← Work
CrowdStrike · Founding designer · 2022–2025

You can't demo your way to trust.


Research said security professionals didn't trust AI. Leadership wanted something brilliant enough to put on a keynote stage. Brilliant means autonomy. Autonomy needs trust. Trust was the thing we didn't have.

That's not a problem you solve with a screen. So we stopped trying to.

The loop we were standing in
  1. 01Leadership wants brilliant.
  2. 02Brilliant means autonomy.
  3. 03Autonomy needs trust.
  4. 04Trust is the thing we don't have.
Act I · Where we started

Two true things that didn't fit together.

The request I got was "make it pretty so leadership invests." I went and did research instead, because we don't know what we don't know, and this one had blind spots in every direction.

What came back was blunt. Deep skepticism about AI across cybersecurity — not one team, the whole field. Low trust in anything generated. Almost no appetite for handing over decisions. These are people who are paid to be suspicious. That's the job. And we were asking them to accept an answer they had no way to verify.

Meanwhile, the pull from leadership was toward the spectacular. Show what it can do. Every impressive thing on that list required Charlotte to act on its own — and frankly, to make assumptions that could be disastrous if it got them wrong.

Both sides were right. That was the problem. We couldn't research our way out of the ambition, and we couldn't demo our way out of the skepticism.

From leadership
Show what it can do. Let's put something brilliant on the keynote stage.
From research
We are paid to be suspicious. Trust but verify.. not sure I can trust.
Act II · How the frame showed up

Nobody hands the intern the hardest case.

In the early days, my product partner and I had these multi-hour Zoom sessions — no agenda beyond "let's think out loud until something breaks loose." Most of them ended with more questions than answers. This one gave us our north star.

I was working through how trust actually gets built, out loud, badly, the way you do. Two things kept surfacing. Trust isn't granted, it accrues — you earn it in small increments by being right about small things, repeatedly, in the open. And just as importantly, you earn it by knowing when you don't know and saying so. That second one became a real guardrail: Charlotte had to be able to recognize the edge of its own knowledge and admit it. An assistant that answers everything is an assistant nobody believes.

You wouldn't hand a brand-new intern the case that takes three years of institutional knowledge to understand. You'd give them something small, something they could complete successfully. When they did it well, you'd give them more.

The sentence that turned into a roadmap

We both lit up. That was the one. I said the sentence; my product partner immediately started mapping it against how security teams actually level their people. That's the move that turned a decent analogy into a roadmap, and it happened inside the same hour.

What the metaphor bought us wasn't a nicer way to describe the product. It was a sequencing argument we could take to anyone. Charlotte starts as an intern. It earns analyst. Then investigator. Then, eventually, teammate. Every rung has to be paid for with a track record from the rung below it.

And the ladder climbs toward people, not over them. Each rung is defined by what work leaves someone's plate, not by who gets replaced. The most autonomous thing at the top is still a peer working a hard problem next to you.

Act III · What each promotion actually shipped

Four promotions, two and a half years.

Rung 01

Intern

Go get me that. Retrieve a large set of records. Read all of this and summarize it. Pull this data, for this window, with these filters. Observation, retrieval, summarization — no analysis, no changing anything, no actions taken or even suggested.

The one thing we snuck in early was navigation. Because of show your work, every answer linked directly back to where the underlying data lived. People clicked those links, and in doing so they got more familiar with a platform they were still learning. A citation requirement turned into an onboarding feature.

The surprise

We built the intern for frontline analysts, and the people who got the most value first were their bosses. Retrieve, gather, summarize, report is a direct line to what a manager or security executive needs — metrics, snapshots, how many alerts, trending up or down. The people making the buying decision were the ones getting immediate value. A very fortunate accident, and not one we planned.

Open the interactive recreation↗
Rung 02

Analyst

This is where the needle moved for people on the front lines. Explaining what a command someone ran on a machine actually did, so an analyst could make a fast judgment call on an alert. Combining separate data sources into one view to surface trends nobody could see in the parts.

Early workflow automation through promptbooks. The beginnings of automated triage — clearing alerts that turn out to be nothing, with a paper trail. And a quieter one I loved: making documentation conversational, so someone newer could just ask what a term meant and get a real answer instead of hunting through a manual.

Open the interactive recreation↗
Rung 03

Investigator

The first rung where Charlotte took action rather than just informing it. Diving into an open investigation to surface insights and recommend next steps. Automated triage shipping for real — identifying and closing false alarms on its own.

Letting people write database queries in plain language instead of code. And injecting AI into the established, already-proven automated playbooks teams had built themselves, rather than asking them to trust a new one.

Open the interactive recreation↗
Rung 04

Teammate

The agentic chapter. Guided response, where Charlotte works alongside you on an investigation — asking better questions, suggesting the next thread to pull, and quietly leveling up newer investigators by giving them a knowledgeable hand to work with.

Two and a half years from the top of this list to here. That distance is the whole argument.

Open the interactive recreation↗
Rung 01·Intern
Loading the recreation…
Act IV · Turning a metaphor into a mechanism

Three rules that made every idea sharper.

A metaphor that only lives in a deck is decoration. Ours needed something operational underneath it, so my product partner and I wrote three principles in one of those same working sessions, took them to leadership, and got real buy-in before we did anything else with them.

01

Do what is told.

Answer the question asked. Not the adjacent one, not the one we wish they'd asked.

02

Show your work.

If a feature has no way to expose how it got there, it isn't done.

03

Prefer determinism.

When there's a reliable path and a clever one, take the reliable one.

Run a response through the rules

This is roughly how the check worked in a room. Pick a principle and watch what it does to the same answer — it doesn't kill the idea, it sharpens it.

