CaseIntermediateDesigning for Uncertainty & Trust / Trust, transparency and explainability in UX / #12

Design the settings page that gives users control over an AI feature.

SPARK the product is Wavelight, a streaming service, and its AI-personalized recommendations and autoplay

Seraphina Kolb has subscribed to Wavelight for three years. Most nights, once her kids are down, she watches for about an hour, and autoplay has always been the thing that let her not touch the remote at all.

The direct answer
Give her three controls, no more. A taste dial for each mood or genre she can push up or down directly, autoplay-next switched off until she turns it on herself, and a visible reason on every recommendation with a one-tap "undo this" button. Skip a full rules engine for the first version. Almost nobody would use it, and building it first delays the three controls that actually matter.
Do this, in order
  1. Turn autoplay-next off by default, until a person explicitly turns it on.Why: an ambient assumption about a shared household screen is the decision most likely to quietly go wrong.
  2. Show a plain reason next to every recommendation.Why: "because you watched X" is what lets her tell the system apart from whoever else touched the remote.
  3. Put an "undo this signal" button right next to that reason.Why: fixing a bad signal in one tap beats quietly losing trust in the whole system.
  4. Give her mood or genre dials, not just per-title thumbs.Why: one dial can correct a drifting pattern that a dozen individual thumbs-up never would.
  5. Leave a full manual rules engine for later.Why: almost nobody would touch it on day one, and it isn't what's actually breaking her trust right now.

How to answer this, stage by stage

You're not being asked to list every possible setting. You're being asked which one decision the whole page should hang on.

Stage 1
Scope it to one real person
Say it like this
"I'll design this for Seraphina, a Wavelight subscriber who watches for about an hour most nights after her kids go to bed."
Why this works
Grounds "give users control" in one real screen, one real hour, instead of an abstract persona.
Stage 2
Say your structure out loud
Say it like this
"I'll use SPARK. Situation, how it works today without me. Payoff, the habit I want to build. Anchor, the one design decision. Risk, what breaks when I'm wrong. Keep out, what I'm deliberately not building yet."
Why this works
Signals you're designing against a specific failure, not just listing toggles.
Stage 3
Name the habit you want
Say it like this
"Today, she either accepts whatever autoplay queues up or gives up and searches manually. I want her to actively steer what Wavelight thinks she likes, instead of doing either of those."
Why this works
Names the payoff as a behavior, not a feeling like "more control."
Stage 4
Give the one anchor decision
Say it like this
"Three things: mood dials she can push directly, autoplay off by default, and a visible reason plus an undo button on every row. That's the whole page."
Why this works
Matches the direct answer exactly, so there's no daylight between what you claim and what you design.
Stage 5
Prove the anchor survives the risk
Say it like this
"One night, autoplay chained three episodes deep into a kids' show at 11pm, because her kids had used her login during the day. With the reason tag showing 'because a profile on this account watched X,' she can undo that exact signal in one tap instead of losing trust in the whole feature."
Why this works
Shows the anchor still works on the actual bad day it's designed for, not just in a demo.
Stage 6
Say what you left out, and close
Say it like this
"I'm not building a full rules engine, or a per-actor blocklist, on day one. Almost nobody uses those, and shipping them first delays the three controls that actually fix tonight's problem."
Why this works
Shows judgment about scope, not a wish list dressed up as a settings page.

Let's learn

Picture the one hour after the kids are asleep, and everything Wavelight assumes about how you spend it, correctly, for months, until one night it doesn't.

Wavelight is a streaming service. Its AI watches what an account plays and skips, then queues up the next thing and recommends more of it, without anyone asking.

Knowledge spark: what's a taste profile? A running record of what an account tends to watch, used to recommend and autoplay similar things. Most streaming services build one profile per account, not one per person, unless everyone in the household switches to their own.

For most of three years, Seraphina finished an episode and the next one simply started, no remote required. She built a real habit around that: she stopped even holding the remote most nights.

Nights per week Seraphina used manual search instead of autoplay
7 3.5 0 Before: 5 of 7 nights After: 1 of 7 nights
She wasn't watching less. She was fighting the system four extra nights a week to get what she actually wanted.

