Kairos — Opportunity Evidence Strategy and Priority Programme
Evidence work only. This programme may map, inspect, reconcile, falsify, rank, pre-register and prepare decision packets. It does not authorize product work, production mutation, a live experiment, a landing page, customer or buyer outreach, an application, spend, transfer, fundraising, or any other material pursuit. No signed Opportunity Schedule means no material pursuit of a qualifying opportunity.
Result
The current opportunity order can now be converted into a disciplined evidence programme, but it cannot honestly be called a completed full-room audit.
The durable vault contains the current opportunity ledger, source atlas, twelve-room access register, candidate-specific evidence, and the predecessor handoff for the exhaustive room comb. It does not contain the named handoff-2026-08-27-opportunity-evidence-strategy-and-priority-programme.md, and the predecessor still says the complete opportunity-by-room recompute is pending. The current top five are therefore the provisional decision order, not a newly audited final order:
- Payment Recovery
- Retention Economics
- GoProxies Conversion System
- Residential Vantage Network
- Crypto-native Access Wedge
The work programme begins by closing that audit gap. It then spends evidence effort in the order most likely to change a decision, not by blindly following candidate rank or whichever source is easiest to read.
The governing strategy is:
- freeze the complete decision-surface and source-room denominators;
- build the few identity, time, money, funnel, operations and product/network contracts that unlock several candidates at once;
- attack the decisive uncertainty in the top three before widening the portfolio;
- run cheap supply, semantics and existence falsifiers before demand work;
- let challengers and generative candidates ride the same evidence rather than create parallel programmes;
- prepare, but do not execute, any test that crosses into material pursuit;
- preserve every negative, blocked, parked and superseded result so the portfolio cannot regress into story-first ranking.
Consequential decisions
These are the calls that shape the system. The recommended call is already clear from the current record, so no further interrogation is required before drafting.
| Decision | Recommended call | Why it matters |
|---|---|---|
| What is the unit of work? | A decision-changing claim, not a source, dashboard, report or candidate narrative. | Source-led work creates impressive inventories without forcing a portfolio decision. |
| Does candidate rank equal work order? | No. Work order is determined by flip power, shared unlocks, evidence quality, cost and time-to-signal. | The best next evidence may sit under #2 but also constrain #1, #3 and a challenger. |
| What earns promotion? | Load-bearing numbers at least at measured working tier, reconciled where possible, with owner-validated semantics before action. | Readability and data volume cannot promote a candidate. |
| What earns a kill? | A bounded falsifier can kill or narrow at any evidence level if it attacks the load-bearing premise. | Cheap negative findings are valuable and should stop weak branches early. |
| How many tracks run at once? | At most three active evidence contracts. | Wide source access makes shallow parallelism tempting; the decision bottleneck is integration, not query volume. |
| How are unknowns handled? | Every cell ends as finding, negative finding, blocked, parked with reason, or not relevant with reason. |
A blank cell hides whether the source was missed, inaccessible, unfit or genuinely irrelevant. |
| How are external tests handled now? | Specify the test, denominator, floor, guardrails and stop rule; do not launch it. | A well-formed test contract is evidence preparation. Running it is material pursuit. |
| How are capabilities treated? | Separately from MN commercial opportunities; they consume attention only when they unlock the evidence programme or accumulate passive proof. | Capability enthusiasm must not inflate the commercial portfolio. |
Portfolio denominator — corrected
The current record supports nineteen decision surfaces but eighteen unique opportunity constructs. The difference is deliberate: Key Maker appears twice because its MN-enabler proposition and its external product proposition have different evidence and decisions. Counting the two propositions as one would mix internal operating value with external willingness-to-pay; counting them as two unique products would double-count the same architecture.
| Class | Decision surfaces | Count |
|---|---|---|
| Formal candidates | Payment Recovery; Retention Economics; GoProxies Conversion System; Poland Incentive Economics; Residential Vantage Network; Crypto-native Access Wedge; Provenance / Proof-of-Origin; Grant-funded Censorship Resistance | 8 |
| Challengers | Delight / Outcome-Verified Reliability Engine; Key Maker external product proposition | 2 |
| Generative candidates | G1 Plan Migration; G2 VPN–Proxy Cross-sell; G3 Node-runner Community as Launch Audience; G4 Engineered Win-back; G5 B2B / Team VPN Packaging | 5 |
| Capability surfaces | Key Maker MN enabler; K1 Cross-boundary Exception Room; K2 Standard-of-Performance Ratchet; K3 Managed Relay Applications | 4 |
| Total decision surfaces | 19 |
This denominator governs the audit matrix. The twelve-room source denominator is the current release target in Kairos — Data Access Evidence Register (2026-08-26) after Pipedrive entered the register. The mechanical coverage grid is therefore 19 × 12 = 228 classification cells. It is not a requirement to perform 228 deep analyses. It is a requirement to account for all 228 cells and justify which deserve a decision contract.
