Executive Summary
"Aria," a specimen AI support copilot, audited end to end: marketing site → signup → onboarding → core chat → escalation → settings → billing → offboarding. Every screen, every state, three user postures. The product's core loop is genuinely strong; the surfaces around it — where trust is won and lost — are where the audit found its work. 23 findings: 3 critical, 8 high, 9 medium, 3 low.
1. Confidence without provenance — the assistant asserts; the interface never shows where answers come from. 2. Failure treated as terminal — error states apologize and stop instead of forking to recovery. 3. The edges don't match the center — billing, settings, and offboarding feel like a different, older product, and users notice exactly at the moments money and data are involved.
The Friction Map
Every surface of the product, walked and scored. The map is the reading order for the rest of the report — and the first honest picture most teams get of where their product actually leaks.
Promise and product are aligned — rare and worth protecting. Both findings are copy-level.
The empty first turn (critical) and four compounding moments that spend the user's patience before Aria has delivered anything.
Strongest surface overall; the critical is provenance — fluent answers with no source, no timestamp, no confidence signal.
The dead-end apology (critical): consecutive failures loop identical copy with no exit ramp — the churn moment of the product.
The "different product" problem. Plan changes bury consequences, the cancel path hides state, and data export is a support ticket. None of it is hard to fix; all of it is expensive to leave.
Two Specimen Findings
Same format as every finding in the report: evidence, the trust cost, a concrete fix, an effort estimate. These two are chosen to show breadth — the Critical Flow specimen shows depth on a single flow.
Finding 9 · High — the plan change that hides its consequences
Evidence: downgrading from Team to Solo silently drops two connected integrations and archives shared history. The confirmation modal says only "You'll lose access to some Team features." Which features, and what "lose" means for existing data, is discoverable only after the downgrade completes.
Why it leaks trust: billing is where users are most alert and least forgiving. A vague consequence at a money moment reads as intentional — even when it's just an unwritten modal — and it converts a plan change into a support ticket and a grudge.
Fix: the confirmation lists exactly what changes, item by item, with what happens to existing data next to each. If the list is long, that's information about the product, not the modal.
Effort: S — the data exists; the modal just doesn't say it. Priority: this sprint.
Finding 17 · Medium — the settings page that answers in a different voice
Evidence: in-chat, Aria explains model behavior conversationally. The settings page for the same behaviors ("temperature," "context retention," "fallback model") is raw vendor vocabulary with no descriptions. Two of the three sessions opened settings, changed nothing, and left.
Why it leaks trust: the product teaches users to expect explanations, then goes silent exactly where the consequential controls live. Users conclude the controls aren't meant for them — and the product loses the trust dividend of the controls it already built.
Fix: every control gets one sentence in the product's own voice stating what changes for the user ("Answers get more careful and more repetitive ↔ more creative and less predictable"). Aria itself should be able to explain — and link to — every setting.
Effort: S — copy. Priority: next sprint.
The Ranked Fix List
All 23 findings, ordered by user impact × engineering effort, grouped into three buckets your team can execute without me. Excerpted:
The empty first turn · the dead-end apology fork · the plan-change modal · settings copy · escalation transcript attach · two empty-state rewrites. A week of engineering that moves every trust metric the product has.
Provenance surfaced in answers · confidence thresholds with honest fallbacks · data export self-serve · unified error strategy · billing state visibility.
Every report includes this list. Features that demo well and test badly; the fastest wins are usually deletions.
What Else You Get
An annotated walkthrough of every audited surface with timestamps, the full 23-finding set in the format above, a 45-minute recorded walkthrough call where you're encouraged to argue with me, and two rounds of async questions over the following two weeks.
Client reports are confidential — showing you a real one would tell you exactly how I'd treat yours. The format, depth, and honesty above are real; "Aria" is a composite assembled from patterns that appear across shipped AI products. When the report about your product lands, it looks like this — about things only your product does.