CPO Trust Ledger + Claim Ledger
Two running files. The trust ledger protects your credibility. The claim ledger protects your model of reality. Start both on day 1. Four minutes a day, total.
From this piece
The template
CPO Trust Ledger + Claim Ledger
Two running files. The trust ledger protects your credibility. The claim ledger protects your model of reality. Start both on day 1. Four minutes a day, total.
Part 1: The Trust Ledger
Every commitment you make in your first 90 days, logged the moment you make it. "I'll look into that" is a commitment. "Let's revisit in two weeks" is a commitment. New executives bleed credibility through small dropped promises they never noticed making. The ledger makes the bleed visible.
The table
| Date | Commitment (verbatim if possible) | To whom | Due | Status | Notes |
|------|-----------------------------------|---------|-----|--------|-------|
| [YYYY-MM-DD] | [What you said you would do. "Get you an answer on the API deprecation timeline"] | [Name, function] | [Date. If you didn't give one, assign one now, then tell them] | [Open / Done / Renegotiated / Dropped-with-apology] | [Where the answer went, or why renegotiated] |
Rules
- Log within the hour. End of day at the latest. A commitment you remember on Friday is a commitment you already half-dropped.
- Vague commitments get dates anyway. If you said "soon," write a real date in the Due column and then send them the date. You just converted a leak into a deposit.
- "Renegotiated" is a legal state. "Quietly late" is not. If you cannot hit the date, say so before the date, propose a new one, log it.
- Dropped-with-apology beats silently open. Some commitments stop making sense. Close them out loud.
The Friday review ritual (15 minutes, non-negotiable)
Every Friday, same time, calendar block:
- Scan every Open row. For each one, do one of three things: do it now if under 10 minutes, schedule it concretely for next week, or renegotiate it today with a message to the person.
- Count your week. Commitments made versus closed. If made exceeds closed two weeks running, you are overpromising. Say "let me get back to you on whether I can commit to that" more often. That sentence is free.
- Spot-check one Done row. Did the person actually get the answer, or did you just produce it? Done means received.
Trust at day 90 is compound interest on this file.
Part 2: The Claim Ledger
Every meaningful claim anyone makes to you in the first 90 days, logged as a falsifiable statement. The listening tour produces 40 interviews of confident assertions, most of them partly wrong, all of them shaped by what each person wants you to believe. The claim ledger is how you turn opinions into an evidence backlog.
The table
| Claim (falsifiable form) | Source | Function | Confidence (1-5) | Contradicts | Evidence needed | Status |
|--------------------------|--------|----------|------------------|-------------|-----------------|--------|
| [Restate as something data could disprove. "Churn concentrates in accounts that never used feature X" not "the product is sticky"] | [Name or "3 people in sales"] | [Eng / Sales / CS / Finance / Board / Exec] | [Your read on how sure THEY were: 1 = hedge, 5 = staked their reputation] | [Row number of any claim this conflicts with, or blank] | [The specific query, eval, or document that would settle it] | [Untested / Confirmed / Refuted / Partly true] |
Rules
- Restate before you log. If you cannot restate the claim in a form data could contradict, it is a vibe, not a claim. Either push for specifics in the moment ("what would I see in the data if that were true?") or do not log it.
- Log contradictions on purpose. When two ledger rows conflict, that pair is gold. The contradiction tells you exactly which evidence to pull first, and resolving it teaches you whose model of the company to weight.
- Track frequency. When the same claim arrives from a third independent source, mark it high-frequency. High-frequency claims that turn out false are the most important findings of your first 90 days, because they are the org's shared illusions.
- Include your own priors. Your day-zero priors file is rows 1 through 10 of this ledger, with you as the source. They get tested like everyone else's claims.
The synthesis pass (run at day 30, day 60, day 85)
- Sort by status. Count Untested rows. At day 30 most rows are Untested and that is fine. At day 60, your highest-frequency and highest-contradiction rows should be Confirmed or Refuted. If they are not, your audits are drifting into tourism.
- Pull the refuted high-confidence claims. Claims people staked their reputation on that the data refuted. Handle these carefully and privately first. They are also your strongest evidence that the org needs new instruments.
- Pull the confirmed unpopular claims. Things one quiet person said that the data backs. Those people go on your coalition map as evidence-runners.
- Write the three-sentence summary. "The org believes X, the data says Y, the gap exists because Z." If you can write three of these by day 85, the situation section of your day-90 readout is done.
The two ledgers together
The trust ledger is what you owe people. The claim ledger is what the org owes reality. Review the first weekly, synthesize the second monthly. The day-90 readout is built almost entirely from the claim ledger. Your standing to deliver it is built entirely from the trust ledger.