Baseline established: July 3, 2026. No prior audit exists for this case. All findings reference the live page as fetched today.
Current-State Summary
The Allē case is the strongest structural artifact in your portfolio. Six labeled decisions across two tracks, problem-to-solution framing at each node, outcome metrics in the hero, four design-direction explorations per surface. The A·01–B·03 decision architecture gives a panel something most Director+ cases never provide: numbered moves they can probe individually instead of a continuous narrative they have to parse under time pressure.
That architecture is doing real work. It's also masking three gaps a sharp panel will find in under ten minutes: no unifying loyalty thesis before the tracks split, near-zero leadership evidence woven into the design narrative, and complete silence on regulatory constraints in healthcare-adjacent work.
Fixable across the board. No rebuilding required. Copy additions and one structural move.
The metrics are partially attributed. Two of three headline numbers connect to specific decisions. The third floats. That third number is your biggest, which means it's the one a CPO asks about first, and you currently have no decision-level answer ready.
Here's the full assessment.
P0 Gating Vulnerability — Confirmed, Known Pattern
The full case page returns HTTP/2 200 with 254,448 bytes of complete HTML before any access check executes. The client-side gate uses the same pf_access_v1 localStorage key as the private essay flagged in the prior audit. JavaScript redirects unauthenticated browsers to /login.html, but the redirect is cosmetic. View-source, curl, unfurl bots, link-preview crawlers, and any non-JavaScript client receives the full case content without authentication.
The severity is arguably higher here than for the essay. This page contains your detailed decision rationale, design-direction explorations, and outcome attribution language. That's your competitive differentiation in an active search, sitting in a 200 response for anyone with the URL.
Fix: Server-side authentication returning 401 for unauthenticated requests. No HTML in the response body until the credential clears. The current approach stops casual visitors. It does not stop anyone with minimal technical awareness, and the people evaluating you at Director+ have that awareness.
This needs to be fixed before your next interview share, not after. If that share is Monday or Tuesday, the July 4th weekend compresses your window. Reach whoever handles your hosting today or tomorrow. The fix itself is small. The scheduling is the constraint.
If a panel member opens the link early and sees full content without entering a password, you've lost control of viewing context and pacing. They browse it in two minutes on a phone instead of the focused review the case is built for.
Criterion 1 — Single Strategic Premise Before Two Tracks
Absent. The case moves from problem framing (Brilliant Distinctions as a transactional pharma points program) directly into "two tracks, six design decisions" without stating the loyalty logic that unifies both surfaces. The before/after contrast implies the thesis. An implied thesis gives the panel nothing to anchor on.
A panel member who opens Track B first, or skips ahead to the provider decisions, has no anchor connecting what they're seeing to the consumer work. They're evaluating six decisions. You need them evaluating one system.
Add a single paragraph between the problem section and the approach section. Three to four sentences. Something close to:
"Allē's loyalty logic had to work as one system across two surfaces with different users, different workflows, and different definitions of value. For consumers, loyalty meant seeing progress toward a goal they chose, not points accumulating toward a threshold Allergan set. For providers, loyalty meant the system doing retention work they were already doing manually, faster and with better data. Every decision on both tracks tested against the same question: does this make the member-provider relationship stickier without adding work to either side?"
Draft your own version. The point: one premise, stated once, before the split. When the panel probes any individual decision, you point back to this as the governing logic. Without it, you're defending six decisions individually instead of defending one system.
Criterion 2 — Decision Rationale Depth
Strong structure, uneven rationale. The A·01–B·03 format is the primary structural advantage of this case. Preserve it. Name it in conversation: "I structured the case around six numbered decisions so you can probe any one directly." That framing tells the panel you built this for their evaluation process, not for a browsing session.
Within each decision, the problem-to-solution pairing is clear. Where the rationale thins: the "why this over alternatives" layer.
A·01 (balance → progress): The milestone architecture is well-described. What's missing: why milestone framing over a streak model, a savings-account metaphor, or a simple countdown? The choice to use percent-to-next-tier implies a specific behavioral hypothesis about loss aversion near thresholds. State it.
A·02 (catalog → care plan): Strongest rationale in the case. The in-app planning conversion at 2.4× front-desk enrollment is a clean causal chain: design decision → behavior change → metric. This is the model the other decisions should match.
A·03 (appointment → evidence): The Progress tab concept is compelling. The rationale for the comparison tool as "clinically useful" needs one sentence on why clinical utility matters for a loyalty product. The bridge between retention goal and clinical framing is implicit.
