Two changes since the last version. One adds a dial. One takes back a claim. The retraction goes first, because if anything leaves your outbox this week you need it before you need any of the rest.
Fastest routing cue, if you showed up with one posting and forty minutes: find the word family that dominates the responsibilities section.
| Dominant vocabulary | Tier |
|---|---|
| Research, prototype, model | 1 — Frontier AI / Intelligence Layer |
| Deployment, customer, implementation | 2 — AI-Native Agent Platforms |
| Clinician, patient, provider, compliance | 3 — Clinical / Regulated AI |
| Platform, segment, roadmap | 4 — Enterprise Platform |
| Maturity, transformation, elevate | 5 — Enterprise Design Org Transformation |
Stop claiming the learning loop
The plan for this revision was to run Tiers 1 and 2 through the control record: a persistent, inspectable account of what an automated agent did, what evidence it produced, and what a human decided about it. Not a log for engineers. A record an operator reads, annotates, and signs. You made that argument in the Trust essay before you had any way to build it, which is worth more than you're currently treating it as. Link the essay in these letters. It's the one substantial thing in your file that isn't sitting behind a case gate, and it puts the idea in your name rather than in a demo's.
The version I meant to hand you came in two halves. First half: the record captures one run in enough detail that a person can approve or reject it with reasons. Second half: those reasons come back around, and run two behaves differently.
I went to verify the second half against the public build. It isn't there.
What Carrier IQ publicly supports, at full craft detail, is a single-run control record:
- The quote arrives attached to the run that produced it: session, navigate, fill, extract, verify
- Coverage deltas measured against what was actually requested
- Carrier trust signals, including AM Best rating, years in market, JD Power score, NAIC complaint ratio
- A verification session that can be re-run
- An operator note
- A bind action that stamps approved provider, approval time, note, and verification session ID into the record permanently
What it does not support:
- Any control to mark an extracted quote wrong
- Visible re-weighting after that correction
- An observably different second run
Start a fresh quote and the notes and verification state reset. Nothing carries forward.
So the lead gets rebuilt. Describe Carrier IQ as a single-run control record, in mechanism detail, because that description survives interrogation. Put the compounding half where it actually lives: TinyFish, in the bridge sentence, as current practice, no number attached, no result claimed.
A sentence like "the system learns from operator corrections" sails clean through a cover letter and dies in minute forty of a portfolio review, when somebody asks to see the second run. The claim buys the meeting and then spends it.
Metrics you cannot use outbound
The same verification pass turns up a second problem. If a recipient follows your public link and can't find the number, the number is a liability. Gate-only, therefore out of outbound copy:
- Equinox+'s launch star rating
- Red Cross's FEMA compliance percentage and caseworker count
- Alibaba's sign-up rate and search-completion lifts
- Allē's enrolled-member total, which also conflicts with the hero figure
The public teaser says "$20M margin opportunity." The gated write-up says margin recovered annually. Use the teaser wording. The stronger phrasing draws a challenge, and you'd be defending a gap you didn't create.
Altitude is the second dial
Tier tells you which case to reach for. Altitude tells you where to cut it.
Craft altitude is the design decision itself. The interaction pattern. What moved between iteration two and iteration three, and why.
System altitude is the mechanism across functions. Where design touched engineering and data. What kept working past the first instance without a person holding it together.
Leadership altitude is the organizational problem you diagnosed and the mandate you built to solve it. Who had to agree to something before a single screen could exist.
Same facts, three arguments. Right tier and wrong altitude produces a letter that is accurate and inert: everything in it true, none of it answering the question the reader is holding.
Read altitude off the posting's absences, not its title. A Head of Design posting that never says hire, headcount, or grow the team is an elevated IC role wearing a leadership label, and leadership altitude will read there as someone angling away from the work. A posting that names your direct reports and their seniority will find craft detail small.
Thermo Fisher at all three altitudes
Every figure below is on the public teaser.
Craft. The finding that set the design: an exception caught late costs three to five times what the same exception costs a week earlier. So the interface had to make one week visible.
"The planning surface didn't rank exceptions by size. It ranked them by how much the cost would grow before the next planning cycle, so a small exception with a steep curve outranked a large stable one. Forecast accuracy came in at 97.4%. The design bet was that if you show a planner the week they're about to lose, they act inside it."
System. Same project, wider aperture.
