Kairos War Room · opportunity board · 27 August 2026

Evidence-first ranking · all context through 27 August

Ranked by evidence.
No torpedo yet.

No formal rank swap. Retention gains the strongest new signal, Crypto-native becomes the most vulnerable hold, and two challengers enter the pressure map without being smuggled into the top five.

A torpedo, in this fleet's vocabulary: a decisive, launch-ready revenue strike—every gate cleared, ready to fire. Nothing on this board has earned the name yet. The title says so on purpose.

For Kairos decision-makersEvidence state · 27 Aug 2026Immutable release · v0.8.0
01 · Two axes

Evidence is not upside

Five ranked candidates, placed by documentary signal and potential asymmetry. Marker state shows how each one knows what it claims to know. Position never indicates launch readiness.

How to read it: further right = stronger real-world evidence; higher = bigger possible prize. Top-right—strong evidence and big upside—is where decisions get made; nothing has reached it yet. Corner labels name each region's failure or proof mode: "story risk" is a big prize on thin evidence, "operational proof" is solid evidence on a modest prize.

Asymmetric upside →Signal strength → Story riskDecision zoneDiscardOperational proof
Measured · working tier (L2-A)51.29% July first-attempt failure across 2,979 Stripe renewal invoices—reproduced and hashed. The voluntary-cancellation test did not trigger the flip-down rule; retained net value and owner semantics remain open.Next · owner semantics + retained-value instrument
Measured · working tier (L2-B)Recent monthly first renewal is ≈32%. Delight adds meaningful support prevalence, but the error/churn association falls to 1.18× after opportunity controls. The problem is credible; causal retained value is not yet established.Next · comparable loss matrix + commissioned joins
Parked · company-reported (L1-B)Accounts and funnel are visible; paid-test labels, revenue amounts and recurring economics remain MN-side. The published 21 Aug evidence gate passed without the cohort ledger.Overdue · economic cohort still absent
Desk signal only (L0-B / L0-D)The category exists and pays; MN's usable supply is unverified. Residential carrying 78–79% of VPN traffic does not prove measurement-node reliability, consent, geography or demand.Next · supply falsifier first; it can kill alone
Weakest hold · direct demand L0-CCloudflare's dated catalyst is narrower than a universal access block. No direct buyer signal has arrived, while Delight and Key Maker now exert evidence pressure on the slot.Next · smoke test before Sept 15 or drop
Measured · working tier Company-reported Desk signal only Parked Hover or focus for context. Activate a candidate to open its evidence.
02 · How this ranking was made

Troops before ghosts

The method is deliberately boring: thresholds before data, grades per claim, and a published condition under which each ranking flips. This is the condensed version a non-analyst can hold.

L0Synthetic / desk

Model reasoning, public sources, analogies. Not zero, never sufficient alone.

L1Company-reported

Decks and dashboards—what MN says about itself. Unaudited.

L2Measured · working tier

Reproduced in the warehouse at known grain; queries logged and hashed.

L3Reconciled

Matches an external ground truth: processor export, finance statement, bank.

L4Owner-validated

The human who owns the system confirms the semantics mean what we think.

"Troops" are L2–L4. "Ghosts" are L0–L1 standing alone. Within a level, an A–D grade scores quality—assigned per load-bearing claim, never averaged per candidate, because averaging is how fake confidence gets manufactured.

The same two axes, one level down

Every claim, placed

How to read it: the board at the top places five candidates. This places every claim those candidates stand on—one dot per claim, drawn straight from the graded lists further down this page. Same grammar as the map: further right = evidence from further inside the real world; higher = better established inside that level. Top-right is decision-grade.

What it shows: the two right-hand columns are empty. No claim on this board has been reconciled against an external ground truth, and none has been confirmed by the person who owns the system—which is the whole argument of the title. The board lives in one column.

Grade within level → Evidence level →
None
Well-argued guessDecision-gradeRumourSloppy measurement A
B
C
D
L0L1L2L3L4
05Crypto wedge ↓0Hover / focus a dot → the claim. Activate → its candidate.

Why two axes and not one: quality without level is a well-argued guess; level without quality is sloppy measurement. A grade never promotes a claim across the ghost line—an L0-A is still a ghost, and the most dangerous kind, because it argues well. Read vertically and a candidate is a cloud, not a point: the same lane holds measured cores and open gates at once. That is why grades are assigned per claim and never averaged into one.

Thresholds before data

Before touching an area: "we proceed if [measurable condition]; drop if [condition]; park only on a named external blocker." Written before the evidence is read, logged if rewritten.

Only verdict-flipping detail

A detail earns investigation only if some plausible value of it can flip the proceed/drop verdict. Everything else gets one line in the log.

The proceed bar

Proceeding requires measured numbers (≥L2) plus owner-confirmed semantics (L4). A drop can happen at any tier the moment a kill condition is met—cheap kills are wins.

Flip conditions, published

Every ranking on this page states the evidence that would change it. A board that can't say what would move it isn't a ranking; it's a mood.

03 · Inner ring

Leaks and levers in the measured business

Candidates derived from MN's own operating data. This is where the troops are—and where the honest ceilings get stated next to every rate.

01 · Measured validation lead · internal

Payment Recovery rescuing failed subscription payments

Core L2-A measuredOpen gate recoverable share L2-ASemantics L4 absent

Half of July's Stripe renewal invoices failed on first attempt. The failure is measured, persistent and concentrated—and now measured as overwhelmingly involuntary—about 97% of the unpaid face is cards that failed, not customers who left. What remains unmeasured is how much of it a better retry can win, because today's retries already try about six times and win 17%.

