The Platform PM
Playbook

Integrating a platform after an acquisition

For the product leader who owns an acquired platform: sort every product and component into kill, keep independent, migrate or shared services, sequence the work, protect customers and revenue, and handle the licences, banks and registrations that slow regulated deals.

For heads of product, directors and VPs running 4-8 PMs and 20-60 engineers at complex B2B platform companies

Last reviewed October 2026

The job on one page

Your company has bought another platform company, or is about to. The deal team owns the price and counsel owns the filings. You own what happens to the products: which outcome each acquired product and platform component gets, in what order the work happens, how customers move without leaving, and who decides what.

Every component gets one of four outcomes.

1. Kill

What happens
Sunset it; move its customers to you or let them go
Choose it when
It duplicates yours and earns less than it costs
Usual cost
Lost customers; notice periods

2. Keep independent

What happens
Its own product, stack and often team
Choose it when
Its value is a market, team or trust you lack
Usual cost
Two of everything; drift

3. Migrate to your product

What happens
Its customers or functions move onto your product and stack
Choose it when
Similar products; a cost or scale thesis
Usual cost
Engineering years; churn per move

4. Shared platform services

What happens
Both stay, on common identity, billing, data, messaging, compliance
Choose it when
You need both products and one customer view
Usual cost
Years; it stalls

Most acquisitions miss at least one stated goal, most often the revenue goal. The popular "70-90% fail" doesn't hold up (False friends), and a meta-analysis found that acquirers' performance doesn't improve with acquisitions (King et al. 2004).

Four ideas organize this playbook. They come from research, so each carries its evidence strength.

  1. Decide early; migrate at the pace risk allows. (Medium: strong studies on speed, case evidence on decisions.) Fast task integration helps and fast human integration hurts (Bauer, King & Matzler 2016, 116 deals); whether speed helps depends on how related the businesses are (Homburg & Bucerius 2006); the "first 100 days" is largely symbolic (Angwin 2004). What delay costs is uncertainty, which an early, realistic preview of changes reduced (Schweiger & DeNisi 1991, via a secondary account), and the biggest losses I found came from wrong decisions, not late ones (FIS-Worldpay, Ericsson-Vonage). Day 100 is my decision deadline, never an integration deadline.
  2. The legal entity is what's regulated, not the architecture. (Strong on the law texts; the product reading is mine.) A stock deal leaves licences, registrations, bank contracts and certifications with the same entity. Cost comes from moving customers, funds, numbers or data between entities, changing who controls one, or changing where a regulated service runs. Even a plan can slow approval: the US money transmission model law's fast track requires that the licensee "will not implement any material changes to its business plan as a result of the acquisition" (Iowa §533C.401).
  3. Shared platform work looks cheap on a slide, takes years and stalls. (Medium: consistent cases, no large sample.) LinkedIn's Azure move, announced three years after the deal, was shelved in December 2023; GitHub stayed in its own data centers for about seven years, then began a 24-month move under capacity pressure; Trello accounts became managed Atlassian accounts about three years after that deal; Fitbit's Google-account deadline slipped twice. The counter-case: Instagram moved into Facebook's data centers in 2013-2014, a young product on a mature platform.
  4. Customers judge the integration by what changes for them. (Strong on direction; weak on how much churn, and when.) Across more than 2,000 deals, customer satisfaction was 1.14% lower and firm value 2.43% lower a year on than at comparable firms, and leaders who kept their attention on customers lost less (Umashankar, Bahadir & Bharadwaj 2022). The limit: with high switching costs, forced change can raise revenue while it builds regulatory exposure, as Broadcom's VMware bundle did.

Two more hypotheses come later: sales and people collisions do the earliest revenue damage (phase 2), and independence is a phase, not an end state (Keep independent).

Put together: decide every component's outcome, and the people and structure around it, by day 100; then move customers only as fast as entities, contracts and reliability allow.

What makes this harder on regulated platforms:

  • Payments and cross-border payouts: US state money transmitter licences are "not transferable or assignable"; the model law adopted in about 33 states requires prior approval of a new controller, as do New York and California; the sponsor bank's contract decides what you may change.
  • Telco and CPaaS: 10DLC brands are keyed to a tax ID, each provider has signed calls with its own STIR/SHAKEN token since September 18, 2025, and a stale Robocall Mitigation Database filing can get your traffic refused.
  • Security and identity: a SOC 2 report or PCI DSS attestation covers a scope, not your new product; FedRAMP wants 30 business days' notice of a "transformative" infrastructure change; consolidating logins means every enterprise customer reconfigures its single sign-on.
  • All of them: putting acquired customers' data on your entities usually means sub-processor notices to every customer, typically 30 days, with termination as the remedy.

This isn't legal advice; where it touches law, it says what to take to counsel.

Sources: HBR 2011 (the uncited 70-90%), Iowa §533C.301, Twilio (tax-ID match), FedRAMP, Atlassian DPA; cases under Case studies; telco rules from the site's earlier telco research.

01Signing to closing

Before close

Every acquired product and component has a draft outcome on paper, every entity-bound asset and contract term is inventoried, and nothing you did steered the target.

