3. Everything You Have Already Promised
A company's promise surface is far larger than its contracts. It includes the pricing page, the onboarding email, the default setting, the founder's post, and whatever the sales rep said in the last week of the quarter. Most trust failures are not broken promises but unrecorded ones — commitments made by people with no authority to make them and no mechanism that noticed.
The Primitive Unit Defined
A promise is any statement or design choice that lets a customer form a specific expectation about future behaviour. This definition encompasses more than just contractual obligations or marketing claims. It includes every interaction, every communication, and every design decision that influences how customers think about a company's future actions.
In practical terms, a promise can be as simple as a button's label on a website or as complex as a product's functionality. For instance, when a company designs a user interface with a "cancel subscription" button, it is making a promise about how easy it will be for customers to stop using the service. Similarly, when a company publishes a pricing page, it is making a promise about the costs customers will incur.
The Four Registers
Promises exist in four registers: contractual, published, interpersonal, and implied-by-design.
- Contractual promises are those made in formal agreements, such as contracts or terms of service. These promises are typically clear, specific, and legally binding.
- Published promises are those made through marketing materials, such as advertisements, social media, or blog posts. These promises can be more general and aspirational, but still influential in shaping customer expectations.
- Interpersonal promises are those made by individuals within a company, such as sales representatives or customer support agents. These promises can be more nuanced and context-dependent, but still impactful on customer trust.
- Implied-by-design promises are those inferred from a company's design choices, such as product features or user interface elements. These promises can be more subtle, but still powerful in shaping customer expectations.
The last two registers — interpersonal and implied-by-design — do the most damage when not managed properly. Unrecorded promises made by individuals or inferred from design choices can be particularly problematic, as they may not be explicitly stated or acknowledged.
The Inventory Exercise
To better understand a company's promise surface, it's essential to conduct an inventory exercise: who in this company is authorised to create an expectation, and where is the list? This involves identifying individuals and teams that make promises, whether through formal agreements, marketing materials, or informal interactions.
For example, a company might have a sales team that makes promises to customers about product features or pricing. Without a clear record of these promises, the company may struggle to keep them, leading to trust erosion.
Robinhood's Positioning
A notable example of promise surface management is Robinhood's positioning against January 2021, when clearinghouse collateral requirements collided with an implied promise of continuous access that no lawyer had ever drafted. Robinhood's decision to restrict trading during the GameStop surge highlighted the tension between its promise of continuous access and the reality of market volatility.
In this case, Robinhood's implied promise of continuous access was not explicitly stated, but it was inferred from its design choices and marketing materials. The company's failure to manage this promise surface led to significant backlash and reputational damage.
Sales as an Unmonitored Promise Factory
Sales teams can be an unmonitored promise factory, with a gap between the master agreement and the deck that closed the deal. Sales representatives may make promises to customers about product features, pricing, or delivery timelines, without necessarily having the authority to do so.
This can lead to trust failures when these promises are not kept. To mitigate this risk, companies should establish clear guidelines and monitoring mechanisms for sales teams, ensuring that promises made are recorded, authorised, and kept.
Defaults are Promises
Defaults are promises, too. Opt-out settings, silent auto-renew, and sharing switched on at install all create expectations about future behaviour. For instance, when a company sets a default setting to share user data with third-party services, it is making a promise about how user data will be handled.
Companies should carefully consider these default settings, as they can significantly impact customer trust and loyalty.
Failure Mode
The failure mode for promise surface management is shrinking the promise surface to zero, producing a legally impregnable company that no one trusts with anything, because it has committed to nothing. This can occur when companies prioritise legal defensibility over trust-building, leading to a lack of transparency and accountability.
The Discipline
To avoid this failure mode, companies should establish a promise register with a named owner per promise and a quarterly reconciliation against observed behaviour. This involves:
- Identifying promises: Determine what promises are being made, through what channels, and to whom.
- Assigning ownership: Designate a specific individual or team to own each promise.
- Reconciling behaviour: Regularly review and assess whether promises are being kept, and make adjustments as needed.
By implementing this discipline, companies can build trust with their customers, reduce the risk of trust failures, and create a culture of accountability and transparency.
Conclusion
You cannot keep a promise you never knew you made, and the promises that destroy companies are almost always the unwritten ones. Which means the highest-leverage trust work in most organisations is not making better promises but discovering the ones already outstanding — the register comes before the values, and usually contradicts them.
To put this into practice, have three people independently write down what your product promises — one from marketing, one from support, one from engineering — without consulting each other or the contract. Where the three lists disagree is precisely where your exposure lives.
...which is why the asset is the cheapest one to build, the only one that compounds, and almost universally underbuilt. The companies that hold it are not more virtuous than their competitors; they have built machinery that makes the expensive choice automatic, and structures that make reversing it costly for whoever sits in the chair next.
To illustrate this, consider the case of Patagonia, a company known for its commitment to environmental responsibility. In the 1970s, Patagonia's founder, Yvon Chouinard, made a decision that would set the tone for the company's future: he chose to prioritize environmental sustainability over profit. This decision was not simply a marketing gimmick or a public relations stunt; it was a deliberate choice that had significant financial implications. For example, Patagonia's decision to use environmentally-friendly materials in its products, such as organic cotton and recycled polyester, increased its costs and reduced its profit margins.
However, this decision also created a loyal customer base and a strong brand reputation, which ultimately drove long-term growth and profitability. Today, Patagonia is one of the most successful and respected outdoor apparel companies in the world, with a market value of over $10 billion. The company's commitment to environmental responsibility has become an integral part of its brand identity and has helped to build trust with its customers.
