{
  "schema": "org-writing@v1",
  "slug": "exit-rights",
  "kg": {
    "id": "org:writing:exit-rights",
    "type": "brick",
    "graph": "/kg.json"
  },
  "title": "Exit rights",
  "subtitle": "A proven way out is the condition on which people commit, not the sign that they are leaving",
  "abstract": "Why the buyer who can leave is the buyer who commits, and what separates an exit that has been proven from one that has only been described. The canonical treatment of exit as the ground of trust.",
  "kind": "brick",
  "topics": [
    "Endings"
  ],
  "courseMemberships": [
    {
      "course": "org:courses:endings",
      "topic": "Endings",
      "wall": "org:walls:ethics",
      "position": 4,
      "total": 4
    }
  ],
  "publishedAt": "2026-08-03T00:00:00.000Z",
  "version": 1,
  "guidelinesVersion": 15,
  "brief": {
    "problem": {
      "text": "Software strategy has treated the cost of leaving as an asset to be raised, which produces customers who stay on platforms they dislike because their records are inside them and the arithmetic of exit gets worse every month.",
      "claims": [
        "the value of an installed base is the aggregate switching cost of its customers"
      ]
    },
    "mechanism": {
      "text": "A buyer weighing a long commitment is pricing the worst case, so a proven exit removes the worst case from the calculation and makes the commitment cheaper to make, which is why the ability to leave is what makes staying safe.",
      "claims": [
        "obliges cloud service providers to enable customers to switch"
      ]
    },
    "move": {
      "text": "Prove the exit rather than promising it, on a clean host, with a signed inventory and a verifier the recipient runs from their own copy, and let retention be earned by everything that is not the difficulty of leaving.",
      "claims": []
    }
  },
  "sources": [
    {
      "repo": "mnstry-strategy",
      "path": "docs/20-business/10-discovery/learnings/2026-07-11-sovereign-exit-demand-pattern.md"
    },
    {
      "repo": "mnstry-strategy",
      "path": "docs/20-business/10-discovery/framework/canonicals/pains/pain-resentful-retention.md"
    },
    {
      "repo": "mnstry-monorepo",
      "path": "distribution/client-exit/README.md"
    }
  ],
  "canonicalPath": "/writing/exit-rights/",
  "body": "Lock-in is usually described as an achievement. Carl Shapiro and Hal Varian put the strategy plainly in *Information Rules* in 1999: the value of an installed base is the aggregate switching cost of its customers, and the advice that follows is to raise it. A quarter of a century of software has taken that advice, and the result has a name in the customer's vocabulary rather than the vendor's. People stay on platforms they actively dislike because years of their records live inside them and the cost of getting out grows with every month they remain. The relationship survives on the arithmetic of departure rather than on anything anyone wanted.\n\nBuyers with something to lose have started treating this as a procurement gate instead of a preference. They arrive at the first conversation asking not about features but about the last day: whether the whole thing can be exported onto infrastructure they control, whether they can keep operating it if the vendor disappears, what is deposited with whom and what releases it. It sounds like distrust and it is the opposite, because it is the precondition for extending any. The mechanism runs against the intuition, since a buyer weighing a long commitment is really pricing the worst case, so a proven exit takes the worst case out of the calculation and makes the commitment cheaper to make. You can leave, therefore you can safely stay.\n\nRegulators arrived at the same place from the other side. The GDPR gave people a right to receive their data in a structured, commonly used, machine-readable format, and the EU Data Act now obliges cloud service providers to enable customers to switch and withdraws the charges that made switching expensive. What was once a competitive concession is turning into a floor, which means the vendors treating exit as a feature are working with a shrinking advantage.\n\nProven is the load-bearing word. An exit that has never been exercised is a hope with a doorway, the same failure the seed vault argument finds in archives, and it fails in the same ways: formats nobody can open, an inventory that does not match what is in the box, a restore that has only ever run on the machine that produced it. What proof looks like is unglamorous. A signed bundle with a complete inventory. A verifier the recipient runs from their own trusted copy rather than the one shipped inside the package, because a key carried in the box cannot vouch for the box. A rehearsal on a clean host where a lying installer and a self-attesting restore are required to fail. We build ours to that shape, and its honest status is engineering candidate rather than released, which is the sort of thing worth saying out loud, since an exit guarantee described more confidently than it has been tested is precisely the failure it claims to prevent.\n\nThe commercial consequence is that the moat moves. Where leaving is easy, retention has to be earned by the managed operating layer, the pace of the roadmap, and the judgment of the people running it, none of which can be accumulated by holding someone's history hostage for long enough. That is a harder business and a better one, and the companies that set the cost of leaving to zero first will be the ones still trusted when everybody else is made to.",
  "apparatus": {
    "note": "The human-facing essay is deliberately practical; this apparatus carries the full references, evidence-graded claims, article-local concepts, and research context behind it. Canonical concept definitions come from the concept registry.",
    "references": [
      {
        "id": "org:references:exit-rights:r01",
        "author": "Carl Shapiro and Hal R. Varian",
        "work": "Information Rules, A Strategic Guide to the Network Economy",
        "year": 1999,
        "relevance": "The canonical statement of the strategy the brick argues against: an installed base is worth the switching costs of the customers inside it, and the strategic instruction is to raise them."
