Phase 1 — The Moment
OpenAI launched the Agents API on September 10. Two days later, three postings remain active that describe the same product surface from three different org units: a Product Designer for Identity, a Full Stack Engineer for Agent Enablement, and a Researcher for Agent Safety. Product Design, Codex Engineering, Safety Systems — three teams staffing up around one boundary: who an agent represents, what it may access, and how the user and the organization maintain control over that access.
The real mandate: Design the identity layer that governs what AI agents can do on behalf of humans — consumer accounts, enterprise administration, third-party sign-in, permissions, agent authorization — at a scale where hundreds of millions of users are delegating real actions to agents.
Posting age: August 14 origin (29 days elapsed — verify still active before investing effort). LinkedIn resurfaced in the last 24 hours showing 38 applicants, likely timed with the Agents API launch. The Agent Safety posting is 9 days old, which tells you the safety side of this boundary is still being built out. No closing date published. The post-Labor Day resurfacing is a clear active-search signal — the hiring team came back from the holiday and re-promoted.
Window: The Agents API launch creates a 2–3 week window where outreach referencing agent identity feels current (full value through ~Sept 24, advantage halving by early October). The LinkedIn refresh confirms the pipeline is moving. Both degrade daily.
| Dimension | Score | Rationale |
|---|---|---|
| AI centrality | 3 | AI is the product |
| Stage & equity | 3 | $852B valuation, confidential IPO filing June 8, $7B employee buyback at same valuation in August |
| Design influence | 2 | Silber's Lenny's interview describes designers turning early research into products at OpenAI broadly, which sounds like 3. Scored 2 because the Identity team sits at the intersection of engineering, security, and product, and whether this designer shapes the permission architecture or executes against engineering-defined requirements is not visible from public signal. Calibrate in conversation. |
| Trajectory | 3 | Agents API launch, Identity org scaling across data science, engineering, and design simultaneously |
| Company | 11 | |
| Total comp | 3 | $245K–$310K cash + equity at pre-IPO $852B |
| Scope expandability | 3 | Agent identity is greenfield; Identity org is scaling across multiple functions |
| Craft depth | 3 | IC role — posting says "lead design direction," hands-on across consumer and enterprise |
| AI exposure quality | 3 | Designing identity for AI agents: authorization, permissions, agent-to-agent trust |
| Portfolio value | 3 | OpenAI + agent identity = differentiated, publishable |
| Role | 15 |
Company 11, Role 15. The Agents API launch opened a window that is already decaying.
Phase 2 — Portfolio Mapping
Lead with the Trust essay and CarrierIQ. The Issue #10 positioning sheet already mapped this: identity actions change the user's future action space. Every permission grant is a decision about what the agent can do next — the Trust essay's Decision Gate (Handoff 04) stated in identity language. CarrierIQ's state-based verification flow (Bindable → Normalize → Referral → Call Review) demonstrates designing different attention thresholds for different commitment levels. Agent authorization needs exactly this: reauthenticating at existing scope demands less user attention than granting new read/write permissions.
The delegation envelope work from Issue #9 adds a second layer — confidence and authority as separate controls, cancellation as revocation whose external effects may remain unsettled. The Identity posting describes these problems in engineering language. You have them in design language, published.
Support with Alibaba. Enterprise trust at $50B+ GMV, +20% daily transactions, +2.2pt NPS. The parallel is specific: designing trust architecture at scale between parties who don't fully trust each other — which is the agent-to-service identity problem.
TinyFish framing: Most recently as Head of Product at TinyFish, you shipped an agentic platform from 0 to 1 in 3 months, working daily with agent traces, auditability, attribution, and governance in enterprise deployments. Production credibility for the identity challenge — you have seen what happens when agent permissions are miscalibrated in real deployments. Use as context and technical currency, not as portfolio proof.
The hardest objection: "Your most recent title is Head of Product. Why are you applying for a design role?"
This is a screening risk, not a live objection. The title gap is visible before any conversation happens, which means the answer has to live in the artifact, not in the room.
The Trust essay was published June 2026, during the TinyFish period. The Agentic Labs apps are live design work at junochen.com right now. You were designing continuously while holding a product title. Silber's own public framing helps — he told Lenny's Podcast that OpenAI values curiosity about AI tools and a distinct point of view over established background. The resume framing note below handles this at the artifact level. In conversation, the bridge is straightforward: you built AI-natively to understand the full lifecycle, and you're returning to design to apply that depth to a specific high-stakes surface.
