Kairos — Opportunity Hypotheses (2026-08-11)
Kairos — Current Opportunity Hypotheses
Decision state, updated 2026-08-27: the top five remain unchanged. Outcome-verified self-healing enters as the leading product intervention hypothesis inside #2 Retention Economics, not as a sixth independently ranked opportunity. It is the strongest current challenger to #5 if later evidence establishes a distinct Mysterium advantage. These are priorities for further work—not recommendations, tested opportunities, or torpedoes.
Selection rule: present signal strength and asymmetric upside separately. A candidate does not become “asymmetric” because it is easy, and it does not become recommendation-grade because the upside is large.
[!important] Payment Recovery category correction — 2026-09-01 The table below is superseded for Payment Recovery only. A category red team classifies its retained-subscription value as NESTED inside Retention Economics, not a separately ranked opportunity. The eligible intent-positive technical-failure cohort is unmeasured, not established as very rare. Gross unpaid face remains a diagnostic ceiling. Broader Payment Operations Reliability value is an adjacent unpriced hypothesis and must earn distinct economics and ownership. The remaining portfolio ranks have not been recomputed; do not promote another candidate mechanically because Payment Recovery lost its separate slot. Independent Opus certification remains unresolved after two sealed zero-output timeouts. See 2026-09-01-payment-recovery-category-red-team.
Ranked verdict
| Rank | Candidate | Lane | Current signal | Asymmetric upside | Verdict |
|---|---|---|---|---|---|
| superseded | Payment Recovery | nested inside Retention Economics | measured first-failure and recovery-system defects; eligible value unmeasured | unknown until a mature joined cohort or distinct payment-operations value pool exists | Remove the separate rank. Do not pursue as a standalone opportunity. |
| 2 | Retention Economics | internal | subscription, churn, cancellation, usage and value surfaces exist with uneven freshness | high if one controllable loss cell dominates | Keep second. Build the comparable loss matrix, not a generic dashboard. |
| 3 | GoProxies Conversion System | internal | broad account, plan, funnel and support diagnostics now exist; revenue, paid-test labels and unit economics do not | potentially strong, but still unpriced | Widen, do not promote. Use the available diagnostics to locate conversion failure; do not mistake them for economics. |
| 4 | Residential Vantage Network | external | category and network possibility are real; MN demand, consent and reliable supply remain unverified | potentially high but incumbent-heavy | Discovery only. |
| 5 | Crypto-native Access Wedge | external | settlement fit exists; current demand and a defensible wedge do not | uncertain | Hold as a narrow option, not a September lead. |
The new data changes the map more than the order. Payment Recovery remains the sharpest measured loss; Retention Economics remains the broader decision frame around it. GoProxies moves from a thin paid-test cohort idea to a real diagnostic system because the data now exposes accounts, plan state, funnel loss and support load. It does not move above #2 because revenue amounts, paid-test identity, retained conversion, margin and delivery economics remain absent. This is an allocation of attention, not a launch recommendation.
2026-08-27 challenger — Delight (working name)
Current rank judgment: inside #2; no separate top-five slot yet. Delight is the working name for the whole opportunity, not a proposed feature brand. The product hypothesis is stronger than “add an AI agent”: Mysterium should detect loss of protection, keep traffic from escaping, make the safest equivalent repair, verify IP/DNS/data-path recovery, and only then explain what happened. A conversational agent and an MCP surface are optional interfaces to the same operator; neither belongs in the protection-critical control loop.
The problem signal is stronger than the current #5 Crypto-native Access Wedge: first-party use has produced a trapped connection, false-connected and false-disconnected states, two matching macOS crash stacks and stale protection state during total link loss; the public client supplies concrete recovery and lifecycle mechanisms; historical company material reports connection errors falling from roughly 10% to 1% alongside lower churn. But the independent-opportunity case is not yet stronger: current production incidence, support prevalence, retained-value impact and a Mysterium-specific advantage over ordinary VPN self-healing are unknown. Counting the same value once under Retention Economics and again as a standalone candidate would inflate the portfolio.
