Work
Work

AI Platform

Rippling AI

AI that runs payroll, hiring, and benefits from inside the work — designed to make payroll changes inspectable before approval.

Role
Principal Designer
Years
2025–2026
Deliverables
AI UX, Interaction Grammar, Product Strategy, Prototypes

Rippling runs HR, IT, and Finance on one data platform, so AI can reach straight into pay, access, and benefits. As Principal Designer, I owned the Rippling AI experience: its chat UI, visual design, model feel, thinking states, and interaction grammar.

Rippling AI given a spot-bonus CSV and asked to distribute it in the next payroll run: it shows its thinking, then the exact changes it will make to payroll as a table of employee, payroll run, country, and current versus new amount

The brief was trust, not chat

Most enterprise AI in 2025 was a text box bolted onto software that already worked. People tried it twice, got a plausible paragraph, and learned to ignore it. Rippling's position was harder. HR, IT, and Finance share one data model and one permissions system, so AI here could actually do things: run a bonus through payroll, reassign a team, hire someone.

The same fact that made it powerful made it dangerous. Throughout late 2025 and into early 2026, I was the only IC designer on the product, working directly with the CEO. I owned the AI experience around that risk: how the model felt, how thinking appeared, how answers exposed evidence, and what a person had to see before they let software touch a paycheck.

Every action is a proposal

The first rule: proposed changes require human confirmation before execution. Hand it a spreadsheet of spot bonuses and ask for them in the next payroll run, and you get the exact table payroll will receive, one row per person, current and new amount side by side, and then it stops. That table is the hero image above.

Structural changes work the same way. "Reassign Michael Johnson's 10 least tenured direct reports to Janet Williams effective next Monday" has four things in it that could go wrong. The model shows how it read each one before it touches anything.

The Rippling AI panel working the request 'Reassign Michael Johnson's 10 least tenured direct reports to Janet Williams effective next monday': it confirms who each name resolved to, describes the fields it is searching, and the query it is running

The request as typed, then the work: both names resolved, the fields it searched, the sort it chose

Then it hands off. The change lands as a review screen with every affected person listed, and nothing moves until a human presses Confirm.

The Review changes screen the request produces: effective date, optional documents, integrations and approvals, and a Changes for all people table with each person's new manager, ending in a Confirm changes button

Ten people, one Confirm. The AI's output is the operator's review screen

That sounds like a safety feature. It is really a placement decision. The AI's output is the operator's review screen, inside the job they were already doing. There is no separate AI mode to learn and no separate log to reconcile. When the staged table is right, approval is a glance. When it is wrong, the error is visible before it costs anything.

Exact answers, with the work attached

In these public examples, Rippling AI queries live company data under the requester's permissions and returns results with supporting evidence. I designed around that rather than hiding it: an answer is a claim plus the evidence for the claim, and both are first-class.

The overtime conclusion below is produced by the model from the data and skills available to it; I did not author that business analysis. My work was the experience that makes generated analysis inspectable: the thinking state, result hierarchy, citations, tables, linked records, and export behavior.

Rippling AI working through its plan for 'Why were our overtime costs so high last quarter': reviewing the request, breaking it down, searching data, looking up schemas, querying by employee and department, and comparing quarters
The finished answer under a collapsed Thinking complete disclosure: overtime spend by department with hours and headcount, timing concentrated in November and December, and the top four employee drivers as linked names with amounts

The plan runs in view, step by step. Then the answer lands as a sentence with the receipts under it: totals by department, timing by month, drivers by name

The recurring shape is a plan you can watch, then a short statement, then the full result. Ask why overtime was high last quarter and you see the model break the question down, pull the data, and compare quarters before a number is on screen. Then the answer lands as prose a manager would actually say, with the line-item math under it.

That is the pressure I wrote about in AI needs receipts: if a number changes and the system cannot show why, nobody should believe it. I spent much of the year on the density of these results, and the work is in the details. Tables that hold up at scale, numerals that line up, one action per result, an export on anything someone might carry into a meeting. It is the discipline of designing for operators, pointed at a model.

