Haute Lumière · The reading

Everyone says they put customers first, which is exactly why nobody believes it

Trust is a forecast about what a company will do when its interest and yours come apart, and the only admissible evidence is what it has already paid.

The rows she is reading were filed under credits, write-offs and revenue not recognised. Nobody has ever added them up.

The rows she is reading were filed under credits, write-offs and revenue not recognised. Nobody has ever added them up.

THE PAUSE

A screen asks for a bank login. Not the account number printed along the bottom of a cheque — the actual credentials, the ones that open everything. There is a small padlock icon and a line of grey type about encryption, and the thumb stops above the keyboard. Whatever is happening in that pause, it is not a mood.

It is a calculation, and it runs faster than language can follow it. The person is not asking whether the company seems pleasant, or whether the interface looks like something a serious firm would build; those are inputs, and weak ones. The question being computed is narrower and colder. When this company's interest and mine come apart — and they will, because they always do — which way does it go?

Almost no company is malicious, and the question is not about malice. It is about an ordinary Tuesday: a product manager deciding whether to sell aggregated transaction data to a partner who will pay six figures for it, a growth team deciding whether cancelling takes one click or four, an analyst deciding whether to absorb a disputed charge or make the customer prove harm. Those rooms are rooms the customer will never be shown, and the thumb is trying to predict what happens inside them.

Trust is not a feeling about a company. It is a forecast about a room you will never be allowed into.

Only one kind of evidence moves a forecast like that, and it is not a sentence the company wrote about itself. It is the record of times the choice has already been made, at cost, where someone outside could see it. Everything else in the marketing budget is a report on your intentions filed by an interested party.

Which is why the subject cannot be managed where it is usually managed. Trust is assembled in the pricing page and the renewal terms, in how much authority the person answering the phone has to make someone whole without escalating, in the first four hours of an incident, in what you do with data you are legally permitted to use. Those are the factory floors. A campaign cannot deposit into an account that accepts one currency, and the currency is revenue you chose not to take.

REPUTATION AND TRUST

The two words get used as synonyms and they are nearly opposite in structure. Reputation is a stock of statements — the reviews, the coverage, the analyst notes, the thing a friend says at dinner. It is backward-looking, socially transmitted, and substantially purchasable. With enough spend and enough well-run press, a firm can manufacture a great deal of what is said about it.

Trust is a forecast: a prediction held by a specific person about a specific counterparty under one condition, divergent interest. Not “I like them” but “I believe that when it costs them, they will still do it.” That cannot be bought, because the thing being predicted is behaviour under cost and the only admissible evidence is prior behaviour under cost. Advertising is evidence of a budget. It is not evidence of anything else.

The distinction is load-bearing rather than semantic, because the two track each other closely in calm weather and detach violently under stress, which is when you find out which one you were holding. The credit rating agencies before 2008 had reputation measured in decades and a regulatory mandate behind it. What they did not have was a record of telling a paying client something it did not want to hear at a moment when the fee was at risk. The gap between the two closed in about ninety days.

In August 1991 Warren Buffett took over as interim chairman of Salomon Brothers in the middle of a scandal with a realistic chance of ending the firm. A trader had submitted false bids in Treasury auctions and management had not promptly told the regulators. The threat was not the fine; it was that the Treasury could bar the firm from bidding and that the counterparties funding it overnight, in enormous size, could stop rolling the paper. His line was that losing money for the firm was understandable and losing a shred of reputation would be met without mercy.

The interesting part is not the sternness but where he was standing when he said it. He was performing, in real time, an emergency recapitalisation of an asset that appears nowhere in the accounts, and doing it by spending: cooperating at cost, disclosing at cost, removing the firm's own leadership at cost. The firm survived. Reputational capital does behave like capital, but the phrase has been quoted in ten thousand slides without anyone specifying how a deposit gets made.

The mechanism is the expensive decision. Capital accumulates when a firm pays something it did not have to pay, in a way the other side can see. Nothing else converts.

WHAT SURVEYS MISS

Consider what a satisfaction survey measures. A customer completes a transaction — the order arrives, the claim is paid, the ticket closes — and is asked how likely they are to recommend the company. The instrument is honest and the data is real, but look at whose data it is. It is overwhelmingly the data of people whose interests never diverged from the company's: they wanted the thing, the company wanted to sell them the thing, it arrived.