Data-access correction — 2026-08-27: unknown does not mean the evidence is absent or inaccessible. The current BigQuery metadata inventory shows reachable app-session, connection-time, error, cancellation, churn and VPN-support objects. The most directly relevant include App_session_connections (1.16m rows), connection_time_sessions (4.68m), app_users_errors (10.4m), App_usage_sessions (1.01bn), App_usage_cancel_reasons (18.2k), users_churn_reasons (119k), and the flattened claude.intercom_vpn_conversations surface (919k rows). Several carry user or pseudonymous identity, platform, app version, event/error, connect-success, churn-date, churn-revenue, reason/tag and timing fields. These objects are reachable but are not yet commissioned together for this decision. Their existence lowers the cost and time-to-signal; it does not raise the evidence grade until grain, freshness, identity, privacy and join fitness are tested and the aggregate analysis is run. Silent false-Connected, route, IP and DNS failures may still be unobservable because a warehouse cannot count events the client never instruments.
Traffic-denominator correction — 2026-08-27: residential routing is not a small tail in the current warehouse counters. A bounded current-snapshot query found residential at 79.03% of traffic counters for 18,291 active users; a separate two-partition history analysis found residential at 77.72% of positive per-user counter growth from 27 July to 26 August. This clears the material-usage gate for investigating residential self-healing, but remains working-tier until MN confirms counter meaning, classification, reset and backfill semantics. It does not yet establish failure incidence, retained-value impact or a defensible recovery advantage. Full queries, receipts and the commissioning sequence live in Kairos — VPN Self-Healing Data Signal (2026-08-27).
It earns a separate slot—most plausibly by replacing #5—only if all four gates clear:
- a current production denominator shows a material, concentrated recovery/protection-truth problem;
- failure exposure predicts support load, cancellation or retained-value loss after obvious cohort differences are controlled;
- a bounded one-platform intervention materially improves verified recovery time and customer outcomes;
- MN's node and connection data creates an advantage that competitors cannot reproduce with ordinary client failover.
Until then, treat Outcome-Verified Reliability Engine as the leading candidate cell to size inside Retention Economics. The full hypothesis, evidence balance, counterarguments and kill tests live in Kairos — Mysterium VPN 30-Day Product Immersion (2026-08-20)#27 August — invisible self-healing operator hypothesis.
2026-08-27 intake — Key Maker (provisional evidence assessment)
Current map judgment: claim-level starting assessment and provisional placement complete; no proceed verdict. Key Maker was developed as a product and architecture hypothesis before it was put through the Opportunities protocol. Release v0.8.0 now places it on two explicit surfaces: a cross-cutting MN enabler and an external generative candidate, not rank #6. Document length, architectural detail and Lee's excitement are not evidence grades.
It must be split into two propositions before ranking:
- MN operating enabler: a governed Key Maker AI reduces access-cycle time, status confusion, human credential work and unsafe custody while unlocking useful work across other opportunities.
- External General System / Mammoth candidate: other companies will pay for the reusable control plane rather than for bespoke access consulting.
