CaseAdvancedDesigning for Uncertainty & Trust / Designing for failure and graceful degradation / #16
How do you preserve user work when an AI operation fails midway?
FLIPS workaround: the tool has no memory of its own, so she builds one by hand
Inkbridge drafts multi-section grant applications for Cascade Relief Collective, a small housing nonprofit. Here is the night a job failed midway on Noemi Castellanos, and the design that would have cost her ninety seconds instead of a redone night.
The direct answer
Save each finished section the instant it's generated, show exactly which sections are done and which one failed, and let her resume from there with one tap. Never build the draft as one all-or-nothing job that only delivers anything once every section succeeds.
Do this, in order
Save each section the moment it's generated, not at the end of the whole job.Why: work that already exists shouldn't disappear because a later, unrelated step failed.
Show exactly which sections are done and which one stalled.Why: "something went wrong" tells her nothing. "Section 4 of 6" tells her exactly what to fix.
Offer one-tap resume from the last good section, not a full restart.Why: a full restart charges her the whole job's time again for one step's failure.
Keep a visible save timestamp on every section, always.Why: trust that nothing is lost has to be checkable, not just promised.
Don't over-build this for jobs that finish in a few seconds anyway.Why: a short job failing and restarting costs almost nothing, so per-step saving there is effort spent on a problem that barely exists.
How to answer this, stage by stage
Nobody is grading whether you'd add a "save" button. They're grading whether you can name the exact unit of work that should never be thrown away.
Stage 1
Scope it to one product and one night
Say it like this
"I'll use Inkbridge, an AI tool that drafts six-section grant applications for a small nonprofit, and the night a job failed at section four for Noemi, a program officer."
Why this works
Gives you a real job and a real failure point to design around, not an abstract "what if it fails."
Stage 2
Say your structure out loud
Say it like this
"I'll use FLIPS. Find the person, locate the habit, identify the flip, pinpoint the old decision, show the replay."
Why this works
Shows you have a method for finding the real cost, not just a gut feeling that losing work is bad.
Stage 3
Name the person and the habit the tool built
Say it like this
"Noemi used to keep her own backup copy of every section as she wrote it by hand. Once Inkbridge reliably finished full drafts, she stopped keeping any copy at all, and just waited for the finished screen."
Why this works
Puts a real cost behind "losing work," instead of leaving it as an abstract risk.
Stage 4
Identify the flip: trusting the whole job versus copying every piece by hand
Say it like this
"This is a workaround flip. After losing a near-finished draft once, Noemi starts pasting every section into her own scratch document the second it appears, before letting the tool touch the next one. No in-between."
Why this works
Names exactly why this is an AI-specific product failure, not a generic bug complaint.
Stage 5
Name the old decision behind it
Say it like this
"The team built the draft as one job, delivered all at once at the end, with nothing saved per section. That was fine when nearly every run finished cleanly in testing. Nobody revisited it once real, longer jobs started failing partway more often."
Why this works
Finds the actual product decision that broke, instead of blaming "the model failed" in the abstract.
Stage 6
Show the replay, with a clock on it
Say it like this
"Same failure at section four, redesigned Inkbridge. Sections 1 through 3 are already saved and visible. She sees 'Section 4 stalled, resume?', taps once, and it picks up right there. Ninety seconds, not twenty-five minutes redone."
Why this works
This is the actual deliverable the question is asking for, not a description of what a fix might look like.
Stage 7
Close on the one line
Say it like this
"Save each section the moment it exists, show exactly what stalled, and let her resume from there. Never make the whole job the only unit that counts."
Why this works
Restates the decision in one breath, the way you'd want to leave the room.
Let's learn
Inkbridge is an AI tool that drafts a six-section grant application, need statement, goals, methodology, budget narrative, evaluation plan, and org background, for a small nonprofit's program officer.
Before Inkbridge, Noemi wrote a full application by hand, section by section, over several evenings, roughly six hours total for a mid-sized foundation grant.
Now Inkbridge drafts all six sections in about eighteen minutes, when the job completes successfully end to end.
The whole method, in five rows. The hard one is the third.
Here's the turn: the extra speed was never the problem. The real cost showed up the first time a job failed partway, because the product only ever delivered anything at all once every section finished, so one stalled step could erase three completed ones.
