Imagined failure narrative
It is launch + 6 months. The relaunch failed badly. Net revenue came in below the pre-launch baseline rather than above it. New-customer activation fell below the old sales-assisted baseline, and the pricing page converted new trials worse than the old one. A wave of existing customers downgraded or churned at renewal; logo churn spiked in the renewal cohorts that hit after launch. Annual-plan mix and blended margin came in light. The support queue the self-serve flow was supposed to shrink hit record volume, with no human backstop. The accounts that “activated” in week 2 disengaged by month 4. The sales team that was reassigned is half gone. Existing customers ended up angrier than the ones newly acquired. Launch-week dashboards looked fine; the six-month numbers did not.
Load-bearing assumptions and the pilot precondition
This pre-mortem rests on five assumptions, each of which drives the analysis. Name any that are wrong and the dominant killer shifts:
- Big-bang to the entire base simultaneously — no canary, no phased ramp. (Counterbranch: if phased, the synchronized-spike and coupling modes soften materially; the dominant risk shifts to self-serve viability and shallow-activation/expansion-loss modes.)
- The full base includes existing customers originally set up sales-assisted, making the new pricing page a repricing/migration event for them, not just a new-prospect funnel. (Counterbranch: if only new customers are repriced and the existing base is untouched, the renewal-cliff and forced-repricing modes largely disappear and the dominant risk shifts to the new-customer funnel modes.)
- Sales-assisted setup is being removed, not made optional — no high-touch fallback for complex accounts.
- The three components ship as one release, coupled in the user’s path (pricing page → annual toggle → self-serve onboard).
- ACV band is unknown and is pivotal: confidence on the self-serve-viability and tier modes rises if ACV sits in the sales-assisted band, falls if genuinely SMB/low.
Several leading indicators below are readable only if the team first runs a pilot — a held-out cohort of real, current-profile accounts put through the new flow. Indicators are tagged [observable now — no pilot] or [pilot-dependent]. If the team declines to pilot, the pilot-dependent signals collapse into concurrent/lagging full-launch observations — you find out while it is happening, not before — which is itself an argument for the pilot. The pilot is only useful if instrumented (see EXE-4); an uninstrumented pilot manufactures false confidence.
Failure mode inventory
ASM-1. Sales-assisted was treated as removable friction, but reps were silently doing the work the new flow assumes the product can do alone. — class: assumption. Plan-specific mechanism: the sales-assisted motion wasn’t just closing deals — reps performed qualification, configuration, data import, expectation-setting, and first-value hand-holding. The plan treated that as friction. Removing it dumped that invisible work on customers who couldn’t do it, or on support who weren’t staffed for it.
ASM-2. The base had already revealed-preference chosen human help; removing it didn’t remove friction, it removed the help they had opted into. — class: assumption. Plan-specific mechanism: distinct from ASM-1’s work-transfer mechanism — this is a preference mechanism. The customers chose the assisted motion; replacing it with self-serve overrode a choice they had already made. Web-anchored basis: self-serve onboarding wins for low-ACV, simple, self-explanatory products; sales-assisted earns its keep in roughly the low-thousands-to-$100K+ band where buying is multi-stakeholder and configuration is non-trivial. Exact thresholds vary by source — the pure self-serve ceiling is often placed nearer ~$5K (not the ~$2K sometimes cited), with a hybrid mid-market zone above it. If ACV sits in that band, the wrong motion replaced the right one for this product. (Tier-2 claim, web-confirmed by multiple independent sources; directional structure solid, exact lower threshold soft.)
ASM-3. The three new tiers were assumed to map to real segments; they didn’t, so they cannibalized. — class: assumption. Plan-specific mechanism: tiers chosen by industry convention (“Good-Better-Best”), not validated against actual usage segments. Features landed in the wrong tier. Existing customers found a cheaper new tier covering their needs and down-migrated (a revenue leak disguised as adoption); or the middle tier dominated and cannibalized the top; or the middle sat dead because nobody’s needs landed there. Some existing customers found current capability now behind a higher price — a de-facto increase, or a downgrade-to-keep-price.
ASM-4. Customers were assumed to self-select the right tier without a rep; three tiers + an annual/monthly toggle created enough cognitive load that they didn’t. — class: assumption. Plan-specific mechanism: with reps gone, tier choice moved entirely onto the pricing page’s clarity. Ambiguous differentiation drove users to default to the cheapest tier (under-monetization) or bounce.
ASM-5. The annual discount was assumed to drive prepay without modeling its cost. — class: assumption. Plan-specific mechanism: the toggle was treated as a growth lever with discount depth set by feel — either generous enough to erode margin on customers who’d have paid monthly anyway, or weak enough that nobody toggled; which one was discovered only after revenue came in light.
ASM-6. The ASM-3 × ASM-5 compounding revenue leak — the two pricing assumptions multiply. — class: assumption. Plan-specific mechanism: the largest single dollar pathway was the product of ASM-3 and ASM-5, not either alone. A customer who both down-migrated to a cheaper tier and toggled annual at a generous discount compounded the leak — lower tier × discounted prepay — and locked it for twelve months where it couldn’t be corrected mid-cycle. Both “adoption wins” read as dashboard success while stacking the deepest revenue hole.
