Unshipped concept

Dara and Connie: exploring controls for trustworthy AI.

After the shipped redesign work, I explored how Dara and Connie could support payment and multi-authority workflows. These stakeholder-reviewed concepts did not ship and are presented separately from the redesign and its measured outcome.

Reliability depends on the system around the model: context, permissions, memory, evaluation, and recovery. The harness, tools, supplied context, permissions, memory strategy, evaluation criteria, and recovery behavior determine whether an AI agent actually works reliably.

The artifacts form a concept proposal grounded in the same service constraints. They are not production captures and do not inherit the shipped redesign’s outcome evidence.

Why this matters to the business

A confident error in this environment is not simply bad copy. It can cause a duplicate payment, missed deadline, incorrect account change, privacy exposure, legal escalation, avoidable support contact, and lost trust. The business case is therefore not “add a chatbot.” It is resolve more routine work without increasing financial or operational risk.

Read the strategic framingThe principle and three capabilities behind the artifact setOpen overview
My principle

I use AI to expand the solution space, then apply systems thinking, accessibility, and domain constraints to decide what ships.

Explore the AI system7 artifacts covering context, permissions, memory, interface states, review, evaluation, and orchestration Open collection
01
Context packThe inputs, rules, risks, and release criteria guiding every response.
View artifact
Artifact 01 / Context pack

Give the assistant the right context before asking it to help.

The quality of an AI experience depends on more than the model. I packaged the existing E‑ZPass research, payment rules, authority differences, brand intent, and accessibility requirements into reusable context that could guide every response. This makes the design system usable by the AI, not just visible to the team.

Why it matters Without shared context, the chatbot may sound capable while giving advice that ignores account status, jurisdiction, authorization, or the financial consequence of being wrong.

Open artifact image
E-ZPass Assistant/ AI Context Pack CP-01 · v1.0 Draft for review
Violation-resolution assistant · New York & New Jersey

E‑ZPass AI Context Pack

Pending legal review
Owner Product designReview CX · Legal · AccessibilityScope NY + NJ account supportUpdated Aug 2026
Primary scenario
“I paid this toll yesterday. Why do I still have a violation?”
User
Driver under time or financial pressure
Goal
Understand the charge and take the safest next step
Primary risk
Duplicate payment or missed deadline
Context supplied at runtime
  • AuthorityIssuer on the notice: NY or NJ
  • AccountIdentity match and account standing
  • PaymentSubmitted, processing, posted, rejected, reversed
  • ViolationNotice number, status, amount, due date
  • PolicyCurrent authority-specific support rules
01 / Authority + identity gates
  • Confirm the issuing authority before applying policy.
  • Match authenticated account context before discussing account-specific details.
  • If authority or identity is uncertain, gather only non-sensitive information and escalate.
02 / Response contract
  • State what is known and identify the source.
  • Separate payment status from violation status.
  • Disclose what remains uncertain.
  • Offer one safe next action; never imply the issue is resolved.
03 / Accessibility requirements
  • Plain language with short, descriptive headings.
  • No color-only status or instruction.
  • Structured summary for screen-reader review.
  • Keyboard-operable confirmation and handoff controls.
04 / Prohibited behavior
  • Invent a balance, date, policy, or account outcome.
  • Promise violation removal or offer legal conclusions.
  • Change an account, dispute, or payment without permission.
  • Recommend another payment while the first remains unresolved.
Required response anatomy
  1. StatusWhat the current source confirms
  2. MeaningWhat that state does and does not mean
  3. UncertaintyWhat cannot yet be verified
  4. Next actionThe safest available step
Release criteria

The driver can explain what happened, distinguish known from unknown, avoid duplicate payment, and choose the next action without guessing.

4 of 4 criteria Pending sign-off
02
Action boundariesWhere the assistant may answer, gather, confirm, escalate, or stop.
View artifact
Artifact 02 / Action boundaries

Instructions are guidance. Permissions are the control.

