My design responsibility
The customer experience
I shaped when learning happened, what evidence analysts could see, and how they could approve or stop a lesson. Model capabilities and API constraints informed those decisions.
Sublime Security · ASA Lesson Store
I designed how analyst corrections become reusable lessons, with clear controls for when ASA learns and how teams intervene.
00 · What is ASA?
ASA investigates suspicious emails and explains whether it thinks they're a threat. Security teams can review its reasoning and correct its verdict when it gets something wrong.
01 · The gap
ASA could investigate an email and explain its verdict, but a correction only fixed that one message. The agent did not retain the organization-specific context behind it.

02 · Defining the system
I worked across design, product, engineering, and ML to turn a model behavior into a learning loop customers could understand and govern.
An analyst changes ASA's verdict.
ML reads the message and its surrounding signals.
ASA creates an organization-specific lesson.
The lesson activates or waits for approval.
That context informs the next investigation.
The lesson feeds the next investigation
My design responsibility
I shaped when learning happened, what evidence analysts could see, and how they could approve or stop a lesson. Model capabilities and API constraints informed those decisions.
ML responsibility
The ML team owned lesson generation and evaluation. Together, we worked through the message-level signals and triggers the product could use.
03 · The pivotal decision
Eight enterprise design partners did not agree on one answer. That disagreement revealed two legitimate governance models.
One learning model. Two trust models.
The analyst's correction is enough to put the lesson to work.
A reviewer approves the lesson before it can influence future verdicts.
Organization-level control
Customers could choose either path or disable lesson creation globally. The product adapted to their trust model instead of forcing one definition of autonomy.
Capture context from analyst corrections.
Choose how your organization starts capturing lessons.
Start capturing lessons immediately.
Submit for AI committee review before activating.
Which corrections are eligible to become lessons
Pre-check “Store this lesson” when submitting a correction
04 · Making the system legible
I reduced a complicated backend into three questions a customer could answer without understanding the model.
Status, message volume, activity, and connected Automations created orientation at a glance.
The correction, source message, creator, and activation state made the lesson traceable.
Application history showed whether the lesson was recurring context or a one-off to deactivate.
Trigger logic, creator, and lesson state in one view.
Recent applications connect the lesson to the messages it influenced.
05 · Learning through rollout
Private beta, public beta, and GA each answered a different design question.
01 · First release
A bare settings page showed ASA's connected Automations, their active or passive state, and a basic table of captured lessons.
What I learnedThe early surface let design partners react to the learning model before the team invested in a finished dashboard.
Capture context from analyst corrections.
Choose how your organization starts capturing lessons.
Start capturing lessons immediately.
Submit for AI committee review before activating.
Which corrections are eligible to become lessons
Pre-check “Store this lesson” when submitting a correction
02 · Second release
This release added message-ingestion and lesson statistics, disagreement visibility, a lesson detail view, and the first complete governance controls.
What I learnedCustomers wanted different trust postures. Some preferred automatic activation. Others needed a second person to approve each lesson.
Your AI analyst for ambiguous messages.
Send User Reports to ASA
Send Suspicious messages to ASA
03 · July 2026
GA expanded the overview with activity trends and made each lesson traceable to its source, creator, state, and real application history.
What I learnedA lesson was only useful if a team could understand why it existed, where it was being applied, and how to stop it.
04 · August 2026
The lesson detail evolved to include a full message table, original-message drill-down, and clearer deactivate and reactivate actions.
What I learnedGovernance worked better when the evidence lived with the lesson instead of behind a link to another part of the product.
06 · Designing beyond ASA
I did not want customers to relearn the product every time they moved between agents. The layout became a shared design framework for the agent portfolio.
07 · Outcome
The work had just reached GA. I am grounding the outcome in what shipped and what changed through beta.
I helped shape the learning model and product experience from the first roadmap conversations through private beta, public beta, and general availability.
The shipped model supported automatic activation and secondary approval, so organizations could match learning to their team structure and trust model.
The agent page established a reusable anatomy for status, statistics, activity, Automations, learned behavior, and underlying data.
What I would carry forward
Let the learning disappear into the workflow. Keep the control within reach.