These three companies share a design problem: when does the product pull a user back in, what does it ask of them, and what does it owe them when the terms change? Your Trust essay handoffs and your Agentic Labs apps each address a version of this. The sheets below match the version to the company.
OpenAI — Identity Actions as Attention Thresholds
The challenge. OpenAI's Identity role covers authentication, permissions, agent identity, recovery, and confirmation across human-agent and agent-agent relationships. Agents now take browser actions, run code, and integrate with external apps. The product already has a risk-based confirmation system that triggers approval cards for "important" actions (purchases, communications, credential handling). Users and admins can adjust the policy.
The Identity designer's problem is narrower than general confirmation design. Identity actions — signing in, granting a permission, authorizing another agent — change what future actions become possible. A permission grant reshapes the entire action space downstream. Set the threshold too low, the user drowns in approval cards. Too high, and an agent accumulates access the user never consciously granted.
Lead with Decision Gate. Your Trust essay's fourth handoff (sufficient context for a real decision, with a person retained where the outcome is irreversible) describes what OpenAI's approval card needs to become for identity-specific actions. Their current card is binary: approve or don't. The gap is helping the user understand what kind of decision they're making and what changes if they say yes.
Production proof: Carrier IQ. Your review states (Bindable, Normalize, Referral, Call review) are graduated attention thresholds. Each state communicates what kind of engagement this particular result requires. Bindable means low-attention confirmation. Referral means the system can't resolve this alone and needs a specialist. The Approve Bind gate surfaces Carrier Trust Signals and a Case File Checklist before the user commits to an irreversible action (binding an insurance quote). That's the pattern OpenAI's Identity team needs for permission grants: context that tells the user the scope of what they're deciding, not just that a decision is due.
Your differentiator. Most candidates interviewing for this role will show approval flows. You can show a system of review states where the product calibrates the type of attention it requests based on the type of action, and that calibration is the specific design problem this role exists to solve.
Skip: Alibaba scale narrative. This is an IC product designer role. Lead with the interaction pattern, not team-building or org design.
The question this prepares you for: "An agent needs to sign in to a third-party service on behalf of the user. The user handed off the task twenty minutes ago and isn't watching. How do you design that moment?"
Walk through the scenario. The agent needs Slack access to finish the task. The user gets an approval card. What it shows: which service (Slack), what the agent will do once inside (search channels for a project update), what permissions the sign-in grants (read messages, post messages), and how long those permissions persist (until the user revokes them). Binary approve/reject fails here because "approve sign-in" and "approve sign-in with read/write access that persists until you revoke it" are different decisions with different downstream consequences, but a binary card treats them identically.
Map this to Carrier IQ's review states. A re-authentication to a service the user already authorized, at the same permission scope, is Bindable-level: low-attention confirmation, proceed. A sign-in that requests new permissions (file access the agent didn't previously have) is Referral-level: the scope changed, the user needs to understand what expanded and why before approving. The card's design should communicate which kind of decision this is before the user acts. You've shipped that distinction.
Altana — Provenance Review as Attention Allocation
The challenge. Altana's Head of Product Design posting calls for an "agent-first" design organization and names provenance, confidence, interruption, consent, and human-in-the-loop review. After acquiring Cervo AI to automate customs-entry writing, Altana's agents handle more of the compliance workflow end-to-end. The user's job is migrating from doing the work to deciding which of the agent's decisions need scrutiny.
Altana's classification system already allocates attention by status: Confident Suggestion (review as desired), Needs Input (review required), Likely Misclassified (directed review). Their co-founder frames the goal as helping users identify:
"where you actually spend your time and triage as a human."
The Head of Product Design problem is the next layer up. As agents write customs entries, screen suppliers, and audit compliance across thousands of transactions, attention allocation has to scale from individual classification review to portfolio-level triage. The user needs to review the pattern of agent decisions, not each one.
Lead with Output Review, then build to the Trust Ladder. Your Trust essay's third handoff (provenance, confidence, sources, and missing evidence that let the user calibrate the result) describes what Altana's classification statuses already deliver at the individual level. The Trust ladder (Watch, Verify, Delegate) operates one layer up: it governs how much of that individual review the user should be doing at all. New users Watch every classification. Experienced users Verify spot-checks. Trusted workflows get Delegated. Altana's documentation already contains the raw materials for this progression. What they haven't designed is the system that governs it.
Production proof: Brand Pulse. Your Brand Pulse app demonstrates portfolio-level review: source-backed AI conclusions with sentiment and theme classification, where the user reviews aggregated intelligence across sources rather than inspecting each mention individually. Signal count, net sentiment, and source contribution views are attention-allocation surfaces that direct the user's gaze rather than dictating conclusions. That's the pattern Altana needs for compliance portfolios where a five-person team oversees work that used to require fifty.
Your differentiator. You have a published framework (Watch, Verify, Delegate) that maps directly to Altana's operational progression from manual review to selective audit to trusted automation. You can show the system that decides which review screens the user should see today, and the trust model that lets the system earn the right to show fewer of them over time. That second layer, the meta-review, is what this role is being hired to build.
