hey, i’m numAy 👋 i design products
mostly systems that refuse to let the wrong thing happen
translating predictive ai into defensible executive action
systematizing operational readiness before the point of failure
forcing cryptographic ground truth in zero tolerance regulatory environments
say hi, or tell me what you are working on

or find me on linkedin

Hi, my name is numAy and I get really annoyed when I push pull doors 🚪
which honestly sums up how I feel about messy software and poorly designed systems
I spend my time as a product designer, turning complicated enterprise data into clean, functional tools that actually make sense
When I am not building systems or writing code, you can usually find me working on music production 🎧 or exploring creative projects
I like building things that just work without making people jump through hoops 🙃
powered by lots of matcha 🍵 and fried rice 🍚
say hi, or tell me what you are working on 👀

or find me on linkedin

Selected work

Three systems where the design decision was the constraint.

A network of connections arcing across the earth at night

Translating predictive AI into defensible executive action.

Applied AI, model uncertainty, human in the loop scoring


/Tacilent

Role
Product Owner and Systems Designer
Team
Engineering, data science, business
Tools
Figma, Linear, Claude Code
Tacilent Command Center home with Oli the AI analyst and scored intelligence alerts
01

The executive TL;DR

The business problem

Enterprise leaders were receiving 8 week old risk audits that failed to provide operational context, leaving them paralyzed on multimillion dollar capital moves.

The system solution

A command center that processes unstructured intelligence, grounds it with verifiable citations, and links a proprietary severity score directly to mandated actions.

My role and stack

Product Owner. Prototyped in Figma, Linear, and Claude Code.

Tacilent Command Center home with Oli the AI analyst and scored intelligence alerts
Four jobs

Assessment, diligence, tabletop, simulation, named as jobs

Entry point

One analyst asking a question, not a wall of charts

Inbound

The day's threats arrive already scored and already priced

Outcome

Decision completion86%
Time to a decision60 min
Capital quantified$450M+
Clients closedVolvo, Atlanta Beltline, Andersen Global
02

The operational friction

A 100 page consultant deck warning of a "78% probability of failure" is chaos masked as data. It does not tell a Chief Risk Officer whether to kill an M&A deal or sign a contract.

During our initial user research across pilots like Volvo and Andersen Global, we uncovered three staggering statistics that defined the problem.

Finding 1, inaction
66%

of delivered risk reports resulted in zero immediate action.

Finding 2, low completion
34%

was the historical baseline for executive decision completion, stalled and flat.

Finding 3, velocity drag
8 wks

per manual risk audit cycle, leaving millions in capital exposed while waiting for clarity.

01

Are we impacted right now?

02

What exactly should we do about it?

03

What is the true cost of acting versus inaction?Financial loss, human safety, regulatory exposure or environmental impact, depending on what the company has told us it protects.

03

The structural logic

External telemetry is useless until it is constrained by internal corporate strategy. That rule set the shape of the pipeline.

EXTERNAL 7 DOMAINS INTERNAL TELEMETRY ALIGNMENT RISK APPETITE within tolerance, kept under watch ACTUARIAL QUANT + AIQ RAPID RISK ASSESSMENT the assessment re enters the loop, re scored on every new signal

Scroll to see the full pipeline

Node 1

Multi vector ingestion

Continuous programmatic ingestion across the 7 main threat domains and 22 sub domains, running parallel to internal enterprise telemetry.

Node 2

Internal alignment engine

The system cross references incoming external threats against the company's historical risk profile and strategic frameworks. Threats that fall within acceptable corporate thresholds are automatically downgraded.

Node 3

The actuarial layer

The normalized data bypasses standard text generation and hits a deterministic pricing engine. It calculates the exact Quant, actuarial dollar exposure, and assigns a composite AIQ score.

Node 4

The actionable surface

Renders the Rapid Risk Assessment, outputting only the financial exposure and the precise mitigation path.

I owned the domain scope, the tolerance rules and the move taxonomy. Engineering and data science owned the ingestion architecture, the matching models and the actuarial math underneath the score.

04

The decision layer above the tools

GRC dashboards, point tools and consultants each do one job. The product had to sit above all three, which meant positioning it on two axes at once.

correlated across domains single domain reactive predictive GRC DASHBOARDS TACILENT POINT TOOLS CONSULTING ENGAGEMENTS

Scroll to see the full matrix

Dashboards report what already happened inside one domain. Point tools go deep on one domain and stop. Consulting correlates across domains but arrives weeks late and never in dollars. The open quadrant was predictive and correlated, and it was empty.

