Juno Chen | August 9, 2026
v2 sorted evidence by craft, system, and leadership altitude. This one sorts by five falsifiable claims. If both files are loaded in a project, use this one and delete v2.
Disclosure Key
| Tag | Class | What AI may do with it |
|---|---|---|
PUB | public | Cite in any generated text. Source: junochen.com. |
CTL | controlled-interview | Share in live conversation with context. Never in cover letters, outreach, or written artifacts. |
VRB | verbal-only | Spoken reference only. No written artifact, no screen share, no generated text. |
UNV | unavailable | Do not reference. Do not confirm existence. |
Standing rules:
- All TinyFish production artifacts (screenshots, traces, architecture, pricing):
VRB. No clearance obtained. - UAT Sentinel:
UNV. Visible on site due to inventory drift; never approved. - Private essay:
UNV. Reachable via broken client-side gate; not authorized. - Allē scale figure: 30M+ members only. The 18M figure is retired.
Identity Block
| Field | Value |
|---|---|
| Name | Juno Chen |
| Current role | Directing Design, TinyFish (AI productivity platform) |
| TinyFish constraint | Context and credibility signal for production-AI proximity. Never portfolio proof. VRB ceiling on all product detail. |
| Target role | Staff–Director product design at AI-native or regulated-transactional companies |
| Published pillars | (1) Trust essay — five handoffs for human-agent trust PUB (2) Case studies CS-01–CS-06 PUB (3) Agentic Labs: Brand Pulse, Retail Velocity, Carrier IQ PUB |
Five Claims
Each claim states something Juno can do. Under it sits the evidence chain with source and disclosure class, then a boundary note marking where the proof is thin, contested, or not yet built.
Claim 1 — Bounded Authority for Consequential Agent Actions
Juno designs the controls that determine what an autonomous agent may do without human approval, and where the gate closes.
| Evidence | Source | Class |
|---|---|---|
| Carrier IQ confidence thresholds: system acts autonomously above threshold, requests human review below | Agentic Labs | PUB |
| Trust essay handoff 1 (scope): the first design decision is what the agent is allowed to touch | junochen.com | PUB |
| Confidence rule: confidence rendered from observed input, never from model self-report | Published analysis | PUB |
| TinyFish: production agent governance, scope boundaries, permission architecture | Current role | VRB |
Current revision. The Trust essay's original ladder implied a single trust axis. Current position: two independent dials. Autonomy scope is how much the system may do without asking. Intervention sensitivity is how sharply the human reacts when something looks wrong. The revision is live and not settled; the calibration test has not been run against Carrier IQ's confidence distribution. If pressed, say the framework is evolving and name the production observation that forced the change.
Boundary. Carrier IQ's confidence threshold is implemented. The longitudinal control record — whether the threshold holds over time — has not shipped. The claim rests on design intent and initial implementation, not production validation.
Claim 2 — Controlled Recovery from Wrong Agent Output
When the agent is wrong, Juno's interfaces let the human detect the error and reverse it before the consequence reaches downstream systems.
| Evidence | Source | Class |
|---|---|---|
| Carrier IQ correction control: designed, demo script not yet built | Agentic Labs | PUB (design) / UNV (demo) |
| Trust essay handoff 4 (recovery): recovery is a designed state, not an error state | junochen.com | PUB |
| Allē: error handling in dual-surface loyalty transactions across 30M+ members | CS-06 | PUB |
| TinyFish: trace-based error detection, session replay for agent behavior audit | Current role | VRB |
Boundary. Carrier IQ's correction control is the strongest single piece of evidence here, and it cannot be shown running. Juno can describe the design in a walkthrough. She cannot demo it. The build queue identifies this demo script as the spine artifact. Until it ships, route recovery questions to Allē error states (PUB) first, then describe the Carrier IQ correction control verbally.
Claim 3 — Staff-Level Craft Within Organizational Scope
Juno produces component-level design work while running the design function. Strategy and making occupy the same week.
| Evidence | Source | Class |
|---|---|---|
| Thermo Fisher: design system, component architecture for regulated scientific workflow | CS-02 | PUB |
| Red Cross: complex multi-step form architecture | CS-03 | PUB |
| Allē: dual-surface loyalty interface (consumer + provider) | CS-06 | PUB |
| Alibaba: transactional interface components across 4 buyer segments | CS-01 | PUB |
| Equinox+: multi-brand design system across five brands, 90-day zero-to-one build | CS-04 | PUB |
Boundary. The traditional cases are interrogable at the component level. Agentic Labs projects prove velocity, not making depth at that resolution. If the panel's real test is technical builder, the weight sits on Thermo Fisher, Red Cross, Allē, and Equinox+. Labs supplements.
