# 04 — Opportunity Register (draft)

**Step:** 5a (AI Solutions Architect) + 5b (Growth & Monetisation Analyst) · **Date:** 2026-07-26
**Subject:** SatuSatu (satusatu.com), 253 SKUs, Bali-dominant TAA platform, operated by **PT Tiptip Network Indonesia** (same legal entity as TipTip; a product line, no separate P&L).
**Inputs:** `00-internal-context.md` · `00-scope.md` (§8 binding constraints) · `01-landscape.md` · `02-competitor-matrix.md` (§8 conflicts) · `03-ops-scan.md` (§4a/4b/4c benchmark bands) · `99-open-questions.md`
**Status:** ⚠️ **Draft for red-team attack.** Nothing here has been softened in anticipation of that attack. Where a number does not exist, this file states a **break-even threshold**, not a forecast.

---

## 0. How to read this file, and what is deliberately absent

**Three binding constraints shape every row. They are not caveats; they are the design inputs.**

| Constraint | Source | Consequence applied here |
|---|---|---|
| 🔴 **No dedicated engineering capacity.** The D2/D3 platform build consumes the team. | `00-internal-context.md` `{{CAPACITY}}`, answered 2026-07-26 | **Effort is the binding constraint, not impact.** Ranking is on **impact per eng-week**. Buy/partner is the default; build carries the burden of proof. Every row states what it **displaces**. |
| 🔴 **Thin margin, split by pool.** Pool A ~10% gross / ~7% after payments+FX; Pool B ~27% gross. | `01-landscape.md` §6.3 `[INFERENCE]`, ceiling anchored on Klook F-1 **11.2% gross profit on $3.04bn GTV** `[VERIFIED, Tier A]`; Pool B anchored on Arival's documented **25–30%** net-rate convention `[VERIFIED, Tier B]` | **Inference cost per transaction is tested against the relevant pool, never a blend.** See §1a. |
| 🔴 **No disclosed funding since November 2022**, EBITDA-positive Q1 2026. | `00-scope.md` §2.5 `[INFERENCE]` | Anything with a long pre-revenue build is disadvantaged on principle. Mechanisms **(d) cost-to-serve** and **(e) leakage** are favoured because they size against money already being spent. |

**Also binding:**
- **Zero AI in SatuSatu's product today** — keyword search only, no semantic search, no personalisation, human concierge `[VERIFIED, Tier A — live product]`. Greenfield. **The group's one production AI system — "AI Event Business Sales Forecasting" for entertainment ticketing — is NOT scored as an existing asset anywhere in this file.** It is a different forecasting problem (date-fixed single-shot events with a pre-sale curve vs 253 evergreen daily-departure low-ASP SKUs), and no source claims it transferred.
- **B2B pricing is decided:** tier by supply source. **D2/D3 monetise Pool B.** Pool A is catalog filler at D2C parity or withheld.
- **The curation promise will be re-anchored** away from catalog-based claims (GATE 1 decision 6, the Civitatis pattern).

**Absent by design:**
- No row is scoped, sized or recommended for tiptip.id ticketing, creator or sponsorship (`00-scope.md` §5.1).
- No model, vendor or framework selection (`00-scope.md` §5.3). Where a row says "vendor-delivered", it names the *category*, not the product.
- No invented internal figures. `{{SCALE}}`, order volume, GMV, concierge minutes per pass, Pass breakage and concierge headcount are all still **UNKNOWN**. Every row therefore carries a **break-even threshold** as its load-bearing number.

---

## 1. Method — the five screens every candidate passed through

1. **Inference cost per transaction vs contribution margin, per pool** (§1a). A candidate that consumes more than ~25% of the contribution margin of the pool it touches is rejected or re-pointed at a different pool.
2. **Data readiness** — Y / N / Partial, stated per row. Data readiness is the most common silent killer of an AI roadmap and three of the four data assets this register would want are `UNKNOWN` (Q9 WhatsApp transcript retention, Q10 search/clickstream logs, Q6 order volume).
3. **Effort in eng-weeks**, with the honest note that **payroll is the wrong price**: the true cost of an eng-week is the D2/D3 roadmap slip it causes (`03-ops-scan.md` §4c.0). Every dollar break-even below is therefore **optimistic by construction, and the direction of error is known**.
4. **Latency budget and failure mode**, with blast radius. The single most important architectural constraint in this register is inherited from `03-ops-scan.md` §4a.3.3: **outbound in-destination messages must be *rendered*, never *generated*.**
5. **Displacement** — what D2/D3 platform work each row competes with.

### 1a. The inference-cost screen, computed once

**Reference ATV = US$25** `[ASSUMPTION ±20% — bracketed by 03-ops-scan §4c.1.2's low/base/high of US$20/25/30, itself [INFERENCE]]`.

| Pool | Contribution per booking | Basis |
|---|---|---|
| **Pool A (D2C)** | **US$1.75** (range $0.75–$2.75) | $25 × 7% net `[INFERENCE, 01-landscape §6.3]` |
| **Pool B (D2C)** | **US$6.75** gross → **US$6.00** after ~3pp payments+FX | $25 × 27% `[INFERENCE, 01-landscape §6.3]` |
| **Pool B (B2B retained)** | **US$3.00** | $25 × 12% retained after a 12pp conceded spread `[INFERENCE, 03-ops-scan §4c.0.3]` — cross-checks exactly against §4c.3.4's independently stated "retained margin US$3.00 per booking" ✅ |
| **Pass (D0)** | Concierge labour per pass **$1.54 / $7.92 / $38.09** | W1 × L14, `03-ops-scan.md` §4a.7 `[INFERENCE]` |

**Vendor-priced AI, metered per resolution — US$0.50 / US$0.99 / US$3.00** `[VERIFIED as vendor pricing, Tier C, 03-ops-scan C1]` — as a share of contribution, at one metered touch per booking:

| | @$0.50 | @$0.99 | @$3.00 |
|---|---|---|---|
| **Pool A (D2C)** | 29% | **57%** | **171%** |
| **Pool B (D2C)** | 8% | 17% | 50% |
| **Pool B (B2B retained)** | 17% | 33% | 100% |

> 🔴 **The screen, stated as a rule: Pool A cannot carry a metered AI touch at any published vendor price. Pool B can carry one at US$0.50–0.99 and cannot at US$3.00.**
>
> This is not a pricing quibble — it is the reason the register's centre of gravity is *deterministic, unmetered* work (rendered templates, rules, schema fields, contract clauses) rather than model calls. It is the same inversion `03-ops-scan.md` §4a.5.5 found from the labour side: **US-priced per-resolution AI does not clear an Indonesian labour arbitrage of US$0.079 per concierge-minute.** Break-even AHT against Fin's $0.99 is **12.5 minutes**; the deflectable concierge tasks are 2–3 minutes each.

**Model-token route:** `03-ops-scan.md` C10 records 2026 model $/Mtok as **NOT FOUND**, and C11 records WhatsApp Business Platform per-conversation fees for Indonesia as **NOT FOUND**. **This register therefore never states a token cost.** Every model-bearing row instead states a **break-even inference cost per transaction** — the price above which the row stops paying. That is a testable number the moment a real price list is opened.

### 1b. The reference volume R, and why the *ordering* is robust to it

`{{SCALE}}` is UNKNOWN. To make rows comparable at all, one reference volume is used and it is **not a SatuSatu figure and not a forecast**:

```
R:  1,000 bookings/month  ·  ATV US$25  ·  65% / 35% Pool A / Pool B by GMV  ·  200 passes/month
    [ASSUMPTION — comparability device only]
→   annual GMV $3.00M · Pool A $1.95M (7,800 bookings) · Pool B $1.05M (4,200 bookings) · 2,400 passes/yr
→   Pool A net gross profit $136,500/yr · Pool B gross profit $283,500/yr
```

> **Because nearly every impact in this register scales linearly in R, the *ranking* is insensitive to R — only the absolute dollar figures move.** The three exceptions are flagged **R-independent** in their cards (avoided-build savings, contract retrofit costs, fixed prerequisite costs). **The break-even threshold in each card, not the dollar figure, is the number to argue with.**

**Sensitivity on the effort price:** all dollar break-evens use the base loaded eng-week of **US$679** `[INFERENCE, 03-ops-scan §4c.0; flag 4c-G1 — no Indonesian engineering salary source was ever collected]`. At the low/high bands (US$390 / US$1,109) **every break-even threshold below scales by 0.57× / 1.63×.**

### 1c. The staffing budget, and how the `[UNSTAFFABLE]` line is drawn

There is **no dedicated capacity**, so "how many eng-weeks are available" is a decision, not a fact. This register does not guess team size. Instead:

- It assumes a **displacement budget of 6 eng-weeks across two quarters** `[ASSUMPTION — must be confirmed by the Head of Product; it is the single most consequential input to §6]`, carved out of the D2/D3 build.
- The ranked table in §6 carries a **cumulative eng-weeks** column so the line can be redrawn at whatever the real budget turns out to be.
- Rows whose *individual* effort exceeds the whole budget, or that sit below the cumulative line at 6 eng-weeks, are labelled **`[UNSTAFFABLE — documented for sequencing, not proposed]`** and moved to §7. They are not padded into the ranked table.

---

## 2. Platform prerequisites — what must exist before any model-bearing row ships

**Nothing in this list exists today.** Every model-bearing row inherits the cost of whichever prerequisites it depends on, and those costs are stated in the row.

| # | Prerequisite | What it actually is here | Cost | Blocks |
|---|---|---|---|---|
| **P1** | 🔴 **Declared `availability_model` per Pool B SKU + a booking state machine** | One schema field with four values (`allotment`, `freesale_capped`, `static_schedule`, `request_to_book`) plus parameters, and a supplier-side booking record. `03-ops-scan.md` §4b.4.3 | **ZE-09** — 0.5/1/2 eng-weeks + ops classification | OPP-02, OPP-03a, OPP-03b, ZE-02, all D2 rows, all D3 rows |
| **P2** | 🔴 **PDP-law ruling: may traveller WhatsApp content go to a third-party model provider?** | One legal opinion. `03-ops-scan.md` §4a.5.8 — "flips buy (config, ≤90 days, feasible) vs build (engineering, not feasible)" | One counsel brief. **Zero eng-weeks.** | Every row that touches traveller conversation content: OPP-01, OPP-03b, OPP-04 |
| **P3** | 🔴 **Liability ruling: does automating a concierge instruction expand exposure beyond the operator disclaimer?** | Same counsel brief as P2. A concierge instruction is **SatuSatu's own act**, not an operator act; and the Pass markets *"a real Bali local"* | Zero eng-weeks | OPP-01, OPP-02, and any in-destination automation |
| **P4** | **Eval harness** | Cheapest viable form: 100–200 manually-labelled examples per task, held out, re-run on every prompt change. `[ASSUMPTION]` 8–16 ops hours = **US$60–130** at the US$8/hour BD rate | Ops hours, **not eng-weeks** | Every model-bearing row |
| **P5** | **Observability on the *right* metric** | **IDIER** (in-destination instruction error rate) via 100% manual QA of a random sample, n≥400; **escaped-defect rate** for catalog; **72h re-contact rate**. 🔴 Explicitly **not** deflection rate and **not** auto-pass rate — both rise as quality falls (`03-ops-scan.md` §4a.3.5, §4b.2.3, Q43) | Ops process | Every model-bearing row |
| **P6** | **Human-in-the-loop tooling** | For concierge assist the queue already exists (WhatsApp) → near-zero. For catalog dedup a review-queue UI is **~⅓ of the dedup build** (`03-ops-scan.md` §4b.1.6) → material | 0 for concierge; 1.3–2.7 eng-weeks for dedup | OPP-D1-2 (light), U3 (heavy) |
| **P7** | **Rendered-not-generated template library + slot mapping** | The single highest-value architectural constraint available. Converts F1 (wrong meeting point/time) and F2 (booking never placed) from mandatory-HITL to gate-able | Inside OPP-02 | OPP-02, and any outbound traveller message |
| **P8** | **Crawl access verified** | Binary gate on everything AEO. "Check the current robots configuration before doing anything else in this subsection" (`03-ops-scan.md` §4b.6.3) | Hours | ZE-11 |

> **P2 and P3 are one counsel brief, cost zero eng-weeks, and gate the highest-value D0 area. They are the cheapest unblocking action in this entire file and they are not engineering work.**

---

## 3. GATE 0 — the kill criterion that precedes every D2 and D3 row

| | |
|---|---|
| **Question (Q29)** | **Are Pool B products already listed on GlobalTix or Klook by their own operators?** |
| **Cost to resolve** | **One day of catalogue cross-checking.** Internal. No engineering. |
| **Why it precedes everything** | Exclusivity of Pool B is the sole justification for D2, for D3, for the tier-by-supply-source pricing architecture, and for the "grow Pool B, not total SKU count" conclusion that Steps 2, 4b and 4c reached independently. |
| **Threshold** | If **>30% of Pool B SKUs `[ASSUMPTION — the threshold is a judgement, the test is not]`** are found self-listed on GlobalTix or Klook by their operators, **the B2B thesis fails** and this register must be rebuilt around D0 and D1 only. |
| **Date** | **2026-08-07** — i.e. before any eng-week is committed. |
| **Compounding evidence that raises the urgency** | GlobalTix will sell the same Balinese operator real-time availability, a booking page **and** channel-manager distribution for **USD 100 one-time + 3%** (`02-competitor-matrix.md` §5b.5, Tier A pricing). **The clock on Pool B exclusivity is set by how fast SatuSatu's own supplier digitises the same operators.** |

> **Every D2 and D3 row below is explicitly contingent on GATE 0. Each states it in its Kill criterion.** No D2/D3 row should be funded before 2026-08-07.

---

## 4. 🟢 ZERO-ENGINEERING LANE — contractual, pricing, config and ops-process moves

**Twelve rows. Combined engineering: 3.7 eng-weeks at base.** Every row here is vendor-delivered, configuration-only, contractual, or an ops-process change. The evidence says this lane contains the highest-return actions available to SatuSatu, and the reason is structural: **the constraints stack (no capacity + thin margin + no raise since Nov 2022) rewards interventions against costs and leaks that already exist over anything with a pre-revenue build.**

---

### ZE-01 · The catalog stops steering buyers toward the low-margin pool
| Field | Value |
|---|---|
| **Direction** | D0 / D1 |
| **Value-chain stage** | 12 — Discovery & conversion (with 4 — catalog scale ops) |
| **Customer** | Traveller (benefit lands on SatuSatu's own margin) |
| **Money mechanism** | **(b) take-rate / margin expansion** |
| **Driver metric** | **Pool B share of GBV** (secondary: share of first-screen impressions held by Pool B) |
| **Sizing basis** | **CURRENT** — the defect is live today |
| **Impact (formula)** | `ΔGP/yr = PoolA_GMV × shift × 0.20`<br>· `PoolA_GMV` = $1.95M `[ASSUMPTION — reference volume R, §1b]`<br>· `shift` = 0.05 / **0.10** / 0.20 `[ASSUMPTION ± — share of Pool-A-diverted GMV recovered to Pool B once the false popularity signal is removed]`<br>· `0.20` = net gross-margin delta per unit of GMV diverted `[VERIFIED-derived, 03-ops-scan G12: ~17pts gross / ~20pts net]`<br>→ **$19,500 / $39,000 / $78,000 per year** |
| **Break-even (volume-free)** | Effort 0.3 ew × $679 = **$204**. At $5.00 net margin gain per redirected booking ($25 × 20pts) → **break-even at 41 bookings redirected from Pool A to Pool B, ever.** |
| **Key assumptions** | (1) The inherited count is actually read by a ranking/sort/badge surface — `03-ops-scan.md` §4b.3.2 rec. 2 says "assume it leaked into more places than anyone remembers"; if it is read nowhere, impact is zero and the audit is still worth days. (2) Pool B has a substitute SKU for the diverted demand — untrue for branded parks (USS, Waterbom), true for the long-tail clusters. |
| **Data required** | Inherited `sold_count` field — **Y** `[VERIFIED, Tier A — USS displays "99k+ sold" on the live product]`. Own booking events — **Partial** (exist; depth UNKNOWN, Q6). |
| **Build / Buy / Partner** | **Build (trivial).** One schema split: `supplier_sold_count` (never displayed, never ranked, never a feature) vs `satusatu_bookings`. Plus a surface audit. |
| **Effort** | **0.3 eng-weeks** (hours for the split; days for the audit) |
| **Confidence** | **85%** — the defect is verified live; only the leak *size* is assumed. |
| **Impact / eng-week** | **~$130,000 per eng-week per year** — the highest in the register |
| **Horizon** | **Now** (≤90 days; ≤2 weeks realistically) |
| **Defensibility** | **Low** — anyone can do this. It is not a moat, it is a leak. Included because it is the cheapest margin in the file. |
| **Top risk** | The audit under-finds. Mitigate by grepping for the field name across code, CMS templates and any BI/sort configuration, not by asking who remembers using it. |
| **Latency budget** | Zero — a schema change and a template edit. No model, no added render time. |
| **Failure mode / blast radius** | None material. Worst case: a "popular" module goes empty until own-platform impressions accumulate. Contained to merchandising. |
| **Kill criterion** | If the surface audit finds the inherited field is read by **zero** ranking, sort, badge or module surfaces, close the row after the field split (retain the split — displaying another platform's transaction count as your own is a live trust and advertising-accuracy flag, `03-ops-scan.md` §4b.3.2 point 2). Decide by **2026-08-24**. |
| **Displaces** | 1.5 days of the D2 partner-dashboard build. |

---

### ZE-02 · Ranking encodes the commercial strategy instead of contradicting it
| Field | Value |
|---|---|
| **Direction** | D0 / D1 (and D2 once agent seats exist) |
| **Value-chain stage** | 12 — Discovery & conversion |
| **Customer** | Traveller / partner |
| **Money mechanism** | **(b) take-rate / margin expansion** |
| **Driver metric** | **Pool B share of GBV**, gated by **on-request share of first-screen results** |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `ΔGP/yr = PoolA_GMV × incremental_shift × 0.20`<br>· `incremental_shift` = 0.05 / **0.10** / 0.10 `[ASSUMPTION ±]` — **capped jointly with ZE-01 at a 0.20 total shift**, so the two rows do not sum to nonsense<br>→ **$19,500 / $39,000 / $39,000 per year** |
| **Break-even** | Effort 1.0 ew = **$679** → **136 bookings redirected, ever.** |
| **Key assumptions** | Same substitution assumption as ZE-01. Plus: an explicit business rule is A/B-testable, so the shift is measurable rather than asserted. |
| **Data required** | Pool tag per SKU — **Y**. Margin per SKU — **Partial** (pool-level bands are `[INFERENCE]`; per-SKU actuals are internal and unstated). Confirmation latency per SKU — **N until ZE-09**. |
| **Build / Buy / Partner** | **Build (config).** A weighted business rule, **not a model.** `03-ops-scan.md` §4b.3.2 rec. 3: "It is a config value, it is auditable, it directly encodes the commercial strategy, and it can be A/B tested." |
| **Effort** | **1.0 eng-week** |
| **Confidence** | **70%** — mechanism certain, magnitude assumed. |
| **Impact / eng-week** | **~$39,000 per eng-week per year** |
| **Horizon** | **Now**, but **strictly after ZE-09 (P1)** |
| **Defensibility** | **Low–Med** — the rule is copyable; the *inputs* (which SKU is exclusive, at what real margin) are not. |
| **Top risk** | 🔴 **The one that must not be got wrong: a margin-optimising ranker surfaces on-request Pool B inventory to an agent who is on the phone with a client.** `03-ops-scan.md` §4c.4.2 point 1 is unambiguous — **margin-weighted ranking must be *gated* on confirmation latency, not merely annotated with it.** Any instant-confirm-required query must return only `allotment` / `freesale_capped` / `static_schedule` SKUs. |
| **Latency budget** | Config value evaluated at query time. Must add **0 ms** — no live availability call in the render path (`03-ops-scan.md` §4b.1.2 sub-problem 4: live dual-feed price/availability selection is "a latency and cost problem, not just a logic problem"). |
| **Failure mode / blast radius** | Boosting an on-request SKU into an instant-confirm context → "let me get back to you" → partner-relationship damage. Blast radius is the partner's client, which is worse than SatuSatu's own customer. Contained by the latency gate. |
| **Kill criterion** | A/B test the margin boost for 60 days from T₀. **Kill if** Pool B share of GBV rises **<2 percentage points**, or if **on-request share of first-screen results exceeds 30%** for any instant-confirm-flagged session. Decide by **T₀+60d = 2026-10-16**. |
| **Displaces** | 1 week of the D2 partner-dashboard build. |

---

### ZE-03 · Refund terms stop being more generous than the supplier's
| Field | Value |
|---|---|
| **Direction** | D0 / D1 |
| **Value-chain stage** | 16 — Post-trip / 4 — catalog scale ops |
| **Customer** | Internal (margin protection) |
| **Money mechanism** | **(e) risk / leakage reduction** |
| **Driver metric** | **Refund-mismatch rate** = cancellations refunded above supplier `percentReturn` ÷ total cancellations |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `Δ/yr = PoolA_bookings × cancel_rate × mismatch_rate × mismatch_depth × ATV`<br>· `PoolA_bookings` = 7,800 `[ASSUMPTION — R]`<br>· `cancel_rate` = 0.05 `[ASSUMPTION ± — no TAA cancellation benchmark exists in the collected sources]`<br>· `mismatch_rate` = 0.10 / **0.20** / 0.40 `[ASSUMPTION ±]`<br>· `mismatch_depth` = 0.50 of ticket value `[ASSUMPTION — 03-ops-scan §4b.5.3's worked example]`<br>→ **$488 / $975 / $1,950 per year** |
| **Break-even** | Effort 0.2 ew = **$136** → **11 mismatched cancellations avoided, ever.** Anchor: on a 10% gross margin, one 50-point refund mismatch "wipes out the margin on five clean ones" `[03-ops-scan §4b.5.3]`. |
| **Key assumptions** | That a manually-authored customer-facing policy currently exists alongside the machine-readable feed field. If policies are already rendered from the feed, impact is zero — **one hour to check.** |
| **Data required** | GlobalTix `isCancellable` + `cancellationPolicy {percentReturn, refundDuration}` per ticket — **Y** `[VERIFIED, Tier A — read from the live API]`. |
| **Build / Buy / Partner** | **Build (trivial).** Render the customer-facing policy *from* the feed field; add a Layer-1 gate rule blocking any SKU whose published policy is more generous than `percentReturn`. Same "render, never author" principle as P7. |
| **Effort** | **0.2 eng-weeks** |
| **Confidence** | **75%** |
| **Impact / eng-week** | **~$4,875 per eng-week per year** |
| **Horizon** | **Now** |
| **Defensibility** | **Low** — hygiene. |
| **Top risk** | Rendering a *harsher* policy than customers were previously promised on in-flight bookings. Apply forward-only; grandfather existing bookings. |
| **Latency budget** | Zero. Deterministic field read. |
| **Failure mode / blast radius** | A feed field is wrong → SatuSatu publishes a wrong policy. Bounded by the Layer-1 sanity rule; the supplier's own field is the best available truth. |
| **Kill criterion** | If a one-hour audit shows published policies already derive from `percentReturn` on ≥95% of Pool A SKUs, close the row. Decide by **2026-08-14**. |
| **Displaces** | 1 day of the D2/D3 build. |

---

### ZE-04 · B2B contracts stop carrying an unhedged FX position by default
| Field | Value |
|---|---|
| **Direction** | D2 / D3 |
| **Value-chain stage** | 7 — B2B rate management |
| **Customer** | Partner (exposure lands on SatuSatu) |
| **Money mechanism** | **(e) risk / leakage reduction** |
| **Driver metric** | **% of B2B contracts denominated in IDR**; secondarily **days of unhedged FX exposure per invoice** |
| **Sizing basis** | **TARGET** — B2B volume is zero today |
| **Impact (formula)** | `avoided/yr = B2B_PoolB_GMV × 0.12 × contribution_share_consumed`<br>· `0.12` = B2B retained margin `[INFERENCE, 03-ops-scan §4c.0.3]`<br>· `contribution_share_consumed` = **25% on a 3% adverse move**, 42% on a 5% move `[INFERENCE-derived arithmetic, 03-ops-scan §4c.5.4]`<br>→ at $100,000 of B2B Pool B GMV: **$3,000 avoided per adverse-3% episode.** ⚠️ Episode frequency **unquantified — no IDR/USD volatility measurement was ever collected (flag 4c-G9).** |
| **Break-even** | Effort **0 eng-weeks** (≈4 BD/legal hours = **$32**). Break-even at **$267 of B2B Pool B GMV** on a single 3% move. Immediate. |
| **Key assumptions** | That B2B partners will accept IDR denomination. Indonesian-domiciled agents *must* — see below. Foreign-domiciled (Singapore, Australia, India outbound) may not. |
| **Data required** | None. Contract template only. |
| **Build / Buy / Partner** | **Contractual.** (1) Denominate B2B net rates in **IDR**; (2) for foreign partners retaining USD, add a **stated FX reset threshold** (re-rate if spot moves beyond ~2% `[ASSUMPTION — the threshold is a commercial choice]`); (3) bound quote validity to **24–72h**; (4) prepay wallet (ZE-10) collapses the window from 30 days to zero. |
| **Effort** | **0 eng-weeks** |
| **Confidence** | **90%** on the mechanism; the *episode frequency* is the uncertain part, not the arithmetic. |
| **Impact / eng-week** | **∞ (no engineering consumed)** |
| **Horizon** | **Now — and it must land before the first B2B contract is signed.** Retrofit is renegotiation. |
| **Defensibility** | **Low** as a differentiator; **High** as an avoided loss. |
| **Top risk** | 🔴 **This is also a compliance question, not only a margin one.** **Bank Indonesia Regulation No. 17/3/PBI/2015** obliges Rupiah use in the territory of Indonesia; Standard Chartered's own customer summary states "The Rupiah must be used in all Invoice issuances for domestic payments" `[VERIFIED — Tier A for the regulation, Tier B for the bank/law-firm summaries]`. **Displaying USD to an Indonesian agent is a compliance question, not a UX choice.** Route to counsel with P2/P3. |
| **Latency budget** | n/a |
| **Failure mode / blast radius** | An FX reset clause invoked mid-season reads as a price rise to the partner. Mitigate with a stated, symmetric threshold rather than a discretionary right. |
| **Kill criterion** | Not killable — it is a compliance control. **Gate instead:** if counsel finds PBI 17/3/PBI/2015 does not reach SatuSatu's B2B invoicing, the FX-reset clause survives on margin grounds alone. Counsel answer by **2026-09-15**. |
| **Displaces** | Nothing. Legal/BD time only. |

---

### ZE-05 · The 1.50% supplier FX markup is negotiated away
| Field | Value |
|---|---|
| **Direction** | D0 / D1 |
| **Value-chain stage** | 6 — Pricing / 15 — payments |
| **Customer** | Internal |
| **Money mechanism** | **(b) take-rate / margin expansion** |
| **Driver metric** | **Realised FX markup on Pool A settlement (bps)** |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `Δ/yr = PoolA_GMV × 0.0150 − SatuSatu_own_SGD_spread`<br>· `0.0150` = GlobalTix FX markup on every non-SGD settlement currency, **including IDR**; **SGD carries `markup: 0`** `[VERIFIED, Tier A — read from the live API currency object]`<br>· `PoolA_GMV` = $1.95M `[ASSUMPTION — R]`<br>→ **gross recovery $29,250/yr**, less SatuSatu's own IDR→SGD bank spread `[UNQUANTIFIED — this is the honest gap in the row; the vendor markup is verified, the replacement cost is not]` |
| **Cross-check** | $29,250 is **21.4% of Pool A's net gross profit at R ($136,500)** — which reproduces `03-ops-scan.md` H12's independently derived "~15% of Pool A gross / ~21% of net" almost exactly ✅ |
| **Break-even** | Effort **0 eng-weeks** (≈2 BD hours = **$16**) → break-even at **$1,067 of Pool A GBV.** |
| **Key assumptions** | (1) SGD settlement is contractually available (Q37 — unanswered); (2) SatuSatu's own bank spread on IDR→SGD is materially below 150 bps. **If (2) is false the row returns nothing** and must be closed rather than reported as a win. |
| **Data required** | GlobalTix currency object — **Y** `[VERIFIED, Tier A]`. SatuSatu's own bank FX spread — **Partial/internal, one treasury question.** |
| **Build / Buy / Partner** | **Contractual / commercial.** One account-manager conversation. Ask in the same call about **`directContractPrice`** — a field present in the GlobalTix schema and `null` in the sample, implying a two-tier rate structure in which volume partners get contract rates below marketplace nett `[SPECULATION, flagged — 02-competitor-matrix §5c]`. **The field name gives you the vocabulary to ask in.** |
| **Effort** | **0 eng-weeks** |
| **Confidence** | **60%** — the markup is verified; whether GlobalTix concedes is not. `01-landscape.md` §8.5 warns the counterparty is "a rational, profitable operator with no reason to concede margin to a 253-SKU reseller." |
| **Impact / eng-week** | **∞ (no engineering consumed)** |
| **Horizon** | **Now** |
| **Defensibility** | **Low** |
| **Top risk** | Raising it invites a rate review that goes the wrong way. Mitigate by asking about SGD settlement and `directContractPrice` as a treasury/ops question, not a renegotiation. |
| **Latency budget** | n/a |
| **Failure mode / blast radius** | SGD settlement introduces a new FX leg on SatuSatu's side. Quantify before switching, not after. |
| **Kill criterion** | **Kill if** GlobalTix declines SGD settlement, **or** if SatuSatu's own IDR→SGD spread exceeds **100 bps**, by **2026-09-30**. |
| **Displaces** | Nothing. |

