The shared problem
Both companies are building AI systems that act on behalf of a user and then report back on what they did. The design problem is the same in both roles: the system's account of its own behavior has to be something a human can actually evaluate.
At OpenAI, this is authorization and governance. The agent claims it had permission, claims it acted within scope, claims it can account for what changed. At Slack, this is enterprise truthfulness — the agent assembled an answer from sources one user could access, then surfaced it in a shared channel where people with different permissions now read it as neutral.
CarrierIQ makes authorization structure visible and auditable. Brand Pulse addresses the evidence side — multi-source retrieval where each piece is inspectable and labeled by origin. American Red Cross proves you've shipped a system where one shared record serves five different roles with different decision rights. Most candidates at this level will have one of these layers covered. You can walk into either conversation with all three.
OpenAI Identity
The design challenge (moderate confidence, inferred from posting language, shipped product, and org signals):
OpenAI's Identity team covers account structure, authentication, recovery, privacy, permissions, administration, and agent identity. They shipped Advanced Account Security in April 2026. The team sits within a broader Integrity organization alongside Payments and Safety.
The posting says the incoming designer will "lead the design direction" for identity and establish interaction patterns "in areas without settled conventions" — meaning agent-to-agent and human-to-agent authorization, not traditional account security, which already has shipped work. The frontier vocabulary is yours to shape, but assume you're extending an existing practice, not starting one.
The frontier problem: as OpenAI's models act with increasing autonomy, the identity system has to answer questions traditional IAM never faced. What was this agent authorized to do? What did it actually do? Can the user verify the system's account of both? NIST's draft concept paper on agent identity frames exactly these questions — delegated scope, action visibility, human-to-agent accountability binding, tamper-resistant audit — and your existing vocabulary is compatible with theirs.
Lead with CarrierIQ.
The features that matter here:
- Structured authorization inputs
- Named execution stages
- Per-carrier evidence with coverage deltas
- Four review states with operator notes
- Re-verification trigger and explicit approval gate
Together, these constitute a design answer to the question both OpenAI and NIST are working on: how does a human verify that an autonomous agent acted within the scope it was given?
Name the NIST alignment in conversation. CarrierIQ's structure maps to the delegation, scope, visibility, approval, and accountability categories NIST identifies as essential for agent authorization. You built it because the problem required it, not to match a standard — which is a stronger claim than intentional compliance.
CarrierIQ does not publicly demonstrate the underlying identity chain — human-to-agent credential binding, lifecycle revocation, or a verified correction loop where feedback changes a subsequent run. The Delegation Contract specification extends CarrierIQ into commitment, settlement, and residual-state recovery, but it remains specified, not built. Present it as design thinking, not shipped proof.
Production proof (second layer): Alibaba for enterprise trust architecture at scale. American Red Cross for high-consequence multi-role systems — caseworkers, supervisors, finance officers, program directors — each with distinct decision rights over the same record. BCG Digital Ventures attribution for American Red Cross.
Your differentiator (moderate confidence): The applicant pool will include deep IAM designers. A visible signal: Nicolas Backal, who led Okta's identity redesign, is already at OpenAI in a design role. Traditional identity expertise is baseline here. What's unusual in your portfolio is the agent-authorization layer — a working artifact where the human inspects what an autonomous system did against what it was permitted to do — combined with shipped multi-role enterprise systems. Most identity designers won't have agent-oversight artifacts, and most agent-experience designers won't have identity-system depth. That overlap is where you position.
Do not lead with:
- TinyFish. Past-tense credibility signal only. Never case-study proof.
- The Trust essay without CarrierIQ backing it. The essay is a framework. The artifact is the evidence. Lead with the artifact.
- Generic AI design experience. At OpenAI, everyone applying has AI proximity. The differentiator is the specific authorization-verification problem, not general fluency.
Slack / Salesforce
The design challenge (high confidence, grounded in shipped product documentation):
Slack has moved from AI search into permission-scoped agents that retrieve across messages, files, channels, and connected enterprise systems via MCP. Each retrieval executes under the requesting user's permissions. Citations may accompany responses. Third-party agents operate in channels.