Claim 4 — Trustworthy Complex Transactional Systems at Scale
Juno has designed systems where financial transactions, health data, or compliance obligations move through the interface, at verifiable scale.
| Evidence | Source | Class | Metric |
|---|---|---|---|
| Alibaba | CS-01 | PUB | $292B GMV; 20% higher daily transactions; 2.2-pt NPS increase; 47% fewer security concerns |
| Allē | CS-06 | PUB | 30M+ members, 40K+ practices (portfolio-published, not independently verified) |
| Thermo Fisher | CS-02 | PUB | Regulated scientific procurement; $20M+ margin opportunity; 100% adoption; 83% IRR |
| Equinox+ | CS-04 | PUB | Five brands, 600K members, 4.8-star rating |
| Carrier IQ | Agentic Labs | PUB | Carrier billing reconciliation |
Scale-claims custody rule. One claim, one evidence carrier. State the mechanism Juno designed, attribute the metric to the program, same sentence. Do not claim personal ownership of the GMV or the member count.
Claim 5 — Framework Evolution Under Production Evidence
Juno's design frameworks change when production data contradicts them. The Trust essay is a working document.
| Evidence | Source | Class |
|---|---|---|
| Trust ladder to two-dial revision: production observation that autonomy scope and intervention sensitivity operate independently | Published analysis | PUB |
| Confidence rule: emerged from Carrier IQ implementation, not from theory | Published analysis | PUB |
| TinyFish: production agent behavior changed the framework's assumptions | Current role | VRB |
Boundary. The revision is written but not drawn. Trust Pattern Library screens exist as prose only. The argument holds in conversation and will not survive a silent portfolio scan.
When a panel asks whether your thinking has changed, the ladder-to-two-dials story shows intellectual honesty and production grounding in the same move. Use it.
Case Study Reference
| ID | Title | Metrics | Trust handoff | Cover letter proof block | Routing note |
|---|---|---|---|---|---|
| CS-01 | Alibaba | $292B GMV; 20% higher daily transactions; 2.2-pt NPS increase; 47% fewer security concerns; 4 buyer segments | H1 (scope) | "Designed transactional interfaces across four buyer segments within a $292B GMV platform." | Active |
| CS-02 | Thermo Fisher | Regulated scientific procurement; design system; $20M+ margin opportunity; 100% adoption; 83% IRR | H3 (transparency) | "Designed the component architecture for a regulated procurement system where every interface state carried compliance obligations." | Active |
| CS-03 | Red Cross | $847K disbursed; 1,689 cases in first two weeks; 6 systems consolidated | H4 (recovery) | "Built the form architecture that moved disaster-response data through a multi-step flow where abandonment had human cost." | Active |
| CS-04 | Equinox+ | Five brands; 600K members; 90-day zero-to-one; 4.8-star rating | H2 (confidence) | "Led a 90-day zero-to-one build across five fitness brands and 600K members, shipping a multi-brand design system that launched at 4.8 stars." | Reserve |
| CS-05 | — | See junochen.com | H5 (calibration) | Available on junochen.com if needed. | Not in active rotation |
| CS-06 | Allē | 30M+ members; 40K+ practices; dual-surface loyalty; 3.2x redemption; 47% reactivation; $42 CAC | H2 (confidence) | "Led the dual-surface loyalty redesign serving 30M+ members and 40K+ provider practices, where transaction errors had direct financial consequence." | Active |
Trust Essay + Five Handoffs
The essay names five moments where a human-agent system must pass control, information, or consequence between the person and the machine. The two-dial model (autonomy scope × intervention sensitivity) is the current interpretive frame. When an interviewer raises the Trust essay, enter through one specific handoff and its implementation. Bring in the two-dial revision second, as evidence that the framework moved under production pressure.