05

Four capital states

The core architectural constraint: an AI score without a mandated action is just an opinion.

To make this actionable, we translated the proprietary AIQ severity score into four explicit capital states to force a decision.

AIQ score THE ONLY INPUT CRITICALAIQ 9 TO 10 Do not proceed Kill the deal, halt the deployment ELEVATEDAIQ 7 TO 8 Mitigate Restructure the contract before signing SOUNDAIQ 3 TO 4 Proceed with conditions Move forward under active monitoring CLEARAIQ 1 TO 2 Proceed Sign the deal

Scroll to see all four bands

The move is hard coded to the score. Drag the AIQ below and three of the four buttons go dead.

Try this, drag the score
AIQ scored Rapid Risk Assessment

A company in your pipeline moved into a tightening sanctions path.

Impact
One term sheet out
Move
Add a closing condition
Exposure
$1.4M at the current mark
8
Elevated
Odds of harm, priced 1 to 10
1510
The shipped AIQ scored assessment card showing impact, move and exposure above the score ring
Same card

The component above, as it shipped

Decision buttons

At AIQ 8 the UI disables Proceed and forces the mandated Mitigate workflow before a commit

Cost of inaction

The specific fallout, mapped to the client's pre configured operational priorities

Detail, shipped assessment card
06

Trade offs and engineering constraints

What data science asked for

Data science teams advocated for surfacing complete statistical transparency on the main dashboard. They wanted executives to see the raw feature weights and full probability distributions to "trust the math."

Why I rejected it

Showing raw statistics triggers analysis paralysis. We compromised by building an asymmetric, human in the loop trust system. Instead of showing the math upfront, I designed a strict Citation Engine.

A Rapid Risk Assessment claim with inline citation anchors, composite AIQ, gross exposure and remediation figures
Score first

The number leads, the analysis follows it

Provenance anchors

Inline citation tags that query the exact intelligence feed, proving the model is not hallucinating

Three numbers

Composite score, gross exposure, and the cost to close it, on one row

Detail, cited assessment
07

The cost of doing nothing

The third question needed a shape, not a sentence. Three postures off one score, each re running the real math.

AIQ trajectory chart forking into do nothing, recommended and stress test paths over 36 months
The fork

Six months out, where inaction and action separate

Today

One score, the anchor every path is measured against

Consequence

The recommended posture lands at AIQ 4, with the math re run

Detail, AIQ trajectory
08

The outcome

We completely replaced the 6 to 8 week static consultant audit with a live, verifiable command center.

Adoption
86%Executive actionability, up from 34%
Velocity
60 minTo a defensible decision
Scale
$450M+At risk capital quantified
Commercial
3Tier one clients closed after the redesign
28m ago

Strait of Hormuz transit disruption, seizures and GPS jamming

Vessel seizures and GPS jamming in the Strait threaten inbound feedstock and components. 2 to 4 week delays likely.

AIQ 9$2.4M to $4.8MCriticalGeopoliticalSupply chain
CritIncident

Tanker seizure and GPS jamming

Coordinates
26.57000, 56.25000
UTC timestamp
2026 06 23, 00:07:06
Data source
GDELT
Direct source link
NASA FIRMSAISStreamGDELTSentinel Hub

Executives now log in to a morning Command Center that instantly surfaces their top 3 customized threats mapped to exact mitigation paths. By translating abstract statistical uncertainty into cited, human in the loop decision scoring, we scaled executive actionability from a 34% historical baseline up to 86%.

09

Reflection

The job was translation. Data scientists need mathematical exhaustiveness. Executives need absolute simplicity.

A forced decision taxonomy on one side and verifiable citations on the other is what let both be true at once.

The open question

Where the boundary sits

Tacilent predicts today and the trajectory is agentic. When a system stops advising and starts acting, the design problem inverts: not how to help a leader decide, but when an agentic system should act on its own and when it should keep a human in the loop. Where that boundary sits, and how far a leader will trust a system to cross it, is the part I want to work on next.

/Xastra Command

Systematizing operational readiness before the point of failure.