---

### ZE-06 · Pool B content can legally be passed to a distribution partner
| Field | Value |
|---|---|
| **Direction** | D2 / D3 (prerequisite) |
| **Value-chain stage** | 2 — Onboarding & catalog production |
| **Customer** | Supplier / partner |
| **Money mechanism** | **(e) risk / leakage reduction** |
| **Driver metric** | **% of Pool B operator contracts carrying a written, sublicensable, perpetual image-and-content grant** |
| **Sizing basis** | **CURRENT** (the contract template is being used now) |
| **Impact (formula)** | `avoided_retrofit = PoolB_contracts × retrofit_hours × BD_rate`<br>· `PoolB_contracts` ≈ 150–250 `[VERIFIED-derived — 03-ops-scan §4b.4.3 sizes the Pool B classification exercise at ~150–250 SKUs]`<br>· `retrofit_hours` = 1.5 `[ASSUMPTION ±]` · `BD_rate` = $8/h `[INFERENCE, 03-ops-scan §4c.0]`<br>→ **$1,800 – $3,000 of avoided renegotiation labour**, plus a **non-zero refusal rate on retrofit that has no price at all** — a refused grant on an irreplaceable SKU removes that SKU from D2/D3 permanently. **R-independent.** |
| **Break-even** | Effort **0 eng-weeks** (one legal template review). Break-even at **~5 contracts** avoided-retrofit. |
| **Key assumptions** | Default contract drafting grants **no** sublicense — "images shall not be resold, sublicensed, or redistributed" `[VERIFIED as the general licensing default, Tier C; no OTA-specific source exists anywhere — 03-ops-scan §4b.1.5]`. |
| **Data required** | Existing Pool B contract template — **Y, internal.** GlobalTix feed grant terms for Pool A — **N** (open item: one written question). |
| **Build / Buy / Partner** | **Contractual.** (a) Add the grant to the Pool B template **before onboarding accelerates** — retrofitting signed contracts is impossible at scale; (b) ask GlobalTix **in writing** whether the feed grant includes sublicensing to SatuSatu's distribution partners, and record the answer; (c) **do not build any Pool A image-derivative pipeline until (b) returns.** |
| **Effort** | **0 eng-weeks** |
| **Confidence** | **80%** that the gap exists; 100% that closing it is nearly free. |
| **Impact / eng-week** | **∞ (no engineering consumed)** |
| **Horizon** | **Now. This is the most time-sensitive row in the register** — its cost rises with every contract signed. |
| **Defensibility** | **Med** — a sublicensable grant over exclusive supply is a real, contract-backed asset that Pool A can never have. |
| **Top risk** | 🔴 **The D2/D3 platform strategy is itself a sublicensing act.** Passing Pool A images to a white-label or B2B partner is redistribution to a fourth party across a chain at least three links long (operator → GlobalTix → SatuSatu → partner). If the chain does not carry a sublicense right, **the D2/D3 build has a content problem underneath it that no amount of engineering fixes.** |
| **Latency budget** | n/a |
| **Failure mode / blast radius** | Operators refuse the clause and onboarding slows. Mitigate by making the grant non-exclusive to SatuSatu and reciprocal (SatuSatu-produced content licensed back). |
| **Kill criterion** | Not killable — it is a precondition. **Gate:** if by **2026-09-30** GlobalTix confirms **no** sublicensing right on Pool A, then every D2/D3 row must be re-scoped to Pool B content only, and any Pool A content in a partner-facing surface must be removed. |
| **Displaces** | Nothing. |

---

### ZE-07 · Pool B demand from agents is proven or disproven without building anything
| Field | Value |
|---|---|
| **Direction** | **D2** |
| **Value-chain stage** | 8 — Partner onboarding (distribution) |
| **Customer** | Partner (Indonesian travel agent / DMC / villa manager) |
| **Money mechanism** | **(a) GMV lift** |
| **Driver metric** | **Repeat-buying agents** (agents placing ≥2 Pool B bookings in 60 days). *Not* agents contacted, and *not* rate sheets sent. |
| **Sizing basis** | **TARGET** |
| **Impact (formula)** | `contribution/yr = partners × (retained_margin_per_partner − support_per_partner)`<br>· base partner retained margin **$2,400/yr**, D2 support **$784/yr** → **contribution $1,616/yr** `[INFERENCE, 03-ops-scan §4c.1.2 / §4c.2.3]`<br>· modal small partner: **$320 − $174 = $146/yr** `[INFERENCE, same]`<br>→ at 10 base-size partners: **$16,160/yr**; at 24 small partners: **$3,504/yr** |
| **Break-even** | Acquisition cost = 30 agents × 14.5 BD-hours × $8 = **$3,480** `[INFERENCE, 03-ops-scan §4c.1.1 base]` → **break-even at 2.2 base-size partners, or 24 small partners.** Effort **0 eng-weeks.** |
| **Key assumptions** | (1) GATE 0 holds — Pool B is genuinely exclusive; (2) the 353 licensed Bali ASITA members `[VERIFIED, Tier A — asita.id WordPress REST API, X-WP-Total 5,222 nationally, 353 Bali; the 36 category counts sum to exactly 5,222 ✅]` are reachable by direct outreach; (3) minimum viable Pool B catalogue of **~20 / 30–45 / 60 SKUs** covering 10/15/20 Bali demand clusters is already met `[INFERENCE, 03-ops-scan §4c.7.3]`. |
| **Data required** | Pool B rate card at agent net rates — **N, an internal pricing decision (Q31, flag 4c-G2)**. Named agent list — **Y** (public ASITA directory). Own booking mix to rebuild the cluster list — **Y, internal, minutes** (flag 4c-G11). |
| **Build / Buy / Partner** | **Ops process.** Rate sheet / CSV + WhatsApp-or-email request-to-book. **Route 1 of six**, and `03-ops-scan.md` §4c.7.4 notes the two cheapest routes are also the only two that work *natively* with on-request inventory — "it **is** the request-to-book workflow." |
| **Effort** | **0 eng-weeks** |
| **Confidence** | **65%** that the test returns a clean signal; **95%** that it costs nothing to run. |
| **Impact / eng-week** | **∞ (no engineering consumed)** |
| **Horizon** | **Now** |
| **Defensibility** | **Med** — the defensibility is the exclusive supply, not the channel. The channel is deliberately disposable. |
| **Top risk** | 🔴 **`03-ops-scan.md` §4c.7.1: "An agent's platform choice is a workflow decision, not a product decision… a Bali-only 253-SKU supplier is, by construction, an *additional* login."** Therefore **Pool B is a reason to *stock* SatuSatu, not to *integrate* it** — it competes for a line item inside whichever platform the agent already uses. The rate sheet is the correct shape *because* it asks for no workflow change. |
| **Latency budget** | Human — the SLA is the product. Publish it (e.g. 2h in-hours / 12h overnight) and measure it. |
| **Failure mode / blast radius** | An agent quotes a client from a stale rate sheet. Bound with a printed validity date (24–72h for FX-sensitive lines, per ZE-04). |
| **Kill criterion** | 🔴 **The most important kill criterion in the D2 chain.** Run to 20–40 named agents for 90 days from T₀. **Kill D2 entirely if fewer than 3 agents place ≥2 Pool B bookings each by T₀+90d = 2026-11-15.** Rationale, stated in `03-ops-scan.md` §4c.7.5: **"If Pool B does not sell by rate sheet, it will not sell by API — and that answer arrives before any engineering is spent."** |
| **Displaces** | Nothing. BD time only. |

---

### ZE-08 · Pool B listings get produced faster without an engineering project
| Field | Value |
|---|---|
| **Direction** | **D1** |
| **Value-chain stage** | 2 — Onboarding & catalog production |
| **Customer** | Internal (content ops) / supplier |
| **Money mechanism** | **(d) cost-to-serve reduction** |
| **Driver metric** | **Pool B SKUs published per content-ops FTE per week** |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `Δ/yr = SKUs_onboarded × (cost_per_SKU_manual − cost_per_SKU_assisted)`<br>· `cost_per_SKU_manual` = $5 / **$22** / $95 `[INFERENCE, 03-ops-scan S1]`<br>· throughput 9 → 14 SKUs/FTE-week base, i.e. **+55%** `[INFERENCE, S4a→S4b]`, Amdahl-limited because the AI touches only the authoring step<br>· saving ≈ **$8/SKU** at base<br>· `SKUs_onboarded` = 240/yr `[ASSUMPTION — 20/month]`<br>→ **$1,920/yr at base** |
| **Break-even** | Effort **0 eng-weeks**; cost is a team LLM subscription `T`. Break-even = `T ÷ $8` SKUs/month → **at any plausible T under $200/month, fewer than 25 SKUs/month.** |
| **Key assumptions** | The operator has *existing source material* — brochure, WhatsApp price list, Facebook page. This is the GYG pattern: **not generation from nothing, but reformatting and field-extraction from source material the operator already has** `[VERIFIED, Tier A — GYG engineering blog 2025-04-23]`. |
| **Data required** | Operator source material — **Partial** (held by operators, obtained during onboarding conversations). |
| **Build / Buy / Partner** | 🔴 **Buy / ops habit — explicitly NOT a build.** `02-competitor-matrix.md` §7: for a company with no dedicated engineering capacity this is "**not a build; it is at most an off-the-shelf-LLM internal ops habit for producing Pool B listing copy faster.**" |
| **Effort** | **0 eng-weeks** (ops process + a subscription) |
| **Confidence** | **80%** — this is the single best-evidenced AI finding in the whole ops scan: **8 of 16 wizard steps auto-completed, ~60 min → 14 min (~4.3× on the authoring step), rolled out to 100%** `[VERIFIED, Tier A]`. |
| **Impact / eng-week** | **∞ (no engineering consumed)** |
| **Horizon** | **Now** |
| **Defensibility** | **Low** — GYG shipped it publicly and it is a prompt. **Label: table stakes** (see §9). |
| **Top risk** | 🔴 **Copy only the boundary GYG drew.** GYG automated 8 of 16 steps; **the other 8 — price, availability, capacity, cancellation terms, meeting point — were not automated by the company with 200K SKUs and four teams on the problem.** Those are exactly the fields whose errors cause the F1/F2/F7 failure classes. Automating them here would be doing what the best-resourced player in the category declined to do. |
| **Latency budget** | Minutes. Batch, human-in-the-loop, no traveller waiting. |
| **Failure mode / blast radius** | Fabricated inclusions or facilities in listing prose. Contained by (a) restricting input to operator-supplied source text and (b) OPP-D1-2's Layer-1/Layer-2 gate. Also note GYG's own first full experiment **FAILED on UX and trust, not model quality** — for a team with no engineering capacity that is the warning: the model is the easy part. |
| **Kill criterion** | **Kill if** escaped-defect rate on AI-assisted Pool B listings exceeds **2× the rate on manually-authored ones**, measured on a 100-listing sample by **T₀+60d = 2026-10-16**. 🔴 Manage **escaped-defect rate**, never auto-pass rate — auto-pass rises as the gate weakens (Q43). |
| **Displaces** | Nothing. |

---

### ZE-09 · Every Pool B SKU carries a declared availability model *(prerequisite P1)*
| Field | Value |
|---|---|
| **Direction** | D0 / D1 / **D2 / D3** — the gating dependency for the entire B2B strategy |
| **Value-chain stage** | **5 — Inventory & availability** (the stage `00-scope.md` §3 Amendment B identifies as owned by no direction) |
| **Customer** | Supplier / partner / traveller |
| **Money mechanism** | **(d) cost-to-serve reduction** *(chosen over GMV lift deliberately: the GMV effect is real but flows through eight dependent rows, and double-counting it here would inflate the register)* |
| **Driver metric** | **% of Pool B SKUs with a declared `availability_model`**; secondary: **share of Pool B bookings requiring a human confirmation round** |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `Δ/yr = PoolB_bookings × share_moved_off_request × cost_per_confirmation`<br>· `PoolB_bookings` = 4,200 `[ASSUMPTION — R]`<br>· `share_moved_off_request` = 0.30 / **0.50** / 0.70 `[ASSUMPTION ± — the classification outcome is unknowable until the operator conversations happen]`<br>· `cost_per_confirmation` = $0.39 / **$0.65** / $1.64 `[INFERENCE, 03-ops-scan §4c.2.1]`<br>→ **$491 / $1,365 / $4,821 per year direct** |
| **Break-even** | Effort 1.0 ew + ~50 ops hours = $679 + $400 = **$1,079** → **3,320 Pool B bookings** at base. ⚠️ **The direct return is modest and this row must not be justified on it.** |
| **Why it ranks above its own number** | 🔴 It is **P1 for eight other rows** (ZE-02, OPP-02, OPP-03a, OPP-03b, OPP-D2-2, OPP-D2-3, OPP-D2-4, OPP-D3-3) and for reconciliation. Two independent analyses converged on it from opposite directions: `03-ops-scan.md` §4b.4.4 (a B2B partner cannot consume "WhatsApp") and §4a.4 (Pool B cannot be exposed to partner traffic without a confirmation state machine). **"Two different analyses, opposite directions, same single blocking dependency. That convergence is the strongest signal in this document."** |
| **Key assumptions** | Patterns 3–6 (`allotment`, `freesale_capped`, `static_schedule`, `request_to_book`) require the operator to adopt **nothing**. That is why they are the only viable set: **39% of tour operators worldwide run no booking system; 58% of small operators have none; 54% of operators founded after 2022 have none** — the newest cohort is the *least* digitised `[VERIFIED, Tier B via C secondary — Arival GOL]`. |
| **Data required** | Per-operator capacity, schedule, blackout dates and cut-offs — **N. This is the work.** It is internal knowledge nobody outside can supply (open question 4b.8 #4). |
| **Build / Buy / Partner** | **Build (minimal) + ops.** One schema field, four code paths, and a classification exercise across ~150–250 SKUs. **Reject pattern 2 (operator adopts a channel manager) as the primary path** — it is the pattern that fails for the >70%-micro population. |
| **Effort** | **0.5 / 1.0 / 2.0 eng-weeks** + ~30–60 ops hours |
| **Confidence** | **90%** that it is the right work; **60%** on the share of SKUs that can leave `request_to_book`. |
| **Impact / eng-week** | **~$1,365 per eng-week per year direct** — low. **Ranks 8th on the metric and 1st on the dependency chain. §6 flags the conflict rather than hiding it.** |
| **Horizon** | **Now** |
| **Defensibility** | 🔴 **High.** `01-landscape.md` §9 Force 1: real-time availability for Bali's long tail **will not exist by 2028**, and the reason is a property of the supply base, not an implementation gap. "**Klook and Viator will not do manual fulfilment for a 30-guest-a-month waterfall operator either.**" Solving it by *contract and classification* rather than by software is the one genuinely incumbent-proof asset in the model. |
| **Top risk** | Oversell on a `freesale_capped` SKU that should have been `request_to_book`. **The product-level split is the whole discipline:** freesale is correct for private car charter, ATV, spa, most transfers, temple entry; it is **never** correct for dive boats, Nusa Penida crossings, small-group treks, sunrise Batur — fixed-departure products where an oversell is unrecoverable. |
| **Latency budget** | `allotment` / `freesale_capped` / `static_schedule` → instant confirm. `request_to_book` → an **explicitly published SLA**, which is "vastly better than the status quo because it makes the commitment explicit and measurable rather than implicit." |
| **Failure mode / blast radius** | F2 — traveller arrives, operator has no record. Severe and unrecoverable on fixed-departure products. |
| **Kill criterion** | **Kill the freesale path (not the row) if** oversell incidents exceed **0.5% of `freesale_capped` bookings** at n≥200 by **T₀+90d = 2026-11-15**; reclassify those SKUs to `request_to_book`. The schema field itself is not killable — without it there is no B2B strategy. |
| **Displaces** | 1 week of the D2/D3 build. **It is arguably not a displacement at all: it is the cheapest possible form of the availability work the D2/D3 build must otherwise do at far greater cost.** |

---

### ZE-10 · B2B launches without a credit function
| Field | Value |
|---|---|
| **Direction** | **D2** |
| **Value-chain stage** | 7 — B2B rate management / settlement |
| **Customer** | Partner |
| **Money mechanism** | **(d) cost-to-serve reduction** |
| **Driver metric** | **Cost of the AR/credit function as % of B2B contribution** |
| **Sizing basis** | **TARGET** |
| **Impact (formula)** | `avoided/yr = finance_FTE_cost + bad_debt`<br>· finance 0.25/0.35/0.50 FTE = **$2,050 / $3,440 / $6,840** `[INFERENCE, 03-ops-scan §4c.6.2]`<br>· bad debt 0.5% / 1.0% / 3.0% of B2B GMV = **$2,000 / $4,000 / $12,000** at $400,000 B2B GMV `[INFERENCE; flag 4c-G10 — no TAA B2B bad-debt rate exists]`<br>→ **$4,050 / $7,440 / $18,840 avoided per year** |
| **The comparison that settles it** | 🔴 Base-case D3 contribution at 20 partners is **$14,200/yr**. Running the credit function at base cost **consumes 52% of it**; at the high band it **exceeds total contribution by 33%** `[03-ops-scan §4c.6.2]`. |
| **Break-even** | Effort 0 / 0.5 / 1.0 ew (a wallet balance, if one does not already exist) = **$340 at base** → break-even immediately at any B2B volume. |
| **Key assumptions** | That deposits and staged payments are an acceptable substitute. They are **already the documented industry norm** — deposit **20–30%**, balance **21–35 days** pre-travel, net-30 credit for established partners only `[VERIFIED as convention, Tier C but mutually corroborating across independent sources]`. |
| **Data required** | None beyond a wallet balance. |
| **Build / Buy / Partner** | **Config + policy.** Top-up balance, book against balance, no invoice, no AR, no underwriting. |
| **Effort** | **0.5 eng-weeks** |
| **Confidence** | **85%** |
| **Impact / eng-week** | **~$14,880 per eng-week per year** |
| **Horizon** | **Now** |
| **Defensibility** | **Low** — but it removes a whole cost centre before it is built, which is worth more here than a moat. |
| **Top risk** | **Credit terms are a genuine agent purchasing criterion** and rank **2nd of 5** in the (inference-based) driver ranking `[03-ops-scan §4c.7.2]` — above inventory uniqueness. Refusing credit costs real deals. **Mitigate: treat credit as a tier-3 privilege earned by trailing volume, deliberately scarce, priced into the tier — never given away as an onboarding sweetener.** |
| **Latency budget** | n/a |
| **Failure mode / blast radius** | Wallet balance and booking state desynchronise → double-spend. Contained by a single authoritative balance ledger. |
| **Kill criterion** | **Revisit (not kill) if** ≥5 qualified partners cite credit as the sole blocker by **T₀+120d = 2026-12-15**. Then extend credit to those named partners only, priced. |
| **Displaces** | 2–3 days of the D2 build — and removes far more D2 build than it consumes. |

---

### ZE-11 · The catalog becomes machine-readable and retrievable by assistants
| Field | Value |
|---|---|
| **Direction** | **D1 / D3** |
| **Value-chain stage** | 11 — Demand generation / 12 — discovery |
| **Customer** | Traveller (via LLM and search surfaces) |
| **Money mechanism** | **(a) GMV lift** |
| **Driver metric** | **AI-referral sessions and AI-referred bookings** (segmented from organic); secondary: **% of SKUs with valid schema.org product markup** |
| **Sizing basis** | **CURRENT** for the markup; **TARGET** for the traffic |
| **Impact (formula)** | Not sizeable without traffic data — `{{SCALE}}` and clickstream logs are both UNKNOWN (Q6, Q10). **Stated as a break-even instead.**<br>Context that justifies attention its current traffic share would not: **AI-source traffic to US travel sites +194% y/y (May 2026), +2,215% since Oct 2024** `[VERIFIED, Tier B — Adobe Analytics]`; **AI-referred conversion −28% but the gap has narrowed ~70% in 19 months**; AI search is still only **0.5–3% of total site traffic** `[Tier C]`. Set against **Bali arrivals −1.77% Jan–May 2026 while Indonesia is +7.7%** `[VERIFIED, Tier A — BPS]`. |
| **Break-even** | Effort 0.5 ew = **$340** → **194 incremental Pool A bookings, or 57 incremental Pool B bookings, lifetime.** |
| **Key assumptions** | (1) AI crawlers are currently permitted — **must be checked first; it is a binary gate (P8)**; (2) markup is how automated consumers actually ingest catalogs — the strongest available evidence is that the WDC Product Data Corpus exists *because* 79,000 e-shops annotate offers with schema.org and machines harvest it at scale `[VERIFIED, Tier A]`. |
| **Data required** | Catalog fields — **Y**. Robots configuration — **Y, internal, hours**. AI-referral segmentation in analytics — **Unknown (Q10)**. |
| **Build / Buy / Partner** | **Build (config) + commercial.** (1) robots/crawl audit — hours; (2) schema.org markup on all SKUs — days; (3) **unique substantive text on Pool B SKUs only** (AI-drafted per ZE-08); (4) raw-MT breadth (OPP-D1-3); (5) pursue **assistant-callable distribution** commercially. **Do nothing about Pool A prose — it cannot win.** |
| **Effort** | **0.5 eng-weeks** |
| **Confidence** | **70%** on mechanism; **30%** on magnitude. |
| **Impact / eng-week** | **Break-even stated; not sizeable at base without traffic data.** |
| **Horizon** | **Now** for (1)–(3); **Next** for (5) |
| **Defensibility** | **Med on Pool B, Zero on Pool A.** 🔴 The structural reason: **Pool A listings are the same text and images as every other GlobalTix reseller.** Such a page cannot win the attraction's head term, gives an answer engine no reason to cite it over any other copy, and may not be indexed as a distinct document at all. **Pool B is the inverse — SatuSatu may be the only structured source on the open web for a set of long-tail Balinese experiences.** |
| **Top risk** | Building AEO tactics on speculation. **Say plainly what is speculation:** `llms.txt`-style conventions have no evidence of retrieval effect in any collected source; **no assistant publishes its retrieval criteria, so every "AEO tactic" list is inference dressed as method**; and "AI content at scale improves AEO" is unverified and probably *inverted* for non-exclusive inventory — more copies of the same feed text is more duplicate content, not more retrievability. |
| **Latency budget** | n/a (static markup). |
| **Failure mode / blast radius** | Invalid markup → de-indexing rather than promotion. Validate before shipping. |
| **Kill criterion** | **Kill if**, 120 days after markup ships, AI-referral sessions remain below **0.5% of total sessions** *and* AI-referred bookings are zero, by **T₀+120d = 2026-12-15**. Note the honest asymmetry: the incumbent play here is **distribution into the assistant** (Viator shipped as a callable app inside ChatGPT `[VERIFIED, Tier A]`), not prose optimisation — so a null result on markup does not kill (5). |
| **Displaces** | 2–3 days of the D1 catalog work. |

---

### ZE-12 · Search stops returning nothing for words customers actually use
| Field | Value |
|---|---|
| **Direction** | D0 / D1 |
| **Value-chain stage** | 12 — Discovery & conversion |
| **Customer** | Traveller |
| **Money mechanism** | **(a) GMV lift** |
| **Driver metric** | **Zero-result rate on non-junk queries** (act above 10%); secondary **null-click rate** (act above 40%) |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `Δ/yr = sessions × zero_result_rate × recovery_rate × conversion × contribution` — **not computable: session volume and search logs are UNKNOWN (Q6, Q10).** Stated as break-even. |
| **Break-even** | Effort 0.2 ew = **$136** → **78 recovered Pool A bookings, or 23 recovered Pool B bookings, lifetime.** |
| **Key assumptions** | At 253 SKUs the dominant search failure is **zero results / vocabulary mismatch** — "quad bike" vs a listing titled "ATV Ride"; "monkey forest" vs "Ubud sacred sanctuary" — not ranking `[INFERENCE, 03-ops-scan §4b.3.1]`. |
| **Data required** | Query logs — **Unknown (Q10). If they do not exist, adding them *is* the first deliverable of this row.** |
| **Build / Buy / Partner** | **Ops / content.** A synonym-and-alias dictionary (English / Indonesian / Chinese variants), query logging with a **weekly zero-result review**, curated collections, facets. **All content-ops work at $0.079/minute, not engineering.** |
| **Effort** | **0.2 eng-weeks** (query logging) + recurring ops hours |
| **Confidence** | **75%** |
| **Impact / eng-week** | **Break-even stated; not sizeable without search logs.** |
| **Horizon** | **Now** |
| **Defensibility** | **Low** |
| **Top risk** | Doing embeddings instead. 🔴 **"Embedding retrieval on 253 SKUs solves a problem the catalog does not have yet, while the zero-result log goes unread."** Semantic search pays at **~2,000 SKUs (band 1,200–4,000)** `[INFERENCE, 03-ops-scan G7]` — see §7 U4. |
| **Latency budget** | Dictionary lookup, sub-millisecond. |
| **Failure mode / blast radius** | Over-broad synonyms return irrelevant results. Bounded, reversible, per-term. |
| **Kill criterion** | **Kill if** after 60 days of weekly review the zero-result rate on non-junk queries is already **<5%**, by **T₀+60d = 2026-10-16** — the catalog does not have this problem and the ops time should move elsewhere. |
| **Displaces** | 1 day of the D1 catalog work. |

---

## 5. ENGINEERING-BEARING CANDIDATES

Twelve rows. **Combined effort 20.0 eng-weeks at base — more than three times the assumed displacement budget.** §6 draws the line.