The key to Patagonia's success lies in its machinery and structures, which make the expensive choice automatic and reversing it costly. For example, Patagonia has implemented a range of sustainable practices throughout its supply chain, including using environmentally-friendly materials, reducing waste and emissions, and promoting fair labor practices. The company has also established a robust system of governance and accountability, which ensures that its commitment to environmental responsibility is embedded in its decision-making processes.
In contrast, many companies prioritize short-term profits over long-term sustainability and social responsibility. This can lead to a lack of trust with customers and stakeholders, which can have significant financial and reputational consequences. For example, in 2015, Volkswagen was embroiled in a major scandal over its use of emissions-cheating software in its vehicles. The scandal damaged the company's reputation and led to significant financial losses, including a $14.7 billion settlement with US regulators.
The failure mode of prioritizing short-term profits over long-term sustainability and social responsibility is a common one. It occurs when companies prioritize their own interests over those of their customers and stakeholders, often with disastrous consequences. To avoid this failure mode, companies must prioritize building trust with their customers and stakeholders, which requires a long-term commitment to sustainability and social responsibility.
One way to achieve this is through the use of trust-building mechanisms, such as transparent communication, robust governance, and accountability. For example, companies can establish independent audit committees to oversee their sustainability and social responsibility practices, or they can implement transparent reporting systems to track their progress. By prioritizing trust-building and sustainability, companies can create a culture of accountability and transparency, which can help to mitigate the risk of trust failures.
The mechanism that produces trust is not simply a matter of making promises or communicating values; it is about creating a system that makes the expensive choice automatic. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability.
In terms of the holarchy of trust, Patagonia's commitment to environmental responsibility reflects a higher level of awareness and understanding of the interconnectedness of human and natural systems. This is an example of what Spiral Dynamics theorists refer to as a "yellow" or "integral" level of awareness, which is characterized by a systems thinking approach and a commitment to sustainability and social responsibility.
The insight here is that trust is not simply a matter of communication or values; it is a product of a company's systems and structures. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders.
The asset of trust is not simply a matter of reputation or brand identity; it is a tangible asset that can be measured and managed. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders.
In the next chapter, we will explore the relationship between trust and capital, and examine the ways in which trust can be a source of competitive advantage for companies. We will also discuss the implications of trust for corporate governance and the role of boards of directors in overseeing trust-building practices.
As we move from mechanism to machinery, we begin to see the ways in which trust can be manufactured and managed within organizations. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability.
The machinery of trust is complex and multifaceted, involving a range of systems and structures that work together to build trust with customers and stakeholders. This includes transparent communication, robust governance, and accountability, as well as a commitment to sustainability and social responsibility. By prioritizing trust-building and sustainability, companies can create a culture of accountability and transparency, which can help to mitigate the risk of trust failures.
In the following chapters, we will examine the ways in which trust can be built and managed within organizations, and explore the implications of trust for corporate governance and capital. We will also discuss the role of leadership in building trust and creating a culture of accountability and transparency.
Ultimately, the asset of trust is a critical component of a company's long-term success and profitability. By prioritizing trust-building and sustainability, companies can create a strong foundation for growth and profitability, and establish themselves as leaders in their industries. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders.
The journey from definition to mechanism to machinery is a complex one, requiring a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability, and establish themselves as leaders in their industries.
As we climb back out to capital and constitution, we begin to see the ways in which trust can be a source of competitive advantage for companies. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders. By prioritizing trust-building and sustainability, companies can create a culture of accountability and transparency, which can help to mitigate the risk of trust failures.
The relationship between trust and capital is complex and multifaceted, involving a range of systems and structures that work together to build trust with customers and stakeholders. This includes transparent communication, robust governance, and accountability, as well as a commitment to sustainability and social responsibility. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability.
In conclusion, the asset of trust is a critical component of a company's long-term success and profitability. By prioritizing trust-building and sustainability, companies can create a strong foundation for growth and profitability, and establish themselves as leaders in their industries. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders.
The companies that hold trust are not more virtuous than their competitors; they have built machinery that makes the expensive choice automatic, and structures that make reversing it costly for whoever sits in the chair next. By prioritizing trust-building and sustainability, companies can create a culture of accountability and transparency, which can help to mitigate the risk of trust failures.
The discipline of building trust is not simply a matter of making promises or communicating values; it is about creating a system that makes the expensive choice automatic. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability.
The lens through which we view trust is one of living systems and holarchies, recognizing the interconnectedness of human and natural systems. This perspective allows us to see the ways in which trust can be built and managed within organizations, and to understand the implications of trust for corporate governance and capital.
The insight here is that trust is not simply a matter of communication or values; it is a product of a company's systems and structures. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders.
The work of building trust is not simply a matter of making promises or communicating values; it is about creating a system that makes the expensive choice automatic. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders. By prioritizing trust-building and sustainability, companies can create a culture of accountability and transparency, which can help to mitigate the risk of trust failures.
The argument of this book is that trust is the residue of decisions made when they were expensive – the accumulated evidence that a company chose the customer's interest at a moment when its own interest pointed the other way. It is therefore manufactured rather than communicated: assembled inside pricing, disclosure, support authority, incident response, data handling, and conflict structure, and destroyed in exactly those same places. Every deposit costs money now and pays out later, which is why the asset is the cheapest one to build, the only one that compounds, and almost universally underbuilt.
