Verification Block
Fetched: July 24, 2026, 7:58 AM PDT.
URL: junochen.com/cs-06-alle.html → 308 redirect to /cs-06-alle → HTTP 200.
Last modified: July 19, 2026.
The full case (254,448 bytes of HTML) ships in the response body before a client-side authentication check. This is the same vulnerability pattern I documented on July 10, now two weeks unresolved. Every word, metric, and prototype link in this case study is publicly accessible to anyone who reads the HTTP response.
The localStorage.getItem("pf_access_v1") check redirects unauthenticated visitors to /login.html, which runs a browser-side SHA-256 hash comparison. The mechanism shifted from an inline overlay to a redirect-after-delivery approach. The core failure is identical: content arrives before authentication.
The teaser page (cs-06-alle-teaser) loads without gating and carries stronger metadata. The full case's <title> is "Allē · Juno Chen" with no meta description. The teaser names dual-surface loyalty, scale (30M members, 40K practices), and outcomes. When a hiring manager shares the full-case URL and the recipient's browser renders the title tag in a link preview, they see a generic label. The teaser would have shown a mandate.
Two housekeeping flags: the full case labels this work as "Case Study 05" while the URL says cs-06. The full case dates the work to 2020; the teaser says 2021. A hiring panel that notices will wonder which number and which year to trust. Small. But these accumulate.
The Central Question
You redesigned two surfaces. A consumer loyalty app serving 30M+ members. A provider backoffice serving 40K+ practices. This audit asks one structural question: do those tracks read as one loyalty architecture expressed through two surfaces, or as two adjacent projects that share a client and a page?
A buyer who reads "one architecture" sees a systems thinker who can own a product. A buyer who reads "two projects" sees a strong executor handling parallel workstreams. Both are valuable hires. They are not the same hire. For the roles you're targeting, that gap is the whole game.
The design work across both tracks is strong. The A·01–B·03 decision-block format is the right structure. What follows is whether the narrative matches the sophistication of the work it describes.
My Issue #3 audit flagged this tension and recommended pulling the teaser's "one information model" language into the full case. That hasn't happened. The gap has widened because the teaser's closing section now makes the system argument better than the full case does.
1. Single Strategic Premise
The hero headline is "points aren't enough," grounded in the observation that this product involves "someone's face." The hero intro says you redesigned both surfaces while defining the connecting strategy. The approach section says "Two tracks. Six design decisions" and frames the consumer app as giving members no reason to return and the provider portal as giving practices no reason to engage.
What's missing: a thesis connecting the two tracks before they diverge. The hero implies connection. The approach splits into Track A and Track B without naming the shared design logic first.
Your teaser's closing does the work the full case never does:
"Two surfaces. One loyalty system. Both live. The same loyalty logic runs both surfaces from one information model. Not 2 products sharing a brand."
That's an architectural claim. The full case closes with a softer line about the program being "built for the channel" and the redesign being "for the relationship." True. Also a tagline, not a thesis.
A CPO scanning the first three screens cannot find the system claim. A CPO who reads both tracks might infer it. Inference is the reader's job when they're reading a novel. It is not the reader's job when they're evaluating you at 10 PM the night before a panel sync.
2. Decision Rationale Depth
The A·01 through B·03 format is the case's best structural asset. Each block names a problem, shows a before state, presents a solution. A·01 explains why milestone architecture replaces a points number. A·02 names four decision anchors and explains why intent-first navigation replaces a product directory. B·01 argues that sort order is a design decision. B·03 explains why reactivation emails should come from the practice, not from Allergan.
The blocks show what changed and why the change matters. They almost never show what else was on the table.
A·01 doesn't say: we considered gamification, we considered a simple countdown, we chose milestone architecture because of X. B·01 doesn't say: we tested recency sort, we tested tier sort, we defaulted to expiry-soonest because the data showed Y.
The format promises rationale. It delivers justification. Justification explains why the chosen solution works. Rationale explains why you chose it over the other solutions that also could have worked. One proves competence. The other proves judgment.
The design explorations (Allē Noir, Prism, Veranda for consumer; Analytics, Daylight, Ember, Canvas for provider) are the closest the case gets to showing alternatives considered. But they're presented as visual explorations, not as decision forks that were evaluated and resolved. A hiring panel looking for judgment evidence needs to see the fork, the weighing, and the kill. Showing what you imagined is different from showing what you weighed and discarded.
The half that's there is strong. The missing half is what proves you chose, not just designed.
3. IC + Manager Proof
The hero brief lists Product Design Director, a team of 3 product designers plus UX research and brand. The decision blocks use first-person-plural or passive voice. B·03 describes a campaign builder where "providers approve and send rather than write from scratch," a system-design decision that implies cross-functional coordination.
