{"slug": "your-ai-brand-reviewer-should-read-the-cancellation-code", "title": "Your AI brand reviewer should read the cancellation code", "summary": "A developer has released Brand Machines, an open-source agent skill that reviews whether a product's stated brand principles match its actual code behavior, using a worked example of a fictional subscription cancellation flow. In the example, an AI reviewer given only the marketing copy \"Cancel anytime. You are in control.\" would approve it, while the cancellation code requires a reason and a viewed retention offer before disabling renewal, contradicting the promise. The skill, installable via `npx skills add berthelius/brand-machines-agents --skill brand-machines`, connects a written principle, the code path and a testable correction.", "body_md": "“Cancel anytime. You are in control.”\n\nThen the cancellation screen asks why you are leaving. Answering is compulsory. A retention offer follows. Somewhere behind the reassuring copy, a function refuses to stop renewal until you have completed the interview.\n\nAn AI reviewer given only the sentence could approve it. The sentence fits the voice. The product breaks the promise.\n\nThis is the kind of problem I wanted *Brand Machines* to address: identity becomes consequential when it changes how a system behaves. If autonomy is a brand principle, it has to reach the cancellation path, including the parts a copywriter never sees.\n\nI have adapted the method into an [open-source skill for agents](https://github.com/berthelius/brand-machines-agents). Here is a worked example of using its review contract to connect a principle, a code path and a correction you can test.\n\n**The subscription product below is fictional.** Its policy, files and report form a teaching fixture, not a client case or a claim about business results. The Python test was executed against both versions shown here.\n\n“We value autonomy” leaves too much room for interpretation. An agent needs to know what the team has decided when autonomy conflicts with another objective.\n\nSave this as `brand/principles.md`. Treat it as an approved policy **within the fictional example**:\n\n```\nP-AUTONOMY — Control over renewal\n\nDefinition: An authenticated account holder can stop future renewal\nfrom billing settings without giving a reason, viewing an offer,\nor waiting for support approval. Paid access lasts to period end.\n\nActivates when: Designing cancellation, retention and billing flows.\nTrade-off: We give up a compulsory retention opportunity.\nExample: Cancellation is confirmed before optional feedback.\nCounterexample: Renewal continues until a retention offer is viewed.\n```\n\nThese fields follow the method's [actionable values](https://github.com/berthelius/brand-machines-agents/blob/v0.2.0/skills/brand-machines/references/en/method.md#actionable-values--chapter-11-section-113): name, definition, activating situations, trade-off, example and counterexample.\n\nThe trade-off does the difficult work. The team can still invite feedback or propose a different plan. It has decided that neither may be a condition of leaving. Without that decision, the agent would be inventing policy while pretending to enforce it.\n\nCreate `web/pricing.md`:\n\n```\nCancel anytime. You are in control.\n```\n\nAnd `web/cancellation.md`, the confirmation copy shown after the flow completes:\n\n```\nYour subscription has ended. Access is now closed.\n```\n\nThe relevant behavior lives in `cancellation.py`:\n\n``` python\ndef cancel(subscription, *, reason=None, offer_seen=False):\n    if not reason:\n        return {\"status\": \"reason_required\"}\n    if not offer_seen:\n        return {\"status\": \"retention_required\"}\n\n    subscription[\"renewal_enabled\"] = False\n    return {\n        \"status\": \"confirmed\",\n        \"access_until\": subscription[\"access_until\"],\n    }\n```\n\nThis is a deliberately small state model. Authentication has already happened; there is no payment provider, persistence or production endpoint. It isolates the decision under review: whether cancellation depends on an explanation and an offer.\n\nThe guards implement that dependency. Even after the customer complies, the confirmation says access has ended while the function preserves the paid-through date. A review confined to tone would miss both defects.\n\nIn Brand Machines terms, the Core supplies the autonomy principle. The Brand OS includes the workflow that must enact it. The Skin includes the promise and confirmation people read. Reviewing their relationship reveals a contradiction that inspecting each file independently can conceal.\n\nInstall the skill in the project you want to review:\n\n```\nnpx skills add berthelius/brand-machines-agents --skill brand-machines\n```\n\nInvoke it with `$brand-machines` in Codex or `/brand-machines` in Claude Code. The installer follows the current repository version; the contracts linked in this article are pinned to [v0.2.0](https://github.com/berthelius/brand-machines-agents/releases/tag/v0.2.0).\n\nWith the example files attached, use this assignment:\n\nReview this fictional subscription product using Brand Machines. Read brand/principles.md as its approved identity; do not substitute Brand Machines' own reference identity. Inspect web/pricing.md, web/cancellation.md and cancellation.py together. Trace what happens when an authenticated customer requests cancellation without giving a reason or viewing an offer. Cite the file and passage behind each finding, connect it to P-AUTONOMY, and propose the smallest correction to behavior and copy. Follow the Guardian report contract. Keep assumptions and untested behavior explicit. Do not change policy or deploy anything.