Case · UX Lead · Webroot & OpenText · 2021–2025
Scam detection designed to open a new revenue channel for Webroot
Customers wanted their security app to answer one question: is this real? I led UX for the feature that answers it — mobile first, with a VPN-bundled premium desktop tier and a partner-distributed channel behind it.
01 The Work
“Is this real?” — a verdict in one paste.
One input takes email text, messages, files, images, video, and links. Detection runs on a partner API; the design owns the trust layer around it — what the product asks for, what a verdict is allowed to say, and how the wait and the answer read. Swipe the journey, then the mobile flows, verdict states, and supporting tabs.
Fig. 1–8 From suspicious content to a plain-language verdict with one recommended action. Tap any figure to view it full size.
Mobile first
I wrote the cross-functional user requirements for the mobile product, then managed and coached offshore design teams to deliver against them — running reviews, resolving requirement questions, and holding the verdict vocabulary and entry-point model consistent with the desktop UX.
Fig. 9–12 Mobile first: paste, camera, gallery, and QR entry, one decision per screen.
Four verdicts, one vocabulary
Fig. 13–16 Every state commits to a position and names a next step. No countdowns, no fear copy, no upsell in the verdict.
Supporting tabs
Fig. 17–19 The other two tabs carry the handoff to mobile and the record of what’s been checked.
A score is not an answer. The product’s job was to take a position and say what to do about it.
The principle that resolved the partner integration
02 Process
The detection was accurate. The assessment wasn’t readable.
The partner’s engine found fraud well. What it returned was written for analysts: a confidence score, matched signals, vendor terms — no verdict, no action. In testing, people couldn’t tell whether they’d been told yes or no.
Redefine the assessment itself
Plain-language verdict first, ranked evidence second, one recommended action third. The spec changed what Webroot rendered and what the partner reported — they adopted the revised model on their own side, after joint reviews on real output and annotated redlines both engineering teams built against.
Four principles, set before any wireframes
Generative research across three personas found the same thing: people felt protected without knowing what protection meant, and abandoned tools that felt alarmist.
Principle 01
No decision burden
Users shouldn’t have to know something is suspicious before submitting it. Paste anything; the product classifies it.
Principle 02
Verdict first, never narrative
Answer, then reasoning, then action — the inverse of how most AI assistants build to a conclusion.
Principle 03
No fear copy, no dark patterns
Every verdict went through bias/risk review. Catastrophizing language and upsell prompts were cut, and the rules went into a copy guide for content and engineering.
Principle 04
Privacy as a design constraint
Data minimization, consent, and retention were settled in design review — before the architecture was final, and before the law required it.
Why it mattered
Security products earn trust by answering plainly, not by alarming. A verdict a person can act on — and a copy guide that forbids fear — is what makes the feature worth paying for and worth distributing.
Demo scenario content is fictional and AI-generated for illustration.