The data-to-decision architecture
flowchart LR
A[Decision-changing claim] --> B[Source connection certified]
B --> C[Inventory and fitness contract]
C --> D[Identity / time / money / funnel / operations / product spine]
D --> E[Bounded evidence packet]
E --> F{Does the evidence change the decision?}
F -->|Yes| G[Promote / narrow / hold / drop]
F -->|No| H[Park with reason]
G --> I{Material pursuit required?}
I -->|No| J[Continue evidence work]
I -->|Yes| K[STOP — Opportunity Schedule and human authority gate]
1. Candidate decision contract
Every active claim starts with:
decision · candidate/surface · load-bearing claim · current grade · decisive uncertainty · flip condition · kill condition · decision owner · pursuit boundary
If no plausible result can change promotion, narrowing, hold or rejection, the work is not currently decision-bearing and should be parked.
2. Source connection contract
Use the full lifecycle in 90-system/skills/kairos-sync/references/data-source-lifecycle.md:
authority → custody → authentication → scope → sufficiency → durability → acceptance → inventory → fitness → lineage → drift
Authentication, one returned object, a stored credential, or an HTTP 200 never raises an opportunity grade. A source may retain historical accepted findings while its current read path is blocked. BigQuery is the current example: earlier bounded contracts remain evidence, while current reads require identity-consent reauthentication.
3. Analytical spines
Do not build every pairwise source join. Build only the six shared spines that can carry several decisions:
| Spine | Contract | Primary candidate unlocks |
|---|---|---|
| Identity | visitor, account, contact, user, subscription, order, campaign, company, buyer, evaluator, node and task identity with direction and cardinality | Payment, Retention, GoProxies, G1, G2, G4, Delight |
| Time | event, ingestion, reporting, settlement, experiment, release and decision windows | Every causal or trend claim |
| Money | gross, net, fees, refunds, chargebacks, commission, direct cost, support cost, currency and legal-entity perimeter | Payment, Retention, GoProxies, Poland, affiliate lanes |
| Funnel | exposure → visit → signup → purchase → use → renewal → churn, with product-specific variants | Retention, GoProxies, G1, G2, G4, G5 |
| Operations | task → decision → release → telemetry → incident → support → outcome | Delight, Key Maker, K1, K2 |
| Product / network | account → request / connection / traffic → service outcome → customer outcome → revenue | Delight, Vantage, Poland, Crypto, Provenance |
4. Evidence cell contract
Every candidate-source cell records:
surface · claim · source · question · decision affected · source state · object/grain · window · denominator · examined · untouched · evidence · counterevidence · joins · exclusions · semantic owner · freshness · confidence · provenance · disposition · next falsifier
Allowed dispositions:
FINDING— the mapped source supports a bounded result;NEGATIVE_FINDING— a bounded falsifier returned a decision-changing negative;BLOCKED— the accepted read path or required authority is absent;PARKED— work is possible but cannot currently change the decision, with the reason named;NOT_RELEVANT— the source cannot plausibly affect the named claim, with the reason named.
No cell may remain blank. UNKNOWN may describe the claim result, but not the work disposition.
5. Evidence ladder and decision rule
Use the existing ladder without averaging away a weak load-bearing claim:
L0— synthetic, desk or architectural evidence;L1— company-reported or direct but unreconciled evidence;L2— reproduced working-tier measurement at known grain;L3— independently reconciled to a second source or control;L4— semantic owner validation and decision ownership.
Promotion normally requires:
- at least
L2on the load-bearing quantity; L3reconciliation where the number can drift across systems;L4semantics before an intervention is treated as interpretable;- a reachable population, reversible intervention and measurable outcome;
- an explicit net-value and harm boundary;
- enough observation time to distinguish signal from noise;
- the applicable Opportunity Schedule before material pursuit.