The turn: the bad recommendations weren't really the problem. The problem was she had no way to tell Wavelight "that wasn't me," so the only lever she had left was to stop trusting autoplay at all and search by hand every single night.

The decision I would take back Wavelight built one shared taste profile per account, with autoplay on by default and no visible reasoning, because that shipped a "smart" experience fastest at launch. That made sense in a single-user pilot. It stopped making sense the moment real households started sharing one login across parents and kids.

What I would leave alone: a single-person account with no shared logins doesn't need any of this. Autoplay drifting toward someone else's taste can't happen if there's only ever been one someone.

She didn't need Wavelight to guess better. She needed a way to say "that wasn't me" and be believed in one tap.

The lesson: a settings page for an AI feature isn't really about exposing every dial the system has. It's about giving the person exactly one lever, in the exact moment the system gets it wrong, so they never have to quietly opt out of the whole thing instead.

Hand sketched flow diagram titled Her evening, today, without a settings page. Four boxes: kids asleep, Wavelight opens, autoplay queues highlighted, she never touches the remote.
This is the routine the whole design has to protect, without asking her to give up the part that made it effortless.

Now here is the same thing as a story

The short version above is what you'd say pitching this settings page in a design review. Read this one for the actual night that made the case.

Every night around nine, once the kids are down, Seraphina makes tea, sits in the one armchair that's hers, and opens Wavelight. It's the only hour of her day nobody else is asking anything of her.

For most of three years, that hour ran itself. She'd finish something, the next episode would already be starting, and she never once thought about the remote sitting untouched on the arm of the chair.

Hand sketched timeline titled Seraphina's timeline. Four milestones: autoplay launches she stops touching the remote, slow drift kids share her login, the 11pm moment cartoon three episodes deep highlighted, settings page ships match rating climbs back up.
Nothing broke on one bad day. It drifted for weeks before it ever became a moment she noticed.

There was no single bad day that started this. Her kids had started using her profile during the day, on the shared living-room screen, since there was only ever one login on the account. Slowly, over weeks, Wavelight's sense of "what this account likes" started drifting, a little kids' content mixed into her evening queue, nothing dramatic enough to notice at first.

Then one night, three episodes into her show, autoplay quietly slid into a children's cartoon. She sat there for almost a full minute before it registered, tea going cold, half-watching something meant for a six-year-old at eleven at night.

Hand sketched comparison diagram titled The night it is wrong. Left panel, a question mark box icon labeled Before, caption 11pm autoplay wanders to kids show. Right panel, a gauge icon labeled After, caption one tap back to her own taste.
Nothing about that night was catastrophic. It was just the moment she stopped trusting the queue to know who she was.

It wasn't the cartoon that bothered her. It was realizing, all at once, that Wavelight didn't know her at all. It knew whoever had last touched the remote, and had no way of telling the difference, and neither did she have any way of telling it.

What that cost, at its worst: she started searching manually almost every night after that, giving up the one piece of the product that had made her evening actually feel easy, because the alternative, trusting a queue that might veer anywhere, felt worse.

Hand sketched labeled parts diagram titled The anchor, close up. Center box icon labeled Settings page, with four callouts: taste dial per mood, autoplay off by default, why recommended tag, undo this signal.
Four small things on one screen, and every one of them exists because of that specific 11pm minute.

I shipped a single shared profile with autoplay always on, because it made the product feel effortlessly smart the moment anyone signed up. It took watching someone quietly give up the entire feature, rather than risk one more surprise, to see that effortless isn't the same thing as trustworthy.

Hand sketched icon list titled What we left for later. Three items: full manual rules engine, per actor blocklists, automatic profile detection.
All three would help someone, eventually. None of them would have caught the 11pm cartoon faster than a plain reason and an undo button.

With the reason tag and the undo button live, the same drifting pattern now surfaces after two or three kids' titles, not three weeks of them, and one tap on "undo this signal" resets her evening queue before it ever reaches an actual show.

SPARK, in one screenNot a feature list. SPARK is what forces the whole page to hang on one decision instead of ten small ones.