---

### OPP-01 · The concierge produces a day plan in a third of the time
| Field | Value |
|---|---|
| **Direction** | **D0** |
| **Value-chain stage** | 13 — Itinerary planning |
| **Customer** | Traveller (Pass buyer) |
| **Money mechanism** | **(d) cost-to-serve reduction** |
| **Driver metric** | **Concierge minutes per pass on itinerary build** (task 2 of 9) |
| **Sizing basis** | **CURRENT** — the cost exists today |
| **Impact (formula)** | `Δ/yr = passes × task2_minutes × compression × cost_per_minute − inference_cost`<br>· `passes` = 2,400/yr `[ASSUMPTION — R]`<br>· `task2_minutes` = 10 / **25** / 60 `[INFERENCE, 03-ops-scan §4a.1.2 — the entire minutes column is INFERENCE; "Replace them; do not cite them"]`<br>· `compression` = 0.20 / **0.30** / 0.40 `[INFERENCE, 03-ops-scan §4c.2.3 assist band]`<br>· `cost_per_minute` = $0.048 / **$0.079** / $0.138 `[INFERENCE, L14]`<br>→ gross **$1,422/yr at base**, before inference cost |
| **Inference-cost test** | 🔴 **Break-even inference cost = $0.59 per pass** (7.5 min × $0.079) at base labour; **$0.36 at low labour.** **A metered vendor at $0.99/resolution fails this test outright.** The row is only viable on a self-managed API call whose price is **NOT FOUND in any collected source (C10)** — so it must be priced before funding, not after. |
| **Break-even (volume-free)** | Effort 4 ew = **$2,716** → **4,603 passes at base** (at zero inference cost — optimistic). At the low-minutes case (10 min, 20% compression = $0.16/pass) break-even is **16,975 passes.** |
| **Key assumptions** | That itinerary build is genuinely 25 minutes per pass. It is the single most load-bearing unknown in D0 (Q8) and **one week of queue data closes it.** |
| **Data required** | Concierge minutes per pass — **N (Q8)**. Pass inclusion list + entitlement rules — **Y**. WhatsApp transcripts for few-shot grounding — **Unknown (Q9)**. |
| **Build / Buy / Partner** | **Build (light) on a bought model.** Retrieval over 253 SKUs is small; the work is the review surface and the entitlement gate. |
| **Effort** | **2 / 4 / 8 eng-weeks** |
| **Confidence** | **45%** — the mechanism is sound; the denominator is unknown and the inference price is unknown. |
| **Impact / eng-week** | **~$356 per eng-week per year** — 🔴 **the worst of the D0 set.** The flagship "AI concierge" idea ranks last among D0 candidates, and the reason is `03-ops-scan.md` §4a.5.5: **the human baseline is $0.079/minute, not the $6–13.50/contact US/EU baseline every vendor business case assumes.** |
| **Horizon** | **Next** (not Now — 4 eng-weeks is not a near-zero-engineering intervention) |
| **Defensibility** | **Low–Med.** The model is commodity. What is not commodity is the **Pool B operator relationships and the local judgement encoded in the templates** — which argues for OPP-02's template library over this row. |
| **Top risk** | 🔴 The Pass is marketed as *"access to a real Bali local who plans your days."* **P3 (liability/representation) must clear first:** substituting a model for the advertised person may create a gap between what was sold and what was delivered, *distinct from and additional to* whether the instruction was correct. And `03-ops-scan.md` §4a.2.5: **64% of customers say they would prefer companies did not use AI for customer service; 89% believe a human option should always exist.** Here the human is not the fallback — **the human is the advertised product.** |
| **Latency budget** | Pre-trip. **Minutes acceptable.** No traveller waiting in-destination. This is what makes it the *safe* side of the mutation boundary. |
| **Failure mode / blast radius** | **F3 transport sequencing — the highest blast radius per single error in the whole decomposition.** One impossible leg (Ubud 10:00 → Uluwatu 12:30) invalidates every downstream booking that day. **Human sign-off is mandatory and non-negotiable**, which also caps the achievable compression: a human reads every plan regardless. |
| **Prerequisites** | P2, P3, P4, P5. Not P1. |
| **Kill criterion** | Pilot pre-trip scope only, 100% QA. **Kill if IDIER > 0.5% at n ≥ 400 audited instructions**, or if measured compression is **<15%** of itinerary-build minutes, by **T₀+90d = 2026-11-15**. The 0.5% threshold is derived, not rounded: `kill when IDIER × cost_per_stranding > minutes_saved × cost_per_minute`; at $600/stranding `[ASSUMPTION — unverified, open question 4a.8 #8]` and 40 minutes saved, break-even IDIER is 0.53%. **Re-derive it the moment a real stranding cost exists.** |
| **Displaces** | 4 weeks of the D2/D3 platform build — **two-thirds of the entire assumed displacement budget for one row.** |

---

### OPP-02 · Day-of messages are rendered from a confirmed record, never written by a model
| Field | Value |
|---|---|
| **Direction** | **D0** (and reusable by D1 self-serve and D2 partners) |
| **Value-chain stage** | 14 — In-destination |
| **Customer** | Traveller |
| **Money mechanism** | **(d) cost-to-serve reduction** |
| **Driver metric** | **Concierge minutes per pass on day-of coordination** (task 5) |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `Δ/yr = passes × task5_minutes × automatable_share × cost_per_minute`<br>· `task5_minutes` = 6 / **18** / 45 `[INFERENCE, 03-ops-scan §4a.1.2]`<br>· `automatable_share` = 0.50 / **0.55** / 0.70 `[ASSUMPTION ± — the template-renderable fraction]`<br>→ **$228 / $1,896 / $9,782 per year** |
| **Inference-cost test** | 🔴 **Zero marginal inference cost in the send path.** The model (if used at all) only *selects* a template; slot values come from the confirmed booking record. A rules-based selector removes the model entirely. **This is the only D0 row that passes the inference screen unconditionally, on either pool.** |
| **Break-even** | Effort 2 ew = **$1,358** → **1,719 passes at base.** |
| **Key assumptions** | A confirmed booking record exists to render from. **For Pool B it does not today (H14: zero reconcilability) — hence the hard dependency on ZE-09.** |
| **Data required** | Confirmed booking record with meeting point, time, pickup window — **Partial for Pool A (Y, via GlobalTix), N for Pool B until ZE-09.** |
| **Build / Buy / Partner** | **Build (light).** A template library + slot mapping + a scheduler. |
| **Effort** | **1 / 2 / 4 eng-weeks** |
| **Confidence** | **75%** |
| **Impact / eng-week** | **~$948 per eng-week per year** — and it is the row whose *risk* reduction most exceeds its cost saving. |
| **Horizon** | **Next** (Now if scoped to Pool A only, ~1 eng-week) |
| **Defensibility** | **Med.** The template library encodes local operational knowledge (which meeting points confuse people, which pickup windows Bali traffic breaks) that a competitor cannot copy from the outside. |
| **Top risk** | Someone "improves" it later by letting the model author prose. **The whole value is the constraint.** Write it into the design doc: **generated in-destination prose is prohibited.** |
| **Latency budget** | Scheduler-driven, sub-second render. Must fire on a clock, not on a request. |
| **Failure mode / blast radius** | 🔴 F1 (wrong meeting point/time/date). **For dawn products — Mount Batur sunrise trek, early temple visits — there is no slack; the sunrise does not wait.** But rendering collapses the failure surface to *slot selection*, which is testable, enumerable and gate-able — which is exactly why `03-ops-scan.md` §4a.3.3 calls this "**the single highest-value constraint in this section.**" |
| **Prerequisites** | **P1 (ZE-09)**, P5, P7. P2/P3 needed only if a model does the selecting. |
| **Kill criterion** | **Kill if** slot-selection error rate exceeds **0.2%** at n ≥ 400 rendered messages, or if any dawn-product message is mis-slotted at all, by **T₀+60d = 2026-10-16**. |
| **Displaces** | 2 weeks of the D2/D3 build. |

---

### OPP-03a · No Pool B booking sits silently unconfirmed
| Field | Value |
|---|---|
| **Direction** | **D0** (prerequisite for D2/D3 volume) |
| **Value-chain stage** | 5 — Availability / 18 — supplier ops |
| **Customer** | Traveller / supplier |
| **Money mechanism** | **(e) risk / leakage reduction** |
| **Driver metric** | **Silent-unconfirmed rate** = Pool B bookings with no operator acknowledgement at T-minus-24h ÷ Pool B bookings |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `avoided/yr = PoolB_bookings × silent_rate × strand_conversion × cost_per_stranding`<br>· `PoolB_bookings` = 4,200 `[ASSUMPTION — R]`<br>· `silent_rate` = 0.005 / **0.01** / 0.03 `[ASSUMPTION ± — no TAA benchmark exists; H7 records that no published TAA no-show rate exists at all]`<br>· `strand_conversion` = 0.20 `[ASSUMPTION ±]`<br>· `cost_per_stranding` = **$600** `[ASSUMPTION — unverified; bounded below by the Pass refund of $59.95–$144.95 and realistically several multiples once re-accommodation, goodwill and a public review are included]`<br>→ **$2,520 / $5,040 / $15,120 per year** |
| **Inference-cost test** | 🔴 **Passes trivially — there is no model.** `03-ops-scan.md` §4b.4.5 is blunt: "**Do this first. And note honestly: it is a scheduler plus a message template. It barely needs AI at all.**" |
| **Break-even** | Effort 1 ew = **$679** → **1.13 strandings avoided per year.** |
| **Key assumptions** | That silent-unconfirmed bookings occur at all today. Pool B is **unreconcilable by construction** — "you cannot reconcile against a WhatsApp thread" — so the current rate is not merely unmeasured, it is **unmeasurable**. That is itself the argument. |
| **Data required** | Booking record with a confirmation state — **N until ZE-09.** Operator WhatsApp number per SKU — **Y.** |
| **Build / Buy / Partner** | **Build (trivial).** Scheduled follow-ups to the operator until a confirmation state is reached, escalating to a human at T-minus-X. |
| **Effort** | **0.5 / 1.0 / 2.0 eng-weeks** |
| **Confidence** | **80%** on mechanism; the stranding cost is the weak input and it is flagged. |
| **Impact / eng-week** | **~$5,040 per eng-week per year** — 🔴 **the best of the engineering-bearing rows.** |
| **Horizon** | **Now** (immediately after ZE-09) |
| **Defensibility** | **Med** — it is the operational discipline that makes a request-to-book SLA credible, and the SLA is what `01-landscape.md` §10.3 says to "market as the product." |
| **Top risk** | Operator fatigue. A micro-operator chased four times a day stops replying. Cap chase frequency and escalate to a human, not to another message. |
| **Latency budget** | Asynchronous. Hours acceptable, bounded by the published SLA. |
| **Failure mode / blast radius** | **F2 — booking never placed.** Concentrated entirely in Pool B, and **unrecoverable on fixed-departure products** (dive boats, Nusa Penida crossings, fixed-seat treks). This row attacks the highest-severity Pool B failure directly. |
| **Prerequisites** | **P1 (ZE-09)**, P5. No P2/P3 — the messages go to operators, not travellers, and are templated. |
| **Kill criterion** | **Kill if** the silent-unconfirmed rate measured after ZE-09 is already **<0.2%** at n ≥ 500 Pool B bookings, by **T₀+60d = 2026-10-16** — the problem does not exist and the eng-week goes elsewhere. |
| **Displaces** | 1 week of the D2/D3 build. |

---

### OPP-03b · Operator replies become a booking state without a human reading them
| Field | Value |
|---|---|
| **Direction** | **D0 / D2** |
| **Value-chain stage** | 5 — Availability / 18 — supplier ops |
| **Customer** | Internal / supplier |
| **Money mechanism** | **(d) cost-to-serve reduction** |
| **Driver metric** | **Agent minutes per Pool B confirmation round** |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `Δ/yr = PoolB_bookings × cost_per_confirmation × compression`<br>· `cost_per_confirmation` = $0.39 / **$0.65** / $1.64 `[INFERENCE, 03-ops-scan §4c.2.1; flag 4c-G5 — minutes per confirmation is unverified and measurable internally in a week]`<br>· `compression` = 0.20 / **0.30** / 0.40 `[INFERENCE, §4c.2.3 assist band]`<br>→ **$328 / $819 / $2,755 per year** |
| **Inference-cost test** | 🔴 **Break-even inference cost = $0.20 per confirmation** ($0.65 × 0.30). **A metered vendor at $0.50–0.99/resolution fails by 2.5–5×.** Viable only as a single cheap classification call — and the price is **NOT FOUND (C10)**. |
| **Break-even** | Effort 2 ew = **$1,358** → **6,790 Pool B confirmations at base.** |
| **Key assumptions** | Extraction accuracy in **real Bali conditions** — Indonesian/English code-switching, voice notes, photos of handwritten notes, "ok" meaning three different things — is **60% / 75% / 88%**, materially below the 85/92/97% achievable on clean single-language text `[INFERENCE, G15/G16]`. |
| **Data required** | Historical operator WhatsApp threads for evaluation — **Unknown (Q9). If not retained, this row starts with a data-collection project and its effort estimate is wrong.** |
| **Build / Buy / Partner** | **Build (light) on a bought model.** Output is a **state transition on a record that already exists**, not free text sent to a traveller — which is what makes it correctly bounded. |
| **Effort** | **1 / 2 / 4 eng-weeks** |
| **Confidence** | **50%** — accuracy band is wide, the data may not exist, and the labour arbitrage makes the payback long. |
| **Impact / eng-week** | **~$410 per eng-week per year** |
| **Horizon** | **Next** |
| **Defensibility** | **Low–Med** |
| **Top risk** | 🔴 **The design rule that makes it safe: bias precision on `confirmed`, never on `unconfirmed`. A false `confirmed` strands a traveller; a false `unconfirmed` costs one chase message. The asymmetry is ~100:1 and the threshold must reflect that, not a balanced F1.** Target **≥99% precision on auto-confirm**, accepting whatever recall that leaves — plausibly only 50–70% automated. |
| **Latency budget** | Seconds to minutes, asynchronous. |
| **Failure mode / blast radius** | F2 via false auto-confirm. Severe. Mitigated by construction (precision threshold), not by review. |
| **Prerequisites** | **P1 (ZE-09)**, **P2 (operator content is third-party PII too)**, P4, P5. |
| **Kill criterion** | **Kill if** auto-confirm precision is **<99%** at n ≥ 300 labelled real Bali replies, **or** if the automated share is **<40%** at that precision, by **T₀+90d = 2026-11-15**. |
| **Displaces** | 2 weeks of the D2/D3 build. |

---

### OPP-04 · Pre-purchase enquiries get answered in one minute, in any language, at any hour
| Field | Value |
|---|---|
| **Direction** | **D0 / D1** |
| **Value-chain stage** | 12 — Discovery & conversion / 17 — customer service |
| **Customer** | Traveller (pre-purchase) |
| **Money mechanism** | **(a) GMV lift** — deliberately **not** (d). The cost case is negative (below); the coverage case is not. |
| **Driver metric** | **First-response time on pre-purchase enquiries**, and **enquiry→booking conversion** |
| **Sizing basis** | **CURRENT** |
| **Impact (formula)** | `Δ/yr = enquiries × incremental_conversion × contribution − enquiries × price_per_resolution`<br>Sizing is **not possible** — enquiry volume is UNKNOWN (Q6/Q7). **Stated as the required conversion instead**, which is the honest form. |
| **Inference-cost test — this is the whole row** | 🔴 At **$0.99/resolution** `[VERIFIED as vendor pricing, Tier C]`, the AI must produce **1 incremental booking per 1.77 resolutions on Pool A (a 57% incremental conversion rate — implausible)**, or **1 per 6.8 resolutions on Pool B gross (15% — arguable)**. **Conclusion: vendor AI customer service clears only if it is pointed at Pool B enquiries. Pointed at Pool A it is value-destroying at every published price.** |
| **Break-even** | **15% incremental enquiry→booking conversion on Pool B enquiries at $0.99/resolution**; 7.4% at $0.50; **44% at $3.00 (fails).** |
| **Key assumptions** | That the justification is coverage, latency and language — **not cost.** `03-ops-scan.md` §4a.5.5: "Any model that shows AI saving money on cost-per-contact against Indonesian labour has the wrong baseline in it." Supporting anchors: Klarna 11 min → **under 2 min** and **35+ languages at zero marginal cost** `[VERIFIED, Tier A]`; Canary/LINE SF median response **10 min → under 1 min** `[Tier C]`; Elite Havens draws guests from **110+ countries** and routes its concierge **by source market, not by destination** `[VERIFIED, Tier A]`. |
| **Data required** | Knowledge base / catalog content — **Y**. Enquiry volume and current AHT — **N (Q7)**. Transcripts for tuning — **Unknown (Q9)**. |
| **Build / Buy / Partner** | 🔴 **Buy — configuration only, zero engineering, if and only if P2 clears.** If traveller content may **not** leave the tenancy, the vendor route closes at the egress point and three of the four fallbacks fail the capacity constraint outright (self-hosting fails; restricting to non-PII surfaces is "technically viable, commercially thin"; redaction consumes engineering that does not exist). **The only branch that preserves a ≤90-day path is in-region hosted inference, whose availability and price are UNVERIFIED.** |
| **Effort** | **0 eng-weeks** (config) — but a **per-resolution meter forever** |
| **Confidence** | **40%** — the coverage benefit is real, the conversion uplift is unmeasured, and the vendor meter is a structural risk. |
| **Impact / eng-week** | **∞ on effort; contingent on P2 and on being pointed at Pool B.** |
| **Horizon** | **Now** if P2 clears; **otherwise not at all** on this architecture |
| **Defensibility** | 🔴 **Zero. Label: table stakes** (see §9). Antavaya already publishes a *named* WhatsApp concierge ("AMY", +62817 768 838) on its homepage; Golden Rama runs a WhatsApp widget. **Any D0 defensibility claim resting on "we serve on WhatsApp" is unsupported.** |
| **Top risk** | 🔴 **Vendor lock-in on a meter whose definition of "resolution" the vendor controls.** The measurement defects are documented and both inflate in the same direction: Intercom's own support engineer confirms "a resolution is counted if the customer clicks 'that helped' **or does not respond to the answer and leaves the conversation**"; one customer reports **confirmed resolution 6–7% against assumed resolution ~60%**. **Negotiate the definition into the contract, or the meter and the value diverge.** Across every vendor in the set, **claimed exceeds measured by 16–40 points, systematically and in one direction** — plan on **claimed − 25 points.** |
| **Latency budget** | Target **<60s first response**. This is the entire product benefit; if it is not met the row has no case at all. |
| **Failure mode / blast radius** | **F8 silent abandonment — and it is counted as a *success* by the industry-standard metric.** "A traveller who goes silent after a bad in-destination instruction is not a resolved ticket. They are a person walking toward the wrong temple." **Scope this row to pre-purchase only.** No in-destination automation ships on it. |
| **Prerequisites** | **P2 (hard gate)**, P5. |
| **Kill criterion** | 🔴 **Never gate on deflection.** Gate on four measured together, any one breaching triggers Hold: **72h re-contact ≤1.5× human baseline** (industry 11.3% AI vs 8.7% human = 1.30×); **confirmed — not assumed — resolution ≥30% by day 60**; **escalation rate ≥20% as a FLOOR, not a ceiling** (an escalation rate that is too low is the alarm — it means the model is not handing off risk); **Pass-buyer CSAT no decline beyond noise.** Gate 1 at **T₀+60d = 2026-10-16**, hard kill/scale at **T₀+90d = 2026-11-15**. |
| **Displaces** | Nothing in engineering. Displaces **procurement and legal attention**, which are also finite. |

---

### OPP-D1-2 · Bad SKUs are stopped at ingest instead of by customers
| Field | Value |
|---|---|
| **Direction** | **D1** |
| **Value-chain stage** | 3 — Feed ingestion / 4 — catalog scale ops |
| **Customer** | Internal / traveller |
| **Money mechanism** | **(e) risk / leakage reduction** |
| **Driver metric** | 🔴 **Escaped-defect rate** = defects found after publish ÷ SKUs published. **Explicitly NOT auto-pass rate** — auto-pass and gate strength move in opposite directions, and a 95% auto-pass rate is evidence of a weak gate as readily as a clean pipeline (Q43). |
| **Sizing basis** | **CURRENT** for Pool A maintenance; **TARGET** for D1 volume |
| **Impact (formula)** | `Δ/yr = SKUs_ingested × defect_incidence × contacts_per_defect × contact_minutes × cost_per_minute + [UNSIZED mispricing leg]`<br>· `SKUs_ingested` = 2,000/yr `[ASSUMPTION — a D1 ramp; there is no SKU roadmap (Q3)]`<br>· `defect_incidence` = 10% / **25%** / 45% `[INFERENCE, 03-ops-scan S7 — decomposed as dead 3/8/18 + mispriced 2/6/14 + duplicated 0/5/15 + season-expired 2/5/12 + content-unsellable 3/8/16, de-overlapped; 🔴 no incidence data is published anywhere]`<br>· `contacts_per_defect` = 1 / **2** / 5 `[ASSUMPTION ±]` · `contact_minutes` = 10 `[ASSUMPTION ±]`<br>→ **$158 / $790 / $6,986 per year on the support leg alone.** ⚠️ **The mispricing leg (2/6/14% of SKUs) is almost certainly the dominant term and it cannot be sized without knowing what a mispriced SKU sells for. Stated as unsized rather than guessed.** |
| **Inference-cost test** | 🔴 **Passes unconditionally — Layers 1 and 2 use no model.** Layer 3 (semantic/editorial) is explicitly **not** funded: no source in this research measures LLM-as-judge accuracy on travel listing copy. Staff Layer 3 with humans on a sample basis. |
| **Break-even** | Effort 1.5 ew = **$1,019** → **1,290 defect-contacts avoided.** At 500 bad SKUs on a 2,000-SKU ramp and 1–5 contacts each, that is **500–2,500 contacts** — so the row breaks even in the base-to-high range and is **marginal at the low end on the support leg alone.** It is the mispricing leg that carries it. |
| **Key assumptions** | The one verified anchor is worse than any band above: **the displayed sold-count on Pool A SKUs is 100% inherited feed data — a 100% defect rate on one live, customer-visible field across the entire Pool A catalog** `[VERIFIED, Tier A]`. Anchor planning on that observation, not on an optimistic prior. |
| **Data required** | Feed fields (price, currency, geo, dates, media, `isCancellable`, `cancellationPolicy`) — **Y** `[VERIFIED, Tier A]`. Category price medians for outlier detection — **Y, derivable.** |
| **Build / Buy / Partner** | **Build (rules).** Layer 1 deterministic/structural, 100% blocking: required-field completeness, price sanity (zero/negative/absent currency/order-of-magnitude outlier/**IDR-USD unit confusion, a live risk in a dual-currency catalog**), currency-FX consistency, geo validity, date/season validity, media technical fitness, duplicate content hash, **cancellation-policy derivation from the feed field**, and **every SKU must declare an `availability_model` or it does not publish.** Layer 2 cross-field consistency: description contradicts structured fields, inclusions contradict price tier, text asserts hotel pickup with no transfer option. |
| **Effort** | **1 / 1.5 / 3 eng-weeks** |
| **Confidence** | **70%** |
| **Impact / eng-week** | **~$527 per eng-week per year on the sized leg** — understated, and honestly so. |
| **Horizon** | **Next**; scope Layer 1 only to make it **Now** at ~1 eng-week |
| **Defensibility** | **Low** as a feature; **High as a precondition.** "A 4.3× faster pipeline with no gate is a 4.3× faster defect pipeline." |
| **Top risk** | Being deferred because D1 volume has not arrived yet. The gate must precede the volume, or the volume arrives as defects on the highest-traffic pages: **a "2,500-SKU catalog" ingested in bulk is realistically ~1,900 sellable, and the 600 bad ones are distributed across page 1, not page 4.** |
| **Latency budget** | Ingest-time, batch. No render-path impact. 🔴 **The design point that saves the most money: put the gate at *ingest*, not at *publish-review*.** A Layer-1 catch costs zero human minutes; a reviewer catch costs 2–10 minutes; a traveller catch costs concierge minutes plus a possible stranding. |
| **Failure mode / blast radius** | An over-strict rule blocks good SKUs. Bounded — the queue is visible and the rule is tunable per check. |
| **Prerequisites** | P5 (escaped-defect instrumentation), **and it implements part of P1** (the `availability_model`-declared check). |
| **Kill criterion** | **Kill if** escaped-defect rate on gated SKUs is not at least **50% below** the ungated baseline at n ≥ 300 published SKUs, by **T₀+90d = 2026-11-15**. |
| **Displaces** | 1.5 weeks of the D1/D2 build. |

---

### OPP-D1-3 · The catalog is retrievable in the languages Bali's arrivals actually speak
| Field | Value |
|---|---|
| **Direction** | **D1** |
| **Value-chain stage** | 4 — Catalog scale ops / 11 — demand generation |
| **Customer** | Traveller |
| **Money mechanism** | **(a) GMV lift** |
| **Driver metric** | **Indexed SKU-pages per language**, then **non-English organic + AI-referral sessions** |
| **Sizing basis** | **CURRENT** (253 SKUs exist now) |
| **Impact (formula)** | Traffic effect not sizeable (Q6/Q10 unknown). **Cost side is fully sized and it is the finding:**<br>· raw LLM MT: **$0.0003 / $0.0005 / $0.009 per SKU per language** `[INFERENCE from VERIFIED Tier C per-million-word rates]`<br>· 253 SKUs × 4 languages ≈ **$0.51 of inference, total**<br>· post-edited by an Indonesia-based FTE: **$0.24 / $0.63 / $2.76 per SKU per language**<br>· post-edited at **Western MTPE rates: $10 / $32 / $84** — **a ~50× difference for the same work** |
| **Inference-cost test** | 🔴 **Passes by four orders of magnitude.** "**The gap between raw MT and post-edited MT is four to five orders of magnitude. The entire cost of multilingual is the human, not the model.**" A 2,500-SKU catalog in 4 extra languages is **~$5 of inference or ~$320,000 of Western post-editing.** |
| **Break-even** | Effort 1 ew = **$679** → **388 incremental Pool A bookings, or 113 incremental Pool B bookings, lifetime.** |
| **Key assumptions** | Which languages: Bali's FY2025 top markets are **Australia 23.44%, India 8.19%, China 7.73%, South Korea 4.99%, UK 4.57%, France 4.02%, US 3.95%, Japan 3.00%** `[VERIFIED, Tier A — BPS Bali]`. English-first addresses **39.0% of March 2026 arrivals**; **India and China are the next two and are addressed by neither the language nor the USD currency.** |
| **Data required** | Source listings — **Y**. Locale routing / hreflang — **Partial.** |
| **Build / Buy / Partner** | **Buy the model, build the pipeline.** **Sequencing rule: raw-MT everything for retrievability; human post-edit only the fields where an error strands or misprices a traveller** — meeting point, inclusions/exclusions, cancellation terms, safety notes. "**That is ~15% of the words and ~90% of the risk.**" |
| **Effort** | **0.5 / 1 / 2 eng-weeks** |
| **Confidence** | **60%** on mechanism; **25%** on magnitude. |
| **Impact / eng-week** | **Break-even stated; traffic not sizeable.** |
| **Horizon** | **Next** |
| **Defensibility** | **Low on Pool A** (duplicate feed text in five languages is still duplicate text). **Med on Pool B.** |
| **Top risk** | Machine-translating the risk fields. A mistranslated meeting point or cancellation term is an F1/F7 event in a language nobody on the team reads. **Gate the 15% and accept raw MT on the rest.** |
| **Latency budget** | Batch, offline. |
| **Failure mode / blast radius** | Wrong-language or garbled pages get indexed, damaging trust. Use **COMET ≥0.85 as the professional reference, ≥0.90 as near-human** `[Tier C]` and sample-audit. |
| **Prerequisites** | P8 (crawl access), P4. |
| **Kill criterion** | **Kill if** non-English sessions remain below **3% of total** 120 days after launch, by **T₀+120d = 2026-12-15**. |
| **Displaces** | 1 week of the D1 catalog work. |

---

### OPP-D1-4 · The second aggregator is contracted so that deduplication never becomes a project
| Field | Value |
|---|---|
| **Direction** | **D1** |
| **Value-chain stage** | 3 — Feed ingestion |
| **Customer** | Internal |
| **Money mechanism** | **(d) cost-to-serve reduction** — expressed in the currency that actually binds |
| **Driver metric** | **Overlapping SKUs between feed 1 and feed 2** (target: zero) |
| **Sizing basis** | **TARGET** |
| **Impact (formula)** | `avoided = second_feed_proper − second_feed_MVP`<br>· proper (auth + delta + canonical model + option-level mapping + dedup + review-queue UI + taxonomy crosswalk + dual settlement) = **11 / 20 / 37 eng-weeks** `[INFERENCE, 03-ops-scan S2c]`<br>· minimum viable (bounded subset, single-source-of-truth per attraction, no live price arbitration) = **3 / 5 / 8 eng-weeks**<br>→ **8 / 15 / 29 eng-weeks avoided = $5,432 / $10,185 / $19,691 at base eng-week cost.** 🔴 **R-independent.** |
| **Inference-cost test** | n/a — no model. The row's entire point is that **the dedup problem is created by a commercial decision and is therefore deletable by a commercial decision.** |
| **Break-even** | Effort **0 eng-weeks** (a contracting decision). Break-even at **any positive overlap avoided.** |
| **Key assumptions** | That a second aggregator will accept a non-overlapping scope. Note the tension honestly: **the overlap concentrates precisely on the SKUs SatuSatu most wants — USS, Singapore Oceanarium, River Wonders, Waterbom Bali, GWK, Taman Safari — and "a second aggregator that did *not* overlap on those would have no commercial value."** So the real form of this row is **non-overlapping *territory*** (non-Bali Indonesia, or Singapore where GlobalTix is strongest and a second feed adds least), not non-overlapping product. |
| **Data required** | Feed-2 catalog list vs GlobalTix's — **N, obtainable commercially.** Whether the two feeds share **any** venue identifier — **N, "one afternoon to check" (Q34); if yes, an exact-identifier join at 0.99 precision solves the head of the catalog outright.** |
| **Build / Buy / Partner** | **Contractual.** Ranked alternatives if overlap is unavoidable: (1) **buy the reconciliation** via a connectivity layer — but ⚠️ that adds **a second margin taker on ~10% gross, which may be fatal; verify the take rate first (Q38)**; (2) zero-overlap sourcing; (3) **single-source-of-truth per attraction, declared manually in a spreadsheet** for the ~20–50 genuinely overlapping attractions — "it costs approximately nothing and makes duplicates structurally impossible rather than probabilistically rare"; (4) 🔴 **do not do live cheapest-of-two price selection** — it is the most expensive line in the table, it sits in the render path, and it buys a few points of margin on inventory carrying ~10% gross. |
| **Effort** | **0 eng-weeks** |
| **Confidence** | **75%** |
| **Impact / eng-week** | **∞ (no engineering consumed) — and it is the single largest eng-week saving in the register.** |
| **Horizon** | **Now — it must precede the feed-2 commitment.** |
| **Defensibility** | **Low** |
| **Top risk** | 🔴 The first duplicate a customer sees is a quality failure, not a data-engineering ticket: **on a 253-SKU catalog where a category page shows the whole inventory, duplicates are on page 1.** And the asymmetry decides the design: **a false merge sells the wrong ticket (F2/F7); a false split is a cosmetic defect.** They must never be traded against each other with a single threshold. |
| **Latency budget** | n/a |
| **Failure mode / blast radius** | Contracting for non-overlap and discovering overlap post-signature. Require the SKU list as a contract schedule. |
| **Prerequisites** | None. |
| **Kill criterion** | **Kill the second-feed programme entirely if** (a) the second aggregator's take rate on top of Pool A's ~10% gross cannot be established in writing, or (b) non-overlapping scope is refused and overlap exceeds **50 head SKUs**, by **2026-10-31**. **The correct outcome of that kill is one feed, not a 20-eng-week project.** |
| **Displaces** | Nothing. It *prevents* 8–29 eng-weeks of displacement. |