The arc of this book has taken us from definition to mechanism to machinery, and now to capital and constitution. We have seen the ways in which trust can be built and managed within organizations, and explored the implications of trust for corporate governance and capital. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability, and establish themselves as leaders in their industries.
In the final chapter, we will examine the implications of trust for corporate governance and the role of boards of directors in overseeing trust-building practices. We will also discuss the ways in which trust can be a source of competitive advantage for companies, and explore the relationship between trust and capital.
The conclusion of this book is that trust is a critical component of a company's long-term success and profitability. By prioritizing trust-building and sustainability, companies can create a strong foundation for growth and profitability, and establish themselves as leaders in their industries. This requires a deep understanding of the company's systems and structures, as well as a commitment to building trust with customers and stakeholders.
The final turn is that trust is not simply a matter of communication or values; it is a product of a company's systems and structures. By prioritizing trust-building and sustainability, companies can create a culture of accountability and transparency, which can help to mitigate the risk of trust failures. The asset of trust is not simply a matter of reputation or brand identity; it is a tangible asset that can be measured and managed. By prioritizing trust-building and sustainability, companies can create a strong foundation for long-term success and profitability.
Brief 3.1 — The Promise Register: One Page, Four Columns, Every Outstanding Commitment
A support lead tells a customer "we'll never charge for seats you don't use." Fourteen months later that customer is billed for provisioned seats, escalates, and nobody inside the company can find any record that the sentence was ever said. It was said. It was true when said. It simply never became an object anyone could see.
The move: keep a single page listing every commitment currently outstanding, with four columns — the promise as the customer would state it, who made it, what it would cost to keep at worst, and when it expires or is reviewed. Not a legal document. A working list, owned by one named person, reviewed monthly.
The mechanism is that a promise you cannot see is a promise you cannot price, and an unpriced promise is one the organization will eventually break by accident rather than by choice. Writing the worst-case cost in column three does most of the work: it converts a warm sentence into a number someone must be willing to defend at a budget meeting. Most bad promises die at that moment, before they reach a customer. The condition the mechanism requires is that the register be shorter than a contract database — one page forces triage, and triage is the point. A register that lists three hundred items is a filing cabinet, and filing cabinets are not read.
Column one has a specific discipline: write the promise in the customer's words, not yours. "Data portability available on request" is what you meant. "I can get my data out whenever I want, in a format I can use" is what they heard. The register tracks what they heard, because that is what will be tested.
The failure mode is bureaucratic capture. Once a register exists, the incentive appears to move promises off it — to phrase things vaguely enough that they never qualify as entries. You will know this is happening when the register stays at nine items for four quarters while the company ships eleven new features. A register that never grows is not a clean company; it is a company that has learned to launder commitments past its own instrument. Guard against this by adding a standing entry: promises we declined to register this quarter, and why.
First action today: open one page. Write down the three commitments you personally know the company is carrying that appear in no contract anywhere. You already know what they are — that is the tell.
Brief 3.2 — Who Is Allowed to Promise? Drawing the Authority Line Before Sales Draws It for You
In the last week of a quarter, an account executive nine points from quota says a version of the sentence every account executive eventually says: "I'll make sure that gets built." Nothing in their comp plan, their training, or their tooling suggested they couldn't. The company will honor it or lose the account, and either way it will discover the commitment months late.
The move: publish an explicit authority ladder that says who may commit to what, in writing, and make it visible to the people bound by it before the quarter closes. Three tiers is usually enough. Anyone may commit to things already true and shipped. Managers may commit to timing on things already funded and on a roadmap. Only a named executive may commit to a feature that does not exist, a price outside the sheet, or an exception to a policy. Everything above your tier requires a countersignature that takes an hour, not a week.
This works because it converts an ambient social pressure into a procedural one. The rep under quota pressure is not dishonest; they are answering a question in real time with no mechanism for saying let me get you an answer by Thursday that doesn't feel like losing. The ladder gives them that sentence and makes it professional rather than weak. The condition — and this is where most implementations fail — is that the escalation path must actually be fast. An authority line with a five-day approval loop teaches reps to promise first and apologize later, which is precisely the behavior you were trying to structure away.
The failure mode is the ladder that exists only to allocate blame. If the first time a rep hears about the authority line is in a post-mortem where they're being held responsible for exceeding it, you have not built governance; you have built a liability shield pointed at your own staff. The signal is unmistakable: reps stop putting commitments in email and start making them on calls. You have not reduced promising. You have made it invisible, which is worse than where you started.
Pair the ladder with amnesty. Announce it alongside a two-week window in which anyone can surface a past commitment with no consequence. The backlog that surfaces is the most valuable diagnostic you will get all year.
First action today: ask your three highest-performing reps what they promised last quarter that they weren't sure they were allowed to promise. Don't take notes in front of them.
Brief 3.3 — Defaults Are Promises: Auditing Every Toggle That Ships Switched On
A product ships with analytics sharing on, email digests on, and a data-retention window set to indefinite. No one lied. Every setting is documented, every toggle reversible. Three years later a journalist describes the product as one that "collects everything by default," and the description is accurate, and the company is genuinely surprised.
The move: inventory every default in the product and write, next to each, the sentence a customer would be entitled to infer from it. Then ask whether you would say that sentence out loud to that customer's face. Where you wouldn't, flip the default.
The mechanism is that a default is a statement about what the vendor thinks is normal, and users read it exactly that way. This is well-established in choice architecture and it is not a subtle effect: the overwhelming majority of users never change a default, which means the default is the product for most of the people using it. A setting buried in a preferences pane is not a choice you offered; it is a choice you made and left a receipt for. The condition under which flipping defaults works is that the on-state must be genuinely valuable to the user rather than to you — if the feature is good, opting in is a small cost. If you find yourself arguing that adoption would collapse under opt-in, you have discovered the real assessment of the feature's value, and it is not the one in your deck.
