Eight named scenarios that could unsettle the 1 Oct 2026 → 31 Dec 2026 launch window. For each: how it triggers, who owns the response, the decision tree the owner walks, the compliance envelope preserved throughout, and the retrospective that follows.
Purpose. Reactive, not aspirational. This is not a “what if the campaign goes viral” document. It is a “what if something goes wrong — who owns it, what do they do in the next four hours” document. Companion to /launch-dashboard (the metric surface) and /launch-90-days (the ops calendar). Every escalation on the dashboard maps to a scenario here.
Compliance envelope preserved in every scenario response. No response — even in a red-alert incident — overrides: ABN, ACN, ACL 387398, mediation disclosure, complaints and privacy links, dignity floor, no beneficiaries named or identified. Y1 audited numbers (31 cases · $1.82M debt resolved · 23-day average resolution · 52% average K10 drop · $1,840 average cost/case · 87c direct-service ratio) appear verbatim when cited.
Corrina reads this once, before Sprint 56 opens (Mon 22 Sep 2026). She does not memorise it. She knows it exists, knows where it is, knows which scenario maps to which dashboard trigger, and knows that walking a scenario means opening this page and following the tree literally — not from memory.
Every scenario has the same structure: Trigger · Owner · Decision tree (with wall-clock times) · Compliance discipline · Retrospective. Wall-clock times are “T+” from the moment the trigger fires. Not from when it was noticed. If a Saturday complaint fires at 4pm and Corrina sees it at 9am Monday, T+0 was 4pm Saturday and the tree walks accordingly — but the “acknowledged within 2 hours” SLA is measured from notice time, not fire time. Both are logged.
Scenario A · Donation-take is below floor
A · Donation-take below floor
Medium risk
Trigger
Weekly metric 2 (Christmas Appeal donation total) fires red: <50% of prior-week rolling average, OR <$X floor once floor is calibrated in Week 2. First trigger possible: Mon 26 Oct 2026 (Week 4 of launch, first full week post donate-flow hardening 25 Oct).
Owner
Corrina compiles. Lisa decides response scope. Laurence checks the funnel technicals before any messaging response ships.
NOT a trigger
A single quiet weekday. A quiet weekend in isolation. The 25–31 Dec dark period (metric suspends). Any week where donate-page had a known outage on metric 11 — that fires Scenario H, not A.
T+0hCorrina posts to #marketing-triad naming the metric, the number, and one hypothesis. No response messaging drafted yet.
T+2hLaurence funnel-check. Is the donate flow reachable? Any error rate spike? Any recent code change? If yes to any — scenario switches to H.
T+4hCorrina channel-check. Which send/channel underperformed? Email? Social? Referrer? Segment isolation, not campaign-wide panic.
T+24hLisa decision. Three options: (1) hold cadence, this is noise; (2) additive touch this week (extra send, not louder send); (3) message-review of next scheduled send. NOT: emergency reduce-urgency Christmas Appeal ship. Founding-donor stewardship cadence untouched regardless.
T+48hIf option 2 or 3 chosen: draft ships to triad for approval BEFORE any additive touch goes out. Voice-fill status honoured. If voice-fill not in hand for an additive touch, the touch does not ship — the response is option 1 by default.
T+1wkRetrospective in Monday pack: what worked, what didn't, and did the response itself register on any other metric (unsub spike, complaint, list churn)? Response that fixes A but breaks C or D is a net loss.
Compliance discipline: no urgency-language additives. No “we need your help right now.” No implied guarantee. Y1 numbers verbatim if cited. Exclude phrase in every additive footer.
Scenario B · New-donor count falls week-on-week
B · New-donor count declining
Medium risk
Trigger
Weekly metric 3 fires red: new-donor count down >25% week-on-week for two consecutive weeks. Distinct from A — A is dollar-take, B is new-relationship formation.
Owner
Corrina compiles. Lisa decides messaging response. Distinct from A because the fix is upstream (awareness / channel) not downstream (conversion).
NOT a trigger
A single week decline (noise). A week where content-calendar planned steward-mode (fewer new-donor asks by design). Post-dark-period recovery week (early Jan — noise).
T+0hCorrina channel-split. Which channel is soft? Email opens? Social reach? Referrer inbound? Search? Segment isolation before response.
