Kairos · terminal red-team conclusion · 1 September 2026

NESTED

Payment Recovery belongs inside Customer Retention.

Count value only when a customer meant to continue and a payment, subscription, or entitlement failure broke that continuity.

The only retained-subscription value that qualifies

1Customer intended to continuePositive evidence, not merely no recorded cancellation.
2Our system broke continuityA source-owned technical or operating failure.
3Action creates durable net valueIncremental recovery after cost, harm, refunds and later churn.
ResultCustomer Retention mechanismCurrent size: UNMEASURED
In plain words

A failed payment is not automatically a lost willing customer. The large unpaid balance is real, but it includes cases we cannot control, cases current retries already recover, people who did not intend to continue, and value that may already sit inside Retention.

01 · The category boundary

One mechanism inside Retention. Separate reliability work outside it.

The red team did not erase Payment Recovery. It put each kind of work where its value can be measured without counting the same money twice.

The operating decision

Remove Payment Recovery from the separately ranked opportunity list. Keep the narrow retention mechanism. Keep reliability defects visible. Book no value until the cohort, counterfactual, durable outcome, cost and ownership are measured.

02 · Why standalone fails

The money is visible. The opportunity is not.

A standalone opportunity must clear every gate below. Current evidence clears none of them completely.

01

Eligible

The intent-positive technical-failure cohort is unmeasured.

02

Current-practice

We cannot yet separate lift from the recovery system already running.

03

Incremental mechanism

No intervention has a mature controlled result against current practice.

04

Durable net value

Next-cycle paid use, retained use, refunds and later churn are not joined.

05

Full cost and harm

Fees, support, engineering, disputes and customer harm are missing.

06

Owner and action loop

No distinct accountable payment or entitlement owner is assigned.

07

No double counting

Unrecovered invoices and retention losses are not reconciled in both directions.

≈51%

Recurring first failures

July 51.29%; August 50.54%. A serious diagnostic signal that still needs decomposition.

18–20%

Observed recovery

Current practice already recovers part of first failures at the observed cutoffs.

≈6

Attempts per failing invoice

The system is already retrying heavily. “Do more retries” is not an open thesis.

27.6

Later attempts per recovery

64,080 later attempts accompanied 2,318 observed recoveries across four advice-code classes.

≈$196/mo

Card-repair proxy ceiling

The visible confirm_card_data surface before cost and durability haircuts.

31.5%

Later churn among matched recovered cycles

Directional warning only: 653 of 2,074 matched recovered cycles later churned.

How to read these numbers

The first-failure rate says “explain the system.” The unpaid face says “bound the diagnostic surface.” Neither says “this is the value we can win.” The earned number would be additional durable customer value above current practice, after all costs and harms.

03 · The rescue attempts

Every material route in the current corpus was tested.

Some routes are dead. Some remain useful operating work. None currently earns a standalone Payment Recovery opportunity.

Killed

More retries

Current later-attempt volume is already heavy. Additional retries have no earned incremental case.

Conditional

Retry timing

A timing test is valid only as a mature holdout against current practice after first-failure pathology is explained.

Nested

Payment-method repair

A customer-experience mechanism with a small visible proxy ceiling, not separate economics.

Rejected now

Gateway routing

Looker and BigQuery point in different directions on unmatched populations. Neither supports a causal routing decision.

Open the complete option ledger
RouteCurrent resultWhat would change it
Do-not-retry enforcementSelection audit, not value. Selected retries recovered 38 of 56 invoices.Joined cost, customer harm and recovery counterfactual.
Attempt-cost reductionUnresolved and unpriced.Per-attempt cost, retry ownership and outcome link.
Recovery communicationQA and measurement first.Correct recipient, send tracking and causal recovery outcome.
Entitlement and webhook repairHigh-priority integrity work, presently nested or reliability-owned.Incidence, accountable owner and durable customer/economic effect.
Fraud, disputes, chargebacksUnscored gap.Joined cohort and preventable share.
Tax, FX, payout, settlementUnscored gap.Cohort economics tied to a controllable mechanism.
Measurement systemNecessary enabling work, not an opportunity thesis.Evidence that it changes a material decision or outcome.
What survives

Diagnosis, measurement repair, customer-state integrity and a bounded Retention question survive. Production changes to retries, routing, blanket suppression and new recovery messages remain blocked.

04 · The data-room answer

Unused data still exists. It now has named jobs.