Those propositions currently have different evidence:
| Load-bearing claim | Current evidence | Starting disposition |
|---|---|---|
| MN has a material access-coordination problem | L1-B, first-party reported: eleven-room mapping, repeated blocked/partial states, unstable status interpretation, operator-hostile instructions and a zero-room day. The operating pain is credible; no accepted baseline yet measures cycle time or attention cost. | Problem signal present. |
| The MN problem is materially expensive | L1-C. Roughly two and a half weeks of work, a zero-room day and attention drag are first-party reports; repeated failure states are preserved, but time, touches, rework and delayed-decision value are not yet measured. | Materiality plausible; baseline open. |
| Key Maker can produce safe useful access inside 15 minutes | L0-C technical plausibility. Current identity, vendor-API, secret-management and policy tooling make the target plausible, but no end-to-end MN run has passed it. Provider-specific manual or approval paths may prevent a universal 15-minute result without governed fallbacks. | Technically plausible; outcome unverified. |
| Key Maker can govern scopes, custody, rotation and revocation without becoming a new control risk | L0-B architecture. Domain model, authority tiers and tests are specified; production enforcement is not implemented or verified. | Feasibility hypothesis. |
| The MN result is repeatable across rooms, roles and organisations | L0-C generalisation hypothesis. No second organisation and no repeated MN deployment exist. | Repeatability absent. |
| A real adjacent market category exists | L0-A category existence. Current first-party sources independently show enterprise AI deployment, agent identity, SaaS access automation, data-access governance and secrets-brokering products and services. | Strong synthetic category signal. |
| Companies buy adjacent products and deployment services | L0-B adjacent-commercial signal. OpenAI is capitalising a deployment company and acquiring an FDE team; identity, access, catalog and secrets vendors sell commercial products and implementation services; vendor-hosted cases report operational savings. | Commercial activity exists; material Key Maker budgets remain open. |
| A company would buy Key Maker in an integrated form | L0-C. The company-as-customer model and adjacent budgets are coherent, but Key Maker's bundle, buyer, make/buy boundary, procurement path and price are inferred. | Key Maker-specific demand and willingness-to-pay unverified. |
| Upside could be asymmetric | High strategic judgment, unmeasured. The same system could unlock MN work, improve operator portability and become reusable infrastructure, but neither value created nor cost to deliver is established. | Asymmetry hypothesis only. |
The Opportunities protocol does not require a buyer interview for admission or for an honest L0 grade. Residential Vantage and Crypto-native Access also carry unresolved first-hand demand; a buyer conversation or market response is a possible climb path, not a prerequisite for appearing on the map. Signal strength and asymmetry remain separate.
Under the generative-lane comparison, Key Maker has strong judged asset-fit to the active MN access work and a strong structural link to measured lanes that usable access can unblock. Its cheapest evidence is not a standalone test: the eleven-room history can be backfilled now, and the next naturally occurring access repair, commissioning pass, analysis unlock, rotation or onboarding can carry the prospective measurement packet as part of ordinary Kairos work. Those factors earn portfolio comparison; they do not manufacture external demand evidence.
This makes Key Maker's MN-enabler proposition stronger on problem proximity than an ordinary L0 external candidate, while its external product proposition remains in the same L0 resolution class as other untested external and generative candidates. Evidence-only, its adjacent-category and commercial signal is stronger than #5 Crypto-native Access, although both retain L0 direct demand; it also has stronger MN problem proximity than #4 Residential Vantage, while Residential has the clearer MN-asset offer and cheaper supply falsifier.
The provisional placement is therefore two surfaces now: a cross-cutting MN enabler node, not a sixth revenue opportunity; and a first-class candidate on the external generative/Mammoth slate. It does not displace the top three because value capture, beneficiary, delivery economics, ownership and proximity to measured MN monthly margin are not yet comparable. Combining the two propositions would let MN's internal pain masquerade as external product demand.
A one-room coordinator journey is one possible evidence unit for the first proposition only. It is not preselected as the next action and would not answer the second proposition. Key Maker moves only after the ordinary portfolio pass compares prize, prior, time-to-signal, unlocks, controllability, kill conditions and evidence cost against the other candidates. The standing Mammoth boundary remains: no signed Opportunity Schedule, no material pursuit.
The full ground-up claim register, passive-capture packet, easiest side-effect evidence, buyer-interview design, synthetic-research source matrix, initial primary-source scan and promotion/kill conditions live in Kairos — Key Maker Access Control Plane (2026-08-27)#Key Maker evidence programme — 2026-08-27.
2026-08-20 integrated update
What the additional context changed
- GoProxies is no longer a zero-data lane. The available operational surfaces show roughly 11.4k accounts, about 2.15k enabled or unblocked, 7,936 with no plan, a 2026 funnel of 468,056 sessions → 13,696 pricing visits → 9,483 plan-checkout visits → 3,652 product-checkout visits → 1,826 payment visits → 277 thank-you visits, and roughly 3,964 support contacts / 1,307 conversations.