B·01 (patient list → priority surface): The sort-by-expiry-first decision is strong and specific. Add one sentence on what you tested or considered before landing on expiry as the default sort. Was it visit recency? Tier proximity? Revenue potential? The fact that you chose expiry over those alternatives is the rationale.
B·02 (checkout → patient context): Solid. The opportunity panel surfacing tier proximity and birthday before the patient sits down is a clear "why this moment" argument.
B·03 (broadcast → provider voice): Weakest rationale. The problem (batch-and-blast from Allergan) is clear. The solution (campaign builder with provider-voice templates) is clear. What's missing: why provider voice specifically? What evidence indicated that the provider relationship was the trust vector rather than the brand? One sentence connecting this to a research finding or behavioral pattern you observed turns a reasonable design choice into a defended strategic decision.
Priority fix: A·01 and B·03. One additional sentence each.
Criterion 3 — IC and Manager Proof
Nearly absent from the narrative. The hero states Product Design Director, names a team of three product designers plus UX research and brand. That's it. The entire case reads as a solo IC producing brilliant work. For a Director+ panel, that's a problem you can't afford.
You led a team through this. The case doesn't show it.
Weave leadership evidence into three specific moments. Not as a separate "leadership" section, but as embedded context within the design narrative:
In the design-direction explorations (Noir/Blush/Prism/Veranda for consumer, Analytics/Daylight/Ember/Canvas for provider): Who generated these? Did each designer on your team own a direction? Did you facilitate the evaluation? How did you and the team converge? This is the most natural place to show craft leadership because the artifact already exists. One sentence: "Each designer on the team developed one direction. We evaluated against [criteria]. Veranda won because [reason]." That's director altitude. The artifacts show the decisions. Nothing shows the leadership behind them.
In B·00 (the backoffice setup section): The three-section workspace structure (Dashboard, Patients, Reconciliation) is an information-architecture decision that almost certainly required stakeholder alignment with provider-facing teams at Allergan. The case presents it as a clean outcome. A panel needs to see the organizational work underneath:
"Restructuring the provider backoffice IA required alignment with Allergan's practice-solutions team, who owned the existing portal and saw the redesign as scope encroachment. I [specific action you took] to [specific resolution you reached]."
Fill in your specifics. The sentence shape matters: organizational obstacle, your action, resolution. Without it, the panel reads "designer who made a good IA call." With it, they read "leader who cleared the organizational path so a good IA call could ship."
Near the outcome metrics: Who presented results to leadership? What happened organizationally after 3.2× redemption and $42 CAC landed? Did headcount change? Did scope expand? One sentence connecting outcomes to organizational consequence shows you operated at director altitude, not IC altitude with a director title.
These are small additions. A panel finishes the case knowing a design leader built the conditions for these decisions to ship. At this level, that's what they're evaluating.
Criterion 4 — Consumer and Provider as One Logic
Structurally implied, never stated. The two-track matrix shows parallel transformations. The A·01–A·03 and B·01–B·03 numbering implies a unified system. The case never makes the connection explicit. A panel member could read Track A and Track B as two separate redesigns that happened to share a timeline and a design director.
The strongest proof of unified logic lives in the seams between the two surfaces. Where does a consumer action trigger a provider-side event? Where does provider data flow back to the consumer experience? The case doesn't surface these connections.
Add one paragraph after the premise (Criterion 1 fix), connecting two or three cross-surface moments:
- A consumer saving a care plan (A·02) should surface as a signal in the provider's priority queue (B·01). Does it? If so, say so.
- A provider sending a reactivation campaign (B·03) should trigger a return-moment notification on the consumer side. Does it? Connect them.
- The expiry alert driving 47% open rate on the consumer side (A·01) presumably also surfaces as an expiry-sorted priority on the provider side (B·01). That's the same data point powering both surfaces. Name it.
One paragraph naming these connections makes the case read as one loyalty system with two interfaces. That's the story a panel evaluating systems thinking needs to hear. If you have time, a simple flow diagram does the same work visually, but the paragraph is the fix. The diagram is the upgrade.
Criterion 5 — Outcome Attribution
Two of three metrics attributed. The headline number floats.
| Metric | Attribution status | Linked decision |
|---|---|---|
| $42 CAC (from $92) | ✅ Attributed | A·02 — in-app planning converted at 2.4× front-desk enrollment |
| 47% reactivation | ✅ Attributed | A·01 — expiry push notifications, 68% cited as return reason |
| 3.2× redemption | ❌ Unattributed | Appears in hero only, no decision-level connection |
Your biggest number has the weakest support. A CPO asks about this one first.
