“Cancel anytime. You are in control.”
Then the cancellation screen asks why you are leaving. Answering is compulsory. A retention offer follows. Somewhere behind the reassuring copy, a function refuses to stop renewal until you have completed the interview.
An AI reviewer given only the sentence could approve it. The sentence fits the voice. The product breaks the promise.
This is the kind of problem I wanted Brand Machines to address: identity becomes consequential when it changes how a system behaves. If autonomy is a brand principle, it has to reach the cancellation path, including the parts a copywriter never sees.
I have adapted the method into an open-source skill for agents. Here is a worked example of using its review contract to connect a principle, a code path and a correction you can test.
The subscription product below is fictional. Its policy, files and report form a teaching fixture, not a client case or a claim about business results. The Python test was executed against both versions shown here.
Give the principle a cost
“We value autonomy” leaves too much room for interpretation. An agent needs to know what the team has decided when autonomy conflicts with another objective.
Save this as brand/principles.md. Treat it as an approved policy within the fictional example:
P-AUTONOMY — Control over renewal
Definition: An authenticated account holder can stop future renewal
from billing settings without giving a reason, viewing an offer,
or waiting for support approval. Paid access lasts to period end.
Activates when: Designing cancellation, retention and billing flows.
Trade-off: We give up a compulsory retention opportunity.
Example: Cancellation is confirmed before optional feedback.
Counterexample: Renewal continues until a retention offer is viewed.
These fields follow the method's actionable values: name, definition, activating situations, trade-off, example and counterexample.
The trade-off does the difficult work. The team can still invite feedback or propose a different plan. It has decided that neither may be a condition of leaving. Without that decision, the agent would be inventing policy while pretending to enforce it.
Put the behavior beside the promise
Create web/pricing.md:
Cancel anytime. You are in control.
And web/cancellation.md, the confirmation copy shown after the flow completes:
Your subscription has ended. Access is now closed.
The relevant behavior lives in cancellation.py:
def cancel(subscription, *, reason=None, offer_seen=False):
if not reason:
return {"status": "reason_required"}
if not offer_seen:
return {"status": "retention_required"}
subscription["renewal_enabled"] = False
return {
"status": "confirmed",
"access_until": subscription["access_until"],
}
This is a deliberately small state model. Authentication has already happened; there is no payment provider, persistence or production endpoint. It isolates the decision under review: whether cancellation depends on an explanation and an offer.
The guards implement that dependency. Even after the customer complies, the confirmation says access has ended while the function preserves the paid-through date. A review confined to tone would miss both defects.
In Brand Machines terms, the Core supplies the autonomy principle. The Brand OS includes the workflow that must enact it. The Skin includes the promise and confirmation people read. Reviewing their relationship reveals a contradiction that inspecting each file independently can conceal.
Give the agent a bounded assignment
Install the skill in the project you want to review:
npx skills add berthelius/brand-machines-agents --skill brand-machines
Invoke it with $brand-machines in Codex or /brand-machines in Claude Code. The installer follows the current repository version; the contracts linked in this article are pinned to v0.2.0.
With the example files attached, use this assignment:
Review this fictional subscription product using Brand Machines. Read brand/principles.md as its approved identity; do not substitute Brand Machines' own reference identity. Inspect web/pricing.md, web/cancellation.md and cancellation.py together. Trace what happens when an authenticated customer requests cancellation without giving a reason or viewing an offer. Cite the file and passage behind each finding, connect it to P-AUTONOMY, and propose the smallest correction to behavior and copy. Follow the Guardian report contract. Keep assumptions and untested behavior explicit. Do not change policy or deploy anything.
That scope gives the reviewer enough context to question the implementation without granting it authority to redefine autonomy. In a real product, include the actual handler and billing integration. A route name or design mockup cannot establish what the payment provider does.
Require findings that a developer can act on
The Guardian contract calls for a scoped judgment, findings, sources, limitations and a suggested revision. Each finding identifies the affected layer, principle and passage.
Here is a worked semantic report for this fixture, written as an example of that contract. It is not output from the optional bm.py checker:
brand: Example subscription product
version: teaching-fixture-1
status: revise
scope: Static review of the supplied cancellation model and copy
findings:
- layer: Brand OS
principle: P-AUTONOMY
passage: 'cancellation.py: if not reason / if not offer_seen'
evidence: >-
Both guards return before renewal_enabled becomes false.
A customer declining the interview cannot stop renewal.
suggested_revision: >-
Confirm cancellation independently of feedback and offers.
- layer: Skin
principle: P-AUTONOMY
passage: 'web/cancellation.md: Access is now closed.'
evidence: >-
The principle preserves paid access; cancellation.py returns
the existing access_until value. The message says otherwise.
suggested_revision: >-
Confirm that renewal is off and state when paid access ends.
sources:
- brand/principles.md
- web/pricing.md
- web/cancellation.md
- cancellation.py
limitations:
- No billing provider or production interface was inspected.
mechanical_result: bm.py was not run on this fixture.
suggested_revision: Repair the guards and confirmation; test the exit path.
The important connection is between the guards, the state they prevent and the policy that forbids that dependency. “This feels off-brand” would leave the developer to rediscover the problem.
The skill's Python checker verifies declared checks and source integrity. It does not infer this cancellation contradiction. The semantic review belongs to the agent reading the sources. Neither a checker result nor this report authorizes a deployment.
Repair the decision, then its expression
Replace the function in cancellation.py with:
def cancel(subscription):
subscription["renewal_enabled"] = False
return {
"status": "confirmed",
"access_until": subscription["access_until"],
}
After confirmation, optional feedback can follow. It must not undo cancellation when ignored. Update the confirmation to “Renewal is off. Your paid access continues until {access_until},” using the date returned by the successful operation.
Save this as test_cancellation.py beside the function:
from cancellation import cancel
subscription = {
"renewal_enabled": True,
"access_until": "2026-10-31",
}
receipt = cancel(subscription)
assert receipt["status"] == "confirmed", receipt
assert subscription["renewal_enabled"] is False
assert receipt["access_until"] == "2026-10-31"
assert subscription["access_until"] == "2026-10-31"
assert cancel(subscription) == receipt # Repeating the request is harmless.
print("Cancellation confirmed; renewal off; paid access preserved.")
Run python3 test_cancellation.py. Against the original function, it fails with AssertionError: {'status': 'reason_required'}. Against the replacement, it prints the success message. Those are the results of executing these snippets, separate from the illustrative semantic report above.
The test captures the approved decision in this model. Production needs evidence that cancellation reaches the billing provider, failures remain visible and the confirmation reflects persisted state. Until those parts are inspected, the review stays bounded to the fixture.
Let identity reach the repository
The most consequential correction here removes a dependency from a function. It also changes a sentence, but polishing the sentence alone would leave customers trapped behind the same guards.
I wrote Brand Machines: A General Theory of Brand Systems to develop this relationship between identity and operation: how principles connect decisions across people, products and agents. The agent skill makes part of that method available inside a working project.
For a first review, choose a promise with observable consequences: cancellation, privacy, accessibility or support. Attach the principle and the code that determines what happens. A useful reviewer should be able to follow the promise all the way to the decision that keeps it.
Top comments (0)