T+24hLisa decision on scope. Options: (1) hold, this is signal about awareness ceiling not campaign failure; (2) additive awareness touch (op-ed pitch, LinkedIn Lisa-voice piece, referrer nudge); (3) paid amplification consideration — requires Ad Grant policy check first.
T+48hIf paid: Corrina runs Ad Grant compliance pre-check. CTR floor 5%. No non-compliant landing pages. If any doubt — scenario response cannot include paid until Ad Grant health confirmed.
T+72hAdditive content drafted, triad-reviewed, voice-fill status honoured. If Lisa-voice piece — Lisa fills or piece does not ship. No generic-scaffold fallback for founder-voice content.
T+1wkRetrospective: did new-donor count recover, and did the response itself pass compliance envelope on the day it shipped?
Compliance discipline: awareness ceiling is real — the response is not to lower voice-quality to raise volume. If the honest voice-quality response cannot ship in the timing window, the trigger holds through the retrospective week.
Scenario C · List-quality event
C · List quality event (unsubs, bounces, spam flag)
Medium risk
Trigger
Weekly metric 4 fires red: unsubs >1.5% on a send, OR bounce rate >3% on a send, OR any spam-flag report from the ESP. Additionally: any single founding-donor unsub is manual-escalation regardless of list-wide rate.
Owner
Corrina owns list-hygiene. Lisa notified on every red. Any founding-donor cohort activity escalates to Lisa personally within 4 hours.
NOT a trigger
Bounces from a stale-address batch already flagged for cleaning. Unsubs on the day of the largest send of the sprint (expected volume-in-noise). Any single amber that clears next send.
T+0hCorrina list-snapshot. Which segments? Which send? Any correlation to a specific message frame? Note: correlation-to-frame is diagnostic gold if found.
T+4hFounding-donor check. Any founding-donor unsubs? Any founding-donor bounces? Escalate immediately to Lisa. Lisa personally acknowledges any founding-donor unsub with a warm hand-written follow-up. No exceptions.
T+24hESP integrity check. Domain reputation clean? SPF/DKIM current? Any warm-up regression from a bulk send? If technical — Laurence responds. If content-frame — Lisa responds.
T+48hContent review of next scheduled send. If the diagnostic pointed at a frame, that frame is retired for the sprint. Voice-fill on replacement mandatory.
T+1wkRetrospective: is list health back within green? What is the standing correction? Update /launch-90-days if a cadence change ships out of the response.
Compliance discipline: unsub processing within 24h is not a marketing minimum — it is a stewardship commitment. Every unsub is logged. No re-adding without written re-consent. Founding-donor unsubs are relationship events, not list events.
Scenario D · Privacy incident
D · Privacy incident or personal-information leak
High risk · Chair-first
Trigger
Any event involving personal information: mis-sent email with visible recipient list (CC not BCC), any inbound complaint mentioning “my details” or “my information,” any suspected breach on any system that touches donor or beneficiary data, any near-miss that a reasonable person would want disclosed. Zero-tolerance metric on daily read.
Owner
Chair-first, always. Not Lisa. Not Laurence. Chair. Because Chair owns board reputation surface. Chair may delegate but never before the initial Chair-decision is made.
NOT a trigger
Nothing. There is no “false alarm” class here. Every candidate event is worked as a real event until Chair rules otherwise.
T+0minWhoever notices, pings Chair. Text or call. Not email. Not Slack channel. Chair phone.
T+30minChair convenes: Chair + Lisa + Laurence. Facts gathering. What was leaked? To whom? How many people? Reconstructable timeline?
T+2hContainment decision. Can further exposure be stopped? Recall messages, revoke tokens, lock accounts. Laurence executes.
T+4hOAIC scoping. Is this a Notifiable Data Breach under the Privacy Act? Chair with legal counsel (if needed, engaged same-day). Any doubt — treat as notifiable and prepare accordingly.
T+24hAffected-party notification drafted. Lisa-voice if founding-donor cohort affected. Chair-voice if it's a board reputation event. Draft reviewed by all three before send.
T+48hBoard notification. Written to board. Filed under complaints log AND board minutes.
T+30dOAIC-timeline compliance retrospective. If notifiable, notification within 30 days is a legal minimum. Retrospective closes with lessons filed to /marketing-governance.
Compliance discipline: the affected-party notification carries the same envelope as any other content — ABN, ACN, ACL 387398, complaints, privacy, dignity. Do not construct different rules for incident communications.