3.2× redemption is almost certainly the compound effect of multiple decisions. That's fine. Say so explicitly. Add one sentence near the outcome metrics:
"Redemption increased 3.2× as a compound effect of three changes: milestone visibility making points feel closer to value (A·01), care plans converting passive members to active planners (A·02), and provider-initiated outreach reaching lapsing members before they churned (B·03)."
Adjust the specific decisions based on what's actually true. Compound attribution stated explicitly is stronger than no attribution, and far stronger than letting the panel assume you don't know what drove your own headline metric.
Criterion 6 — Regulated Framing
Completely absent. No mention of regulatory constraints, compliance requirements, HIPAA considerations, privacy protocols, or any acknowledgment that Allergan operates in a healthcare-adjacent space where treatment records, provider-patient relationships, and medical aesthetics data carry regulatory weight.
This gap matters for two reasons. Any panel member from a regulated or healthcare-adjacent company will notice the absence and wonder whether you navigated real constraints or operated in a sandbox where compliance was someone else's problem. And this connects to your broader positioning: constraint dissolution is one of your strongest differentiators. The Red Cross work proves you can embed regulatory requirements into the product so they accelerate rather than drag. The Allē case has the same opportunity and leaves it on the table.
I don't know whether the constraints you navigated were HIPAA, state medical-board requirements, FDA marketing restrictions on treatment claims, or Allergan's internal compliance protocols. You do. The specificity matters. A panel member from a regulated company hears the difference immediately. "We had compliance constraints" is generic. "Our treatment-history surfacing had to clear Allergan's medical-affairs review because provider-facing treatment data fell under their internal HIPAA-adjacent protocols" puts you in the room where the constraint was negotiated. Name the actual framework. Name the actual review body.
Add regulated-context framing in two places:
In the problem section: One sentence acknowledging that Allergan's pharmaceutical-loyalty context meant treatment data, provider-patient records, and reward-redemption flows operated under specific privacy and compliance constraints. If Allergan had an internal medical-affairs team that reviewed what data could surface in the provider backoffice, that's the detail that earns credibility.
In B·02 or B·03: These decisions most likely involved data-handling constraints. The opportunity panel in B·02 surfaces treatment history and patient data at the point of care. The campaign builder in B·03 uses patient-level data for targeted outreach. Both had to navigate what data could be surfaced, to whom, under what consent model. One sentence per decision showing the constraint shaped the design, not just the review process. If Allergan's legal and compliance teams were in the room for these decisions, say so. That's leadership evidence and regulated-context evidence working together.
Priority Actions
Ranked by impact on panel survival:
- Fix the gating vulnerability. Server-side auth. Before your next share, not after.
- Add the unifying premise paragraph. One paragraph between problem and approach. Changes how the entire case reads.
- Attribute 3.2× redemption. One sentence of compound attribution. Your biggest number cannot float without a decision-level answer.
- Weave leadership evidence into three moments. Design-direction convergence, B·00 stakeholder navigation, outcome-to-org-consequence. Small additions, large signal change.
- Add regulated-context framing. Two placements, two to three sentences total. Name the specific constraint framework. This moves the case from "consumer loyalty redesign" to "healthcare-adjacent loyalty system designed within real constraints."
- Strengthen rationale on A·01 and B·03. One sentence each on why this approach over alternatives.
The case's structural architecture is genuinely strong. The A·01–B·03 decision format is the kind of thing panels remember after a long day of portfolio reviews. The missing layer is connective tissue binding six good decisions into one defended system, plus the contextual signals proving a director made them. Both are additive fixes, and most of this is executable tonight.
- Headway's dual-surface parallel: Headway's Design Director, Provider Experience posting describes an EHR spanning scheduling, telehealth, clinical documentation, and billing with AI at the center, making the Allē dual-surface loyalty logic directly transferable if the regulated framing gets added.
- Gusto's constraint-dissolution match: Gusto's Senior Product Design Manager, Payroll posting names automation and AI initiatives that reduce manual work without compromising accuracy or trust, which is the exact constraint-dissolution pattern the Allē case should be proving but currently undersells.
- Capital One's org-transformation lens: Capital One's Director, Product Design — AI in Experience Design role evaluates operating-model judgment and CDO-proximity leadership, so the IC-manager proof gap in the Allē case would be the first thing that room notices.
- Client-side gating across all cases: The full case-study pages all use the same
pf_access_v1localStorage redirect pattern, meaning the gating vulnerability flagged here applies to every password-protected case and should be fixed as a single server-side change across the site.