That's everything. That is every piece of leadership evidence on this page.
No mention of how the team was structured across the two tracks. No mention of how you managed the tension between consumer and provider priorities when they competed for the same week. No mention of stakeholder dynamics at Allergan, a pharmaceutical company where design decisions touch marketing, medical affairs, legal, and compliance simultaneously. No mention of whether you inherited the dual-track mandate or argued for that scope.
The case reads as the work of a very strong IC who happened to hold a director title. For Director-level roles, this is the single largest gap. The design work is visible. The design leadership is invisible.
Two paragraphs fix this. Name the team structure across tracks. Name one stakeholder tension and how you resolved it. Name whether you inherited or built the dual-surface scope. That's the distance between a buyer seeing "she can do the work" and "she can run the function."
4. Loyalty Logic Unity
The approach section pairs the two tracks and says each required three decisions "to unlock the relationship." The reactivation-moments section (Expiry Warning, Reward Unlocked, Referral Converted, Seasonal Moment) implicitly connects both surfaces because expiry and reactivation touch both the member and the practice. B·01's default sort by expiring-points-soonest mirrors A·01's expiry-alert redesign. B·03's provider campaign builder uses the same reactivation triggers that A·01 surfaces to the consumer.
The connecting tissue exists in the design. It does not exist in the writing.
A reader who notices that A·01's expiry alert and B·01's expiry sort are two views of the same data event is doing analytical work the case should have already done for them. The case never says: the same loyalty event (points expiring, tier proximity, treatment timing) generates a consumer-facing notification and a provider-facing action surface, and that symmetry is the design.
The teaser handles this. Its midpoint section pairs "the patient sees" with "the practice sees." Its closing names "one information model." The full case never uses that phrase.
Unified in the work. Fragmented in the writing. A buyer who scans will see two projects. Buyers at this level scan.
5. Outcome Attribution
Strongest criterion.
A·01 ties the expiry-alert redesign to a 47% open rate on push notifications and reports that 68% of reactivating members named the notification as the reason they returned. A·02 ties in-app care planning to 2.4× the conversion rate of front-desk enrollment and CAC dropping from $92 to $42. The hero repeats 3.2× redemption, 47% reactivation, and $42 CAC.
A buyer scanning this page can trace CAC reduction to A·02 and reactivation trigger effectiveness to A·01. They cannot trace any headline metric to a provider-track decision. The 47% reactivation number appears in the hero but is never tied to B·01's expiry-based default sort or B·03's provider-voiced campaign builder. The 3.2× redemption number sits in the hero as an aggregate outcome, unattributed.
This makes Track B read as a nice addition rather than a co-equal driver. If the provider-side mechanics contributed to reactivation, say so and name how you measured it. If you can't attribute cleanly, frame reactivation as the system-level outcome of both surfaces working together. Either framing beats leaving the number floating above Track B with no connection to it.
One more problem. The member count is internally inconsistent.
| Source | Count | Context |
|---|---|---|
| Hero section | 30M+ | No date or definition given |
| Problem section | 18M | "at relaunch" |
| Allē Help Center (current) | 7M+ | Current active members |
These may represent different populations (cumulative enrollments vs. active members at relaunch vs. current active). The case doesn't specify. A reader who checks the Help Center will see a number that contradicts both figures on your page. Pick one. Date-stamp it. Name what it measures. Use it consistently.
6. Regulated / Healthcare-Adjacent Framing
The case uses the words pharmaceutical, medical aesthetics, treatment history, provider, practice, injector, patient panel. It names BOTOX, Juvéderm, and Latisse. It describes a referral program and a provider campaign builder that sends reactivation messages under the practice's name.
It never acknowledges that these words carry regulatory weight.
BOTOX Cosmetic is a prescription product with a boxed warning. Dermal fillers are FDA-regulated medical devices. Provider messaging about treatments touches prescription-drug advertising rules. A loyalty program tying rewards to treatment visits operates adjacent to anti-kickback considerations. A campaign builder letting providers message patients using treatment history raises HIPAA-adjacent questions. California law restricts discount and referral incentives by licensed practitioners.
The case treats Allē as a consumer loyalty platform that happens to involve aesthetic treatments. It is a loyalty platform operating in a healthcare-adjacent regulatory environment where what you can show a consumer, what a provider can say in outreach, what data you can use to trigger a message, and how you structure referral incentives are all constrained by forces outside the design team's preferences.
Those constraints make the design decisions harder and more impressive. A·03's before/after photo comparison isn't just a retention feature; it had to be designed within clinical-evidence norms. B·03's campaign builder isn't just a messaging tool; the provider sends the message in part because prescription-product marketing, HIPAA constraints, and state referral-incentive rules all create pressure for the practice, not the pharmaceutical company, to own the patient relationship in outreach. The case presents these as product-design choices. They are also compliance-informed choices, and naming the compliance dimension is what separates a loyalty redesign from a loyalty redesign under constraint. The constrained version is rarer. It's yours. Say so.