Plan; don't steer. Until closing, the companies are still competitors: "Right up until consummation, the merger parties are still independent businesses," as the FTC's competition bureau put it in 2018. The HSR Act bars the buyer from taking operational control before the waiting period ends (30 days for a reportable deal; the 2026 threshold is $133.9M), and the Sherman Act bars coordinating prices, customers or bids until closing, filing or not. Enforcers have charged the corporate version of everyday product moves:

Computer Associates and Platinum (DOJ, 2002)

What the buyer did
Pre-approved target discounts above 20%; coordinated bids
Result
$638,000; consent decree
Product equivalent
Approving their deals or prices

Three crude-oil producers (FTC, January 2025)

What the buyer did
Approved spending above $250,000 and routine hires; halted planned work
Result
$5.6M, a record HSR penalty
Product equivalent
"Pause that roadmap item"

Altice and PT Portugal (EU, 2018)

What the buyer did
Vetoes over appointments, pricing and contracts
Result
€124.5M; largely upheld in 2023
Product equivalent
Veto rights over launches

Facebook and Giphy (UK CMA, 2021)

What the buyer did
Breached a hold-separate order after closing
Result
£50.5M
Product equivalent
Integration frozen after close

Illumina and Grail (EU)

What the buyer did
Closed while reviews were pending
Result
€432M fine fell away (2024); deal unwound
Product equivalent
Integrating before clearance

Clean teams. The FTC treats prices, discounts, costs, strategic plans, future products and customer-level data as competitively sensitive: share only what diligence needs, through a clean team vetted by counsel, with aggregated data and masked customer names. My reading, for counsel: roadmaps, unreleased features, per-customer pricing and usage, win-loss data and pipeline are clean-team-only when the companies compete or could. So plan on paper, analyze aggregated overlap, draft Day-1 messages and prepare filings; don't approve the target's deals, pause its roadmap, direct its staff, sell jointly, tell its customers a product will die, or connect systems and data. Interim covenants, joint planning and retention agreements are grey: ask deal counsel.

Do diligence for the four outcomes, not just the price. Build three inventories: a regulated-asset register keyed by legal entity (licences, bank programs and BINs, network registrations, PCI attestations, telco identifiers, SOC 2, ISO and FedRAMP scopes, data processing agreements, residency promises), each item with an owner, renewal date and change-of-control trigger; a contract inventory with revenue counted per clause type; and a platform inventory of APIs, SDK versions, webhooks, traffic and revenue by segment, and transition services.

Check foreign investment, and file the plan you'll run. CFIUS mitigation on data access or location can rule out shared services, and in the UK an uncleared deal that needed a National Security and Investment Act notice is void. Filings that promise no material changes while your deck assumes a migration cost you the money transmission fast track and some credibility.

Write the Day-1 promise: what won't change for customers (APIs, pricing, support, data location), for how long, and who may change it. When Okta rebranded Auth0 in 2023 it promised no changes to URLs, APIs or code libraries; I'd copy that, with at least 12 months. Fast integration after close needs longer preparation before it (Meglio, King & Risberg 2017; GE Capital in Ashkenas et al. 1998, practitioner).

Sources: FTC guidance, Orrick, DOJ (search result), FTC 2025, A&O Shearman, CMA and Legal Dive (search results), Paul Weiss (search result), Auth0.

Checklist

  • Get counsel's written gun-jumping protocol: what may be shared, who sits on the clean team, what stays with the target
  • Keep people with pricing or roadmap roles off the clean team, and approve nothing for the target: no discounts, contracts, hires, launches or pauses
  • Draft an outcome for every acquired product and major component, with your confidence and open questions
  • Build the regulated-asset register by legal entity, with an owner, renewal date and change-of-control trigger for each item
  • Count revenue exposed to change-of-control, assignment, sub-processor, residency and SLA terms in customer contracts
  • Map the filings that gate closing (state licences, FCA, PSD2, RPAA, CFIUS or NSIA, FCC 214) and check they describe the plan you'll run
  • List the people the thesis depends on and agree retention terms and future roles with HR and counsel
  • Write the Day-1 promise (what won't change for customers, for how long, who can change it) and draft Day-1 messages, sending none before close

02Days 1-100, with gates at day 30 and day 100

The first 100 days

Customers, people and revenue are stable, and every acquired product and component has a decided and announced outcome, an owner and a date.

Stabilize by day 30, decide by day 100. I keep "100" because a deadline forces decisions, not because integration belongs in that window.

By day 30: stabilize

People first, because the best leave first. In about 4,000 acquisitions of US high-tech startups, 33% of acquired workers left in the first year, against 12% of comparable hires, top performers most (Kim 2024). Senior, visible executives leave soonest (Walsh 1988); their departures hurt performance, and real top-team roles helped (Cannella & Hambrick 1993). The gap is widest in senior, technical, business development and sales roles, and shrinks when founding teams stay intact and units stay separate (Ng & Stuart 2022). So announce the acquired team's top two layers in the first weeks (GE Capital did it within days). Money holds people through a cliff date, not past it; 159 HR and compensation executives surveyed in 2024 rated career opportunities the most effective non-cash tool (CFO.com).

Sales and people collisions do the earliest revenue damage. (A hypothesis, medium: one strong case plus the attrition studies.) Okta merged its sales forces while buyers were still unsure which product to lead with; attrition rose and long-term targets went under review about 16 months after close (case). Write down who sells what to whom before you merge anything.

Give customers a name. Each acquired product gets one visible owner; top accounts hear who it is and what won't change, in calls where you mostly listen. Freeze customer-visible changes except security fixes.

File what the change of control triggers: FinCEN re-registration within 180 days of a transfer above 10%; FINTRAC and RPAA updates within 30 days; Robocall Mitigation Database within 10 business days; Form 499 within a week; FCC numbering and international 214 notices within 30 days. Then tell auditors and meet each sponsor bank.

By day 100: decide and announce

Every component gets an outcome, an owner, a cost and dates, using the four decisions, what can move when and the cost model, each in a decision record (Nygard 2011), so a reversal becomes a "superseded" status, not an argument.

Decide internally; announce when the path exists. Twilio announced the end of Programmable Video in December 2023, extended it after protests and reversed it in October 2024; Meta announced Parse's shutdown with an open-source server, a migration tool and a year's notice. Tell top accounts privately first.

Plan the dis-synergies. Customer loss is the classic revenue dis-synergy deal models leave out (McKinsey 2004, seen only in summary). Track key-people retention, renewal intent, market share and release velocity, not just synergies: FIS beat its synergy targets, then wrote down $17.6bn (case).

Say what isn't decided. My cadence: a Day-1 all-hands on what is and isn't decided, a weekly written update, and a dated calendar of open decisions.

Sources: Kim 2024, Okta call, 31 CFR 1022.380, Bank of Canada, FINTRAC (search result), 47 CFR 52.15, 63.24 and 64.1195, DQS (search result), Twilio, ADTmag (search result).