- Those diagnostics do not establish the economics. The accessible surfaces still do not identify revenue amounts, paid-test membership, cohort retention, contribution margin, delivery cost or account-level commercial outcomes. The correct promotion is therefore from Paid-Test Conversion to GoProxies Conversion System, not from rank #3 to rank #1.
- The top two do not swap. Payment Recovery has the hardest measured loss signal. Retention Economics is the necessary wider frame that prevents a local payment lift from being mistaken for durable value. More context strengthens their relationship; it does not produce evidence for reversing them.
- No torpedo is earned. None of the five has yet cleared accessible decision-grade economics, a named intervention owner, a pre-registered measurement contract and enough observation time.
Customer-review guardrail
The public VPN review corpus is an early-warning and falsification source, not a measure of customer prevalence or revenue. Its apparent 2026 Q3 improvement is highly sensitive to a new Trustpilot reviewer group: all 18 current-quarter ratings average 3.44/5 with 33% rated 1–2 stars; excluding ten one-public-review profiles leaves eight ratings averaging 2.00/5 with 63% rated 1–2 stars and reverses the platform-adjusted direction by roughly −0.39. A one-review profile is context, not evidence of a bot, competitor or fake account.
This does not change the ranking. It adds a hard safeguard to Payment Recovery and Retention Economics: separate accidental payment failure from prior cancellation or refund intent before retrying payment. The decisive internal checks are cancellation-to-renewal outcomes, 7040/7042 restriction cohorts, support resolution, reliability by platform/geo/endpoint, and product or acquisition changes around June 2026. The full evidence, limitations and team-readable synthesis live at Customer Reviews and What the customer reviews change for Kairos.
Newly visible Kairos opportunities — separate slate
These are new relative to the older MN opportunity board, but they are Kairos operating leverage, not additions to the MN commercial top five:
- K1 — Cross-boundary exception room: a governed place where evidence, authority and blocked decisions can cross the Lee/Šaras boundary without copying private payloads or confusing messages with adoption.
- K2 — Standard-of-Performance ratchet: turn recurring review failures into named, tested operating standards that raise the floor across both agent systems.
- K3 — Managed relay applications: productise the proven pointer-not-copy, receipt-backed agent relay pattern for bounded multi-principal workflows. Current portfolio: Kairos — Autonomous Agent Relay Use-Case Portfolio (2026-08-20).
The separation matters: K1–K3 may be strategically valuable to Kairos, but using them to inflate the MN opportunity ranking would mix an operating-system portfolio with company commercial bets.
Historical build-up — database-first sprint move (opposing-reviewed; immediate plan repaired)
[!important] Opposing review and adjudication — 2026-08-11 Tris on
claude-opus-5returned REPAIR through a sealed six-file review. Codex accepts the verdict. The direct Sol High → localbq→ BigQuery architecture survives, with query text, output, timestamp and hash logging added. The broad two-arm value-leak matrix is superseded as the immediate move: unequal source coverage predetermines the retention comparison, and the 12-hour plan misses the Thursday read-ahead wall. Full source: Tris red-team — next MN database work — 2026-08-11.
Immediate database decision question
Is MN's recurring first-attempt payment failure rate an emergency above 25%, or a measurement artifact at or below 15%—and does the duplicate-carrying revenue surface reconcile to the clean purchase-grain source?
[!success] Answered for the Thursday read-ahead Emergency confirmed at working tier. July's canonical Stripe renewal cohort is 2,979 invoices with 1,528 first-attempt failures (51.29%; 50.72% excluding Radar). The attempt-weighted rate is 83.36%, confirming retry inflation. Clean purchase-grain revenue and the zero-length-excluded revenue model reconcile to the cent in every month observed; Looker matches the duplicate-carrying surface to the cent. The decision page is Kairos — Payment Funnel Decision (2026-08-12), with exact aggregates and query hashes in MN payment-funnel query audit — 2026-08-12.