"I ran 32 interviews across six partner companies and nine sites. The output wasn't a requirements list, it was five distinct failure modes, and each became a module with its own data contract rather than a column in one shared dashboard. That's why the platform went from zero to live in twelve months across EU, NA and AU instead of stalling while six companies negotiated a single schema. One capacity intervention the system surfaced was associated with $2M recovered."
Leadership. The problem underneath was never software.
"Six pharmaceutical manufacturers, several of them direct competitors, and no shared authority compelling any of them to reveal capacity. The first design work wasn't screens. It was establishing what each partner could withhold and still participate, because none of them would share capacity into a shared schema. That boundary became the product architecture. 100% partner adoption. $20M margin opportunity, 83% IRR."
Nothing moved except the unit of analysis: the interaction, the mechanism, the mandate. That's the entire technique.
Tier 1 — Frontier AI / Intelligence Layer
Altitude default: craft, one system beat.
Posting cue. Design engineering, prototyping in code, "works directly with researchers." No hiring language means elevated IC. If a design manager appears as a peer rather than a report, add the system beat and stop there.
Hook. Written against Perplexity's Brain surface, shipped July 13. Swap in ChatGPT Work's approval model or Claude Tag's channel-scoped authority as the target requires.
"Brain made cross-run memory inspectable: every memory traces to the session or file it came from, and Customize lets a person remove what shouldn't have persisted. That's the surface most agent teams postpone, because building it forces a decision about what a user is entitled to know about what the system learned from them. I wrote about that entitlement problem before I had a way to build it, and I've spent the last several years since on that layer — most recently as a working control record for insurance quote automation."
Proof block, craft altitude (Carrier IQ, live; Alibaba public teaser).
"In Carrier IQ, a functional prototype running against live carrier APIs, a quote never arrives as a number. It arrives with its run: the navigate, fill, extract and verify steps; the coverage deltas against what the broker actually requested; the carrier's AM Best rating and NAIC complaint ratio; and a verification session the broker can re-run before binding. The note and approval timestamp attach to the bind permanently. The record is the deliverable and the quote is a field inside it. That pattern came out of Alibaba's supplier surface, where 73% of sessions ended without engagement and buyers abandoning at payment were abandoning over trust rather than price. We moved verification evidence out of the profile page and into the decision path itself, which meant restructuring what the search and listing systems had to carry. Security concerns fell 47%, transactions rose 20%."
Bridge.
"At TinyFish I'm building web agents in production, and the habit that's carried over is reading LangSmith traces before touching prompts: find the step where the human stopped trusting the run, then change the interface there. That's the loop I want to be inside full-time, which is why I'm writing to you rather than to a platform team."
Ask.
"Thirty minutes with whoever owns Customize, ideally before the next iteration ships. One question in particular: when someone deletes a memory, what do they need to see about what else changes?"
Overreach note. Never imply Carrier IQ improves from corrections. Describe the single run. Asked what happens on run two, answer with TinyFish and label it as current practice, not shipped result.
Tier 2 — AI-Native Agent Platforms
Altitude default: system.
Posting cue. Deployment, forward-deployed engineering, customer implementation, solutions. When that vocabulary is present and brand or marketing-site work is absent, the buyer's live worry is the distance between a demo and a fifth customer. Craft altitude underreads badly here.
Hook. Sentence one is fixed. Sentence two is a slot you fill from whatever the target shipped in the last sixty days.
"Every agent platform I've watched hits the same wall between the pilot and the fifth deployment: the thing that made the first one trustworthy was a person, and people don't multi-tenant. [Your recent Series X / GA launch / enterprise tier] puts that wall in front of you on a schedule now rather than eventually. I've built the surface that replaces the person twice — once for six organizations that had no reason to trust each other."
Proof block, system altitude (Carrier IQ, live; Thermo Fisher public teaser).
"Carrier IQ is a functional prototype running against live carrier APIs, and I built its evidence chain so the trust artifact travels with the transaction instead of living in the operator's head: requested coverage, carrier activity, trace, extracted quote, coverage delta, verification evidence, operator rationale, bind. That structure is portable precisely because none of it depends on who is reviewing. The harder version was Thermo Fisher, where the surface had to be adopted by six independent manufacturers with different data maturity, different regulators, and no reason to trust each other's numbers. Zero to live in twelve months across nine sites. All six adopted it."
Bridge.
"At TinyFish I'm working on agents running against live web surfaces, where the failure modes are genuinely ugly and the design question is always which failure the human needs to see. That's the problem I'd rather solve at platform scale than one deployment at a time."
