Course 11 · Advanced $149 New in v2

Monetization, Compliance and Resilience

Small publishers rarely fail because revenue was too low. They fail because all of it came from one place, and that place changed its mind. This course builds a revenue stack with hard concentration limits, a compliance floor you can defend, and a live risk register that turns bad surprises into pre-decided responses.

  • 6 lessons
  • 6 labs
  • 6 artifacts
  • 1 scenario assessment
  • ≈6 hours
  • Prereq: Course 10
Your progress · 0/6 lessons0%

Overview

Everything to this point built assets and measurement. This course decides how they earn, and what limits that earning must respect. The single most important idea is Rule 7 made operational: concentration is the dominant risk for a small publisher, and it is always most comfortable at exactly the moment it is most dangerous, because concentration and success look identical from the inside.

The four limits — affiliate ≤30%, single site ≤50%, traffic source ≤60%, single sponsor ≤25% — are deliberately uncomfortable. They will cost you revenue in a good quarter. That is the premium you pay to still be operating after a bad one.

LessonLabArtifact
11.1 Revenue stackModel 5 streams against real costRevenue stack model
11.2 Concentration limitsMeasure all four, per siteConcentration report
11.3 Ad operationsCompute revenue per visit vs experience costAd policy & density record
11.4 Owned-audience revenuePrice and test one direct offerDirect offer test
11.5 Compliance floorAudit every commercial surfaceCompliance audit
11.6 Risk registerPopulate all 10 categoriesLive risk register

11.1 What belongs in the revenue stack?

What is it?

A deliberate mix of revenue streams chosen for how they behave under stress — display advertising, affiliate, sponsorship, direct products, and services — each modelled against the fully loaded cost of serving it.

Why it matters

Streams fail differently. Display revenue moves with advertising markets and with traffic; affiliate revenue can be terminated by one partner's decision; sponsorship depends on a small number of relationships; direct product revenue depends on your owned audience and almost nothing else. A stack whose components fail for different reasons is resilient; three streams that all depend on the same traffic are one stream wearing three hats.

How to do it

  1. Model each stream with its own revenue driver, its loaded cost to operate, and its dominant failure mode.
  2. Identify which streams share a driver. Display and affiliate both scale with search traffic — treat them as correlated, not diversified.
  3. Prioritise streams that depend on the owned audience, because those are the ones you control.
  4. Cost each stream honestly: sponsorship needs sales time, products need support time, ads need ops time.
  5. Rank by contribution margin, not gross revenue. A stream that grosses well and consumes ten hours a week may be your worst.
  6. Re-model quarterly, and after any partner or platform change.
Revenue streams, drivers and failure modes
StreamDriverDominant failure modeOperating cost
Display advertisingTraffic volume × RPMTraffic decline; ad market softeningLow, but degrades experience
AffiliateCommercial-intent traffic × conversionProgramme terminated or rates cut unilaterallyMedium: verification and compliance
SponsorshipEngaged owned audienceFew relationships; slow sales cyclesHigh: sales and account time
Direct productOwned audience trustWeak product-market fit; support loadHigh to build, moderate to run
ServicesYour own hoursDoes not scale; displaces asset buildingVery high: your time

Tools needed

Revenue & RPM calculator, unit economics model, and your Course 7.5 loaded costs.

Lab 11.1

Model five streams for one site with driver, loaded operating cost, contribution margin and failure mode. Then mark which streams share a driver — that grouping, not the count of streams, tells you how diversified you actually are.

Artifact

Revenue stack model
  Stream | Driver | Gross | Loaded operating cost | CONTRIBUTION MARGIN | Failure mode
  Streams sharing a driver (correlated, not diversified): ___
  True independent stream count: ___
  Ranked by contribution margin: 1___ 2___ 3___

Common mistakes

  • Counting display and affiliate as diversification when both scale with the same traffic.
  • Chasing gross revenue into a stream whose operating cost eats the margin.
  • Drifting into services because the cash is immediate, then having no hours left to build assets.