The population that could tell you something is the one that ended up somewhere the firm had a live financial reason to behave badly — the refund outside the window, the data in the breach, the edge case the policy did not cover, the cancellation, the denied claim. They are a small minority of respondents. They are frequently excluded by construction, since nobody surveys the churned. And where they do appear, their scores are read as a service problem to remediate rather than as the only real signal in the set.

A high score and a low score are equally uninformative about trust. The high one is more dangerous, because it is reassuring.

Which produces the finding most executives have backwards. A company with excellent satisfaction scores and no expensive decisions on its record does not have weak trust, or immature trust, or trust that needs a little more work. It has none. It has an untested reputation, indistinguishable from trust in every instrument you own and every conversation you have with your board, right up to the second it matters.

The absence of tests is not a clean record. It is an absence of evidence, and it leaves you in exactly the same position of ignorance as your customers about what your own company would do. The reflex of every well-run firm is to avoid the test — keep the incidents down, keep the disputes out of view, keep the divergence from ever surfacing. But the test is not the threat to the asset. The test is the only thing that produces the asset.

So the goal is not to avoid being tested. It is to arrange to be tested early, cheaply and visibly, while the stakes are survivable. Publish the failure rate before anyone asks for it. Refund something you were entitled to keep. Tell a prospect the product is wrong for them. Each is a test you scheduled rather than one scheduled for you, and each buys evidence at a price you set rather than the price your worst day will set.

The decision that will matter was taken on an unremarkable afternoon, by someone whose name will not appear in the case study.

The decision that will matter was taken on an unremarkable afternoon, by someone whose name will not appear in the case study.

THE LEDGER

Model the thing properly and most of the confusion resolves. Trust has a stock — the accumulated balance held with a customer or a market — and a flow, the deposits and withdrawals of the current period. Almost every management conversation about trust is a conversation about the stock, conducted by people with no instrument for the flow.

A deposit has four conditions and all four are load-bearing. The interests genuinely diverged. The company chose the customer. It cost something real. Someone outside the building could tell. A choice that cost nothing is not a deposit but an alignment, and alignments carry no information, because a company with the opposite intentions makes the identical choice. A choice nobody outside could observe may well be integrity, which is worth having for its own reasons, but a forecast cannot update on evidence that was never received.

Deposits are structurally small: a fee waived, a limitation disclosed before purchase, a refund honoured past the window, a sale not made. Withdrawals are the same structure reversed, and they arrive already labelled — the mandatory fee hidden until checkout, the renewal that fired without warning, the outage called degraded performance for six hours while everyone watching knew it was down.

Here is the strange part of the accounting, and it explains more organisational behaviour than any theory of incentives. Firms book the withdrawals and none of the deposits. Withdrawals come with owners, root-cause analyses and remediation timelines. Deposits come labelled as something else: credits issued, discounts given, revenue not recognised, write-offs, cost-to-serve, leakage. Every deposit into the trust account is recorded in the actual accounts as a loss.

There is a standing organisational campaign to reduce the deposit rate, and it is called margin improvement.

That is the quiet spending, and it is why nobody can find the decision that caused it. Nobody authorises spending trust. What happens instead is a hundred decisions to reduce a cost line that happens to be the deposit line, each correct on the numbers presented in the room, which sum to a company that has stopped funding the one asset it cannot replace.

The exercise takes an afternoon. Four quarters, one row for every decision where the customer's interest and the quarter's genuinely came apart — not where they might have, but where someone had a choice with money on one side of it. Four columns: what diverged, what you chose, what it cost in currency rather than adjectives, and whether anyone outside could have known. Firms doing this honestly tend to find between zero and three rows that went the customer's way at real cost with real visibility, and not because they are dishonest. The empty quarters are the finding, not the full ones.

THE ASYMMETRY

Deposits are small and slow. Withdrawals are total and instant. A single visible expensive choice moves a customer's forecast a little, and it takes a pattern spread across enough different situations before the customer believes the behaviour is structural rather than accidental. That accumulation curve is shallow and long and has no dramatic moments in it.