INT-1. Self-serve hit its activation/completion metric — and that very success killed retention via shallow setup. — class: interaction. Plan-specific mechanism: to prove self-serve “worked,” the flow was optimized to maximize activation/completion — a fast “done” state. But the reps it replaced used to enforce configuration depth (data import, integration setup, sane defaults, expectation-setting) — work that produces durable value but doesn’t show up in a completion checkmark. Users now activated shallowly, clearing the flow without the setup that makes the product stick.
INT-2. Self-serve hit its efficiency goal — and that’s what killed revenue, because the removed sales touch was also the expansion/upsell motion. — class: interaction. Plan-specific mechanism: the flow succeeded narrowly — cost-to-serve dropped, sales headcount came out — but the sales touch removed was also the in-conversation expansion/upsell motion. New-customer acquisition got cheaper while net revenue retention fell. CAC was optimized and NRR lost, and NRR is the bigger number.
INT-3. The annual-discount toggle worked too well and shifted revenue timing/lock-in against you. — class: interaction. Plan-specific mechanism: the toggle pushed users to annual, but for an at-risk launch that meant either (a) discount-driven margin compression across the base at the moment you needed revenue, or (b) annual lock-in of customers who then hit a disappointing self-serve experience and became loud detractors / refund-demanders / chargeback risks. Overlaps ASM-5 on discount economics; the distinct mechanism here is the timing/lock-in of detractors.
INT-4. The pricing page, optimized for new-logo conversion, confused the existing base — flooding the support team being shrunk. — class: interaction. Plan-specific mechanism: the page was tuned to convert cold trials, but existing customers used it to understand their own changed pricing and couldn’t. Confusion converted into support tickets — into the exact CS/support capacity cut on the assumption self-serve would reduce load. The two changes compounded instead of canceling. Distinct from ASM-4: that is new-customer mis-selection; this is existing-customer comprehension flooding support.
CTX-1. Forced repricing of the full base with no grandfathering decision made in advance, plus renewal timing, turned the migration into a churn cliff. — class: context-shift. Plan-specific mechanism: hitting the full base at once changed every customer’s terms simultaneously. Existing customers react not at launch but at their renewal date; the first one or two renewal cohorts faced a new price and a worse-to-them onboarding story at the same moment, and some used renewal as the natural exit. The grandfathering question got deferred into launch week and answered under pressure. The churn didn’t show in launch-week dashboards — it accumulated silently and surfaced as a cliff months later, after the window to act had closed.
CTX-2. The full-base big-bang hit support and infra simultaneously, and first impressions were set during the spike. — class: context-shift. Plan-specific mechanism: rolling to the entire base at once meant every confused self-serve user, every existing customer reacting to new pricing, and every onboarding edge case arrived in the same two-week window. Support volume spiked past capacity precisely when first impressions were being set.
EXE-1. Billing edge cases around the annual toggle were never QA’d, because the toggle was treated as UI, not a billing change. — class: execution. Plan-specific mechanism: mid-cycle switches, proration, existing annual contracts, and tax/currency interactions weren’t in the test matrix — the toggle looked like a front-end feature and got front-end QA. Customers hit broken invoices; finance hit a reconciliation mess; support filled with billing disputes.
EXE-2. Existing customers’ configurations didn’t migrate cleanly into the self-serve flow. — class: execution. Plan-specific mechanism: the flow was built and tested for new users on a clean slate. Existing accounts carried settings, integrations, and seat structures the new flow didn’t account for, so the cutover dropped them into a flow assuming they were starting fresh.
EXE-3. Self-serve content/docs/in-product guidance lagged the product, so “self-serve” had nothing to serve. — class: execution. Plan-specific mechanism: self-serve only works if in-product guidance, docs, tooltips, and help content cover the paths reps used to walk people through. These are the last things built and first cut under deadline; the flow shipped with gaps where reps used to fill silence.
EXE-4 (E-INSTR). The pilot ran blind / there was no instrumentation to diagnose failure in flight — the telemetry the leading indicators depend on was never built. — class: execution. Plan-specific mechanism: nearly every mitigation depends on observing a signal — activation lift (ASM-1), toggle take-rate and margin (ASM-5), expansion gap (INT-2), pricing-page-origin tickets (INT-4), stalled-user ownership (MOT-3), step-level funnel drop-off. But the funnel, take-rate, expansion, and ticket-origin telemetry were never instrumented before cutover, so the indicators existed in principle and produced no data. The pilot ran blind; the team mistook “no alarming signal” for “no problem” when there was no signal at all. When activation dropped, nobody could see where in the onboarding users fell out.
EXE-5. The team never proactively told the base why everything changed; customers discovered a new price and a removed human contact by surprise at login. — class: execution. Plan-specific mechanism: distinct from the pricing-page comprehension problem (INT-4) — even a perfectly clear page is a passive surface the customer must go find. No active, proactive announcement (email, in-app, account-manager outreach) explained that pricing was restructured, what it meant per customer, and where the human help went. The change arrived as a surprise, read as something done to them rather than for them.
