AI Platform
Rippling AI
AI that runs payroll, hiring, and benefits from inside the work — designed to make payroll changes inspectable before approval.
Rippling runs HR, IT, and Finance on one data platform, so AI can reach straight into pay, access, and benefits. As Principal Designer, I owned the Rippling AI experience: its chat UI, visual design, model feel, thinking states, and interaction grammar.

The brief was trust, not chat
Most enterprise AI in 2025 was a text box bolted onto software that already worked. People tried it twice, got a plausible paragraph, and learned to ignore it. Rippling's position was harder. HR, IT, and Finance share one data model and one permissions system, so AI here could actually do things: run a bonus through payroll, reassign a team, hire someone.
The same fact that made it powerful made it dangerous. Throughout late 2025 and into early 2026, I was the only IC designer on the product, working directly with the CEO. I owned the AI experience around that risk: how the model felt, how thinking appeared, how answers exposed evidence, and what a person had to see before they let software touch a paycheck.
Every action is a proposal
The first rule: proposed changes require human confirmation before execution. Hand it a spreadsheet of spot bonuses and ask for them in the next payroll run, and you get the exact table payroll will receive, one row per person, current and new amount side by side, and then it stops. That table is the hero image above.
Structural changes work the same way. "Reassign Michael Johnson's 10 least tenured direct reports to Janet Williams effective next Monday" has four things in it that could go wrong. The model shows how it read each one before it touches anything.

The request as typed, then the work: both names resolved, the fields it searched, the sort it chose
Then it hands off. The change lands as a review screen with every affected person listed, and nothing moves until a human presses Confirm.

Ten people, one Confirm. The AI's output is the operator's review screen
That sounds like a safety feature. It is really a placement decision. The AI's output is the operator's review screen, inside the job they were already doing. There is no separate AI mode to learn and no separate log to reconcile. When the staged table is right, approval is a glance. When it is wrong, the error is visible before it costs anything.
Exact answers, with the work attached
In these public examples, Rippling AI queries live company data under the requester's permissions and returns results with supporting evidence. I designed around that rather than hiding it: an answer is a claim plus the evidence for the claim, and both are first-class.
The overtime conclusion below is produced by the model from the data and skills available to it; I did not author that business analysis. My work was the experience that makes generated analysis inspectable: the thinking state, result hierarchy, citations, tables, linked records, and export behavior.


The plan runs in view, step by step. Then the answer lands as a sentence with the receipts under it: totals by department, timing by month, drivers by name
The recurring shape is a plan you can watch, then a short statement, then the full result. Ask why overtime was high last quarter and you see the model break the question down, pull the data, and compare quarters before a number is on screen. Then the answer lands as prose a manager would actually say, with the line-item math under it.
That is the pressure I wrote about in AI needs receipts: if a number changes and the system cannot show why, nobody should believe it. I spent much of the year on the density of these results, and the work is in the details. Tables that hold up at scale, numerals that line up, one action per result, an export on anything someone might carry into a meeting. It is the discipline of designing for operators, pointed at a model.




Ambiguity is a question, not a guess
The most consequential decision was the least glamorous: the model is not allowed to guess who you mean. Type "Reassign @michael" and, before the request is sent, the composer resolves it against the real org. Five Michaels, each with a department. The person selects a specific employee record before sending.

Resolution happens in the composer, before the person sends the request

Two Level 7s exist, so it offers both and waits

The boundary first, then the part you are allowed to see
When the ambiguity is in the data rather than the name, the model asks instead of picking. Hire someone at Level 7 and there are two Level 7 tracks; it lays out both and waits.
The same discipline governs what the model will not show. Ask for salaries beyond your own team and you get the honest boundary, then the part you are permitted to see, because the model only ever queries as the person asking. The refusal is written to be useful, not defensive.
One grammar across the product
Rippling ships dozens of products, and its AI appears across HR, IT, Finance, Payroll, Talent, and Time. I designed a shared five-move grammar that those surfaces could apply with their own nouns while preserving the same model feel, safeguards, and handoff to a person.
- ProposeProposed changes require human confirmation before execution.
- Show the workIn these public examples, the plan runs in view and answers include supporting queries, reports, or linked records.
- Resolve ambiguityNames become records in the composer. Two possible answers means a question.
- Respect the boundaryIt queries as you. A refusal states the limit, then shows what it can.
- Stage for reviewThe change lands on the operator's review screen. A person confirms it.
Same grammar, different nounsPayrollHRTalentTimeFinanceIT


Recruiting and Time, side by side: a sentence with the names linked, then the table, then Export CSV. Same shape, different nouns
Outcome
Rippling AI launched publicly in March 2026 as AI that answers exact questions from live company data and takes real action across HR, IT, and Finance, with every change staged for human review. The grammar is what makes that safe to say: it stages proposed changes for human confirmation before execution, shows its work, refuses to guess who you mean, respects the permission boundary, and hands the last step to a person.
Alongside the product work, I used AI and LLM prototyping tools in a lab-style process to generate, compare, and validate interaction variations. The product screenshots are cropped from Rippling's public launch materials and public AI product page. The commentary describes my design contribution and interpretation of these public examples.
- Role
- Principal Designer; sole IC through much of late 2025 and early 2026, working directly with the CEO
- Scope
- Chat UI, visual design, model feel, thinking states, and shared AI interaction grammar
- Grammar
- Propose, show the work, resolve ambiguity, respect permissions, stage for review
- Shipped
- Rippling AI, public launch March 2026