible、message delivered、reactivated、mature valueを別eventにした。
- outcomeが来た顧客だけをdenominatorにしない。
-
NOT_DUE / MISSING / UNKNOWNをobserved zeroにしない。 - backdated correctionは新snapshotで評価する。
Form 12 — Support, cost and matured economics
Section titled “Form 12 — Support, cost and matured economics”retention_lifecycle_contract_id:decision_snapshot_id / as_of_recorded_at:currency / internal_founder_hourly_cost:
arm: REFERENCE | CANDIDATEfrozen_eligible_intents:matured_intents:direct_exit_reached_x / n:preconfirmation_failure_x / n:unclassified_preconfirmation_x / n:intent_fulfilled_x / n:unexpected_charge_x / n:early_access_loss_x / n:data_closeout_completed_x / due_n:
settled_follow_up_recurring_cash:refund_and_credit_applied:PSP_store_MoR_fee:indirect_tax_collected_for_others:variable_infra_AI_data_notification_cost:offer_discount_cost:support_founder_minutes / declared_cost:migration_remediation_unexpected_charge_cost:
matured_customer_safe_contribution:reconciliation_coverage:support_queue_p95 / capacity_cap_result:missing / duplicate / disputed component:Arm comparison:
reference_contribution:candidate_contribution:candidate_minus_reference:reference_contribution_per_reference_eligible_intent:candidate_contribution_per_candidate_eligible_intent:matured_customer_safe_contribution_delta_per_eligible_intent:formula: candidate_per_candidate_eligible - reference_per_reference_eligible
absolute x/n and uncertainty:sensitivity range:causal_claim_cap: DESCRIPTIVE | ASSOCIATION | CAUSAL_CANDIDATEEconomics gates:
- safety gateを先に評価し、利益でharmを相殺しない。
- support / founder timeを0円にしない。
- offer cost、notification、data、AI / infra、remediationを含めた。
- same frozen eligible denominatorとpredeclared follow-upを使う。
- confirmation前のerror / accessibility failure / forced diversion / abandonmentをeligible分母から除いていない。
- total差分をcandidate件数や両arm合計件数で割らず、arm別per-eligible差を計算した。
- annual LTVやuniversal save rateへ外挿しない。
Form 13 — Incident, customer harm and remediation
Section titled “Form 13 — Incident, customer harm and remediation”retention_lifecycle_contract_id:incident_or_harm_id:detected_at / source:status: OPEN | CONTAINED | REMEDIATED | CLOSED | UNKNOWNseverity / affected_scope:
harm_type: UNEXPECTED_CHARGE | BROKEN_CANCEL | EARLY_ACCESS_LOSS | WRONG_TARGET | DUPLICATE_ACTION | DATA_LOSS_OR_OVERRETENTION | PRIVACY_SECURITY | INACCESSIBLE_EXIT | PROVIDER_DRIFT | UNAUTHORIZED_LIVE_AUTHORITY | OTHER
affected_eligible_lifecycle_intent_ids:affected_lifecycle_request_ids if confirmed:provider / entitlement / invoice / data evidence:containment_action / owner / completed_at:customer_notification / delivered_at:refund / credit / access_restore / data_remedy receipt:root_cause / contributing_factors:corrective_artifact / rollback:regression_fixture:independent_close_review:
stop_flag:pause_flag:safe_for_new_assignment:residual_unknown:Incident precedence:
- active unauthorized charge、broken cancellation、early access loss、privacy/security、data loss、live authority →
STOP_AND_REMEDIATE - contained customer harmでもremedy未完了ならpositive decisionへ進めない。
- provider / policy / terms driftやnew assignment safety不明 →
PAUSE - incident count、refund、support timeをeconomics ledgerにも一度だけ反映する。
Form 14 — Decision, review, signature and Codex handoff
Section titled “Form 14 — Decision, review, signature and Codex handoff”retention_lifecycle_contract_id:contract_version:decision_snapshot_id / snapshot_sha256:snapshot_cutoff / generated_at:
stop_flag / evidence refs:pause_flag / evidence refs:unknown_flag / missing refs:fix_lifecycle_flag / breached cap:maintain_flag / evidence:proposal_ready_flag / evidence:
decision_state:work_order: STOP_AND_REMEDIATE_CUSTOMER_HARM | PAUSE_NEW_ASSIGNMENT | COLLECT_MISSING_EVIDENCE | FIX_LIFECYCLE_BEFORE_OPTIONS | MAINTAIN_CURRENT_LIFECYCLE | PROPOSE_NEXT_LIFECYCLE_VERSION
matured_customer_safe_contribution_delta_per_eligible_intent:intent fulfillment / unexpected charge / early access / data closeout:provider / entitlement / cash / data reconciliation:support capacity / incident status:claim_cap / limitations:
independent_reviewer:reviewed_snapshot_sha256:review_decision / reviewed_at:accountable_human_signature_ref:
authority_cap: NEXT_LIFECYCLE_PROPOSAL_ONLYlive_action_authority: NONEnext_owner / due_at:rollback_artifact:customer_remedy_runbook:Codex task brief:
You may:- validate redacted schemas, event order, idempotency and synthetic fixtures;- map current provider observations to a proposal without inferring entitlement;- compute approved safety and economics fields as of a frozen cutoff;- flag missing, stale, wrong-target, duplicate-principal, early-access, unexpected-charge, unresolved-closeout and authority failures;- draft NEXT_LIFECYCLE_PROPOSAL_ONLY.