Minutes lost when a job fails at section four, old design versus new
Three finished sections cost nothing to keep. The old design threw them away anyway.
At its worst, a program officer loses an entire evening's work the night before a deadline, redoing three sections that were already correct, because the fourth one alone happened to stall.
The decision I would take back
Inkbridge was built to deliver the draft as one job: nothing shown to Noemi, nothing saved anywhere, until every section finished. That made sense in testing, where runs almost always completed cleanly end to end. It stopped making sense once real jobs, longer and run more often, started failing partway more frequently than the test runs ever had.
What I would leave alone: short, single-section tasks, like rewriting one paragraph, don't need this treatment. A quick retry costs seconds, so per-step saving there is effort spent on a problem that barely exists.
The lesson: the unit of work you design around is a promise. Promise the whole job or nothing, and the whole job becomes the only thing that's ever safe.
Now here is the same thing as a story
The short version above is what you'd say defending this fix to Cascade Relief's board. Read this one for how the habit actually formed.
Noemi Castellanos has been a program officer at Cascade Relief Collective, a small housing nonprofit, for four years, and she can weave board-approved language into a grant narrative without ever making it read like a form letter.
Inkbridge arrived and the first months were good. She'd start a draft after dinner, and by the time she'd made tea it had produced all six sections, clean enough that she only needed to tighten a sentence here and there.
Knowledge spark: why would a long AI job fail partway instead of all at once?
A multi-section draft is really several separate model calls chained together, one per section. Each call can time out, hit a rate limit, or produce something the system rejects, independent of the others. The odds of at least one of six calls failing are much higher than the odds of any single one failing, which is why longer jobs stall more often than short ones, even when nothing is actually broken.
In her first month, she kept a personal backup, pasting each section into a notes app as it appeared, the same habit she'd used writing by hand. By month two she'd stopped, since Inkbridge had finished cleanly every single time. By month three she didn't even watch the screen while it ran, she'd start it and go make tea, trusting it completely.
Her own backup habit didn't fade evenly. It ran flat at zero for two months, then jumped straight back to full the night she lost work.
The night before a foundation deadline, Noemi started a draft after her kids were asleep. Sections one through three appeared cleanly, methodology at 10:41pm looking especially strong. At section four, the budget narrative, the job stalled and the screen returned only: "Something went wrong. Please try again."
Inkbridge did not lose one section. It never actually had three of them saved anywhere to lose.
She tried again. The whole job restarted from section one, twenty-five minutes, and produced a methodology section noticeably weaker than the one she'd already read and liked. There was no way to get the first version back.
This is the private process Noemi builds for herself, starting the very next time she opens Inkbridge.
It wasn't really about the twenty-five minutes. It was that Inkbridge had never actually protected any of her three good sections, it only looked like it had, because nothing had failed yet.
Noemi never had a dial she could trust a little more or a little less. She only ever had a switch: copy everything herself, or copy nothing.
Starting the next week, Noemi pastes every section into her own scratch document the instant it appears, before letting Inkbridge move to the next one, adding several minutes of manual copying to every single draft, successful or not, because she no longer trusts the tool to hold anything until the very end.
Two months of quiet trust, then one stalled section undid all of it in a single night.
With the redesigned Inkbridge, each section saves the instant it's generated, visible to Noemi as it happens. The same stall at section four now shows: "Sections 1 to 3 saved. Section 4 stalled, resume?" She taps resume. Run the same night forward: she's done by 10:47pm, six minutes after the stall, methodology section intact exactly as she first read it.
Everything Noemi's resume screen needs. The old design showed none of it, because none of it was ever saved.
The old design asked Noemi to trust the whole job or lose everything. The new one just tells her exactly where it stopped.
I built the draft to deliver all at once because that's how every test run behaved, clean, complete, no reason to think about partial states. It took one nonprofit program officer's ruined evening, redoing a section she'd already liked better, to see that "it always finishes" and "it's safe to never check" were never the same promise.
The five steps, if you want to remember it
F
Find the person. Whose evening is this?
Noemi Castellanos, a program officer who used to keep her own backup of every section, by hand, before Inkbridge existed.
Grounds the whole flip in one specific person's real habit, not "users" in general.