The withdrawal is not a curve. One sufficiently clear instance of the company choosing itself, in a domain where it had claimed it would not, and the forecast collapses rather than degrades, because a counterexample is decisive in a way a confirmation never is. The customer held a prediction of the form “they will not do this to me” and now holds a demonstration that the company will. Every prior deposit is reread as luck, or as an absence of temptation.

The operational consequence is the reason the serious half of this subject is machinery rather than intention. If the payoff structure is many small deposits and one catastrophic withdrawal, the binding constraint is not your average behaviour. It is your worst behaviour, at your least supervised moment, by your least empowered person, in your most pressured quarter. A company optimising its mean is optimising the wrong statistic entirely.

In the autumn of 1982 seven people in the Chicago area died after taking Extra-Strength Tylenol capsules laced with cyanide. The contamination was introduced after the product reached retail shelves; Johnson & Johnson had not been tampered with in its own factories and was, in the narrow legal and causal sense, not at fault. It pulled the product nationally anyway, before it was compelled to, while the known incidents were still geographically confined, and then rebuilt the packaging around tamper-evidence and took the industry with it.

The number that matters is not the recall cost. It is that Tylenol was among the most profitable products the company had, that the consensus at the time was that the brand was finished, and that the decision was therefore made without knowing whether the franchise would survive it. That is what made it expensive and what made it a signal: a company quietly willing to trade customer lives against quarterly revenue could not have afforded it, and everyone watching understood that without being told.

Four decades on it is still cited, which means a cost incurred in one quarter of 1982 is still paying. Under any standard framework that quarter was a catastrophe. The asset it created has no line, no amortisation schedule and no owner — and an asset nobody books loses every budget argument to assets that do.

THE LIAR'S COST

Put the sentence on the table and ask the only question that matters about it. A company writes, on its security page: “We take the protection of your data seriously.” Now imagine the least scrupulous operator in the category — three unpatched servers, a shared admin password, a plan to sell the email list if the round does not close. Could that company publish that exact sentence tomorrow morning, and at what cost?

It could, at none. No filing to make, no auditor to satisfy, no revenue foregone, no exposure created. The sentence is free to the honest company and free to the dishonest one, and a sentence free to both carries no information about which one you are reading. Its truth value is unrelated to its presence on the page. It is not a lie, exactly. It is worse than a lie, because a lie can at least be caught.

That question is the operating test, and it runs in ten minutes against everything a company currently claims. The idea underneath it comes from biology before economics: a signal is credible only when it is differentially costly to fake. The peacock's tail is metabolically expensive and makes its owner easier to catch, and a sick peacock cannot grow one — it carries information not because it is beautiful but because it is expensive in exactly the currency the weak bird lacks. Michael Spence's version, which took a Nobel in 2001, made the structure legible for markets.

Money that both types can spend equally is not a signal. It is an expense with an audience.

The word doing the work is differentially, and it is where most executives lose the thread. It separates this argument from the vulgar version that says spend enough and people will believe you. They will not. A signal separates the honest from the dishonest only when its cost is higher for the dishonest, and a cost both types bear identically separates nothing at any size.

Run it on the standard toolkit and most of the toolkit disqualifies itself. Brand advertising about how much you care is painfully expensive and available to the unscrupulous competitor at the same rate card. Values pages and founder posts are structurally free, and the most cynical firm in the sector can publish a more moving one, being unconstrained by having to mean it. Security certifications cost real auditor hours — and in most enterprise categories a weak firm can obtain a clean report by scoping narrowly and choosing an accommodating auditor, with pass rates approaching unanimity. A certificate everyone in the category holds is not a signal, it is a licence.

Now run a refund with no questions and no window. The unscrupulous competitor can offer it only by eating the cost, and the cost lands asymmetrically: a company selling something that disappoints has far more claims made against it than one selling something that satisfies. The promise is cheap for the good product and ruinous for the bad one. That is a separating signal, and it works whether or not a single customer consciously reasons any of it through.

Nothing on the page is being defended. The only question asked of each line is what it would cost if it turned out to be false.

Nothing on the page is being defended. The only question asked of each line is what it would cost if it turned out to be false.