Context aware governance, dual currency FX, dynamic readiness rendering


Role
Product Design Lead, 0 to 1 build
Team
Internal Operations, Engineering, Finance
Tools
React, REST APIs, Claude Code, Figma
Command · Readiness, next 14 days3 Sep, 08:14 WAT
9days
Mobilization, Vessel 4
14 October · 12 crew rotating offshore
3 not ready
Chidi BalogunNo driver assigned for transferLogistics
Chidi BalogunAccommodation not bookedLogistics
Ingrid SharmaPassport lapses inside the rotationHR
01

The executive TL;DR

Over $1.3M in monthly multi currency payroll and offshore vessel logistics was exposed because workflows were fragmented across spreadsheets, email and unstructured messaging.

I designed and prototyped Xastra Command from 0 to 1, an internal operations platform that introduces the intuitive design of readiness. It translates disjointed departmental data into a single, dynamically evaluated state machine that systematically governs multi currency payroll. It eliminated multi day manual reconciliation cycles and secured the pipeline by programmatically enforcing sequence compliance.

Scale
$1.3M+Monthly dual currency FX payroll secured
Velocity
100%Systematic sequence compliance enforced
Adoption
400+Offshore consultants and operational nodes managed
02

The operational friction

Answering "is this crew ready for payroll?" took days of manual cross referencing across three teams that could not see each other.

A logistics coordinator confirmed a vessel transfer in an email, an HR manager tracked passport expirations in a local spreadsheet, and finance executed a USD transfer off a chat thread. There was no single source of truth, so one miscommunication could pay a consultant who was never deployed, or send someone offshore with expired safety credentials.

050100
3 days

average time to confirm whether one crew was clear to deploy or be paid.

050100
31%

of blockers were caught before the date. The rest surfaced at the gate.

050100
4 days

of month end reconciliation across four spreadsheets and three channels.

03

The structural logic

The core architectural constraint: the intuitive design of readiness.

Rather than relying on operators to double check each other, the system dynamically calculates a unified readiness state. A payment or deployment cannot be authorized unless the logistics schedule, timesheet and HR compliance nodes synthesize into a verified ready state. Each role writes only to its own node and reads only what it is accountable for.

ROLE NODES, WRITE SCOPED SYNTHESIS GATED ACTIONS HRCredentials, contracts, bank details OperationsCertified hours, vessel deployment LogisticsDrivers, accommodation, travel Readiness state Recomputed on every write, scoped per role and per event Travel bookingRenders only on a clear credential Payroll executionRenders only on all three verified HELD Any node false, the action does not render A ROLE CAN CLEAR ONLY ITS OWN NODE. EVERYTHING ELSE ROUTES TO THE TEAM THAT OWNS IT.

Scroll to see the full model

04

Trade offs and engineering constraints

Graceful degradation over a brittle live dependency.

Finance requested a live API integration that locked the daily USD to naira rate at the exact moment of execution. I pushed back. Nigerian banking APIs time out under load, and an unintelligent fetch would freeze the entire run if the connection dropped. The system attempts the live rate, and if latency exceeds five seconds the UI transitions into an elevated manual input state with a two factor confirmation, so the pipeline never stalls on an external outage.

FX rate · September run Live rate unavailable
0s2.5s5.0s threshold

Banking API did not respond within the window. The run degrades instead of hanging.

A second confirmation is required before the batch unlocks.

05

The execution

Readiness is not one number. Each team is measured on what it actually owns, and Finance is measured on everyone else.

HR is credentials and contracts. Operations is hours and deployment. Logistics is drivers, accommodation and travel. Switch the role and the definition of ready changes with it. A team can clear only its own gaps, everything else routes to the team that owns it and waits.

Command · Readiness, next 14 days
0 of 2
Logistics readiness
Drivers, accommodation and travel for the October rotation
Not ready
Role scoped

Switching the role changes what readiness means, not just what is filtered

Own it or route it

A team clears only its own gaps. Everything else goes to the team that owns it and waits

Derived, not asserted

Finance has no readiness of its own. It inherits the other three and cannot override them

06

The outcome

The failure moment moved. Gaps that used to surface at the gate now surface with days of runway, inside a normal working week.

Time to answer readiness
90 secfrom 3 daysOne surface replaces the cross referencing
Blockers caught early
96%from 31%Surfaced before the date, not at it
Month end reconciliation
40 minfrom 4 daysOne traceable view, one click resolution

Before

  • Transfers confirmed in email, passports in a local spreadsheet
  • USD runs executed against fragmented chat threads
  • Coordination itself was the work, three teams chasing each other
  • Overpaid contracts and travel booked against lapsed credentials

After

  • Cross departmental dependencies evaluated programmatically
  • 100% sequence compliance with zero unverified payroll deployments
  • Finance does not chase Logistics, the state simply will not release
  • Every blocker named, owned, and routed in one click
What I would carry forward

Building the 0 to 1 prototype myself is what made the handoff safe. Pressure testing the data pipelines, the API integrations and the role based access logic before engineering touched it meant the team inherited a de risked system rather than a specification. The rule I would keep on any operational build: readiness is calculated by the system, never asserted by a person.

