Phase 1 — The Moment
Vanta's design org lost its VP Design and a senior design leader within weeks of each other this summer, leaving a Head of Design backfill open for 55 days and a fresh Director posting live since August 25 — five days ago. The mandate: design the trust boundary for AI agents that detect compliance risks with high confidence but lack the authority to remediate them, while building the experience vision for a workflow builder that barely exists as a named product.
Urgency verdict: Act Now. Five-day-old posting. The 55-day unfilled Head search means the committee has calibrated through failure — they know what the first slate lacked, the pipeline is thin at reset, and early Director candidates matching the revised mandate get outsized attention. A September 10 product launch where Epling introduces custom agent and workflow capabilities creates a natural outreach hook. That hook decays after the event.
Rubric:
| Dimension | Score | Basis |
|---|---|---|
| AI centrality | 3 | Custom Agents in production, capability-layer architecture shipping, Sep 10 launch expanding agent surface |
| Stage & equity | 3 | Series D, $4.15B valuation, pre-IPO, $300M ARR tripled in two years |
| Design influence ceiling | 2 | 40-person design org with director-level seats across product areas, but two senior departures and a Glassdoor review alleging strategic accountability without strategic authority |
| Trajectory | 3 | Revenue tripling, customer acceleration, active product expansion into agentic workflows |
| Company total | 11/12 | |
| Total comp | 3 | $275K–$323K + equity at $4.15B pre-IPO (grant economics undisclosed — ask in first conversation) |
| Scope expandability | 2 | Ceiling depends on who fills the Head role; the Head posting says Head leads design directors, so this Director likely reports into that hire |
| Craft depth | 3 | Net-new experience vision + team leadership + design strategy ownership |
| AI exposure quality | 3 | Designing approval gates, delegation boundaries, and trust surfaces for agents acting on compliance data |
| Portfolio value | 3 | AI workflow builder in a regulated compliance domain — publishable, differentiated |
| Role total | 14/15 |
Verdict: Act. Company 11 ≥ 10, Role 14 ≥ 12.
The Head of Design role is open. This Director likely reports into that hire, not directly to Epling. Ask about reporting structure in the first conversation.
The Head posting says the Head will lead design directors across GRC, Trust, Platform, Self-serve, and AI. Until that person is hired, you may report to Epling or to an interim lead — remaining directors include Kowitz, Sheehan, and Larson. Ask in the first conversation who you'd report to during the transition and after the Head starts. This is a scope question you cannot resolve from public signal.
Phase 2 — Portfolio Mapping
The intelligence layer is the entry point. Vanta's core product surfaces compliance intelligence — risk detections, control failures, vendor assessments — for human decision-making. Their Custom Agents documentation reveals the live authority model: agents inherit creator permissions, propose policy or SLA changes, and enter a "Needs approval" state that blocks execution until a human approves or rejects. The design problem sits in the gap between what the agent surfaces and what the human is authorized to do about it. Your Trust essay's five handoffs — Intent-Setting, In-Progress, Output Review, Decision Gate, Loop Feedback — map onto this approval architecture.
Lead with the delegation-envelope artifact. Vanta's current Custom Agents surface has a binary approval gate: the agent proposes, the human approves or rejects. But the posting describes workflows spanning risks, assets, vendors, controls, tasks, frameworks, owners, approvals, and organizational hierarchies. That means the design problem scales past binary approval into graduated delegation — which actions can an agent execute autonomously, which require review, which require escalation to a different human with different authority. Your Watch → Verify → Delegate ladder and the confidence/authority distinction (high confidence in detecting a vendor risk does not equal authority to remediate it) are the design framework this product needs as it moves from single-user agents to enterprise-wide workflows.
Supporting evidence:
- Carrier IQ (case study): Agent-generated insurance quotes with provenance layers, evidence review states, and a human approval boundary in a regulated domain. The analogy to Vanta's compliance agents is direct — both require the human to verify agent-surfaced intelligence before authorizing action with downstream consequences.
- Thermo Fisher mySupply (Product Design Director, BCG DV): $20M+ margin, 6 pharma partners, 100% adoption. FDA-regulated supply chain platform built 0→1. A wrong decision in pharma compliance carries regulatory consequences — the same dynamic applies in Vanta's GRC domain, where a wrong remediation creates audit exposure.
- American Red Cross (Product Design Director, BCG DV): $847K disbursed, 6 systems consolidated to 1, national deployment. Mission-critical 0→1 build where the design surface governed real disbursement decisions under federal oversight.
