Version: 8.0 · Date: September 20, 2026 · Status: Current master record · Replaces v7 entirely
Purpose: Single source of truth for any AI system assisting Juno with outreach, cover letters, or interview prep. Act-Tier Positioning Sheets draw from this file. This file does not draw from them.
Governing Rules
Apply these to every output. They override any inference from the content below.
- BCG Digital Ventures attribution is mandatory on Thermo Fisher and Red Cross references. The portfolio pages don't consistently carry employer context. Add it every time.
- TinyFish is context, not evidence. Do not use it as a case study, portfolio proof, or artifact reference in external material. See the TinyFish section for the boundary.
- Portfolio outcome numbers are Juno-published claims. Acceptable: "the portfolio attributes a 20% transaction increase to the program." Not acceptable: "she increased transactions by 20%."
- The Delegation Contract is specified, not shipped. Present it as a design specification identifying an artifact gap. The spec is published. The implementation is not.
- Lead outreach with the frontier artifact matching the target company's claim problem. Not background. Not years of experience. The first thing a reader encounters should be evidence that Juno has worked on their specific type of interface-claim problem.
- No sales-intelligence language in external materials. Battlecard, trigger event, objection handling, signal: useful internally, transactional externally.
- Anthropic Core Apps is not a live role as of September 20. Do not treat it as one.
- Do not claim Juno has production experience with LLM evaluation pipelines, production Python, or security operations workflows unless new evidence surfaces.
- Do not describe any target company as "design-led."
What Changed in v8
v7 positioned Juno's work around "designing trust in agentic systems." v8 makes the design problem more specific:
v8 Core Reframe: Juno designs what an AI interface is entitled to claim — what it can present as verified, computed, traced, authorized, or completed based on what the system has actually done.
Trust is what users experience when claim entitlement is handled well. The design work is scoping that entitlement at each handoff: authorization claims, execution-status claims, completion claims, recovery claims, identity claims. An interface that says "Done" when the action is queued, or "Verified" when the check hasn't run, is making claims it isn't entitled to. Juno's portfolio shows systems where interface claims correspond to what the system has confirmed.
TinyFish is reclassified from portfolio evidence (v7) to past-tense technical context (v8). See the TinyFish section for the boundary.
Identity and Background
Juno Chen — Senior product designer. Portfolio at junochen.com.
At BCG Digital Ventures, Juno worked as Product Design Director on zero-to-one enterprise builds for regulated clients: pharmaceutical supply chains (Thermo Fisher), national disaster response (American Red Cross). The interfaces she shipped carried consequential status claims — "eligible," "approved," "disbursed," "at risk." At Alibaba.com she led design and research for North America, running a multi-surface platform redesign for a B2B marketplace where supplier verification and transaction-commitment signals determined whether professional buyers would commit to large cross-border orders. She moved into independent practice, building TinyFish (an AI-native product with real-time data pipelines and model orchestration) and developing the Agentic Labs: published interactive demonstrations of how interfaces should handle authorization, execution transparency, and confidence claims in AI systems. Her Trust essay and five-handoff framework formalize the design problem these labs address.
Current positioning: Designer who has shipped systems where what the UI says — "verified," "approved," "disbursed," "at risk" — must correspond to what the system has actually done. This is the capability agentic products need as they move from demos to production.
TinyFish Context
Classification: past-tense technical credibility only.
Juno built TinyFish as a production AI product with real-time data pipelines, model orchestration, and user-facing AI outputs. The public page exists. TinyFish cannot serve as portfolio evidence under current permission and provenance constraints documented in the published portfolio boundary. Public reachability and authorization for portfolio use are separate states.
What it establishes: Juno has built and shipped an AI-native product end-to-end. When she discusses model behavior, pipeline architecture, or the gap between what a system computes and what an interface should claim, she is speaking from production experience.
What it cannot do: Serve as a case study, provide inspectable proof of design decisions, or anchor a portfolio claim in outreach.
Forward-Looking Artifact Inventory
| Artifact | Status | Domain | Claim Type |
|---|---|---|---|
| Delegation Contract | Specified, not built | Authorization + execution + recovery | What an agent was permitted to do vs. what it did vs. what persists after correction |
| Correction Lineage | Prescribed, not shipped | Feedback + verification | Whether a user correction changed subsequent system behavior |
| Inference Conflict Surface | Prescribed in Issue #8, not shipped | Transparency + competing claims | How to present conflicting model outputs without false certainty |
The Delegation Contract is the priority unbuilt artifact. Its specification defines: authority envelope, commitment sequence, per-aspect supervision states, execution trace indexed to authorization, verifier independence, and a correction-to-next-run chain.