A negative can kill earlier if it destroys the premise. A positive cannot promote merely because it is large, current or easy to explain.
6. Decision packet
The end product of each contract is one page, not a dashboard:
- decision and prior state;
- evidence and counterevidence;
- denominator, examined count and untouched remainder;
- source fitness and join boundary;
- what changed and what did not;
- promote / narrow / hold / drop / blocked;
- cheapest next falsifier;
- authority boundary;
- correction and supersession links.
Programme sequencing rule
Candidate rank determines whose uncertainty matters most. Work priority is then lexicographic:
- can the evidence kill or materially narrow a top-three candidate?
- does it unlock two or more decision surfaces?
- does it move a load-bearing claim from reported or measured to reconciled or owner-validated?
- can it be obtained read-only, safely and reversibly?
- is there a real information-decay deadline?
- among ties, choose the cheaper and faster falsifier.
This avoids false precision from a weighted score while still producing a deterministic work order.
Sequenced evidence work programme
Gate 0 — close the audit denominator
Purpose: establish the actual starting portfolio before allocating deep work.
Inputs: the nineteen decision surfaces, twelve registered source rooms, current candidate notes, current source receipts, and source-neutral public or internal evidence already preserved.
Work:
- freeze the nineteen-surface manifest and the Key Maker dual-surface rule;
- freeze the twelve-room source manifest from the newest receipt state;
- classify all 228 cells;
- require denominator, examined count and untouched remainder for every cell marked
FINDINGorNEGATIVE_FINDING; - reconcile the current top-five ledger against every material delta;
- publish a candidate-by-candidate delta: strengthen, weaken, hold, merge, split or retire;
- preserve Payment Recovery's accepted findings separately from the draft, red-team-pending v0.2 architecture;
- label the result self-reviewed unless a separate opposing strategic review occurs.
Exit: no blank or unclassified cells; every candidate has one current state, one decisive uncertainty and one cheapest next falsifier.
Until this gate closes, the current rank order remains provisional.
Wave 1 — top-three decision discriminators
Run at most three contracts in parallel.
Track A — Payment Recovery: net recoverable value, semantics and programme truth
Decision: is there a lawful, controllable recovery or prevention class with material net retained value after natural recovery, intent, fees, fraud, disputes and existing dunning are accounted for?
Use: accepted payment-funnel evidence; current processor and billing semantics; existing recovery-programme history; advice-code and retry conformance; processor export or independent control when available.
Must resolve:
- one invoice / renewal grain and one current denominator;
- voluntary, involuntary, unresolved and already-recovered classes;
- net retained value, not failed face value;
- existing retry, communication and orchestration treatment by class;
- fee, dispute, refund, fraud and scheme-rule boundaries;
- whether the observed programme changed an outcome;
- the payments, revenue-model and compliance semantic owners.
Output: a class-level decision table and a reconciled programme-effect finding. Do not design a live routing change until the evidence establishes a lawful, material class.
Stop / park: source discrepancy, absent owner semantics, no independent processor control, or conservative net value below the published flip threshold.
Track B — Retention Economics: comparable customer-value loss matrix
Decision: which controllable loss cell dominates retained contribution after product mix, acquisition mix, price, platform, payment, usage, service failure and support burden are separated?
Use: accepted warehouse cohorts; commissioned Intercom aggregates; cancellation and churn reasons; acquisition and lifecycle exposures; Grafana only after metric fitness; realised contribution components when available.
Required matrix:
loss cell · eligible population · observed loss · natural recovery · retained contribution · controllability · reversibility · time-to-signal · evidence grade · semantic owner
At minimum compare:
- involuntary payment loss;
- voluntary cancellation;
- non-activation / failed first value;
- product or reliability failure;
- price / plan / market mismatch;
- acquisition-quality and channel-mix effects;
- support-intensive but retained cohorts;
- win-back and reactivation.
Output: one ranked loss matrix and one leading intervention hypothesis. The matrix must keep observed association separate from causal effect.
Stop / park: incompatible windows, unfit identity joins, undefined contribution, or a loss ranking that changes under plausible cohort definitions.