Checklist

  • Day 30: announce leaders and reporting lines for the acquired team's top two layers
  • Day 30: confirm retention terms and roles for the people the thesis depends on, and review departures weekly
  • Day 30: name one owner per acquired product and tell top accounts who it is and what won't change
  • Day 30: freeze customer-visible changes (pricing, API deprecations, support model) except security fixes
  • Day 30: write "who sells what to whom" rules before any sales merger
  • Day 30: file the post-close regulatory notices and tell auditors and certification bodies
  • Day 100: record an outcome, owner, cost, revenue at risk and dates for every component in a decision record
  • Day 100: budget two stacks, with dis-synergies and churn as plan lines next to synergies
  • Day 100: write the trigger and end state for every unit you keep independent, and publish a dated calendar of open decisions

03Months 4-12

Build the bridge

The migration path exists and has been rehearsed, new business goes to the target platform, and the public notice is out early enough to give customers at least 12 months.

Budget for architecture you'll throw away. Martin Fowler's strangler fig grows new components around the old system until it can be retired, paying for "transitional architecture" on the way. Two rules (Cartwright, Horn & Lewis):

  • Legacy mimic: your platform impersonates the old one toward whatever can't change yet (a partner bank's files, a carrier interface, customers' code). A facade that speaks the acquired API, webhooks included, lets customers cut over without code changes; Stripe's "version change modules" show how to contain old behavior.
  • Not feature parity, which turns every undocumented behavior and workaround into a requirement. Ask: parity for which customer jobs, held by what share of revenue?

Run the new path in parallel first. GitHub ran a rewritten merge path beside the old one, returned the old result, logged mismatches and ramped from 1% to 100% of traffic over four days, finding bugs in the old system too. Stripe moves live data by dual-writing and backfilling, then moving reads, then writes, then deleting the old.

Lay shared groundwork in order. My draft order, from the cases rather than a study: internal services (employee identity, finance reporting, security monitoring), then observability and on-call, customer identity, billing and entitlements, messaging and payment rails, and compute last. Identity can move in bulk or lazily at each user's first login; either way inactive users need a final sweep, and each enterprise customer reconfigures its own SSO. For billing I found no public timeline.

Move new business first. From September 1, 2019 Microsoft sent new Skype for Business Online customers to Teams while existing ones kept the old service until July 31, 2021; in payments, new customers go to the new processor while existing cards stay on the old one until imported. End sales of the old product at notice.

Give at least 12 months' notice, the floor big platforms commit to for generally available APIs:

PlatformPublished commitment
Google Cloud12 months' notice before discontinuing a service or breaking a customer-facing API
SalesforceEach API version at least 3 years; 1 year's notice before retirement
ShopifyEach quarterly version at least 12 months, with 9 months' overlap
Meta GraphEach version at least 2 years
GitHub RESTPrevious version at least 24 months after a new one

Working back, a shutdown at month 24 needs the notice out by month 6 to 9. Mark endpoints with the Deprecation header (RFC 9745, March 2025) and the date with Sunset (RFC 8594). Deep integrations, regulated customers and registrations deserve 18 to 24 months (my judgment).

Move regulated pieces in regulated order. Move customers between entities only after the destination entity holds the licences, bank program, registrations and certifications. Start third-party work early: 10DLC campaigns move between providers in minutes without re-vetting if the connectivity chain is kept ("clear chain" wipes the vetting); an old card processor takes "a few days or several weeks" to release card data, and declines can spike after the move.

Design the rollback first. Keep the old system warm, make writes reversible, name the point of no return (the first settlement file, carrier route change or SSO switch) and rehearse at production scale. TSB tested only one of its two data centers (case).

Watch the retention cliff. Retention periods (a median of 18 months for senior leaders and 12 for others, in an earlier survey seen in summary) land mid-migration; stagger them for people on the critical path, and say which feature work is paused.

Sources: Fowler, feature parity, Stripe on versioning and online migrations, GitHub Scientist, Auth0 docs and Microsoft (search results), Stripe card import (vendor docs), Google Cloud, Salesforce (search result), Shopify, Meta, GitHub, RFC 9745, Bandwidth (vendor), Slaughter and May, HR Magazine and The New Stack (search results).

Checklist

  • Build a compatibility facade for the acquired API and webhooks, with Deprecation and Sunset headers, and run the new path in parallel on production traffic with logged mismatches
  • Start shared identity and billing groundwork: the SSO migration path, the entitlements model, invoice and tax mapping
  • Onboard new customers to the target platform and end sales of the old product
  • Publish the public notice with dates at least 12 months before shutdown, longer for regulated customers and deep integrations
  • Ship migration tooling: self-serve for the long tail, assisted for larger accounts, and a progress view customers can see
  • Before customers change entity or shared services touch regulated flows, have the destination's licences, bank program, registrations and certifications ready, file outsourcing and sub-processor notices, and get the sponsor bank's sign-off
  • Run a pilot wave with friendly customers and rehearse rollback at production scale
  • Stagger retention cliffs for people on the migration's critical path

04Months 12-36

Migrate in waves and decommission

Customers have moved, or left on purpose; the old stack is off, reconciled and archived; its licences and registrations are surrendered; and every unit you kept independent has been reviewed.

Segment, then move in waves. My default: top accounts get a named plan and engineer, mid-size accounts move in waves led by customer success, and the long tail gets a tool, reminders and a date. Different deadlines by tier are fine if disclosed: Google stopped standard Universal Analytics on July 1, 2023 and gave paying 360 customers until July 1, 2024. Every wave has entry and exit criteria, a rollback path, a customer message and stop rules agreed in advance.

Pay for the customer's move. These offers recur in the cases; that they beat the alternatives is my hypothesis.