Use Sol High to iterate through invoice-grain SQL. Lock the metric dictionary before query one; split pre/post Payments Orchestration at 2026-07-23; separate renewal, new checkout and first post-trial; compute first-attempt and attempt-weighted rates side by side; use a settled cohort for mature recovery; measure failure concentration and retry waste; then reconcile clean revenue, duplicate-carrying revenue and Stripe succeeded charges over 13 months. Log and hash every query and output because warehouse audit attribution currently attaches to the shared MN principal.
Stop if more than 10% of failed charges remain unclassifiable, the invoice-grain denominator cannot be reproduced from two sources, or no defensible rate exists within four hours. Under those conditions ship reconciliation-only or volume-only with the limitation explicit. Before the Thursday read-ahead, output one decision page—not a dashboard and not a torpedo contract—with the rate by count and value, the misleading attempt-weighted rate, mature net unrecovered rate if available, the reconciliation line, and asks for the payments owner, revenue-model owner and a named Kairos read-only principal.
Do not run the retention arm, LTV/CAC work, proxy reconciliation or the eight-hour second pass before the read-ahead. The value-leak matrix below remains a later-stage option only after both arms have defensible coverage.
Correction reset
Lee's 2026-08-11 question was not “how should we investigate the warehouse anomaly?” It was: what is the highest-leverage use of the database to advance the September sprint? The governance/audit response is preserved in Kairos — Database Integrity and Fraud-Risk Assessment (2026-08-11), but it is not the primary database workstream.
Recommendation: build a VPN value-leak matrix that forces a candidate decision
Use the warehouse to choose between the Payment-Recovery Candidate and the VPN Retention Stack, identify the one or two intervention-ready segments inside them, and either promote the strongest into a complete torpedo contract or kill both. Do not build another general business-health dashboard.
This is the highest-leverage database move because:
- the current #1 candidate, Paid-Test Conversion, cannot be validated deeply from BigQuery: proxy paid-test revenue and account economics are absent;
- Residential Vantage Network needs buyer and network-supply evidence, not VPN subscription tables;
- the warehouse does contain transaction, charge-attempt, churn, cancellation, usage, attribution, fee and aggregate LTV/value surfaces capable of materially changing the ranking of the two internal VPN candidates.
Defensible spine and coverage limits
Start from claude.vpn_purchases, not the duplicate-carrying revenue table. It currently has 292,089 rows and 292,089 distinct purchase_id values, covering 134,471 users and 167,442 subscriptions from 2023-04-20 through 2026-08-11. Treat one purchase as the transaction spine, then build subscription episodes and cross-check every dollar total against a second source.
Join only after grain checks:
- Stripe charge attempts and invoice recovery for involuntary payment loss;
mv_vpn_users_churnfor provisional churn timing, traffic bucket and revenue-at-risk fields;mv_vpn_cancel_reasonsfor voluntary-cancellation reason and subscription linkage;mv_vpn_users_usage_activityfor activation/usage behaviour;mv_vpn_web_sources_subsfor the attributed web minority;mv_vpn_fees,looker.daily_ltvandmv_vpn_users_value_statusas aggregate comparators, not unquestioned truth.
Coverage is not uniform. Usage activity ends at 2026-02-09 and web-source attribution at 2026-04-08, while purchases run through 2026-08-11. mv_vpn_users_churn reaches 2026-08-12 and therefore needs owner confirmation before “churn date” is treated as an observed event. Do not force these into one current-period model. Use two explicit windows:
- Current payment window: recent invoice failures, natural recovery, retry class, gateway/issuer/geo segments and retained value.
- Mature retention window: cohorts old enough for usage, cancellation and later-payment outcomes, ending no later than the least-current source required by each cut.
Questions the matrix must answer
- Where does retained gross revenue actually disappear: failed first renewal, later involuntary churn, voluntary cancellation, non-activation, plan/price mismatch, or a narrow gateway/geo segment?
- Which loss is largest after collapsing retries and subtracting natural recovery?
- Which segment has a reachable population, a reversible intervention, a named product surface and enough time to measure before the board decision?
- Which apparent opportunity dies when evaluated on mature retention rather than approval rate, delayed cancellation or gross-attempt dollars?