Pro astuces

  • Count independent drivers, not streams. Most "five-stream" publishers have two drivers, and both are search traffic.
  • Services are legitimate as deliberate bridge funding with an end date. They are dangerous as a drift, because they consume exactly the hours the assets need.
Not saved yet
Artifact: Revenue stack model

11.2 What are the four concentration limits?

What is it?

Four hard ceilings, checked monthly: affiliate revenue ≤30% of total, any single site ≤50% of portfolio revenue, any single traffic source ≤60% of arrivals, any single sponsor ≤25% of revenue.

Why it matters

These are the numbers that determine whether one external decision ends your business. A publisher with 80% of revenue from one affiliate programme is not running a business, they are running a position in someone else's programme. The limits exist because concentration feels like focus while it is accumulating; only a pre-committed number will make you act against a stream that is currently performing.

How to do it

  1. Measure all four monthly, from the Course 9 dashboard, on the same date.
  2. Treat approaching a limit as the trigger, not breaching it. At 80% of a limit, start the diversification work.
  3. Diversify by building the alternative, not by damaging the leading stream. Growing a second stream is the only healthy correction.
  4. Write the pre-committed response for each breach before it happens, so the decision is not made under pressure or optimism.
  5. Reassess after every partner change, platform change or site launch — those events move the ratios fastest.
  6. Record every breach and its resolution. A repeated breach in the same category is a structural problem, not an incident.
The four limits and their pre-committed responses
LimitCeilingWhy this numberPre-committed response on breach
Affiliate share of revenue≤30%Programmes are terminated or repriced unilaterally, often without noticeFreeze new affiliate assets; build sponsorship or direct product until the ratio recovers
Single site share of revenue≤50%One site's displacement should not end the portfolioInvest the next quarter's capacity in the second-strongest site only
Single traffic source share≤60%Intermediaries change behaviour without warning or explanationRedirect acquisition effort to owned channels; re-run the Course 3 newsletter push
Single sponsor share of revenue≤25%One relationship ending should not be an emergencyDo not renew above the cap; open two replacement conversations before renewal

Image placeholder — concentration limits panel

Generation prompt: "Flat vector dashboard panel showing four horizontal gauge bars labelled 'Affiliate share 30% cap', 'Largest site 50% cap', 'Top traffic source 60% cap', 'Top sponsor 25% cap'; each bar has a dashed cap marker, three bars filled within the cap in teal and one bar exceeding its cap shown in amber; slate grey minimal interface, thin strokes, no photographic elements, generous white space, 16:9."

Prefer a real screenshot? Steps to produce it
  1. Compute all four ratios from one month of real revenue and arrivals data.
  2. Enter them into your Course 9.6 dashboard with the cap shown beside each value.
  3. Capture the panel while at least one ratio is genuinely near or above its cap, so the warning state is real rather than staged.
  4. Capture at 1440px wide, 2× device pixel ratio, light theme.
  5. Convert absolute revenue to percentages before publishing, and caption with the month measured.
Four ratios, four caps, four responses decided in advance.

Tools needed

Your Course 9.6 dashboard, the risk register, and revenue data by stream and by site.

Lab 11.2

Compute all four ratios for the current month. For each, write the pre-committed response now, while nothing is breached. Then identify which limit you are closest to and start the corresponding work this week.

Artifact

Concentration report (monthly)
  Affiliate ___% (cap 30) | Largest site ___% (cap 50)
  Top traffic source ___% (cap 60) | Top sponsor ___% (cap 25)
  Closest to breach: ___  | At 80% of cap? Y/N → diversification work started ___
  Pre-committed response per limit (written before breach): ___
  Breach history: date | limit | cause | resolution

Common mistakes

  • Measuring the ratios only when something has already gone wrong, which is when correction is most expensive.
  • "Correcting" a breach by cutting the winning stream, which reduces revenue without building resilience.
  • Granting yourself an exception because the concentrated stream is currently growing — the exact reasoning the limit exists to override.