In plain words

Subscriptions renew by charging the customer's card automatically. In July, half of those charges failed on the first try. Some failures are customers who chose to leave—nothing to rescue there. Many are cards that just didn't work that day: no balance, expired, a prepaid card that ran dry. Recovery means winning back that second group—for example, a card that declines for insufficient funds on the 1st usually has balance again mid-month, so a retry timed to payday keeps the customer without them lifting a finger. That question is now answered: matched against MN's own churn dates, only about 3% of the unpaid July renewals belong to customers who had already cancelled; the rest are cards that failed. The new fact is that those cards are already being retried about six times each and only 17% come back—so the lever is smarter retries (which decline class, what timing, which route), not more of them. Confirming what MN's decline codes and dunning rules actually mean, with the person who owns them, is this lane's next step.

The measured core51.29%

first-attempt failure across 2,979 July Stripe renewal invoices (50.72% ex-Radar). Denominator reproduced twice; SQL and result hashed. The attempt-weighted 83.36% is retry inflation—it retires the ~75% family, it does not describe invoices.

The honest ceiling$18.5k/mo involuntary

July's still-unpaid renewal invoices, Stripe-only, after voluntary correction: $19,150 face, of which $540 (2.8%) belongs to customers who had already cancelled and $644 (3.4%) is unresolved same-day. This bounds the problem, not the prize—it is what today's dunning already failed to win. Stripe is only 38% of July gross ($87.9k of $230.3k); the other gateways were blindspot row 1, killed 16 Aug—the stores bill and retry out of sight, PayPal and Coingate have no charge table—so this ceiling does not rise from the warehouse.

Persistent, not a spike38.5–43.8% → 46–56.7%

canonical recurring failure, H2-2025 into 2026; mature recovery runs 15.0–19.5% on settled cohorts. insufficient_funds is the largest addressable pool; prepaid and debit cards carry most first failures.

Load-bearing claims, graded12 claims · grades L2-A to absent
  • L2-A

    July 2026: 2,979 Stripe renewal invoices, 1,528 first-attempt failures = 51.29% (50.72% ex-Radar). Denominator independently reproduced twice; SQL + result hashed.

  • L2-B

    Persistent, not a spike: canonical recurring failure 38.5–43.8% (H2-2025) → 46–56.7% (2026). Single pipeline, method visible.

  • L2-B

    Mature recovery is weak: 15.0–19.5% for Jan–Jun 2026 cohorts by cutoff.

  • L2-A

    July still-unpaid renewal face value $19,187—one amount per invoice, derived twice independently.

  • L0-B

    External reference: Stripe's published subscription first-attempt failure baseline ≈9%; MN runs more than 5× that. Older publication, broad mix.

  • L2-A

    The gate, measured: of July's 1,251 first-failed-never-recovered renewal invoices ($19,150.50), 38 ($540, 2.8%) show churn dated before the attempt—voluntary; 897 ($13.9k) churn on average 3.6 days after it, 276 ($4.1k) have no churn row. About 97% involuntary. Stop rules cleared (unresolved same-day 3.4% vs 15% ceiling; unlinked 0.08% vs 10% floor). Cohort reproduces the 08-11 count to 0.1%; SQL and result hashed. Invisible-invoice caveat still applies.

  • L2-B

    Retry saturation: July's 1,556 first-failed renewal invoices absorbed about 9,200 charge attempts (≈6 each) and 269 (17.3%) recovered; 341 were never retried. Invoice grain from the charges table, reproducing the 08-12 rates. "Retry more" is not the lever.

  • L2-B

    Fees do not kill it: Stripe 4–5% of gross, Adyen ≈3.7%, Google 15%, Apple ≈24% (recorded only from Dec 2025), PayPal 6–7%, Coingate 1%; blended 11.6% in Q1-2026. Fee table frozen 2026-04-28, so nothing after April. A recovered Stripe renewal nets ≈95%.

  • L2-B

    Failure concentration: insufficient_funds is the largest addressable pool (23.6% recovery); prepaid 31.3% and debit 48.9% of first failures.

  • L2-B

    Payments Orchestration shows no detectable first-attempt improvement yet (52.35% pre vs 53.18% post, right-censored). Descriptive split, non-causal.

  • L2-A

    Stripe is $87.9k of $230.3k July gross (38%)—apple, google, coingate and paypal carry the rest, unexamined.

  • L4 · absent

    Decline-code semantics, dunning rules and orchestration scope—owner answers outstanding, including whether previously_declined_do_not_retry is intentional.

Flip condition · published

If the failed pool turns out to be dominated by customers who meant to cancel, plus charges that never resolve either way—pushing conservative rescuable value below ~$2k/mo—payments drops off the lead. That is the number that would change this page. Tested 16 Aug 2026: voluntary $540 plus unresolved $644 of $19,150 face—not triggered.

Next test · the L4 gate

The matched voluntary-cancellation test has run (16 Aug; ≈97% involuntary, stop rules cleared, flip condition not triggered). Next: an owner session on dunning and decline semantics—state the retry-class selection rule or include do_not_honor / invalid_account—then a processor export for one month of renewal invoices, then one pre-registered, reversible experiment on a single owner-approved decline class.

02 · Measured lane · conviction ↑ · internal

Retention Economics pricing, churn and verified reliability

Level L2-B measuredDelight inside #2Next pass loss matrix + joins

Revenue doubled in 24 months on price, not volume—and first-renewal retention on recent monthly cohorts now sits materially below the external corridor. Delight adds one concrete product-intervention hypothesis: detect failure, contain unsafe fallback, recover, and verify the outcome. The lane strengthens; causation remains open.

In plain words

MN doubled revenue by charging more, not by winning more customers. The open question is what that did to loyalty: of the people who start a monthly plan now, only about one in three pays a second month—against an industry norm above one in two, and below MN's own 2024 customers. Two suspects, deliberately kept apart: the higher prices, or a shift in who's buying (more customers from countries and app stores where everyone quits sooner). One warehouse query can tell the suspects apart—and the answer changes the move. If price did it, the finding is "stop raising." If the customer mix did it, the price rises were free money and the leak is elsewhere.