Rank candidate cells on addressable retained dollars × evidence confidence × controllability × reversibility × time-to-signal. Keep cost/CAC gaps explicit; absent marketing spend and support cost mean this is not yet full contribution economics.
Bounded execution sequence
- Pass 1, four-hour cap: grain/freshness audit, two-window cohort contract, and rough sizing across payment versus retention. Stop if the joins or definitions cannot be made defensible.
- Pass 2, additional eight-hour cap: deepen only the leading segment, independently reconcile its numerator and denominator, specify the eligible population and pre-register measurement/guardrails.
- Output: one comparable decision table, aggregate evidence cells only, plus either a complete torpedo contract for the winner or an explicit rejection/blocker record. No raw customer rows enter Git or the vault.
Quality and model contract
Lee's 2026-08-11 correction is controlling: highest quality and evidence resolution outrank token economy for this database sprint. Do not route any model-mediated extraction, join interpretation, anomaly classification, candidate ranking, or synthesis through a lower-capability model. If model parallelism is useful, use Sol at high reasoning; Claude/Tris remains the independent strategic reviewer where required.
Conserve usage through deterministic SQL and scripts, batched queries, narrow evidence packets, cached/reused outputs, and early elimination of invalid joins—not through a capability downgrade. If the available weekly capacity cannot support the work at this standard, narrow or pause the sprint and preserve the evidence state; do not silently trade resolution for completion.
The likely strategic gain is not “better analytics.” It is an evidence-backed decision about which internal candidate deserves the sprint's scarce implementation and observation window.
Historical candidate record — Paid-Test Conversion
The hypothesis
Convert the existing July paid-test cohort into durable contracts—or learn, account by account, why the tests do not convert.
Actual asymmetry
The downside could be bounded: a small board, twice-weekly review, targeted customer work, and product help only where a named blocker justifies it. The upside is recurring revenue from buyers who have already paid to test. It could also produce a reusable failure map even if the conversion result is poor.
Why Mysterium specifically
Mysterium already owns the cohort, the product telemetry, the commercial conversations, and the delivery context. A competitor can copy the operating method; it cannot act on this exact first-party cohort.
Signal already present
- The 2026-08-07 all-hands deck reports $11,628 for the displayed July proxy result.
- $9,084—78%—is paid tests, not new MRR.
- This is direct company-reported evidence of paid intent. It is not yet evidence of retention, margin, or conversion quality.
Strongest red-team attack
This may be ordinary sales hygiene dressed as strategy. The cohort may be dominated by one-off technical evaluations, low-fit buyers, or tests that cannot convert economically. Gross margin, delivery capacity, concentration, decision-maker access, and reasons for failure are still missing. If Kairos merely creates a prettier CRM view, the opportunity is false.
Next validation step
First reconcile one row per paid test: buyer and use case; amount; technical success criterion; economic buyer; blocker; next action; owner; decision date; expected MRR; contribution margin; and conversion probability. Only then decide whether a live intervention exists.
Kill condition
Kill or narrow the candidate if the cohort cannot be reconciled to named accounts, if most tests have no reachable economic buyer or repeat need, or if expected retained contribution cannot justify the delivery and product work required.
Concrete next step
Estimated Kairos effort: 12–20 hours, excluding MN product implementation. With complete access, reconciliation may take two working days. Any conversion claim still depends on real account decisions and elapsed time; the estimate is not a launch promise. No material product build before the blockers are real and ranked.
Historical candidate record — Payment-Recovery Candidate
The hypothesis
A possible torpedo: route eligible failed Stripe payments through the planned Adyen fallback and measure incremental retained revenue—not approval rate theatre.
Actual asymmetry
If the implementation path exists, the intervention could be narrow and reversible. It would act on demand that already exists. A small recovered cohort could repay the work; a null result could stop it without a strategic hangover.
Why Mysterium specifically
Mysterium already has the affected payment attempts, the Payments Orchestration path, and a planned Adyen fallback. The advantage is timing and first-party failure data, not a proprietary idea.
Signal already present
- The all-hands deck reports Payments Orchestration as live and instrumented.
- Adyen fallback is named as the next bet.