Pro astuces

  • Act at 80% of a cap. At 100% you are correcting under pressure, and the cheapest options have already gone.
  • The traffic-source limit is the one that most directly answers the governing question. Watch it more closely than the revenue ones.

Knowledge check (3 questions)

1. Why act at 80% of a limit rather than at the limit?

Because building an alternative stream takes months. If you wait for the breach, you are correcting under pressure with fewer options and less cash, and the temptation to grant an exception is at its highest.

2. Why is cutting the leading stream the wrong correction?

It reduces total revenue without adding any independent driver, so the portfolio becomes smaller and no more resilient. The only healthy correction is growing the alternative, which is why the trigger has to fire early enough to allow it.

3. Why do display and affiliate not count as two independent streams?

Both are driven by the same underlying traffic. If that traffic is displaced, both fall together — so they are correlated exposure, not diversification. Independence is counted in drivers, not in stream names.

Self-score: Not scored yet
Not saved yet
Artifact: Concentration report

11.3 How do you run ads without destroying the asset?

What is it?

An explicit written ad policy: how many slots per template, where they may never appear, the experience cost measured in Core Web Vitals, and the revenue-per-visit threshold below which advertising is not worth running at all.

Why it matters

Display advertising is the easiest revenue to add and the easiest way to degrade the thing generating the revenue. The degradation is gradual and each individual slot seems harmless, which is why only a written cap works. On low traffic, advertising can also earn so little that it is genuinely not worth its cost in experience — and that is a legitimate finding, not a failure.

How to do it

  1. Write the slot cap per template and the forbidden positions: never above the answer in the first screen, never inside a tool's input area, never interrupting a table or a code block.
  2. Reserve every slot's height in CSS at every breakpoint, so nothing shifts whether the ad loads or fails. This site is the worked example.
  3. Measure the experience cost: Core Web Vitals with ads live versus blocked, on a mid-range phone. That gap is the price you are paying.
  4. Compute revenue per visit and per thousand visits. Compare against the experience cost and against what a direct offer earns on the same page.
  5. Set a floor: below a stated revenue per thousand visits, remove the slot. Empty or near-worthless inventory costs real experience for nothing.
  6. Keep ads off the highest-intent commercial pages where they compete with better-converting revenue.
This site's own ad policy, stated openly

Every page here carries responsive ad slots: one leaderboard below the page head, two in-article slots at section boundaries, one sidebar, one footer. Each has its height reserved in CSS per breakpoint, so the layout is identical whether or not an ad loads — and none sits above the page's main answer. That is the pattern the lesson describes, published rather than merely recommended.

Tools needed

Revenue & RPM calculator, CWV measurements from Course 8.5, and your ad configuration.

Lab 11.3

Write the ad policy with a numeric slot cap and forbidden positions. Measure revenue per thousand visits per template and the CWV gap with ads live versus blocked. Then decide, with a number, whether each slot earns its experience cost — and remove the ones that do not.

Artifact

Ad policy & density record
  POLICY: slots per template ___ | forbidden positions: ___ | reserved heights confirmed? Y/N
  PER TEMPLATE: revenue per 1000 visits ___ | CWV with ads ___ | without ads ___ | gap ___
  Floor: remove slot below ___ per 1000 visits
  Slots removed: ___ | Revenue change ___ | CWV change ___

Common mistakes

  • Adding slots to compensate for falling traffic, accelerating the decline in the experience that produced the traffic.
  • Running ads on high-intent commercial pages where they cannibalise better-converting revenue.
  • Never measuring the CWV gap, so the experience cost of advertising is never actually known.

Pro astuces

  • Removing the worst-performing slot often changes revenue very little and improves the experience measurably. Test it before assuming otherwise.
  • On a small site, one relevant sponsorship frequently out-earns every display slot combined, at a fraction of the experience cost.
Not saved yet
Artifact: Ad policy & density record

11.4 How do you earn from an owned audience?

What is it?