MOT-1. The sales team, knowing self-serve replaced them, disengaged during the very transition that depended on them. — class: motivational. Plan-specific mechanism: the plan removed sales’s role in setup, but needed sales to keep feeding pipeline and backstop the flow while it proved out. Rational response: reps viewed the project as a threat, the best reps left first, pipeline thinned in the run-up, and tacit onboarding knowledge — why customers need help, the edge cases reps handle — walked out the door before the flow could absorb it. The institutional knowledge needed to make self-serve good was held by the people the plan was sidelining.
MOT-2. The team treated ship date as the finish line, so the mitigations themselves went unstaffed. — class: motivational. Plan-specific mechanism: the entire mitigation set — phased-rollout monitoring, kill-criterion enforcement, per-component rollback discipline, surge support, renewal-cohort tracking — requires sustained attention in the weeks after ship, but launches feel “done” at ship. Leadership declared victory, reallocated product/eng to the next roadmap item, and the post-ship vigilance the defenses depend on had no owner. The kill criteria existed on paper, but nobody watched the dashboards to pull the trigger.
MOT-3. Ownership of the stalled self-serve customer was nobody’s job. — class: motivational. Plan-specific mechanism: when self-serve users got stuck, it was unclear who caught them — sales had been reassigned, CS assumed the product handled it, the product assumed a human would. Stuck customers fell through the gap and churned silently. Distinct from MOT-2: MOT-2 is monitoring/kill-criterion ownership; this is operational stuck-user ownership.
Causal pathways to failure
ASM-1 → breakage point: removing reps. Immediate consequence: onboarding tasks reps absorbed become user-facing. Cascade: complex users stall at configuration → time-to-first-value collapses → activation drops → early churn. Surfaced failure: the efficiency revenue never materializes.
ASM-3 → breakage point: tier boundaries drawn by intuition. Immediate consequence: existing entitlements straddle the new boundary. Cascade: at renewal, “pay more for same” or “lose features to keep price” → downgrade revenue loss or churn. Surfaced failure: net revenue negative even where logo retention holds.
ASM-4 → breakage point: rep-guided selection removed. Immediate consequence: the page must carry all disambiguation, and the tiers are ambiguous. Cascade: users pick down or abandon. Surfaced failure: ARPU and conversion both miss.
ASM-5 → breakage point: discount depth set by feel. Immediate consequence: either margin erosion on customers who’d have paid monthly anyway, or near-zero take-rate. Cascade: the effect compounds across the base. Surfaced failure: revenue comes in light, and which failure occurred is discovered only afterward.
ASM-6 → breakage point: down-migration and the annual discount modeled as separate line items. Immediate consequence: a single customer takes both a cheaper tier and a discounted annual prepay. Cascade: lower tier × discounted prepay, locked for twelve months where it can’t be corrected mid-cycle. Surfaced failure: the deepest revenue hole, hidden because both moves read as adoption wins on the dashboard.
INT-1 → breakage point: optimizing the flow for activation-rate. Immediate consequence: enforced deep configuration is stripped or made skippable. Cascade: users complete shallow setup → week-2 activation dashboard looks great → accounts never reach real value → churn at month 3–6. Surfaced failure: six-month retention craters while launch-week metrics said “success” — which is why dashboards looked fine while the six-month number did not, tying directly to the renewal cliff.
INT-2 → breakage point: removing the sales touch. Immediate consequence: the expansion side-effect of sales-assist disappears. Cascade: activation/CAC improve while NRR declines. Surfaced failure: net revenue falls even where acquisition looks healthy.
INT-3 → breakage point: an aggressive annual default. Immediate consequence: either (a) blended-ARPU/margin compression when revenue was needed, or (b) annual lock-in of customers with a bad onboard. Cascade: refund requests / public complaints / chargebacks. Surfaced failure: a component “succeeded” while undermining the whole.
INT-4 → breakage point: page tuned for new-logo conversion. Immediate consequence: existing customers can’t parse their changed price. Cascade: pricing-page-origin support tickets collide with cut support headcount. Surfaced failure: queue overflow.
CTX-1 → breakage point: full-base repricing live with the grandfathering question unanswered. Immediate consequence: existing customers see it at staggered renewal dates. Cascade: downgrade/churn decisions land over the following two quarters. Surfaced failure: six-month retention craters after launch metrics looked fine.
CTX-2 → breakage point: big-bang to the whole base. Immediate consequence: a synchronized demand spike. Cascade: support SLA collapse → unanswered users abandon during onboarding → negative reviews / social posts cluster in the same window. Surfaced failure: reputational damage compounds the operational one.
EXE-1 → breakage point: the toggle scoped as UI. Immediate consequence: billing switch scenarios untested. Cascade: broken invoices/proration in production. Surfaced failure: finance reconciliation + support dispute load.
EXE-2 → breakage point: flow designed for clean-slate new users. Immediate consequence: existing-account state unhandled. Cascade: cutover lands existing customers in broken/ambiguous states. Surfaced failure: stalls and tickets.