Price-led growth+73% ticket · +19% count

Average ticket $10.52 → $18.19 across the tier repack; purchase count nearly flat. The doubling was a pricing event—which proves the lever can move revenue at 2× scale.

Below the corridor≈32% first renewal

on recent monthly cohorts, against a 53–61% external median (RevenueCat, 115k apps) and down ~7 points from 2024 cohorts across the repricing window. No loyalty plateau: long-tenure survivors still decay ~8%/mo.

Cause · openTwo rival explanations.

Price is one hypothesis. Geo/channel mix shift is the named rival: survivors skew web-card tier-1/2 ≈2.5× Google-Play tier-3. Claiming either now would outrun the evidence.

Load-bearing claims, graded8 claims · level measured, causes open
  • L2-B

    Revenue doubled in 24 months price-led: new-purchase count +19%, average ticket +73% ($10.52 → $18.19); the tier repack did it. Survives the duplication correction.

  • L2-B

    First renewal on recent monthly cohorts ≈32% vs 38–40% for 2024 cohorts—a ~7pt deterioration across the repricing window; cross-validated in two independent tables.

  • L2-B

    2026 new-purchase volume drifts down since January (7,160 → 6,346).

  • L2-B

    Churn by country tier is measured on a month-start cohort: tier 3 turns over ≈1.5× tier 1 every month Feb–Jul 2026 (July gross 38% vs 25%; net of 30-day recoveries 28% vs 19%). List price is uniform across tiers on Stripe, Coingate, PayPal and Apple, so the tier gap is not price elasticity; tier-3 cancellers name product failure more and price less on every platform (survey sample). Row W6 carries it.

  • L0-C

    The cause of the deterioration. Price (elasticity) is untested hypothesis H1; seasonality, marketing and store-mix shift have equal standing—survivor skew makes mix shift a serious rival.

  • L1-C

    MN itself intends adaptive-pricing tests "hopefully end of August" (all-hands; ownership risk flagged)—a live attachment point for pre-registered measurement.

  • L2-B

    Support prevalence at working tier: 889 of 9,060 unique Intercom conversations in the latest 90-day window matched the locked human-tag connection-failure taxonomy—9.81% of all conversations and 21.67% of tagged conversations.

  • L2-B

    The crude error-exposed/churn association was 8.52×; controlling for observed user days reduced it to 2.00×, and also controlling for recorded event-volume opportunity reduced it to 1.18×. Recorded errors may precede cancellation, but these fields do not establish causal retained value.

Flip condition · published

Per-tier, per-geo cohorts showing the deterioration is a mix-shift artifact re-park the pricing half. And if elasticity shows the 2026 volume drift is price-caused, the upside flips sign—the finding becomes "stop raising prices," still decision-grade.

Next test · choose the largest controllable loss

Build the comparable loss matrix across payment failure, voluntary cancellation, non-activation, price/mix and product reliability. For Delight, commission incident-to-support/cancellation/value joins only after grain, freshness and identity fitness pass. The candidate earns independence only on production incidence, retained-value effect, a bounded intervention result and a Mysterium-specific advantage.

04 · Reserve / park · drop-lean

Poland incentive economics

MN pays people to run nodes; the deck reports +20% Polish nodes on dynamic incentives—L1-C, with no baseline, cost, persistence or utilisation, and ~35% same-day node-registration churn in the 2024 corpus. No incentive table among the enumerated warehouse datasets. One Šaras question locates the data or drops the area.

Folded

Retention-stack interventions

No measured below-corridor defect stood alone until the retention-economics lane entered—so save-flow work folds into lane 02. The 2024 cancellation-button history argues repair framing, not friction.

04 · Generative ring · new lane

What the data cannot rank

An evidence-first ranking is a streetlight: it can only rank what already has data, and MN's data only describes what already exists. This ring exists so the ladder cannot become a box.

G1L0 by designjoint · MN owner

Plan-migration offer monthly → annual

Why MN: tier appetite is proven at 2× scale (+73% ticket), and an annual plan has 1 renewal event where monthly has 12—migration structurally deletes involuntary-churn exposure while pulling cash forward. The failed-renewal moment is a natural offer point: "card failed—switch to annual instead."

Cheapest test: design rides the payments experiment. The rare move that is simultaneously generative and welded to the board's best-measured lane.

Known counter-evidence: none found for VPN plan migration; unexamined.

G2L0 by designjoint · MN owner

VPN ↔ proxy cross-sell

Why MN: GoProxies is in-house—two paying audiences, one company, zero cross-sell ever examined. Nobody else owns both lists, and proxy needs ~25× demand growth.

Cheapest test: one in-product or email offer cohort in each direction.

Known counter-evidence: Oct-2024: small self-service proxy purchases don't convert upward—a caution for proxy-side upsell, silent on VPN→proxy.

G3L0 by designKairos authority

Node-runner community as launch audience

Why MN: ~33k crypto-native operators are MN's own distribution channel; no incumbent has one attached.

Cheapest test: folds into the crypto-wedge smoke test as its first outreach pool—community post and opt-in before any cold outreach.

Known counter-evidence: node-count basis conflicts; community activity level unknown.

G4L0 by designone query first

Winback as an engineered offer

Why MN: Winback is already a warehouse revenue type—$12.6k in July. Reactivation exists; nobody has examined whether it is systematic or accidental. First-party lapsed-customer list, years deep.

Cheapest test: one warehouse query (organic or campaign-driven?), then one offer test.

Known counter-evidence: none; genuinely unexamined.

G5L0-C · heldKairos authority

B2B / team VPN packaging

Why MN: selling the same network to companies as a team product—higher ARPU and stickier than consumer, on existing infrastructure.

Cheapest test: desk scan plus one landing test, market-side.

Known counter-evidence: crowded category (Tailscale and peers). Held.