Revenue that comes directly from the people who chose to hear from you: paid briefings, premium data access, templates and tools, cohort teaching, or clearly labelled newsletter sponsorship.

Why it matters

This is the only revenue whose driver you own. It does not require an intermediary to send anyone, it is not repriced by a partner, and it is the direct commercial expression of the governing question. It is also the hardest to start, because it requires something people will actually pay for — which is exactly why it is worth building.

How to do it

  1. Ask what your audience currently pays someone else to do, and whether your data or tools do it better.
  2. Start with the smallest sellable thing — one template, one dataset, one paid briefing — not a course or a membership.
  3. Price against the buyer's alternative cost, not against your production hours.
  4. Sell to a small group first. Ten paying customers teach you more than a thousand subscribers.
  5. Keep the free asset genuinely valuable. A free tier degraded to force upgrades destroys the trust the whole portfolio rests on.
  6. Model the support cost before launching. Support is the line that turns a promising product into a bad business.
Direct offer types by effort and durability
OfferBuild effortSupport loadBest when
Template or spreadsheet packLowVery lowYour artifacts are already the product
Premium data accessLow if the API existsLowYou run a recurring dataset (Course 9.5)
Paid briefing tierMediumMedium — it is recurring foreverThe free brief already has engaged readers
Newsletter sponsorshipLowMedium — sales timeEngaged audience ≥ a few thousand
Cohort teachingHighHighYou have demonstrable outcomes to teach
Selling has its own compliance obligations

Taking payment introduces consumer rights, refund and cancellation duties, tax registration and invoicing requirements, and clear pre-contract disclosure — all varying by jurisdiction and by whether buyers are consumers or businesses. Take the legal counsel question sheet to a qualified adviser before your first sale. This is not legal or tax advice.

Tools needed

Your newsletter platform, a payment provider, your existing artifacts, and professional advice.

Lab 11.4

Define one smallest sellable offer, price it against the buyer's alternative, and offer it to a small segment of your engaged audience. Record conversion, revenue, refunds and support minutes per customer — then decide whether the margin survives the support load.

Artifact

Direct offer test
  Offer | What buyers currently pay for instead | Price | Basis for the price
  Segment size | Conversions | Revenue | Refunds | Support minutes per customer
  Margin after support: ___  | Free tier degraded? MUST BE NO
  Continue / modify / stop — decided in writing

Common mistakes

  • Building a large course before validating that anyone will pay for a small thing.
  • Pricing from your production hours rather than from the buyer's alternative cost.
  • Degrading the free asset to drive upgrades, which destroys the audience the offer depends on.

Pro astuces

  • Your Course 7–10 artifacts are often the product. People pay for the completed register, the model and the template far more readily than for the explanation of them.
  • Measure support minutes per customer from the first sale. It is the number that decides whether the offer is a business or a job.
Not saved yet
Artifact: Direct offer test

11.5 What is the compliance floor?

What is it?

The minimum standard every commercial surface must meet before it earns anything: clear disclosure, accurate claims, honest comparisons, working contact and complaint routes, and correct handling of data and payments.

Why it matters

Compliance failures are correlated with revenue: the pages that earn most are the ones with affiliate links, price claims and recommendations. A single serious failure can end an advertising relationship, an affiliate programme or the business — and in the Phase 1 niches, where readers act on financial and security guidance, the potential harm is real, not merely reputational.