EXE-3 → breakage point: deadline pressure deprioritizes content/enablement. Immediate consequence: users hit an unguided step. Cascade: no rep to ask → stall. Surfaced failure: support ticket or abandonment.
EXE-4 → breakage point: ship/pilot without step-level + take-rate + expansion + ticket-origin telemetry. Immediate consequence: drop visible only in aggregate. Cascade: no diagnosis → no targeted fix. Surfaced failure: false confidence.
EXE-5 → breakage point: no proactive change-comms. Immediate consequence: customers log in to a new price, new flow, no warning. Cascade: surprise read as something done to them. Surfaced failure: churn-at-renewal + support volume.
MOT-1 → breakage point: self-serve framed as rep-replacement. Immediate consequence: reps withhold tacit knowledge / don’t flag edge cases / route accounts around the flow / depart. Cascade: the flow ships missing exactly the cases reps knew about; pipeline thins pre-launch. Surfaced failure: those cases fail in production.
MOT-2 → breakage point: ship-date framed as completion. Immediate consequence: attention/staffing reallocated post-ship. Cascade: kill-criterion monitoring + rollback decision-rights unowned → early warnings (CTX-2 backlog, CTX-1 first renewals, INT-1 shallow activations) observed by no one. Surfaced failure: recoverable problems run unchecked; mitigations never fire.
MOT-3 → breakage point: an unowned handoff seam. Immediate consequence: stalled users unrouted. Cascade: stuck customers fall through the gap. Surfaced failure: silent churn.
Leading indicators per failure mode
ASM-1 — leading indicators: shadow-run/pilot self-serve onboarding with a sample of real incoming accounts (15–30) and measure completion-to-activation vs. the sales-assisted baseline; a measurable activation gap (a gap >15pp is the tell) is the signal. [pilot-dependent] Signal-acquisition cost: low — instrument the existing flow, recruit the cohort. Lead time before visible failure: weeks before launch.
ASM-2 — leading indicator: the existing base’s revealed preference (they bought through sales-assisted setup) read against the ACV band; if ACV sits in the low-thousands-to-$100K+ band, the signal is present today. [observable now — no pilot] Signal-acquisition cost: low. Lead time: now.
ASM-3 — leading indicators: map every existing account’s current entitlements onto the proposed tiers and compute who lands in “pay more for same,” “lose features to keep price,” or “clean upgrade”; watch projected middle-tier occupancy (a near-empty middle is a mispackaging signal). Signal = size of the first two buckets / empty middle. [observable now — no pilot] Signal-acquisition cost: low — roughly one analyst-day. Lead time: now.
ASM-4 — leading indicators: moderated five-second + task tests on the page (“which tier fits you and why?”); signal = mis-selection rate and stated confusion. [observable now — no pilot] Signal-acquisition cost: low. Lead time: weeks out.
ASM-5 — leading indicators: pilot annual-toggle take-rate and blended margin impact per cohort; near-zero take-rate or margin compression below threshold are both failures. [pilot-dependent] Signal-acquisition cost: low-medium — a finance margin model now, plus pilot A/B instrumentation. Lead time: model now; take-rate weeks out via pilot.
ASM-6 — leading indicator: in the ASM-3 paper-mapping, flag accounts landing on both a cheaper tier and a likely annual toggle; size the combined annualized exposure. [observable now — no pilot] Signal-acquisition cost: low — incremental to ASM-3 mapping. Lead time: now.
INT-1 — leading indicators: in the shadow cohort, measure downstream setup-depth (integrations connected, data imported, key features adopted) against the sales-assisted baseline, and correlate shallow activations with early disengagement; signal = high completion but low setup-depth relative to rep-led accounts. [pilot-dependent] Signal-acquisition cost: low — instrument alongside the ASM-1 cohort. Lead time: weeks before launch.
INT-2 — leading indicators: in the pilot, track expansion/upsell rate of self-serve cohorts vs. sales-assisted history — not just activation and CAC; a widening expansion gap is the tell. [pilot-dependent] Signal-acquisition cost: medium — requires the pilot plus expansion instrumentation. Lead time: weeks, via pilot.
INT-3 — leading indicators: model the discount’s blended-ARPU and cash impact across realistic annual-adoption scenarios before setting depth; in the shadow cohort, watch whether annual-buyers who hit onboarding friction file refund requests. [pilot-dependent for refund signal; observable now for the model] Signal-acquisition cost: low to moderate. Lead time: now for the model; weeks for refund signal.
INT-4 — leading indicators: in pilot, rate of pricing-page-origin support contacts from existing users, and projected ticket volume vs. planned post-launch support headcount. [pilot-dependent] Signal-acquisition cost: low-medium — ticket-origin tagging in the pilot. Lead time: weeks, via pilot.
CTX-1 — leading indicators: cross the ASM-3 paper-mapping (who faces an increase) with the renewal calendar; a cluster of price-increase accounts renewing in the first post-launch quarter is a loaded gun with a visible fuse. Track renewal-cohort behavior from the first post-launch renewals (week 2 onward), not aggregate logo count; optionally a pre-launch survey of a sample on the new pricing. [observable now — no pilot] Signal-acquisition cost: low — roughly one analyst-day crossing paper-map with renewal calendar. Lead time: now; continuous from launch.