---

### OPP-D2-3 · Agents book Pool B themselves, against a prepaid balance
| Field | Value |
|---|---|
| **Direction** | **D2** |
| **Value-chain stage** | 9 — Partner dashboard |
| **Customer** | Partner |
| **Money mechanism** | **(a) GMV lift** |
| **Driver metric** | **Pool B GMV per active partner per month** — 🔴 **never partner count, seats, or subscription revenue.** |
| **Sizing basis** | **TARGET** |
| **Impact (formula)** | `contribution/yr = partners × (retained_margin − D2_support)` = partners × **($2,400 − $784) = $1,616** at base `[INFERENCE, 03-ops-scan §4c.1.2 / §4c.2.3]`<br>→ at break-even 5 base partners: **$8,080/yr**; at 10: **$16,160/yr**; at 37 small partners: **$5,402/yr** |
| **Inference-cost test** | n/a — no model in the base row. (The AI layer on top is OPP-D2-2, §7.) |
| **Break-even** | Annualised D2 fixed cost = 5 / 12 / 24 eng-weeks = **$1,950 / $8,148 / $26,616** `[INFERENCE, 03-ops-scan §4c.3.4]` → **N\* ≈ 5 base-size partners, or ~37 small partners.** 🔴 **D2 breaks even ~4× more easily than D3 and tolerates the modal small partner. D3 does not.** |
| **Key assumptions** | (1) GATE 0 holds; (2) **the counter-intuitive one that makes D2 work at all: Indonesian labour arbitrage makes human-assisted B2B onboarding affordable at an ACV where SaaS orthodoxy says it cannot be.** At **US$6–11 per loaded BD hour**, a 10-hour hand-held onboarding costs **$60–110** — under a year's contribution from even the smallest viable partner. "The standard advice ('low ACV forces pure self-serve') is a conclusion drawn from US/EU salary structures and **does not transfer.**" → **Staff human onboarding; do not build self-serve tooling to avoid it** (and see §8 R-03). |
| **Data required** | Pool B net-rate card — **N (internal pricing decision, Q31)**. Partner entity/KYC (NIB, NPWP, sector licence) — **N, collected at onboarding**. Wallet ledger — **N, built here**. |
| **Build / Buy / Partner** | **Build (minimal).** Agent seats on the **existing D2C site**: net-rate flag + prepay wallet. Route 4 of six `[03-ops-scan §4c.7.4]`. |
| **Effort** | **3 / 5 / 8 eng-weeks** |
| **Confidence** | **55%** — contingent on ZE-07 producing repeat buyers first. |
| **Impact / eng-week** | **~$1,616–$3,232 per eng-week per year** |
| **Horizon** | **Next — and only if ZE-07 produces repeat buyers.** |
| **Defensibility** | 🔴 **Low as a portal; Med only via the inventory.** **"D2's pitch cannot be 'a portal.' Golden Rama has one. Traveloka is building one. Panorama has an app and a wholesale platform. A portal is table stakes and confers nothing"** — the same conclusion Step 2 reached about WhatsApp. **Label: table stakes** (§9). |
| **Top risk** | 🔴 **Never charge for access.** `03-ops-scan.md` §4c.0.2 corrects the rezio read explicitly: **"D2 has no revenue line of its own and should never be given one. It is a channel, and its only KPI is retained margin on Pool B volume, net of the cost of running the channel."** rezio's ceiling was **~US$6.0M ARR on 5,000+ operators at US$50–217/month** with no separate entity and no separate reported revenue; **Viator's certification carries no fee; Holibob gives its white-label away.** A subscription here would suppress the volume that *is* the product. Second risk: **Traveloka TPN ships "Travel Activities" as a named B2B line with 60,000+ activities, an announced Travel Agent Booking Engine, and Trip.com inventory pooling since June 2026 — treat Traveloka as the clock, not a distant threat.** |
| **Latency budget** | Agent is often on the phone with a client. **Search-to-quote must be <10s**, and the binding constraint is availability truth, not model speed. |
| **Failure mode / blast radius** | An agent commits a client to an on-request SKU. **Blast radius is the partner's customer relationship, which is worse than SatuSatu's own.** Contained only by ZE-02's latency gate. |
| **Prerequisites** | **P1 (ZE-09)**, ZE-04 (IDR denomination), ZE-06 (image sublicense), ZE-10 (prepay wallet), and **GATE 0**. |
| **Kill criterion** | **Kill if** fewer than **5 base-size-equivalent partners** (or 37 small-partner equivalents by contribution) are actively transacting **180 days** after launch, by **T₀+270d = 2027-05-14**. Prior gate: do not start unless ZE-07 clears its 3-repeat-agent test on **2026-11-15**. |
| **Displaces** | 5 weeks of the D2/D3 build. **Arguably it *is* the D2 build, in its cheapest defensible form** — which is the honest way to present it to a Head of Product who is already funding a bigger version. |

---

### OPP-D2-4 · Pool B reaches agents who are already logged in somewhere else
| Field | Value |
|---|---|
| **Direction** | **D2 / D3** |
| **Value-chain stage** | 10 — API / connectivity (as a *supplier*, not a distributor) |
| **Customer** | Partner (indirectly, via an aggregator's agent base) |
| **Money mechanism** | **(a) GMV lift** |
| **Driver metric** | **Pool B bookings originated through the third-party rail** |
| **Sizing basis** | **TARGET** |
| **Impact (formula)** | `contribution/yr = bookings × retained_after_aggregator_take`<br>· retained ≈ **12%** of ATV = **$3.00/booking** after conceding 10–20pts of the 27% `[INFERENCE]`<br>→ at 2,000 bookings/yr: **$6,000/yr**; at 500: **$1,500/yr** |
| **Break-even** | Effort 1 ew = **$679** → **227 incremental Pool B bookings.** Against **GlobalTix's 12,000+ agents** `[Tier A-as-claim, unaudited]` that is **0.02 bookings per agent per year.** Trivially clearable **if any agent buys at all** — which is precisely the untested proposition. |
| **Key assumptions** | Aggregators handle on-request supply routinely, so **this route works natively with Pool B's availability model** — unlike an API SatuSatu builds. |
| **Data required** | Pool B rate card + a structured feed — **Partial**. `availability_model` per SKU — **N until ZE-09.** |
| **Build / Buy / Partner** | **Partner.** List Pool B as a *supplier* on a rail agents already use. Route 2 of six. The aggregator absorbs **certification, integration support, agent onboarding, credit, AR, disputes and FX — i.e. §4c.1, §4c.3 and §4c.6 in their entirety.** |
| **Effort** | **0 / 1 / 2 eng-weeks** |
| **Confidence** | **50%** — high on feasibility, low on whether it should be done with GlobalTix. |
| **Impact / eng-week** | **~$6,000 per eng-week per year at 2,000 bookings** |
| **Horizon** | **Next**, and **selectively** |
| **Defensibility** | 🔴 **Negative if done wholesale.** This is the register's sharpest trade and it must be presented as a trade, not a recommendation: **"distribution reach now, at the cost of the exclusivity that makes Pool B worth distributing."** |
| **Top risk** | 🔴 **Disintermediation, and it is concrete and directional, not theoretical.** GlobalTix sees the volume, sees which Balinese operators produce it, and can contract them directly — it has the scale, the 12,000-agent base, an Indonesian GM, and an **Indonesian SOE channel-manager mandate (InJourney / Borobudur, 2025-10-07/08, Tier A)** demonstrating it does exactly this kind of direct sourcing. It also already holds a **Travel Agent Licence (TA03367)** and runs a `/resellers/` page whose pitch — *"our powerful API… instantly searchable, bookable and cancelable in real-time"* — **is D3's pitch, shipped, at scale, since at least 2022-12-29.** And **ingestion is disclosure**: every `product/list`, `checkEventAvailability` and `booking/reserve` call already tells SatuSatu's supplier which SKUs it merchandises, when demand spikes, and what converts. |
| **Mitigation** | 🔴 **Partial listing is the hedge: list the *replaceable* part of Pool B to buy reach; withhold the genuinely irreplaceable SKUs. That makes the disintermediation risk a bounded loss rather than an unbounded one.** Prefer a counterparty that does **not** compete for the Bali traveller — Prioticket / Experience Technology Group (OCTO-native, fully public Distributor API, owned by nobody competing in Bali) or Holibob — over GlobalTix, ⚠️ **contingent on verifying their Indonesian SKU depth, which is unverified and on which the whole preference rests.** |
| **Latency budget** | The aggregator's own on-request flow. Not SatuSatu's to set. |
| **Failure mode / blast radius** | Exclusivity loss is **irreversible**. Once Pool B is on an aggregator, it is no longer exclusive. |
| **Prerequisites** | **GATE 0**, ZE-06 (sublicensable content grant — you are handing content to a third party), ZE-09. |
| **Kill criterion** | **Kill if** fewer than **227 Pool B bookings** arrive through the rail in the first **180 days** of listing, by **T₀+180d = 2027-02-13** — the reach thesis is false and the exclusivity concession bought nothing. **Additional hard stop: if any listed Pool B operator is observed contracted directly by the aggregator within 12 months, halt all further listing immediately.** |
| **Displaces** | 1 week of the D2/D3 build. |

---

### OPP-D2-5 · Partners answer their own routine questions
| Field | Value |
|---|---|
| **Direction** | **D2** |
| **Value-chain stage** | 9 — Partner dashboard / 17 — customer service |
| **Customer** | Partner |
| **Money mechanism** | **(d) cost-to-serve reduction** |
| **Driver metric** | **Exception contacts per 100 partner bookings** (base 5.5, band 3–8) |
| **Sizing basis** | **TARGET** |
| **Impact (formula)** | `Δ/yr = partners × exception_cost_per_partner × deflection_rate`<br>· exception queue = **$6 / $114 / $1,963 per partner per year** `[INFERENCE, 03-ops-scan §4c.2.2]`<br>· deflection = **25–45%** of *exception* contacts `[INFERENCE — "agents are repeat, trained users, the single most deflectable audience there is"]`<br>→ at 20 partners and 35%: **$798/yr**; at 20 high-volume partners: **$13,741/yr** |
| **Inference-cost test** | Self-serve status/voucher/rate/invoice/policy lookup is **deterministic — no model, no meter.** 🔴 And the key negative finding: **true deflection on the availability loop is ~0% until Pool B has a feed. "No amount of AI deflects a question whose answer does not exist in any system."** |
| **Break-even** | Effort 2 ew = **$1,358** → **$1,358 of deflected support**, i.e. **~34 base-size partners at 35% deflection**, or **~2 high-volume partners.** At 20 base partners the payback is **1.7 years.** |
| **Key assumptions** | That the B2B exception queue exists at material volume. It does not today (no partners). **This row is sized against a cost that does not yet exist — the weakest sizing basis in the register, and it is why the row ranks low.** |
| **Data required** | Booking status, voucher, rate card, invoice, cancellation policy per partner — **Partial (Pool A yes, Pool B no until ZE-09).** |
| **Build / Buy / Partner** | **Build (config) inside OPP-D2-3, or buy whatever ships in the existing support stack.** Do not procure separately. |
| **Effort** | **1 / 2 / 4 eng-weeks** |
| **Confidence** | **45%** |
| **Impact / eng-week** | **~$399 per eng-week per year at 20 base partners** |
| **Horizon** | **Later** |
| **Defensibility** | **Low. Label: table stakes.** |
| **Top risk** | Building it before there are partners. Recomputed on SatuSatu's own cost base a B2B exception runs **$1.04 / $2.60 / $8.18** — **7–58× cheaper than the US benchmarks** ($25–35/ticket, "$15–20 saved per deflected ticket"). **The labour arbitrage lowers the value of deflection automation rather than raising it.** Any vendor case built on US per-ticket costs recommends the wrong thing here. |
| **Latency budget** | Self-serve, instant. |
| **Failure mode / blast radius** | A wrong self-serve answer on a cancellation policy → partner refunds their client on the wrong terms. Render from the contracted field (ZE-03's principle), never author. |
| **Prerequisites** | OPP-D2-3, P1. |
| **Kill criterion** | **Do not start** until the B2B exception queue exceeds **40 contacts/month** sustained for 2 months. **Kill if** that threshold is not reached by **2027-06-30.** |
| **Displaces** | 2 weeks of the D2/D3 build. |

---

### OPP-D3-3 · Indonesian wholesalers can carry Pool B without SatuSatu building an API
| Field | Value |
|---|---|
| **Direction** | **D3** |
| **Value-chain stage** | 10 — API / connectivity |
| **Customer** | Partner (wholesaler / DMC) |
| **Money mechanism** | **(a) GMV lift** |
| **Driver metric** | **Pool B bookings originated by named wholesalers** |
| **Sizing basis** | **TARGET** |
| **Impact (formula)** | `contribution/yr = bookings × $2.21` where **$2.21 = retained margin $3.00 − variable cost $0.79** (availability confirmation $0.65 + exception load $0.14) `[INFERENCE, 03-ops-scan §4c.3.4]`<br>→ at 2,000 bookings/yr: **$4,420/yr** |
| **Break-even** | Effort 0.5 ew = **$340** → **154 Pool B bookings.** Compare with a real D3 API: **≥480 Pool B bookings per partner per year (~9/week) merely to pay for its own integration and maintenance** — a floor that "excludes the modal agent" `[03-ops-scan §4c.3.4]`. |
| **Key assumptions** | The counterparties have reach and no competing attractions feed. **Panorama Group** — JTB acquired 40% of PT Panorama Tours Indonesia (announced 2017-02-01, verified against Panorama Sentrawisata's own corporate timeline, Tier A); **Panorama Destination is Indonesia's largest verifiable inbound DMC** (founded Dec 1999, 500+ staff, 250+ licensed guides); **Wupi** is a live "wholesale B2B Travel Distribution Platform… for travel agents in low and mid-tier markets" `[SHIPPED, Tier A]` — **but it carries "tour packages and flight tickets", not ticketed attractions.** **Golden Rama** runs a live two-sided portal with both an Agent Login and a **Supplier Login** — but its public agent surface self-describes as a **"Hotel reservation Center"**. 🔴 **"Every single Indonesian incumbent's B2B distribution is built around hotels, flights and packaged tours. Not one of them distributes ticketed attractions to agents."** They have the rails and are not putting attractions on them; SatuSatu has attractions and lacks distribution. |
| **Data required** | Structured Pool B feed (CSV or OCTO-shaped) — **Partial**; `availability_model` — **N until ZE-09**. **What Golden Rama's agent portal sells post-login — N; requires an agent account, and it is "the single most valuable remaining Indonesian check."** |
| **Build / Buy / Partner** | **Partner.** A structured feed into their existing rail, on their integration queue, not SatuSatu's. |
| **Effort** | **0.25 / 0.5 / 1 eng-weeks** |
| **Confidence** | **40%** — the counterparties are credible, the appetite is untested. |
| **Impact / eng-week** | **~$8,840 per eng-week per year at 2,000 bookings** — high, and low-confidence, and both should be said. |
| **Horizon** | **Next** |
| **Defensibility** | **Med** — a named Indonesian wholesaler that does not compete for the Bali traveller is a materially better counterparty than the incumbent aggregator (OPP-D2-4's risk does not apply as sharply). |
| **Top risk** | These are **packaged-tour, quote-and-confirm businesses**, not real-time attraction distributors. The integration may stall in their queue indefinitely — and SatuSatu has no leverage to move it. |
| **Latency budget** | Their workflow is already quote-and-confirm, which is why Pool B fits it. **This is the one place where Pool B's on-request nature is not a handicap.** |
| **Failure mode / blast radius** | Rate-sheet staleness inside a partner's packaged product. Bound with contract expiry defaulting to **suspension of rates, not rollover**. |
| **Prerequisites** | **GATE 0**, ZE-04, ZE-06, ZE-09. |
| **Kill criterion** | **Kill if** no named wholesaler has a signed rate agreement **and** first booking within **180 days** of first contact, by **T₀+180d = 2027-02-13**. |
| **Displaces** | 2–3 days of the D2/D3 build. |

---

## 6. RANKING — impact per eng-week, not RICE

**Why not RICE.** With effort as the binding constraint, RICE surfaces high-impact/high-effort rows that cannot be staffed at all. The ranking below divides sized annual impact at reference volume **R** (§1b) by **eng-weeks**. Because nearly every impact scales linearly in R, **the ordering is robust to R; only the absolute figures move.**

**Three honest warnings before the tables:**
1. **Rows sized only as a break-even threshold cannot be ranked on this metric.** They are listed separately, not silently dropped and not given a fabricated number.
2. **The metric and the dependency chain disagree, and the dependency chain wins.** ZE-09 ranks 9th on impact per eng-week and is a hard prerequisite (P1) for four rows above it. §6c corrects for this explicitly rather than hiding it.
3. **The sum in §6a mixes recurring, one-off and per-episode impacts.** Each is labelled. Do not read the total as a run-rate.

---

### 6a. 🟢 ZERO-ENGINEERING LANE — ranked

**Twelve rows. 3.7 eng-weeks in total. ~$140,500 of annualised impact at R.** On this evidence the lane dominates everything else in the register, and the reason is structural rather than lucky: **the constraints stack rewards moves against money already leaking over anything with a pre-revenue build.**

> ⛔ **SUPERSEDED BY §6 RED TEAM (Step 5c, 2026-07-27).** Original rows retained unedited below with red-team verdicts appended. **The $140,500 total is withdrawn** — see §6.4 for the recomposition ($12,160–$51,160) and §6.5 for the person-week cost this table prices at zero. **The revised ranked order is §6.18.**

| Rank | ID | Opportunity | Dir | Mechanism | Impact/yr at R (base) | Eng-wks | **Impact / eng-wk** | Conf | Horizon | 🔴 **Red-team verdict** |
|---:|---|---|---|---|---|---:|---:|---:|---|---|
| — | **ZE-05** | 1.50% supplier FX markup negotiated away | D0/D1 | (b) margin | **$29,250** *(recurring)* | **0** | **∞** | 60% | Now | **[KILLED as a sized opportunity]** — 60% confidence entered at face value; own-spread on the replacement SGD leg unquantified and **creates the exposure ZE-04 exists to remove**; the "✅ cross-check" against H12 is the same division twice. **EV ≈ $7,900 at R, ≈$2,370 at 300 bookings/mo.** Action retained at 2 BD hours. §6.2 |
| — | **ZE-07** | Pool B agent demand proven by rate sheet + WhatsApp | **D2** | (a) GMV | **$16,160** at 10 base partners *(recurring)* | **0** | **∞** | 65% | Now | **[DOWNGRADED]** — **$16,160 is the same $16,160 as OPP-D2-3, from the same 10 partners.** Sized at 8,000 bookings; its own kill criterion tests **6**. **0 eng-weeks conceals ~11 BD person-weeks** against a function whose existence is unverified. Blocked on Q31 (no rate card). Experiment retained, number withdrawn. §6.5 |
| — | **ZE-04** | B2B contracts denominated IDR + FX reset clause | **D2/D3** | (e) leakage | **$3,000** per adverse-3% episode at $100k B2B GMV | **0** | **∞** | 90% | Now | **[DOWNGRADED]** — episode frequency **unquantified** (4c-G9); exposure window largely closed by ZE-10's wallet. Retained as an **unsized compliance control**, not an opportunity. |
| — | **ZE-06** | Sublicensable image/content grant in Pool B template | **D2/D3** | (e) leakage | **$1,800–3,000** avoided retrofit *(one-off)* + unblocks D2/D3 content | **0** | **∞** | 80% | **Now — most time-sensitive row in the file** | **[DOWNGRADED — SURVIVES]** — **one-off; must never enter an annualised total.** Survives on irreversibility. |
| — | **ZE-08** | AI structured extraction for Pool B listings (ops habit) | **D1** | (d) cost-to-serve | **$1,920** *(recurring)* | **0** | **∞** | 80% | Now | **[SURVIVES, SKU-contingent]** — R-independent. 240 SKUs/yr implies ~100% Pool B growth, inherited from nowhere; at 60 SKUs/yr it is $480. Table stakes — never claim it. |
| **1** | **ZE-01** | Catalog stops steering buyers to the low-margin pool | D0/D1 | (b) margin | **$39,000** | 0.3 | **$130,000** | 85% | Now | **[DOWNGRADED — SURVIVES at rank 1 on cost]** — **$39,000 withdrawn.** Shift parameter unbounded; substitution admitted false on branded parks, which are the **only VERIFIED instance** of the defect. Size at break-even (**41 bookings**). Do it as a trust/advertising-accuracy fix. §6.3 |
| **2** | **ZE-02** | Ranking encodes the commercial strategy | D0/D1/D2 | (b) margin | **$39,000** | 1.0 | **$39,000** | 70% | Now, after ZE-09 | 🔴 **[KILLED]** — **the same money as ZE-01**: same denominator, same G12 constant, same mix shift, jointly capped at ZE-01's own high case. Both rows are items 1–3 of one recommendation list in `03-ops-scan.md` §4b.3.2. Config change folds into ZE-01; **1.0 eng-week returned.** §6.3 |
| **3** | **ZE-10** | B2B launches without a credit function | **D2** | (d) cost-to-serve | **$7,440** | 0.5 | **$14,880** | 85% | Now | **[DOWNGRADED]** — avoided cost of a credit function the register recommends **never building.** Right decision, fictional number. Retained as a **launch policy**, unsized. |
| **4** | **ZE-03** | Refund terms stop exceeding the supplier's | D0/D1 | (e) leakage | **$975** | 0.2 | **$4,875** | 75% | Now | **[SURVIVES]** — on ratio, not magnitude. Below the $3,000 floor, but so is 0.2 ew; a one-hour audit may close it free. |
| **5** | **ZE-09** | Declared `availability_model` per Pool B SKU **(P1)** | D0/D1/**D2/D3** | (d) cost-to-serve | **$1,365** direct | 1.0 | **$1,365** | 90% | **Now — see §6c** | **[SURVIVES, re-justified]** — direct return is a 15-month payback, not a case. **Five of the eight rows it is P1 for are GATE-0-exposed**; it still survives a GATE 0 failure on OPP-02+OPP-03a+OPP-03b (~$7,755). Best-designed row in the file: asks the operator to adopt **nothing.** |
| n/r | **ZE-11** | Machine-readable + assistant-callable catalog | **D1/D3** | (a) GMV | break-even: **194 Pool A or 57 Pool B bookings, lifetime** | 0.5 | not rankable | 70%/30% | Now | 🔴 **[KILLED as a funded row]** — the card itself concedes *"every AEO tactic list is inference dressed as method"*; 30% confidence on magnitude; the real channel is **distribution into the assistant**, a commercial act the incumbents already hold; kill test needs Q10 segmentation that may not exist. **Retain only P8 (robots audit) + schema.org markup at ≤0.1 ew.** §6.8 |
| n/r | **ZE-12** | Search stops returning nothing for real queries | D0/D1 | (a) GMV | break-even: **78 Pool A or 23 Pool B bookings, lifetime** | 0.2 | not rankable | 75% | Now | **[SURVIVES — RECLASSIFIED]** — from (a) GMV lift to **instrumentation.** It is the only row that manufactures data the rest of the register lacks (query logs close Q10). |
| 🆕 | **M-1** | **Nightly rate-integrity rule-check** (margin floor · expiry · tier · parity crawl) | D2/D3 | (e) leakage | unsized | <1.0 | — | — | Now | 🆕 **[ADDED BY RED TEAM]** — `03-ops-scan.md` §4c.5.2 calls it *"the highest return per eng-week of anything in 4c"* and it defends the highest-severity failure in the file. **Omitted from the original register.** §6.15 |
| 🆕 | **M-2** | **Chargeback / dispute leakage** (measure Q33 → 3DS/AVS config + dispute template) | D0/D1 | (e) leakage | unsized; H5: **8–18% of Pool A gross profit** | ~0.2 | — | — | Now | 🆕 **[ADDED BY RED TEAM]** — same order as ZE-05's entire claim, on better evidence. **Omitted.** §6.15 |
| 🆕 | **M-3** | **Pass float / breakage governance** vs the Sightseeing Pass precedent | D0 | (e) leakage | unsized | 0 | — | — | Now | 🆕 **[ADDED BY RED TEAM]** — `00-scope.md` §3 Amendment C was approved at GATE 1 specifically for this and **the register has zero rows on it.** §6.15 |

> ⛔ 🔴 **The cross-check below is WITHDRAWN by §6.4.** It is not corroboration. Of the $140,510: **$39,000 (28%) is ZE-02 double-counting ZE-01; $26,600 (19%) is TARGET-basis on a B2B business with zero partners; $2,400 is one-off; $3,000 is per-episode at unquantified frequency.** Reproducing H12 arithmetically is the same division run twice, not an independent check. **Recomposed total: $12,160–$51,160.**
>
> ~~🔴 **Cross-check worth stating plainly: ~$140,500 is 103% of Pool A's entire net gross profit at R ($136,500).** That is not a coincidence and it is not double-counting — ZE-01, ZE-02 and ZE-05 all act directly on the Pool A margin chain, either by recovering the vendor's FX take or by stopping demand being steered into the 7%-net pool. **It says the leak is the same size as the pool.**~~

---

### 6b. ENGINEERING-BEARING CANDIDATES — ranked

**Twelve rows. 20.0 eng-weeks at base.**

> ⛔ **SUPERSEDED BY §6 RED TEAM.** Original rows retained unedited; verdicts appended. **Revised order: §6.18.** 🔴 **Half this ordering inverts inside the register's own stated parameter bands** — see §6.9, closing note.