Separate slate · updated 27 Aug

Kairos opportunities—not MN candidates

Scope line: these emerged from the autonomous-agent relay portfolio, Standard of Performance work and the Key Maker intake. They do not enter the MN top five, do not inherit another candidate's evidence, and do not authorize product build, outreach, transfer or spend.

K1comparative judgment · 17/20

Cross-boundary opportunity and exception room

What is new: the relay turns conflicting evidence, permissions, owners and deadlines into one decision surface with receipts. In the current portfolio it ranks alongside payment exceptions as the strongest internal Kairos application.

Cheapest proof: run it on one real exception-heavy workstream and score decisions closed, contradictions surfaced and time-to-resolution.

Boundary: 17/20 is a comparative strategy score, not measured economics. The current relay runtime is not production-load ready.

K2capability · not revenue

Standard-of-Performance ratchet

What is new: every completed investigation can improve the next one—questions, evidence gates, owner semantics, rejection logic and release receipts compound instead of disappearing in chat.

Cheapest proof: compare repeated work before and after the ratchet on coverage, correction rate and decision latency.

Boundary: this is an internal delivery system until a buyer, price and external operating contract exist.

K3external slate · untested

Managed relay applications

Where it may travel: billing-exception rooms, cyber-incident coordination, healthcare revenue-cycle exceptions, and M&A or joint-venture work where evidence and authority cross organisations.

Cheapest proof: one buyer-specific exception map before any product claim.

Boundary: these belong to a separate Kairos opportunity slate. None is launch-ready; none belongs on MN's board without a direct Mysterium fit.

K4MN problem L1 · external proposition L0

Key Maker governed access without human credential toil

Two propositions, kept separate: inside MN, Key Maker could reduce access-cycle time, status confusion, human touches and unsafe custody while unlocking work across the ranked opportunities. Outside MN, the same operating system may become a reusable offer.

Evidence now: first-party MN problem signal; adjacent category existence L0-A; adjacent commercial activity L0-B. Capture timing, touches, retries, false-green states and useful work unlocked as a side effect of ordinary onboarding. The external path separately needs buyer, budget, price and delivery-economics evidence.

Boundary: not rank #6. Key Maker-specific demand, buying form, price and repeatability remain L0-C or unmeasured. Evidence-only, its adjacent-category and commercial signal is stronger than #5; a normalized portfolio pass still decides whether that becomes a rank move. Open Key Maker →

05 · Outer ring

External candidates

The September brief's bar: a nameable external candidate with first-hand signal—or an evidenced empty statement. First-hand demand signal is currently absent across the lane, and this page says so before it is asked.

01 outer · #04 overall · discovery

Residential Vantage measurement from real home connections

Structure L0-BCoverage L0-D conflictedDemand absent

Hypothesis: a consented subset of Mysterium nodes becomes a last-mile measurement and geo-compliance network—selling observations instead of anonymous egress. The lane inverts MN's structural fragility: operator identity becomes an asset.

In plain words

MN's network is thousands of volunteer computers in real homes. Today they relay traffic. This candidate would sell something different: observations. From a real home connection you can see what a datacenter cannot—whether a streaming app actually loads in Warsaw, how fast a bank's site feels to a normal household, whether a government block is really in effect. Companies already pay for such measurements; RIPE Atlas, Catchpoint and ThousandEyes sell versions of it. Example buyer: a streaming service paying to know "does our app work right now on real home connections in Poland, as residents actually experience it?" The two open questions, in test order: does MN's supply really cover what the pitch claims—and would any buyer pick MN over the incumbents.

The category is realIncumbents already sell it.

Synthetic monitoring from datacenters structurally cannot see what a residential vantage sees. RIPE Atlas, Catchpoint, ThousandEyes and Kentik prove the category pays—and that it is already competitive.

The supply questionNode counts conflict three ways.

32,570 across 182 countries vs 31,547 across 135 vs the deck's 33,000—with 60,092 reported in 2022 and ~35% same-day registration churn. "Node" is not yet a defined unit. The new finding that residential carries roughly 78–79% of VPN traffic is a usage denominator for self-healing—not proof of stable, consented Vantage supply.

Test orderThe falsifier is cheap.

A node-registry coverage cut (via Šaras) is cheaper than any demand test and can kill the candidate alone. Only if supply holds: two credible buyer conversations before proposing anything wider.

Load-bearing claims, graded5 claims · coverage is the D
  • L0-B

    The category exists and pays: real comparables sell residential-vantage measurement; datacenter probes structurally cannot replicate it.

  • L0-B

    The lane inverts MN's structural fragility—measurement, verification and compliance make operator identity an asset; the raid-risk profile disappears.

  • L0-D

    MN's usable supply supports the claim—node counts conflict; "node" undefined; ~35% same-day registration churn.

  • Absent

    Any first-hand buyer signal.

  • L1-C

    Supply reliability is first-order: persistence before buyers.

Flip condition · published

Supply measurement contradicting the coverage claim kills this candidate regardless of demand. Kill conditions carried verbatim: no two credible design partners naming a costly unsolved problem; no stable consented nodes by country/ASN; or required integrity demanding a new network rather than a thin layer.

Next test · supply falsifier first

The node-registry coverage cut via Šaras—count, geography, persistence at known grain. It can kill alone, which is exactly why it runs first.

Expand incumbents and limits
02 outer · #05 overall · weakest hold

Crypto-Native Access Wedge internet access AI agents can pay for in crypto

Demand L0-C · no buyerCatalyst Sept 15 · narrowAuthority Kairos-side

The one slice the July screen didn't kill: protocol-level, no-KYC, crypto-paid egress for crypto-native and agent-infra builders who don't want a vendor relationship. Second by evidence, first by test order—because the catalyst has a date.

