War-game a spam threshold change before precision claims, false-positive budgets, and rollback steps harden into what every block will quote.
Spam threshold changes fail when the runbook invents precision the classifier never had, when allowlists dual-count the same sender path as blocked and as exempt, when money routes still lack a named false-positive owner, and when ops cannot show who owns the decision after a partial threshold misfire. A neat policy PDF is not evidence.
Freeze the threshold
One sentence for why the threshold exists, which surfaces and message types it covers, who owns precision classes, logging, and rollback, and the abort trigger if false positives or appeal lag past a named threshold. Attach the draft cut line, sample classifier logs, allowlist map, and the measured path from detection to restored traffic. If trust, growth, and product disagree on which surfaces are truly covered, stop and reconcile first.
Name the decision you will make if the war game finds nothing new, and the delay criteria if any money path still lacks a named rollback owner or a verified canary.
Who speaks
Trust and safety should say where precision invents coverage or hides shared rules across surfaces. Growth should say where bypasses still leave the queue and become standing exceptions. Product should say which customer decision breaks first when legitimate traffic is blocked. Support should show how status language trails the customer-visible complaint rate. A skeptic should pick the claim that looks strongest and is least evidenced by prior threshold drills.
Give every seat the same source pack. Secret allowlists for favorite senders only create fake calm. Require a canary surface with a measured open-and-reconcile pass before any money path joins the threshold. If the canary still depends on a verbal allowlist, keep the change in hold.
Private loop
Feed Pingpong the draft threshold, canary notes, and open risk list. Early passes steelman the design. Later passes attack from trust, growth, product, support, and skeptic seats. End with a pass that turns surviving objections into clearer owners, a timed canary, or a hold. Delete invented "we already filter cleanly" claims and dual-counted success rates.
Ask for a month-after narrative: what happens if a partner quotes a retired allowlist, if a billing message path starts failing precision checks, or if an operator widens an allowlist under launch pressure. If those stories outrun the mitigation plan, fix the package before you ship the cut line.
Pair with the trust and safety lead seat, a report queue SLA review, a ban appeals ladder stress test, a UGC moderation ladder review, and the war-game decisions hub.