Prism

Operating Principles

Prism Customer Success Handbook — Section 1.1

About this page

Written last, deliberately. These principles are derived from decisions actually made while designing this function — not authored upfront as aspirations. Each one below points to where it was decided and, more usefully, names what it costs. A principle with no cost isn't a principle; it's a slogan everybody already agrees with.

It sits first in the handbook because it's the frame for everything after it. It was written ninth because it couldn't be honest any earlier.


1. Health scores inform decisions. They don't make them.

The model computes; the human decides. Every scoring mechanism here has a deliberate human override, and the overrides win.

Where it was decided: Risk Level exists as a signal separate from health band, because a composite average can't express two risks compounding (1.6 Health Scoring Methodology). Forecast is deliberately decoupled from health, because judgment sees competitive threats and budget freezes the data model can't (2.6 Renewal Forecasting). Renewal Risk fires on the CSM's forecast alone, ungated by health or renewal timing (3.2 Renewal Risk). Escalation forces Risk Level to Critical regardless of the computed tier (2.7 Escalation Management).

What it costs: manual judgment is inconsistent and vulnerable to systematic optimism. The movement rules, stated reasons, and quarterly accuracy review exist because the tradeoff is real, not because the judgment is untrustworthy.

2. Never score on data we couldn't believably collect.

If a signal would require data the company wouldn't plausibly have, it doesn't go in the model — even when it would make the model look more sophisticated.

Where it was decided: Commercial Risk was cut as a health category because nothing non-circular remained to compose it from. Adoption breadth was cut because the denominator — the customer's total client book — lives in their business, not ours. Ticket CSAT was cut for sparse coverage. NRR was left out because expansion history doesn't exist (1.6 Health Scoring Methodology, 1.8 Metrics Library).

What it costs: a simpler model that measures less. Four categories rather than five, and several metrics a larger CS org would report. Worth it, because a model built on invented inputs collapses the moment someone asks how a number is calculated.

3. Enter risk early. Exit it slowly.

An account enters At-Risk if either health falls below Stable or any risk playbook is active. It returns to Healthy only when both clear (1.6 Health Scoring Methodology).

Where it was decided: the asymmetry is explicit in the state transition rules, and it recurs — Risk playbooks fire on OR conditions while Expansion requires an AND of three (3.5 Expansion Opportunity).

What it costs: false positives. Some accounts get attention they didn't need. That's the intended trade: an unnecessary check-in costs an hour, a missed decline costs an account. The inverse asymmetry on Expansion exists for the same reason in reverse — an unwarranted expansion approach costs credibility, so that one triggers conservatively.

4. A signal that fires on everything fires on nothing.

Alert discipline is a design responsibility, not a preference. Every notification competes for the same finite attention.

Where it was decided: Health Decline fires on a band crossing, not a threshold, so an account sitting at 55 doesn't re-alert weekly (3.1 Health Decline). Playbooks carry a 30-day cooldown (3.0 Playbook Index). Support tickets are all visible but only selectively notified — pull for awareness, push for action (2.5 Cross-Functional Interfaces). Ticket volume isn't scored at all, because it's ambiguous in both directions (1.6 Health Scoring Methodology).

What it costs: some things get noticed later than they could have. Accepted, because a channel that interrupts constantly gets ignored entirely — including on the day it matters.

5. Diagnose before contacting.

Know what changed before reaching out. The generic check-in is the weakest move available in customer success: it asks the customer to do our diagnostic work and signals that we noticed a number move and know nothing else.

Where it was decided: step 1 of Health Decline is identifying the driving category before any outreach (3.1 Health Decline). Low Adoption separates "never reached value" from "regressed" before anything else, because they're different problems (3.3 Low Adoption). The stall-to-intervention table exists so that education isn't sent at a structural problem (2.9 Customer Education & Enablement).

What it costs: slower first contact. An account stalled on credentials waits an extra day while we work out that's what it is — and gets a useful message instead of a tutorial it didn't need.

6. Service level comes from the coverage model, not from who asks loudest.

What an account receives is determined by segment and situation, not by volume of asking.

Where it was decided: prioritization ranks by risk, stage, and consequence — a customer request is an input, not a tier (2.4 Account Prioritization Framework). SMB has no standing calls by design (2.2 Meeting Standards & Working Norms). An SMB account demanding high-touch service gets "no, with warmth," and if it genuinely warrants more, the answer is re-segmentation rather than serving it off-model (2.11 Exception Handling).

What it costs: telling reasonable people no. The qualifier that makes it defensible: requests are always answered quickly even when the underlying work is queued. Acknowledgement is fast; the work is prioritized.

7. Renewals are earned continuously, not negotiated at the end.

If the first renewal conversation is also the first value conversation, the motion has already failed. Everything after that is negotiation, and negotiation is where discounts substitute for value.

Where it was decided: renewal checkpoints start at T-150 for Enterprise (3.7 Renewal Motion). The value record starts at onboarding close-out, while AMs still remember what the old process cost (3.6 New Customer Onboarding). EBRs exist to put outcomes in front of the buyer who never sees them (4.3 EBR Kit). "A discount closed it" is explicitly not a resolution (3.2 Renewal Risk).

What it costs: sustained effort on accounts that look fine. Most of it is invisible — you can't point at the renewals that were never at risk because the work was done.

8. Say what's not working before the customer does.

Naming problems first is the highest-trust move available, and it's cheapest when volunteered.

Where it was decided: the EBR deck has a mandatory "what didn't go well" slide (4.3 EBR Kit). Escalation updates go out on schedule even when there's no news (2.7 Escalation Management). Declined feedback is closed honestly with reasoning, because customers accept no far better than silence (2.8 Voice of Customer & Product Feedback). Silent drift is watched for so breakage is raised before the customer notices (1.5 Customer Journey Map).

What it costs: volunteering bad news that might have gone unnoticed. The alternative — being told by the customer — costs the credibility of everything else you said.

9. Record the exception rather than hiding it.

Deviations from process get logged with their reason. Unrecorded exceptions become invisible norms: the handbook says one thing, the function does another, and nobody can tell which is which.

Where it was decided: every exception in 2.11 Exception Handling carries a recording requirement. An incomplete handoff is proceeded with and logged (2.1 Sales → CS Handoff Standard). A renewal closed on discount is recorded as such so the pattern is visible (3.2 Renewal Risk). Unlogged customer interactions are treated as not having happened, because health, triggers, and the renewal record all read from the activity log (2.2 Meeting Standards & Working Norms).

What it costs: writing down the times you bent the rule. That's the point — six recorded instances of the same exception is evidence the rule is wrong.

10. Improve the system, not just the accounts.

Working accounts well is the job. Improving what catches them is also the job.

Where it was decided: the quarterly system review examines false positives, false negatives, forecast accuracy, playbook abandonment, and coverage reality — with concrete changes or an explicit decision to change nothing as its output (2.3 Operating Rhythm). Stale playbooks stay open rather than auto-closing, because auto-closing would hide the finding (3.0 Playbook Index). Churn reviews cluster in aggregate, because three losses to one cause is a process problem, not three account problems (4.5 Churn Review Template).

What it costs: time spent on the function rather than on customers, in a role with no spare capacity. Protected on the calendar for exactly that reason — it's the first thing a busy quarter would drop.


The two that govern the rest

If the other eight collapsed, these would remain:

The model computes; the human decides. Every automated signal here is an input to judgment, never a replacement for it.

Don't build on data you couldn't believably have. Everything else in this handbook depends on the measurements being real.