Scenario E · Beneficiary-naming breach
E · Beneficiary named or identified
High risk · Chair-first
Trigger
Any published, scheduled, or draft-approved content that names, identifies, or renders identifiable any beneficiary. Includes: real names, uniquely identifying detail (rare condition + suburb, e.g.), photos, quotes attributed by name, case-vignettes that read composite but are not verifiably composite. Zero-tolerance daily metric.
Owner
Chair-first. Then full triad. Then complaints-log entry. Then board note.
NOT a trigger
Composite case-vignettes labelled composite in-line, drawn from Y1 audited aggregate (31 cases). Composite is a rigorously defined class, not an evasion — if a vignette pulls from a single case with identifiable detail, it is not composite even if labelled such.
T+0minContent is pulled immediately. Corrina or whoever notices — pull first, decide second. No “let me check with the triad first.” Pull.
T+30minChair notified. Chair convenes triad.
T+2hScope assessment. Was it published (public-reachable) or only scheduled/drafted? Cached anywhere (search engines, RSS, social)? Actual reach in the exposure window? If mediation-consented case — consent scope check.
T+4hBeneficiary contact. If any identifiable beneficiary is reachable, Chair makes contact personally. Apology, explanation, corrective actions. Ask what they want done — their wishes carry.
T+24hRetraction protocol. Public retraction on any surface that carried the content. Cache-purge requested where indexable. Correction filed alongside original artefact for permanent transparency.
T+48hBoard note. Written to board, filed under board minutes as a governance breach. Root-cause analysis with named process fix.
T+30dRetrospective: the beneficiary is followed up on their terms. The board rules on whether any staff / contractor consequences apply. The process fix is live in /marketing-governance and referenced in the next dashboard read.
Compliance discipline: the identified beneficiary's wishes lead. If they want the retraction quiet, it is quiet. If they want it loud, it is loud. If they want compensation, that goes to the board. Marketing operator preferences do not carry against beneficiary wishes in this scenario, ever.
Scenario F · Founder unavailable
F · Lisa or Laurence unavailable during launch
Medium risk
Trigger
Lisa or Laurence unavailable >48 hours during the 90-day window — illness, family emergency, planned leave. Distinct from “busy this afternoon” — a founder is unreachable, not just delayed.
Owner
The available founder plus Corrina plus Chair. Every content decision that would normally sit with the unavailable founder routes to the other two for adjusted-authority ruling.
NOT a trigger
A weekend where Lisa is off but reachable for founding-donor emergencies. Laurence coding-focus days where he handles voice-fill on his own schedule. Any planned unavailability communicated in advance and covered by explicit interim rulings.
T+0hAvailable founder + Chair + Corrina convene. Scope of unavailability. Estimated return. What content is in the pipeline over the window.
T+2hVoice-carrying content triage. Any voice-fill dependent on the unavailable founder — three options: (a) delay if delay does not break stewardship cadence; (b) available founder pinch-hits with their own register, clearly framed as such; (c) ship generic scaffold with placeholder-retained if piece can carry that. Founding-donor touches cannot use option (c).
T+24hChair-signed ruling on each queued piece, filed to /marketing-governance Weekly Signature File.
T+1wkWeekly re-review. Founder status update. Refresh queue rulings.
ReturnReturning founder briefing. Everything shipped in their absence, every decision Chair made in their voice. Full read within 48h of return.
Compliance discipline: no content shipped in an unavailable founder's name without their explicit ex-ante consent covering the exact frame, or Chair-signed ruling substituting the available founder's voice openly. No ghostwriting-for-Lisa or ghostwriting-for-Laurence, ever. This is not a discipline that softens under pressure.
Scenario G · External narrative attack
G · External narrative attack (media, social, competitor)
High risk · Chair-first
Trigger
Any external actor (journalist, social media account with reach, competing organisation, aggrieved former counterparty) publishes narrative that mischaracterises LWD, its numbers, its people, or its work. Distinct from criticism-in-good-faith (which is engaged with) — this is mischaracterisation-with-reach.
Owner
Chair-first. Chair, Lisa, and Laurence convene. Corrina does NOT respond publicly on any surface until triad ruling is issued. Silence in first 24h is a discipline, not an absence.
NOT a trigger
Individual social-media disagreement (engaged in Lisa's voice, on her judgement). Fair critical journalism on a real weakness (engaged transparently, not defensively). Anonymous forum grumbles at low reach (monitored, not responded to unless amplifying).