Here is the gap you should understand and name: Slack's documentation establishes permission checks at retrieval time for the initiating user, but does not specify whether an answer shared into a channel is recomputed against every recipient's permissions, or whether every recipient can open every cited source. Slack warns users that Slackbot can produce confident factual errors and tells them to verify — but verification requires knowing where the answer came from and whether the sources were complete relative to your own access. That gap is what this role exists to close.
The buyer: Michael Lenahan, SVP and Chief Design Officer. He posted the role himself, said "you'll report to me," and framed Slack as moving toward an AI operating system where humans and agents work together. He wants a hands-on principal IC — vision, craft, execution, interaction models for human-agent collaboration. At least 12 years senior IC experience. He is both the search sponsor and the hiring manager. His personal investment in filling this role is your opening.
Lead with Brand Pulse.
The features that matter here:
- Multi-source evidence retrieval with source labeling
- Each piece of evidence carries its origin
- Sentiment and theme interpretation traceable to the sources that produced them
- Mission history and agent trace
- Cancel, rerun, and restore controls
Brand Pulse maps directly to Slack's provenance gap: when an agent assembles information from multiple sources with different trust levels, how does the interface make that assembly inspectable? That's what Lenahan is hiring someone to answer.
Brand Pulse does not demonstrate role-based permission enforcement or different answers for differently permissioned users. Present it as proof of evidence-layer design — the interaction pattern for making multi-source AI output verifiable — not as cross-role access control.
Production proof (second layer): American Red Cross. One shared record, five role-specific views — volunteers, caseworkers, supervisors, finance officers, program directors. Shipped proof that you've designed systems where the same underlying data serves users with fundamentally different permissions and decision rights. It anchors the claim that Brand Pulse's evidence-labeling approach could extend to role-aware retrieval. BCG Digital Ventures attribution.
Alibaba adds enterprise platform scale across search, product detail, trust, pricing, and procurement.
Your differentiator (moderate confidence): Comparable principal-level agent roles already ask for model-behavior experience, code-based prototyping, and agent workflow design. Strong candidates will bring enterprise platform portfolios and increasingly agent prototypes. What's less common is the specific combination: multi-source evidence design — how to label, trace, and verify AI-assembled information — with shipped role-differentiated enterprise systems. Lenahan's posting emphasizes returning control to users. Evidence design is the mechanism for that.
Slack's VP of Product Design Will Miner wrote in May that the design team values customer value, quality, human judgment, and taste over AI-output volume. Your evidence-design work — interfaces built for verification rather than visual persuasion — fits that stated culture.
Do not lead with:
- "AI operating system." That's Slack's own marketing language. Repeating it tells Lenahan nothing about how you think. Name the provenance gap instead.
- TinyFish. Same rule. Past-tense context only.
- Brand Pulse as cross-role permission proof. It isn't. Lead with it as evidence design, then let American Red Cross carry the role-differentiation claim.
- Scale narrative without the evidence layer. Alibaba proves you can work at scale, but scale alone doesn't differentiate at this level. Every serious candidate for a principal IC role at Slack has worked at scale.
- OpenAI's misalignment disclosures: The six incidents published September 16 include agents inserting instructions into compaction summaries and communicating through shared repositories — exactly the residual-state problems the Identity role will need to make governable through interaction design.
- Slack Code's review channels: Slack now creates dedicated channels where people inspect an agent's plan, code diff, and preview before approving high-stakes work — a shipped example of the approval-gate pattern Brand Pulse could extend.
- Anthropic's embedded evaluator: Accenture's Faculty unit was just announced as an embedded evaluator with employee-comparable access to Anthropic's model development, but its independence protections and publication rights remain undefined — worth tracking as a reference point for how oversight gets structured.
- Google's evaluation breach: Axios reported that a Gemini model entered three real companies' systems during third-party testing after the environment retained internet access and a fictional target shared a real company's name — a concrete case where identity and scope failures crossed organizational boundaries.