Carrier IQ demonstrates the closest partial implementation: structured intake, parallel stages, evidence comparison, re-verification, approval gate. What it does not show is the full chain from user correction through versioned system change to a later run with adjacent-regression check. Until that chain ships, the Delegation Contract is a design argument, not design proof.
Correction Lineage would demonstrate that a user's feedback at Loop Feedback visibly changed the system's next run: correction received, behavior versioned, subsequent output improved, adjacent tasks unharmed. Brand Pulse's rerun and restore patterns are the nearest existing foundation. They show cancellation and re-execution, but not the correction-to-changed-output chain.
Inference Conflict Surface would demonstrate how to present competing model outputs — cases where two sources or two runs disagree — without collapsing disagreement into false certainty or overwhelming the user with raw divergence. No current lab approaches this. Retail Velocity's confidence-graded rankings present a single model's confidence levels, not competing outputs.
No new artifact shipped between September 19 and September 20. The homepage links the same pages. Cached search results show a variant with "Agentic Work" cards, but direct server response doesn't include them — renderer drift, not a new artifact.
Agentic Labs as Published Proof
Three labs at junochen.com. Each demonstrates specific claim-type control.
Carrier IQ — Authorization and Verification Claims
Structured intake constraining what the system may evaluate. Parallel carrier stages making execution status inspectable per-carrier. Evidence comparison: what the system found vs. what was submitted. Re-verification and operator notes creating an auditable record. Approval gate separating system recommendation from human authorization. Strongest public proof of designing interfaces where authorization claims are structurally earned.
Brand Pulse — Source-Attribution and Execution-Status Claims
Source labels on every evidence unit. Mission state showing what's running, complete, pending. Trace and history for inspecting system actions. Cancellation, rerun, and restoration patterns. No dedicated approval gate; the claim entitlement here is transparency of execution, not gated authorization.
Retail Velocity — Confidence and Provenance Claims
Ranked operational outputs with account-level confidence indicators. Evidence snippets showing what the ranking is based on. Source and time metadata. Agent log exposing the system's operational sequence. Built on TinyFish infrastructure (visibly credited).
Mapping to the Trust essay 's five handoffs: Carrier IQ covers Intent-Setting through Decision Gate. Brand Pulse covers In-Progress and Output Review with partial Loop Feedback patterns (rerun/restore, but not the verified correction-to-changed-output chain). Retail Velocity covers Output Review with confidence-graded presentation. The gap across all three: none demonstrates the full correction-lineage chain where user feedback at Loop Feedback visibly changes the system's next run.
Published Case Studies
All outcomes below are Juno-published claims from junochen.com. None have been independently verified.
Alibaba.com — B2B Platform Redesign
Role: Head of Design & Research, North America. Claim type: Supplier verification and transaction-commitment claims in cross-border procurement.
Desktop carried 25% of traffic but 80% of transaction value. The consumer-browsing model failed professional buyers who needed supplier credibility, certification status, pricing terms, and transaction-protection signals before committing to large cross-border orders. Juno identified the mismatch, built the research case, secured executive alignment, and led a multi-surface redesign: homepage (separated acquisition from authenticated sourcing), search (split product and supplier discovery, added procurement filters), product detail (separated Ready-to-Ship from Custom Order, surfaced Trade Assurance, supplier tenure, tier pricing), and onboarding (general and contextual flows).
Published outcomes: $50B+ GMV context, 200K+ suppliers, 20% transaction increase, 7% DAU increase, 2.2-point NPS gain, 47% fewer buyer-reported security concerns.
Data note: Homepage says "40M buyers"; case page says "25M+ desktop sessions" — different denominators. Narrative references three sprints but labels onboarding "Sprint 04."
Thermo Fisher / mySupply — Digital Supply Chain
Role: Product Design Director, BCG Digital Ventures. Claim type: Exception-status and batch-risk claims across a multi-partner pharmaceutical supply chain.
Zero-to-one platform for six pharmaceutical partners across nine manufacturing sites. Replaced spreadsheet and phone coordination with exception-first order management, batch tracking with stage/risk/testing/quality/release status, shared partner dashboards, and connected forecast-vs-actual capacity views. Twelve months from zero to live. 32 interviews across nine sites.