In plain words

AI agents—software that browses and fetches data on its own—increasingly need internet access their code can buy without a human: no sales call, no contract, no identity check. Established providers won't sell it that way. MN's network already takes crypto and doesn't need to know who you are—which for this buyer suddenly reads as a feature, not a bug. Example buyer: a small team whose research agents fetch public web pages from many countries, paying per gigabyte from a crypto wallet. The test is cheap and dated: a landing page plus a direct ask to ~20 named teams building such agents—before Cloudflare's Sept-15 bot-rule change forces everyone to confront the question.

The defensible slicePermissionless is the moat.

Incumbents structurally won't go permissionless; Grass is the only comparable. The generic agent-access market is a knife-fight the July screen already killed—this wedge deliberately excludes it.

The dated catalystSept 15 · narrower than the story.

Cloudflare will block Agent and Training bots on ad-bearing pages by default for newly onboarded domains. That raises the information value of testing; it does not create universal demand for paid egress.

The test, in-authorityDays, near-zero cost.

Landing page and opt-in plus outreach to ~20 named crypto-agent teams—starting inside MN's own node-runner community (G3). Market-side, fully inside Kairos's settled self-run authority, with a pre-registered response floor.

Flip condition · published

Real conversions above the pre-registered floor put this above Vantage. A ~zero response drops it to the rejection log with evidence—an equally useful result.

Next test · before Sept 15 or drop

Run the smoke test now; pre-register the floor before outreach. After Sept 15 the catalyst has passed and the candidate drops on the calendar alone.

03 · Hold · folded into Vantage

Provenance / proof-of-origin selling verifiable proof of where traffic really came from

Certifying that a connection or measurement genuinely originated from a real household in a stated place—proof a buyer could audit. Same risk-inversion cluster as Vantage (L0-B structurally) but a less-formed buyer set and no catalyst date. It rides Vantage's discovery conversations as a secondary probe—and promotes only if buyers keep reaching for exactly that proof.

04 · One bounded pass

Grant-funded censorship resistance foundation money for keeping the open internet reachable

Mission-aligned, near-zero revenue in the possibility map (L0-B). No named program with an inside-horizon deadline exists anywhere in evidence. One bounded search pass (≤2h) for a program with a ≤6-month award; otherwise it takes an honest line in the rejection log—which strengthens the portfolio.

06 · Not on the board

Rejected and held

A rejection log is evidence that selection happened. This one inherits the July screening kills verbatim, with reasons—because a candidate that re-enters through the side door wastes a month.

July kill

Generic agent-access outbound

Selling internet access to AI-agent builders in general: vendor-dense and freshly VC-funded (Browserbase, Anchor, Firecrawl), and the big proxy incumbents already ship ready-made agent products. The wedge above deliberately excludes this market.

July kill

Head-on B2B proxy

Against Bright Data and Oxylabs—Oxylabs alone runs 397 people, in the same city.

July kill

Token-first revival

Rebuilding the business around the MYST crypto token. Base rates say no; every precedent that pulled it off needed a bigger trough and a war chest.

July kill

"Ethical supply" as legal moat

Bright Data's federal court wins removed the moat.

July kill

Consumer dVPN growth race

Doubling down on growing the consumer VPN against free and giant incumbents. No MN-specific right to win emerged from the July screen.

July kill

FWA / consented-mobile supply

Growing the network's supply side through mobile and fixed-wireless connections. Screened out in the July right-to-win pass: a supply thesis without a matched buyer.

Folded

Provenance as September lead

Folded into Vantage's probes; promotes only on buyer pull.

Excluded

Org-wide intelligence layer

A means, not a September opportunity. Material pursuit remains gated separately.

Folded

Retention stack as standalone

Folded into the #2 retention-economics lane; repair framing, not friction.

Lane coverage · declared, not implied
Internal lane

Measured evidence at working tier: warehouse-reproduced July figures with logged, hashed queries. Semantics validation (L4) is still open everywhere—no internal candidate is past its proceed bar yet.

External lane

Screening and discovery depth only. First-hand demand signal is absent across the lane, and the thin-result posture is pre-declared under the September brief's own empty-result clause.

Context fact: GoProxies is MN's own in-house brand—MN captures 100% of proxy revenue, and per the infrastructure assessment capacity is not the constraint; demand is.

07 · Not yet investigated

The blindspot map

What Kairos has not touched, in the order it should be touched, and why—now a working map, not a list: every row is a quest with a lane, a decision rule written before the data, an owner column, and a status that is derived from the map's own event record. Judgment stays visible; there is still no composite score.

13 quests · 3 open · 1 scouting · 6 with signal · 3 clearedday — of 30Kill test · first claim on 16 Aug 2026 — the map is being usedPredicted vs actual · 9 of 9 predictions held; 0 ran late.

How to read it: three working lanes, each spending a different resource, each in pull order — top row of a lane is the next quest in that lane. Chips: Prize how much money the territory touches · Prior our L0 judgment that a lead-class finding hides there · Data where the evidence lives · Signal predicted days from claim to first measured number, and the gate · Owner the person who holds this territory's meaning · Status where the quest is. A quest ends only as climbed (a candidate), killed (the drop rule fired), or parked (a named blocker with a revisit date). Every rule was written before the data and changes only in a release.

Warehouse lane Self-serve. Kairos can query these today; the only gate is BigQuery access. Pull in this order. Spends: Kairos hours.

W1

Non-Stripe payment funnels the other four gateways, same failure question

apple, google, coingate and paypal carry ~62% of July gross with zero failure or recovery analysis. The proven Stripe method extends directly—and public store data (billing errors run 15–32% of store cancellations) says the involuntary class plausibly exists there too, at a bigger base.

Unlocks → Raises Payment Recovery's ceiling from Stripe-only (38% of July gross) to the whole base.