| Rank | ID | Opportunity | Dir | Mechanism | Impact/yr at R (base) | Eng-wks | **Impact / eng-wk** | Cum. ew | Conf | Horizon | 🔴 **Red-team verdict** |
|---:|---|---|---|---|---|---:|---:|---:|---:|---|---|
| — | **OPP-D1-4** | Second aggregator contracted for zero overlap | **D1** | (d) cost-to-serve | **8 / 15 / 29 eng-weeks avoided** = $10,185 at base *(R-independent)* | **0** | **∞** | 0 | 75% | Now | ✅ **[SURVIVES — PROMOTED TO RANK 1 OF THE FILE]** — the only row that **returns** the binding constraint rather than spending it. R-independent, GATE-0-independent. Weakness stated honestly in the card: the real form is non-overlapping **territory**, not product. |
| — | **OPP-04** | Pre-purchase enquiries answered in <60s, any language | D0/D1 | (a) GMV | **contingent** — needs **15% incremental conversion on Pool B enquiries** at $0.99/resolution; **fails on Pool A at every published price** | **0** *(per-resolution meter)* | **∞ on effort, gated on P2** | 0 | 40% | Now if P2 clears | 🔴 **[KILLED at any per-resolution price]** — **the meter cannot be pointed at Pool B.** You do not know an enquiry's pool until you have answered it, and by then it is metered; the two WhatsApp queues split by **entitlement**, not supply pool. On the blended queue the requirement is **~42% incremental conversion** — the register's own word for 57% is *"implausible."* Returns only as a **fixed-cost** arrangement at an unverified price. §6.6 |
| **1** | **OPP-D3-3** | Indonesian wholesalers carry Pool B, no API built | **D3** | (a) GMV | **$4,420** at 2,000 bookings | 0.5 | **$8,840** | 0.5 | 40% | Next | **[SURVIVES, weakly]** — the only D3-specific staffable row; the one place Pool B's on-request nature is an **advantage**; counterparties do **not** compete for the Bali traveller — the precise reason OPP-D2-4 died and this did not. Gated on GATE 0 + the Golden Rama post-login check. |
| **2** | **OPP-D2-4** | Pool B reaches agents already logged in elsewhere | **D2/D3** | (a) GMV | **$6,000** at 2,000 bookings | 1.0 | **$6,000** | 1.5 | 50% | Next, selectively | 🔴 **[KILLED]** — **$3.00 per booking against the only High-defensibility asset in the file.** The mitigation ("list the replaceable part") **cannot be executed before GATE 0, because GATE 0 is the exercise that identifies it.** Counterparty holds an Indonesian SOE channel-manager mandate, a TA licence, and sells the same operator availability + booking page + distribution for **USD 100 + 3%.** Own card: *"Defensibility: negative if done wholesale"*, *"exclusivity loss is irreversible."* Re-open only as salvage. §6.7 |
| **3** | **OPP-03a** | No Pool B booking sits silently unconfirmed | D0 | (e) leakage | **$5,040** | 1.0 | **$5,040** | 2.5 | 80% | Now | ✅ **[SURVIVES]** — no model; attacks F2, the unrecoverable Pool B failure; break-even **1.13 strandings/yr**, robust to a 3× error in the unverified $600. Watch: `n≥500` may be unreachable in 60 days at low volume, and operator fatigue is the same behavioural risk §4b.4.5 #5 flags for AI outbound. |
| **4** | **OPP-D2-3** | Agents self-book Pool B against a prepaid balance | **D2** | (a) GMV | **$16,160** at 10 partners *(N\* = 5 base partners)* | 5.0 | **$3,232** | 7.5 | 55% | Next | **[DOWNGRADED]** — **its $16,160 is ZE-07's $16,160**, same 10 partners, booked in both lanes. Own budget conversation; not before ZE-07 clears 2026-11-15; own §9 label is **table stakes.** |
| **5** | **OPP-02** | Day-of messages rendered, never generated | D0 | (d) cost-to-serve | **$1,896** | 2.0 | **$948** | 9.5 | 75% | Next | **[SURVIVES — RECLASSIFIED]** — below the materiality floor as a **saving**; above it as a **control.** P7 converts F1 from mandatory-HITL to gate-able and forecloses U-06 by construction. Fund it as the outbound-messaging standard. |
| **6** | **OPP-D1-2** | Bad SKUs stopped at ingest, not by customers | **D1** | (e) leakage | **$790** sized + **[UNSIZED mispricing leg, likely dominant]** | 1.5 | **$527** | 11.0 | 70% | Next | **[SURVIVES — SCOPED]** — **Layer 1 only, ~1.0 ew.** Layers 2–3 unfunded: no source measures LLM-as-judge accuracy on travel listing copy. Anchor on the one verified fact — a **100% defect rate** on the displayed sold-count across the whole Pool A catalog. |
| **7** | **OPP-03b** | Operator replies become booking state automatically | D0/D2 | (d) cost-to-serve | **$819** | 2.0 | **$410** | 13.0 | 50% | Next | **[DOWNGRADED → Later]** — starts as a data-collection project unless Q9 is Yes; **60/75/88%** real-Bali extraction accuracy against a **≥99% precision** bar, with a 40% automated-share floor that may be unreachable at that threshold. |
| **8** | **OPP-D2-5** | Partners answer their own routine questions | **D2** | (d) cost-to-serve | **$798** at 20 base partners | 2.0 | **$399** | 15.0 | 45% | Later | 🔴 **[KILLED — moved to §7]** — the card itself: *"sized against a cost that does not yet exist — the weakest sizing basis in the register."* True deflection on the availability loop is **~0%**; start is gated on a 40-contacts/month queue needing ~20 partners who do not exist and are GATE-0-gated. **2.0 eng-weeks returned.** |
| **9** | **OPP-01** | Concierge produces a day plan in a third of the time | D0 | (d) cost-to-serve | **$1,422** | 4.0 | **$356** | 19.0 | 45% | Next | 🔴 **[RE-OPENED — ranking unsafe]** — the $0.079/min baseline is **fully loaded and holds** (THR, BPJS, supervision, attrition, shrinkage, triangulated ×2). But the register scored the row on **cost-to-serve without ever testing capacity.** At 100 min/pass one FTE serves **1,068 passes/yr**; R assumes 2,400. If the Pass is concierge-capped, the mechanism is **(a) GMV lift** and the impact is **~$7,760, not $1,422** — moving it from 9th to ~2nd. Answer Q7 + Q8 + utilisation, then re-score. §6.9.1 |
| n/r | **OPP-D1-3** | Catalog retrievable in the languages arrivals speak | **D1** | (a) GMV | break-even: **388 Pool A or 113 Pool B bookings, lifetime** | 1.0 | not rankable | 20.0 | 60%/25% | Next | **[DOWNGRADED]** — the cost finding (4–5 orders of magnitude, raw MT vs post-edited) is the strongest arithmetic in the file and stands. But **India (8.19%) and China (7.73%) are addressed by neither the language nor the USD currency** — the register says so itself. **Raw-MT only; traffic claim withdrawn.** |

> ⛔ **RED TEAM, §6.9:** the labour-baseline half of this callout **survives verification** — $0.079/min is fully loaded, not minimum wage, and the 12.5-minute break-even against $0.99 stands. **The ranking half does not.** The row was scored on cost-to-serve without testing whether the concierge is a **capacity constraint on Pass sales volume**, which the register's own §4a.7 W-series makes computable. **OPP-01 is re-opened, not confirmed last.**
>
> 🔴 **The finding that will be least welcome and is best supported: OPP-01 — the AI concierge, the most intuitive AI idea in the business — ranks last of nine on impact per eng-week and consumes two-thirds of the entire assumed displacement budget on its own.**
>
> The cause is not that the idea is bad. It is that **the labour baseline is US$0.079 per concierge-minute, not the US$6–13.50 per contact that every vendor business case assumes.** Break-even AHT against a $0.99/resolution vendor is **12.5 minutes**; the tasks that are actually safe to automate are 2–3 minutes each. **Any model that shows AI saving money on cost-per-contact against Indonesian labour has the wrong baseline in it.** The register's centre of gravity therefore sits in deterministic, unmetered work — and that is a finding about SatuSatu's cost structure, not a lack of ambition.

---

### 6c. The dependency correction, and the recommended Now slate at a 6-eng-week budget

**The ranking and the dependency chain disagree in one place and the chain must win.** ZE-09 (declared `availability_model`) ranks 5th in the zero-engineering lane on its own direct return of $1,365/yr — but it is **prerequisite P1 for ZE-02, OPP-03a, OPP-D2-4, OPP-D3-3, OPP-02, OPP-03b, OPP-D2-3 and OPP-D2-5.** Four of those sit *above* it on impact per eng-week. Ranking alone would sequence it too late.

> ⛔ **SUPERSEDED BY §6.18.** The slate below is retained for audit. Four corrections, each fatal to it as written: **(1)** the "~$150,000" total mixes CURRENT, TARGET, one-off and per-episode figures and contains one number twice (§6.4); **(2)** it prices 5.2 eng-weeks and **zero of the ~14 person-weeks of BD, ops, legal and content time it commits to in the same quarter** (§6.5); **(3)** it schedules ZE-07 in step 1 although ZE-07 is blocked on Q31, an unmade internal pricing decision; **(4)** it places nine rows after GATE 0 in reading order but starts them in the same window, when **17 of 24 rows are GATE-0-exposed** (§6.10).

**Recommended Now slate — 5.2 eng-weeks of the assumed 6:** *(original — see verdict column)*

| Order | ID | Eng-wks | Cum. | Why here | 🔴 **Red-team** |
|---:|---|---:|---:|---|---|
| 0 | **GATE 0** (Q29 Pool B exclusivity cross-check) | 0 | 0 | One day. Gates every D2/D3 row below. Answer by **2026-08-07**. | ✅ **Kept — and it gates far more than the D2/D3 rows.** §6.10 |
| 0 | **P2 + P3** (PDP-law + liability, one counsel brief) | 0 | 0 | Gates OPP-04, OPP-01, OPP-03b. Costs zero eng-weeks. | ✅ **Kept.** |
| — | 🆕 **Q6 — count the bookings** | 0 | 0 | *(absent from the original slate)* | 🆕 **ADDED AS THE FIRST ACTION.** Nothing in this file can be ranked without `{{SCALE}}`. §6.11 |
| 1 | **ZE-05 · ZE-06 · ZE-04 · ZE-07 · ZE-08 · OPP-D1-4** | 0 | 0 | Contractual / commercial / ops. **~$50,300/yr recurring + $2,400 one-off + 8–29 eng-weeks avoided, for no engineering at all.** | ⛔ **"~$50,300/yr recurring" WITHDRAWN.** ZE-05 → ~$7,900 EV; ZE-07 → unsizeable and **~11 person-weeks**, blocked on Q31; ZE-04 → unsized; ZE-06 → one-off. **OPP-D1-4 survives and is the best row in the file.** |
| 2 | **ZE-01** | 0.3 | 0.3 | Highest impact per eng-week in the register. | **Kept at rank 1 on cost; $39,000 withdrawn.** |
| 3 | **ZE-09** | 1.0 | 1.3 | **Pulled up from rank 5 — it is P1 for four rows below.** | **Kept, re-justified.** Five of its eight dependents are GATE-0-exposed. |
| 4 | **ZE-02** | 1.0 | 2.3 | Requires ZE-09's latency field to be safe. | 🔴 **[KILLED] — same money as ZE-01. 1.0 ew returned.** |
| 5 | **ZE-03** | 0.2 | 2.5 | Hours of work, permanent margin protection. | ✅ **Kept.** |
| 6 | **ZE-10** | 0.5 | 3.0 | Removes a cost centre before it is built. | **Kept as a policy; $7,440 withdrawn.** |
| 7 | **OPP-03a** | 1.0 | 4.0 | Best engineering-bearing impact per eng-week that is not gated on unproven demand. | ✅ **Kept.** *(But it is gated on ZE-09, which is GATE-0-urgent.)* |
| 8 | **OPP-D3-3** | 0.5 | 4.5 | Contingent on **GATE 0**. | **Kept, 40% confidence.** |
| 9 | **ZE-11** | 0.5 | 5.0 | Crawl audit is hours and is a binary gate on everything AEO. | 🔴 **[KILLED] — retain only P8 + markup at ≤0.1 ew. 0.4 ew returned.** |
| 10 | **ZE-12** | 0.2 | **5.2** | Content-ops work; the eng-week is only for query logging. | ✅ **Kept — reclassified as instrumentation.** |
| 🆕 | **M-1 · M-2 · M-3** | <1.4 | — | *(absent from the original slate)* | 🆕 **ADDED.** §6.15 |

> ⛔ ~~**Slate total: 5.2 eng-weeks · ~$150,000 of annualised impact at R** (of which $2,400 one-off and $3,000 per-episode), **plus 8–29 eng-weeks of second-feed build avoided.**~~
>
> 🔴 **Corrected slate: ~2.0–2.9 unconditional eng-weeks + ~2.2 person-weeks (§6.18a); the conditional lane does not start before 2026-08-07. Annualised impact at R: $12,160–$51,160, not $150,000. At 300 bookings/month: $4,900–$16,700. At 150: nothing clears a materiality floor.**

**First row above the line:** **OPP-D2-4** (1.0 ew) at a 6.2-eng-week budget. **Second:** OPP-D2-3 (5.0 ew) — which needs its own budget conversation, not a rounding of this one, and should not start until ZE-07 clears its 3-repeat-agent test on **2026-11-15**.

> ⛔ 🔴 **OPP-D2-4 is [KILLED] (§6.7) and must not be the first row funded by any budget increase.** The first row above the line at a larger budget is **OPP-D1-2 (Layer 1, ~1.0 ew)**, then **OPP-02 (2.0 ew)**. **OPP-D2-3's caveat is correct and is retained.**

---

## 7. `[UNSTAFFABLE — documented for sequencing, not proposed]`

**Six rows.** Each exceeds the entire two-quarter displacement budget on its own, or is blocked by a condition that cannot be met inside two quarters. **They are kept out of the ranked table deliberately** — including them would produce exactly the feature wishlist the plan forbids. They are documented here so Step 6 can chain the dependencies.

| ID | Opportunity | Dir | Effort | Blocking condition | Depends on | Would become fundable when |
|---|---|---|---:|---|---|---|
| **U-01** | **D3 reseller API (request-to-book)** | **D3** | **24–46 eng-wks build + 8.7 / 21.3 / 50 eng-wks per year to run** | 🔴 **Pool B cannot pass an industry-standard API certification.** Viator gates production access on real-time availability and pricing, **booking hold** as a distinct operation, `/availability/schedules/modified-since` ingestion, a **calendar view of available dates**, and a 120-second timeout tolerance `[VERIFIED, Tier A]`. Pool B has none of these. **D3 could therefore only be request-to-book — an API that adds latency to a workflow whose only defect is latency.** | ZE-09, GATE 0, OPP-D2-3, ZE-04, ZE-06 | **All four, together:** GATE 0 passes · a material share of Pool B is instant-confirmable · **2–5 named partners already transacting ≥480 Pool B bookings/yr** through routes 1–4 · a budget of 33–96 eng-weeks in year one. Break-even is **~20 partners at base assumptions, defensibly 25–40** once the unquantified never-launch rate (40–60% would raise cost per productive integrator 1.7–2.5×) and an uncostable certification queue are allowed for. |
| **U-02** | **OCTO-conformant connectivity client** | D1/D3 | **8 / 14 / 24 eng-wks** `[ASSUMPTION ± — derived from the S2c second-feed bands; OCTO is a published spec rather than a bespoke adapter, so the low end is credible]` | Effort. | ZE-09 | It is **the only structural answer to single-feed concentration**: one conformant client reaches Prioticket/ETG, Ventrata, Bókun and any future OCTO supplier, and makes each vendor swappable. `02-competitor-matrix.md` §4d: *"This should be a named decision in the D3 architecture, not an implementation detail."* **Fundable at a ≥14-eng-week budget, and it should be the first thing funded when one exists.** |
| **U-03** | **Second aggregator integrated properly** (canonical model + option-level mapping + dedup + review queue + dual settlement) | **D1** | **11 / 20 / 37 eng-wks** | Effort — **and it is avoidable.** | OPP-D1-4 | **It should never become fundable in this form.** OPP-D1-4 (zero-overlap contracting, 0 eng-weeks) or manual single-source-of-truth per attraction removes the need. Documented here only so nobody rediscovers it as "the obvious way to add a second feed." |
| **U-04** | **White-label agent storefront** | **D2** | **8 / 14 / 20 eng-wks** | Effort **and product logic**: a consumer-facing storefront that cannot confirm is a bad storefront, so it **degrades on exactly the inventory it would be built to sell.** | ZE-09, OPP-D2-3 | Only after Pool B is majority instant-confirmable. Precedent is unhelpful: Holibob gives its white-label experience website away as channel enablement, not as a product. |
| **U-05** | **OPP-D2-2 · AI quoting assistant for agents** — itinerary assembly under constraints (multi-day, multi-pax with age bands, geographically coherent, target agent margin, branded quote output) | **D2** | **3 / 6 / 12 eng-wks**, on top of OPP-D2-3's 5 | Individually at the budget ceiling; the **pair is 11 eng-weeks.** | OPP-D2-3, ZE-09, ZE-02, GATE 0 | 🔴 **Analytically the best-positioned AI application in the whole B2B bracket** — it is generative *plus* constraint-satisfying, and it is **pre-booking, so an error costs a re-quote, not a wrong booking.** Money mechanism **(a) GMV lift**; driver metric **quote→book conversion**. **Break-even: 1,843 incremental Pool B bookings/yr** (6 ew ÷ $2.21 contribution per booking) ≈ **35/week across the partner base, or ~1 extra booking per agent per week at 20–40 agents.** 🔴 **Hard design constraint if ever built: every Pool B line must carry an explicit subject-to-confirmation state in the client-facing output, and quotes must expire in 24–72h** — otherwise the assistant manufactures unhonourable quotes at machine speed. Fundable at a ≥12-eng-week budget **and** only after OPP-D2-3 has live partners. |
| **U-06** | **In-destination generative concierge** (model authors instructions to travellers in-destination) | D0 | 6+ eng-wks | 🔴 **Governance, not effort.** Blocked on P2 (PDP law) and P3 (liability — a concierge instruction is SatuSatu's own act, and the Pass markets *"a real Bali local"*). Additionally **failure class F5 (safety-adjacent: water and surf conditions, volcano status, scooter advice, medical/allergen guidance) must not be AI-issued at all, reviewed or otherwise.** | P2, P3, OPP-02, P5 | **Probably never in this form.** The correct substitute already exists in the register: **OPP-02 renders instead of generating**, which collapses the failure surface to slot selection. Documented so that "AI concierge" is not re-proposed as a single undifferentiated idea when only half of it is safe. |

🔴 **U-07 — added by the red team, demoted here from §6b rank 8:**

| ID | Opportunity | Dir | Effort | Blocking condition | Depends on | Would become fundable when |
|---|---|---|---:|---|---|---|
| **U-07** | **OPP-D2-5 · Partners answer their own routine questions** | **D2** | 2 eng-wks | 🔴 **The cost it deflects does not exist.** The card's own words: *"sized against a cost that does not yet exist — the weakest sizing basis in the register."* True deflection on the availability loop is **~0%** until Pool B has a feed, and the labour arbitrage **lowers** the value of deflection (a B2B exception costs $1.04–8.18 here, 7–58× below the US benchmarks every vendor case rests on). | OPP-D2-3, P1, GATE 0 | Only when a B2B exception queue exceeds **40 contacts/month sustained for two months** — which requires ~20 transacting partners who do not exist. **Do not rank it until they do.** |

**Dependency edges for Step 6, in one line:**
~~`GATE 0 → ZE-09 → {ZE-02, OPP-03a, OPP-02, OPP-03b} and {ZE-04, ZE-06, ZE-10} → OPP-D3-3 / OPP-D2-4 → OPP-D2-3 → {U-05, U-04} → U-01`~~, with `OPP-D1-4 → (avoids U-03)` and `U-02` sitting off the critical path as the concentration-risk hedge.

🔴 **RED-TEAM-CORRECTED EDGE LIST (ZE-02 and OPP-D2-4 killed; Q6 and M-1 added):**
`Q6 (count the bookings) → GATE 0 → ZE-09 → {OPP-03a, OPP-02, OPP-03b} and {ZE-04, ZE-06, ZE-10} → ZE-07 (needs Q31) → OPP-D3-3 → OPP-D2-3 → {U-05, U-04, U-07} → U-01`, with `OPP-D1-4 → (avoids U-03)` **off the critical path and fundable immediately**, `M-1 / M-2 / M-3` likewise, and `U-02` as the concentration-risk hedge.

---

## 8. CUT LIST — candidates considered in 5a/5b and rejected, with the reason

**These are my kills, made during synthesis. The Red-Team Skeptic runs next and will add its own. Keeping the two lists separate is the point** — a reader must be able to tell what the author rejected from what the critic rejected.

Rejections fall into three classes: **arithmetic** (the money does not work at SatuSatu's cost structure), **data** (the input does not exist and cannot be manufactured), and **evidence** (the claimed benefit is vendor-asserted and unmeasured).

| # | Candidate considered | Class | Why it was cut |
|---|---|---|---|
| **C-01** | **Learned / ML ranking of the catalog** | **Data** | 🔴 Not merely unstaffable — **arithmetically impossible on the data.** Per-SKU learned signals need **30 / 50 / 100+ own booking events per SKU** `[INFERENCE, G10]`. A 2,500-SKU catalog would need **75,000–250,000 own bookings** to have that everywhere. GetYourGuide runs cold-start as a **funded ML workstream at 200K SKUs and ~40M monthly visitors** and still needs a dedicated approach. **"The honest answer is that learned ranking is not on the roadmap at any point covered by this research."** ZE-02's explicit business rule does the commercially important part for 1 eng-week. |
| **C-02** | **Semantic / hybrid search now** | **Data + premature** | Pays at **~2,000 SKUs, band 1,200–4,000** `[INFERENCE, G7]`; the catalog is **253**. **"Embedding retrieval on 253 SKUs solves a problem the catalog does not have yet, while the zero-result log goes unread."** Replaced by ZE-12 (synonyms, query logging, curated collections, facets) at 0.2 eng-weeks. **Re-open on the trigger metric, not the SKU count: zero-result rate >10%, or null-click rate >40%.** |
| **C-03** | **Availability prediction from booking history** | **Data + asymmetric risk** | Needs **100+ observed departure-days per SKU** before it is even arguable `[INFERENCE, G19]`; almost no Pool B SKU will reach that soon. And the cost of a wrong prediction is an **oversell — the unrecoverable failure** on fixed-departure products. **A `max(observed)` cap with a safety margin is a one-line rule that gets most of the benefit at zero risk of model error.** |
| **C-04** | **AI partner-onboarding tooling** (enrichment/ICP scoring, clause redlining, KYC document extraction, in-portal setup assistant) | **Arithmetic** | Best realistic compression is **~20–35%, i.e. 3.0–4.9 hours saved per partner = US$24–39** at the US$8 loaded BD hour. At 100 partners that is **US$2,400–3,900/yr against 4–10 eng-weeks of payback** — the tooling costs more than it saves for years, charged against the constrained resource. 🔴 **"The labour arbitrage that makes human onboarding affordable is the same fact that makes automating it uneconomic."** Take whatever ships inside the existing CRM/e-sign stack and stop. |
| **C-05** | **AI reconciliation matching** (bank credit → invoice → booking → operator payable) | **Arithmetic (premature)** | Deterministic matching with a fuzzy tail; the fuzzy tail is a genuine AI fit but it is a **small tail at 20 partners**. **Do not build. Revisit above ~100 partners.** |
| **C-06** | **AI integration copilot / self-serve sandbox tooling to cut D3 integration time** | **Evidence** | Searched specifically. **Only vendor marketing (Tier C), no disclosed methodology, no baseline definition, no independent verification** — every quantified claim traced back to an API-management vendor selling the thing being measured (flag 4c-G12). And the structural point: **Viator ships docs + sandbox + a published checklist and still mandates human certification, because the checks are semantic (age-band bucketing, per-person vs unit pricing, refund disclosure before cancellation), not syntactic. Sandboxes catch syntax; certification exists because syntax was never the problem.** Planning position: assume **0–20% savings** and fund nothing on it. |
| **C-07** | **AI-generated / AI-derived imagery** (re-cropping, upscaling, background removal, variant generation) | **Rights, not cost** | Creates **derivative works, and derivative-work rights are a separate grant from display rights.** The Pool A licence chain is at least three links long (operator → GlobalTix → SatuSatu) and **no collected source, and no source found by direct search, states what rights an OTA reseller receives in supplier photography.** **Blocked upstream by ZE-06, not by budget.** The affordable media work is Layer-1 technical validation plus **hero-image selection from what the operator already supplied** — GYG's own two image papers are about *choosing* among existing images, not creating them. |
| **C-08** | **AI-written SEO/AEO content at scale across Pool A** | **Evidence — and probably inverted** | Pool A listings are **the same text and images as every other GlobalTix reseller**; such a page cannot win the attraction's head term, gives an answer engine no reason to cite it, and may not be indexed as a distinct document at all. **"More copies of the same feed text is more duplicate content, not more retrievability."** `03-ops-scan.md` §4b.6.3 priority 6 is explicit: **do nothing about Pool A prose.** Unique text is funded on **Pool B only** (ZE-11 + ZE-08). |
| **C-09** | **AI dynamic pricing / margin optimisation** | **Evidence + contractual ceiling** | Tempting because **everyone in the category scores ~1 on pricing and ~0–1 on payments/fraud — "a real gap in the category, not just in these two companies."** Cut anyway: Pool A is **floored by GlobalTix's `minimumSellingPrice`, with blacklisting as the stated consequence** `[VERIFIED, Tier A]`, and MSP is set equal to RSP, which **functionally converts a "recommendation" into a fixed price.** Pool A's band is therefore **"not a market outcome SatuSatu can optimise its way out of — it is a contractual box."** On Pool B the pricing lever is a **rate card and a bundle**, not a model. Note also **only 6% of operators use dynamic pricing at all** (69% static, 25% variable). |
| **C-10** | **Reuse of TipTip's "AI Event Business Sales Forecasting"** | **Structural** | 🔴 Cut on the merits, not on politics. Concert ticketing is **a small number of high-value, date-fixed, single-shot events with a pre-sale demand curve**; TAA is **253 evergreen, daily-departure, low-ASP SKUs with no comparable pre-sale signal. It is a different forecasting problem, not a port.** The associated **+50% contribution-margin claim is correlational and single-source** — every Tier A/B account says "after"/"following"; the only causal phrasing is a Tier C aggregator's rewrite, off one release dated 2026-05-04, as a relative lift on an undisclosed base, with two competing non-AI explanations in the same release. **What is genuinely reusable is organisational, not technical: people who have shipped production evals, monitoring and a retraining loop inside the same legal entity. Borrow the people; do not port the model.** |
| **C-11** | **Deflection-first AI customer service across the whole queue** | **Arithmetic + measurement** | The deflectable tasks are **8% of concierge minutes** (3 / 8 / 21 of 32 / 100 / 276 minutes per pass) — **"the tasks that are safe to fully automate are the tasks that barely cost anything."** The 80% that matters is **assist**, not deflection. And the metric itself is corrupt for this product: deflection counts silence as success, **"a traveller who goes silent after a bad in-destination instruction is not a resolved ticket — they are a person walking toward the wrong temple."** OPP-04 survives only re-scoped to **pre-purchase Pool B enquiries and justified on coverage/latency/language, never on cost per contact.** |
| **C-12** | **Charging partners for D2 access (subscription or seat fee)** | **Arithmetic — and the precedent is unambiguous** | rezio's ceiling is **~US$6.0M ARR on 5,000+ operators at US$50–217/month**, with **no separate legal entity, no separately reported revenue and no separate P&L**, against KKday's ~US$70M Series D. **Viator's certification carries no fee. Holibob gives its white-label away.** 🔴 **"D2 has no revenue line of its own and should never be given one. It is a channel, and its only KPI is retained margin on Pool B volume."** A subscription would suppress the volume that *is* the product. **Any plan scoring D2 on partner count, seats or subscription revenue is measuring the wrong thing.** |
| **C-13** | **Requiring Pool B operators to adopt a reservation system or channel manager** | **Data on the population** | Pattern 2 of seven. Requires the operator to **buy software, learn it, and keep a calendar current daily — forever.** Against a population where **39% of operators worldwide run no booking system, 58% of small operators have none, and 54% of operators founded after 2022 have none** — the newest cohort is the *least* digitised. **"Any Pool B roadmap premised on 'operators will get on channel managers' is premised on a trend that the data says is not happening."** Retained only as an *opportunistic* path for the largest 5–10% of Pool B operators who already run something. |

---

## 9. TABLE-STAKES REGISTER — what must never be sold as a differentiator

Per plan §7.7. Each of these is worth doing; **none of them is a moat**, and presenting any of them as one would be the fastest way to lose the room.