CTX-2 — leading indicators: capacity-model launch-week support and infra load from the shadow cohort’s contact rate × base size; signal = projected volume exceeds staffed capacity. [partly pilot-dependent for contact rate; modelable now] Signal-acquisition cost: low. Lead time: now.
EXE-1 — leading indicators: count of billing-path test cases covering switch scenarios (monthly→annual mid-cycle, existing-annual→new-annual, refunds/proration); near-zero two weeks out is the open hole. [observable now — no pilot] Signal-acquisition cost: low — audit the test matrix. Lead time: now, before code freeze.
EXE-2 — leading indicators: a migration dry-run on a sample of real existing accounts — count how many land in a broken or ambiguous state; anything non-trivial is the warning. [observable now — no pilot] Signal-acquisition cost: low-medium — one engineer running real account snapshots through the flow. Lead time: now, ahead of date commitment.
EXE-3 — leading indicators: content-coverage audit against the actual rep-walkthrough script — map every step a rep handled to a self-serve asset; signal = uncovered steps. [observable now — no pilot] Signal-acquisition cost: low — interview 2–3 reps, list the steps. Lead time: now. (This audit also feeds ASM-1 and INT-1.)
EXE-4 — leading indicators: a pre-pilot instrumentation checklist — does each leading indicator have a data source wired before the pilot starts? Confirm the dashboard can answer “what % completed each onboarding step?” and “how deep was each completed setup?” on test traffic. A checklist with gaps is the tell. [observable now — no pilot] Signal-acquisition cost: low-moderate — a checklist review against the indicator list. Lead time: now, before the pilot/launch.
EXE-5 — leading indicators: does a written change-communication plan exist, with an owner, a per-segment message, and a send date before cutover? Absence (or a plan covering only new logos) is the tell. [observable now — no pilot] Signal-acquisition cost: low — confirm plan and owner exist. Lead time: now.
MOT-1 — leading indicators: sales attrition rate and pipeline-generation trend in the pre-launch months; rep engagement/participation in onboarding-flow design and testing (low participation, or reps privately keeping setup workarounds, is the signal). [observable now — no pilot] Signal-acquisition cost: low/free — sales-ops/HR already track attrition and pipeline; observe the collaboration. Lead time: now, continuous.
MOT-2 — leading indicators: before launch, check whether phased-rollout monitoring, each kill criterion, and rollback decision-rights are assigned to named people with time allocated for the post-ship weeks; signal = no named owner / no allocated time / a vague “we’ll watch it.” [observable now — no pilot] Signal-acquisition cost: free — an org/staffing review question. Lead time: now.
MOT-3 — leading indicators: in the pilot, resolution time and ownership of self-serve users who stall; if “who owns this stuck user?” has no clean answer in the pilot, it has none at scale. [pilot-dependent] Signal-acquisition cost: low-medium — observe stuck-user routing in the pilot. Lead time: weeks, via pilot.
Pre-commitment mitigations
-
Shadow-cohort kill criterion (ASM-1, ASM-2) — what it locks in before commitment: run the shadow cohort and set a kill criterion — if self-serve activation is below an agreed % of the sales-assisted baseline for accounts above a complexity threshold, ship self-serve only for the simple segment and keep a sales-assisted/hybrid path for complex accounts. Anchor the threshold to an instrumentable line (integration count, seat count, required data-import volume), corresponding to the ACV bands the web evidence places between roughly the low-thousands and $100K+. Sample the cohort against that same dividing line so the kill criterion is read per-segment, not in aggregate. Keep a “request a human” escape hatch wired in from day one; don’t dismantle sales-assist until the flow clears the floor. Which failure mode(s) it addresses: ASM-1, ASM-2. Cost to implement before launch: low — instrument the existing flow, recruit 15–30 real accounts.
-
Tier-boundary validation + decision gate (ASM-3) — what it locks in: validate tier boundaries against real segment usage data, not the convention; lock a grandfathering/migration policy before launch (see mitigation 5) for any account that would lose ground; run a small live price-sensitivity test (fake-door or limited cohort) on the boundaries. Decision gate: don’t ship boundaries until the “pay more for same” bucket is below an agreed threshold or covered by grandfathering; if paper-mapping shows down-migration, restructure tiers or fence new pricing to new logos. Which failure mode(s) it addresses: ASM-3. Cost: low — roughly one analyst-day for the mapping.
-
Pricing-page usability bar (ASM-4) — what it locks in: usability-test the page to a pass bar before launch; commit to a “help me choose” affordance if mis-selection exceeds threshold. Which failure mode(s) it addresses: ASM-4. Cost: low.
-
Discount margin model (ASM-5) — what it locks in: model the discount’s revenue-recognition and margin effect at three discount levels before locking one; set depth from the model, not a round number; A/B the depth in the pilot. Which failure mode(s) it addresses: ASM-5, and feeds INT-3. Cost: low-medium — a finance margin model plus pilot A/B instrumentation.