Decision rule — written before the data, changed only in a release
Proceed if
first-attempt failure on any non-Stripe gateway is measurable at charge grain and ≥ 20% of that gateway's renewal invoices.
Drop if
every gateway is < 10%, or the class is structurally invisible (store-billed, no retry visibility).
Park
only if the charge-grain tables carry no outcome field — a named data blocker, not a shrug.
Prize · highPrior · highData · in-warehouseSignal · fast · ≤7 dOwner · not yet namedStatus · killed
W2

Marketing economics what MN spends to win a customer, and through which door

Spend, CAC, ROAS, channel and geo contribution. The datasets exist in-warehouse, never opened—and for 82% of revenue MN cannot currently say which marketing channel brought the customer. Deck claims stay unverified and the quality-customer question is undecidable without it.

Unlocks → Decides the quality-customer question and the retention cause (price vs mix); gives every offer test its CAC denominator.

Decision rule — written before the data, changed only in a release
Proceed if
spend + attribution tables let us compute CAC for ≥ 50% of July revenue at channel grain.
Drop if
spend data is absent from all 24 datasets — then this becomes an MN-side ask and changes lane.
Park
on the ask, with the date it was made.
Prize · highPrior · highData · in-warehouseSignal · medium · ≤21 dOwner · not yet namedStatus · killed
W3

Pricing / packaging elasticity does the price move the churn — per tier, per country

Per-tier, per-geo response—the climb path for the #2 lane. What is now measured: the direct gateways charge one list price across tiers ($13.49 a month for the plus plan on Stripe, Coingate, PayPal and Apple, in every tier; Google Play tier 3 lands ≈7% lower), and tier-3 users churn ≈1.5× faster than tier 1 while naming price less when they cancel. Because the tiers do not differ in price, the tier churn gap is not elasticity evidence — the lever it points at is product (row W6). Elasticity itself remains untested.

Unlocks → The climb path for Retention economics (#2): turns L0-C on cause into a measured answer.

Decision rule — written before the data, changed only in a release
Proceed if
per-tier, per-geo cohorts show a renewal difference of ≥ 5 points between price tiers with ≥ 200 renewals per cell.
Drop if
cells are too thin to read (< 200 renewals) across the board — then elasticity is untestable at this scale and the row says so.
Park
never — the data is in-warehouse.
Prize · highPrior · mediumData · in-warehouseSignal · medium · ≤21 dOwner · not yet namedStatus · signal · 0 d
W4

Support economics what customers write in about, and what each contact costs

What customers contact support about, what each contact costs—and what share of conversations are about billing, which cross-checks the payments lane. The Intercom datasets sit in-warehouse and MN just automated tagging: a cheap voice-of-customer layer, unopened.

Unlocks → Cross-checks Payment Recovery from the customer's side; a voice-of-customer layer for any offer test.

Decision rule — written before the data, changed only in a release
Proceed if
the billing-related share of conversations is classifiable and ≥ 15%.
Drop if
tags cannot separate billing from the rest — then the layer is unreadable and the row closes.
Park
on tagging coverage, if the automated tags start after the period we need.
Prize · mediumPrior · mediumData · in-warehouseSignal · medium · ≤21 dOwner · not yet namedStatus · signal · 0 d
W5

Fraud / abuse is the failure denominator clean — chargebacks and card-testing

July's failed first attempts are already shown not to be card-testing (1.27 attempts per customer)—which partially clears the payment-failure denominator. Chargebacks remain unquantified.

Unlocks → Clears or dirties the payment-failure denominator that Payment Recovery stands on.

Decision rule — written before the data, changed only in a release
Proceed if
chargebacks are quantifiable and > 1% of gross.
Drop if
chargebacks < 0.5% of gross — the denominator is clean and the row closes as a win.
Park
if chargeback data is absent from the warehouse — then it is a processor-export ask.
Prize · mediumPrior · lowData · in-warehouseSignal · fast · ≤7 dOwner · not yet namedStatus · killed
W6

Android product experience in the largest paying geography tier-3 users leave faster and, when asked, name product failure over price

Nigeria is the #1 country by 2026 new purchases (8,208, mostly Google Play at $12.90 a month). Users in tier-3 countries churn about 1.5× faster than tier 1 on a month-start cohort (July: 38% gross / 28% net of 30-day recoveries, against 25% / 19%). When they cancel in the app they name price less than tier-1 users on every platform (Android 23% vs 30%, iOS 19% vs 29%, Windows 16% vs 25%) and disconnects, blocked sites, missing features and error 7040 more. That is a survey-sample direction, not a churn cause: the sample is self-selected, app-only, ~7.5k submissions against ~44k churn rows.

Unlocks → Gives Retention Economics (#02) its tier cut and moves the lever from price to product; a survival curve by plan duration is the climb step.

Decision rule — written before the data, changed only in a release
Proceed if
the tier-3 cohort churn excess stays ≥ 5 points above tier 1 for three consecutive months AND a survival curve by plan duration keeps the gap after yearly plans are held out.
Drop if
the excess closes below 5 points, or disappears once plan duration is held constant — then it was plan mix, not the product.
Park
never — the data is in-warehouse.
Prize · highPrior · mediumData · in-warehouseSignal · fast · ≤7 dOwner · not yet namedStatus · signal · 1 d
W7

Failed payments as a churn label — and the remainder billing never recovers how much churn carries a billing-retry label, and how much of it comes back

In 2026 about 48% of churned subscriptions carry a billing-retry label; the rest are voluntary, including explicit cancellation requests. One churn row is one subscription. Separately, about a quarter of churn rows in the status ledger reverse within 30 days. 93% of recurring-type reactivations arrive within 30 days of the churn row (10,328 of 11,064). That recurring-type reactivation equals billing recovery rather than a returning customer is a hypothesis — the reason join matched 10.1% and cannot carry it (ask 14). Name the query: reactivation rows in 2026 by ≤30 d × type, to give P(Recurring | ≤30 d) directly. What the warehouse cannot say is which labelled churns were involuntary in outcome, or how large the never-recovered remainder is: the key that pairs a churn with its billing attempts is MN's.