How to do it

  1. Inventory every commercial surface: affiliate pages, comparisons, sponsored content, newsletter ads, the display slots themselves, and any paid product.
  2. For each, verify disclosure is clear, prominent and placed before the reader acts — not in a footer. See the FTC endorsement, influencer and review guidance.
  3. Verify every commercial claim against a primary source, and register it with a short volatility cycle (Course 7.3).
  4. Disclose common ownership of the three sites wherever they reference or review each other.
  5. Ensure contact, complaint and correction routes exist and are answered — an unmonitored contact form is itself a failure.
  6. Take professional advice on your actual pages, in your jurisdiction, and record the date. Re-check annually and whenever you add a revenue stream.
Compliance audit (per commercial surface)
  Surface | Type (affiliate / comparison / sponsored / display / paid product)
  Disclosure present? | Placement (before the reader acts?) | Exact wording
  Claims verified against primary source? | In claim register? | Cycle length
  Common ownership disclosed where relevant? Y/N
  Contact & complaint route working and monitored? Y/N
  Professional advice taken on ___ (date) | jurisdiction ___ | next review ___
  FAILURES FOUND: ___  | Fixed on ___
This course cannot tell you your obligations

Disclosure standards, consumer protection rules, tax duties, data protection requirements and sector-specific regulation (financial promotions in particular) vary by jurisdiction and by audience. Everything here is an editorial floor to raise with a qualified adviser — not a compliance opinion, and not legal, financial or tax advice.

Tools needed

The legal question sheet, your claim register, your disclosure pages, and a qualified adviser.

Lab 11.5

Audit every commercial surface across all three sites against the floor. Fix every failure before the next publishing action. Then book the professional review and record the date.

Artifact

Compliance audit covering every commercial surface, with failures, fixes and the advice date recorded

Common mistakes

  • Footer-only disclosure, which arrives after the decision it should have informed.
  • Stale prices on the highest-revenue pages — simultaneously a trust and a compliance failure.
  • An unmonitored contact form, which converts a solvable complaint into an escalation.

Pro astuces

  • Audit the highest-revenue pages first. Exposure and earnings are concentrated in the same place.
  • Keep the dated advice record with the audit. It is the first thing a partner's compliance team asks for, and it makes renewals straightforward.
Not saved yet
Artifact: Compliance audit

11.6 How do you keep a risk register alive?

What is it?

Rule 7. A living register across ten categories, where each risk has a leading indicator you actually measure, a pre-committed trigger, an owner and a review date — reviewed monthly, not written once.

Why it matters

The register's purpose is to convert panic into procedure. When traffic halves or a programme is terminated, the response should already be written down, decided calmly, by someone who was not under pressure. A register written once and never reviewed is a document; one reviewed monthly is an operating system.

How to do it

  1. Populate all ten categories, even where the current exposure is low. Empty categories are where surprises come from.
  2. Give every risk a leading indicator that you already measure. A risk with no measurable indicator cannot be managed.
  3. Write the trigger as a decision, not an intention: what will be done, by whom, within what period.
  4. Review monthly alongside the concentration report and the dashboard. Update the indicator values, not just the text.
  5. Record every time a trigger fired and what actually happened. That history is the only real test of whether the register works.
  6. Retire risks that no longer apply, and add new ones after every platform, partner or regulatory change.
The ten risk categories with example indicators and triggers
#CategoryLeading indicatorPre-committed trigger
1Platform / algorithmImpressions stable, clicks falling 3 monthsRun displacement triage (Course 6.6) on affected assets
2Traffic concentrationTop source >60% of arrivalsRedirect acquisition to owned channels for one quarter
3Revenue concentrationAffiliate >30%, sponsor >25%, site >50%Freeze the concentrated stream; build the alternative
4Compliance / disclosureAny commercial claim past expiry, or a missing disclosurePublishing freeze until the register is clear
5Content accuracyCorrections per month rising; reviewer backlogCut publishing rate to the reviewed capacity
6Key personOne person holds an undocumented critical processDocument and cross-train within 30 days
7Technical / hostingFailed deploys, uptime incidents, expiring certificatesRun the Course 5 ops runbook; verify backups restore
8Data loss / portabilityExport→import round trip untested this quarterRe-test immediately; archive an owned snapshot
9Financial runwayMonths of cost covered below the stated minimumApply Rule 2 kill criteria at the next gate, without renegotiation
10Reputational / partnerUnresolved complaints; partner concerns raisedEscalate, respond publicly if warranted, log the correction

Tools needed

The risk register, your Course 9.6 dashboard, and a fixed monthly review slot.