S
Situation. Today, without you.
Seraphina either accepts whatever autoplay queues, or gives up and searches by hand every night.
Grounds the design in one real evening, not a generic user story.
P
Payoff. The habit to build.
She actively steers what Wavelight thinks she likes, instead of passively accepting it or quietly opting out.
Names a behavior, not a vague feeling of "empowerment."
A
Anchor. The hard step.
Mood dials, autoplay off by default, and a reason plus undo button on every recommendation.
The one decision everything else on the page hangs on.
R
Risk. What breaks when it's wrong.
A shared login lets a kid's viewing quietly reshape the evening queue for weeks before anyone notices.
Names the exact failure the anchor has to survive.
K
Keep out. Not day one.
A full manual rules engine, per-actor blocklists, automatic profile detection.
Shows judgment about scope, not everything the team could possibly build.
Weekly "this matches me" rating, six weeks
100% 50% 0 40% 35% 28% 55% 74% 88% Wk1 Wk3 Wk5
Week 3 is the 11pm cartoon week. The settings page ships right after, and the rating climbs for three weeks straight.

The recap, one line per letter: situation is her either accepting drift or giving up on autoplay, payoff is actively steering the taste profile, anchor is the three-control settings page, risk is a shared login quietly reshaping the queue, and keep out is everything that wouldn't have caught tonight's problem anyway.

And if you want to be sure it really works, try it somewhere elseSame five letters, a fitness wearable instead of a streaming queue. A different industry, and this time the anchor is a dial on effort, not taste.

Larkspur Health makes a fitness wearable whose AI auto-adjusts a person's daily step goal and workout suggestions based on recent activity. Ingeborg Halvorsen has worn one for four months.

Mapped onto SPARK: situation is that today, Ingeborg either follows whatever goal the app sets or ignores the app entirely on days it's clearly wrong. Payoff is her actively telling the app how hard today should feel, instead of silently overriding it in her head. Anchor is a training-intensity dial she can nudge for the day, plus a reason tag ("goal raised because of last week's pace") and a one-tap "pause auto-adjust for today" button. Risk is a bad week, an injury or a bout of flu, quietly training the app to expect less from her permanently. Keep out is a full manual training-plan builder, which almost no casual user would ever open.

Hand sketched quadrant titled Sorting fitness app controls by use and trust. Axes how often used from rare to daily, how much trust it builds from little to a lot. Intensity dial sits top right, daily and high trust. Pause auto-adjust sits top left, rare and high trust. Reason tag sits top right. Full history export sits bottom left, rare and low trust.
The dial and the pause button do almost all the trust-building work. The export feature barely moves it.

Swap the trigger and it still runs.
Speed: an interviewer caps you at sixty seconds. Say "mood dials, autoplay off by default, reason plus undo on every row," and stop.
Cost: there's no budget this quarter for per-row reasoning. Ship the autoplay default change alone first, since it costs the least and removes the exact risk that caused the 11pm moment.
The model gets better, for real: even if Wavelight's recommendations get more accurate next quarter, a shared login can still drift the profile in a way accuracy alone never fixes.

Where people run it wrong.
They build a settings page as a list of every possible toggle, instead of the one decision the actual failure needs.
They ship a powerful rules engine nobody uses instead of the small, high-traffic controls that would have caught the real problem.
They leave a risky default, like autoplay on for a shared login, untouched because "most people are fine with it," which is true right up until they aren't.

How to use it live. When asked to design a settings page for an AI feature, ask yourself first: what's the one moment this feature will visibly get it wrong, and what single control lets someone fix that moment without losing the whole feature's convenience?