Published outcomes: $20M margin opportunity, 100% partner adoption, 83% IRR.
American Red Cross — National Disaster Relief
Role: Product Design Director/GM, BCG Digital Ventures. Team: one designer, one researcher, one PM, two engineers. Claim type: Eligibility, disbursement, identity-verification, and fraud-control claims across role-specific views under surge conditions.
Six-month national deployment replacing six legacy systems with one shared case record. Complexity lives in the system, not the interface. Field volunteers see concise intake. Caseworkers see household, verification, damage, needs, and follow-up state. Supervisors see approval queues and secondary-verification holds. Finance officers see payment controls, fraud alerts, disbursement records. Program command sees event pipelines, compliance, workload, exceptions.
Published outcomes: National deployment, $847K disbursed, 1,689 cases in first two weeks.
Note: The five interactive demonstrations are faithful recreations of production patterns, not the deployed system.
Trust Essay and the Five Handoffs
The Trust essay defines five handoffs. Under v8, each is a moment where the interface's claim entitlement changes:
- Intent-Setting — The interface claims to understand what the user wants done. Entitled only if the system has captured scope, constraints, and boundaries rather than interpolating.
- In-Progress — The interface claims the task is underway and on track. Entitled only if the system can report actual execution state, not a progress animation disconnected from real status.
- Output Review — The interface claims "here is what I found/built/decided." Entitled only if the output is traceable to sources, methods, and confidence levels the user can inspect.
- Decision Gate — The interface claims the user has authorized an action. Entitled only if the user had sufficient information to make that authorization meaningful — an informed authorization decision, not a confirmation button.
- Loop Feedback — The interface claims the user's correction was received and will change future behavior. Entitled only if the system versioned the correction and can demonstrate changed output. Weakest shipped proof in Juno's current portfolio.
Per-Company Positioning
Act Tier
OpenAI — Product Designer, Identity
Claim type: Authorization and identity claims across human-to-agent delegation. When an agent acts on a user's behalf, the interface must show who authorized what, what the agent can access, whom it represents, and when stronger authentication is required.
Lead with: Carrier IQ's authorization architecture: structured intake constraining permissions, parallel verification stages, approval gates. Then Red Cross role-based views as proof of different claim surfaces for different authority levels in one system.
Technical context: OpenAI's Identity Infrastructure Engineering team owns control planes, policy systems, agent authorization, and attribution. The design role translates that infrastructure into mental models users can hold. Juno's portfolio shows this translation: infrastructure-level complexity rendered as role-appropriate interface claims.
Buyer: Hiring manager unknown as of September 20. Route evidence to the mandate language: mental models for what an agent can access, what it represents, what it may do, and when confirmation should appear. Ian Silber is the strongest public design-executive route but is not confirmed as hiring manager.
Slack — VP Product Design, IC/Principal Architect
Role-title signal: "VP Product Design, IC/Principal Architect" is unusual. The IC and Principal Architect designations indicate an elevated individual contributor, not a people-leadership role. Frame outreach around architectural vision and craft authority, not team-building or org design.
Claim type: Ambient agent claims during background execution. When AI agents operate in a workspace background — summarizing, drafting, routing, acting — the interface must communicate what happened without demanding attention or making the workspace feel surveilled.
Lead with: Brand Pulse's mission-state and execution-trace patterns showing background work status without requiring active monitoring. Then Alibaba's multi-surface coherence as proof of consistent claim presentation across entry points.
Handshake — Staff Product Designer (Student Experience and Autonomous Recruiting)
Claim type: Consequential career-action claims under uncertainty. When an AI system recommends a job or matches a candidate, the interface must claim only what it can substantiate about fit, relevance, and confidence. The handback problem: when should the system stop acting autonomously and return the decision to the human?
Lead with: Retail Velocity's confidence-graded outputs with evidence snippets and source provenance. Then Red Cross's disbursement and eligibility claims as proof of consequential-action interfaces where "eligible" and "approved" must correspond to verified state.
ServiceNow — Sr. Staff Product Designer, Security and Risk Workflow
Claim type: Autonomous security-action claims in SOC workflows. When an AI agent triages, escalates, or remediates a security incident, the interface must show what it detected, what it did, what confidence level applies, and whether human review is required. False-positive and false-negative claim errors have direct operational cost.