Track C — GoProxies: commercial identity and unit-economics gate
Decision: does any paid-test, customer or use-case cohort convert to durable recurring margin at account grain?
Current boundary: ClickUp and historical warehouse surfaces expose accounts, plans, funnel loss and support, but not paid-test identity, revenue amounts, recurring outcome, delivery cost or contribution. Pipedrive and the GoProxies API are currently blocked.
Work:
- preserve the diagnostic funnel as a bounded finding;
- retrieve the existing ICP and buyer-persona artifacts before inventing replacements;
- specify the company → buyer → evaluator → paid test → integration → usage → recurring margin contract;
- prepare the exact read-only Pipedrive and GoProxies acceptance fixtures;
- require a paid-test ledger with amount, date, account, end state and recurring outcome;
- reconcile delivery and support burden before any conversion claim.
Output: either a positive cohort-economics table or an explicit ECONOMICS_UNOBSERVABLE / COHORT_LEDGER_ABSENT finding. Funnel visibility alone cannot promote the candidate.
Stop / park: no accepted account identity, no cohort ledger, or non-positive recurring contribution.
Wave 2 — shared challenger and supply falsifiers
Start only after Wave 1 contracts have stable denominators or have parked cleanly.
Delight — inside Retention Economics
Current read paths have exhausted their present security and semantic boundary. Residential traffic share and support prevalence establish materiality for further investigation; current fields do not establish true production failure incidence, verified recovery, causal retained value or a Mysterium-specific advantage.
Next evidence is owner-confirmed outcome telemetry:
eligible incident → detected state → traffic containment → recovery action → route/IP/DNS/data-path verification → exposure → customer outcome → retention/value
Prepare the R4 contract and acceptance criteria only. Do not instrument, alter the client, run a live intervention or promote Delight outside #2 under this programme.
Residential Vantage + Poland Incentive Economics — one supply packet
These candidates share the same first falsifier: what supply actually exists, persists, is consented, can be selected, and costs.
One read-only node and incentive packet should measure:
- stable nodes by country, ASN, protocol and observation window;
- persistence, availability, utilisation and reset/churn semantics;
- consent and permitted measurement boundary;
- incentive outlay, payout, direct cost and any observed persistence effect;
- which counts refer to registered, active, reachable, usable or consented nodes.
Decision consequence: a failed supply contract kills or sharply narrows Vantage before buyer work and can separately retire Poland as an opportunity. A successful supply contract earns the right to prepare demand research; it does not authorize outreach.
Key Maker — internal enabler
Use passive evidence from naturally occurring access work. Every access request, repair, rotation, revocation or onboarding event may record elapsed time, touches, retries, authority states, acceptance result and useful work unlocked.
Do not build a separate Key Maker system to prove Key Maker. Promote the MN-enabler proposition only if natural-work journeys establish material delay and show that a bounded governed mechanism can reduce it without introducing a master-key risk.
Wave 3 — external and generative evidence preparation
This wave may perform desk research, source mapping, passive analysis and test pre-registration. It must stop before live demand generation or product-touching execution.
| Surface | Evidence work now | Material-pursuit boundary |
|---|---|---|
| Crypto-native Access Wedge | Refresh category, catalyst, competitor and node-community denominator; write the landing/outreach experiment, sample, response floor and kill rule. | Do not publish the landing page, contact teams or post to the community. |
| Provenance / Proof-of-Origin | Keep folded into Vantage; define the attestation question to code if future authorised discovery repeatedly surfaces it. | No independent outreach or product work. |
| Grant-funded Censorship Resistance | Run one bounded desk-only programme search and record FOUND or NO_MATCH against the six-month award horizon. |
Do not contact funders or submit an application. |
| Key Maker external proposition | Complete confirm-and-kill market research against adjacent identity, access, catalogue and secrets products; specify buyer-interview sample and promotion floor. | Do not recruit or interview buyers. |
| G1 Plan Migration | Model the eligible payment/renewal population and pre-register incrementality, cannibalisation and retention measures. | No offer or product change. |
| G2 VPN–Proxy Cross-sell | Establish identity overlap, plausible jobs, eligible denominator and conflict/exclusion rules. | No in-product or email offer. |
| G3 Node-runner Community | Measure reachable community and activity denominator; bind it to the crypto test design. | No community post or cold outreach. |
| G4 Engineered Win-back | Determine whether historical reactivation is organic or campaign-exposed and whether retained contribution can be observed. | No campaign launch or lifecycle mutation. |
| G5 B2B / Team VPN Packaging | Desk scan the category, buyer jobs, credible negative space and MN asset fit; define a landing-test contract. | No landing page, sales outreach or packaging change. |
Wave 4 — capability evidence, kept off the commercial scoreboard
| Capability | Evidence method | Promotion rule |
|---|---|---|
| Key Maker MN enabler | Passive natural-work journey capture | Material baseline plus measured improvement without added control risk |
| K1 Cross-boundary Exception Room | Score existing exception-heavy work on decision closure, contradiction detection and time-to-resolution | Repeatable improvement across real workstreams; no production-load claim from one case |
| K2 Standard-of-Performance Ratchet | Compare recurrence, correction rate, coverage and decision latency before and after tested guards | A durable reduction in repeated failure, not more policy prose |
| K3 Managed Relay Applications | Maintain buyer/problem hypotheses and one buyer-specific exception-map design | Park until external demand work is authorised; no product claim from internal relay use |
Capabilities do not outrank or dilute MN commercial evidence. They run only as passive measurement or when they directly reduce the cost, risk or latency of this programme.