- These are company-reported implementation signals. The recoverable failure volume and net value are unknown.
Strongest red-team attack
This is payment hygiene, not a strategic opportunity. Dual routing can lift approvals while worsening fees, fraud, chargebacks, latency, or low-quality retention. Without failure-class eligibility and a stable Stripe baseline, any uplift will be uninterpretable.
Next validation step
Confirm the payments owner, failure-class data, Adyen implementation path and baseline quality. If they exist, pre-register eligible failure classes, baseline Stripe approval, routed cohort, Adyen recovery, incremental captured revenue, processing cost, fraud and chargeback guardrails, issuer/geo splits, and retained value.
Kill condition
Kill or segment down if net recovered retained revenue is non-positive after fees and losses, if uplift disappears by issuer/geo class, or if the baseline and routed cohort cannot be made comparable.
Concrete next step
Estimated Kairos effort: 4–8 hours for design and analysis, excluding MN implementation. A billing cycle may exceed the board window. Until it completes, report readiness or launch status—not a result.
Historical candidate record — Residential Vantage Network
The hypothesis
A subset of Mysterium's residential node estate could become a consented network for last-mile measurement, geo-compliance checks, and service-access verification—selling observations rather than anonymous egress.
Actual asymmetry
The upside could be a recurring B2B measurement product with lower abuse exposure than proxy resale. The wager becomes unattractive the moment it requires a broad network conversion before demand is demonstrated.
Why Mysterium specifically
The potential edge is existing residential presence across many networks and geographies, plus node software and settlement. The edge is not verified current coverage: MN's published node/IP counts conflict, and stability, ASN diversity, consent, targeting, and measurement permissions are unknown.
Signal already present
- Mysterium publicly describes a peer-to-peer network of residential connections across participating countries.
- Commercial observability vendors already sell last-mile and endpoint vantage points, which verifies the problem category but also proves incumbency.
- RIPE Atlas already operates more than 12,000 measurement probes and exposes customised measurements.
- Kairos has no Mysterium customer request, pipeline signal, willingness-to-pay evidence, or technical permission model for this use yet.
Strongest red-team attack
The “unused asset” may be imaginary. Nodes built for traffic relay are not automatically reliable measurement probes. Catchpoint, ThousandEyes, Kentik and RIPE Atlas already cover global measurement from last-mile, endpoint, backbone, or cloud agents. Mysterium may have worse control, weaker consent, unstable availability, and no credible buyer reason to switch.
Next validation step
Before promising interviews or a node pilot, confirm outreach authority, a credible buyer list, a technical owner, consent rules and whether five to ten stable nodes can even be selected. If those gates clear, seek two serious discovery conversations before proposing a wider study.
Kill condition
Kill if no two credible design partners name a costly problem that existing tools do not solve, if MN cannot select stable consented nodes by country/ASN without exposing operators, or if required reliability and evidence integrity demand a new network rather than a thin layer on the current one.
Concrete next step
The earlier 24–40 hour estimate describes a fuller discovery cycle, not a September commitment. First gate: 4–8 hours to establish outreach authority, buyer access and technical feasibility. No product test in the current window; no material outreach programme or pursuit without the applicable Opportunity Schedule.
Why the other candidates are not on the podium
- Agent-payable access — hold. Interesting settlement fit; no current Mysterium demand signal; incumbents can expose APIs and alternative payment rails.
- Provenance / proof-of-origin — reject for September lead. The required attestation and consent capability is not established; build and trust burden arrive before demand.
- Grant-funded censorship resistance — hold. Mission fit is real, but the opportunity is funding-capped and likely transport/build heavy.
- VPN retention stack — reserve. Strong internal-operating candidate once churn, payment-failure, cancellation, and support data can be joined.
- Poland incentive economics — reserve. Valuable causal audit, but currently more a capital-allocation test than a standalone opportunity.
- Org-wide intelligence layer — excluded. Robertas explicitly ruled it a means rather than a September opportunity; material pursuit also remains Mammoth-gated.
