Reviews, evidence, and privacy
Customer reviews are evidence summaries for selected Business workspaces in the private beta. They are not generally available and they are not proof of causation.
Read health and lifecycle separately
Section titled “Read health and lifecycle separately”The account header shows two independent states:
- Health describes observed product behavior. The available states include insufficient data, healthy, watch, at risk, and recovered.
- Lifecycle comes from a trusted update. It can show unknown, trial, active, cancellation scheduled, paused, or churned.
An account can therefore be behaviorally at risk while its lifecycle is still active, or show confirmed churn without a clear behavioral break. This is expected and should remain visible in any customer review.
Evidence coverage and missing data
Section titled “Evidence coverage and missing data”Evidence coverage is the confidence signal for a health result. It reflects how much of the configured account-level evidence was actually available for the review. Missing information lowers coverage. It does not count as negative behavior.
When there is not enough evidence, leadmaps shows Insufficient data, Not enough evidence, or No clear behavioral break. Do not replace these states with a churn assumption.
Examples of evidence that may contribute include recent activity, configured product value events, active users, feature use, product friction, and journey exits. The customer page shows these categories in plain language without exposing an internal scoring recipe.
Risk reviews and churn autopsies
Section titled “Risk reviews and churn autopsies”A risk review is created after an eligible observed health transition. A churn autopsy requires a trusted scheduled-cancellation or churn event.
A ready review can include:
- A plain-language headline and summary.
- The first stable change supported by the available evidence, or an honest statement that no stable first change was found.
- Links to the lifecycle update, tracked events, Experience issues, and an eligible session replay.
- The ordered account journey with recent steps and exits.
The review may say that one observed change was the strongest available association. It must not say that the change caused the customer outcome.
Every review uses deterministic customer-facing copy. An optional AI evidence selector can be enabled only after the separate private-beta provider and privacy gates pass. It receives bounded aggregate factors and opaque evidence tokens, not workspace, account, user, route, event, session, contact, or provider identifiers. It can select citations only and cannot write the headline or summary. If the provider is unavailable or returns unsupported output, leadmaps keeps the deterministic evidence set.
Open the cited evidence
Section titled “Open the cited evidence”Evidence links return to the existing authorized dashboard surface. Opening a link rechecks workspace access. A copied internal route does not bypass tenant permissions.
Session replay is optional evidence. A new replay citation appears only when replay was captured with the required consent, the account association is explicit, and replay data is available when the review is generated. Customer health does not start replay capture or weaken masking rules.
A historical citation can outlive the underlying event or replay after the workspace retention period ends. The source route can then be unavailable. Treat it as missing evidence, not as support for a churn conclusion. A subject erasure separately removes the affected account membership and queues the account for a review rebuild from the evidence that remains.
Give feedback
Section titled “Give feedback”Owners and admins answer two separate questions on ready reviews: whether the review was useful, and whether every displayed finding opened matching evidence. Choose Yes for usefulness only when the review supports a specific next investigation or truthfully rules one out. Confirm evidence correctness only after opening every cited item. One reviewer can submit one immutable response for a review.
The first prompt is Was this review useful? The evidence-correctness prompt is separate so a useful review cannot hide a broken or mismatched citation.
Feedback is used to evaluate the private beta. It does not rewrite lifecycle history, change the current health state, or send customer data to a provider.
Privacy boundary
Section titled “Privacy boundary”- Account identity comes only from an explicit account identifier and known user association.
- Browser behavior never becomes a trusted churn event.
- Review evidence stores links to authorized data rather than copying replay content or raw page contents into the review.
- Query strings, private contact data, provider credentials, and replay bytes are not included in Integration Hub customer-health messages.
- Account evidence remains in the workspace data region. A regional move must verify the copied customer data before deleting its source.
- Subject erasure removes affected membership identity and rebuilds affected derived reviews from the evidence that remains.
Read Consent gating, PII filtering, and Data retention for the surrounding data controls.
Integration Hub actions
Section titled “Integration Hub actions”After the underlying account state is verified, an owner or admin can create an opt-in automation for a supported customer transition. Examples include at risk, recovered, cancellation scheduled, churned, reactivated, and review ready.
The action sends only the bounded customer-health fields shown in its preview. It does not send raw analytics, page contents, replay data, or provider secrets. Retries reuse the logical action identity so a temporary destination failure does not create a second customer action.
Limitations
Section titled “Limitations”- Customer health remains a selected-workspace Business private beta.
- Reviews are account-level. They are not a substitute for customer interviews, support history, billing facts, or contractual context.
- A review can explain only the product evidence leadmaps received and was allowed to retain.
- Missing or revoked replay consent means no replay evidence is available.
- A connected CRM is trusted only for the fields and status values explicitly mapped by an owner or admin.
- Externally shareable review links are not part of this beta.