Lab 11.6

Populate all ten categories with a measured indicator value, a pre-committed trigger and an owner. Then check which triggers are already met today — that is your real current position, and it is usually more than expected.

Artifact

Live risk register (10 categories)
  # | Category | Risk statement | Leading indicator | CURRENT VALUE | Trigger | Owner | Review date
  Triggers already met today: ___
  Trigger history: date fired | category | action taken | outcome
  Next monthly review: ___

Common mistakes

  • Lagging indicators — "revenue fell" is an outcome, not a warning.
  • Triggers written as intentions ("consider diversifying") rather than as decisions with a deadline and an owner.
  • Writing the register once at launch and never updating the indicator values, which is the most common failure of all.

Pro astuces

  • Reviewing the register beside the concentration report takes twenty minutes a month and is the highest-return governance activity in the portfolio.
  • The trigger history is what makes the register credible to a buyer, a partner or an advertiser. It proves the governance is real rather than decorative.
Not saved yet
Artifact: Live risk register

Scenario assessment: the best quarter and the worst position

Your best quarter yet. One affiliate programme now supplies 64% of portfolio revenue after the partner raised commissions; the B2B SaaS site accounts for 71% of the total; organic search delivers 78% of arrivals; and a single sponsor has just offered a twelve-month renewal that would represent 34% of revenue. Every concentration limit is breached. The affiliate partner has also asked you to remove the drawbacks column from your comparison table "to keep the messaging consistent", hinting that the improved rate depends on it. Cash runway is nine months. The Month 9 pruning gate is in three weeks.

Decide first, then open (5 questions)

1. Is a record quarter with four breached limits a good position?

No — it is the most dangerous position in the curriculum, and it looks like success from the inside. Every independent driver has collapsed into one: the affiliate programme, on one site, fed by one traffic source. A single decision by the partner or the intermediary removes most of the revenue at once. This is precisely the situation Rule 7 and the four limits exist to catch while cash is still available.

2. How do you respond to the request to remove the drawbacks column?

Refuse, unambiguously. Removing drawbacks because a commission depends on it makes the comparison misleading and turns the page into undisclosed paid advocacy — a breach of the Course 8.4 standard and a consumer-protection risk. The fact that the rate improvement is implicitly conditional makes it worse, not more acceptable. Document the request and the refusal in the register under compliance and partner risk.

3. Should the sponsor renewal be signed at 34% of revenue?

Not at that level. The cap is 25%, and signing a twelve-month commitment above it converts a monthly ratio problem into a year-long structural dependency. Negotiate a smaller scope that fits the cap, or a shorter term, and open two replacement conversations before renewal — that is the pre-committed response from 11.2.

4. With nine months of runway, is there room to do nothing until the numbers worsen?

Nine months of runway is exactly enough to build an alternative stream, and not nearly enough to survive losing 64% of revenue without one. The pre-committed responses fire now: freeze new affiliate assets, invest capacity in the second-strongest site, redirect acquisition to owned channels, and accelerate the Course 11.4 direct offer. Waiting spends the only asset that makes correction possible — time.

5. What happens at the Month 9 gate?

The gate runs on evidence, not on the quarter's revenue. Present the four ratios, the trigger history including the refused request, and the diversification work started. Contribution margin per site — not gross revenue — decides keep, prune or kill. A site can be growing and still fail the gate if all of its growth is concentrated exposure, and that verdict should be recorded plainly.

Self-score: Not scored yet

Final project: a revenue stack with limits and a live register

Make the money durable: diversified drivers, hard caps, a defensible compliance position, and a register that turns surprises into procedures.