  • Fund their dual-run: Atlassian waived server renewals for up to 12 months after a cloud purchase and gives Opsgenie customers 120 days of parallel access; Palo Alto Networks offered free migration services to IBM QRadar SaaS customers.
  • Make it an upgrade (Skype users signed in to Teams Free with their Skype credentials and contacts), step price protection down rather than off (Atlassian's loyalty discount went from 40% to 20%), and give an exit to those who won't move (Parse open-sourced its server).
  • Avoid killing before the replacement exists (Twilio Video), very short notice (Heroku's free tier got about 95 days) and price shocks bundled with the move (VMware).

The deal rarely needs consent; the migration often does. Under Delaware law a reverse triangular merger isn't an assignment of the target's contracts (Meso Scale v. Roche, 2013), but moving a customer onto your product usually means a new contracting entity, terms and sub-processors: a renewal-like moment when it can renegotiate or leave. Under the EU Data Act, customers can switch on two months' notice, and switching charges are banned from January 12, 2027. Run consent campaigns before announcing dates.

Expect the tail to outlast the plan. Twilio moved Notify's end of life twice, from October 2023 to December 31, 2025; Fitbit's deadline moved twice. Publish one date and budget the old stack for 6 to 12 months beyond it. Never shorten a published date: pulling CentOS 8's end of life forward from 2029 to December 31, 2021 caused lasting backlash. Let an account go when migrating and serving it costs more than its lifetime margin, with an export and a referral.

Reconcile before you switch off. In payments, reconcile three ways daily through the dual-run (old ledger, new ledger, bank or scheme statements), never net breaks off, and switch off only after zero unexplained breaks for agreed periods. After the middleware company Synapse filed for bankruptcy in April 2024, reconciliation found a gap of $60M to $95M between its ledger and partner-bank records, and end users were frozen for weeks or months.

"Migration complete" is three milestones: customers moved; old system off; contracts, data, registrations and certifications closed. Archive before deleting: PCI DSS keeps 12 months of audit logs, three immediately available (requirement 10.5.1, read through a mirror). Give leavers at least 30 days to retrieve data, then surrender the licences, registrations, leases, numbers and bank programs you no longer need.

Measure traffic and revenue, not accounts, as GitHub's workload-by-workload reports on its Azure move do.

Review what you kept independent against the trigger written on day 100: continue, shared services, migrate or sell. Then write the post-mortem: codified integration know-how improved later deals, while raw experience didn't (Zollo & Singh 2004, 228 US bank deals).

Sources: Search Engine Land, ITPro, Opsgenie migration, Palo Alto Networks, TechCrunch on Skype and Heroku, Harvard Law forum, Faegre Drinker, Twilio Notify, Mobilesyrup and iTWire (search results), CFPB complaint and Banking Dive (search results), PCI mirror, GitHub availability report.

Checklist

  • Run waves by segment, each with entry and exit criteria, a rollback path and a customer message: named plans for top accounts, waves led by customer success for mid-size accounts, a tool and a date for the long tail
  • Enforce stop rules: pause a wave when mismatches, reconciliation breaks, authorization or delivery rates, or top-account escalations cross agreed thresholds
  • Run consent campaigns for contracts that need assignment or new terms before announcing their dates
  • Budget one extension and segment it by contract value if needed; never shorten a published date
  • Review the scorecard weekly: traffic and revenue migrated, accounts by stage, deprecated calls, breaks, old-stack cost
  • Switch off old access only after zero unexplained reconciliation breaks for agreed periods, archive to retention rules, and give leavers an export window
  • Surrender unneeded licences and registrations, retire BINs, release numbers and short codes, and close extra compliance scopes
  • Review every independent unit against its written trigger, then write the post-mortem and update your playbook

The four decisions

Classify each product and component, not the deal. The classic typology sorts whole deals into absorption, preservation, symbiosis and holding (Haspeslagh & Jemison 1991), roughly migrate, keep independent and shared services; but integration and autonomy are separate dimensions you can set per component (Zaheer, Castañer & Souder 2013). Kill isn't in the typology, yet it's common: about half the consumer apps that five big tech companies bought from 2015 to 2019 were discontinued (Affeldt & Kesler 2021).

Six questions per component (my draft, from the studies):

  1. Where does the value come from? Cost or scale from similar assets points to migrate or kill; capabilities, talent or a market you lack point to keep independent or shared services.
  2. How mature is it? Structural integration lowered the chance of new launches by targets that hadn't launched yet (Puranam, Singh & Zollo 2006).
  3. Who would leave, and what would customers have to change?
  4. What do regulators, licences and contracts allow? Microsoft gave the European Commission five-year commitments on LinkedIn.
  5. Can your stack carry it? GitHub's Azure move was triggered by capacity, not a synergy plan.
  6. Does it need a different capital model? FIS said its merchant business needed acquisition capital "we just cannot feed" inside FIS.

Kill

Choose it when the product duplicates yours, costs a large share of its revenue to run, or its customers want your product anyway. By my cost model, a $5M-a-year product costing $6M to run is better killed on almost any retention assumption.

What it costs: the customers who don't follow, notice periods, credits and an archive. Atlassian bought Opsgenie in 2018, announced its end on March 3, 2025, stopped selling it on June 4, 2025 and will shut it down on April 5, 2027, deleting unmigrated data: about 25 months from end of sale to shutdown.

Early signs it's wrong: extension requests in the first weeks; escalations because the replacement can't yet do the customer's job.

Regulated platforms: bank program wind-downs (BIN retirement, cardholder notices), number port-outs, short-code and campaign decisions, and possibly a material business-plan change for the licence.

Acqui-hires need a customer plan too: in July 2025 Google's $2.4bn licence-and-hire deal took an AI coding start-up's CEO and some researchers to Google DeepMind, and days later another company bought the rest, with more than 350 enterprise customers (NBC DFW, seen in summary).

Keep independent

Choose it when the value is a market, team or trust you lack, the product is young, or the licensed entity is the asset. Separation also lowers attrition.

What it costs: two of everything, and drift; Ericsson kept Vonage separate for a market that hadn't formed and wrote off about two thirds of the price.