TinyFish bridge: Most recently as Head of Product at TinyFish, you shipped an enterprise web agent platform from 0→1 in three months, working daily with agent traces, auditability, attribution, and governance. This is what makes the delegation-envelope artifact credible — you've seen how agents behave in production, where they fail, and what the human needs to see to trust or override them. It also grounds you for the workflow builder mandate: you've built the agent infrastructure that a visual workflow surface sits on top of.
The objection that will come up:
"She's been in product, not design, for the past year. Is she returning to design or passing through?"
What makes it hard: the TinyFish title is Head of Product, and the gap between that title and Director of Product Design invites a commitment question.
What answers it: junochen.com shows four Agentic Labs projects (Carrier IQ, Brand Pulse, Retail Velocity, UAT Sentinel) and a published design-leadership essay — continuous design work regardless of title. The move to product was deliberate: build AI-natively from zero, understand the engineering reality that makes design decisions survive production. The return to design applies that depth to a specific high-stakes domain.
Phase 3 — The Outreach Package
First Contact Message
To Jeremy Epling. LinkedIn or email. ~180 words.
Jeremy — your August 6 post on agents needing the right context to be effective, paired with "nothing moves without your approval," describes the design problem I've been working on: the gap between what an agent can detect with high confidence and what a human has the authority to act on.
I've been designing for that boundary from two directions. As Head of Product at TinyFish, I shipped an enterprise agent platform from zero to production in three months — agent traces, auditability, governance. Before that, as Product Design Director at BCG Digital Ventures, I built regulated platforms where wrong decisions had compliance consequences: Thermo Fisher's pharma supply chain ($20M+ margin, 100% partner adoption) and the American Red Cross disaster-relief system (6 legacy systems consolidated, national deployment).
I also published a design framework for agentic trust boundaries — five handoffs from intent-setting through loop feedback — that addresses the approval architecture your Custom Agents product is building toward.
I'd welcome 20 minutes to discuss the Director of Product Design role.
Resume Framing Note
Lead your summary with regulated-platform 0→1 builds and the confidence/authority design problem. Vanta's buyer cares about someone who has designed for consequential decisions under compliance constraints. Surface Thermo Fisher first ($20M+ margin, pharma regulatory) over Alibaba — the B2B scale story is less relevant here than the regulated-domain proof. Position TinyFish as: "Most recently shipped AI-native enterprise tools in production as Head of Product at TinyFish — agent traces, governance, auditability — returning to design to apply that depth to high-stakes vertical domains." Subordinate Equinox+ and Allē; consumer engagement metrics won't register with this buyer. Avoid the phrase "design-led." Vanta's design influence is aspirational right now, and claiming it as a requirement signals you haven't read the org situation.
Cover Letter Hook
Your agents already surface compliance risks with high confidence — the design problem is what happens next: who has authority to remediate, what the agent needs to show them to earn that delegation, and how the system learns when the human overrides. I've designed for that boundary in pharma supply chains, federal disaster relief, and enterprise agent deployments, and published a framework for how trust scales from watch to verify to delegate.
Phase 4 — Window Summary
| Action | Deadline | What degrades without it |
|---|---|---|
| Send first contact to Epling | September 2 | Posting enters second week; early-candidate advantage halves. Outreach before Sep 10 launch positions you as tracking product direction. |
| Ask about reporting line (Head search status, interim structure) | First conversation | Scope-expandability score is unresolvable from public signal; waiting to learn this after investing in interviews wastes cycles if the structure is wrong. |
| Prepare delegation-envelope walkthrough for interview | September 8 | Sep 10 product launch will generate internal energy around Custom Agents; arriving with a framework for graduating their binary approval gate into enterprise delegation tiers lands differently before the event than after it. |
September 2, 2026.
- Epling's September 10 launch: Vanta's CPO is introducing capabilities for customers to build custom agents, skills, and end-to-end workflows — watch for new product language that sharpens or replaces the "workflow builder" framing in the Director posting.
- Vanta's capability-layer architecture: Their engineering team published how a shared capability layer exposes the same business logic across web, API, CLI, Agent, and MCP — interview-ready context for discussing how the workflow builder inherits authorization from the underlying system.
- Custom Agents authority model: Vanta's help documentation reveals that agents inherit creator permissions and enter a "Needs approval" state for policy changes, but administrator-wide visibility is explicitly not yet available — a design gap worth naming in conversation.
- Agent cancellation is cooperative: The MCP Tasks specification defines cancellation as a request that does not guarantee the underlying operation stopped, which matters for your delegation-envelope walkthrough when a compliance agent is mid-remediation and the user wants to stop it.