The ask
"How many detections on this host in the last 24 hours?"
Before
After

They read as modest. They were not. They were a shared test we could run out loud in a room without it becoming personal — which is the part I care about most. Disagreeing with someone's feature is a fight. Checking a feature against three rules everyone already agreed to is just Tuesday.

They didn't kill ideas. They made ideas clearer. If a response came back with more than the prompt asked for, we cut it down. If a feature couldn't show its work, it got rewritten until it could. Scope creep and slippery-slope arguments both lose their footing fast when there's a shared standard to point at.

I walked the team through them with examples, and then we started using them. They began as design principles and became product principles. Later, they were one of the first things we shared with any team who wanted to build AI into their own part of the platform — before the patterns, before the components. Here's how we think. Start here.

Act V · Restraint

"But wouldn't it be cool if Charlotte…"

Leadership said this a lot. And the ideas were genuinely, really cool. That was the hard part — saying no to a bad idea is easy.

But the answer was never no. The answer was not yet. You don't kill a great idea. You hold onto it until you can execute it well, because you respect it. That distinction mattered enormously to how those conversations went. Nobody stops bringing you ideas when the response is "let's earn our way to that one."

The reasoning was almost always the same: we could do that once, on a stage, and it would be magnificent. We could not do it reliably, across the range of real questions real people ask, on a Tuesday afternoon in someone's actual environment.

A demo failure is embarrassing. A trust failure is permanent.

If the assistant is confidently wrong once in front of a security professional, you don't get a second look — you've just confirmed everything they already suspected.

So we spent longer than anyone wanted proving Charlotte could answer straightforward questions excellently before we let it answer impressive ones at all. Boring, on purpose, for a while. That was the bet, and it's the one I'd defend hardest.

Act VI · Promptbooks

A feature full of promise, looking for a problem.

Promptbooks let customers chain a series of questions together and run them as a set. It shipped. It never caught on. I'd rather tell you about it than not, because the diagnosis is the useful part.

Loading the recreation…

What I argued for and didn't win

A genuinely robust catalog of ready-made promptbooks customers could run as-is or clone and customize. Research already told us customers struggled to come up with one good question. Asking them to author a sequence of them from a blank page was a much harder version of the thing they'd already told us was hard. We shipped with a catalog, but a thin one, and it didn't grow much after launch.

The constraint underneath it

Responses couldn't build on one another. Step two's output couldn't feed step three. The dynamic part — variables in the steps — stopped the moment you hit run. That one limitation is the difference between a saved list of questions and an actual workflow. It's what would have made the feature sing, and without it the whole thing was dead in the water.

What made iteration hard

No staging, no testing, no approval step before something went live. And the path from a promptbook you'd written for yourself to one your whole organization could use had real friction in it.

What shipped
  • A thin catalog that didn't grow much after launch
  • Steps that ran in sequence but couldn't pass anything between them
  • Variables that stopped being dynamic the moment you hit run
  • A straight path to production with nothing in between
What I argued for
  • A deep, opinionated catalog built from workflows customers already ran
  • Chained responses — step two's output feeding step three
  • Variables that stayed live through the whole run
  • A staging and approval step before anything went org-wide

And then the failure compounded

Once usage was flat, the enhancements I wanted often couldn't clear the bar — the effort was real and product wasn't confident it would pay off next to other proposals, so they sat in the backlog. That's the honest shape of it. A feature that underperforms doesn't just underperform; it frequently loses the argument for its own fixes. I had ideas for how to save it. I still do. They lost on level of effort, not on merit.

Failure has value

Promptbooks unlocked prompt queueing for customers, and it laid genuine groundwork for the agentic workflows that came later. The bones were right and the rung was right. What we got wrong was investment — we optimized for shipping it rather than shipping it ready, and the catalog and the chaining both paid for that.

What the groundwork became·Agentic Studio
Loading the recreation…
Act VII · What a shared frame does

It stopped being ours pretty quickly.

The thing I didn't anticipate is how far a good metaphor travels once other people find it useful.

The ladder

One sentence about interns, said out loud on a Zoom call, that turned into the shared language for a product with teams across the globe.

Internally

How we talked about Charlotte

And how we briefed leadership. It helped us decide what Charlotte needed to be excellent at answering right now — a scoping decision in friendlier clothes.

Documentation

How support articles got structured

The docs team picked it up and used the rungs as their organizing principle.

In product

Which example prompts we shipped

The examples had to match the rung. If Charlotte was an intern, we didn't suggest an investigator's question.

With customers

The fastest level-set I've ever had

A security executive would describe something ambitious. Instead of managing expectations downward, I could ask: would you hand that investigation to an analyst? You'd watch them nod, already mapping it onto their own team.

Across the platform

One coherent product, not four

As more product teams started building AI into their own areas, the ladder and the three principles were what kept everyone shipping the same thing.

What I carry forward

Trust is a design constraint, not a feature.

Two-plus years on Charlotte convinced me that with AI products, the interface question is rarely how it looks. It's what this has earned the right to do — and whether the person on the other side can verify it.

What I'd defend

Sequencing capability behind credibility.

Principles that make ideas sharper instead of arguments louder.

Being boring on purpose while the track record accrues the trust.

What I'd redo

Ask customers and our own analysts for the workflows they already run, and build the catalog from those instead of guessing.

Push harder for observational research. What people say they need and what you see they need are often different.

Integrate across more of the platform sooner; I pushed back because design wasn't ready, and now I know I was protecting craft at the expense of momentum.

There is a lot more to dive into. More demos to share. More challenges to discuss. Let's talk.

Set up time with me →
Credit

Charlotte went from a scrappy internal team to something with layers of leadership, stakeholders, teams across the globe, and more integrations than I can count. What didn't change was how it got built. From day one this was a collaboration and a constant sharing of what each of us knew. The principles and the partnerships are what made it possible, and that's still true today.