Unlocks → Sizes the un-recovered remainder that Payment Recovery (#01) can act on and Retention Economics (#02) must net out.

Decision rule — written before the data, changed only in a release
Proceed if
the pairing lands and never-recovered billing-labelled churn is ≥ 10% of monthly churned subscriptions.
Drop if
MN answers that no pairing key exists AND no proxy join reaches ≥ 90% match — then the remainder is an MN-side number, not a Kairos one, and the row says so.
Park
if the key is unanswered by the drop-by date — parked on the ask, revisited when it lands.
Prize · highPrior · mediumData · in-warehouseSignal · medium · ≤21 dOwner · not yet namedStatus · signal · 1 d
W8

The Primer switch and the payment label it hides under a new web payment gateway that the revenue spine still labels Stripe

Primer replaced Stripe as the web gateway in the week of 22 July 2026. The web funnel shows it (Stripe transactions fall to near zero, Primer takes them); the revenue spine does not — it keeps every Primer payment under the stripe label. Week by week on identical New-type populations, web dollars ran at 101 · 102 · 101 · 100 · 100 · 110% of the spine's across the 22 July switch — flat through the cut-over, with the final week 10% over. Nothing visible is missing at weekly grain; row-level completeness is unprovable (the web table carries no transaction id, ask 16), and any Stripe-keyed analysis — Payment Recovery's failure rates included — silently absorbs Primer traffic.

Unlocks → Keeps Payment Recovery (#01) honest about its denominator; a lineage fix upstream is the cheapest win on the board.

Decision rule — written before the data, changed only in a release
Proceed if
Primer's first-attempt failure rate at charge grain differs from Stripe's by ≥ 5 points on ≥ 500 charges a week — then the recovery candidate needs a Primer arm.
Drop if
the rates match and the label is corrected upstream — then this row's only product was the lineage fix, and it closes.
Park
never — the data is in-warehouse.
Prize · mediumPrior · highData · in-warehouseSignal · fast · ≤7 dOwner · not yet namedStatus · signal · 1 d

Human lane These live in MN people's heads or MN-side records. Start now and run in parallel — never let this lane become the critical path. Spends: MN people's time.

H1

Metric lineage & owner semantics who owns each number, and what it means to them

What each measured field actually means to the human who owns it—the L4 gate for every area above. Until it clears, every "proceed" on this board stays conditional.

Unlocks → Lifts the two measured candidates from L2 to L4 — the only move on this board that can. Fills the owner column of every other row.

Decision rule — written before the data, changed only in a release
Proceed if
the owner of each load-bearing field on the two measured candidates confirms its semantics in a sit-down — recorded, dated.
Drop if
not applicable — a gate does not drop.
Park
on owner availability, with the date asked.
Prize · gates allPrior · gatesData · owner sessionsSignal · medium · ≤21 dOwner · assumedStatus · scouting · since 16 Aug 2026
H2

GoProxies economics and owner semantics the funnel is visible; the money and paid-test labels are not

The warehouse now exposes GoProxies accounts, plans, products, checkout stages and support. It still lacks revenue amounts, paid-test cohort labels, prices, margins and recurring outcomes. That corrected boundary broadens candidate 03 without promoting it. Rider: GoProxies' own ToS names no legal entity, a confirmed diligence gap that is MN's own to fix.

Unlocks → Grades the GoProxies conversion system; un-parks its paid-test core; opens the VPN↔proxy cross-sell candidate.

Decision rule — written before the data, changed only in a release
Proceed if
MN supplies a paid-test cohort ledger with amount, end date and recurring outcome at account grain.
Drop if
the ledger does not exist — then the paid-test thesis drops, even though broader funnel diagnostics remain.
Park
the economic claim on the ask; continue only bounded warehouse diagnostics that can change a conversion decision.
Prize · highPrior · mediumData · mixedSignal · medium · ≤21 dOwner · not yet namedStatus · open
H3

Node / incentive economics what the node network costs, and how much of it is real

Poland cost, persistence, utilisation, payout flows. The node-count conflict is now three-way (32,570/182 countries vs 31,547/135 vs the deck's 33,000)—this row gates both the Poland reserve and the Vantage supply claim.

Unlocks → Gates the Poland incentive reserve and the Residential Vantage supply claim.

Decision rule — written before the data, changed only in a release
Proceed if
MN supplies incentive outlay and node persistence at node grain.
Drop if
measured outlay < $5k/mo with no retention effect — the Poland flip condition.
Park
on the ask.
Prize · mediumPrior · mediumData · MN-sideSignal · slow · ≤30 dOwner · not yet namedStatus · open
H4

Partnerships / affiliates / resellers does a partner channel exist at all

No MN data of any kind in Kairos evidence—existence unknown, and that is the finding. One question sizes whether the channel exists at all.

Unlocks → Sizes a channel or closes it; either is progress.

Decision rule — written before the data, changed only in a release
Proceed if
the channel exists and carries > 5% of revenue.
Drop if
it does not exist, or carries < 1% — closed as a finding.
Park
on the ask.
Prize · unknownPrior · unknownData · one askSignal · slow · ≤30 dOwner · not yet namedStatus · open

Corpus lane Self-serve but slow: the all-hands deck corpus and public filings. Runs in the background. Spends: Kairos hours, unattended.

C1

Finance perimeter burn, runway, headcount — the denominator of everything

Burn, runway, headcount, entity map—the denominator of every materiality judgment on this board. Two self-serve paths: the all-hands deck corpus sweep, and public registry filings—MN Intelligence UAB, 2025 revenue €1,132,969, net loss €268,369, 13 employees (one entity of several; BlockDev AG Zug separate). Transaction fees are already fillable in-warehouse (July ≈ $17.2k).