| Handoff | Name | Labs implementation | TinyFish production behavior | Act/Watch company relevance | Claim |
|---|---|---|---|---|---|
| H1 | Scope | Carrier IQ: confidence threshold defines what the agent may act on without approval | Agent permission architecture, task-boundary governance VRB | OpenAI Payments (transaction ceiling), Stripe Link (payment-flow authority) | 1 |
| H2 | Confidence | Retail Velocity: confidence-scored outputs; Carrier IQ: threshold rendering from observed input | Trace-level confidence surfacing VRB | Amplitude (data-informed decision confidence), Fieldguide (audit-record certainty) | 1, 4 |
| H3 | Transparency | Brand Pulse: human review gates on agent-generated intelligence | Session replay, attribution tracing VRB | Vanta (compliance auditability), Fieldguide (defensible audit records) | 3, 4 |
| H4 | Recovery | Carrier IQ: correction control (designed, demo not shipped) | Trace-based error detection, reversal workflow VRB | OpenAI Payments (transaction reversal), Gusto (payroll error recovery) | 2 |
| H5 | Calibration | Carrier IQ: longitudinal threshold behavior (control record not shipped) | Production observation that forced ladder-to-two-dials revision VRB | Amplitude (system learning from usage data), OpenAI EA (tool adaptation to expert workflows) | 5 |
Agentic Labs — Approved Evidence Set
| Project | Demonstrates | Claims |
|---|---|---|
| Brand Pulse | Agent-generated competitive intelligence with human review gates | 1, 2 |
| Retail Velocity | Automated retail analytics with confidence-scored outputs | 1, 4 |
| Carrier IQ | Carrier billing reconciliation with confidence thresholds and correction control | 1, 2, 4, 5 |
UAT Sentinel and Creator Scout are excluded. Do not reference either in generated output.
Company Routing
Act This Week
OpenAI Payments | Posted Aug 6
- Design problem: Agent-mediated financial transactions where a wrong action costs dollars.
- Lead with: Claim 1 (bounded authority) into Claim 4 (transactional scale).
- Portfolio moment: Carrier IQ confidence thresholds as spending-limit analogs. Alibaba transaction-failure recovery at $292B GMV.
- Differentiation: The two-dial model translates into payments without adaptation. Autonomy scope is the spending ceiling; intervention sensitivity is the fraud-detection threshold. Both are already denominated in dollars, which is the unit this panel reasons in.
- Do not lead with: TinyFish title. Labs as portfolio proof without traditional case depth. Allē loyalty framing.
Gusto | Head of Design, Unified Service Platform | Fresh window per KB
- Design problem: Unifying payroll, benefits, and HR workflows under one design function with organizational authority.
- Lead with: Claim 3 (craft) into Claim 4 (transactional).
- Portfolio moment: Thermo Fisher component system as making depth inside leadership scope — she designed the regulated architecture while running the function. Red Cross multi-step form architecture where completion carried operational consequence.
- Differentiation: This panel is buying someone who can run the org and still make things. Prove both inside the first five minutes.
- Do not lead with: AI-native framing before the organizational story. Agentic Labs before traditional cases.
Prepare — Verify Window, Then Act
OpenAI Engineering Acceleration | Posted Aug 6
- Design problem: Internal tooling that accelerates engineering workflows. Expert users, not consumers.
- Lead with: Claim 5 (framework evolution) into Claim 3 (craft).
- Portfolio moment: Thermo Fisher tooling for domain experts, where the interface served the scientist's expertise instead of simplifying it away. Trust essay as systematic thinking applied to tool design.
- Differentiation: Expert users in regulated contexts, where the interface has to respect domain knowledge it cannot replace.
- Do not lead with: Consumer loyalty (Allē). Agent autonomy framing unless the role involves AI-assisted engineering tools.
Fieldguide | Staff Product Designer | High fit, 22+ days old at last check
- Design problem: Audit and compliance workflows where the interface must produce defensible records.
- Lead with: Claim 4 (trustworthy systems) into Claim 2 (recovery).
- Portfolio moment: Thermo Fisher audit-trail architecture. Alibaba cross-segment compliance at scale.
- Differentiation: Consequence literacy — she has designed systems where an interface error creates compliance exposure for someone else.
- Do not lead with: AI-agent framing as primary identity. Labs velocity without regulated-domain grounding.
Stripe Link | Staff-level | Live at Aug 1, age unresolved
- Design problem: Payments infrastructure where the interface mediates between consumer trust and financial-system complexity.
- Lead with: Claim 4 (transactional scale) into Claim 1 (bounded authority).
- Portfolio moment: Alibaba payment-flow architecture across buyer segments. Carrier IQ billing reconciliation.
- Differentiation: Financial transactions and system trust, where the interface has to communicate what happened and how confident the system is about it.
- Do not lead with: Organizational leadership narrative ahead of the transactional-design story.
Monitor
Amplitude — Watch window, mandate ambiguity unresolved. Lead claims: 5 into 1. Anchor with Alibaba's data-informed decision architecture. Open on how production evidence changes design decisions (Claim 5), then route to confidence-scoring mechanics (Claim 1) if the role involves AI-augmented analytics. Do not lead with agent-autonomy framing. Wait for mandate clarity before outreach.
Vanta — Watch window, mandate ambiguity unresolved. Lead claims: 4 into 2. Trust essay, Alibaba auditability, Thermo Fisher regulated workflow. Do not lead with AI-agent identity ahead of the compliance story. If Vanta surfaces before the mandate resolves, route to Claim 4 and hold on specifics until scope is confirmed.