You must not:- ingest credentials, secrets, identity documents, private contracts, raw support attachments or unnecessary personal data;- infer actor authority, legal rights, refund eligibility or customer intent;- mutate live subscriptions, invoices, entitlements, accounts, data, consent, offers, messages or assignment;- turn API 2xx, webhook delivery, provider status or eval pass into completion;- exceed live_action_authority = NONE.Decision review checklist:
- state precedenceを上から評価した。
- exact snapshot、contract version、artifact digest、reviewが一致する。
- reviewerはproposal authorとindependentである。
- positive decisionでもmutation tool / credential / live authorityを持たない。
- next actionは新contract / human approvalの提案で、current cohortを変更しない。
Fully synthetic completed example
Section titled “Fully synthetic completed example”次は算術・state・authorityの接続だけを示す。顧客結果や施策効果のbenchmarkではない。
retention_lifecycle_contract_id: SYN-RETENTION-001contract_version: 1.0.0environment: SYNTHETICprovider / route: SYNTHETIC_WEB_BILLING / WEBprimary_intent: CANCEL_RENEWAL
reference_lifecycle_revision: SYN-DIRECT-EXIT-R1candidate_lifecycle_revision: SYN-DIRECT-EXIT-PLUS-OPTION-R1assignment_method: SYNTHETIC_PREDECLARED_1_TO_1frozen eligible: 20 reference + 20 candidatematured: 20 reference + 20 candidate
customer-safety gates: direct_exit_reached: 20/20 reference, 20/20 candidate preconfirmation_failure: 0/20, 0/20 unclassified_preconfirmation: 0/20, 0/20 intent_fulfillment: 20/20 reference, 20/20 candidate unexpected_charge: 0/20, 0/20 early_access_loss: 0/20, 0/20 due_data_closeout: 0/0 N/A, 0/0 N/A
reference contribution: 160000 cash - 8000 refund/credit - 12000 fee - 20000 variable cost - 0 offer - 32000 support - 0 remediation = 88000 JPY
candidate contribution: 205000 cash - 10000 refund/credit - 15000 fee - 24000 variable cost - 18000 offer - 30000 support - 0 remediation = 108000 JPY
candidate_minus_reference: +20000 JPYreference_contribution_per_reference_eligible_intent: 4400 JPYcandidate_contribution_per_candidate_eligible_intent: 5400 JPYmatured_customer_safe_contribution_delta_per_eligible_intent: +1000 JPY
stop_flag: 0pause_flag: 0unknown_flag: 0fix_lifecycle_flag: 0maintain_flag: 0proposal_ready_flag: 1
decision_state: PROPOSE_BOUNDED_OPTIONwork_order: PROPOSE_NEXT_LIFECYCLE_VERSIONcausal_claim_cap: SYNTHETIC_ARITHMETIC_ONLY
independent_reviewer: SYNTHETIC_REVIEWER_Breview_decision: APPROVED_FOR_PROPOSAL_ONLYauthority_cap: NEXT_LIFECYCLE_PROPOSAL_ONLYlive_action_authority: NONEこのoutputはdiscount、pause、cancel、refund、entitlement、account、data、messageを変更しない。accountable humanはcurrent provider / plan / storefront、contract / law / policy、UI / accessibility、cash / support capacity、rollback、customer remedyを再確認し、新しいchange contractでのみlive actionを承認する。