There is a second-order effect worth naming: defaults set the baseline against which every later change is judged. Shipping restrictively and loosening with consent reads as generosity. Shipping permissively and tightening reads as taking something away, even when the tightened state is more protective. The order of operations is the whole game.
The failure mode is the audit that becomes a privacy theater exercise — flipping the three defaults that would appear in a headline while leaving the twelve that determine actual data flow. You'll recognize it when the audit is run by communications rather than engineering, and when its output is a blog post rather than a diff.
First action today: open your product's settings screen as a brand-new account. Screenshot it. Every toggle that is on is a promise you have already made.
Brief 3.4 — The Deck Against the Contract: Reconciling What Sales Said With What Legal Signed
The MSA says the platform provides "commercially reasonable uptime." Slide 14 of the deck that won the deal says 99.99%. Both documents are in the customer's possession. Only one of them was read closely, and it was not the MSA. When the outage comes, the customer will quote slide 14 — and in the room where the renewal is decided, slide 14 is the operative document regardless of what a court would say.
The move: before every enterprise contract is countersigned, run a ten-minute reconciliation in which someone reads the final deck against the final agreement and lists every place they diverge. The list goes to the customer, not into a file. "Here are four things we said in the presentation that the contract handles differently — here's which one governs."
The mechanism is that trust is destroyed at the seam between what was sold and what was signed, and that seam is invisible to everyone except the person who has read both artifacts — a person who, in most companies, does not exist. Legal reads the contract. Sales reads the deck. The customer reads neither in full. Creating that reader is a small, cheap structural fix that catches the specific failure this chapter is about: the unrecorded promise. The condition is timing. Run it before signature and it is a clarification the customer respects. Run it after an incident and it is a company producing paperwork to explain why it doesn't owe you anything.
Sending the divergence list feels like handing the customer a list of reasons to renegotiate. Occasionally it is. What it more often does is establish, at the outset, that you are the vendor who tells them what the contract actually says — which is worth more in the third year than the marginal terms you protected in the first.
The failure mode is reconciliation that resolves every gap in the contract's favor and calls it done. The output should sometimes be changing the contract, because sometimes the deck described what you actually intend to deliver and the agreement was drafted defensively by someone who had never met the customer. If ten reconciliations in a row end with "the contract governs," you are not reconciling. You are documenting.
First action today: pull the deck and the signed MSA from your largest recent deal. Read them side by side. Time-box it to twenty minutes.
Brief 3.5 — Reading the Silence: Expectations You Created by Never Saying Anything
For six years, a company never raised prices on existing customers. It never announced this. There was no grandfather clause, no policy page, no commitment of any kind. Then it raised prices, with ninety days' notice and a clear explanation, and the reaction was not the reaction to a price increase. It was the reaction to a betrayal.
The move: list the things your company has consistently done for long enough that customers have stopped expecting anything else, and decide deliberately which ones to formalize, which to keep informally, and which to end now while ending them is still cheap.
The mechanism is that a pattern held long enough becomes a promise without anyone having made one. Customers do not distinguish between a policy and a reliable habit; both produce the same planning behavior, and it is planning behavior — not stated belief — that defines an expectation. When a company breaks a six-year pattern, the customer isn't upset that the pattern changed. They're upset that they built something on it and were never told it was load-bearing. The condition for this working is honest recall: you cannot list your own silences from the inside, because from the inside they are simply how things are. You need the customer's view, which means asking former customers and long-tenured account managers rather than product leadership.
Silence has a particular quality that spoken promises don't: it is free. You accrued this expectation without ever paying the cost of committing to it, which is precisely why so much of it accumulates. The unspoken commitment is the most over-issued instrument in the company because nobody had to approve it.
Formalizing has a real cost — it converts an option into an obligation. Keep some things informal on purpose. What you must not do is keep them informal and let customers rely on them for years while telling yourself you never promised anything. That posture is legally sound and relationally fatal.
The failure mode is over-correction: announcing that everything unstated is now explicitly disclaimed. A page reading "we make no commitment regarding pricing, support response, or feature continuity" is technically accurate and reads to every customer as a company preparing to do something. You have converted an unspoken promise into a spoken threat.
First action today: ask one account manager who has been with a customer three-plus years: "What do they assume about us that we've never actually told them?"
Brief 3.6 — Positioning as Liability: What "Unlimited", "Forever", and "Democratize" Actually Commit You To
The word "unlimited" appears on the pricing page because it converts better than "generous." Eighteen months later, 0.3% of accounts are consuming forty percent of infrastructure spend, and the company discovers that its options are to enforce a limit it promised didn't exist, or absorb a cost it never modeled. Both roads lead through a customer telling the internet what "unlimited" turned out to mean.
The move: treat every absolute word in your marketing as a term with a cost, and before it ships, write the sentence you will say on the day you have to walk it back. If that sentence is not one you can imagine saying without embarrassment, change the word now.
The mechanism is that absolutes eliminate your own discretion. A qualified claim — "generous limits, and we'll talk if you hit them" — leaves room for the judgment call that will inevitably be required. An absolute forecloses it and forces the company into a choice between a costly promise and a visible reversal. "Forever" is worse than "unlimited," because it commits an institution beyond the tenure of everyone who approved it. "Democratize" is a third species: it commits you to a direction, which means every subsequent enterprise-tier decision will be read as apostasy by people who took the word seriously.