THE BILL

Published failure data passes the test, and it passes hardest when the numbers are bad. On 2 July 2019 Cloudflare pushed a single regular expression into a firewall rule that backtracked catastrophically across its global network, and a large fraction of the internet returned errors for about half an hour; the post-mortem went out the same day, naming the expression and explaining that the change had gone out globally rather than in stages. Two years earlier, during a late-night incident, a GitLab engineer deleted the wrong database directory, and the recovery revealed that several backup and replication mechanisms were not working. The company livestreamed the recovery and afterwards published how many hours of customer data were unrecoverable.

A negligent competitor could publish a post-mortem. It could not publish those, because those contain the specific, checkable, damaging admissions its lawyers would never clear and its own engineers would rather bury. The cost of the disclosure falls on the disclosing company in proportion to how bad the underlying truth is. And something follows: publishing your failure rate makes the failure rate expensive to you, which is an incentive to reduce it. The signal stops being evidence of the machinery and becomes part of it.

In December 2009 Domino's went on television and told the United States that its pizza was not good. The campaign opened with focus-group footage of customers saying the crust tasted like cardboard and the sauce like ketchup, and internal footage of executives reading comment cards calling it the worst pizza they had eaten. Then the president of the company said on camera that the recipe had been thrown out and the pizza rebuilt from the crust up.

A company that had not reformulated cannot run that advertisement, for structural rather than moral reasons. It is a nationally broadcast invitation to re-test the product, recruiting millions of lapsed customers to place one more order specifically to see whether the claim is true. If the pizza is unchanged, the firm has spent a fortune reminding the market of its worst attribute and then confirming it. The following quarter produced the largest domestic same-store sales jump the chain had recorded, on the order of fourteen percent, which is a move that essentially does not happen in mature restaurant chains.

The lesson is routinely mistold as honesty sells, which is precisely the free sentence the unscrupulous competitor can also say. What the company did was construct a situation in which its own claim would be verified by the market within weeks, at scale, with revenue riding on the verdict. Any company can be vulnerable in a video. Only one that genuinely changed the product can afford to hand the audience a test and a deadline.

Backblaze arrived at the same structure from the opposite direction, building from nothing in a category where the buyer cannot inspect what is bought. Since 2013 it has published quarterly statistics on every hard drive in its data centres: manufacturer, model number, drive-days observed, failures, annualised failure rate. Not a summary — the data set, model by model, including the years a particular Seagate three-terabyte model failed at several times the fleet average, with the part number attached. The company sells backup storage, not drives, so every quarter it hands its suppliers' competitors a credible marketing asset and hands its suppliers an embarrassment, while depending on them for procurement and pricing.

A competitor cannot match that by publishing nicer numbers, because the set is longitudinal: drive-days accumulate, models age in view, and a fabrication would have to stay coherent against physics and against every other operator's experience for years. You cannot start this signal today. The cost is not the publication, it is the decade of not having stopped.

And the other half of the arithmetic. L.L. Bean carried an unconditional lifetime guarantee for roughly a century, one of the most powerful trust assets in American retail, and in February 2018 ended it, limiting returns to one year with proof of purchase, because too many people were returning items bought at yard sales or worn for a decade. The signal worked because it was expensive and it ended because it was expensive. Anyone offering the credibility without the bill is selling the counterfeit.

THE COUNTERFEIT

Wherever a costly signal reliably produces a return, a cheap imitation of its surface appears and usually wins on distribution, because it is cheaper to produce. Telling the two apart is most of the practical skill here, and the tell is portable across industries.

The clearest current specimen is the published cost breakdown. Everlane built a brand on what it called Radical Transparency: for each garment, a diagram showing the cost of materials, hardware, labour, duties and transport, set beside the company's price and a comparison to what a traditional retailer would charge. It is arresting the first time you see it.

Then run the test. The least scrupulous competitor could publish an identical breakdown tomorrow, and could publish a better one. The numbers are self-reported, unaudited and structurally unverifiable by a reader who cannot check a labour cost in a factory they cannot name. Nothing in the disclosure creates exposure; nothing in it can be falsified by a customer. And a breakdown of unit costs is an argument that the price is fair, which is a marketing claim wearing a spreadsheet's clothes.