WIP, cadence and stopping controls
Active-work limit
- maximum three active evidence contracts;
- one named coordinator owns integration and the decision ledger;
- extractors or scripts may produce rows but cannot promote candidates;
- one candidate can have several claims, but only one current decision state;
- a blocked source does not block unrelated sources or cells.
Contract close states
Every contract closes as one of:
DECISION_CHANGED;NEGATIVE_FINDING;BLOCKED_EXACT_REQUEST_READY;PARKED_NO_CURRENT_FLIP_POWER;SUPERSEDED_BY_BETTER_CONTRACT.
“More analysis needed” is not a close state unless the missing evidence, owner, source and decision consequence are exact.
Reopen rules
Reopen a candidate only when one of these changes:
- a load-bearing source, schema, denominator or metric definition;
- an owner validates or rejects semantics;
- a cross-source contradiction appears;
- a new measured outcome crosses a published flip or kill threshold;
- the authority boundary changes;
- a time-sensitive external condition materially changes information value.
Source priority — current boundaries
The source priority is governed by decision unlocks, not room prestige.
| Source / source class | Current use | Highest-value next contract |
|---|---|---|
| BigQuery | Historical bounded findings remain usable; current reads are blocked on interactive reauthentication | Restore the existing principal through identity consent, then rerun exact bounded payment, retention, Intercom and product/network contracts |
| Intercom-derived warehouse corpus | High-ceiling first-party voice; now partially commissioned for Delight, not a general customer-truth system | Human-audit taxonomy, identity/selection-bias contract and cohort linkage |
| Processor / billing controls | Not fully commissioned directly | One independent invoice/result control plus retry, advice-code, refund, dispute and fee semantics |
| Pipedrive + GoProxies product/economics | SOURCE_BLOCKED |
Read-only company/deal/activity and account/usage/payment fixtures tied to the cohort-economics decision |
| Grafana / VictoriaMetrics | Complete dashboard inventory; semantic and safety gates remain partial | Fitness-score only the exact reliability, node, protocol and outcome series selected by a candidate contract |
| ClickUp | Complete structural inventory and bounded activity pulse; underlying token remains overprivileged | Retrieve exact research/ICP/journey artifacts and decision lineage without treating tasks as outcomes |
| Slack snapshot | Bounded historical public-channel prior art | Locate owners, artifacts, definitions and prior tests; never infer current outcome from message recurrence |
| Omnisend | Complete 16-campaign structure; performance, content and segments blocked | Historical exposure/incrementality contract only after Analytics, segment and identity semantics are lawfully available |
| CJ + impact.com | Bounded partner reports with scope or selector limits | Source-owned control and warehouse identity/attribution reconciliation before partner-quality conclusions |
| Ahrefs | Bounded market and search signal | Reconcile to GSC/GA4/backend outcomes before acquisition or customer-value claims |
| Node / network / incentive sources | Partial telemetry and conflicting counts | One stable supply, consent, persistence, utilisation and cost contract shared by Vantage and Poland |
| Customer artifact estate | Specific pointers exist; room denominator is not yet registered | Read-only inventory of Drive, Docs, Sheets, Figma, Notion and attachments by owner, date, method and status |
Mechanical acceptance checks
The programme is ready to drive work only when all of the following are true:
- nineteen decision surfaces and twelve rooms are machine-enumerated;
- all 228 classification cells have an allowed disposition;
- every deep-work cell has a decision-changing question and stop rule;
- every finding states denominator, examined count and untouched remainder;
- every cross-source result has identity, grain, time, missingness and reconciliation contracts;
- every candidate has one current state and one published flip condition;
- rank changes cite the exact new evidence and preserve the prior state;
- blocked cells contain an exact source-owner request and acceptance fixture;
- no current source failure is rewritten as business absence;
- no source readability is converted into candidate promotion;
- no external test or product-touching step has been executed;
- the Opportunity Schedule gate is explicit wherever material pursuit would begin.