The condition is that this only works if marketing is in the room where the cost is modeled. Positioning language is typically approved on the conversion metric alone, by people with no visibility into the load it creates. The fix is procedural, not moral: absolute claims require a signature from whoever owns the cost line they touch.
There is a real trade here, and pretending otherwise is dishonest. Hedged language converts worse. Sometimes materially. The argument for hedging is not that it's safer — it's that a claim you can keep for a decade is a compounding asset and a claim you retract in year two is a permanent tax on everything else you say. That's a bet about time horizon, and companies with short horizons should make the other bet knowingly.
The failure mode is the asterisk. Writing "unlimited*" with a footnote to a fair-use policy is worse than either honest option: you get the conversion of the absolute and the credibility of the fine print, and when enforcement comes, the asterisk is read as proof you planned this.
First action today: grep your marketing site for unlimited, forever, always, never, any. Read what you find as a customer's lawyer would.
Brief 3.7 — The Founder's Post Problem: Personal Statements That Bind an Institution
A founder posts at midnight: "We will never sell user data. Not now, not ever." It's sincere, it's true, and it earns nine thousand reposts. Four years later the founder has left, the company is acquired, and a data-sharing arrangement is proposed that is legally clean, commercially sensible, and completely irreconcilable with a sentence typed by someone who no longer works there.
The move: give founder commitments a formal home. When a personal statement makes a claim about what the company will do, either promote it into policy within thirty days — with an owner, a mechanism, and a review cadence — or publicly restate it as a personal intention rather than a corporate commitment.
The mechanism runs on how audiences actually assign authority. A founder speaking is not read as an individual with an opinion; they are read as the institution speaking in its most candid register. That candor is exactly why the statement travels, and exactly why it binds. The asymmetry is brutal: the statement costs nothing to make and is enormously expensive to unmake, and the person who makes it is rarely the person who eventually pays. Promotion into policy fixes this by moving the commitment from a person to a structure — a structure that survives the person and can be pointed at by the next executive who wants to honor it.
The condition is that promotion must be real. A commitment that lives in a values page with no owner and no enforcement is not policy; it is the same post in a nicer font. Real promotion means: someone's job description contains it, some process would visibly fail if it were violated, and reversing it requires an act more public than a quiet product update.
The failure mode is the chilling effect. If every founder statement triggers a legal review, founders stop speaking candidly, and you lose the single most valuable trust-building channel most companies have. The instrument here is not silence — it is a deliberate register. Founders should say sweeping things. They should just know, in the moment, which of two registers they're in: "here's what I believe" or "here's what this company commits to." The first is free and valuable. The second costs money and requires a mechanism. Confusing them is the whole problem.
First action today: search your founder's public posts for the words "never" and "always." Pick the strongest one. Ask who owns it now.
Brief 3.8 — Promise Expiry: Retiring a Commitment Without It Reading as a Betrayal
A free tier introduced in year two to seed adoption is, in year six, consuming a fifth of infrastructure and converting almost nobody. Everyone internally agrees it should end. Nobody can say how to end it, because every proposed approach ends with a Hacker News thread titled [Company] kills free tier, and so the decision is deferred for another two quarters, during which it becomes more entrenched and more expensive to unwind.
The move: retire commitments through honored-then-closed rather than terminated. Keep the promise fully intact for everyone who has it, close it to new entrants immediately, and say plainly why. The grandfathered cohort is a cost you pay once and amortize; the reputational damage of revocation is a cost you pay indefinitely.
The mechanism is that trust is built on evidence of expensive choices, and grandfathering is that evidence, made unusually legible. Every existing user who keeps their tier is a live demonstration that this company honors what it said even when it hurts — and crucially, that demonstration is visible to prospects who never had the tier. You are not paying to retain a cohort. You are paying to broadcast a fact about your character, and the broadcast reaches people who will pay full price. The condition is that the promise must be bounded: honored-then-closed works when the grandfathered cost is finite and modeled. If the commitment is unbounded — unlimited storage forever on a free plan — you cannot grandfather it, and you must instead negotiate an exit with the affected cohort directly, individually, and generously.
The second condition is the reason. Not a reason — the reason, stated in plain numbers. "This tier costs us $2.1M a year and converts at under one percent" is a sentence people accept. "We're evolving our product strategy to better serve our community" is a sentence people correctly read as concealment, and concealment is what turns a business decision into a scandal.
The failure mode is the slow squeeze: keeping the promise nominally alive while degrading it — quietly lowering the limit, removing support, letting it rot until users leave on their own. This is worse than revocation because it is revocation plus deceit, and it teaches every remaining customer that your commitments decay rather than end. They will price that in everywhere.
First action today: name one commitment you're carrying that you'd never make again. Write the honest number it costs.
Brief 3.9 — Onboarding as Contract: The Sentences New Customers Still Remember Six Months Later
Six months into a contract, a customer says: "Your implementation lead told us migration would take two weeks." Nobody can find this in any document. What exists is a welcome email, a kickoff call, and a getting-started guide — none of which are treated as commitments by anyone internally, and all of which arrived during the two-week window when the customer was paying more attention to you than they ever will again.
The move: audit onboarding as a promise surface. Read every email, screen, and script a customer encounters in their first thirty days, and mark every sentence that states or implies what will happen. Then make someone own each one.