Early signs it's wrong: no shared roadmap item after a year; restated milestones; impairment tests; shrinking headroom.

Independence is a phase, not an end state. (A hypothesis, medium: four cases.) GitHub ran independently from 2018 to 2025, then joined Microsoft's CoreAI group without a new CEO and began moving to Azure. LinkedIn's CEO also took over Office in June 2025. Twilio ran Segment as a division, then a business unit, then embedded its profiles in communications products from 2024. Okta ran Auth0 as a business unit, merged sales, then re-specialized its sellers. So write down the trigger that ends it (the founder leaving, capacity running out, a missed cross-sell milestone) and the end state.

Regulated platforms: the cheapest outcome: a stock deal leaves licences, registrations and certifications in place, though you still owe controller approvals and ownership notices.

Migrate to existing product infrastructure

Choose it when the products are similar, the thesis is cost or scale, and your platform can carry the load. Integration improved performance in similar businesses (Zollo & Singh's banks).

What it costs: the most engineering, a churn event at every customer move and a long dual-run. In my model it's the only outcome that beats keep independent in steady state, paying back around year 7 on cost alone.

Early signs it's wrong: the parity list keeps growing and no customer has moved after six months; a contract or a dual-run bill, not readiness, sets the cut-over date (TSB).

Regulated platforms: customer-by-customer assignment or new contracts; new KYC, bank programs and BINs where entities differ; campaign moves and number ports; a PCI scope change; GDPR controller notices.

Move to shared platform services

Choose it when you need both products and one view of the customer: one login, one invoice, one data model for cross-sell. Twilio's Segment thesis needed exactly that, yet Segment ran as a division for about three years; after a $285.7M impairment of its intangibles in late 2023 (seen in a filing summary), Twilio kept it under a new president.

What it costs: years. Bain puts full IT integration at two to three years (Bain 2014); LinkedIn's Azure move was shelved; GitHub's is a 24-month plan. In my model, if the work takes 36 months instead of 18, this outcome trails keep independent for more than five years.

Early signs it's wrong: "pause" memos; platform work competing with the roadmap; the acquired team's release cadence dropping.

Regulated platforms: outsourcing notices (UK PSRs regulation 25, the EBA guidelines and the DORA register all cover intragroup providers), sub-processor notices to every customer, sponsor-bank approval of subcontractors, PCI, SOC 2 and ISO re-scoping, a FedRAMP transformative-change notice, and any CFIUS mitigation on data location.

Sources: Twilio, Business Wire, Constellation Research, EBA guidelines (search result).

Who decides and how to record it

My draft split of decision rights:

RoleOwns
Executive sponsorThe thesis; which businesses stay independent; kills with material revenue
Integration management officeOne plan, cadence, escalations; synergy and dis-synergy tracking with finance
Head of product (you)Recommends each outcome; customer roadmap; migration, sunset and deprecation plans
EngineeringArchitecture, cut-over method, dual-run budget, reliability gates
Legal, compliance, riskVeto on anything tied to a licence, registration, certification or contract term
Sales and customer successWho sells what to whom; account ownership; the renewal risk list
HRRetention list, leadership appointments, communication cadence

Behind the shape: integration managers create value and stop it leaking (Teerikangas, Véry & Pisano 2011); an 80%-right decision beats delay (Bain 2001); good acquirers focus on about 20 critical decisions (Bain 2024).

Record each outcome as a decision record: context, outcome, owner, notice date, dual-run dates, decommission date, cost line, and kill criteria written in advance (for example: the replacement covers the jobs of accounts holding 90% of revenue, and no licence is tied only to the acquired entity).

What can move when

The entity holds the licence, so a stock deal moves almost nothing and an entity change moves almost everything. As of October 2026; "estimate" marks an inference. Not legal advice: every row varies by jurisdiction, deal structure and contract.

US state money transmitter licence

Stock deal
Stays; control approval per state
Asset deal or entity merger
Doesn't transfer; new licences
Approval or notice
Prior approval in model-law states, NY, CA; control presumed at 10%
Lead time
~60 days per state once complete; 3-9 months nationwide (estimate)
For the four outcomes
Keep the entity; a kill or migrate plan can lose the fast track

UK or EU payment or e-money firm

Stock deal
Stays; the new controller needs approval (UK) or gives notice (EU)
Asset deal or entity merger
Not transferable (inference)
Approval or notice
UK: prior approval, and closing without it is a crime; EU: notice at 20, 30, 50%
Lead time
UK: up to 60 working days; EU: national
For the four outcomes
Shared services need outsourcing notices and a DORA register update

Canada RPAA registration

Stock deal
New application before control changes
Asset deal or entity merger
New application
Approval or notice
Prior
Lead time
Not found
For the four outcomes
Gates Canadian end users

Sponsor-bank program, network registrations

Stock deal
Contract decides; consent often needed
Asset deal or entity merger
Bank consent; new sponsor registers agents
Approval or notice
Contract, bank diligence, network rules
Lead time
Weeks to months (estimate)
For the four outcomes
BIN migration, re-underwriting; the bank may veto shared services

PCI DSS attestation

Stock deal
Stays for its scope
Asset deal or entity merger
New validation
Approval or notice
Card brand or acquirer decides
Lead time
Next assessment
For the four outcomes
Migrate or shared expands your card scope

10DLC brands and campaigns

Stock deal
Unchanged (same tax ID)
Asset deal or entity merger
New brand and vetting; customers' campaigns move between providers
Approval or notice
Registry and carrier review
Lead time
Minutes to 3 weeks
For the four outcomes
Throughput may reset; campaigns are the most portable layer

Numbers, short codes

Stock deal
Stay
Asset deal or entity merger
Port; lease transfer, carrier moves
Approval or notice
Industry process, authorization letters
Lead time
Days to weeks
For the four outcomes
Port-outs on a kill

FCC 214 authority

Stock deal
Domestic: day 31 if streamlined; international: prior approval
Asset deal or entity merger
Assignment approval
Approval or notice
FCC, plus security review if foreign
Lead time
31 days to months
For the four outcomes
Gating if the target is a carrier