| Capability | Why it is table stakes | Evidence |
|---|---|---|
| **A WhatsApp support/concierge channel** | 🔴 **Antavaya publishes a *named* WhatsApp concierge — "AMY", +62817 768 838 — on its homepage. Golden Rama runs a WhatsApp widget. Pigijo listed WhatsApp as primary contact.** The "WhatsApp-first SEA player" was investigated as a category and **refuted** — three search framings returned **zero named consumer-facing companies**, only a vendor layer selling WhatsApp engines *to* travel businesses. **"Any D0 defensibility claim resting on 'we serve on WhatsApp' is unsupported."** | `00-scope.md` §4 Group 4 |
| **A B2B partner portal** | **"D2's pitch cannot be 'a portal.' Golden Rama has one. Traveloka is building one. Panorama has an app and a wholesale platform. A portal is table stakes and confers nothing."** | `02-competitor-matrix.md` §5b.1 |
| **A public reseller API** | **"The API itself is table stakes — Klook, GYG, Viator, KKday and Headout all ship one, and Viator's is an industry default with formal certification."** And publishing one guarantees nothing: **Headout's public API docs were last pushed 2024-07-29 — ~24 months stale — at a profitable, 400+-city company that has engineers.** | `00-scope.md` §6(b); `02-competitor-matrix.md` §7 |
| **A pass / bundle product** | **Klook Bali Pass is live now** — activity ID 68512, choose 2/3/4/5 from **40+ Bali activities**, "save up to 45%", published in **25 locale variants of one activity ID**. It is a merchandising construct (bundle SKU + purchase/activate/redeem state machine), **not an AI or platform construct** — which is exactly why a horizontal incumbent can bolt one on in a week. **This inverts the plan's central risk.** | `02-competitor-matrix.md` §5d |
| **AI-assisted listing creation from operator source material** | GetYourGuide shipped it publicly on **2025-04-23**, 8 of 16 wizard steps, **100% rollout**. It is a prompt over content the operator already has. **Do it (ZE-08) — and never claim it.** | `02-competitor-matrix.md` §2.1 |
| **AI customer-service deflection** | Every credible vendor sells it; **claimed exceeds measured by 16–40 points systematically**; and the deflectable fringe here is 8% of concierge minutes. | `03-ops-scan.md` §4a.2.2 |
| **Instant confirmation on Pool A** | Deterministic API behaviour SatuSatu resells. **It is plumbing, not service** — "no reason to withhold from anyone." | `03-ops-scan.md` §4a.4 |

> ⛔ **RED TEAM, §6.10:** the claim below is **100% conditional on GATE 0 and this section does not say so.** Its subject is *"**exclusive** direct-contracted Balinese long-tail supply."* If Pool B is not exclusive there is no moat in this document — only a well-argued operations improvement. **And OPP-D2-4, ranked 2nd in §6b, proposed to sell part of it for $3.00 a booking; that row is [KILLED].**
>
> **What is *not* table stakes, and is the only thing in this register with High defensibility:** a **contracted, classified availability model over exclusive direct-contracted Balinese long-tail supply** (ZE-09 + ZE-06 + GATE 0). It is defensible precisely because it is unglamorous and unautomatable: **`01-landscape.md` §9 Force 1 concludes real-time availability for Bali's long tail will not exist by 2028, and "Klook and Viator will not do manual fulfilment for a 30-guest-a-month waterfall operator either."** Solving it by contract and classification rather than by software is the one asset an incumbent's capital cannot short-circuit. ⚠️ **Its clock is set by GlobalTix, which will sell the same operator availability + a booking page + channel distribution for USD 100 one-time and 3%.**

---

## 10. ADJUDICATION OF CONFLICT C6 — GetYourGuide's connectivity position

### The conflict
| Reading | Source | Claim |
|---|---|---|
| **Vulnerability** | `00-scope.md` §4 Group 3 (Tier A facts) | *"GYG routes supply through the systems of its two largest competitors. That is a nameable strategic vulnerability and Step 3 should treat it as one."* |
| **Control** | `02-competitor-matrix.md` §4c (Tier A facts) | *"GYG is **not** a tenant. It owns the ingestion contract."* Authors the spec, runs certification, publicly grades Bókun above FareHarbor, keeps the catalog as system of record, built an AI wizard around the content dependency, dilutes across 9+ connectors. |

Step 3 flagged this as *"genuinely unresolved, and both readings rest on Tier A evidence… They differ on interpretation, not on facts."* **It is resolvable, and it must be, because it decides SatuSatu's build/buy/partner posture.**

### Ruling: **CONTROL, not vulnerability.** Four reasons, ranked by weight.

**1. The control evidence is positive, dated and specific; the vulnerability evidence is a null.**
GYG authors the spec (`code.getyourguide.com/partner-api-spec/`, Apache-2.0, **360 commits, last push 2026-07-21**), runs a **Connectivity Partner Program with certification and an Integrator Portal**, and on **2026-02-10** published a tiered public ranking placing **Bókun (Tripadvisor-owned) Premium** above **FareHarbor (Booking-owned) Advanced** `[all VERIFIED, Tier A]`. Against that, Step 3 searched and found **no dispute, no deprecation notice, no acquisition of a channel manager, no public complaint, no price event.** A vulnerability claim resting entirely on an ownership diagram, with **zero observed friction across eight years** (Tripadvisor bought Bókun 2018-04-20; the relationship is intact in 2026), is an inference from structure against an absence of events. **A vendor does not publicly grade its landlord second-tier.**

**2. The catalog is the system of record, which makes the connector replaceable by construction.**
*"You must create your product in the Supplier Portal before connecting it to your reservation system."* The channel manager syncs availability, price categories and bookings **against a record GYG already owns**. **If a connector is lost, the catalog survives.** That is the definitional difference between a dependency and a tenancy.

**3. GYG spent engineering specifically to reduce the connector's value, and it worked.**
The **2025-04-23 AI product-creation wizard** (8 of 16 steps auto-completed, ~60 min → 14 min, **rolled out to 100%**) lets a supplier build a complete listing **directly in GYG's own portal from a paste of their own website** `[VERIFIED, Tier A]`. That is a deliberate, shipped reduction in the value of channel-manager-mediated content onboarding. **Companies do not fund that against a dependency they are comfortable with, and they do not succeed at it if they are the weaker party.** Add portfolio dilution — nine+ named Premium/Advanced systems plus a long tail — and **no single connector is load-bearing.**

**4. The economics of the category run the other way.**
In this sector connectivity vendors charge the **supplier**, not the demand side. Step 3 is explicit that whether GYG pays anything per booking is **unverified — "do not assert."** But the asymmetry test is informative: **if GYG paid rent, Bókun's owner would have an incentive to raise it, and we would expect at least one public price event in eight years. There is none.** Corroborating the direction: when Tripadvisor bought Bókun it announced it would move pricing *toward* **"a fraction of a percent per booking, far under the industry standard"** — *"a company buying a toll booth in order to demolish it"* — and the whole middleware layer now sells **neutrality** and is standardising on **OCTO**. ⚠️ **The Bókun per-booking rate itself was NOT re-evidenced in Step 3 (C15) and must be re-verified before it appears in a recommendation** — the ruling does not depend on it.

### The correction both readings need — and this is the decision-relevant part

**GYG's posture is neither "partner for the plumbing" nor "tenant." It is: own the record, rent the pipes, grade the landlords.** And that posture **required a decade and a Supplier Portal to establish.** The ownership of the record is what makes the rest safe.

🔴 **Therefore the C6 ruling does not license "partnering for connectivity is safe" as a general lesson for SatuSatu. It licenses exactly one narrower thing: own the canonical product record before integrating anything.**

**SatuSatu does not currently do this.** Pool A arrives from GlobalTix and **ships to customers with the supplier's own transaction count intact and displayed** — "99k+ sold" on a product SatuSatu has not sold 99,000 times `[VERIFIED, Tier A]`. That is the **opposite** of owning the record, and it is the precise mechanism by which the catalog steers buyers into the 7%-net pool (ZE-01). SatuSatu has 253 SKUs, no supplier portal, no spec anyone implements, and no capacity to author one.

### Build / buy / partner consequences, stated as instructions

| Layer | Call | Reason |
|---|---|---|
| **The canonical product record** (product model, option mapping, `availability_model`, pool tag, margin tag, confirmation latency) | 🔴 **BUILD — and it is the only build this register endorses without hesitation.** ZE-01 + ZE-09, **1.3 eng-weeks combined.** | It is what GYG's whole position rests on, it is cheap at 253 SKUs, and it is unrecoverable later. |
| **Connectivity and reconciliation** (feed adapters, dedup, normalisation) | **BUY / PARTNER, or delete the requirement.** OPP-D1-4 deletes it for 0 eng-weeks; U-02 (OCTO) buys vendor-swappability at 8–24 eng-weeks. | Middleware prices at **~5.7% of processed volume** `[INFERENCE on Travel Curious → Redeam: >$40M against >$700M projected]`, sells neutrality, and is commoditising on an open standard. **"Do not build to be the connectivity layer."** |
| **The distribution surface** (portal, API) | **PARTNER first** (OPP-D2-4, OPP-D3-3), build only the minimum (OPP-D2-3). | Table stakes (§9), and U-01's break-even needs ~20–40 partners each clearing 480 Pool B bookings/yr. |
| **Grading and certifying other people's systems** | 🔴 **DO NOT ATTEMPT.** | GYG can carry a staffed certification queue because it amortises across thousands of partners. **SatuSatu cannot amortise it across twenty**, and the alternative — no certification — means accepting partners who ship mispriced, stale, parity-breaking storefronts under SatuSatu's supply. **Neither option is acceptable, which is itself an argument against D3.** |

---

## 11. COVERAGE PER DIRECTION

**24 deduplicated candidates in the register** (12 zero-engineering + 12 engineering-bearing), plus **6 `[UNSTAFFABLE]`** rows documented for sequencing and **13 cut** candidates. Rows tagged to more than one direction are counted under each; the primary tag is bolded in the cards.

| Direction | Candidates | IDs | Verdict |
|---|---:|---|---|
| **D0** — curated Pass + human concierge | **9** | OPP-01, OPP-02, OPP-03a, OPP-03b, OPP-04, ZE-01, ZE-02, ZE-03, ZE-12 (+ ZE-05, ZE-09 shared) | ✅ **Over-covered, as expected — this is the D0 gravity the plan warned about.** Note the corrective finding: the D0 rows rank *worst* on impact per eng-week among model-bearing work, because the labour baseline is $0.079/minute. 🔴 **RED TEAM §6.17: the row count is honest (37.5%, not two-thirds) but the gravity is in the money — D0/D1 carries 77% of the zero-engineering lane's headline, 52% of the Now slate's eng-weeks, and 100% of the impact that survives the red-team pass. The mechanism that hides it is summing CURRENT-basis D0/D1 dollars with TARGET-basis D2/D3 dollars into one total.** Also: **six of the 24 cards carry no bolded primary tag** (ZE-01, ZE-02, ZE-03, ZE-05, ZE-12, OPP-04), so this table is not reconcilable with the cards it summarises. |
| **D1** — horizontal catalog | **6** | OPP-D1-2, OPP-D1-3, OPP-D1-4, ZE-08, ZE-11, ZE-12 (+ ZE-01, ZE-02, ZE-03 shared) | ✅ **Met.** But flag the strategic caveat: **D1 scales the lowest-margin pool.** Adding SKUs at ~7% net multiplies revenue while adding catalog, content and support cost linearly. Every D1 row here is therefore either a **leak-stopper** or a **retrievability play** — none is a growth bet. |
| **D2** — B2B partner dashboard | **6** | ZE-07, ZE-10, OPP-D2-3, OPP-D2-4, OPP-D2-5, ZE-04 (+ ZE-06, ZE-09, U-05 shared) | ✅ **Met.** All six are explicitly contingent on **GATE 0**. The cheapest (ZE-07, 0 eng-weeks) is also the one that decides whether the other five should exist. |
| **D3** — reseller API | **3 nominally, and I am recording this as UNDER-COVERAGE** | OPP-D3-3, OPP-D2-4 *(shared with D2)*, ZE-11 *(shared with D1)*; plus ZE-04 and ZE-06 as enablers; plus U-01, U-02 `[UNSTAFFABLE]` | 🔴 **See below. Not padded.** |

### 11a. 🔴 D3 under-coverage statement

**D3 cannot currently field three credible, independently-fundable candidates, and I am not going to invent them.**

Of the three rows tagged D3, **only one (OPP-D3-3) is D3-specific and staffable**; **OPP-D2-4 is shared with D2 and is really the same move against a different counterparty**; and **ZE-11 is a demand-generation row that happens to produce a machine-readable surface.** 🔴 **Not one of the three is an API that SatuSatu builds. That is the finding, not an omission.**

**Four reasons D3 cannot be populated, each established independently and each pointing the same way:**

1. **Pool B cannot pass an industry-standard API certification.** Viator gates production access on real-time availability and pricing, **booking hold**, availability ingestion via `modified-since`, and a **calendar view of available dates** `[VERIFIED, Tier A]`. Pool B has none of them. **D3 could therefore only be request-to-book — and a request-to-book API, from an agent's seat, is a slower, more brittle version of the WhatsApp message they already send. The API adds latency to a workflow whose only defect is latency.**
2. **Pool B is a reason to *stock* SatuSatu, not to *integrate* it.** **"An agent's platform choice is a workflow decision, not a product decision"** — what they buy is one login, one rate logic, one invoice, one AR relationship. **A Bali-only 253-SKU supplier is, by construction, an *additional* login.** Pool B competes for a line item inside whichever platform the agent already uses. That is an argument for OPP-D3-3 and OPP-D2-4 (get into existing rails) and against building a rail.
3. **The break-even is out of reach on the partner distribution.** **~20 actively-transacting partners at base assumptions, defensibly 25–40** once the unquantified never-launch rate and an unaffordable certification queue are allowed for — and **each must transact ≥480 Pool B bookings/yr (~9/week) merely to pay for its own integration and maintenance.** That floor **excludes the modal agent**, and applying Arival's *>70% small or micro* finding symmetrically to the agent population says the modal agent is exactly who would sign up. **D3's viability rests entirely on acquiring the top decile. Any D3 plan with a partner-count target rather than a partner-volume target is mis-specified.**
4. **The effort exceeds the whole two-quarter budget by 4–8×.** 24–46 eng-weeks to build, 8.7 / 21.3 / 50 eng-weeks per year to run.

**What would have to change for D3 to become fundable — all four, not any:**

| # | Condition | Currently | How it gets answered |
|---|---|---|---|
| 1 | **GATE 0 passes** — Pool B is verifiably exclusive, per SKU, in a form an agent can spot-check | Unanswered (Q29) | **One day of catalogue cross-checking.** Deadline 2026-08-07. |
| 2 | **A material share of Pool B is instant-confirmable** — `allotment` / `freesale_capped` / `static_schedule`, not `request_to_book` | No availability model exists at all | ZE-09, then measure. 🔴 **"Closing Pool B's availability gap is worth more than building D3. Doing D3 first spends the scarce resource on the wrong layer."** |
| 3 | **2–5 *named* partners already transacting ≥480 Pool B bookings/yr through routes 1–4** | Zero partners | ZE-07 → OPP-D2-3. **"If Pool B does not sell by rate sheet, it will not sell by API — and that answer arrives before any engineering is spent."** |
| 4 | **A budget of 33–96 eng-weeks in year one** | ~6 eng-weeks assumed | A capacity decision, not a research question. |

**And one input that is missing rather than negative — the honest gap in this whole section:**

> 🔴 **Q39 — what actually drives Indonesian agent platform selection — has no Tier A or Tier B source anywhere.** `03-ops-scan.md` §4c.7.2 ranks the drivers on structural evidence and puts **inventory uniqueness — the stated answer, and the entire basis of D2/D3 — fourth of five**, behind incumbent/workflow consolidation, credit terms and rate. **"The stated answer is the driver for which we found the *least* supporting evidence, while the drivers with the most evidence behind them are ones SatuSatu either cannot win or cannot afford to win."**
>
> **10–15 agent interviews would settle it and cost almost nothing.** It is the single cheapest experiment that would change the shape of this register, and it is the one I would run alongside GATE 0.

---

## 12. THE SEVEN INPUTS THAT WOULD MOVE THIS RANKING MOST

Ordered by how much the register changes when each is answered, not by how hard they are. **Six of the seven are internal or contractual and cost no engineering.**

| # | Input | Currently | What it changes | Cost to close |
|---|---|---|---|---|
| **1** | **GATE 0 / Q29 — is Pool B actually exclusive?** | Unanswered | 🔴 **Thesis-level.** A failure removes 6 D2 rows, 3 D3 rows and the whole tier-by-supply-source pricing architecture, and rebuilds the register around D0/D1 only. | **One day.** Internal. |
| **2** | **The displacement budget in eng-weeks** (§1c assumes 6) | A decision nobody has made | Moves the line in §6c. At 12 eng-weeks OPP-D2-3 and OPP-02 come in; at 24, OPP-01 and U-02; below 4, only the zero-engineering lane survives. **This is the single most consequential assumption in the file.** | **One conversation.** |
| **3** | **Q11 / P2 — may traveller content reach a third-party model provider under Indonesia's PDP Law?** | Unanswered; only trace is an analyst flagging it as material for Indonesian BPO | Binary. A "no" closes the vendor route at the egress point and **flips OPP-04 from a configuration purchase to an engineering project that cannot be staffed.** Three of four fallbacks fail the capacity constraint outright; the only survivor is in-region hosted inference, **whose availability and price are unverified.** | **One counsel brief**, jointly with P3. |
| **4** | **Q8 / Q7 — concierge minutes per pass, headcount, current AHT** | Unknown. The entire minutes column in the decomposition is `[INFERENCE]` and is labelled *"Replace them; do not cite them."* | Every D0 sizing. OPP-01's break-even swings from **4,603 passes to 16,975** across the band. | **One week of queue data.** |
| **5** | **Q32 / open item 1 — real Pool A and Pool B margin, from matched SKUs** | Both bands are `[INFERENCE]` | The feasibility screen for **every** row. Four API calls with credentials SatuSatu already holds convert the Pool A band from inference to verified: `product/list?countryCode=ID` → bucket by `cityId` 2 (Bali) and 112 (Ubud) → `product/options` on a matched sample → compare `nettPrice` vs `minimumSellingPrice` vs Klook/Viator live retail. **Highest value per hour on the whole list.** | **One hour.** |
| **6** | **Q31 / 4c-G2 — the conceded B2B spread on Pool B** | An internal pricing decision, not research | **Every D2/D3 contribution figure scales linearly off it.** At 8% retained rather than 12%, OPP-D2-3's break-even rises from ~5 to ~8 base partners. | **One decision.** |
| **7** | **Q39 / 4c-G7 — what drives Indonesian agent platform selection** | 🔴 **Nothing found. No Tier A or B source exists.** Inventory uniqueness ranks 4th of 5 on structural evidence. | The shape of D2 and D3 — whether SatuSatu is selling exclusivity, rate, credit or workflow. | **10–15 agent interviews.** Cheapest experiment in the study by impact. |

**Two further numbers that are load-bearing and unverified, flagged so the red team does not have to find them:**
- **Cost per stranding incident — assumed $600** `[ASSUMPTION, unverified]`. It sets the IDIER kill threshold at 0.5% and it sets OPP-03a's entire impact. Internal incident, refund and goodwill history closes it.
- **Loaded cost of an eng-week at SatuSatu — assumed US$679** `[INFERENCE, flag 4c-G1; no Indonesian engineering salary source was ever collected]`. **Every dollar break-even in this file scales 0.57×–1.63× across the band.** And even the correct payroll figure is the *wrong price*: with zero dedicated capacity the true cost of an eng-week is the D2/D3 roadmap slip it causes, so **every break-even here is optimistic by construction and the direction of error is known.**

---

## 13. WHAT THIS REGISTER SAYS, IN FIVE LINES

> ⛔ **AMENDED BY §6 RED TEAM.** Lines 1 and 5 below are withdrawn as written; the amendments follow each.

1. **The highest-return AI-adjacent actions available to SatuSatu are not AI.** ~~$140,500 of annualised impact at reference volume sits in twelve zero-engineering rows costing 3.7 eng-weeks~~ — contract clauses, a schema field split, an FX conversation, a rate sheet, and a ranking rule.
   🔴 **AMENDED:** the *qualitative* claim survives and is the register's best finding. **The number does not.** Recomposed: **$12,160–$51,160 at R**, after removing one duplicate ($39,000), one probability-unweighted supplier concession ($21,350), one figure booked in both lanes ($16,160), and $12,840 of TARGET, one-off and per-episode items. **And the lane's "3.7 eng-weeks" conceals ~14 person-weeks of BD, ops, legal and content time that nothing in the register prices.** §6.4, §6.5.
2. **The reason is the cost structure, not a lack of ambition.** At **US$0.079 per concierge-minute** and **~7% net on Pool A**, metered AI priced against a US/EU labour baseline is value-destroying on the larger pool and marginal on the smaller one. **Pool A cannot carry a metered AI touch at any published vendor price.**
3. **One field is worth more than one direction.** A declared `availability_model` per Pool B SKU (1 eng-week + days of ops) is prerequisite to eight rows, to reconciliation, and to the entire B2B strategy. **Closing Pool B's availability gap is worth more than building D3.**
4. **D3 cannot be populated honestly today**, and the four conditions that would change that are named in §11a. Three of them cost no engineering.
5. **Everything downstream of GATE 0 is provisional.** ~~One day of catalogue cross-checking decides whether 9 of the 24 rows survive.~~
   🔴 **AMENDED: it is not nine. GATE 0 kills 8 of 24 ranked rows and 4 of 6 `[UNSTAFFABLE]` rows outright; re-prices ZE-01, ZE-02, ZE-09, OPP-02 and OPP-03a through the Pool B margin band; re-opens `{{B2B_PRICING}}` (Q15) which the Head of Product has already signed off; invalidates the §1a feasibility screen for Pool B; and removes the only High-defensibility claim in the file. Seventeen of twenty-four rows, one pricing architecture and one moat.** §6.10.

6. 🔴 **ADDED BY RED TEAM — the sixth line, and it should be the first.** Every dollar in this file is `R × parameter`, and `R` is an [ASSUMPTION]. **At 300 bookings/month exactly one CURRENT-basis row clears a $3,000/yr materiality floor. At 150, none does — and several kill criteria cannot reach their own sample sizes inside their own deadlines, so they will expire rather than decide.** `{{SCALE}}` is internal and takes hours. **Count the bookings before funding anything.** §6.11, §6.19.

---

*End of draft Opportunity Register. Nothing above has been rounded, softened, or promoted across a status marker. Where a number does not exist, the row states a break-even threshold and the threshold is stated. Ready for Step 5c red-team.*










---
---

# 6. RED TEAM

**Step:** 5c (Red-Team Skeptic) · **Date:** 2026-07-27 · **Target:** §§0–13 above.
*Numbered "6" per the Step 5c brief; sits after §13 in document order and supersedes the ranked tables in §6a/§6b/§6c, which are marked inline below.*

**Method:** every candidate attacked on the eleven tests in the brief, using only evidence already on disk (`00-internal-context.md`, `00-scope.md`, `01-landscape.md`, `02-competitor-matrix.md`, `03-ops-scan.md`, `99-open-questions.md`). No web access was used. Where I could not verify, I have written **unverified** rather than filled the gap.

**Standard applied:** a row survives if (a) its mechanism is verified, (b) its number is not a restatement of another row's number, (c) it clears a materiality floor at a volume the company plausibly has, and (d) nothing else in this register contradicts it. Rows that fail (b) are the largest category and were the least expected.

---

## 6.0 Verdict in one paragraph

**The register's analysis is unusually honest and its arithmetic is unusually traceable — which is exactly what made it attackable.** Six candidates are killed, eleven are downgraded, and the zero-engineering lane's headline of **$140,500/yr is overstated by between 2.8× and 12×** depending on how generously you treat the one mix-shift assumption it books twice. The structural fault is not in any single row. It is that **the ranking metric — impact per eng-week — assigns `∞` to any row whose cost is human rather than engineering**, and the register then stacks **~13 person-weeks of BD, ops, legal and content time into a single quarter and prices none of it.** Underneath that sits a deeper problem: every dollar in the file is `R × parameter`, `R` is an [ASSUMPTION] chosen for comparability, and the defence that "the ranking is insensitive to R" is false — it is insensitive to R only if the parameters are uncorrelated with volume, and at least four of them are not.

---

## 6.1 🔴 THE KILL LIST

**Six candidates die. Two are the #1 and #2 rows of the zero-engineering lane. One is the first row above the §6c budget line.**

| # | ID | What dies | Why it dies |
|---|---|---|---|
| **K-1** | **ZE-05** — 1.50% GlobalTix FX markup | **The $29,250 and the rank-1 position. The 2-hour question survives.** | Three independent failures, and they compound. See §6.2. |
| **K-2** | **ZE-02** — margin-weighted ranking rule | **The row, entirely. Mechanism folds into ZE-01; 1.0 eng-week returns to the budget.** | It is the same money as ZE-01, from the same denominator, with the same constant, capped by an assumption. See §6.3. |
| **K-3** | **OPP-04** — pre-purchase AI enquiry handling | **The row at any per-resolution price.** | Its break-even requires pointing the meter at Pool B enquiries only. **You cannot know a traveller's pool before they ask.** On the blended queue the required incremental conversion is ~42%, and the register's own word for 57% is "implausible." See §6.6. |
| **K-4** | **OPP-D2-4** — list Pool B on a third-party rail | **The row, entirely.** | A $6,000/yr trade against the only High-defensibility asset in the file, executed with a counterparty that has demonstrated direct-sourcing behaviour, **before** the exercise (GATE 0) that would identify which SKUs are safe to trade. See §6.7. |
| **K-5** | **ZE-11** — machine-readable / assistant-callable catalog | **The row as a funded 0.5-eng-week Now-slate item.** Retain P8 (robots audit, hours) and schema.org markup as ≤0.1 ew catalog hygiene, with no AEO thesis attached. | The register's own top-risk field concedes that "every AEO tactic list is inference dressed as method," confidence on magnitude is 30%, the real channel (distribution *into* the assistant) is a commercial act the incumbent already occupies, and the kill criterion depends on AI-referral segmentation that may not exist (Q10). See §6.8. |
| **K-6** | **OPP-D2-5** — partners self-serve routine questions | **The row, out of the ranked table into §7.** 2.0 eng-weeks returned. | The register itself calls it "sized against a cost that does not yet exist — the weakest sizing basis in the register," records true deflection on the availability loop at **~0%**, and gates its own start on a 40-contacts/month queue that requires ~20 transacting partners who do not exist and are GATE-0-gated. **A row that cannot start and cannot be sized does not belong in a ranked table.** |

**Eng-weeks returned to the displacement budget by the kills: 3.5 of 20.0 in the engineering lane and 1.5 of 3.7 in the zero-engineering lane.** That is the one unambiguously good news item in this pass: killing these rows buys back **more capacity than the entire Now slate spends on ZE-01, ZE-03, ZE-09 and ZE-12 combined.**

---

## 6.2 🔴 K-1 · ZE-05 — the $29,250 that assumes a supplier concedes because it is asked

**What is real.** The 1.50% markup on every non-SGD settlement currency and the `markup: 0` on SGD are **[VERIFIED, Tier A]** — read from the live GlobalTix currency object, recorded at `03-ops-scan.md` H10. Nothing below disputes the field.

**Failure 1 — the counterparty has no motive, and the file says so twice.**
`01-landscape.md` §8.5: GlobalTix is *"a rational, profitable operator with no reason to concede margin to a 253-SKU reseller"* — cash-flow positive on a ~US$5M Series B while issuing 25M tickets/yr across ten countries. `01-landscape.md` §9 Force 4 goes further: *"A 253-SKU reseller has no negotiating position in that chain and will be the last to receive any improvement and the first to absorb any compression."* The register cites §8.5 in its own Confidence field, scores the row **60%**, and then books **100% of $29,250** into the ranked table and into the §13 headline. **A 60%-confidence number entered at face value is not a forecast, it is a rounding of an opinion.**

**Failure 2 — the SGD leg creates a new exposure that the register does not price, and it contradicts ZE-04 in the same lane.**
The row's actual mechanism is not "negotiate the markup away" — it is "settle in SGD, where the markup is zero." That is a *better* ask than a margin concession (SGD is the supplier's home currency). But it moves the FX leg onto SatuSatu. PT Tiptip Network Indonesia's functional currency is IDR; its storefront charges USD. Settling in SGD means SatuSatu buys SGD against IDR or USD on **100% of Pool A payables (~$1.76M of settlement at R)**. IDR↔SGD is a thin cross with no direct interbank liquidity for a small Indonesian corporate — the bank routes IDR→USD→SGD and charges twice. **No collected source contains an IDR/SGD or IDR/USD spread; this is unverified and the register says so.**

🔴 **The contradiction the register does not surface: ZE-04, one row above in the same lane, exists to *eliminate* unhedged FX exposure and cites Bank Indonesia Regulation No. 17/3/PBI/2015 in support. ZE-05 proposes to *create* one, on the entire Pool A cost base, to save 150 bps.** Two rows, same lane, both 0 eng-weeks, both ranked, strategically opposed. Neither card mentions the other.