Flashcards (tap any card to flip it)

1 · THE FRAMEWORK
What framework fits "design the settings page for an AI feature"?
Tap to flip
ANSWER
SPARK: situation, payoff, anchor, risk, keep out. The anchor is the one decision the whole page hangs on.
2 · THE PEOPLE
Who is this answer about?
Tap to flip
ANSWER
Seraphina Kolb, a three-year Wavelight subscriber who watches for about an hour most nights after her kids are asleep.
3 · THE HABIT
What habit had Seraphina built because autoplay worked?
Tap to flip
ANSWER
She stopped touching the remote at all, most nights, for nearly three years.
4 · THE ANCHOR
What's the one design decision this whole answer hangs on?
Tap to flip
ANSWER
Mood dials, autoplay off by default, and a visible reason plus undo button on every recommendation.
5 · THE OLD DECISION
What decision would you take back?
Tap to flip
ANSWER
Building one shared taste profile per account with autoplay always on, to make the product feel smart from the first sign-up.
6 · THE NUMBER
Fill in the blank: before the redesign, Seraphina searched manually ___ nights out of 7.
Tap to flip
ANSWER
5 nights out of 7. After the redesign, that fell to 1 night out of 7.
7 · THE REPLAY
Same shared-login drift, redesigned page. What changes?
Tap to flip
ANSWER
The drift surfaces after two or three kids' titles, not three weeks, and one tap on "undo this signal" resets her evening queue.
8 · CROSS PRODUCT TRANSFER
Section 4 runs SPARK again on a different product. Which one, and what plays the role of the taste dial?
Tap to flip
ANSWER
Larkspur Health's fitness wearable. There, a training-intensity dial plays that role, plus a "pause auto-adjust for today" button.

Check yourself Score: 0 / 0

Short answer, apply it yourself
1. Think of an app on your own phone with an "auto" setting (autoplay, auto-adjust, auto-suggest). What single control would you want if it ever got you wrong, without turning the whole feature off?
Show hint
Think about Seraphina's "undo this signal" button.
Show answer
Model answer: Most people land on some version of "tell it that one specific thing was wrong, without losing everything else it's learned about me."
Multiple choice
2. Why does this answer put "autoplay off by default" above building a full manual rules engine?
  • A. Because rules engines are technically impossible on streaming apps.
  • B. Because the risky default is what actually caused the 11pm moment, while almost nobody would use a rules engine anyway.
  • C. Because autoplay costs less to build than any other feature.
  • D. Because Wavelight's engineers refused to build a rules engine.
Show hint
Look at the "keep out" step of SPARK.
Show answer
B. SPARK's anchor targets the actual risk. A rules engine most people never open doesn't fix that risk any faster.
True or false
3. True or false: this answer recommends Wavelight automatically detect which family member is watching, without them doing anything.
  • True
  • False
Show hint
Look at "what we left for later."
Show answer
False. Automatic profile detection is explicitly left for later. The v1 fix relies on a visible reason and a manual undo, not automatic detection.
Fill in the blank
4. Fill in the blank: the weekly "this matches me" rating dropped to ___ percent the week of the 11pm cartoon moment, before recovering.
Show hint
Look at the line chart of the weekly match rating.
Show answer
28 percent. It climbed to 55, then 74, then 88 percent in the three weeks after the settings page shipped.
Short answer, where it wouldn't matter
5. Name a kind of Wavelight account where this whole redesign wouldn't matter much.
Show hint
Look at "what I would leave alone."
Show answer
Model answer: A single-person account with no shared login. There's no other viewer's activity around to drift the profile in the first place.
Before you close the answer
Why this works
Tests whether you can design one anchored control that survives a real failure, instead of listing every toggle a settings page could theoretically contain.
Follow-up traps
"Why not just force everyone to create separate profiles?" Response: that was considered and rejected, since most households won't adopt the friction of switching profiles every time, and it still wouldn't give a visible, correctable reason when something goes wrong.

"Doesn't turning autoplay off by default just make the product feel less magical?" Response: only for the first session; the mood dials get someone to a personalized queue within a couple of taps, and it removes the exact risk of a stranger's evening being reshaped by whoever last touched the remote.
If pressed
The real "why recommended" tag is generated from the single strongest recent signal, not a full list of every contributing factor, since testing showed a reason with three or more causes listed got skimmed past entirely, while a single clear reason got read and acted on.
From U2xAI Academy

From answering questions to owning outcomes.

A live workshop where you ship a working AI agent, defend a launch decision, and walk away with a portfolio recruiters can't wave off, not just more questions to study.

  • A live AI agent you actually shipped
  • A launch decision you can defend under pressure
  • An interview-ready portfolio, not more flashcards
Know more