SOC 2 report, ISO certificate

Stock deal
Stays; bridge letters ~3 months; tell the ISO body
Asset deal or entity merger
New scope or system description
Approval or notice
Auditor, certification body
Lead time
Next audit or observation period
For the four outcomes
Separate reports while independent

FedRAMP authorization

Stock deal
Stays
Asset deal or entity merger
Open question
Approval or notice
Transformative change: 30 business days ahead
Lead time
Months if reassessed
For the four outcomes
Infrastructure moves are slowest

Customer data (GDPR)

Stock deal
Controller unchanged; notice when your affiliates process
Asset deal or entity merger
New controller: notices, lawful basis
Approval or notice
Contract: typically 30 days' notice, then termination
Lead time
30 days or more
For the four outcomes
Every customer can object; pooling data changes the controller

Customer contracts

Stock deal
Change-of-control clauses only
Asset deal or entity merger
Assignment needs consent
Approval or notice
Contract
Lead time
Weeks to months
For the four outcomes
Consent campaigns before migrating

CFIUS, NSIA, EU FDI

Stock deal
Clearance before closing
Asset deal or entity merger
Same
Approval or notice
CFIUS mandatory filing 30+ days before completion; NSIA void if uncleared
Lead time
30 to 120+ days
For the four outcomes
Mitigation can forbid shared services

What the table hides. Under the money transmission model law, a change of control is deemed approved 61 days after a complete application, or 30 days after a notice for an already-approved controller with no material business-plan change; I found no guidance on whether an integration plan counts. Regulators approve people and money, not architecture, so technology can usually consolidate behind a licensed entity under intragroup agreements, within outsourcing and safeguarding rules (the UK has required daily safeguarding reconciliations per firm since May 7, 2026). And many limits are contracts: Block's agreement with Marqeta keeps its Cash App program served for a period if Marqeta changes control.

Take these to counsel, in writing:

  1. Which pre-closing product activities may we do jointly, only through a clean team, or not at all, and do our interim covenants give us consent rights over the target's decisions?
  2. State by state, is our change of control prior approval, notice or post-closing, and does our integration plan rule out the fast track?
  3. If the acquired payment firm moves onto our group platform, is that outsourcing, and what must we notify, and when?
  4. Does our sponsor bank need to consent to this change of control, or to moving processing or ledgers to our entities?
  5. If we pool both products' customer data in one service, do we become a new controller or sub-processor, and for which customers?

Sources: Iowa §533C.401, CSBS model law, Goodwin (law firm), FCA, PSRs reg. 25, PSD2 art. 6, Sidley on DORA, Bank of Canada, Marqeta 10-K, Visa, PCI SSC FAQ (search result), Bandwidth (vendor), Short Code Registry, FCC porting order, 47 CFR 63.03, Schellman and Bastion (auditor, vendor), FedRAMP, ICO, GDPR art. 28, CFIUS; UK safeguarding from the site's cross-border payouts research.

Costing the four outcomes

Price each outcome on three-year net and on steady state, and keep revenue synergies out of the cost case so they can't hide a weak one. Per component: one-off costs (engineering, tooling, the customer program, incentives, legal work, re-registrations, decommissioning); run cost for both stacks, then steady state; revenue at risk (revenue by segment times the extra churn); and time, since every month of dual-run is a cost line.

A worked example, in $M. Every input is an assumption except the loaded engineer cost, which rests on the BLS median software developer wage ($135,980, May 2025) and wages being about 70.1% of private employers' compensation costs (December 2025): about $194,000, rounded to $200,000. The acquired product earns $40M a year, flat, from 1,250 customers (the top 50 hold 60%, 400 mid-size accounts 30%, 800 small ones 10%). Its stack costs $14.8M a year (infrastructure 3.0, 55 people 11.0, compliance and licences 0.8); serving moved revenue on your platform costs 20% of it. Three years, undiscounted.

Keep independent (reference)

3-yr revenue
120.0
3-yr cost
44.9
3-yr net
75.1
Steady state a year
25.2
Overtakes keep independent
n/a

Kill: notice at month 6, off at month 18

3-yr revenue
95.4
3-yr cost
36.4
3-yr net
59.0
Steady state a year
18.9
Overtakes keep independent
Never, at these inputs

Migrate: waves in months 6-24, old stack off at month 30

3-yr revenue
114.2
3-yr cost
54.9
3-yr net
59.3
Steady state a year
28.9
Overtakes keep independent
Around year 7

Shared services: identity, billing, observability, notifications

3-yr revenue
118.8
3-yr cost
47.75
3-yr net
71.05
Steady state a year
26.5
Overtakes keep independent
Around year 6

The churn assumptions do the work: kill keeps 70% of top-account revenue, 50% of mid-size and 20% of the tail (23.6 of 40); migrate keeps 95%, 88% and 70% (36.2); shared services loses 2% to visible SSO and billing changes. Migrate's one-off of 20.9 covers 25 acquired engineers for two years, 10 of yours, tooling, a customer program and credits.

What I read from it (hypotheses):

  • On cost alone, keep independent wins over three years for a healthy $40M product; migrate wins only in steady state, late. The case for migrate or shared services has to come from the thesis: 10% cross-sell on retained revenue from year 3 brings migrate's crossover to about year 5. That fits a survey of 232 horizontal deals in which market-related performance mattered more than cost savings (Homburg & Bucerius 2005).
  • Migrate's biggest levers: top-account churn (each 10 points costs $2.4M of revenue a year) and dual-run length (each extra six months costs about $4.9M).
  • Shared services is most sensitive to time: at 36 months instead of 18, the one-off roughly doubles and savings arrive 18 months later.
  • Left out: roadmap opportunity cost, key-person attrition, regulatory lead times, revenue synergies.

For scale: across 236 deals of $500M or more, integration cost 1% to 4% of deal value, with IT among the top three cost drivers (EY, consultancy). I found no public figure for dual-run cost.

