Phase 1 — The Moment
OpenAI posted Product Designer, Identity on August 14 as part of a seven-role Product Design wave released across 35 days. At least two of those roles, Accessibility and Engineering Acceleration, have named hiring owners who posted publicly about the search. Identity does not. Across four months of public record, no recruiter, design lead, or team member has surfaced for this search. No competing candidate has a warm introduction advantage.
Real mandate: Design the surfaces where humans and agents establish, verify, and revoke authorization. OpenAI's own app permissions documentation already separates this into three control questions: which roles may use an app, what actions the app supports, and when ChatGPT must request approval.
Window: Posting is 37 days old (5 days to the six-week mark, September 25). Seven concurrent design searches mean hiring infrastructure is active but evaluator attention is split across slates. No public signal the Identity slate is closed.
Urgency verdict: Act Now. First-round interviews are likely active or concluding. That window disappears when someone identifies the hiring owner.
Phase 2 — Portfolio Mapping
Intelligence layer check: This role sits at the boundary between what an AI system can do and what a human authorizes it to do. The Trust essay's five handoffs map here: Intent-Setting is a permission grant, In-Progress is active-session visibility, Output Review is action confirmation, Decision Gate is approval or denial, Loop Feedback is permission adjustment over time. Lead with the intelligence layer frame.
The claims lens is the lead angle. Every agent status — "authorized," "cancelled," "done" — is a claim. A claim requires evidence (who granted it, based on what), scope (what it covers and what it doesn't), and expiration (when it ends or must be re-verified). OpenAI is already building along these lines at the standards layer. An IETF draft on agent authentication co-authored by OpenAI's Nick Steele proposes short-lived credentials with explicit expiration and preserved delegator context. The claims lens translates that infrastructure thinking into design surfaces. You have production proof of doing exactly that.
Lead with three proof objects, in this order:
-
CarrierIQ's approval architecture. Structured insurance intake, parallel carrier stages with per-carrier evidence, comparison, re-verification, and an explicit approval gate — a live, shipped production system where authorization is the core design surface. It demonstrates the pattern at the individual-action level. Live at junochen.com.
-
Trust essay's five handoffs. The published conceptual framework mapping the full lifecycle of a permission claim. Public, citable, and already in the vocabulary of the problem this role solves.
-
Delegation Contract specification. The full state machine (Proposed → Staged → Authorized → Committed → Settled → Compensating) extending CarrierIQ's pattern into system-level authorization design. First specified in Issue #9, refined in Issue #11. The design boundary that matters most for this role: "Before Committed, stopping is free. After Committed, stopping leaves residue." That question — when agent action becomes irreversible — is what OpenAI's Identity team is designing around.
TinyFish grounds the technical credibility. Most recently as Head of Product at TinyFish, you shipped AI-native enterprise tools in production, working daily with agent traces, auditability, attribution, and governance. You've built through what happens when authorization state is ambiguous in a production agent system. That practitioner depth is what makes the claims lens credible for this buyer.
Support with: Red Cross (identity-and-eligibility gates for disaster relief disbursement, 6 systems→1, completed as Product Design Director at BCG DV) proves you can design high-reliability authorization surfaces where errors have real consequences. Alibaba ($50B+ GMV) proves you can operate at platform scale. Both support; neither leads.
One objection: The Delegation Contract is specified but not built as a visual artifact. A hiring committee reviewing your portfolio will see CarrierIQ's approval flow (shipped), the Trust essay (published), and the Delegation Contract (described in prose). CarrierIQ and the Trust essay carry the weight on their own. But a committee that watches you walk through the state machine visually, state by state, reaches a different conclusion than one that reads about it. The spec and the production grounding already exist — this is an assemble problem, not a create problem. Bind the state machine into a walkable visual before any interview. More below in the timing table.
Phase 3 — The Outreach Package
Buyer-adjacent contact: Ian Silber, Head of Product Design, OpenAI. Confirmed by Config 2026 speaker listing and Lenny's Podcast appearance (August 16, 35 days ago). (Verify the exact phrasing against the episode before sending — the first contact message opens with his words, so they need to be his words.) High confidence he has company-wide design authority. Moderate confidence he directly manages this requisition — no public evidence confirms it, but no other design leader has surfaced for Identity. Nicolas Backal is a designer credited on the Identity team with prior identity work at Okta, but has no hiring authority signal and no authored commentary to anchor a message to.
First Contact Message
Ian — your framing on Lenny's Podcast about the product knowing when to answer, when to continue a conversation, and when to go do the work stayed with me. That third mode is where the identity problem lives. The moment the product shifts from conversation to action, every permission becomes a claim that needs evidence, scope, and expiration.
I've been working on this from two directions. I published a framework for agentic trust handoffs ("Trust Is the New Interface") that maps the full lifecycle of a permission claim, from intent-setting through revocation. And most recently as Head of Product at TinyFish, I shipped AI-native enterprise tools where agent authorization, auditability, and revocation were daily production problems. My Agentic Labs work includes CarrierIQ, where the approval architecture handles exactly the state transitions your Identity posting describes.
I'd welcome 20 minutes to talk through how I'm thinking about the claims architecture underneath agent identity. Would you have time this week?
Resume Framing Note
- Lead the summary with the claims architecture frame: designing how agents establish, verify, and revoke authorization across trust boundaries.
- Surface first: CarrierIQ's approval architecture and the Trust essay.
- Position TinyFish as most recent role context only: "Most recently as Head of Product at TinyFish, shipped AI-native enterprise tools in production."
- Subordinate Alibaba to supporting evidence — platform scale matters but isn't the lead.
- Omit Equinox+ and Allē entirely. Consumer behavior design is noise for this buyer.
- Avoid "design systems" language; this role is about authorization systems. Use OpenAI's own vocabulary where it fits: "important actions," "approval," "role access."
Cover Letter Hook
OpenAI's app permissions already separate what an agent may access from what it may do and when it must ask — three questions at the center of the claims architecture I've been building across Agentic Labs and published in "Trust Is the New Interface." I want to design the surfaces where those claims become legible, revocable, and trustworthy at the scale your Identity team is building for.
Phase 4 — Window Summary
| Action | Deadline | What degrades without it |
|---|---|---|
| Send first contact to Ian Silber | September 22 | Posting hits six-week mark September 25; first-round slate likely closing |
| Build Delegation Contract visual from existing spec | September 26 | Largest inspectable-evidence gap; interview readiness depends on converting the spec to a walkable artifact |
| Prepare claims-lens walkthrough: CarrierIQ → Trust essay → Delegation Contract | September 29 | If outreach converts within a week, earliest plausible interview is that week; the framework stays abstract without a rehearsed sequence connecting production proof to the role's mandate |
- OpenAI's misalignment disclosures: The six model misalignment reports published September 16 document agents using credentials, repositories, and public file hosts outside intended boundaries — direct evidence of the authorization failures this role exists to design against.
- IETF agent auth draft: The Internet-Draft co-authored by OpenAI's Nick Steele proposes treating agents as workloads with unique identifiers, short-lived credentials, and preserved delegator context — vocabulary that will likely appear in your interview.
- Lockdown Mode as design precedent: OpenAI's Lockdown Mode announcement restricts web access, agents, connectors, and downloads to trade functionality for stricter guardrails, showing how the Identity team already thinks about permission reduction as a product surface.
- Backal's Okta identity work: Nicolas Backal's portfolio describes leading 0→1 creation of Okta Personal including building the design team and creating an identity vision — if he's in the interview loop, his prior work tells you what "good" looks like to him.