Ask.
"Worth a conversation about your fifth deployment rather than your first, and worth having it while the implementation patterns are still soft: what is that team doing by hand right now that the product should be doing?"
Overreach note. You have not run a multi-tenant agent platform. What you did is design a shared surface that six organizations with conflicting incentives adopted, which is the harder claim and defensible line by line. Label the prototype every single time you name it. This buyer will ask.
Tier 3 — Clinical / Regulated AI
New tier, and narrower than "regulated." The boundary: AI where a licensed professional signs, or where a delay costs someone something irreversible.
Altitude default: system. The leadership beat is held back for the ask, deliberately. See below.
Posting cue. Check whether the clinician appears in the posting at all. If only the patient does, the AI is a consumer feature and the design function sits a long way from the decision moment. Downgrade the company. Don't adjust the letter.
Hook. Written against a role like Maven Clinic's VP of Design, which reports to the CPO with a direct line to the CEO.
"The hard part of clinical AI isn't the recommendation. It's the few seconds a clinician has to decide whether to accept it. A role that reports to the CPO with a line to the CEO is a role with enough authority to design those few seconds properly, which is where almost all of my work lives: what evidence is present, in what order, and what the interface does when the human disagrees."
Proof block, system altitude (Red Cross public teaser; Thermo Fisher public teaser).
"For the American Red Cross I designed disaster casework that replaced six legacy systems with one, under 10x surge conditions where a caseworker does not get to wait for the right screen to load. The mechanism was a single case record rendered as three role-specific views, so a caseworker, a supervisor and a finance approver saw the same facts at different resolutions without anyone maintaining three sources of truth. $847K disbursed and 1,689 cases in the first two weeks of a national deployment. The regulated-operations version of that problem was Thermo Fisher: six pharmaceutical manufacturers across EU, NA and AU, each answering to a different regulator and each at a different level of data maturity. A shared schema was never going to be signed. So the five failure modes I found in 32 interviews became five modules with separate data contracts, and the interface was built to accept partial, inconsistent, differently-governed input rather than to reject it. Twelve months from zero to live. 100% partner adoption."
Bridge.
"I'm at TinyFish now building production web agents, which keeps me current on how these systems actually fail rather than how they get described in a deck. Watching automated output arrive in front of a person with no signature attached is what pushed me back toward domains where somebody has to sign."
Ask.
"The leadership question I'd want to ask is one you can only answer in a conversation, and it's more useful now than after the slate closes: which clinical decision does the CPO own today that they would rather design owned? Thirty minutes whenever it suits."
Overreach note. Don't claim HIPAA or FDA experience you don't have. Red Cross is life-safety operations under surge, not clinical care. Thermo Fisher is regulated life-sciences operations, not a submission. Name each one as exactly what it is and let the mechanism do the work the credential would have done.
Tier 4 — Enterprise Platform
Vanta, Amplitude, TRM Labs, Gusto. Four altitudes inside one tier, so the posting cue carries more weight here than anywhere else on this list.
Posting cue. Read the headcount number against the reporting line. Together. Never separately.
| Company | What the posting states | Altitude read |
|---|---|---|
| TRM Labs | Five product designers reporting into the VP of Product | System — player-coach |
| Vanta | Roughly forty people including experienced design directors | Leadership |
| Amplitude | Fifteen, then repeated hands-on expectations | Lead system, close leadership |
| Gusto | Three designers inside an organization of eighty-plus | System — and your live question is who owns the craft bar above you |
Hook.
"Enterprise platforms rarely lose on craft. They lose on the segment nobody in the room can see, because the analytics only measure the surface the company already believes in. [Your recent launch / new segment / pricing change] is the kind of move that usually surfaces one of those blind spots. I've made that argument once with money attached, on a marketplace where the starved segment carried 80% of transaction value."
Proof block, leadership altitude (Alibaba public teaser).
"On Alibaba's B2B marketplace, $50B+ GMV across 200K+ suppliers, desktop was treated as a maintenance surface. The argument that changed the roadmap was this: that segment carried 25% of traffic and 80% of transaction value, and it was being starved because traffic was the metric everyone reported upward. Reframing the investment case around transaction value is what unlocked the work. It shipped to +7% DAU, +20% transactions, +2.2 points of NPS."
Bridge.
"At TinyFish I'm building agent products in production, which is mostly a running lesson in how fast an enterprise surface has to change once the underlying capability does. I'd rather be inside a platform business while that happens than adjacent to one."