So here is the tell, and it works without knowing anything about the industry. Real disclosure has a victim inside the company — a team whose numbers look worse, a product that sells less, a supplier who is angry, a lawyer who objected and was overruled. If you read a transparency initiative and cannot identify who inside the building lost, you are reading marketing.

Third-party verification rots in a predictable way, and the mechanism is issuer-pays. When the party being rated pays the rater, the rater's revenue depends on the rated party's satisfaction, and satisfaction correlates with favourable ratings. Nothing about this requires anyone to be corrupt; it requires only that raters compete, that ratings be shoppable, and that time pass. Before 2008, arrangers of structured mortgage products could take a deal to several agencies, learn what each would rate it, and place the business accordingly. Triple-A, the designation carried by sovereign debt, went onto enormous volumes of securities backed by loans that defaulted within eighteen months, and most of those ratings were later downgraded by ten notches or more within months.

The most telling case is not a rotted certificate but an abandoned one. Etsy certified as a B Corporation in 2012 while private, went public in 2015, and in 2017 declined recertification, because maintaining the status would have required restructuring as a public benefit corporation at a moment of activist pressure, a new chief executive and cuts. The certification was cheap while the company was private and controlled by people who wanted it. It became genuinely expensive at exactly the moment it would have carried information — when public shareholders would have had to be told the company had bound itself. Cost and information content rose together, and at that point it was dropped.

Then the purest form of the failure, theatrical costliness: spending real, verifiable, enormous money in a way that says nothing about the thing the customer needs to predict. FTX bought a Super Bowl advertisement in February 2022 telling viewers not to miss out, having already paid for naming rights to the arena in Miami on a nineteen-year agreement worth well over a hundred million dollars. Nine months later it collapsed amid allegations that customer deposits had funded an affiliated trading firm, and its founder was subsequently convicted of fraud.

The spend proved FTX could spend. It proved nothing about whether customer assets were segregated, which was the one question in the room, because a company misappropriating deposits can afford that advertisement more easily than an honest one — it is spending money that does not belong to it. The cost asymmetry ran backwards. And the tell was available in advance without inside knowledge: ask what specific claim the expenditure would be falsified by. If the money would have been spent identically whether the claim was true or false, it is decoration regardless of size.

HOSTAGES NOT PROMISES

Run the test enough times and it does something nobody expects. You begin using it as a filter on language — which claims to keep, which to delete — and then notice that every claim which survives has the same shape, and the shape is not a sentence about your character. It is a structure that will hurt you if you misbehave.

The refund policy that costs money if the product disappoints. The published failure rate that costs enterprise deals if it worsens. The commitment made in public with a verification deadline attached. In each case the company has not asserted its integrity; it has arranged to be punished for the absence of it, and made that arrangement legible to the people deciding whether to believe it.

You are not trying to become the kind of company that keeps its word. You are trying to become one that would be ruined by breaking it.

This relocation is the most useful move available, because character does not survive contact with a bad quarter and exposure does. Intentions are unobservable to your customer, unenforceable by your board, and unreliable in your successor, who never read the founding memo and is under pressure you never faced. Exposure is observable, enforceable, and stays in the structure after you have left the chair. Predictions are made about incentives, not about souls, so give the customer incentives to look at.

It also explains the asymmetry every operator has noticed and few can account for: why an enormous, sincere, beautifully made brand campaign moves nothing, while one paragraph on a status page admitting exactly how much data was lost moves a great deal. The campaign is a report on your intentions from an interested party. The paragraph is a hostage.

Contract design solved this decades before marketing noticed the problem, and the instruments sit unused. The hostage is something you value, placed where your own bad behaviour destroys it — a standing quarterly metric, a public roadmap with dates, a reference policy with no approval step; it need not be valuable to the receiver, only costly to the giver. The bond is a sum posted in advance and forfeited on a defined failure, and its consumer form is the automatic service credit, issued by your own monitoring without a human deciding. JetBlue's Customer Bill of Rights in February 2007 did exactly this, with self-imposed payouts for delays the airline itself caused. The escrow removes your discretion altogether.