**Failure 3 — the "✅ cross-check" is circular.**
The card states: *"$29,250 is 21.4% of Pool A's net gross profit at R ($136,500) — which reproduces `03-ops-scan.md` H12's independently derived '~15% of Pool A gross / ~21% of net' almost exactly ✅."* H12 **is** `1.50% × Pool A GMV ÷ Pool A net GP`. Reproducing it is the same division performed twice. It is not corroboration and it must not be presented as a tick. *(The same defect appears in §1a: "$3.00 retained per booking" cross-checked against §4c.3.4's "$3.00 retained per booking" — `12% × $25` compared against `12% × $25`.)* **Two of the register's three headline cross-checks are tautologies.**

**Failure 4 — the downside tail is unpriced.** The card's own Top risk is *"raising it invites a rate review that goes the wrong way."* Against Force 4 that is not a footnote; it is the documented direction of travel for a reseller of this size. No expected value is assigned.

**Expected value, stated so it can be argued with.**
`P(GlobalTix contractually accepts SGD settlement)` — unverified (Q37 open). Generous, because SGD suits the supplier: **0.6**. `P(SatuSatu's own IDR→SGD all-in spread lands materially below 150 bps)` — unverified, thin cross, small corporate, two legs: **0.45**. → **EV ≈ 0.27 × $29,250 ≈ $7,900/yr at R**, before the new exposure and before the tail. **At 300 bookings/month, EV ≈ $2,370.**

> **Verdict: KILLED as a sized opportunity and removed from rank 1. RETAINED as a two-hour action** — ask the account manager about SGD settlement and `directContractPrice` **in the same week you ask your bank for an IDR→SGD and USD→SGD corporate quote.** Both halves or neither. Do not report the gross number to anyone until the second half exists.

---

## 6.3 🔴 K-2 · ZE-01 and ZE-02 are one mechanism counted twice

**The brief asked whether $39,000 + $39,000 is the same money. It is, and the provenance proves it.**

`03-ops-scan.md` §4b.3.2 closes with a single five-item recommendation list. **The register turned items 1–2 of that list into ZE-01 and item 3 into ZE-02, then sized both against the same constant (G12: ~20 net points per unit of GMV diverted), on the same denominator (Pool A GMV $1.95M), for the same outcome (Pool A → Pool B mix shift).** They are not two opportunities. They are two steps of one intervention, split across two ranked rows, which then appear as **rank 1 ($130,000/eng-week) and rank 2 ($39,000/eng-week)** of the zero-engineering lane.

**Three further problems with the shift assumption itself, which apply to the combined row:**

1. **The cap is the tell.** ZE-02's formula carries `incremental_shift = 0.05 / 0.10 / 0.10` — note the base and high are identical — "capped jointly with ZE-01 at a 0.20 total shift, so the two rows do not sum to nonsense." ZE-01's own band already runs to 0.20. **ZE-02 therefore adds nothing that ZE-01's high case does not already contain.** The register has taken one parameter's high case, halved it, and booked both halves as independently ranked rows.

2. 🔴 **The substitution assumption is false precisely where the verified defect lives.** ZE-01's own Key assumptions field concedes Pool B substitution is *"untrue for branded parks (USS, Waterbom)."* But the **only VERIFIED instance** of the inherited sold-count defect is **Universal Studios Singapore's "99k+ sold"** — a branded park. The mechanism is proven on the SKUs where the remedy provably does not work, and assumed on the long tail where nothing has been observed. A 0.20 shift means **$390,000/yr of Pool A GMV — 1,560 bookings — redirected to a Pool B that carries 4,200 bookings/yr in total.** That is a **37% increase in Pool B volume** produced by removing a badge and adding a ranking weight.

3. 🔴 **ZE-02's own latency gate suppresses the shift it is sized on.** ZE-02's Top risk is unambiguous: *"margin-weighted ranking must be **gated** on confirmation latency, not merely annotated with it. Any instant-confirm-required query must return only `allotment` / `freesale_capped` / `static_schedule` SKUs."* ZE-09 assumes only **30% / 50% / 70%** of Pool B can leave `request_to_book`. So at base, **half of Pool B is gated out of exactly the queries the margin boost is supposed to win.** The register never nets the gate against the shift. The sized impact and the safety rule are computed as if they do not interact.

> **Verdict: ZE-02 KILLED as a row.** The ranking-rule config change is retained inside ZE-01's scope (it is the same source recommendation list, and it is a config value, not a build). **1.0 eng-week returns to the budget — the largest single engineering line in the zero-engineering lane.**
> **ZE-01 DOWNGRADED:** keep rank 1 **on cost**, withdraw the $39,000. **Size it as the register says it should be sized — at its break-even: 41 redirected bookings, ever.** The row survives on two grounds that need no shift assumption at all: the fix costs hours, and *displaying another platform's transaction count as your own is a live trust and advertising-accuracy exposure* (`03-ops-scan.md` §4b.3.2 point 2). **Do it because it is wrong, not because it is worth $39,000.**

---

## 6.4 🔴 The zero-engineering lane's headline, recomposed

The $140,500 decomposes exactly as follows, and every one of the ten components fails at least one test.

| Row | Booked | Basis | Verdict | Sized after red team |
|---|---:|---|---|---:|
| ZE-01 | $39,000 | CURRENT | Shift assumption unbounded; substitution false on the verified SKUs | **break-even only** |
| ZE-02 | $39,000 | CURRENT | **Same money as ZE-01** | **$0 — KILLED** |
| ZE-05 | $29,250 | CURRENT | 60% confidence × unquantified own-spread; circular cross-check | **~$7,900 EV** |
| ZE-07 | $16,160 | **TARGET** | **Same $16,160 as OPP-D2-3, same 10 partners** | **$0 — unsizeable** |
| ZE-10 | $7,440 | **TARGET** | Avoided cost of a credit function the register recommends never building | **$0 — a policy, not an opportunity** |
| ZE-04 | $3,000 | **TARGET, per-episode** | Episode frequency **unquantified** (4c-G9); largely delivered by ZE-10's wallet | **$0 — a compliance control** |
| ZE-06 | $2,400 | CURRENT | **One-off** avoided labour — must never enter an annualised total | **excluded from the run-rate** |
| ZE-08 | $1,920 | CURRENT | R-independent; assumes 240 SKUs/yr onboarded against a 150–250-SKU Pool B base (≈100% growth) | **$1,920, SKU-contingent** |
| ZE-03 | $975 | CURRENT | Survives | **$975** |
| ZE-09 | $1,365 | CURRENT | Survives on dependency, not on this number | **$1,365** |
| **Total** | **$140,510** | | | **$12,160 – $51,160** |

**The band, and how to read it.**
- **$12,160** = hard floor. Only mechanisms that are verified, CURRENT, recurring, non-double-counted, and probability-weighted: ZE-03 + ZE-08 + ZE-09 + ZE-05's EV.
- **$51,160** = generous ceiling. The above **plus the single mix-shift credited once at the register's own base case** ($39,000), which requires the unbounded 0.10 shift assumption to hold on the long tail.

🔴 **The headline is therefore overstated by 2.8× (generous) to 11.6× (strict). The "≈103% of Pool A's entire net gross profit" cross-check is not evidence that the leak is the size of the pool. It is evidence that the total was built by adding CURRENT recurring cash, TARGET contingent revenue, per-episode avoided losses, one-off labour savings, and one number entered twice — and that nobody re-read the sum against the parts.** The register's §6a warns "do not read the total as a run-rate" and then §13 line 1 reads it as a run-rate.

**Category audit of the total:** of $140,510, **$26,600 (19%) is TARGET-basis on a B2B business with zero partners**, **$2,400 (2%) is one-off**, **$3,000 (2%) is per-episode at unquantified frequency**, and **$39,000 (28%) is a duplicate.** Only **$72,510 (52%) was ever CURRENT recurring**, and most of that is one unbounded assumption.

---

## 6.5 🔴 The ranking metric hides the register's largest cost — ~13 person-weeks in one quarter

**This is the finding I would put in front of the CEO first, ahead of any individual row.**

`impact / eng-week` awards **`∞`** to any row that consumes no engineering. Five of the twelve zero-engineering rows and two engineering-lane rows carry `∞`. That is not a ranking; it is a divide-by-zero dressed as a result, and it **systematically promotes exactly the rows whose real cost is invisible.**

**ZE-07 is the clean case the brief asked about.** Costed at **0 eng-weeks**. Its actual bill, from its own card: **30 agents × 14.5 BD-hours = 435 hours.** That is **~11 working weeks of one person's undivided time**, or roughly one full-time FTE for the entire 90-day test window. Against `{{CAPACITY}}` = *"none dedicated"*, `{{COST_BASE}}` = **UNKNOWN**, and a `$8/hour loaded BD rate` that `03-ops-scan.md` §4c.0 flags as *"Unverified — no Indonesian BD salary source was collected"* — **the register has imported a price for a role whose existence it never established.** There is no evidence in any file that SatuSatu has a BD or partnerships function.

**And ZE-07 cannot start when the slate says it does.** Its own Data-required field: *"Pool B rate card at agent net rates — **N, an internal pricing decision (Q31, flag 4c-G2)**."* **You cannot send a rate sheet without a rate card.** §6c places ZE-07 in step 1 of the Now slate; it is blocked behind a pricing decision nobody has made.

**The full non-engineering load the §6c slate commits to in one quarter, summed from the register's own numbers:**

| Item | Human hours | Source |
|---|---:|---|
| ZE-07 — outreach to 20–40 named agents | **435** | own card |
| ZE-09 — Pool B classification across 150–250 SKUs | 30–60 | own card |
| ZE-01 — surface audit ("days") | ~16–24 | own card |
| P4 — eval harness, 100–200 labelled examples per task | 8–16 | §2 |
| GATE 0 — catalogue cross-check | ~8 | §3 |
| Q39 — 10–15 agent interviews (register's own "cheapest experiment") | ~30–60 | §11a |
| ZE-12 — weekly zero-result review, recurring | ~26/quarter | own card |
| ZE-05 / ZE-04 / ZE-03 / ZE-06 — treasury, legal, audit | ~10 + counsel | own cards |
| **Total** | **~565–645 h ≈ 14–16 person-weeks** | |

🔴 **The register applies its binding-constraint discipline to five engineers' weeks and then books fourteen person-weeks of BD, ops, legal and content time at zero.** At `{{COST_BASE}}` = UNKNOWN, nobody knows whether that capacity exists. **If it does not, the zero-engineering lane is not cheap — it is simply unfunded in a different currency.**

**Correction required:** every `∞` in §6a and §6b must be replaced with **person-weeks**, and the Now slate must carry a **two-column budget: eng-weeks AND person-weeks.** Until then the ranking is not comparing like with like.

---

## 6.6 🔴 K-3 · OPP-04 — the meter cannot be pointed at Pool B

The register's rescue of OPP-04 is a scoping instruction: *"vendor AI customer service clears **only if it is pointed at Pool B enquiries.** Pointed at Pool A it is value-destroying at every published price."* Required incremental enquiry→booking conversion: **15% on Pool B** at $0.99/resolution, versus **57% on Pool A**, which the register itself calls *"implausible."*

🔴 **The instruction is operationally unimplementable, and its impossibility is definitional rather than a matter of effort.** A pre-purchase enquiry arrives on WhatsApp *before* the traveller has chosen a product. **You do not know which pool an enquiry belongs to until it has been answered** — and by then the resolution has already been metered. There is no intake attribute, no routing key, and no queue split that could carry it: `00-scope.md` §2.5 records exactly **two** WhatsApp numbers, general and Pass concierge, split by **entitlement**, not by supply pool.

**So the meter runs on the blended queue.** Weighting the register's own two requirements by its own R mix (65% Pool A / 35% Pool B by GMV):

`0.65 × 57% + 0.35 × 15% ≈ **42% required incremental enquiry→booking conversion**`

**42% is not achievable and the register has already said so about a lower number.** At $3.00/resolution the requirement rises past 100%. At $0.50 it is ~21% — still above any conversion rate evidenced anywhere in the file.

**Three compounding problems the register raised and then did not carry into the verdict:**
- **The meter's definition belongs to the vendor.** Intercom's own support engineer: a resolution counts *"if the customer clicks 'that helped' **or does not respond to the answer and leaves the conversation**."* One customer reports **confirmed 6–7% against assumed ~60%**. So the denominator of the cost inflates in exactly the cases where the value is zero.
- **Silent abandonment is scored as success** — and for a pre-purchase travel enquiry, silence is a lost booking, which is the numerator of the value.
- **The advertised product is a human.** `03-ops-scan.md` §4a.2.5: 64% prefer companies did not use AI for CS; 89% want a human option. The Pass markets *"a real Bali local."*

> **Verdict: KILLED at any per-resolution price.** The coverage, latency and language benefits are real and remain the correct justification — but they cannot be bought on a meter whose denominator is the whole queue. **If OPP-04 returns, it returns as a fixed-cost arrangement (subscription or in-region hosted inference) whose price is UNVERIFIED and must be obtained before, not after, a decision.** As an unpriced option it is not a candidate; it is a procurement question. Gate P2 still precedes everything.

---

## 6.7 🔴 K-4 · OPP-D2-4 — selling the moat for $3.00 a booking

This row is the register's own "sharpest trade," ranked **2nd** in the engineering lane and named as the **first row above the §6c line at a 6.2-eng-week budget.** It should not be above the line; it should not be in the register.

**What it sells.** §9's closing statement names the only High-defensibility asset in the entire file: *"a contracted, classified availability model over **exclusive** direct-contracted Balinese long-tail supply (ZE-09 + ZE-06 + GATE 0)."* OPP-D2-4 puts that supply on a third party's rail for **$6,000/yr at 2,000 bookings — $3.00 per booking.**

**Five reasons it dies, in order of force:**

1. 🔴 **Sequencing is impossible.** The mitigation is *"list the replaceable part of Pool B; withhold the irreplaceable."* **GATE 0 is the exercise that determines which SKUs are replaceable** — and it is unanswered until 2026-08-07. Before GATE 0 you cannot execute the mitigation. After GATE 0 there are only two outcomes and both refute the row: **if Pool B is exclusive**, you have just located the asset and are proposing to hand part of it to the party best placed to take it; **if Pool B is not exclusive**, there is nothing exclusive to list, the operators are already on the rail, and the row reduces to adding a second margin taker to inventory already carrying Pool A economics.
2. 🔴 **The counterparty has demonstrated the exact behaviour.** GlobalTix holds an **Indonesian SOE channel-manager mandate (InJourney / Borobudur, 2025-10-07/08, Tier A)**, a **Travel Agent Licence (TA03367)**, an Indonesian GM, and a `/resellers/` page shipping D3's pitch **since at least 2022-12-29**. It will sell the same Balinese operator real-time availability, a booking page **and** channel distribution for **USD 100 one-time + 3%** (`02-competitor-matrix.md` §5b.5). **The register calls this "the clock on Pool B exclusivity" in §3 and then proposes to hand it the operator list.**
3. **"Ingestion is disclosure" cuts the wrong way.** The register notes GlobalTix already sees SatuSatu's Pool A demand signal through `product/list`, `checkEventAvailability` and `booking/reserve`. That is true — and it is precisely why listing Pool B is the marginal harm: **operator identity is the one thing the current integration does not disclose.**
4. **The safe counterparty is unverified and the unsafe one is not.** The preference for Prioticket / Experience Technology Group or Holibob rests entirely on Indonesian SKU depth that `02-competitor-matrix.md` §8b item 2 records as **the open item on which "the entire rank-1 second-aggregator recommendation is contingent."** So the recommended version of this row is unverified and the executable version is the dangerous one.
5. **Irreversibility.** The card's own Failure mode: *"Exclusivity loss is irreversible."* A row whose downside is unbounded and irreversible, whose upside is $6,000/yr, and whose mitigation cannot be executed in the required order, is not a trade. It is an option written against the company's only moat for a premium of three dollars a booking.

> **Verdict: KILLED.** Re-open only as **salvage**, and only when all three hold: (a) GATE 0 has **failed** or ZE-07 has **failed**, i.e. the exclusivity thesis is already disproven; (b) ETG/Holibob Indonesian depth is verified; (c) the listed set is explicitly the SKUs GATE 0 found already self-listed. **Distribution reach is worth buying when you have nothing to lose, not while you still do.**

---

## 6.8 K-5 · ZE-11 — an AEO thesis the register itself labels inference

Killed as a funded row on the register's own words. Its Top-risk field concedes: *"`llms.txt`-style conventions have no evidence of retrieval effect in any collected source; **no assistant publishes its retrieval criteria, so every 'AEO tactic' list is inference dressed as method**."* Confidence on magnitude: **30%.** Sizing: none.

Three additional strikes:
- **The channel the incumbents actually won is not markup.** `00-scope.md` §4 Group 5 and `01-landscape.md` §9 Force 2: Klook is a first-party ChatGPT app; Viator shipped as a callable app; the flow ends *"tap View on Klook."* **Distribution into the assistant is a commercial deal, not a schema.org attribute.** The register's own kill criterion admits this ("a null result on markup does not kill (5)") — which means the row's fundable half and its promising half are different things wearing one ID.
- **The base is contracting.** AI-referral upside is applied to a Bali session base whose underlying arrivals are **−1.77% Jan–May 2026** while Indonesia is **+7.7%**.
- **The kill test may be unmeasurable.** It requires AI-referral segmentation in analytics, recorded as **Unknown (Q10)**.

> **Verdict: KILLED as a 0.5-eng-week Now-slate row. RETAIN two fragments, unranked: (i) P8 — check the robots configuration, hours, because it is a binary gate and costs nothing; (ii) schema.org markup on Pool B SKUs only, as ≤0.1 ew of routine catalog hygiene, with no traffic claim attached.** Do nothing about Pool A prose — on that the register is right (C-08).

---

## 6.9 OPP-01 — the labour baseline holds, and the register still got the row wrong

**The brief asked me to test whether $0.079/concierge-minute is minimum wage rather than fully loaded. It is not, and I will not manufacture a kill here.**

`03-ops-scan.md` §4a.5.3 is the best-constructed input in the file. It starts from a **market band above generic CS** (Rp 4.5/6.5/9.5m) explicitly *because* the role carries English fluency and destination expertise; grosses up by **THR ×1.0833**, **BPJS ×1.11**, and a **non-wage operating load ×1.25/1.40/1.60** that itemises supervision/QA, tooling, workspace, device, recruitment and **attrition replacement at 25–35% Indonesian BPO attrition**; applies **12–18% shrinkage**; and triangulates against two independent sources ($6,000–9,000/FTE Jakarta; Plane $9,989 total employment cost). **The conclusion does not reverse. Break-even AHT against $0.99 is 12.5 minutes; the deflectable tasks are 2–3 minutes. That finding stands.**

**Two real gaps, neither of which reverses it:**
- 🔴 **No 24/7 shift coverage is modelled.** L12 assumes **1,780 productive hours from a 40-hour statutory week**, and the gross-up contains **no night-shift or public-holiday differential**. Covering a clock for a market drawing 39% English-first arrivals across UK/US/EU time zones — and issuing dawn instructions for Batur sunrise and early temple visits — requires ~4.2 FTE per continuously-covered seat. **The register prices a 40-hour cost per minute for a product marketed on availability.** This does not move OPP-01 (it would need a ~12.5× increase) but it **strengthens OPP-04's coverage argument** and it means the "$0.079" must never be quoted as the cost of an *available* minute.
- **Wage escalation is +5.97% to +7.26%/yr, two years running (L5).** Over a three-year payback the baseline rises ~20%. Immaterial to the conclusion; material to any multi-year model.

### 6.9.1 🔴 The reverse case the register never ran: the concierge is a capacity constraint, not a cost line

**This is a modelling error, not a nitpick, and everything needed to catch it is in the register's own §4a.7.**

One concierge FTE = **1,780 productive hours = 106,800 minutes/year.** Against W1 (32 / 100 / 276 minutes per pass):

| Concierge minutes per pass | Passes servable per FTE per year |
|---|---:|
| 32 (low) | **3,338** |
| **100 (base)** | **1,068** |
| 276 (high) | **387** |

R assumes **2,400 passes/yr**, which requires **0.7 / 2.2 / 6.2 concierge FTE.** Concierge headcount is **UNKNOWN (Q7)**. `00-scope.md` §2.5 records **one** dedicated Pass concierge WhatsApp number. **If SatuSatu runs one or two concierges, the Pass is capacity-capped somewhere between ~400 and ~2,100 passes per year — today, before any growth.**

**If that is true, the money mechanism on OPP-01 is (a) GMV lift, not (d) cost-to-serve, and the register's number is wrong by a factor of five.** Compressing itinerary build by 30% of 25 minutes frees 7.5 minutes of 100, raising throughput per FTE by **8.1%**. On a 2,400-pass base that is **~194 additional passes**; at the Pass ladder ($59.95 / $104.95 / $144.95) even a conservative $40 contribution per pass gives **~$7,760/yr against the register's $1,422** — moving OPP-01 from **9th of nine ($356/eng-week) to roughly 2nd ($1,940/eng-week).**

> **Verdict on OPP-01: NOT KILLED. RE-OPENED, and the register's ranking of it is unsafe.** The flagship D0 idea was scored last on a basis (cost-to-serve) chosen before anyone checked whether the constraint was cost or capacity. **Do not fund it and do not dismiss it. Answer Q7 (headcount) and Q8 (minutes per pass) and Pass utilisation — one week of queue data, the same week that closes Q8 — and re-score.** If utilisation is low, the register's ranking stands and OPP-01 stays last. P3 (liability, and the *"a real Bali local"* representation) gates it either way.

**One further methodological consequence.** §6 asserts *"the ordering is robust to R; only the absolute figures move."* That is true of R and **false of the parameter bands**, which are not correlated across rows. Run OPP-01 at its own high case (60 min × 40% compression × $0.138) and it earns $7,949/yr — 4th, not 9th. Run OPP-02 at its low case and it earns $228 — last. **Half the ranked order in §6b inverts inside the register's own stated bands. R-robustness is not band-robustness, and the register conflates them.**

---

## 6.10 🔴 GATE 0 — it is not nine of twenty-four. It is seventeen, plus the pricing architecture, plus the only defensibility claim in the file.

§13 line 5 says *"One day of catalogue cross-checking decides whether 9 of the 24 rows survive."* §12 row 1 says *"6 D2 rows, 3 D3 rows."* **Both undercount, because both stop at the first order.**

**First order — rows that die outright (8 of 24, + 4 `[UNSTAFFABLE]`):**
ZE-04, ZE-06, ZE-07, ZE-10, OPP-D2-3, OPP-D2-4, OPP-D2-5, OPP-D3-3 · plus U-01, U-02, U-04, U-05.

**Second order — the Pool B margin band itself moves, and this is the one nobody traced.**
`01-landscape.md` §6.3 states the Pool B band's basis explicitly: *"direct contracting at operator net rate, i.e. the full 25–30 points that Arival documents as the wholesaler/receptive convention, **plus exclusivity supporting the upper end**."* **Exclusivity is a term in the margin, not merely a term in the sales pitch.** If Pool B operators are self-listed on GlobalTix and Klook, Pool B prices toward Pool A:

| | Register's Pool B | Non-exclusive Pool B |
|---|---:|---:|
| Gross margin | 27% | ~15–20% *(toward the Arival floor, unverified)* |
| Contribution per booking (D2C, after ~3pp) | **$6.00** | **~$3.00–4.25** |
| A $0.99 metered AI touch, as share of contribution | 17% | **23–33%** |

🔴 **At the low end that breaches §1a's own rejection rule ("more than ~25% of contribution → rejected or re-pointed"). A GATE 0 failure would push Pool B toward failing the register's own feasibility screen** — which means the screen in §1a, the table every model-bearing row is tested against, is itself provisional on an unanswered question. Nothing in §1a says so.

**Third order — the mix-shift constant collapses, taking the zero-engineering lane's biggest number with it.**
G12's ~17 gross / ~20 net points per unit of GMV diverted is `Pool B margin − Pool A margin`. At a non-exclusive Pool B the delta falls to roughly **5–13 points**, i.e. **ZE-01's sized impact halves or worse.** The register presents the zero-engineering lane as the GATE-0-independent safe harbour. **It is not.** By component: **$29,000 (21%) of the $140,500 is directly GATE-0-gated (ZE-07, ZE-10, ZE-04, ZE-06), and a further $78,000 (55%) rides the G12 delta.** 🔴 **~76% of the lane's headline is GATE-0-exposed.**

**Fourth order — two things GATE 1 already signed off get un-signed.**
- 🔴 **`{{B2B_PRICING}}` (Q15) reverts to open.** The Head of Product's answer is *"channel conflict is structurally avoided rather than managed, **because the pools are disjoint on exclusivity**."* Remove exclusivity and the pools are not disjoint, the tier-by-supply-source architecture has no basis, and **risk §1.3(3) — declared resolved at GATE 1 — is live again.** Nobody has modelled that; the register asserts a stated policy exists and tests against it.
- 🔴 **GATE 1 §8.2 finding 2 — "grow Pool B, not total SKU count" — loses its support**, because the only two arguments for it (exclusivity and the margin band) fail together.

**Fifth order — the register's single High-defensibility claim is 100% conditional and §9 does not say so in the row where it matters.** §9's closing paragraph is the one place the file claims a moat. Its subject is *"exclusive* direct-contracted Balinese long-tail supply." Without GATE 0 there is no moat in this document — only a well-argued operations improvement.

> **Corrected count: GATE 0 kills 8 of 24 ranked rows and 4 of 6 `[UNSTAFFABLE]` rows outright; materially re-prices ZE-01, ZE-02, ZE-09, OPP-02 and OPP-03a through the margin band; re-opens Q15; invalidates the §1a feasibility screen for Pool B; and removes the only defensibility claim in the file. **17 of 24 rows, one architecture and one moat.** Nothing — not one eng-week, not one BD hour, not the rate sheet — should be committed before 2026-08-07.**

---

## 6.11 🔴 R — the reference volume, and the volume at which each row dies

**Attacking R directly, as instructed.**

R = 1,000 bookings/mo · ATV $25 · 65/35 Pool A/B · 200 passes/mo → $3.0M annual GMV. It is labelled `[ASSUMPTION — comparability device only]`, and the register's defence is that *"the ranking is insensitive to R."*

**The defence fails on four counts, all of them parameters that move with volume:**
1. **Pool B substitutability.** The mix-shift in ZE-01 requires Pool B to absorb 1,560 diverted bookings/yr — a 37% volume increase on a 150–250-SKU pool where §4c.7.3 puts the *minimum viable* catalogue at 20–60 SKUs. At lower R the absolute shift shrinks; at higher R it exceeds what Pool B can fulfil manually.
2. **Concierge capacity** (§6.9.1) — a step function in FTE, not a linear scalar.
3. **Kill-criterion sample sizes** — n≥500, n≥400, n≥400, n≥300, n≥300, n≥200 across OPP-03a, OPP-01, OPP-02, OPP-03b, OPP-D1-2 and ZE-09.
4. **The margin delta itself**, via GATE 0 (§6.10).

**What can be said about R without inventing a number.** The only observed quantity is **253 SKUs**. Displayed sold-counts are inherited feed values and Q6 is explicitly answered *"unusable as a proxy."* R implies **3.95 bookings per SKU per month** and **~2 bookings per Pool B SKU per month**, each of which requires a human WhatsApp confirmation round (§4c.2.1). It also implies **200 passes/month from a product launched ~May 2026** — three months old, and observed entirely on the rising limb into Bali's July peak (peak-to-trough 1.55×). **Annualising a three-month-old product observed across its seasonal high is the definition of the instability risk §1.3(5) was written to prevent.**

**Materiality floor.** A row must return **≥$3,000/yr** to justify a decision-maker's attention — that is ≈1% of company gross profit at R (~$300k) and ≈4.4 loaded eng-weeks. Applying it:

| Row | Impact at R | Bookings/month at which it falls below $3,000 | Verdict |
|---|---:|---:|---|
| ZE-01 (mix shift, once) | $39,000 | **77/mo** | Survives almost any volume |
| ZE-05 (probability-weighted) | $7,900 | **380/mo** | Dies below ~380/mo |
| OPP-03a | $5,040 | **595/mo** | Dies below ~595/mo |
| ZE-08 | $1,920 | *R-independent; dies below ~375 SKUs onboarded/yr* | **Below floor at R** |
| OPP-02 | $1,896 | **1,582/mo** | **Below floor at R** |
| OPP-01 (cost basis) | $1,422 | **2,110/mo** | **Below floor at R** |
| ZE-09 (direct return) | $1,365 | **2,198/mo** | **Below floor at R** — survives on dependency only |
| ZE-03 | $975 | **3,077/mo** | **Below floor at R** — survives on ratio only |
| OPP-03b | $819 | **3,663/mo** | **Below floor at R** |
| OPP-D1-2 (sized leg) | $790 | *SKU-driven* | **Below floor at R** unless the unsized mispricing leg carries it |

🔴 **Thirteen of twenty-four rows sit below a $3,000/yr floor at the register's own optimistic reference volume.**

**The low case, and what survives it.**

| Scenario | Bookings/mo | Annual GMV | What still clears $3,000/yr on a CURRENT basis |
|---|---:|---:|---|
| Register's R | 1,000 | $3.0M | ZE-01, ZE-05(gross), OPP-03a — **three rows** |
| Plausible mid | 300 | $900k | **ZE-01 ($11,700) only** |
| Plausible low | 150 | $450k | **Nothing.** ZE-01 falls to $5,850; every other CURRENT row is under $1,000 |

**At 150–300 bookings/month — a range entirely consistent with 253 SKUs, one feed, keyword-only search, no AI, a three-month-old hero product and a contracting arrivals base — the correct output of this research is not a ten-row slate. It is two actions: answer GATE 0, and count the bookings.**

**And the sample sizes stop working.** At 300 bookings/mo (105 Pool B), OPP-03a's `n≥500 Pool B bookings` takes **4.8 months, not the 60 days its kill criterion allows**; ZE-09's `n≥200 freesale bookings` takes ~4 months. 🔴 **Several kill criteria cannot reach their own sample sizes inside their own deadlines at any plausible low volume. They will neither kill nor confirm — they will expire, and the rows will survive by default.** That is the worst possible failure mode for a register built on kill criteria.