Deliverable
1. Revenue stack model: 5 streams with driver, loaded cost, contribution margin and failure mode — plus the TRUE independent driver count
2. Concentration report: all four ratios measured, with a pre-committed response written for each limit
3. Ad policy: numeric slot cap, forbidden positions, reserved heights verified, revenue per 1000 visits per template, CWV gap with ads live vs blocked, and a removal floor
4. One direct offer tested with a real small segment: price basis, conversions, refunds, support minutes per customer, margin after support
5. Compliance audit of EVERY commercial surface across all sites, failures fixed, professional advice date recorded
6. Live risk register: all 10 categories with measured indicator values, pre-committed triggers and owners
7. A list of triggers already met today, with the work started against each

Pass standard: you can state all four concentration ratios with a date, every commercial surface discloses before the reader acts, and every one of the ten risk categories has a measured indicator and a written trigger.

Course 11 checklist

0 complete

AI-agent prompt for Course 11

Revenue resilience & compliance auditor
Act as a revenue resilience auditor for an independent publisher running three monetised sites in SMB finance, B2B SaaS/AI tools, and SMB cybersecurity. Treat CONCENTRATION as the dominant risk, not low revenue.

I will paste: revenue by stream and by site, arrivals by source, my loaded costs, my sponsor and affiliate relationships, my ad layout, and my cash runway.

Do this:
1. Model every revenue stream with its DRIVER, loaded operating cost, contribution margin and dominant failure mode. Then group streams that share a driver and tell me my TRUE independent driver count — not my stream count.
2. Compute the four concentration ratios: affiliate share of revenue (cap 30%), largest single site (cap 50%), largest single traffic source (cap 60%), largest single sponsor (cap 25%). Flag anything above 80% of its cap as requiring action now.
3. For each limit, write a pre-committed response that BUILDS AN ALTERNATIVE rather than cutting the leading stream. Never recommend damaging a performing stream to fix a ratio.
4. Audit my ad layout: slot cap per template, forbidden positions (never above the answer in the first screen, never inside a tool's inputs), reserved heights per breakpoint, and a removal floor in revenue per 1000 visits. Tell me to measure CWV with ads LIVE and treat any ads-off measurement as invalid.
5. Propose the SMALLEST sellable direct offer to my owned audience, priced against the buyer's alternative cost — never against my production hours. Require me to measure support minutes per customer, and refuse any plan that degrades the free tier to force upgrades.
6. Audit every commercial surface against a compliance floor: disclosure clear and placed BEFORE the reader acts, all commercial claims verified and registered with a short cycle, common ownership of the three sites disclosed, contact and complaint routes monitored.
7. Populate a risk register across exactly these 10 categories: platform/algorithm, traffic concentration, revenue concentration, compliance/disclosure, content accuracy, key person, technical/hosting, data loss/portability, financial runway, reputational/partner. Each needs a LEADING indicator I can measure, a trigger written as a decision with an owner and a deadline, and its current value.
8. List which triggers are ALREADY MET today.

Rules:
- Never propose removing drawbacks, negatives or disclosures to satisfy a commercial partner. If I report such a request, tell me to refuse it and log it.
- Never treat display + affiliate as diversification when both depend on the same traffic.
- Never recommend signing a sponsor or partner commitment that breaches a cap, regardless of the offer.
- Compliance, consumer protection, tax and data protection are legal matters: state that requirements vary by jurisdiction and that you are not giving legal, financial or tax advice.
- Do not invent RPMs, conversion rates, commission benchmarks or "typical" publisher revenue. Mark anything unmeasured as UNMEASURED.
- Use contribution margin, never gross revenue, for every keep/kill recommendation.
Output as tables, with breached caps, refusals and already-met triggers called out in plain text above the tables.

Primary sources

Ad platform policies, affiliate terms and disclosure requirements change frequently and vary by jurisdiction. Every claim here is a dated claim with a 90-day expiry — log it in your register, re-verify against the primary source, and take professional advice for your own situation.