The mechanism is a well-documented property of memory: information received during a period of high attention and high stakes is encoded far more durably than the same information received later. Onboarding is that period. A customer reads your welcome sequence with an intensity they will never again bring to your communications — they are, in that moment, deciding whether they made a good decision. Sentences absorbed under that condition become the customer's model of the relationship and are startlingly resistant to later correction. This is why the MSA loses to the kickoff call: the MSA was read by procurement in month zero, and the kickoff call was heard by the person who will run the renewal.
The condition is that onboarding is usually written by whoever had time — a growth marketer, an implementation lead, a founder in year one — and then never revisited while the product changes underneath it. The audit is largely archaeological. Expect to find promises about features that were deprecated eighteen months ago.
The genuine tension: onboarding copy is optimized for activation, and confident specific claims activate better than careful ones. "Most teams are live in two weeks" outperforms "timelines vary." You do not resolve this by hedging everything. You resolve it by making the specific claim true — measure your actual median implementation time and quote it — which is more work and better on every axis.
The failure mode is sanitizing onboarding into legal safety, producing a first-week experience that reads like a terms-of-service page. You will have eliminated the unrecorded promise and, with it, the warmth that made the customer glad they signed. Precision is the target, not caution.
First action today: read your own welcome email as a customer. Underline every future-tense verb.
Brief 3.10 — The Under-Promise Trap: When Legal Safety Costs You the Sale and the Trust Together
A prospect asks the direct question: can you handle our volume at quarter-end? The honest answer is yes — you've done it four times for comparable customers. The answer that leaves the room is: "Our architecture is designed to scale, and we'd be happy to discuss your specific requirements." The prospect hears a company that won't commit, and buys from the competitor who said yes. The competitor was also telling the truth.
The move: identify the claims you can make specifically and defensibly, and make them specifically. Reserve hedging for genuine uncertainty, and say which is which out loud. "We've handled 4x that volume for three customers in your industry, and I'll put you on a call with one of them. Where I can't commit is the custom-connector timeline — that's genuinely unknown until we scope it."
The mechanism is that hedging is not read as honesty. It is read as evasion, and the reading is usually correct, which is why buyers are so good at detecting it. Uniform caution destroys the signal that would let a customer distinguish between the things you know cold and the things you're unsure of — and that signal is the actual product of a sales conversation. A vendor who hedges everything has told the buyer nothing except that the vendor is protecting itself. A vendor who commits hard in four places and refuses to commit in the fifth has handed the buyer a map of the real risk, which is what they were trying to buy all along.
This is the mirror image of the chapter's central problem, and both errors come from the same root: no mechanism for distinguishing a commitment you can keep from one you can't. Without that mechanism, an organization oscillates — over-promising when the quarter is tight, over-hedging when legal is ascendant — and never lands on the calibrated position that would serve it. Fix the register and the authority line, and calibrated confidence becomes available for the first time. You can promise boldly precisely because you now know what you're carrying.
The failure mode is confidence uncoupled from evidence — reps who learn "be specific" and generate specificity rather than retrieving it. Invented precision is worse than hedging, because it is falsifiable. The rule is narrow: specific claims require a specific instance behind them, retrievable within an hour.
First action today: write down the three claims about your product you are certain are true and have never said in a sales call because someone told you not to.
Essay 3.1
The prompt
The boundary between expectation and invention is not drawn in statute but in the friction of interpretation, and when a company designs a signal that invites inference, it cannot later disavow the inference as merely invented. The tension lies in the asymmetry of knowledge: the company knows the architecture of the interaction, including every default, every omission, and every path of least resistance; the customer navigates that architecture with limited cognitive bandwidth and no access to the system's constraints. If the company creates an environment where a reasonable user is virtually compelled to draw a specific conclusion, the cost of ambiguity falls on the architect of the environment, not the navigator. The cost falls on the company because the company holds the power of definition, and when that power is exercised to capture value through interpretive gaps, the resulting friction is not a user error but a design tax. To argue otherwise is to argue that trust is the customer's burden to manage, a proposition that collapses under the weight of behavioral reality where defaults become promises and omissions become contracts.
What a serious answer has to do
A serious answer must establish the mechanism of "interpretive labor" and show how it shifts across the boundary of a promise surface. It must demonstrate that when a company designs a system with high cognitive friction on exit or low visibility on constraints, it effectively subsidizes its revenue with the customer's interpretive labor, and this subsidy must be priced or removed. The evidence must come from regulatory history and case studies where courts or regulators distinguished between "bait" (created expectation) and "switch" (invented expectation), such as the evolution of negative-option marketing rules or the enforcement actions against hidden cancellation flows. The cheap answer—that customers should read the terms or that invention is the customer's responsibility—must be argued past by showing that terms are read only when the cost of reading is lower than the cost of the error, and that the company structures the interface precisely to make reading irrational. The essay must prove that the company bears the cost of ambiguity when the ambiguity is a function of the company's design choices, not the customer's negligence.
Where to look
One should look to the regulatory history of "negative option" marketing in the United States and the European Union, tracing how the law moved from "buyer beware" to "active consent" when the cost of interpretation became systemic. Case studies of SaaS cancellation flows reveal how companies balance friction against conversion, often designing "dark patterns" that make cancellation harder than subscription, a practice that regulators are increasingly treating as a deception of omission. Behavioral economics literature on "endowment effect" and "loss aversion" provides the mechanism for why defaults are treated as promises, and specific instances of consumer protection tribunals, such as the UK's Competition and Markets Authority actions against gym contracts or software auto-renewals, offer concrete examples where the cost of ambiguity was assigned to the merchant. The reader should also examine the litigation history of "bait-and-switch" advertising to see how courts define the point where a signal becomes a commitment, regardless of fine print.