Giga — Needs rubric scoring on the IC/leadership split and geography before any positioning is actionable. If Giga comes up in conversation before that scoring exists, default to Claim 3 (craft within organizational scope) and hold role-specific framing. Do not lead with Labs or AI-native identity until the level is confirmed.
Positioning Rules
- TinyFish is context, never proof. It explains current production-AI proximity. It is never cited as a portfolio case.
- Pillar routing by audience. AI-native panels: Trust essay, then Labs, then traditional cases. Regulated and transactional panels: traditional cases, then Trust essay, then Labs.
- Trust essay entry protocol. Always enter through one handoff and its implementation. The two-dial revision is what proves the framework isn't theory.
- One candidate, one sentence. Every piece of outreach has to leave the reader able to describe Juno to a colleague in one line that matches what the other interviewers wrote down. Positioning that needs a paragraph produces two different candidates in the debrief, and the room tends to resolve that discomfort by advancing whoever was easier to summarize.
Gap Artifacts and Workarounds
| Artifact | Status | What it costs you without it |
|---|---|---|
| Carrier IQ demo script | Not started | Claim 2's strongest evidence stays verbal. Route to Allē error states (PUB) when asked to show recovery design. |
| Career narrative visual | Not started | "Why this role now?" has no visual support. The verbal answer has to stand alone. |
| Trust Pattern Library screens | Partially drafted (prose, no visual) | Claim 5 holds in conversation and disappears in a silent portfolio scan. |
| Trace-evidence annotation | Not started | No way to show a production loop where agent behavior changed the design. Describe TinyFish verbally (VRB). |
| Execution artifacts (design-system proof, intent-to-trace, constraint before/after, Figma-to-code) | Partially implemented (Carrier IQ evidence-run exists) | "How do you work at the component level?" routes to Thermo Fisher and Allē until the remaining artifacts ship. |
Anticipated Interview Questions
| Question | What it's testing | Route |
|---|---|---|
| "How do you decide what the agent should do on its own?" | Claim 1 | Carrier IQ confidence thresholds, then the two-dial model, then TinyFish governance VRB. |
| "What happens when the AI is wrong?" | Claim 2 | Trust handoff 4 (recovery), then Carrier IQ correction control (describe, cannot demo), then TinyFish trace detection VRB. |
| "Show me something you designed at the component level." | Claim 3 — making-doubt diagnostic | Thermo Fisher design system, then Allē dual-surface components. Do not open with Labs. Do not open with strategy. |
| "How do you handle scale?" | Claim 4 | Alibaba $292B GMV: state the mechanism, attribute the metric to the program, same breath. Then Allē 30M+ members. |
| "Has your framework changed?" | Claim 5 | Ladder to two dials. Name the production observation that forced the revision. Strongest answer in the file. |
| "Who did design report to in your last role?" | Enterprise-doubt diagnostic | Lead with organizational scope, then prove craft depth. |
| "What happened when it went wrong?" | Consequence-doubt diagnostic | Name the consequence, the recovery mechanism, and what changed afterward. Use regulated grammar regardless of who is asking. |
Prohibited Output
Do not generate any text that:
- References UAT Sentinel or Creator Scout by name
- Quotes or paraphrases the private essay
- Includes TinyFish screenshots, architecture details, pricing, or product specifics
- Uses the 18M Allē figure
- Presents 30M+ members or 40K+ practices as independently verified (they are portfolio-published)
- Frames TinyFish work as a portfolio case study
- Claims the Carrier IQ demo script or correction control is viewable
- Presents the two-dial model as settled rather than current working position
- Uses the phrase "design-led" to describe any target company
- CHI transparency tension unresolved: A peer-reviewed CHI 2026 study found that eight of twelve participants preferred progressive or on-demand transparency over maximal process visibility, which directly challenges the Trust essay's argument that confidence develops through visible work — prepare a spoken position on where you draw the line.
- Anthropic's permission model: Anthropic's agent research on trustworthy agents frames permission as always-allow, require-approval, or block per action rather than per trust level, which maps to the two-dial revision and gives you external vocabulary if a panel asks about capability boundaries.
- Vercel's codified judgment approach: Vercel now stores accepted product decisions as reviewed, agent-accessible code because coding agents can see existing code but cannot infer why decisions were made — a concrete industry example to reference when Gusto, Amplitude, or Vanta ask how you preserve design reasoning for agents.
- Stripe Agentic Commerce gone: The former Senior Staff Product Designer, Agentic Commerce URL now returns a 404, so any cached search results should not be treated as evidence of an open role — verify Link's window freshness independently before outreach.