My earlier audit recommended adding regulated-constraint language to A·03, B·03, and the design explorations. That recommendation stands. The constraint story is real, differentiating, and currently invisible.
The Verdict
The answer to the central question: this case presents two strong projects, not one system. The system exists in the design. It does not exist in the narrative. Every recommendation below is aimed at closing that gap. The work deserves the framing. Give it the framing.
Prioritized Recommendations
P0. Fix the gating vulnerability. (Structural.) The full case ships 254K of HTML before authentication. Two weeks since first documented. Fix server-side delivery or accept that this content is public. Do not leave a client-side gate on content that argues for trust in consequential systems.
P1. Add a strategic-premise section before the tracks diverge. (Structural: new section between hero and approach.) Right now the hero implies connection and the approach splits into tracks without naming the shared logic. Add 3–4 sentences: one information model, two role-specific views, the same loyalty event generating a consumer notification and a provider action surface. This single addition converts "two projects" into "one system" in a buyer's read.
P1. Add leadership narrative. (Structural: new paragraphs in the approach or a dedicated section.) The case names title and team size in the hero brief and says nothing else about leadership. Name the team structure across tracks. Name one stakeholder tension and how you resolved it. Name whether you inherited or built the dual-surface scope. Two paragraphs. IC-only read becomes IC+manager read.
P2. Attribute at least one headline metric to a provider-track decision. (Copy-level: add attribution language to B·01 or B·03.) The 47% reactivation number appears in the hero but connects to nothing in Track B. If B·03's campaign builder or B·01's expiry-based sort contributed, say so. If attribution is unclear, frame reactivation as the system-level outcome of both surfaces working together. Either framing beats leaving the number unattached.
P2. Add "why this over the alternatives" to at least two decision blocks. (Copy-level: one sentence per block.) A·01 and B·01 are the strongest candidates. The design explorations (Noir, Prism, Veranda, etc.) could serve this purpose if repositioned as evaluated alternatives rather than visual explorations. One sentence per block: "We considered X; we chose Y because Z." Justification becomes judgment evidence.
P2. Add regulated-context framing to A·03, B·03, and the design explorations. (Copy-level: add constraint language to existing sections.) Name the constraints. A·03: before/after imagery in a clinical context carries requirements a consumer app doesn't. B·03: the provider sends the message in part because prescription-product marketing, HIPAA constraints, and state referral-incentive rules create pressure for the practice to own the patient relationship in outreach. You don't need a compliance brief. You need the constraint named so a buyer understands the difficulty.
P3. Fix the metadata gap. (Copy-level.) The full case needs a <title> and meta description matching or exceeding the teaser's. "Allē · Juno Chen" communicates nothing in a link preview.
P3. Reconcile the member count. (Copy-level.) 30M+ in the hero, 18M in the problem section, 7M on Allē's current Help Center. Pick a number. Date-stamp it. Name what it measures. Use it consistently.
P3. Fix the date and case-number discrepancies. (Copy-level.) URL says cs-06; page says Case Study 05. Full case says 2020; teaser says 2021. Small inconsistencies that accumulate into a trust signal for a reader evaluating attention to detail in a case about attention to detail.
P3. Move the teaser's closing language into the full case's closing. (Structural: replace or expand the current one-line closing.) The full case ends with one line about channel versus relationship. The teaser ends with a paragraph that names the system, ties mechanics to metrics, lands the dual-surface thesis. The full case should close at least as strongly as the teaser does.
- Multi-sided loyalty parallels: Maven Clinic's VP of Design role asks for design leadership across member, employer, and health-plan surfaces with AI-native workflows and conversational interfaces, making the Allē dual-surface system argument directly transferable if the regulated-constraint framing is added.
- Provider workflow as proof: Headway's Design Director posting owns provider EHR experience across scheduling, documentation, and billing, and explicitly asks designers to reimagine provider workflows with AI at the center, which means the Allē provider track becomes stronger outreach evidence once B·01–B·03 carry outcome attribution.
- Constraint-forward positioning in market: Gusto's published AI principles argue that AI decisions should start with whether a business owner running payroll actually needs the intervention, reinforcing that regulated-context framing is now a competitive differentiator, not a footnote, across healthcare-adjacent and finance-adjacent roles.
- Teaser metadata as template: Alibaba's teaser now carries mandate-forward metadata naming Head of Design & Research, 32 interviews, and outcome metrics in the title and description tags, which sets the standard the Allē full-case metadata should match once the P3 fix lands.