\n\nThat scope gives the reviewer enough context to question the implementation without granting it authority to redefine autonomy. In a real product, include the actual handler and billing integration. A route name or design mockup cannot establish what the payment provider does.\n\nThe [Guardian contract](https://github.com/berthelius/brand-machines-agents/blob/v0.2.0/skills/brand-machines/references/en/review.md) calls for a scoped judgment, findings, sources, limitations and a suggested revision. Each finding identifies the affected layer, principle and passage.\n\nHere is a **worked semantic report for this fixture**, written as an example of that contract. It is not output from the optional `bm.py` checker:\n\n```\nbrand: Example subscription product\nversion: teaching-fixture-1\nstatus: revise\nscope: Static review of the supplied cancellation model and copy\nfindings:\n  - layer: Brand OS\n    principle: P-AUTONOMY\n    passage: 'cancellation.py: if not reason / if not offer_seen'\n    evidence: >-\n      Both guards return before renewal_enabled becomes false.\n      A customer declining the interview cannot stop renewal.\n    suggested_revision: >-\n      Confirm cancellation independently of feedback and offers.\n  - layer: Skin\n    principle: P-AUTONOMY\n    passage: 'web/cancellation.md: Access is now closed.'\n    evidence: >-\n      The principle preserves paid access; cancellation.py returns\n      the existing access_until value. The message says otherwise.\n    suggested_revision: >-\n      Confirm that renewal is off and state when paid access ends.\nsources:\n  - brand/principles.md\n  - web/pricing.md\n  - web/cancellation.md\n  - cancellation.py\nlimitations:\n  - No billing provider or production interface was inspected.\nmechanical_result: bm.py was not run on this fixture.\nsuggested_revision: Repair the guards and confirmation; test the exit path.\n```\n\nThe important connection is between the guards, the state they prevent and the policy that forbids that dependency. “This feels off-brand” would leave the developer to rediscover the problem.\n\nThe skill's Python checker verifies declared checks and source integrity. It does not infer this cancellation contradiction. The semantic review belongs to the agent reading the sources. Neither a checker result nor this report authorizes a deployment.\n\nReplace the function in `cancellation.py` with:\n\n``` python\ndef cancel(subscription):\n    subscription[\"renewal_enabled\"] = False\n    return {\n        \"status\": \"confirmed\",\n        \"access_until\": subscription[\"access_until\"],\n    }\n```\n\nAfter confirmation, optional feedback can follow. It must not undo cancellation when ignored. Update the confirmation to “Renewal is off. Your paid access continues until {access_until},” using the date returned by the successful operation.\n\nSave this as `test_cancellation.py` beside the function:\n\n``` python\nfrom cancellation import cancel\n\nsubscription = {\n    \"renewal_enabled\": True,\n    \"access_until\": \"2026-10-31\",\n}\nreceipt = cancel(subscription)\n\nassert receipt[\"status\"] == \"confirmed\", receipt\nassert subscription[\"renewal_enabled\"] is False\nassert receipt[\"access_until\"] == \"2026-10-31\"\nassert subscription[\"access_until\"] == \"2026-10-31\"\nassert cancel(subscription) == receipt  # Repeating the request is harmless.\nprint(\"Cancellation confirmed; renewal off; paid access preserved.\")\n```\n\nRun `python3 test_cancellation.py`. Against the original function, it fails with `AssertionError: {'status': 'reason_required'}`. Against the replacement, it prints the success message. Those are the results of executing these snippets, separate from the illustrative semantic report above.\n\nThe test captures the approved decision in this model. Production needs evidence that cancellation reaches the billing provider, failures remain visible and the confirmation reflects persisted state. Until those parts are inspected, the review stays bounded to the fixture.\n\nThe most consequential correction here removes a dependency from a function. It also changes a sentence, but polishing the sentence alone would leave customers trapped behind the same guards.\n\nI wrote [*Brand Machines: A General Theory of Brand Systems*](https://machines.brthls.com/en/?utm_source=devto&utm_medium=social&utm_campaign=2026-09-30-brthls-devto-brand-machines-guardian&utm_content=article#book) to develop this relationship between identity and operation: how principles connect decisions across people, products and agents. The [agent skill](https://github.com/berthelius/brand-machines-agents) makes part of that method available inside a working project.\n\nFor a first review, choose a promise with observable consequences: cancellation, privacy, accessibility or support. Attach the principle and the code that determines what happens. A useful reviewer should be able to follow the promise all the way to the decision that keeps it.", "url": "https://wpnews.pro/news/your-ai-brand-reviewer-should-read-the-cancellation-code", "canonical_source": "https://dev.to/brthls/your-ai-brand-reviewer-should-read-the-cancellation-code-36ge", "published_at": "2026-09-30 15:00:12+00:00", "updated_at": "2026-09-30 15:17:01.410051+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-products"], "entities": ["Brand Machines", "Codex", "Claude Code", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/your-ai-brand-reviewer-should-read-the-cancellation-code", "markdown": "https://wpnews.pro/news/your-ai-brand-reviewer-should-read-the-cancellation-code.md", "text": "https://wpnews.pro/news/your-ai-brand-reviewer-should-read-the-cancellation-code.txt", "jsonld": "https://wpnews.pro/news/your-ai-brand-reviewer-should-read-the-cancellation-code.jsonld"}}