Honest September scope
Kairos can commit to screening three to five candidates across internal and external lanes, using one comparable structure and a rejection log. Screening is not testing in the market. It can aim to deepen the strongest one or two and prepare one complete torpedo contract; launch remains conditional.
The current decision portfolio is therefore:
- one internal lead for validation;
- one internal conditional experiment candidate;
- one external discovery candidate whose job is to earn or lose the right to continue;
- additional candidates only if they clear the same evidence threshold.
A proper torpedo requires accessible data, a named owner and implementer, a stable baseline and eligible population, an implemented reversible intervention, pre-registered metrics and guardrails, and enough observation time for an interpretable result. If that gate is not clear by the end of the second working week, do not manufacture a superficial launch in the final week. A no-launch result can still be honest and useful.
Evidence-history policy
The War Room Opportunities surface is an immutable evolving series, not one page whose prior claims disappear. The stable /opportunities/ route points to the latest release; every public state also receives a semantic-version archive, an append-only changelog, a hash-chained machine manifest, and a side-by-side history view.
The first preserved sequence is:
- v0.1.0 — “Three Survivors. One Lead.” Initial public ranking; it blurred screening with serious real-world testing inside the four-week window.
- v0.2.0 — “Three Candidates. No Torpedo Yet.” Corrected the stage contract: screen 3–5, deepen 1–2, prepare one complete torpedo contract, and launch at most one only through the hard gate.
- v0.2.1 — immutable-series shell. Preserves the ranking from v0.2.0 while adding footer version links, the changelog, release manifest, and comparison timeline.
- v0.2.2 — pre-click evidence explanations. Every graph point now exposes its signal, strongest uncertainty and readiness state on hover or keyboard focus before opening the full validation plan. The project release verifier hardcodes this interaction contract and refuses a deploy if any point loses its explanation, accessibility wiring, visible interaction hint, hover/focus behavior, or reduced-motion handling.
- v0.6.3 — complete pre-20-August board. Preserved in full as the direct Before this update footer link.
- v0.7.0 — 20-August strategy update. Holds #1 and #2, broadens #3 to the GoProxies conversion system, corrects the warehouse boundary, and adds the separate K1–K3 Kairos slate.
- v0.7.1 — current live release. Preserves v0.7.0's content and ranking while containing mobile claim explanations and synchronising the top-bar date. Deployed and verified on the branded Opportunities route on 2026-08-20; v0.6.3 remains the direct full pre-update archive in the footer.
The current candidates are not required to become the final recommendations. Movement in the ranking is expected when stronger evidence arrives. The integrity test is whether the new release says what changed and preserves the earlier state—not whether the final answer resembles the starting hypothesis.
Sources
- Kairos — Mysterium All-Hands Analysis (2026-08-07) — company-reported July figures, Payments Orchestration state, and candidate test designs.
- Kairos — Node Use-Space (2026-07-31) — initial possibility map; explicitly not a recommendation.
- Kairos — September Opportunity Target (2026-08-11) — Robertas's acceptance contract and Lee's scope correction.
- Mysterium ecosystem — public network description; current node-count interpretation remains contested.
- RIPE Atlas — global probe network and customised measurements.
- Catchpoint Global Observability Network — commercial last-mile, backbone, wireless, and cloud agents.
- Cisco ThousandEyes Endpoint Agents — measurement from end-user environments.
- Kentik Global Agents — global synthetic measurement incumbency.
Evidence boundary
The July amounts and implementation states are company-reported, not audited. The 20-August GoProxies counts are warehouse working-tier aggregates at known operational grains; they have not been reconciled to finance records or confirmed by system owners. The external market sources verify that residential/last-mile measurement is a real category and already competitive; they do not verify demand for a Mysterium product. Candidate rankings and asymmetric-upside judgments are Kairos prioritisation judgments, not launch recommendations. Data-access friction remains a delivery dependency and should be logged, but not converted into a judgment about any individual.
Related
Autonomous agent relay use-case portfolio · Kairos — Standard of Performance (2026-08-14) · Kairos — Mammoth Protocol Architecture (2026-07-24)