-
Combined down-migration + discount exposure model and grandfathering decision (ASM-6, CTX-1) — what it locks in: model down-migration and the annual discount together, not as separate line items; if combined exposure is material, fence new pricing to new logos or cap the annual discount on down-migrating accounts. Make the grandfathering decision now, explicitly, in writing; sequence the rollout against the renewal calendar rather than flipping everyone at once; proactively reach the highest-value accounts approaching renewal rather than letting them discover the change at the worst moment. Which failure mode(s) it addresses: ASM-6, CTX-1. Cost: low — incremental to the ASM-3 mapping. (This is an argument against full-base big-bang.)
-
Activation-with-depth success metric (INT-1) — what it locks in: define the launch success metric as activation-with-depth (a setup-completeness bar), not raw completion; pre-commit that the flow gates or strongly nudges the configuration steps reps enforced; set the kill/iterate criterion on setup-depth. This makes launch-week observability actually predict the six-month outcome. Which failure mode(s) it addresses: INT-1. Cost: low — instrument alongside the ASM-1 cohort.
-
Design where expansion lives before dismantling sales (INT-2) — what it locks in: before committing, design where expansion lives in a self-serve world (in-product prompts, usage-triggered outreach, a retained “expansion” sales sliver); don’t dismantle the motion until its replacement is proven to expand. Which failure mode(s) it addresses: INT-2. Cost: medium — requires the pilot plus expansion instrumentation.
-
Refund/cooling-off policy on annual plans (INT-3) — what it locks in: set discount depth from the model; pre-commit a refund/cooling-off policy so a bad onboard on an annual plan doesn’t convert into a chargeback or public complaint. Which failure mode(s) it addresses: INT-3. Cost: low to moderate.
-
Separate existing-customer comprehension target + protect support capacity (INT-4) — what it locks in: treat existing-customer comprehension as a separate design target from new-logo conversion (possibly a separate view); do not cut support capacity until self-serve ticket-deflection is measured, not assumed. Which failure mode(s) it addresses: INT-4. Cost: low-medium — ticket-origin tagging in the pilot.
-
Phased rollout with surge support and pause trigger (CTX-2) — what it locks in: phase the rollout so volume arrives in staffable waves; pre-stage surge support coverage and a triage runbook; set a rollout-pause trigger tied to support backlog depth. Which failure mode(s) it addresses: CTX-2. Cost: low. (Counterbranch: if already phased, this degrades from acute to manageable.)
-
Billing-specific test plan as launch gate (EXE-1) — what it locks in: require a billing-specific test plan as a launch gate, owned jointly by finance + eng, with proration/migration cases enumerated before code freeze. Which failure mode(s) it addresses: EXE-1. Cost: low — audit the test matrix.
-
Migration path as first-class deliverable + dry-run (EXE-2) — what it locks in: build and test the migration path as a first-class deliverable, separate from the new-user happy path, and dry-run it on real account snapshots before committing a date. Which failure mode(s) it addresses: EXE-2. Cost: low-medium — one engineer running real account snapshots through the flow.
-
Content-coverage launch gate (EXE-3) — what it locks in: make content-coverage a launch gate; pre-commit that no component ships until its onboarding steps have coverage. Which failure mode(s) it addresses: EXE-3 (and feeds ASM-1, INT-1). Cost: low — interview 2–3 reps, list the steps.
-
Instrument before you pilot (EXE-4) — what it locks in: gate the pilot itself on telemetry coverage for activation, annual-toggle take-rate, expansion/upsell, ticket-origin tagging, and step-level funnel; no instrumentation, no pilot — an uninstrumented pilot is worse than none. The shadow cohort is also the test that the telemetry actually works. Which failure mode(s) it addresses: EXE-4, and unblocks the leading indicators for ASM-1, ASM-5, INT-2, INT-4, MOT-3. Cost: low-moderate — a checklist review against the indicator list.
-
Segmented change-comms plan as launch gate (EXE-5) — what it locks in: make the change-comms plan a launch gate with a named owner; segment the message (price-increase accounts, down-migration-eligible accounts, sales-assist regulars losing their contact each need a different note); send before cutover, not at it. Which failure mode(s) it addresses: EXE-5. Cost: low — confirm plan and owner exist.
-
Define sales’s new-world role with retention incentives + “where will this break?” session (MOT-1) — what it locks in: decide and communicate the sales team’s role in the new world before launch (complex-account hybrid, expansion, escalation backstop, human backstop) with retention incentives tied to a clean transition and to self-serve success; run a structured rep-led “where will this break?” session as a design input, so knowledge flows into the flow rather than around it. Which failure mode(s) it addresses: MOT-1. Cost: low/free.
-
Staff the post-ship window before you ship (MOT-2) — what it locks in: name an owner for each kill criterion, put rollback decision-rights in writing, book the team’s calendars for the monitoring weeks before ship; pre-commit that the launch is “done” not at ship but at a defined post-ship stability gate. This mitigation protects every other mitigation. Which failure mode(s) it addresses: MOT-2 (and protects the firing of every kill criterion above). Cost: free — an org/staffing review question.