The audit did not declare every source exhausted. It converted the remaining unknowns into explicit reversal tests.

Decision-specific coverage

28

rooms dispositioned

13 registered15 shadow

Warehouse inventory

505

BigQuery objects dispositioned

Coverage strongExhaustion not claimed

What this proves

No unidentified room or object family currently supplies a standalone case.

The obvious reversal paths have been named and checked against the current corpus.

It does not prove every room body has been queried, joined or content-exhausted.

Known evidence still sitting in rooms or waiting to be commissioned

Seven bodies can still reverse or refine the decision.

  1. Identity and value joinPayer → account → subscription → entitlement → use → support → refund or churn.
  2. Intent and causePositive continuation evidence plus a source-owned technical or operating failure.
  3. Current configurationActual retry ownership and settings across Stripe, Adyen, Apple, Google, PayPal and CoinGate.
  4. FinanceContribution, attempt fees, refunds, disputes, tax, FX, support and engineering cost.
  5. Durable outcomeIncremental recovery, next-cycle paid use, entitlement continuity and harm guardrails.
  6. Adjacent reliability valueFalse declines, routing, attempt cost, fraud/risk and state integrity, priced separately.
  7. Cross-rail denominatorComparable failed obligations across VPN, MystNodes, GoProxies, Superproxy and other payment rails.
What changed

The gap is no longer “maybe useful data is somewhere.” We know which missing joins, configurations and outcomes could change the decision, what each must prove, and which work stays outside Customer Retention.

05 · The cheapest decisive sequence

Measure the intersection before building the machine.

Do not commission a full customer-episode system first. Run the cheapest tests that can kill or reopen the thesis.

  1. 01

    Preregister the decision thresholds.

    Set materiality, direction and stop rules before looking at reversal results.

  2. 02

    Establish the minimum identity join.

    Connect payer or invoice to account, subscription and UUID. Report unmatched rows, duplicates and identity conflicts.

  3. 03

    Test double counting in both directions.

    Reconcile July and August billing-retry churn rows against unrecovered invoices at one mature episode or failed-obligation .

  4. 04

    Explain the 51% first-failure signal.

    Split by invoice sequence, subscription tenure and rail. Add country or card fields only when a source-owned field exists.

  5. 05

    Test continuation behavior with controls.

    Compare same-UUID re-subscription and privacy-safe post-failure use against successful renewals and recorded voluntary exits.

  6. 06

    Commission the full episode join only if the cohort survives.

    Then add technical cause, current-practice recovery, durable paid use, finance and harm before any intervention test.

Reopen toward standalone

A material controllable pool appears.

Either the intent-positive technical-failure cohort proves material with a distinct action system, or a separate payment-operations pool clears its own economics and ownership.

Downgrade toward kill

No material willing-to-continue cohort survives.

Failures concentrate in acquisition or uncontrollable rails. Retain only justified reliability and integrity work.

Current state

Stay nested.

Investigate the system, measure the cohort, assign reliability ownership and authorize no production intervention yet.

06 · Evidence and limits

What is proved, and what is still open.

The conclusion passed opposing verification with no remaining blocking or material findings. That certification applies to the current classification, not to every unanswered payment question.

Verified current conclusion

  • NESTED is stronger than STANDALONE or KILL on current evidence.
  • The eligible retention cohort is UNMEASURED.
  • Material rescue cases in the current corpus were red-teamed.
  • No production intervention or value booking is authorized.

Still open

  • Intent-positive technical-failure cohort size.
  • First-failure decomposition and denominator health.
  • Cross-rail, fraud, dispute, chargeback and finance denominators.
  • Incremental durable value, costs, harm and accountable owner.
  1. 1

    Payment Recovery category red team. Integrated conclusion and current decision, 1 September 2026. Bound target SHA-256 begins baea5660.

  2. 2

    All-room evidence receipt. Decision-specific coverage of 13 registered and 15 shadow rooms. Coverage is not content exhaustion.

  3. 3

    Live BigQuery evidence receipt. Cohort, advice-code, censoring and warehouse-gap evidence from the authenticated live warehouse pass.

  4. 4

    Terminal certification. High-confidence NESTED classification; opposing verification returned PASS with zero blocking or material findings.

Machine-readable decision record

Same decision, structured for reuse.

The JSON record preserves the classification, evidence limits, production boundary and reopen rules without the page layout.

Open machine brief