ADDY RUTH
Staff / Principal Level Product Designer
Automation  •  AI  •  Industrial UX  •  Decision Intelligence
SYMPHONYAI SENSA / AML + FRAUD

Designing AI-Assisted Investigations Without Removing Analyst Judgment

A risk score could tell an analyst where to look without explaining what they would find there.

AI could prioritize suspicious activity, but analysts still had to investigate the evidence and own the conclusion. I led UX work across the investigation lifecycle, helping users move from alert to evidence to defensible decision without losing sight of why the case surfaced.

PRODUCT DESIGN · AI-ASSISTED INVESTIGATION

THE OPERATING MODEL

Detection began the workflow. It did not finish it.

TriagePrioritize attention
EvidenceUnderstand the trigger
InvestigationExpand and compare context
DecisionDetermine significance
DocumentationPreserve the reasoning

Workflow reconstruction, not an internal product screen.

The system could prioritize attention. Accountability still belonged to the investigator.

01 / THE TENSION

A recommendation without evidence created more work.

“High risk” was a starting point, not an explanation. Analysts needed to know which activity contributed, which entities were involved, whether the pattern was unusual and whether broader history contradicted the alert.

The challenge was navigating dense information without losing the investigative thread—not simply making a score more prominent.

The evidence surrounding a case
Alert + rationale
Why the case surfaced and which detection factors contributed.
Transactions + entities
Activity, amounts, dates, accounts, organizations and counterparties.
History + relationships
Prior behavior, connected activity and earlier case decisions.
Investigator findings
Additional evidence, interpretation and documented reasoning.
02 / THE DESIGN PATTERN

AI output was evidence, not a verdict.

The interface needed to distinguish what the system surfaced from what the investigator concluded. Observed activity, historical facts, inferred relationships, missing information and analyst interpretation should not accidentally look equally certain.

Explain throughout the workflow

Why was the alert created? Why is this evidence relevant? Why is the case prioritized? Why did the analyst decide this?

Preserve context through depth

Move from triage to focused review to deeper investigation without making each navigation step restart the reasoning.

Design decisions behind the pattern
  • Keep detection rationale near the investigative entry point.
  • Separate system evidence from analyst findings.
  • Support progressive depth rather than forcing every case through every view.
  • Make important evidence easy to revisit and reference.
  • Standardize investigation mechanics, not conclusions.
  • Show relationships that answer the investigative question—not every connection the database knows.
03 / WORKFLOW RECONSTRUCTION

Investigate a high-risk alert

Review the trigger, expand the evidence, compare interpretations and preserve the eventual decision.

Follow the investigation step by step
  1. Review the queue. Establish priority and basic case context.
  2. Open the case. Inspect the initial rationale and relevant activity.
  3. Review evidence. Examine transactions, entities, dates, amounts, history and contributing factors.
  4. Expand the investigation. Follow related accounts, counterparties, activity and prior alerts without losing context.
  5. Compare interpretations. Does broader evidence strengthen or weaken the initial alert?
  6. Document findings. Preserve significant evidence and the analyst’s interpretation.
  7. Decide. Close, continue or escalate according to the organization’s workflow.
  8. Keep the decision inspectable. A later reviewer can trace the signal, investigation, evidence and reasoning.

Conceptual workflow summary; not a claim that every step existed in this exact form.

04 / EVIDENCE → DECISION → TRADEOFF

More transparency also meant more information.

Evidence
Analysts had to interpret dense transactional and entity evidence after a model or rule surfaced suspicious activity.
Decision
Center the experience on an explainable investigation, not a score treated as the conclusion.
Tradeoff
Explanation increases transparency but can increase cognitive load. Layered evidence and preserved context make depth available without requiring it everywhere.
05 / LEADERSHIP + METHODS

Leading design while staying close to the work.

I managed two designers while remaining hands-on: shaping interaction approaches, reviewing workflow consistency, mentoring the team and partnering with Product, Engineering and domain experts.

Original design methods

Workflow / product requirements → information architecture → Figma interaction design → prototype review → engineering collaboration → iteration.

Historical method summary; exact delivery artifacts still need recovery.

How I would prototype it today

Investigation state model → synthetic case data → AI-assisted workflow exploration → coded investigation → test evidence, confidence and explanation behavior.

Proposed contemporary approach, not a historical LLM feature or an already-built investigation prototype.

What I would test
  • Can the analyst explain why the case surfaced and which evidence matters?
  • Can they distinguish system-generated evidence from analyst findings?
  • Can they identify missing or inferred information?
  • Can they follow related activity without losing context?
  • Can they disagree with the recommendation?
  • Can another reviewer reconstruct the reasoning later?

Evaluate whether assistance reduces investigative work or merely moves it elsewhere.

06 / REALITY CHECK

The model surfaced suspicion. The analyst established meaning.

Design could help

Prioritization, evidence organization, relevant history, relationship exploration, consistent mechanics, explanation and documentation.

Human responsibility remained

Interpreting context, resolving conflicting evidence, recognizing missing information and making and defending the final decision.

This page describes product-design and leadership work—not authorship of detection models, a fictional copilot or independently measured detection, investigation-speed or compliance outcomes.

TRANSFERABLE PATTERN

From recommendation to accountable decision.

Surface the recommendation → explain its basis → expose evidence and uncertainty → support investigation → preserve disagreement → document the decision.

Useful anywhere AI helps prioritize or interpret evidence but humans remain accountable for the outcome.

CONNECTED ACROSS THE PORTFOLIO

Different signals. The same boundary.

Related workSystem contributionHuman responsibility
Carrier MatchingRules and ranking narrow viable optionsBroker decides with relationship context
Equipment SignalsTelemetry exposes equipment conditionsEngineer interprets and coordinates action
Emissions Tracking & SimulationA model suggests possible trajectoriesUser interprets assumptions and uncertainty
AML / FraudA model surfaces riskAnalyst investigates and owns the conclusion

The system should reduce the cost of understanding evidence without hiding the limits of what it knows.

Material Flow connects the same principle to shared operational understanding.