Close crop of the thinking steps: a ring beside 'Understood @Michael Johnson as Michael Johnson', then 'Searching for fields related to employee', then 'Querying for Michael Johnson's direct reports', then an open ring beside 'Checking the available columns'
Each name confirmed as a record before a query runs
Close crop of the payroll table's Spot Bonus columns, Current and New: $200.00 to $300.00, $200.00 to $300.00, £152.04 to £228.06 on a highlighted row, $200.00 to $300.00, decimals aligned
Current beside new, decimals aligned, in the currency each person is paid
Close crop of the answer's drivers list: 'Top employee drivers (by overtime cost)' in bold, then four bullets, each an underlined name link followed by an amount: William Allen $714.00, Steven Zavala $696.00, Sophia May $693.00, Martha Sullivan $686.00
In this public example, names link to employee records, with each amount beside its name
Close crop of a results table's right-hand side: an Export CSV button above the header row Department, Passes Given, Later Failed, Later-Failed Rate, then rows of linked department names with their counts and percentages
CSV export for the table in this public example

Ambiguity is a question, not a guess

The most consequential decision was the least glamorous: the model is not allowed to guess who you mean. Type "Reassign @michael" and, before the request is sent, the composer resolves it against the real org. Five Michaels, each with a department. The person selects a specific employee record before sending.

The Rippling AI composer with 'Reassign @michael' typed, showing an inline picker of five employees named Michael with their departments, and a Work locations group below

Resolution happens in the composer, before the person sends the request

Asked to hire Aisha Mansour like the last Customer Service Specialist at L7, Rippling AI replies that it found two Level 7 options and asks which one, offering A. Management 7, B. IC 7, and C. Other as choices; the person answers IC 7

Two Level 7s exist, so it offers both and waits

Asked to show the Product team's salaries, Rippling AI says it cannot show the entire team's salary because it is not accessible with your permissions, then lists base pay for the asker's direct reports

The boundary first, then the part you are allowed to see

When the ambiguity is in the data rather than the name, the model asks instead of picking. Hire someone at Level 7 and there are two Level 7 tracks; it lays out both and waits.

The same discipline governs what the model will not show. Ask for salaries beyond your own team and you get the honest boundary, then the part you are permitted to see, because the model only ever queries as the person asking. The refusal is written to be useful, not defensive.

One grammar across the product

Rippling ships dozens of products, and its AI appears across HR, IT, Finance, Payroll, Talent, and Time. I designed a shared five-move grammar that those surfaces could apply with their own nouns while preserving the same model feel, safeguards, and handoff to a person.

  1. ProposeProposed changes require human confirmation before execution.
  2. Show the workIn these public examples, the plan runs in view and answers include supporting queries, reports, or linked records.
  3. Resolve ambiguityNames become records in the composer. Two possible answers means a question.
  4. Respect the boundaryIt queries as you. A refusal states the limit, then shows what it can.
  5. Stage for reviewThe change lands on the operator's review screen. A person confirms it.

Same grammar, different nounsPayrollHRTalentTimeFinanceIT

The shared grammar. Each surface changes the nouns while preserving the interaction model
Rippling AI answering which Engineering tech-screen interviewers advance candidates who then fail the next interview: a sentence naming the top interviewers, then a table of interviewer, title, department, passes given, later failed, and later-failed rate
Rippling AI answering which managers have the most pending time-entry approvals: a sentence naming James O'Connor, Lamar Foster, and Marko Kovac with their counts, a key insight, then a table of manager, department, pending approvals, average approval time, and completed approvals

Recruiting and Time, side by side: a sentence with the names linked, then the table, then Export CSV. Same shape, different nouns

Outcome

Rippling AI launched publicly in March 2026 as AI that answers exact questions from live company data and takes real action across HR, IT, and Finance, with every change staged for human review. The grammar is what makes that safe to say: it stages proposed changes for human confirmation before execution, shows its work, refuses to guess who you mean, respects the permission boundary, and hands the last step to a person.

Alongside the product work, I used AI and LLM prototyping tools in a lab-style process to generate, compare, and validate interaction variations. The product screenshots are cropped from Rippling's public launch materials and public AI product page. The commentary describes my design contribution and interpretation of these public examples.

Role
Principal Designer; sole IC through much of late 2025 and early 2026, working directly with the CEO
Scope
Chat UI, visual design, model feel, thinking states, and shared AI interaction grammar
Grammar
Propose, show the work, resolve ambiguity, respect permissions, stage for review
Shipped
Rippling AI, public launch March 2026
NextGoogle Android →