Sources: BLS wages, BLS compensation (search result).

Case studies

Figures are company-reported unless marked.

FIS and Worldpay: synergies beaten, then written down

Deal: announced March 18, 2019, about $43bn in enterprise value. Thesis: scale and cross-selling to bank clients; $500M of revenue and $400M of cost synergies by end-2021. Outcome: shared platform services and cross-sell inside FIS's merchant segment. What happened: by end-2021 FIS reported about $750M of run-rate revenue synergies and $900M of cost synergies; on February 13, 2023 it took a $17.6bn impairment on the merchant business and planned a separation; reporting cited share lost to fintech rivals and operational missteps. A majority stake went to GTCR (closed January 31, 2024), and in January 2026 Global Payments bought all of Worldpay. Lesson: the synergy scorecard measured the integration, not the competitive position.

Sources: FIS 2019, 2021 results, 2022 Q4, Kitco/Reuters, Payments Dive, Business Wire, Digital Transactions.

Ericsson and Vonage: kept separate for a market that didn't arrive

Deal: announced November 22, 2021, $6.2bn in cash; closed July 21, 2022 after a CFIUS-related delay. Thesis: sell network APIs through Vonage's developer platform. Outcome: keep independent, with the network link to come (from September 2024 also through Aduna, a joint venture with 12 operators). What happened: impairments of SEK 32bn in October 2023 and SEK 11.4bn in July 2024 wrote off about two thirds of the price; Vonage reportedly lost about $450M at the operating level on $5.3bn of revenue from mid-2022 to 2025, and got a new CEO and turnaround plan in August 2026. Lesson: independence plus a thesis waiting for a market gives nobody a reason to change; set milestones that trigger a kill, merger or sale.

Sources: RCR Wireless, Bloomberg Law, Ericsson, Telecoms.com, Light Reading, Fierce Network.

Okta and Auth0: product kept, sales merged too early

Deal: about $6.5bn in stock, closed May 3, 2021; Auth0 became a business unit under its co-founder. Thesis: workforce plus customer identity, with Auth0 for developers and Okta for IT buyers. Outcome: keep independent for the product; one sales force from early 2022 (one summary says 2023). What happened: on August 31, 2022 Okta described confusion over which product to lead with and higher-than-expected sales attrition (reported above 20%), cut guidance and put its fiscal 2026 target of $4bn under review; the CEO said the problems rested "squarely on my shoulders". It later aimed Auth0 at developers and, in March 2025, split sellers into Okta and Auth0 specialists; Auth0's co-founder retired that month. Lesson: go-to-market integration is its own outcome decision.

Sources: Okta, Q2 FY2023 call, BankInfoSecurity and Q4 FY2025 call (search results), Okta 2025.

Microsoft and LinkedIn: independent on purpose

Deal: announced June 13, 2016, $26.2bn in cash; closed December 8, 2016 after EU clearance. Thesis: connect the network with Office 365 and Dynamics. Outcome: keep independent (its own brand, culture and CEO), with selective product links and five-year EU commitments that limited tying LinkedIn into Office and Windows in Europe. What happened: an Azure move announced in 2019 was reported shelved on December 14, 2023, reportedly because Azure capacity was needed for external customers and LinkedIn's tooling didn't fit native Azure services. In June 2025 LinkedIn's CEO also took over Office. Lesson: independence protected a network whose value is user trust, and regulators can mandate it for a time; even so, units converge at the top.

Sources: LinkedIn, Microsoft, NBC Philadelphia/CNBC, Microsoft FY2025, Redmond.

Microsoft and GitHub: seven years independent, then a move under pressure

Deal: $7.5bn, closed October 26, 2018, to "operate independently" under its own CEO. Outcome: keep independent until 2025, then shared platform services: in August 2025 GitHub joined CoreAI with no new CEO, and in October 2025 a 24-month plan to leave its own data centers put feature work second. What happened: on August 17, 2026 a capacity failure in its Central US data center caused a 7-hour-47-minute outage; Azure then served about 58% of platform load, up from 12% in May 2026. The CTO wrote: "We failed to scale critical components before demand exceeded their capacity." GitHub targets the end of 2026 for moving its main site's traffic; others report 2027. Lesson: a deferred platform decision has a bill, and it can arrive as an incident.

Sources: Microsoft, Gigazine, The New Stack (search result), GitHub on the outage, GitHub availability report.

Microsoft and Skype: migrated onto Teams, then killed

Deal: eBay had paid $2.6bn for Skype in 2005, taken a $1.43bn charge in 2007 and sold about 65% in 2009 at a $2.75bn valuation. Microsoft paid $8.5bn in cash (closed October 13, 2011). Outcome: migrate to existing, then kill. What happened: new business customers went to Teams from September 1, 2019, and Skype for Business Online retired on July 31, 2021. Consumer Skype closed on May 5, 2025, about 9.5 weeks after the announcement: users signed in to Teams Free with their Skype credentials, contacts and chats carried over, and an export was offered. Lesson: a clean path makes a kill survivable; set the sunset date when you set the path, or the tail runs for years.

Sources: NBC News, Telecoms.com, Torys, Petri, PCWorld.

Broadcom and VMware: divest, bundle, force new terms

Deal: about $69bn, closed November 22, 2023. Outcome: divest the non-core (end-user computing sold to KKR as Omnissa for about $4bn; Carbon Black merged into Symantec) and migrate the core into the VMware Cloud Foundation bundle, ending perpetual licences and reshaping partner programs. What happened: 87% of the largest 10,000 customers were on the bundle by the second quarter of fiscal 2025, and infrastructure software revenue was reported at $6.7bn in the first quarter, against $4.55bn a year earlier. Bills reportedly rose fivefold or more; a European cloud trade association's complaint of March 19, 2026 alleges increases above 1,000%; Gartner expects more than 35% of VMware workloads elsewhere by 2028. Lesson: with high switching costs, forced change can raise revenue while it builds regulatory, partner and reputational exposure that arrives later.