-
Name the stalled-user owner with an SLA (MOT-3) — what it locks in: name the owner of the stalled-self-serve path explicitly before launch, with an SLA and a routing rule. Which failure mode(s) it addresses: MOT-3. Cost: low-medium — observe stuck-user routing in the pilot.
Residual unmitigated risks
-
Coupling itself — the load-bearing residual. Which failure modes remain exposed: all of them, in combination. Even with every mitigation, shipping three interacting changes simultaneously to the full base means that if any one fails you can’t tell which, and the failures interact (billing breakage → support flood → team collapse; pricing-page dip and onboarding-activation dip are indistinguishable in the aggregate funnel). Conditions under which it materialises: any single-component failure under big-bang. Whether this should warrant rethinking the plan: yes — this residual doesn’t argue for a better test plan, it argues for decoupling: phase the components and/or roll to cohorts against the renewal calendar instead of all-at-once. (Counterbranch: if already phasing, this dissolves — phasing IS the mitigation — and the residual shifts to running two parallel pricing/onboarding systems during the window.)
-
Tier-boundary economics remain a genuine bet. Which failure modes remain exposed: ASM-3, ASM-6 partially. Even with usability testing and grandfathering, the strategic choice of what goes in which tier is a pricing judgment no pre-launch test fully de-risks. Conditions under which it materialises: if competitor pricing shifts or willingness-to-pay is softer than the test cohort suggested. Whether this should warrant rethinking the plan: no — normal residue; warrants a price-revision plan for Q+1, not rethinking the plan.
-
Phasing extends the timeline and the entangled old/new-system maintenance burden. Which failure modes remain exposed: a new operational risk introduced by the coupling mitigation. Decoupling trades big-bang risk for a longer window running two pricing/onboarding systems in parallel. Conditions under which it materialises: if the phased timeline slips into a quarter where revenue was needed sooner. Whether this should warrant rethinking the plan: no — worth accepting; diagnosis-and-rollback value dominates.
-
Self-serve may have a hard ceiling for the most complex segment. Which failure modes remain exposed: ASM-1, ASM-2. If the shadow cohort shows complex accounts simply can’t self-serve, “replace sales-assisted” was the wrong frame for part of the base. Conditions under which it materialises: shadow-cohort activation for complex accounts stays below floor regardless of flow improvements. Whether this should warrant rethinking the plan: yes — this residue does warrant amending the plan’s scope, from “replace” to “replace for simple, hybrid for complex.”
-
Competitive / macro context shift. Which failure modes remain exposed: none of the controllable modes — a competitor move or market change during the quarter is largely outside your control. Conditions under which it materialises: a competitor move or market change during the launch quarter. Whether this should warrant rethinking the plan: no — out-of-scope-for-mitigation; monitor, don’t plan to prevent. This is the one genuinely external item; everything else traces to a decision still held.
Confidence per finding
- ASM-1 (reps doing invisible work) — high that this is the dominant killer if the base skews complex / sits in the sales-assisted ACV band. Grounding: the structure of a sales-assisted motion and what reps actually perform during setup.
- ASM-2 (revealed-preference for human help) — high; basis: the existing base bought through sales-assisted setup, a revealed preference. Rises if ACV lands in the sales-assisted band, falls if genuinely SMB/low. Web-confirmed by multiple independent sources; directional structure solid, exact lower threshold soft.
- ASM-3 (tiers don’t map to segments) — medium-high; basis: the “Good-Better-Best” three-tier structure was adopted by convention, not validated; resolves with the paper-mapping.
- ASM-4 (cognitive load on tier self-selection) — medium.
- ASM-5 (annual discount unmodeled) — medium; basis: the discount was set by feel rather than modeled; resolves with a margin/revenue-recognition model and pilot A/B.
- ASM-6 (ASM-3 × ASM-5 compounding leak) — medium-high; basis: both modes independently plausible, and they multiply rather than add.
- INT-1 (shallow activation kills retention) — medium-high; the genuine “narrow-success-defeats-purpose” case on the retention axis.
- INT-2 (efficiency goal kills expansion/NRR) — medium-high; basis: sales-assist’s hidden role as the expansion/upsell engine; resolves with pilot expansion data vs. sales-assisted history.
- INT-3 (annual toggle shifts timing/lock-in) — medium.
- INT-4 (pricing page confuses base, floods shrinking support) — medium; basis: the page was tuned for cold-trial conversion, a different job than helping an existing customer parse their own changed price; resolves with pilot ticket-origin data.
- CTX-1 (forced repricing → churn cliff) — high; the most load-bearing failure in the inventory, conditional on existing-base repricing.
- CTX-2 (big-bang spike on support/infra) — medium-high given the big-bang assumption.
- EXE-1 (billing toggle un-QA’d) — high; basis: categorizing a billing change as a front-end feature is a common, checkable error; resolves by inspecting the test matrix.
- EXE-2 (existing configs don’t migrate) — medium-high; basis: the flow was built and tested for new users on a clean slate; resolves with a migration dry-run on real snapshots.
- EXE-3 (content/docs lag) — medium.
- EXE-4 (pilot ran blind / no instrumentation) — medium-high; basis: the mitigation architecture silently assumes telemetry the plan never names; resolves by checking instrumentation coverage against the indicator list.