Immediate execution queue
The first five work packets are:
- Portfolio audit packet — nineteen surfaces × twelve rooms; close every cell and issue the candidate delta.
- Payment–Retention common spine — customer/subscription/payment identity, two time windows, net-value semantics and processor control.
- GoProxies economic unlock packet — existing ICP artifact, paid-test ledger, Pipedrive and product/API acceptance contracts.
- Network supply packet — Vantage + Poland + Delight-relevant node/protocol semantics, persistence, consent and cost.
- External pre-registration bench — Crypto, Key Maker external, Grant and G5; research and test design only.
Packet 1 must close before a new ranking is claimed. Packets 2–4 may then occupy the three active lanes. Packet 5 begins only when one lane frees or when a true information-decay deadline outranks a current lane under the sequencing rule.
Machine record
- Status
- Active evidence programme · audit incomplete · opportunity order provisional
- Order
- Payment Recovery · Retention Economics · GoProxies Conversion System · Residential Vantage Network · Crypto-native Access Wedge
- First work
- Portfolio audit → Payment–Retention spine → GoProxies unlock → network supply → external pre-registration bench
- Boundary
- No signed Opportunity Schedule means no material pursuit.
- Audience
- Kairos Core only · Lee and Šaras
- Review
- Codex self-review only; independent opposing review remains required before promotion into pursuit.
Verification and review state
- Handoff resolution: the named handoff is absent from the current vault and has no Git history under that filename. The current predecessor is handoff-2026-08-27-opportunity-evidence-room-comb, which still records the exhaustive recompute as pending.
- Opportunity source: Kairos — Opportunity Hypotheses (2026-08-11) remains the vault decision ledger. The team-readable Opportunities board is v0.8.1 dated 2026-08-27; this Core-only evidence programme is a separate decision-control layer and does not promote or reorder that board.
- Live boundary: deployed on 2026-08-27 to
https://kairos-war-room.leematulis.com/notes/kairos-opportunity-evidence-strategy-and-priority-programme-2026-08-27. A signed-in Lee/Core browser returned the canonical title, H1 and machine record withdata-pursuit-status="prohibited"and no console errors. A Robertas/team service-token probe redirected the note request through the Core root to/team/without returning the strategy body or Core machine record. - Shared Kairos state: the shared checkout remains dirty and no shared-repository publication is claimed. The War Room deployment is a separate Core-only surface.
- Review: this strategy is Codex self-review only. It is not an independent opposing strategic verdict. Independent review is required before this programme promotes a candidate into a material decision or is used to justify pursuit.
Core sources
- Kairos — Opportunity Hypotheses (2026-08-11)
- handoff-2026-08-27-opportunity-evidence-room-comb
- Kairos — Source Atlas
- Kairos — Data Access Evidence Register (2026-08-26)
- Kairos — Customer Intelligence Spine
- Kairos — Payment Funnel Decision (2026-08-12)
- Kairos — Payment Recovery — Foundation Architecture v0.2 (2026-08-25)
- Kairos — VPN Self-Healing Data Signal (2026-08-27)
- Kairos — Key Maker Access Control Plane (2026-08-27)
- Kairos — Ahrefs SEO Opportunity Map (2026-08-27)
- Kairos — Omnisend Campaign Operating Review (2026-08-27)
- Kairos — Impact-to-BigQuery Reconciliation (2026-08-27)
90-system/skills/kairos-sync/references/data-source-lifecycle.md