/LytBase

Forcing cryptographic ground truth in zero tolerance regulatory environments.

Enterprise resource planning, biometric integration, government regulatory compliance

Role
Product Designer and Technical Strategist
Team
Engineering, Compliance Operations, Enterprise Client (Exxon)
Tools
React, REST APIs, Figma, advanced data visualization frameworks
Scope
ERP, biometric integration, regulatory compliance
01

The executive TL;DR

The business problem

Executing enterprise training for clients like Exxon meant relying on human driven data collection in chaotic physical environments. That created a massive vulnerability. In regulatory compliance, human input is inherently fragile and a legal liability.

The system solution

I architected LytBase as a strict hardware to software translation layer. By forcing a direct integration between edge biometric scanners and our relational database, we engineered the human operator out of the data collection loop entirely.

The impact

We established an immutable chain of custody for enterprise data. By designing intentional systemic constraints, we guaranteed 100% audit readiness and insulated the enterprise from regulatory exposure.

My role and stack

Product Designer and Technical Strategist. React, REST APIs and Figma, working across engineering, compliance operations and the enterprise client.

02

The chain of custody

Every point where a person touches a compliance record is a point where the record can be disputed. The old path had four of them. The new path has none.

Under the legacy model an instructor asserted attendance on paper, an administrator transcribed it, a coordinator compiled it, and someone assembled the export. Four human assertions, each one a place an auditor can ask how do you know, and each one a place the answer is because somebody wrote it down.

LEGACY PATH Trainee attendsphysical presence Instructor assertssigns a paper sheet HUMAN ASSERTION 01 Admin transcribesinto a spreadsheet HUMAN ASSERTION 02 Coordinator compilesacross contractors HUMAN ASSERTION 03 Audit pack assembledby hand, on request HUMAN ASSERTION 04 LYTBASE PATH Trainee presentsfingerprint at the device Edge scanner capturesbiometric, on device NO ASSERTION POSSIBLE Hardware handshakedirect to the database NO ASSERTION POSSIBLE Relational recordimmutable, timestamped NO ASSERTION POSSIBLE Export generatedread from the record NO ASSERTION POSSIBLE

Scroll to see the full chain

Legacy path
4Points where a person asserts a fact, and therefore four places the record can be challenged
LytBase path
0The operator is outside the loop. There is no screen on which a human can claim attendance happened
03

Flexibility against systemic integrity

Field operators demanded a manual override. If a scanner lost power, they wanted to check trainees in by hand so a class would not be delayed.

It is a reasonable request and the operational logic is sound. I rejected it. Giving a human the ability to override the hardware destroys the cryptographic trust of the final government audit, because a record that can be entered by hand is a record that can be disputed by hand. One override button makes every record in the system a claim rather than a fact. We traded physical operational convenience for absolute digital integrity.

A scanner has lost power in Bay C, mid session
The same moment, with the button operators asked for and with the design that shipped.
Instructor · attendanceDevice offline 09:41
No reading captured for this session
The class continues. The record does not. Attendance for Bay C cannot be entered from this screen by anyone, at any permission level.
The reasoning

04

The outcome

An immutable chain of custody, enforced by systemic constraint rather than by policy or training.

The constraint is the product. A rule that says do not enter attendance by hand is a policy and gets broken under pressure. A system with no field to enter it in is an architecture, and it holds on the worst day of the programme, which is the only day that matters to an auditor.

Human assertions in the record
0Removed from the collection loop entirely, by design
Audit readiness
100%Guaranteed via hardware level biometric synchronization
Override paths shipped
NoneIncluding for administrators and the coordinator role
05

Reflection

The defining challenge was enforcing digital rigidity in a chaotic physical environment, and holding it when the people closest to the chaos asked me not to.

The override would have made the product easier to use and impossible to defend. Refusing it meant accepting that on some days the system would be inconvenient, and that inconvenience is the visible cost of a record nobody can argue with.

The open question

As edge computing and biometric hardware become increasingly invisible, the physical act of verifying attendance will disappear entirely. How do we design visual trust and operational transparency in a zero UI compliance system where human operators are completely removed from data collection, yet remain entirely liable for the final government audit?