- EXE-5 (no proactive change-comms) — medium-high; basis: proactive change-communication is a discrete, easily-deferred deliverable; resolves by checking whether a change-comms plan with an owner exists.
- MOT-1 (sales disengages during the transition) — medium-high; basis: the rational response of reps to a telegraphed replacement; resolves with current attrition/pipeline trend, observable today.
- MOT-2 (ship date treated as finish line; mitigations unstaffed) — medium; the self-referential motivational failure.
- MOT-3 (stalled-user ownership unassigned) — medium; basis: a handoff seam where sales was reassigned, CS assumed the product caught it, the product assumed a human would; resolves with pilot observation of who actually catches stuck users.
- Inventory depth (optimism-residue check) — no optimism-residue flag warranted: the inventory spans all five Klein classes with multiple modes each (assumption ×6, interaction ×4, context-shift ×2, execution ×5, motivational ×3). Whether the inventory matches the plan’s true complexity still depends on the actual ACV band and whether a pilot is committed — both flagged unknown.
Root-cause synthesis and the highest-leverage moves
Two complementary namings of the deepest cause survive; they agree on the structure and differ on which facet is most load-bearing:
- Emphasis A: the plan treated three coupled, irreversible changes as one big-bang bet to the entire base, while removing the humans who were silently doing the work the new flow assumes the product can do alone — and then optimized the replacement flow for a completion metric that hid the loss. Everything else cascades from those structural choices.
- Emphasis B: the one decision that kills this is doing all three changes, to everyone, at once, with the grandfathering question unanswered. The fix isn’t more QA — it’s narrowing the blast radius so any single failure is survivable and diagnosable rather than mutually amplifying.
Highest-leverage pre-commitment moves, all available now:
- Decouple and phase the release — independent feature flags per component + cohort rollout sequenced against the renewal calendar + per-component rollback. Converts one unobservable bet into three observable, reversible ones; addresses the coupling residual, CTX-2, CTX-1 sequencing, and the diagnosis problem in EXE-4 at once. If you act on one thing, this is it.
- Shadow-run self-serve against real, current-profile (and complex) accounts and set a kill criterion — directly tests the load-bearing ASM-1/ASM-2 premise before committing the base. Run it as a dual-use instrument: the same cohort that reveals where self-serve fails (retreat to hybrid) also reveals where it serves customers better and faster than reps did — letting you scope where to lean into self-serve aggressively. Defense and targeting come from one test, strengthening the case to fund it.
- Instrument before you pilot (EXE-4) — no telemetry, no pilot; an uninstrumented pilot manufactures false confidence and the other moves are blind without it.
- Staff the post-ship monitoring before you ship (MOT-2) — name owners for each kill criterion and put rollback decision-rights in writing, because the other moves are worthless if no one is watching the dashboards when the signals arrive.
Surfaced tensions and stance notes
These disagreements are preserved rather than resolved, because they carry decision-relevant information:
- Classification disagreement on the big-bang/repricing failure. One framing classifies the renewal cliff as context-shift (the customer’s world changing at renewal) and treats coupling as a structural/diagnosis failure carried in the interaction section (explicitly not a “narrow-success-defeats-purpose” case); another classifies forced full-base repricing + renewal spike squarely as context-shift and treats coupling as a meta-residual rather than a numbered failure mode. The disagreement reveals what’s contested: whether “coupling” is itself a failure mode or a property of the plan that amplifies all other modes.
- Two genuine interaction failures, distinct mechanisms. Self-serve’s narrow success defeats the larger purpose along two separate axes that both survive: optimizing for activation/completion masks shallow setup and kills retention (INT-1); optimizing for cost-to-serve removes the expansion/upsell motion and kills NRR (INT-2). The team should monitor both.
- Leading-indicator disagreement on the same risks. The self-serve-viability risk is indicated both by activation-gap vs. baseline and by setup-depth vs. baseline; the annual-discount risk by both a pre-launch margin model and pilot take-rate. Monitor multiple indicators rather than choosing one.
- The pivotal unknowns that shift the dominant killer. (a) Big-bang vs. phased: if phased, CTX-2 and the coupling residual soften, and the dominant risk shifts to self-serve viability (ASM-1) and shallow activation/expansion loss (INT-1/INT-2). (b) Existing-base repriced vs. new-customers-only: if new-only, CTX-1 and the renewal cliff largely disappear and the dominant risk shifts to the new-customer funnel modes (ASM-3, ASM-4, INT-3); if existing customers are repriced, CTX-1 is among the top killers. (c) The actual ACV band sets confidence on ASM-1/ASM-2/ASM-3.
Two minor stance questions are surfaced rather than silently resolved: (a) schematic causal arrows (“remove reps → tasks become user-facing”) are used as diagrammatic shorthand inside an otherwise past-tense narrative; (b) anchored conditionals (“if our ACV sits in that band, we replaced…”) scope a past-tense claim to an unknown rather than hedge into forward projection. Both are read as past-tense-anchored, not slippage; a stricter reading could call the schematic tense a partial slip.