The length
2,500 words minimum.
Essay 3.2
The prompt
To ship "unlimited" is to ship a lie about thermodynamics, yet infrastructure inevitably imposes caps, and the walk-back—when it comes—destroys the trust capital accumulated during the period of abundance. The tension arises because "unlimited" is a powerful acquisition signal that competitors cannot easily match, while any subsequent restriction is perceived as a betrayal rather than a realization of physical limits. If a company never ships "unlimited," it cedes market share to rivals who promise more, even if those rivals also cap; if it does ship "unlimited," it risks a catastrophic loss of trust when the inevitable constraint arrives, because the walk-back signals a broken model, not a constraint. The cost of the walk-back is exponential because it does not merely correct a price; it rewrites the user's history, implying that the value received was fraudulent and that the company's integrity was always compromised. The question is whether a company can ever ship a word it knows it will eventually have to walk back, or whether the only path to trust is to never make the promise, thereby accepting a lower growth rate for a higher retention probability.
What a serious answer has to do
The essay must define the mechanism of "graceful decay" versus "hard cutoff" and show that the walk-back cost is a function of the transition design, not the constraint itself. It must establish that "unlimited" is not a capacity claim but a priority claim, and that trust survives if the company maps "unlimited" to a clear, non-betrayal mechanism such as "fair use" or "priority queuing" that is disclosed before the cap is hit. Evidence must come from telecommunications history, where "unlimited" data plans evolved into throttling regimes, and from streaming services that introduced device limits or download caps; the companies that maintained trust did so by announcing constraints proactively and adjusting usage patterns transparently before the user was blocked. The cheap answer—that "unlimited" is marketing puffery protected by the terms—must be argued past by showing that users do not read terms and that the experience of being cut off while using the service is a violation of the social contract, regardless of the legal text. The essay must argue that a company can ship "unlimited" only if it builds a governance structure that treats the constraint as a feature to be managed, not a secret to be kept, and that the walk-back is acceptable only when it is preceded by a period of "sober transparency" about the limits.
Where to look
Look to the history of telecommunications regulation and the "great throttling wars" of the 2010s, where carriers like AT&T and Verizon faced backlash over throttling policies, and examine how companies like Google Fi or T-Mobile managed the transition by adjusting marketing language and offering "unlimited premium" tiers. Case studies of streaming services, such as Netflix's introduction of device limits or Spotify's "Family Plan" sharing restrictions, reveal how companies handle the tension between growth and infrastructure. The discipline of "service design" offers frameworks for managing user expectations through progressive disclosure and graceful degradation, and specific examples of companies that have avoided trust crises by using "fair use" policies prominently can be found in cloud computing providers that offer "unlimited" storage with clear performance tiers. The reader should also examine the "bandwidth cap" literature in behavioral economics, which shows how consumers react to caps based on the salience and timing of the notification.
The length
2,500 words minimum.
Essay 3.3
The prompt
A sales commission paid on the signature is a promise that has been liquidated before delivery, and when the sales incentive structure rewards the promise while the delivery team bears the cost of the breach, the organization is structurally incentivized to over-promise. The tension lies in the principal-agent problem: the company wants growth, the sales rep wants commission, and the customer wants value, but the comp plan aligns the rep with the company's growth goal at the expense of the customer's experience. If the comp plan does not internalize the promise, sales will sell features that do not exist, contracts that are unenforceable, or timelines that are impossible, because the rep is insulated from the cost of the breach. The cost of this misalignment is not merely rework; it is the erosion of trust capital, which compounds faster than revenue because every breach requires a deposit of effort to repair, and the effort is rarely sufficient to cover the loss. To design a compensation structure that internalizes the promise is to make the sales rep a residual claimant on the customer's success, but such a structure breaks growth, creates risk aversion, and may paralyze the sales organization if the metrics are too complex or the clawbacks too punitive.
What a serious answer has to do
The essay must design a mechanism for "probability-weighted revenue" or "full-lifecycle value" scoring that ties sales commission to the probability of successful delivery, not just the signature. It must show that clawbacks are too crude and reactive; instead, the comp plan must use a "risk score" at the point of sale that adjusts the commission based on the complexity of the implementation, the fit of the product, and the historical success rate of similar deals. Evidence must come from companies that have moved beyond "commission on sign" to "commission on realization" or "commission on retention," such as certain enterprise software vendors that pay a portion of commission on the anniversary of the contract or when the customer reaches specific usage milestones. The cheap answer—that sales should just be trained to sell accurately—must be argued past by showing that training does not change incentives, and that as long as the comp plan rewards the signature, sales will game the system. The essay must argue that the compensation structure must include a "deal desk" governance function that has veto power over deals that exceed the risk score, and that the sales rep must share the risk of the breach, not just the reward of the close. The insight is that the comp plan is the true contract, and that trust is a function of the incentive structure, not the mission statement.
Where to look
Look to incentive design literature in organizational economics, specifically the principal-agent problem and the theory of "risk-sharing" contracts. Case studies of enterprise software companies, such as Salesforce or HubSpot, which have experimented with "customer success" metrics in sales compensation, or insurance companies that tie agent commissions to claim ratios, provide concrete examples of comp structures that internalize the promise. The discipline of "behavioral operations" offers insights into how sales reps respond to complex metrics, and specific examples of "clawback" policies in industries like pharmaceuticals or financial services can illustrate the risks of punitive structures. The reader should also examine the role of "deal desks" in B2B sales organizations, which often serve as governance functions that balance sales enthusiasm with delivery risk, and how these functions can be integrated into the comp plan to create a feedback loop.