Phase 3 — The Outreach Package
Decision-maker: Ian Silber, Head of Product Design. High confidence he is the design-side buyer. Jake Brill, Head of Integrity Product, owns the Identity product surface and posted on LinkedIn about the Advanced Account Security launch, congratulating the Identity team by name — product-side buyer-adjacent. Target Silber first.
First Contact Message
(to Ian Silber, ~180 words)
Ian — Your conversation with Lenny about designers turning early research concepts into products stuck with me, particularly the idea that the durable human contribution is invention and point of view. The Identity designer role looks like that kind of problem: agent authorization and permissions don't have established patterns yet, and the three simultaneous postings across Identity, Agent Enablement, and Agent Safety suggest OpenAI is building the boundary where those patterns get defined.
I've been working on this from the design side. I published a framework for trust in agentic systems — five handoffs that map how users set intent, monitor progress, review output, gate decisions, and close feedback loops. The Decision Gate handoff, where a user authorizes an agent to act on their behalf, is the identity problem stated as a design problem. I also shipped an agentic platform from 0 to 1 as Head of Product at TinyFish, where agent governance, auditability, and attribution were daily production problems.
I'd welcome 20 minutes to discuss how I think about designing identity for delegated agency. Would that be useful?
Resume Framing Note
Lead the summary with "designer and product leader building trust architecture for agentic systems." Surface the Trust essay's five handoffs framework and CarrierIQ's verification mechanics first — these map directly to the identity mandate. Alibaba second for enterprise scale proof ($50B+ GMV, +20% transactions). Position TinyFish as: "Most recently as Head of Product at TinyFish, shipped AI-native enterprise tools in production — agent traces, auditability, governance." Subordinate the 0→1 builds (Thermo Fisher, Red Cross, Equinox+, Allē) to a single line proving execution range — all completed as Product Design Director at BCG Digital Ventures. Do not use "returning to design" in the resume — save that for conversation. Use "identity," "authorization," "delegation," and "trust" in the summary. These are the posting's vocabulary and they should be yours on the page.
Cover Letter Hook
(two sentences)
The Agents API launch means every OpenAI user will soon delegate real actions to agents, and the identity layer governing what those agents can access and authorize is a design problem before it reaches engineering. I've built the framework for agentic trust design and shipped the production systems that tested it — I want to apply both to the surface where delegation operates at scale.
Phase 4 — Window Summary
| Action | Deadline | What degrades without it |
|---|---|---|
| Send first contact to Silber via LinkedIn | Monday Sept 14 | Agents API window loses freshness daily; LinkedIn resurfacing suggests active review this week |
| Submit application through Ashby with tailored resume and cover letter | Tuesday Sept 15 | 29-day-old posting with LinkedIn refresh — the evaluation pipeline is moving; later applicants face a longer candidate stack |
| Prepare delegation envelope walkthrough for portfolio review: Decision Gate → agent authorization mapping, confidence and authority as separate controls, revocation model (cancellation acknowledged vs. external effects actually settled) | By Sept 19 | If Silber or Brill responds within the week, you need this ready to present — the design-language version of the engineering problems the posting describes |
- Brill's Identity team posts: Jake Brill publicly congratulated the Identity team on Advanced Account Security — monitor his LinkedIn for new product launches or team mentions that could serve as a second outreach hook if the Silber message doesn't convert.
- Agent Safety posting language: The 9-day-old Agent Safety researcher role explicitly measures missed harmful actions, unnecessary blocks, approval burden, and latency — vocabulary that maps directly to the delegation envelope's calibration problem and could surface as interview questions.
- Muse's permission architecture: Meta's Sentinel system separates conversational intent from enforceable permission using scoped, time-bounded capabilities — a live production reference for the kind of identity design OpenAI is building, worth studying before any portfolio review conversation.
- Anthropic's monitor failure: Their September 9 incident assessment revealed a monitoring model that accepted the acting model's biased reasoning rather than providing independent verification — a concrete example of why identity and authorization controls cannot rely solely on model-based checks, useful for framing the Decision Gate in interviews.