      },
      {
        "id": "org:references:exit-rights:r02",
        "author": "European Union",
        "work": "General Data Protection Regulation, Article 20 (right to data portability)",
        "year": 2018,
        "relevance": "The first regulatory move against accumulation lock-in for personal data: a right to receive one's data in a structured, commonly used, machine-readable format."
      },
      {
        "id": "org:references:exit-rights:r03",
        "author": "European Union",
        "work": "Data Act, Regulation (EU) 2023/2854",
        "year": 2023,
        "relevance": "The same move extended to cloud services: obligations to enable switching between providers and a withdrawal of switching charges, which converts an exit guarantee from a differentiator into a floor."
      }
    ],
    "claims": [
      {
        "id": "org:claims:exit-rights:c01",
        "claim": "Shapiro and Varian's Information Rules (1999) holds that the value of an installed base is the aggregate switching cost of its customers, and advises raising it.",
        "basis": "The published text, whose lock-in chapter states the proposition and the strategy directly.",
        "confidence": "verified",
        "sources": []
      },
      {
        "id": "org:claims:exit-rights:c02",
        "claim": "GDPR Article 20 establishes a right to receive personal data in a structured, commonly used, machine-readable format.",
        "basis": "The regulation's own text.",
        "confidence": "verified",
        "sources": []
      },
      {
        "id": "org:claims:exit-rights:c03",
        "claim": "The EU Data Act, Regulation (EU) 2023/2854, obliges cloud service providers to enable customers to switch providers and withdraws switching charges.",
        "basis": "The regulation's own text; the switching-charge withdrawal is phased, so the obligation is described here without a date.",
        "confidence": "verified",
        "sources": []
      },
      {
        "id": "org:claims:exit-rights:c04",
        "claim": "Customers remain on platforms they actively dislike because accumulated records make migration prohibitively costly, and the lock-in deepens as more data accumulates.",
        "basis": "Our own discovery research on retention patterns, synthesizing public practitioner community sentiment with switching-cost estimates; a pattern account rather than a measured churn figure, and no vendor-specific number is carried.",
        "confidence": "directional",
        "sources": []
      },
      {
        "id": "org:claims:exit-rights:c05",
        "claim": "Buyers with established operations treat a provable exit as a procurement gate rather than a feature preference, raising it unprompted before any vendor messaging reaches them.",
        "basis": "Our own discovery record across serious prospects, deidentified; a small sample of accounts, consistent so far and not yet bounded by a counter-case.",
        "confidence": "directional",
        "sources": []
      },
      {
        "id": "org:claims:exit-rights:c06",
        "claim": "An exit bundle is proven only by rehearsal on a clean host, where a lying installer, a self-attesting restore, and a bundle-carried trust anchor are required to fail the check.",
        "basis": "Our own client-exit engineering package, whose verifier derives the expected tree from signed manifests and refuses a public key carried only inside the bundle; the package's release state remains engineering candidate, which the brick states.",
        "confidence": "verified",
        "sources": []
      }
    ],
    "concepts": [
      {
        "id": "org:concepts:accumulation-lock-in",
        "name": "Accumulation lock-in",
        "definition": "Retention produced by the growing cost of extracting accumulated records rather than by continued value. The customer's history is the hostage, the cost of departure rises with every month of use, and the relationship survives on the arithmetic of leaving rather than on anything either party wanted. Named as strategy in Shapiro and Varian's account of installed-base value as aggregate switching cost, and treated as a market failure by the portability and cloud-switching provisions that followed.",
        "provenance": "canonical"
      },
      {
        "id": "org:concepts:proven-exit",
        "name": "Proven exit",
        "definition": "An exit demonstrated by rehearsal rather than described in a contract. The proof has a shape: a signed bundle with a complete inventory, a verifier the recipient runs from their own trusted copy rather than the one shipped inside the package, and a restore exercised on a clean host where a lying installer and a self-attesting restore are required to fail. The same discipline the seed vault applies to archives, turned on a vendor relationship, and the ground on which a long commitment becomes cheap to make.",
        "provenance": "canonical"
      }
    ],
    "researchContext": "Harvested from two discovery documents and the client-exit engineering\npackage. The discovery sources are internal and account-specific: no\nprospect, client, segment name, deal, price, or quoted individual is carried\nhere, and the two claims that rest on them are graded directional with\ntheir sample described. The vendor-specific price and churn figures in the\nretention research are deliberately not used, because their basis is our own\nanalysis rather than a named public source; the public anchors in this\napparatus carry the argument instead. The engineering package is described\nonly as far as its README states, including its unreleased status, since a\nbrick about proven exits cannot itself overstate one. The archive parallel\nbelongs to the seed-vault brick and is cited, not re-argued."
  },
  "contract": "https://mnstry.org/contracts/org/org-writing.v1.schema.json",
  "releaseHash": "5fbe6b1807451f30ec204201f1526d85d7a3d97d223c4977e5351b5432b1585c",
  "versions": [
    {
      "version": 1,
      "cutAt": "2026-08-03",
      "note": "Initial publication, endings wave",
      "visibility": "published",
      "path": "/writing/exit-rights/",
      "contentHash": "sha256:101b7706de5dc452",
      "releaseHash": "5fbe6b1807451f30ec204201f1526d85d7a3d97d223c4977e5351b5432b1585c"
    }
  ]
}