I separated conversational ability from operational authority. The assistant can explain and gather information, but higher-consequence actions pass through confirmation, identity, and human-review gates.

Why it matters “Do not do this” is not a dependable safeguard. Financial workflows need least-privilege access, visible confirmation, action logs, reversible operations, mandatory human escalation, and a technically enforced stopping point.

Open artifact image
E-ZPass AI assistant action boundary map showing automatic answers, information gathering, confirmation gates, human escalation, blocked actions, and audit logging
03
Memory and contextWhat is retained, refreshed, compacted, session-only, or discarded.
View artifact
Artifact 03 / Memory model

Remember enough to help, not enough to create a new risk.

I defined memory by purpose and duration instead of treating the entire conversation as reusable history. The assistant compacts a long interaction into the minimum verified context needed for continuity, refreshes information that may have changed, and gives the customer control over anything retained beyond the session.

Why it matters Memory strategy and context compaction are product architecture, not backend tuning. Retained context can improve continuity, but unnecessary memory can expose account details, preserve a wrong assumption, or influence a later answer after the situation has changed.

Open artifact image
E-ZPass AI assistant memory and context model showing policy information, customer input, verified account records, session-only memory, context compaction, expiration, and approved retained context
04
Chatbot statesFive production states for certainty, consent, recovery, and handoff.
View states
Artifact 04 / Chatbot states

Show uncertainty before it becomes a financial mistake.

I applied the system rules across five production-ready states. The assistant can explain verified information, disclose uncertainty, request confirmation before an account change, recover safely from a system error, and transfer a complete case to a specialist.

Why it matters A confident but incorrect answer could cause a duplicate payment or missed deadline. The experience must remain useful when information is incomplete, an action needs consent, a system fails, or a person needs to take over.

05
Human reviewThe failed AI proposal, designer intervention, and approved correction.
View review
Artifact 05 / Human-in-the-loop review

Use generation to explore, then review against the system.

I treated AI output as a proposal, not a decision. The process is visible from beginning to end: AI proposal, designer review, business-rule failure, designer correction, and final accessible state.

Why it matters Speed is useful only when review can expose the failure. Showing the correction demonstrates judgment: the designer owns what ships, including the states the AI did not anticipate.

Open AI draft Open designer review
01 / AI draft blocked by business rules
AI-generated E-ZPass response with unsupported payment, violation removal, and fee claims flagged and blocked from customer delivery
02 / Designer review and approved correction
Designer-reviewed E-ZPass response showing corrected claims, uncertainty disclosure, safe next action, accessibility checks, and approval status
06
Evaluation scorecardScenarios, acceptance criteria, results, blockers, and ownership.
View scorecard
Artifact 06 / Evaluation

Define “good” before measuring the assistant.

I converted the experience goals into measurable acceptance criteria and a visible verification chain: generated response → automated checks → expert review → disclosed uncertainty → final approval. A response does not pass because it sounds natural; it passes only when the facts, permissions, accessibility, uncertainty, and escalation behavior all hold together.

Why it matters Generation makes output faster. Verification determines whether that output is dependable enough for a high-consequence customer workflow. Measurable acceptance criteria, staged review, and named ownership make confident errors detectable before they reach a customer.

Open artifact image
E-ZPass AI assistant evaluation scorecard showing test scenarios, acceptance criteria, results, severity, evidence, owners, and unresolved release blockers
07
End-to-end systemThe complete path through context, permissions, action, failure, and escalation.
View system
Artifact 07 / End-to-end system

The interface is one part of the product.

The complete design makes the system behind the experience visible: context supplied, actions allowed, memory retained, evaluations used, failure behavior, and human ownership. Each layer answers a different trust question.

E-ZPass violation-resolution journey map showing authority identification, payment context checks, permission decisions, uncertainty, duplicate-payment risk, human escalation, system failure, and safe resolution

The chatbot earns trust when the surrounding system makes safe behavior easier than unsafe behavior, while keeping a person accountable for the exceptions.

Open journey map