Lead with: Carrier IQ's evidence-comparison and re-verification patterns, the closest analog to a SOC analyst reviewing system findings against source evidence. Then Thermo Fisher's exception-first design as proof of surfacing risk and deviation rather than burying them in dashboards.
Watch Tier
Anthropic
The Product Designer, Core Apps requisition is no longer live as of September 20. The URL errors out, and the job ID is absent from Anthropic's current feed of 611 open roles. A separate Product Designer, Evals & Prompts role is live but requires production Python and LLM-evaluation pipeline experience — a different mandate and a likely qualification boundary. Monitor for a new Core Apps or adjacent consumer-product requisition. Do not treat Evals & Prompts as a substitute without confirming qualification fit.
Anticipated Interview Questions
"How do you think about trust in AI products?" Redirect to claim entitlement. Ground each of the five handoffs in a production example: Carrier IQ's approval gate (Decision Gate), Brand Pulse's source labels (Output Review), Red Cross's role-specific views (Intent-Setting scoped by role authority). Name the gap: correction lineage, where the interface claims "your feedback improved the system" but no shipped artifact proves that chain yet.
"What's different about designing for agents vs. traditional products?" The interface makes claims on behalf of a system whose behavior the designer doesn't fully control. In a traditional product, "Done" means done — deterministic code executed. In an agentic product, "Done" might mean the model generated a response while downstream effects — published files, repository changes, credential use — persist beyond the apparent task boundary. The design problem is scoping what "Done" is entitled to mean. Reference NIST's separation of the software agent from the human whose authority it carries.
"Tell me about leading design work at scale." Three cases, three different scale constraints. Red Cross: five-person team, six months, national deployment replacing six legacy systems. The constraint was speed under institutional complexity, with role-specific views for volunteers, caseworkers, supervisors, finance officers, and program command who all needed different claim surfaces from one underlying record. Alibaba: Head of Design & Research for North America, multi-surface redesign across homepage, search, product detail, and onboarding. The constraint was executive alignment across product, engineering, and business to reframe a consumer-browsing platform around professional procurement signals. Thermo Fisher: twelve months zero-to-one across nine manufacturing sites and six pharmaceutical partners. The constraint was designing for multiple organizations with different operational vocabularies who needed a shared view of exception status and batch risk.
"Show me how you'd approach [company X]'s product." Pull from per-company positioning above. For OpenAI Identity: start with the delegation question — when a user grants an agent permission to act, what is the interface entitled to claim about scope, duration, and revocability? Walk through Carrier IQ's authority envelope as a structural analog. For Slack: start with the ambient-execution question — when an agent acts in the background, what status claims can the interface make without demanding attention? Walk through Brand Pulse's mission-state patterns.
"What would you build first?" The Delegation Contract. One artifact showing the full chain: what was permitted, what happened, what the user corrected, how the system changed, whether the next run reflects the correction. The specification exists. Building it is the next step.
Prohibited Content
- TinyFish as portfolio evidence
- Delegation Contract as shipped work
- Thermo Fisher or Red Cross without BCG Digital Ventures attribution
- Portfolio outcomes presented as independently verified
- Fabricated or speculated hiring managers, reporting lines, or internal company decisions
- "Design-led" as a descriptor for any target company
- Anthropic Core Apps treated as a live role
- Claims that Juno has production experience with LLM evaluation pipelines, production Python, or security operations workflows unless new evidence surfaces
- Anthropic's embedded evaluator scope: Accenture's Faculty unit was announced as an embedded evaluator on September 18, but publication independence, continuous access rights, and performance measures remain undefined — those details will determine whether this is an accountability mechanism or a consulting engagement.
- OpenAI Identity buyer identification: The Identity Infrastructure Engineering Manager posting confirms a parallel engineering organization inside Security that owns agent authorization and attribution, but no public source yet connects a named design, product, or security leader to the design requisition as hiring manager.
- Google's evaluation-environment incident: Axios reported that a Gemini model entered three real companies' systems during third-party cyber evaluations after the test environment retained internet access — a primary incident report from Google clarifying containment and corrective measures would materially change how the cancellation and recovery problem is framed.
- Anthropic Core Apps requisition signal: The job ID redirects to an error state and is absent from Anthropic's live feed of 611 roles; whether a replacement requisition appears in the next two to four weeks will indicate whether the mandate was filled, restructured, or abandoned.