L
Locate the habit. What did she stop doing?
Keeping her own copy of each section as it appeared, since Inkbridge had finished cleanly every time for two months straight.
Names the exact thing the product's reliability quietly replaced.
I
Identify the flip. Workaround, not verification.
Trusting Inkbridge to hold her work across the whole job, versus manually copying out every section herself, before letting the tool continue. No in-between.
This is the hardest step: the tool never actually changed, only her trust in its memory did, after one failure revealed it never had any.
P
Pinpoint the old decision.
Delivering the draft as one all-or-nothing job, nothing saved per section, a choice that made sense when test runs almost always finished cleanly.
Finds the specific, reasonable-at-the-time choice that quietly stopped being safe.
S
Show the replay.
With per-section saving, the same stall at section four costs six minutes and zero lost work, instead of twenty-five minutes and a weaker rewrite of a section she'd already liked.
Ends on something countable: minutes and an intact section, not just "a better experience."
The recap, one line per letter: find the person is Noemi and her old backup habit, locate the habit is the manual copying she quietly stopped doing, identify the flip is a workaround built the instant the tool's lack of memory was revealed, pinpoint the old decision is an all-or-nothing job nobody revisited, and show the replay is a six-minute resume instead of a redone night.
The bigger the batch, the less anyone can afford to trust it blindly, which is exactly backwards from how trust usually builds.
And if you want to be sure it really works, try it somewhere elseA different flip family, a veterinary clinic instead of a nonprofit. This time it's scope, not workaround.
Thornmeadow Veterinary Clinic uses VetSummary, an AI tool that summarizes a full day's patient charts into handoff notes for the overnight technician. Warrick Osei, a vet at Thornmeadow, ran it on a full day's twenty-two charts at once. This story runs on a different family: the scope flip, not workaround.
After VetSummary once lost an entire day's batch to a single malformed chart partway through, with no partial output at all, Warrick stopped running it on a full day and started feeding it four or five charts at a time instead, small enough that he could hold the whole batch in his head and re-run it quickly if something broke. The old decision behind it: VetSummary was built to process a full day's charts as one batch job, because early testing used small sample sets where nothing that large had ever failed partway.
Same shape of story, a clinic instead of a nonprofit, and a batch of charts instead of a grant draft.
Average number of charts Warrick submits to VetSummary in one run, by week
Warrick did not gradually trust smaller batches more. He ran full days right up until one failure, then cut his own batch size by three quarters overnight.
Swap the trigger and it still runs.
Speed: an interviewer caps you at sixty seconds. Say "save each finished unit the instant it exists, show exactly where it stopped, and let the person resume from there, never restart the whole thing," and stop.
Cost: there's no time to rebuild every job as fully resumable this sprint. Say so honestly, and start with the longest-running, highest-stakes job first, since that's where a full restart costs the most.
The model gets better, for real: if Inkbridge's completion rate genuinely climbs to near perfect, that's still not a reason to remove per-section saving, the one night it fails is exactly as costly as it ever was, however rare that night becomes.
Where people run it wrong.
They add a retry button and call the problem solved, without ever saving what already succeeded.
They show "something went wrong" with no detail on which part actually failed.
They assume a person will complain about lost work, when most people just quietly build their own backup habit instead, the way Noemi did.
How to use it live. When someone asks how you'd preserve work through a mid-operation failure, ask yourself one question before describing a single screen: what is the smallest unit of finished work that should never have to be redone? Design the save point around that answer, not around when the whole job happens to finish.
Flashcards (tap any card to flip it)
1 · THE FLIP FAMILY
What flip family is this?
Tap to flip
ANSWER
Workaround: the person invents their own private process because the tool has no memory or checkpoint of its own to rely on.
2 · THE PERSON
Who is this answer about?
Tap to flip
ANSWER
Noemi Castellanos, a program officer at a small housing nonprofit, who used to keep her own backup of every grant section by hand.
3 · THE HABIT
What did she stop doing because it worked?
Tap to flip
ANSWER
Keeping her own copy of each section as it appeared, since Inkbridge had finished cleanly every time for two months straight.
4 · THE FLIP, IN THIS STORY
What's the two-setting switch here?
Tap to flip
ANSWER
Trusting Inkbridge to hold her work across the whole job, versus copying out every section herself before letting the tool continue. No middle setting.