Sources: StorageNewsletter, O'Melveny and Security Boulevard (search results), The Register in 2025 and 2024, CISPE, Gartner via The Register.

TSB and Sabadell: a big-bang weekend

Deal: Banco Sabadell bought TSB in 2015; TSB kept running on a cloned Lloyds Banking Group platform under a transitional arrangement whose rising fees cut its 2017 profit by about £20M. Outcome: migrate to existing. What happened: after slipping from November 2017, the migration moved about 5.2 million customers in one weekend in April 2018; the data moved, the platform failed, and business as usual returned only in December 2018. An independent review found the single-event approach was chosen without substantive discussion of alternatives, and only one of two data centers was tested. The FCA and PRA fined TSB £48.65M on December 20, 2022; it paid £32.7M in redress. Lesson: a rising dual-run bill pushes toward a big-bang date; budget the dual-run so readiness, not cost, sets the cut-over.

Sources: Bank of England, Slaughter and May, ITPro, City A.M..

Failure modes

Thesis fails behind green synergy numbers

Early signs
Synergies met while share and win rates slip
Who pays
Shareholders; customers in a later split
Case
FIS and Worldpay

Sales collision

Early signs
Sellers unsure what to lead with; acquired pipeline drops
Who pays
Revenue for the next 2 to 4 quarters
Case
Okta and Auth0

Key people leave

Early signs
Top-layer and technical exits in year one
Who pays
The acquired roadmap
Case
Slack's CEO, about 18 months after close

Deferred platform work becomes an incident

Early signs
Shrinking capacity headroom
Who pays
Customers; trust
Case
GitHub, 2026

Big-bang cut-over set by a date

Early signs
Date fixed before readiness; rehearsals cut
Who pays
Customers, then fines and redress
Case
TSB, 2018

Forced change without a reason

Early signs
Short-notice price changes; partner complaints
Who pays
Long tail and partners first
Case
VMware

Independence without a value path

Early signs
No shared roadmap item after a year
Who pays
Shareholders; the acquired team
Case
Ericsson and Vonage

Integration kills what you bought

Early signs
Acquired release cadence drops after the reorganization
Who pays
Future revenue
Case
Puranam et al. 2006

Reconciliation gaps

Early signs
Breaks carried forward; manual adjustments growing
Who pays
End users, then regulators
Case
Synapse, 2024

Sources: the sections above; CX Today on Slack (search result).

False friends

TermWhat you'd assumeWhat it means here
"70-90% fail"A research findingUncited at 90%; the 70% mixes share price, executives' opinions and revenue synergies
SynergyValue createdA planned number: FIS reported $750M run-rate before a $17.6bn write-down
IndependentSeparate foreverOwn brand and CEO, often shared infrastructure and HR; a phase
First 100 daysThe integration windowA convention; at best a decision deadline
MigratedDoneAccount created, traffic moved, old access revoked, data reconciled: four stages
DeprecatedIt stopsTo engineers "no new use", to customers "it stops": say end of sale and shutdown
Change of controlCrossing 50%10% under the money transmission model law; well below 50% for CFIUS; contracts set their own
ControllerOne meaningFCA: a shareholder with control. GDPR: whoever decides why and how data is processed

On the first row: a 1999 KPMG study found 83% of deals didn't add shareholder value a year on, while 82% of executives thought theirs had succeeded (sample unclear); McKinsey's 2004 study of 160 mergers found about 70% missed revenue synergies, often misquoted as "70% fail" (seen only in summary).

Sources: Mail & Guardian and just-food (KPMG 1999), CFO.com (McKinsey 2004), Bain 2024.

Ask an expert

For an operator who has done this:

  1. Which decision did you make too late, and what did the delay cost?
  2. How did you choose each component's outcome, and which call did you reverse?
  3. What did you plan for churn and dis-synergies, and how close was it?
  4. When did you merge the sales teams, if ever, and what rule decided who sold what?
  5. How long did you run two stacks, at what monthly cost, and what let you turn the old one off?
  6. What notice did your largest customers actually need, compared with what their contracts said?
  7. Which offer moved the most revenue: credits, waived renewals, price locks or white-glove help?
  8. In payments, what reconciliation standard did you require before switching off the old ledger?
  9. In telco, did merging stacks force re-registering campaigns, short codes or numbers, and what did customers notice?
  10. For anything you kept independent, what trigger would end independence, and did it fire?

Self-check: 15 questions

  1. Why doesn't "70-90% of acquisitions fail" hold up, and what's a better statement? Answer
  2. Which decisions should be fast, and which shouldn't run on a 100-day clock? Answer
  3. Your team wants to ask the target to pause a roadmap item before close. What's the risk? Answer
  4. What goes in a regulated-asset register, and why key it by legal entity? Answer
  5. What must be done by day 30, and what by day 100? Answer
  6. Why decide who sells what to whom before merging sales teams? Answer
  7. How much notice do big platforms give before breaking an API, and when must yours go out? Answer
  8. What does "migration complete" mean, in three milestones? Answer
  9. Name the four outcomes and an early sign that each is the wrong choice. Answer
  10. Why is independence a phase, and what do you write down when you choose it? Answer
  11. Who recommends each component's outcome, and who can veto it? Answer
  12. After a stock deal closes, what happens to the target's state licences, 10DLC brand and SOC 2 report? Answer
  13. Why might a plan to kill or migrate a licensed product slow its approval? Answer
  14. Why does keep independent win the worked model over three years, and what would change that? Answer
  15. What did FIS and Worldpay, and TSB, each teach about measuring an integration? Answer

Sources

Read on October 2, 2026 unless dated; "search result" means seen only as a search snippet or summary.

Academic research

Consultancy and survey figures (marked in the text)

Books and practitioner writing (ideas only)

Regulators, law and standards

Law firms, auditors and advisers

Company documents, filings and reporting

  • Linked where cited, under each case and in each section's Sources line

Cost inputs

Playbooks are one practitioner's operating notes, not management, legal or financial advice. Adapt them to your company before you act on them.