What the three share is that they move the decision out of your hands at the moment you would most want it back. A promise is a claim about your future self; a bond is a constraint on it, imposed by your present self, and a customer can tell which they are looking at with one question — who decides whether this pays out? The failure mode is collateral with a discretion clause folded quietly into it. Legal will want an exclusion for circumstances beyond reasonable control, and the moment it exists a sophisticated buyer reclassifies the instrument as a promise, correctly. A small bond with no escape hatch outperforms a large one with three.

WHAT OUTLASTS YOU

The parts are not independent, which is why the order of building matters more than the enthusiasm brought to any one of them. Promise comes first: a company that cannot keep the commitments it has already made, because it never inventoried them, has no business attempting sophisticated disclosure. Disclosure next, then restraint — the ability to decline revenue — because a firm that discloses well and has no mechanism for refusing money will find its disclosures growing steadily more careful and less true. Then conflict, which is whose side you take when both sides of a transaction are paying you. Then consistency, which is whether the answer would be the same in ten years.

The promise surface is larger and stranger than the three pages anyone audits, because promises get made in places nobody classes as promises. The default state of a checkbox. The sentence a salesperson says to close. The renewal clause nobody has read since it was drafted. The thing the product does that the documentation never mentioned and the customer now depends on. An audit of the homepage produces ten rows; an audit of the actual promise surface produces hundreds.

Then the three conditions that break all of it. The worst day, when the incident is real and every instinct in the building is to protect the company, which is also the day the balance is read most closely. The front line, where a person with no authority is asked to represent a promise the company made, and where a refund limit set for cost control quietly overrides every value printed on the wall behind them. And the automated system, which will keep whatever promise you encoded and no other, with perfect consistency and no capacity to notice that this case was the one that mattered.

A machine keeps the promise you wrote, not the one you meant. So does an agent with a hard limit and a full queue.

Counting matters for an unglamorous reason. A deposit shows up in the accounts as a write-off, so the only way the deposit rate survives a margin review is if somebody can put a number beside it that a finance function will accept as a number. This is not a plea for a softer metric. It is the observation that an asset with no line, no schedule and no owner loses every budget argument it enters, to people who are doing their jobs correctly.

And then the real test, the one everything else prepares for. Anything held in place by your personally caring about it lasts exactly as long as your tenure and not one day longer. The work is to write at least one constraint into the company that your successor cannot quietly remove: a charter provision, a contractual right held by the customer rather than granted by you, a payout that fires without a human, a published series that would be conspicuous to stop. Virtue is not the input, and virtue is not distributable. Structure is buildable, which is the good news in an otherwise demanding argument.

Start where it is cheap. Open three pages — home, pricing, security — take the first ten claims, and write one column beside them whose heading is a question rather than a category: what would this cost us if it were false? Most rows come back blank, and the blank is the finding. Then convert one. Taking your data seriously becomes a published notification commitment with a stated maximum number of hours and a named executive who owns the clock. Standing behind the product becomes a refund with no window, which will tell you within a quarter which of your products are weak.

Expect the objection, and expect it from your own counsel, who will be doing the job correctly. Specificity creates liability in a way a vague assurance does not. That is true, and it is not a defect — it is the mechanism. The exposure your counsel is working to eliminate is the identical exposure your customer is working to detect, and you cannot keep one without the other. What you can do is choose which exposures to accept deliberately, price them, and build the machinery that holds you on the right side of them, rather than meeting them by accident, at full size, on the worst day you will ever have.


Free to read

Free to read, and free to hear. Every chapter of every book in this house, and every narration of it, is open to anybody. No account, no card, nothing to cancel.

Earned — 13 chapters, 122,668 words.

Buying a volume is now for keeping it — the EPUB, the PDF and the press file, yours on disk. The reading is free either way.

Read it free Keep the files — $44.44

What is in it


Reputation is what has been said about you. Trust is what will be predicted about you when it costs.
An unblemished record is usually an unspent one, and an unspent balance was never verified.
Character is what you intend. Exposure is what your customer can check.
Virtue leaves with the person who held it. A clause stays in the contract.

Keep looking

Every phrase on this page opens into the house search. The shelf holds The Press and six other shelves, and the reading is free.