Unlocks → Sets the materiality of every candidate and every row above.

Decision rule — written before the data, changed only in a release
Proceed if
burn and runway established from corpus + registry within ±20%.
Drop if
not applicable — a frame does not drop.
Park
if neither the deck corpus nor the registry yields it — then it is an MN finance ask.
Prize · frames allPrior · framesData · corpus + registrySignal · slow · ≤30 dOwner · not yet namedStatus · signal · 0 d

Watched, not worked Real for MN, outside Kairos's leverage. Named so it is not forgotten; not a quest. Spends: nothing.

X1

Token / MYST exposure the token risk MN carries, outside Kairos's reach

Named a major struggle in the deck. Real risk, weak Kairos leverage—watch, don't work.

Note not a quest — promoted to a row only if MYST exposure shows up material inside the finance perimeter.

Prize · low for KairosPrior · lowData · lowSignal · slow · ≤30 dOwner · not yet namedStatus · watched

Standing pass Repeats every release rather than ending. Reports its yield or its emptiness. Spends: one pass per release.

S1

The offer/packaging space itself meta the search for offers that don't exist yet

No divergence pass had ever been run on MN's existing base—every prior candidate was a diagnosis, not an offer. The generative ring above is the first pass, and the pass repeats each release.

Note not a quest — the pass repeats each release and reports its yield or its emptiness.

Prize · unknown by naturePrior · by natureData · divergence passSignal · fast · ≤7 dOwner · KairosStatus · standing
08 · Provenance

What this ranking rests on

Warehouse measurement at working tier, company reports, public primary sources, explicit inference—and named unknowns.

01
Mysterium All-Hands Analysis · 08-07

July figures, paid-test share, orchestration state and candidate context—company-reported tier.

02
Kairos Master State

Current constraints, corrected claims, hypothesis board and authority gates.

03
Warehouse query audit

The measured claims: reproduced denominators, logged SQL, hashed results, known grain. The 20 Aug audit also fixes the GoProxies coverage boundary: operational surfaces present, revenue amounts and paid-test labels absent.

04
RIPE Atlas · official

Global probe network, customised measurements and current probe scale.

05
Catchpoint · official

Current commercial agent inventory and last-mile positioning.

06
Cisco ThousandEyes · official

Endpoint agents and measurements from user environments.

07
Kentik · official

Global synthetic agents and private deployments.

08
Kairos Standard of Performance · 08-14

The internal evidence ratchet behind K2. Capability claim only; not an MN revenue opportunity.

09
Current Opportunity Hypotheses · through 08-27

The canonical rank judgment, Delight placement, Key Maker claim grades and explicit no-torpedo boundary.

10
Data Access Map · 08-27

Eleven source connections: 2 ready for a bounded question, 3 partially mapped, 6 blocked. Access changes time-to-evidence; it does not change a candidate's economics by itself.

11
Delight · working opportunity

The bounded detect → contain → recover → verify loop, inside #2 Retention Economics and not independently promoted.

12
Key Maker · working proposal

The future-state operating concept. Its proposal surfaces do not assert current MN access truth; the opportunity grade on this page remains separate.

09 · Machine record

Same board. Structured.

A compact reading layer for collaborator agents; no hidden evidence and no added authority. The full structured payload travels in this page's embedded machine brief.

Verdict
No formal rank swap. Payment Recovery remains #1; Retention Economics remains #2 and gains the strongest new signal; GoProxies remains #3 with its economic gate overdue; Residential Vantage remains #4; Crypto-native Access remains #5 and becomes the weakest hold. Delight stays inside #2. Key Maker is pressure on #5, not rank #6. No candidate is yet a proven opportunity.
Inner ring
01 Payment Recovery (measured validation lead) · 02 Retention Economics (conviction up; Delight inside the lane) · 03 GoProxies conversion system (funnel visible; paid-test economics parked and overdue) · Poland incentives (reserve, drop-lean).
Generative ring
G1 plan-migration · G2 VPN↔proxy cross-sell · G3 node-community launch audience · G4 winback engineering · G5 B2B packaging (held). All L0 by definition; ranked on asset-fit, never dressed as validated.
Separate Kairos slate
K1 cross-boundary exception room · K2 Standard-of-Performance ratchet · K3 managed relay applications · K4 Key Maker. Key Maker has first-party MN problem signal and stronger adjacent-category/commercial evidence than #5, but its external buyer, price and delivery economics remain unverified.
Outer ring
04 overall · Residential Vantage (discovery; supply falsifier first) · 05 overall · crypto-native access wedge (weakest hold; smoke test still unrun) · provenance (hold, folded) · grant-CR (one bounded pass).
Method
Thresholds before data; L0–L4 evidence ladder with A–D grades per claim; proceed needs ≥L2 numbers plus L4 semantics; flip conditions published; blind re-derivation adjudicated before release.
Blindspots
Twelve untouched areas, now a working map: ten quests in three lanes (warehouse · human · corpus) plus one watched and one standing row, each with a decision rule written before the data, an owner column, a predicted days-to-signal, and a status derived from the map's own event record. Warehouse lane leads with non-Stripe payment funnels (~62% of July gross); human lane leads with metric lineage and the owner map (the L4 gate). The map carries its own kill test: unused by day 21, it says so.
Access effect
Eleven source connections: 2 SOURCE_READY, 3 MAPPING_PARTIAL, 6 SOURCE_BLOCKED. BigQuery and Slack lower time-to-signal for internal lanes; GoProxies economics and Vantage supply still depend on MN-side evidence.
Acquisition watch
Context lane only. It raises the weight of retention, revenue quality, margins, distribution, reliability and transferable assets; Key Maker reduces diligence friction but does not create acquisition value.
Authority
No material pursuit, build, outreach programme, transfer or spend is authorized by this page. Product-touching generative tests are joint decisions with an MN owner; market-side tests run in Kairos authority.