The model that explains "why is this account at risk" must produce decomposable answers. No black-box reasoning on the customer-impact path.
The AI playbook can prepare the email, the calendar invite, the in-app message. A named human ratifies before anything fires.
Every paragraph in the board memo traces to a numerical source listed in §2 or a documented assumption in §5.
A signal known to be unreliable (broken data lineage) is suppressed by the validation layer before it reaches a CSM.
Where AI explains a customer-impact decision, the explanation must be decomposable into named drivers. Opaque models forbidden on the explain path.
The AI can compose. The AI cannot send. A named human confirms before any customer touch — email, call, in-app, invoice, refund.
Every ADR's "do not" list becomes a grep pattern the build layer runs before commits land. Forbidden lines never reach production.