T+0hWhoever notices, pings Chair. Screenshot the artefact, URL, reach estimate. No engagement, no response, no like, no reply. Silence.
T+2hTriad convenes. Facts audit: what does the artefact claim? Which claims are false, which are honest disagreement, which are misinterpretation of accurate information?
T+8hResponse scope decision. Options: (a) no response — artefact will not travel; (b) private correction to the author; (c) public correction (rare); (d) legal engagement (rarer). Default is (a). Escalate deliberately.
T+24hIf (b) or (c): response drafted. Lisa or Chair voice depending on scope. Y1 numbers verbatim. Envelope preserved. No adversarial tone. Corrections offered, not demanded. Consulted with legal if any factual dispute may go to record.
T+48hStakeholder pre-brief if response likely to travel. Founding-donor cohort informed BEFORE they see it via media. Chair-signed private note.
T+1wkRetrospective: did response work? Did it draw more attention than the original? Did any downstream metric (founding-donor unsub, donor complaint, list churn) register? Lessons filed.
Compliance discipline: attacks tempt defensive posture; envelope preserves calm. No urgent claims. No hidden context. No numbers other than the six audited. If Y1 numbers are disputed, the audit-file provenance is offered — not more numbers.
Scenario H · Portal outage during scheduled send
H · Portal outage during scheduled campaign send
Medium risk
Trigger
Daily metric 2 fires red (donate-page 500-errors 3+, or any 5xx during a scheduled send). OR: weekly metric 11 (portal uptime) drops below 99.5%. OR: any donor reports inability to complete a donation via inbound-support.
Owner
Laurence-first. Then Corrina on comms scope. Then Lisa on personal-outreach need if any donor was affected in a way that requires direct follow-up.
NOT a trigger
Cloudflare region-specific outage that is confirmed upstream and expected to clear within minutes (monitor, don't respond). Any single 5xx outside a send window that clears on retry.
T+0minLaurence pages himself. Diagnosis: is it us, is it upstream, is it CDN? Rollback available? Fix-forward available?
T+15minCorrina holds any queued sends. No new campaign traffic to a broken donate-page. Any send in flight — assess whether a follow-up correction email is needed.
T+30minResolution or escalation. If resolved — document. If not — incident-comms drafted for stakeholder audiences.
T+2hAffected-donor identification. Any donation attempts that failed in the window — reconcile with ESP data if any. Direct follow-up to donors whose intended donations didn't process.
T+1wkRetrospective in Monday pack. Metric 11 recovery trajectory. Any downstream effect on metric 2 (donation take). Any donor communications outstanding.
Compliance discipline: incident comms carry the same envelope. Do not construct different rules for “we broke” comms. Apologise plainly. Do not overstate impact. Do not understate impact.
Retrospective discipline — across all 8
Every fired scenario ends in a retrospective, and every retrospective closes with process artefact. Not a slack thread. Not a “we agreed verbally.” A file, edited into /marketing-governance, dated, and referenced in the next dashboard read.
Retrospective is not blame-review. It is what-would-we-do-differently review. Named humans held to named commitments, with the understanding that a red event fired means the system detected something before it became a story — that is the metric surface working as designed. Punishing detection kills detection. The retrospective preserves detection while sharpening response.
End-of-sprint compilation. The sprint-56 review (/sprint-56-review) rolls up every fired scenario into a single Q1 read. Zero-fires is not the target — it might be a signal that the metric surface isn't sensitive enough. Sensible-fires-with-clean-response is the target.
What is NOT in this playbook
Fundraising strategy pivots. If the launch is fundamentally not working, that is a Sprint 57 planning conversation, not a reactive playbook scenario. Playbook is for events, not trend-lines.
Growth acceleration. If a campaign is over-performing, there is no reactive scenario — the discipline is to maintain the envelope regardless of dollar-take. Momentum is a Sprint 57 topic.
Beneficiary-side incidents. Anything involving CMS mediation practice, ACL 387398 conduct, or licensed-practitioner concerns routes to CMS operational surface, not this playbook. Chris (CMS) is the counterparty. The registrations-governance cupboard is where those file, distinct from this marketing playbook.
Board conflict scenarios. Any triad-internal disagreement or board-level dispute is not a marketing playbook scenario. Governance ruling routes through Chair per the standing constitution.