It starts with a definition. Churn is stated precisely — for a contract business, non-renewal within a window after term end; for a self-serve one, cancellation or a defined period of inactivity. Without that, every downstream number is unfalsifiable. The definition is configuration, because it genuinely differs by business model.
Features are computed as of a cutoff. Every signal — engagement trend, breadth of feature use, active seat ratio, support sentiment trend, payment behaviour, champion activity — is calculated using only data available before the cutoff, and the prediction window sits strictly after it. This is unglamorous and it is the difference between a model that predicts and one that describes the past.
Risk is presented with its reasons and, crucially, with an action. Each risk pattern maps to a playbook entry — an owner, a suggested intervention, a timeframe — so what lands in front of a human is a task, not a number. Assignment is recorded, and the outcome of every intervention is tracked against it.
A fraction of eligible at-risk accounts is deterministically held back from intervention. It is uncomfortable and it is the only way to answer whether the programme works. Holdout assignment is a hash of the account id so it is stable across runs, and the interface shows the comparison honestly, including when the difference is not yet distinguishable from noise.