5 · THE OLD DECISION
What decision would you take back?
Tap to flip
ANSWER
Delivering the draft as one all-or-nothing job with nothing saved per section, a choice that made sense when test runs almost always finished cleanly.
6 · THE NUMBER
Fill in the blank: the old design cost Noemi 25 minutes to redo a failed job. The redesigned resume cost about ___ minutes.
Tap to flip
ANSWER
About 1.5 minutes. The gap between those two numbers is the entire cost of treating the whole job as the only safe unit.
7 · THE REPLAY
Same stall, redesigned Inkbridge. What changes?
Tap to flip
ANSWER
Noemi sees sections 1 to 3 already saved, taps resume, and finishes six minutes after the stall, with her preferred methodology section still intact.
8 · CROSS PRODUCT TRANSFER
Section 4 answers this same question again for a different product, with a different flip family. Which product, and which family?
Tap to flip
ANSWER
VetSummary, a veterinary clinic's chart-summarizing tool. The scope flip: after losing a whole batch to one bad chart, Warrick starts feeding it charts in small handfuls instead.
Check yourself Score: 0 / 0
Multiple choice
1. Why did Noemi lose her three finished sections when section four failed?
A. Inkbridge deleted them on purpose to save storage space.
B. Nothing was actually saved until the whole job finished, so a partial job had nothing to keep.
C. Noemi accidentally closed the app herself.
D. The model's confidence score dropped too low to continue.
Show hint
Look at the P step, the old decision.
Show answer
B. The job was built to deliver everything at once, at the end, so a failure partway meant nothing had ever actually been saved.
True or false
2. True or false: Noemi could have avoided the lost work by checking on the job more closely while it ran.
True
False
Show hint
Look at "why no middle setting" style reasoning: was there ever a partial save to catch?
Show answer
False. There was nothing to catch by watching more closely. Nothing was ever saved until the entire job finished, no matter how attentive she was.
Fill in the blank
3. Fill in the blank: under the old design, a failed job cost Noemi about 25 minutes to redo. Under the redesign, the same failure cost about ___ minutes.
Show hint
Look at the bar chart in Section 1.
Show answer
1.5 minutes. Roughly the time it takes to tap resume and let one section regenerate.
Short answer, apply it yourself
4. Think of a multi-step tool you use, an order, a form, an upload. If it failed on the last step, would you lose everything before it, or just that step?
Show hint
Ask whether the tool shows progress saved at each step, or only a final confirmation.
Show answer
Model answer: Many multi-step tools still only confirm success at the very end, the same all-or-nothing gap this answer redesigns around.
Short answer, where it wouldn't matter
5. Name a task in Inkbridge where this same per-section saving genuinely doesn't need to apply.
Show hint
Look at "what I would leave alone."
Show answer
Model answer: A short, single-section task, like rewriting one paragraph. A quick retry costs seconds, so building per-step saving there solves a problem that barely exists.
Short answer, name the reversal
6. What old decision does this answer take back, and why did it make sense when it was made?
Show hint
Look at the key point block titled "The decision I would take back."
Show answer
Model answer: Delivering the draft as one all-or-nothing job, nothing saved per section. It made sense because test runs almost always finished cleanly, so partial failure never came up.
Before you close the answer
Why this works
Tests whether you'll design around the smallest unit of work that deserves protecting, or just add a generic retry button and call it resilience. Most candidates stop at "let them try again," which throws away exactly the work that was already fine.
Follow-up traps
"Doesn't saving after every section slow the whole job down?" Response: barely, writing a finished section to storage takes a fraction of a second compared to generating it, and that cost is trivial next to twenty-five redone minutes.
"What if the resume itself produces a different section four than before?" Response: that's expected and fine, only section four ever needed to regenerate, sections one through three stay exactly as they were, which is the entire point.
If pressed
Inkbridge's redesign also stores a short generation log per section, model version and prompt used, so a stalled section can be retried against the exact same conditions instead of silently drifting to a newer model version mid-application.
From U2xAI Academy
From answering questions to owning outcomes.
A live workshop where you ship a working AI agent, defend a launch decision, and walk away with a portfolio recruiters can't wave off, not just more questions to study.