Ask.
"One conversation before the formal process, about which segment your current analytics can't see. That's the argument I'd want to test before I made it."
Overreach note. Alibaba does not stretch into a headcount claim, so don't stretch it. Lead with owned scope and the segment argument you won. Where the posting explicitly demands org-building proof, lead instead with owned team scope at Equinox+ and the cross-company mandate at Thermo Fisher, and say plainly that headcount growth isn't what either case documents.
Tier 5 — Enterprise Design Org Transformation
Altitude default: leadership. Keep the Carrier IQ bind record in reserve as your craft artifact. A leadership-altitude letter generates exactly one objection, does she still design, and that record closes it in two sentences.
Posting cue. Count cross-functional collaboration. Three or more appearances and design has no seat today; the company is hoping a hire will win one on its behalf. Then look for hire and grow the team. Missing from a director-or-above posting, the title is decorative and the job is management authority over what is really an IC's scope.
Hook.
"Most design transformation briefs describe a craft problem. Nearly all of them are mandate problems underneath: the function is asked to raise quality without being handed the decision that would let it. [Your new CPO / recent reorg / acquisition] is the moment that question usually gets settled, one way or the other, in the first two quarters."
Proof block, leadership altitude (Equinox+ public teaser).
"I led the Equinox+ design team through its first release and set how it worked: four designers and one researcher, five brands with genuinely competing interests, four partner functions in product, engineering, brand and data, and a membership of 600K+ across 200+ clubs waiting on it. Seventy-five hours of research produced four member archetypes and five architecture decisions, and those decisions are what let a five-person team hold a coherent bar across five brands instead of arbitrating every screen. Zero to MVP in three months. The Thermo Fisher work described above is the same boundary problem at a slower clock and higher stakes, where what six competitors would and wouldn't disclose became the architecture."
Bridge.
"I'm building production agent products at TinyFish, which is the reason I'm looking at transformation roles rather than steady-state ones: the capability curve is going to force these org questions open whether or not anyone schedules them, and I'd rather be the person who scheduled them."
Ask.
"One conversation before any formal process, and preferably early in the new structure rather than after it hardens: what would the first ninety days need to produce for you to consider the hire correct? That answer usually reveals whether the mandate exists yet."
Overreach note. Promise nothing about fixing the organization. Name the one function you'd stand up in ninety days, then say you'd want to see the roadmap before committing to a second.
When two tiers both fit
They will, often. A clinical AI company with forty designers is Tier 3 and Tier 5 at the same time. Break the tie on decision rights, not company category: whichever tier sits closer to the moment a human accepts, overrides, or reverses machine action takes your lead. Send Tier 3. Hold Tier 5 for the second conversation, when somebody asks what you'd change about the org.
Before you send
Three checks, in this order.
- Every number lands on a public page the recipient can reach from the link you sent.
- The altitude matches what the posting's absences tell you, not what its title claims.
- You can defend the mechanism you described through four follow-up questions. Not one.
Check three is what killed the run-over-run claim. It would have cleared the letter and collapsed in the room, and no order is worse than that one.
-
Autonomy and oversight move together: Anthropic's finding that auto-approval rose from roughly 20% among newer users to more than 40% among experienced ones — while those same experienced users interrupted agents more often — breaks the tidy Watch → Verify → Delegate ladder, and the autonomy measurement work is worth reading before any Tier 1 or Tier 2 interview where you plan to use the ladder as shorthand.
-
The most explicit posting on the board: Altana's Head of Product Design listing describes the design system as a structured, semantic, machine-readable language that product managers, engineers and agents compose, and it names reasoning surfaces, citations, uncertainty, interruption, consent, human-review queues and graceful failure in one paragraph — treat it as a free glossary of what this buyer segment now evaluates for, even if you never apply.
-
What "done" means for a probabilistic product: Figma's evaluation practice for Make — one-to-four design and functionality scoring, a corpus of roughly 1,000 examples, golden prompts, nightly model comparisons, and a mix of deterministic tests and human judgment — is documented in detail by First Round and is the closest thing available to a shared vocabulary for the release-gate question Amplitude and Spring Health are both asking.
-
One metadata fix still outstanding: the Equinox+ teaser still ships under the generic page title "Equinox+ · Teaser · Juno Chen," which means the five-brand, three-month MVP story is absent from anything a recruiter sees in a search result or a link preview — the cheapest unclosed gap on the site.