The length
2,500 words minimum.
Essay 3.4
The prompt
Robinhood's January 24, 2021, decision to restrict buying on certain stocks was not a breach of contract but a collision with clearinghouse physics, and the question is whether a company can be held to a promise that capital requirements made impossible to keep. The tension lies in the asymmetry of information and control: Robinhood users saw a restriction on their app and interpreted it as the company denying them access, while Robinhood was actually restricted by Cboe Clearing, which had raised margin requirements to cover systemic risk. The company owed its users the truth of the constraint, not the execution, but by failing to communicate the clearinghouse mechanics, Robinhood created a narrative of malice that destroyed trust. The question is whether a company can be held to a promise of "free, easy trading" when the promise relies on a financial infrastructure that can fail, and what the company owes when that infrastructure collapses. The answer is not that the company is blameless, but that the breach of trust lies in the opacity of the constraint, not the constraint itself; the company owed its users "sober transparency" about the limits of the system, and by hiding the mechanics until the break, Robinhood failed its users.
What a serious answer has to do
The essay must define the mechanism of "systemic risk transmission" and show how a company acts as a node in a financial network, subject to constraints it cannot control. It must establish that the promise of "free, easy trading" is a promise of access, not a promise of guaranteed execution at all times, and that the company can break the promise only by failing to communicate the constraints clearly. Evidence must come from the Robinhood January 24, 2021, incident, including the Cboe Clearing margin calls, the company's response, and the subsequent regulatory scrutiny. The cheap answer—that Robinhood was forced by the clearinghouse and therefore blameless—must be argued past by showing that the company had choices: it could have disclosed the clearinghouse requirements proactively, or it could have structured its business to avoid the constraint, or it could have communicated the reality to users in real-time. The essay must argue that the company owed its users "sober transparency," a governance function that aligns the user's mental model with the system's reality, and that the failure to do so was a breach of trust regardless of the external constraints. The insight is that trust is preserved not by keeping a broken promise, but by aligning the user's view with the system's reality, and that the cost of opacity is higher than the cost of the constraint.
Where to look
Look to the regulatory history of Robinhood, including the SEC's investigation and the company's consent order, which detail the failure to disclose clearinghouse constraints. Case studies of financial crises, such as the 2008 financial collapse or the Archegos scandal, reveal how companies manage risk and communicate with users when infrastructure fails. The discipline of "financial regulation" offers insights into clearinghouse mechanics and the role of margin requirements, while "behavioral finance" shows how users interpret restrictions based on the transparency of the system. Specific examples of companies that have maintained trust during crises, such as banks that communicated clearly with depositors during runs, can illustrate the value of "sober transparency." The reader should also examine the litigation history of Robinhood, including the class-action lawsuits, to see how courts viewed the company's disclosure practices.
The length
2,500 words minimum.
Essay 3.5
The prompt
The marketing department no longer writes the promises; the interface writes them in CSS and state machines, and the largest source of untracked promises has moved from the brochure to the product screen. The tension lies in the governance of "default bias" and "progressive disclosure": every default setting, every onboarding flow, and every error state communicates a promise to the user, often without the company's explicit intent, and when the product behaves differently than the interface suggests, the resulting trust failure is unrecorded because no one owns the promise. If the governance function does not track the promise surface of the interface, the organization accumulates "trust debt" that compounds silently, eroding retention and increasing support costs. To assign ownership of the interface promise is to create a new governance function, such as a "Product Legal" or "UX Ethics" board, that has veto power over design decisions that create a delta between the user's expectation and the system's behavior, but such a function risks paralyzing product velocity and creating a compliance theater where governance is just another checkbox. The question is which governance function should own the interface promise, and how that function can balance the need for trust with the need for agility.
What a serious answer has to do
The essay must define the mechanism of "interface as contract" and show how the product interface is the primary vehicle for promise-making in modern software. It must establish that the governance function must be "design-time compliance," integrated into the product development lifecycle, rather than "post-hoc legal review," which is too late to prevent the promise. Evidence must come from case studies of "dark patterns" and "dark UX," such as the FTC's actions against companies that used confusing cancellation flows or hidden fees, and from specific examples of companies that have implemented "UX Ethics" boards or "Product Legal" roles. The cheap answer—that product teams should just "do the right thing" or that users should "read the terms" must be argued past by showing that design choices are not random and that companies optimize for metrics that often conflict with trust. The essay must argue that the governance function must have the authority to veto designs that create a high probability of trust failure, and that the metric for success is not "compliance rate" but "trust velocity," the speed at which users can verify that the system is behaving as promised. The insight is that the product interface is the new legal code, and that governance must be embedded in the code, not the contract.
Where to look
Look to the literature on "dark patterns" by Harry Brignull and the "UX ethics" movement, which documents how interface design can manipulate user behavior. Case studies of companies that have faced backlash for interface design, such as Facebook's privacy changes or Spotify's "Family Plan" sharing restrictions, illustrate the cost of untracked promises. The discipline of "behavioral design" offers frameworks for understanding how defaults and choices influence user behavior, and specific examples of companies that have implemented "UX Ethics" boards, such as Microsoft's "Responsible AI" standards or Apple's "App Tracking Transparency" framework, can show how governance can be structured. The reader should also examine the role of "product legal" in tech companies, which serves as a bridge between legal risk and product design, and how these functions can be integrated into the development process to prevent trust debt from accumulating.
The length
2,500 words minimum.