---

## 6.12 🔴 Bali is shrinking, and eleven CURRENT-basis rows are sized on the assumption that it is not

`01-landscape.md` §1.2, VERIFIED Tier A (BPS Bali): **Jan–Apr 2026 −1.11% y/y; Jan–May −1.77%; Apr −6.41%; May −3.98% — while Indonesia nationally is +7.7%.** The register cites this once, inside ZE-11, and nowhere applies it to a sizing.

**Eleven of sixteen CURRENT-basis rows scale with a base that is contracting:** ZE-01, ZE-02, ZE-03, ZE-05, ZE-09, ZE-11, ZE-12, OPP-01, OPP-02, OPP-03a, OPP-03b, OPP-04. *(SKU-driven and therefore insulated: ZE-06, ZE-08, OPP-D1-2, OPP-D1-3.)*

**Three compounding facts that make it worse than −1.8%:**
- 🔴 **The contracting segment is SatuSatu's segment.** Europe is **−5.9% y/y into Indonesia in May 2026**, and `01-landscape.md` §9 Force 5 notes specifically that European travellers are *"the high-spending, long-staying segment."* UK (4.57%) + France (4.02%) + US (3.95%) are exactly the English-first, USD-comfortable, high-ATV cohort an English-first USD storefront addresses. The growing cohort is Australia — **six hours away, repeat, price-sensitive.** **Both terms of GMV = volume × ATV are under pressure at once, and the register's ATV band ($20/25/30) carries no segment-mix analysis.** A mix drift toward Australian short-haul repeat pulls ATV toward $20, which is a further −20% on every row above.
- **Occupancy and cruise:** Bali star-hotel occupancy **60.88% Dec 2025 vs 63.71% Dec 2024**; sea arrivals **−94.61% m/m in April 2026** as cruise calls ended.
- **Domestic is not the offset:** Bali inter-province domestic arrivals **−8.02% in 2025** while national domestic trips hit a record **+18.95%.** Bali lost share on both sides.

**And no kill criterion is seasonally adjusted.** Bali's peak-to-trough is **1.55×**, Jun–Sep is **38.2% of the year**, and every 60/90-day window in the register runs from T₀ ≈ 2026-08-16 into the Sep–Nov shoulder — i.e. **measured across a falling seasonal limb.** Absolute-volume criteria (OPP-03a's n≥500, ZE-09's n≥200, OPP-D1-2's n≥300) will under-read; share-based criteria (ZE-02's Pool B share of GBV) are partly protected. **Nobody has written down which is which.**

> **Correction required:** every CURRENT-basis row must state whether its driver is volume-linked or SKU-linked, and volume-linked rows must be sized on a **flat-to-−4%** base, not an implicitly flat one. `01-landscape.md`'s own base case for FY2026 is **−1.7% y/y with a low case of −3.7%.**

---

## 6.13 DOWNGRADES — eleven rows that survive with a smaller claim

| ID | Downgrade | Reason |
|---|---|---|
| **ZE-01** | Keep rank 1 **on cost**; withdraw the $39,000; size at **break-even (41 redirected bookings, ever)** | Shift parameter unbounded; substitution false on the only VERIFIED instance (branded parks); its own kill criterion admits impact may be zero. **Do it because displaying another platform's transaction count is a trust and advertising-accuracy exposure**, not because it is worth $39,000. |
| **ZE-05** | $29,250 → **~$7,900 EV**; removed from rank 1 | §6.2. Retained as a two-hour question, bundled with a bank quote. |
| **ZE-07** | $16,160 → **unsizeable**; `0 eng-weeks / ∞` → **~11 BD person-weeks**; blocked on Q31 | Double-counted with OPP-D2-3; sized at 8,000 bookings while its own kill criterion tests **6**; requires a rate card that does not exist; requires a BD function whose existence is unverified. **The experiment is still the right one to run and is still the cheapest decisive test in the file.** |
| **ZE-04** | Ranked row → **unsized compliance control** | Episode frequency **unquantified** (4c-G9); the exposure window is largely closed by ZE-10's wallet, so the marginal FX value is the foreign-partner subset only; PBI 17/3/2015 reaches SatuSatu only per a Tier B summary the register itself routes to counsel. **Right action, fictional number.** |
| **ZE-10** | $7,440 → **$0 sized; a launch policy** | Avoided cost of a credit function the register elsewhere recommends **never building**. Avoiding a cost you were never going to incur is not impact. |
| **ZE-06** | Removed from any annualised total | **One-off** $1,800–3,000. Survives strongly on irreversibility — cost rises with every contract signed and a refused retrofit on an irreplaceable SKU is unpriceable — but it is not a run-rate line. |
| **ZE-08** | $1,920 held, marked **SKU-contingent and R-independent** | 240 SKUs/yr against a 150–250-SKU Pool B base implies ~100% annual Pool B growth, inherited from nowhere. At 60 SKUs/yr it is $480. Also table stakes (§9) and Amdahl-limited to the authoring step. |
| **ZE-09** | Keep, **re-justified** | Direct return $1,365 vs $1,079 cost is a 15-month payback — not a case. Its case is dependency, and **five of the eight rows it is P1 for are GATE-0-exposed.** It still survives a GATE 0 failure on OPP-02 + OPP-03a + OPP-03b alone (~$7,755 combined). It remains the best-designed row in the file: **it asks the operator to adopt nothing**, which is the only requirement the evidence says this supply base can meet. |
| **OPP-01** | **Re-opened**, ranking unsafe | §6.9.1. Wrong mechanism selected; capacity never tested. Do not fund, do not dismiss. |
| **OPP-03b** | Now → **Later** | Starts as a data-collection project unless Q9 (transcript retention) is Yes; **60/75/88%** extraction accuracy in real Bali conditions against a **≥99% precision** requirement is a hard ask, and the register's own automated-share floor (40%) may be unreachable at that precision. |
| **OPP-D1-3** | Raw-MT only; **traffic claim withdrawn** | The cost finding (four to five orders of magnitude between raw MT and post-edited MT) is the strongest arithmetic in the file and survives intact. But the two markets it targets — **India 8.19%, China 7.73%** — are addressed by neither the language **nor the USD currency**, and the register says so itself. **Translation without a payment-and-currency answer moves nothing.** |

---

## 6.14 SURVIVORS — and why each survived

**A survivor with a stated reason is worth more than an unexamined one.**

| ID | Survived because |
|---|---|
| **GATE 0** | It is not a row. It is the precondition for 17 of 24. One day. **2026-08-07.** |
| **P2 + P3** (one counsel brief) | Zero eng-weeks, gates the highest-value D0 area, and P3 additionally gates the *"a real Bali local"* representation which no amount of model quality addresses. |
| **NEW · Q6 — count the bookings** | **Promoted to the first action in the file.** Nothing here can be ranked until `{{SCALE}}` exists. It is internal and takes hours. §6.11 shows the register's conclusions change shape between 150 and 1,000 bookings/month. |
| **OPP-D1-4** (2nd aggregator contracted for zero overlap) | 🔴 **The strongest row in the register and it should be rank 1 of the whole file.** 0 eng-weeks, **R-independent**, and it is the only row that *returns* the binding constraint rather than spending it: **8–29 eng-weeks avoided.** It also survives GATE 0 in both directions. Its one weakness is honest and stated — the overlap concentrates on exactly the head SKUs, so the real form is non-overlapping *territory*, not non-overlapping product. |
| **ZE-09** | See §6.13. Dependency, plus zero operator adoption required, plus it is the only asset in the file an incumbent's capital cannot short-circuit — **conditional on GATE 0.** |
| **ZE-01** | Cheapest fix in the file (0.3 ew), and it is a live trust exposure independent of any margin argument. |
| **OPP-03a** (no Pool B booking sits silently unconfirmed) | **No model.** Attacks F2 — the highest-severity, unrecoverable Pool B failure on fixed-departure products. Break-even is **1.13 strandings avoided per year**, which is a low bar even if the $600/stranding figure is wrong by 3×. Weaknesses: $600 is unverified (4a.8 #8), the n≥500 sample may be unreachable at low volume (§6.11), and operator-fatigue is a real behavioural risk the register flags for AI outbound (§4b.4.5 #5) but not for scheduled outbound, which carries the same risk. |
| **ZE-03** (refund terms) | Survives **on ratio, not magnitude.** $975 is below any floor, but so is 0.2 eng-weeks, and a one-hour audit may close the row for free. The asymmetry is right: one 50-point refund mismatch wipes the margin on five clean Pool A bookings. |
| **ZE-12** (search stops returning nothing) | Survives on a basis the register undersells: **it is the only row that manufactures data the rest of the file lacks.** Query logs close Q10, which gates every ranking, relevance and personalisation question. **Reclassify from (a) GMV lift to instrumentation** and fund it as such. |
| **ZE-06** (sublicensable content grant) | Irreversibility. Not a run-rate. |
| **ZE-08** (AI listing extraction as an ops habit) | Best-evidenced AI finding in the corpus (GYG, Tier A, 100% rollout) and it is a subscription, not a build. **Copy GYG's boundary exactly — the 8 steps they automated, not the 8 they declined to.** Never claim it (§9). |
| **ZE-10** (prepay-only launch) | Right decision, wrong ledger. Keep as policy. |
| **ZE-04** (IDR denomination) | Compliance control. Keep, unsized. |
| **OPP-02** (rendered, never generated) | Survives **on risk architecture, not on its $1,896.** P7 is the single most valuable constraint available: it converts F1 from mandatory-HITL to gate-able and it forecloses U-06 by construction. Below the materiality floor as a saving; above it as a control. **Fund it as the standard for all outbound messaging, and write "generated in-destination prose is prohibited" into the design doc before anyone can argue otherwise.** |
| **OPP-D1-2 (Layer 1 only, ~1.0 ew)** | Survives scoped to Layer 1 deterministic checks. **Layer 2 and Layer 3 unfunded** — no source in this research measures LLM-as-judge accuracy on travel listing copy, and the register says so. Anchor on the one verified fact: the displayed sold-count is a **100% defect rate on one live customer-visible field across the entire Pool A catalog.** |
| **OPP-D3-3** (Indonesian wholesalers carry Pool B) | Survives **weakly, at 40% confidence.** It is the only D3-specific staffable row; it is the one place Pool B's on-request nature is an advantage rather than a handicap (their workflow is already quote-and-confirm); and the counterparties do not compete for the Bali traveller — which is the precise reason OPP-D2-4 died and this did not. Gated on GATE 0 and on the **Golden Rama post-login check**, which `02-competitor-matrix.md` §8b calls "the single most valuable remaining Indonesian check." |
| **OPP-D2-3** (agent seats + prepay wallet) | Survives as *the D2 build in its cheapest defensible form*, **not as a Now item.** 5.0 eng-weeks is its own budget conversation. Do not start before ZE-07 clears on 2026-11-15. Its own §9 label is **table stakes** — a portal confers nothing. |

---

## 6.15 THREE ROWS THAT SHOULD BE IN THE REGISTER AND ARE NOT

Coverage gaps, all cheap, all better-evidenced than several rows that made the ranked table.

| # | Missing row | Evidence | Why it matters |
|---|---|---|---|
| **M-1** | 🔴 **Nightly rate-integrity rule-check** — four deterministic assertions: every live net rate ≥ cost × margin floor; no expired contract serving live rates; every partner's tier matches trailing-90-day volume; a parity crawl of partner storefronts against the contracted floor | `03-ops-scan.md` §4c.5.2, verbatim: *"plausibly under 1 eng-week… **Highest return per eng-week of anything in 4c**"* | It defends against the **highest-severity item in the whole 4c failure table** — net-rate confidentiality or parity breach, whose consequence is *"loss of the contract, i.e. loss of the exclusivity that is the entire D2/D3 thesis."* The source names it as the best row in its own bracket and **the register does not contain it.** |
| **M-2** | **Chargeback and dispute leakage** | H1/H4/H5: travel chargeback rate **0.89% base, 2.0% high**; one chargeback destroys the gross profit of **~9 clean Pool A bookings** (~13 on net); an industry-average rate consumes **8–18% of Pool A gross profit**. Q33 is internal and cheap. Travel disputes **+30% y/y**, friendly fraud named as the driver | **This is the same order of magnitude as ZE-05's entire claim, on better evidence, and the register has no row for it.** Mechanism (e), CURRENT basis, near-zero engineering (3DS/AVS configuration and a dispute-response template). |
| **M-3** | **Pass float and breakage governance** | `00-scope.md` §3 **Amendment C**, approved at GATE 1, elevates deferred-liability/float management to *"its own risk surface."* Precedent: **Sightseeing Pass suspended operations ~June 2025 and stranded prepaid customers**, with Go City publishing a poaching page within days. Go City then tightened **both** float levers in 2025 (redemption 60→30 days; shelf life 24→12 months). SatuSatu's Pass carries a **90-day activation window** | A spine amendment was approved specifically for this and **the register contains zero rows on it.** *"Breakage % **is** the Pass margin"* (`{{PASS_ECON}}`) — the register sizes concierge minutes against a Pass whose margin it never establishes. |

---

## 6.16 RE-TEST OF THE EIGHT RISKS (`00-scope.md` §1.3 (1)–(8))

**Of eight, none is genuinely retired. Two declared resolved at GATE 1 are provisional. Three are materially worse. One is now thesis-level.**

| # | Risk | GATE 1 status | Status 2026-07-27 | Change |
|---|---|---|---|---|
| **1** | **Two-clock problem** — TARGET sized against a hope | Partly resolved: distribution-in confirmed live, so the dedup/quality cluster sizes CURRENT | 🔴 **Not solved — aggregated away.** `{{GROWTH_PLAN}}` and `{{SKU_ROADMAP}}` remain UNKNOWN, and the register now **sums CURRENT recurring cash, TARGET contingent revenue, one-off savings and per-episode avoided losses into one $140,500 headline and one "$150,000 slate."** §6a warns against reading the total as a run-rate; §13 line 1 reads it as one. | **WORSE** |
| **2** | **Curation vs completeness** | Retired — GATE 1 decision 6: the promise will be re-anchored | ⚠️ **Live again by a different route.** ZE-01/ZE-02 re-anchor toward Pool B exclusivity; **OPP-D2-4 sells that same exclusivity to a third party.** Two rows in one register pull opposite ways on the same promise. Killing OPP-D2-4 (K-4) restores the retirement. | **CHANGED** |
| **3** | **D2/D3 channel conflict with D2C** | Resolved — tier by supply source; *"structurally avoided rather than managed"* | 🔴 **Provisional, and nobody says so.** The resolution rests entirely on the pools being **disjoint on exclusivity** — i.e. on GATE 0. A GATE 0 failure un-answers Q15, a question the Head of Product has already signed off. | **PROVISIONAL** |
| **4** | **D3 sells a non-exclusive catalog** | Open (Q24 → superseded into Q29) | 🔴 **Elevated from risk to thesis.** It is now the single question 17 of 24 rows sit on (§6.10). | **ELEVATED** |
| **5** | **Pass economics not yet stable (~2 months of data)** | Flagged | 🔴 **Worse.** The Pass is ~3 months old and the register annualises **200 passes/mo → 2,400/yr** into OPP-01 and OPP-02 without re-flagging it. Worse still, those three months are **entirely on the rising limb into Bali's July peak** (peak-to-trough 1.55×, Jun–Sep = 38.2% of the year). Annualising a peak-observed launch overstates. | **WORSE** |
| **6** | **Single-destination (Bali) concentration** | Declared *"partly obsolete"* — 15 locations, 7 outside Bali, plus Singapore | 🔴 **Worse, and it was retired on the wrong evidence.** The non-Bali SKUs (~27 of 253) are **Pool A feed inventory — coverage without margin.** Every economic input in the register is Bali: ASITA **Bali** 353 members, Bali demand clusters, Bali UMK wages, Bali arrivals, Bali operators. And Bali arrivals turned **negative** in 2026 while Indonesia is +7.7%. **The concentration became more expensive at exactly the moment it stopped being treated as a risk.** | **WORSE — re-raise** |
| **7** | **Inbound-arrival dependency; D2 is the hedge** | Open (`{{D2_PLAN}}` UNKNOWN, Q13) | 🔴 **The hedge is not a hedge, and this is a new finding.** ZE-07 targets **353 Bali ASITA members** — domestic Indonesian agencies whose volume is a **derivative of the same Bali arrival number that is falling.** D2 as specified concentrates the exposure it was supposed to diversify. A genuine hedge would be domestic-outbound or non-Bali inbound partners, neither of which is in scope anywhere. | **INVERTED** |
| **8** | **Public sold-counts are bucketed display values** | Confirmed and closed as a proxy (Q6 partial) | ⚠️ **Reinstated in a new form.** An unusable *measurement* was replaced with an invented *assumption* (R), and the whole file was scaled to it. Substituting an assumption for a bad measurement does not resolve the risk; it relocates it into the denominator of every row. | **CHANGED** |

---

## 6.17 D0 GRAVITY — the count, and where the gravity actually is

**By row count, the register is not two-thirds D0 and the research did not under-serve the strategy.**

| Direction | §11 self-report | Share | My recount |
|---|---:|---:|---|
| **D0** | 9 of 24 | **37.5%** | Confirmed. Generous re-assignment of the six ambiguous D0/D1 rows takes it to **10 of 24 (42%)** — still not two-thirds. |
| **D1** | 6 | 25% | Confirmed |
| **D2** | 6 | 25% | Confirmed |
| **D3** | 3 | 12.5% | Confirmed — and **§11a is the most intellectually honest section in the file.** It declines to invent D3 rows and states four independently-established reasons. Credit where due. |

**Two defects in the count itself.** (i) **Six of twenty-four cards carry no bolded primary tag** (ZE-01, ZE-02, ZE-03, ZE-05, ZE-12, OPP-04) although §11 says the primary tag is bolded in the cards — so the coverage table is not reconcilable with the cards it summarises. (ii) The table shows 9+6+6+3 = 24 while the text says shared rows are counted under each direction; both cannot be true.

🔴 **But the gravity is in the money, not the row count, and there it is severe.**

- Of the zero-engineering lane's **$140,500**, rows tagged D0/D1 carry **$108,225 = 77%.**
- Across both lanes' sized impact (~$176,500), D0/D1 carries **~62%.**
- Of the §6c Now slate's 5.2 eng-weeks, D0/D1-primary rows consume **2.7 = 52%.**
- 🔴 **Of the impact that survives this red-team pass, 100% is D0/D1.** Every D2/D3 sized figure in the file is TARGET-basis on a business with zero partners, and every one is GATE-0-gated.

**The mechanism that hides it:** D0/D1 rows carry CURRENT-basis dollar figures; D2/D3 rows carry TARGET-basis contingent figures; **the register adds them into one total and one slate.** The result reads as a balanced four-direction register and spends like a D0/D1 one.

> **Verdict on D0 gravity: the research is clean, the register is not.** The correct fix is not more D2/D3 rows — §11a is right that they cannot be honestly invented. It is to **stop summing CURRENT and TARGET into one number**, and to present two slates: what is true today, and what becomes true if GATE 0 passes.

---

## 6.18 REVISED RANKED ORDER

**Two lanes, two bases, never summed.** Person-weeks are shown alongside eng-weeks because §6.5 shows the register's binding constraint was applied to only one of them.

### 6.18a Unconditional — true regardless of GATE 0 and regardless of R

| Rank | ID | Action | Eng-wk | Person-wk | Sized impact | Why it is here |
|---:|---|---|---:|---:|---|---|
| **0** | **Q6** | **Count the bookings.** `{{SCALE}}` — monthly orders, GMV, passes sold, Pass utilisation | 0 | ~0.1 | — | Nothing below can be ranked without it. §6.11. |
| **0** | **GATE 0** | Pool B exclusivity cross-check | 0 | 0.2 | — | Gates 17 of 24. **2026-08-07.** |
| **0** | **P2 + P3** | One counsel brief — PDP law + liability/representation | 0 | counsel | — | Zero eng-weeks; gates the highest-value D0 area. |
| **1** | **OPP-D1-4** | Contract feed #2 for zero overlap *(or one feed)* | **0** | ~0.5 | **8–29 eng-weeks avoided**, R-independent | The only row that **returns** the binding constraint. |
| **2** | **ZE-01** | Split `supplier_sold_count` / `satusatu_bookings`; audit every surface *(now includes ZE-02's ranking rule)* | **0.3** | ~0.5 | break-even: **41 redirected bookings** | Hours of work; a live trust exposure independent of margin. |
| **3** | **M-1** 🆕 | **Nightly rate-integrity rule-check** (margin floor · expiry · tier · parity crawl) | **<1.0** | ~0.1 | unsized | §4c.5.2: *"highest return per eng-week of anything in 4c."* Defends the highest-severity failure in the file. **Omitted from the original register.** |
| **4** | **ZE-06** | Sublicensable content grant in the Pool B template | **0** | legal | one-off $1,800–3,000 | Irreversible: cost rises with every contract signed. |
| **5** | **ZE-03** | Render refund policy from `percentReturn`; Layer-1 gate | **0.2** | ~0.1 | $975 | Survives on ratio. One hour may close it for free. |
| **6** | **ZE-12** | Query logging + synonym dictionary + weekly zero-result review | **0.2** | ~0.3/qtr | **instrumentation** | Reclassified: it manufactures the data that closes Q10. |
| **7** | **M-2** 🆕 | **Chargeback / dispute leakage** — measure Q33, then 3DS/AVS config + dispute template | **~0.2** | ~0.1 | unsized; H5 band **8–18% of Pool A gross profit** | Same order as ZE-05's claim, on better evidence. **Omitted.** |
| **8** | **ZE-08** | AI listing extraction as an ops habit (buy, never build) | **0** | ops | $1,920 SKU-contingent | Best-evidenced AI finding in the corpus. Copy GYG's boundary exactly. |
| — | **ZE-05** | Ask about SGD settlement **and** get a bank IDR→SGD quote, same week | **0** | ~0.1 | **~$7,900 EV** *(was $29,250)* | Free to ask. Both halves or neither. |
| — | **M-3** 🆕 | **Pass float / breakage governance** vs the Sightseeing Pass precedent | 0 | finance | unsized | GATE-1-approved spine amendment with no row. **Omitted.** |
| — | **OPP-01** | **Re-open as a capacity question.** Answer Q7 + Q8 + Pass utilisation, then re-score | 0 *(measure)* | ~0.2 | **$1,422 or ~$7,760** | The register scored it on the wrong mechanism. §6.9.1. |

**Unconditional engineering total: ~2.0–2.9 eng-weeks. Unconditional person-weeks: ~2.2 plus counsel.**

### 6.18b Conditional on GATE 0 passing — do not start before 2026-08-07

| Rank | ID | Eng-wk | Person-wk | Sized | Gate |
|---:|---|---:|---:|---|---|
| **1** | **ZE-09** — declared `availability_model` per Pool B SKU **(P1)** | 1.0 | 0.8–1.5 | $1,365 direct; **P1 for four survivors** | Survives a GATE 0 failure on OPP-02+OPP-03a+OPP-03b alone. Start it either way; the *urgency* is GATE-0-dependent. |
| **2** | **OPP-03a** — no Pool B booking sits silently unconfirmed | 1.0 | 0.1 | $5,040 · break-even **1.13 strandings/yr** | ZE-09 |
| **3** | **OPP-02** — day-of messages rendered, never generated | 2.0 | 0.2 | $1,896 — **fund as a control, not a saving** | ZE-09, P5, P7 |
| **4** | **OPP-D1-2 (Layer 1 only)** — bad SKUs stopped at ingest | 1.0 | 0.2 | $790 sized + unsized mispricing leg | Layers 2–3 unfunded |
| **5** | **ZE-07** — rate sheet to 20–40 named agents | 0 | 🔴 **~11** | **unsizeable** | **Q31 first — no rate card, no rate sheet.** GATE 0. |
| **6** | **ZE-04 · ZE-10** — IDR denomination; prepay-only launch | 0 / 0.5 | 0.2 | **unsized policies** | Before the first B2B contract |
| **7** | **OPP-D3-3** — Indonesian wholesalers carry Pool B | 0.5 | 0.3 | $4,420 at 2,000 bookings, **40% confidence** | GATE 0 + the Golden Rama post-login check |
| — | **OPP-D2-3** — agent seats + prepay wallet | 5.0 | — | $16,160 at 10 partners | **Own budget conversation.** Not before ZE-07 clears 2026-11-15. |
| — | **OPP-03b** — operator replies → booking state | 2.0 | — | $819 | **Later.** Q9 first. |
| — | **OPP-D1-3** — raw-MT breadth | 1.0 | — | not sizeable | Needs a currency answer, not just a language one |

### 6.18c What changed against §6a / §6b / §6c

- **Killed:** ZE-02, ZE-05 *(as a sized opportunity)*, ZE-11, OPP-04, OPP-D2-4, OPP-D2-5.
- **Eng-weeks freed:** 1.0 (ZE-02) + 0.4 (ZE-11) + 1.0 (OPP-D2-4) + 2.0 (OPP-D2-5) = **4.4**, against a 6-week assumed budget.
- **Added:** M-1, M-2, M-3, and Q6 as the first action in the file.
- **Re-ordered:** OPP-D1-4 to rank 1 overall; ZE-05 out of rank 1; OPP-01 re-opened; ZE-12 reclassified as instrumentation; OPP-02 reclassified from saving to control.
- **Sums withdrawn:** the $140,500, the "$150,000 slate", and the "103% of Pool A net gross profit" cross-check.

---

## 6.19 🔴 THE SINGLE MOST LIKELY WAY THIS REGISTER IS WRONG

**It is a precisely-reasoned answer about a business whose size nobody has measured.** Every dollar in the file is `R × parameter`; `R` is an [ASSUMPTION] the authors chose for comparability and then defended with the claim that the *ranking* is insensitive to it — a defence that only holds if the parameters are uncorrelated with volume, and at least four of them are not (Pool B's ability to absorb a 37% volume shift, concierge capacity as a step function, the kill criteria's sample sizes, and the Pool A/Pool B margin delta itself via GATE 0). If SatuSatu is a **200–400 booking-per-month** business — a range fully consistent with 253 SKUs, a single aggregator feed, keyword-only search, no AI anywhere in the product, a three-month-old hero product, and a Bali arrivals base that turned negative in 2026 while the country around it grew 7.7% — then the headline is not $140,500 but roughly **$5,000–17,000**; **thirteen of twenty-four rows fall below the cost of the meeting convened to discuss them**; several kill criteria cannot reach their own sample sizes inside their own deadlines and will expire rather than decide; and the honest deliverable is not a ten-row slate at all. It is two sentences: **answer GATE 0, and count the bookings.** The register's greatest strength — that it refused to invent internal numbers and stated break-even thresholds instead — is also the mechanism of this failure, because a break-even threshold expressed against an invented reference volume is still an invented number wearing a disclaimer. **The most likely way this is wrong is not that any individual row is wrong. It is that the whole thing is a well-built machine bolted to an unmeasured base, presented to a CEO in dollars.**

---

*End of Step 5c red-team pass. Six kills, eleven downgrades, three omissions restored, eight risks re-tested, no metric invented. Everything above is traceable to a file on disk; where it was not, it says **unverified**.*