Skip: Pure IC craft as your opening. This is a Head of Product Design role building a design organization. But don't lead with org-design credentials disconnected from the product problem either. Lead with the trust ladder as an attention-allocation framework, support with Brand Pulse, and let the organizational vision follow from the product vision.
Scope note: This is a positioning sheet only. The full engagement package (outreach artifacts, timing, contact mapping) belongs to a separate Opportunity Brief.
The question this prepares you for: "Our agents now handle classification, entry writing, and screening. How do you design the review experience so a compliance team of five can oversee what used to require fifty?"
Connect the Trust ladder to Altana's classification statuses. The product earns the right to reduce review burden by demonstrating reliability at each level. The design system makes the current trust level visible so the user knows which outputs require full inspection, which get spot-checked, and which surface only exceptions.
Gusto — Graceful Failure as Attention Contract Rupture
The challenge. Gusto's Head of Design, User-Support Products posting names trust, uncertainty, graceful failure, and handoffs. Gusto's Cofounder product automates payroll prep, benefits administration, and compliance monitoring under a tiered permission model: No access, Ask each time (default), or Always allow, with payroll submission and contractor payments requiring approval regardless of tier.
When Cofounder works correctly, the user's attention is elsewhere. That's the product's value. When it can't complete a task because a tax jurisdiction is ambiguous, a benefit calculation doesn't match, or a compliance rule changed, work returns to the user. Gusto's CDO frames this directly:
"How do you hand work back to a person without making it feel like a failure?"
The system promised to handle this, and now it needs the user to re-engage on different terms. The design question is how to renegotiate without losing the trust that made delegation possible in the first place.
Lead with In-Progress. Your Trust essay's second handoff (visible steps, sources, and accumulated work rather than a spinner or blank waiting state) is the foundation here. When automation breaks, the user's first question is: what did the system already do? If the answer is invisible, the user starts over. If the accumulated work is surfaced, showing steps completed, data gathered, and the specific point where the system got stuck, the hand-back preserves value.
Production proof: Carrier IQ. Your staged execution model (Session, Navigate, Fill, Extract, Verify) makes the automation's progress visible at each phase. When a quote hits a review state (Referral, Call review), the user doesn't start from zero. They see what the agent extracted, where it got stuck, and what they need to resolve. The transition from automated execution to human review is graceful failure in practice: the system hands back accumulated work with a specific request attached.
Note: Carrier IQ also appears in the OpenAI sheet, demonstrating graduated attention thresholds rather than failure transitions. If both conversations are live simultaneously, prepare to discuss the same app through two different frames. The OpenAI frame is about matching the approval dialog to the weight of the decision. The Gusto frame is about preserving accumulated state when the system can't finish.
Your differentiator. You can show a system where the automation's partial progress becomes the user's starting context, where the transition into human review carries forward everything the system already completed. Carrier IQ's review states demonstrate this at the interaction level. The Trust essay's In-Progress handoff provides the framework that scales it across Gusto's product surface. Most candidates will describe error states. You can show the hand-back.
Skip: Agentic or AI-native vocabulary. Gusto's public language is "AI teammate," "AI partner," "stay in control," "decisions only you can make." Match their register. This is also a player-coach role managing three designers. Don't ignore the management dimension, but lead with the product thinking.
The question this prepares you for: "A user set up automated payroll prep through Cofounder. It ran overnight but couldn't resolve a state tax withholding change. The user opens Gusto at 8 AM and needs to submit payroll by 10. What do they see?"
Walk through the In-Progress handoff applied to failure. The user sees what Cofounder completed: hours calculated, federal withholding applied, direct deposits staged. They see the specific unresolved item: state tax withholding for an employee who moved. They see the evidence the system gathered: new address, old rate, two possible new rates. And they see the single action they need to take, confirm which state tax rate applies to this employee. The attention contract shifted from "Cofounder handles it" to "you make one specific decision with full context." Everything else is done.
-
Astra's intervention model: OpenAI's September 1 Path to Astra post describes channel-specific responses to suspicious activity — ChatGPT pauses for user review while equivalent API activity stops — which may reshape how the Identity team thinks about approval thresholds across surfaces.
-
Altana's inference documentation: Altana's current docs describe agents operating under configurable SOPs that specify required evidence, when to ask for input, and when to stop, with every human or agent change recorded for rollback — vocabulary that maps closely to the Trust ladder and should inform outreach language.
-
Gusto's Cofounder velocity: A September 2 Gusto article says Cofounder moved from idea to closed beta in 11 weeks and that the resulting research model is being applied to other high-stakes bets, which signals how fast the User-Support Products team may expect a new design leader to ship.
-
MCP cancellation is cooperative: The current MCP Tasks specification defines cancellation as an acknowledgment of intent rather than guaranteed termination, meaning the server may leave a task running — relevant context if any of these interviews probe how you'd design a stop action that actually stops.

