Skip to main content
DebE
← Back to work
UI/UX2023

Sóra

A speculative safety tool built around a dangerous question: could you verify a stranger's past before you trust them - and should you?

View prototype →

A speculative biometric safety tool, built ethics-first - and named for the discipline of caution I grew up with.

At a glance

  • Role: Designer (team of 4)
  • Methodology: Lean UX, value-driven design
  • Tools: Figma
  • Shown at: Communitech, Waterloo, Ontario

I owned the organization onboarding and ID-verification flow, and led the depth pass on the criminal-records profile - the most sensitive screen in the product. Before any of that, I led the project's ethical evaluation, running the concept through cultural relativism and a set of speculative-design exercises so we knew what we were building, and who it could hurt, before we committed to building it.


Why Sóra

Where I come from, we have a phrase: look face. It means read the person in front of you before you trust them. The eyes, the posture, the thing they are not saying. It's not recognized as paranoia, it is seen as survival, and everyone learns it young.

Sóra is that phrase, turned into a product.

The Yoruba word ṣọ́ra means "be careful". It's not gentle advice, but an instruction. And the more my team talked about safety, the more I noticed how differently that word lands depending on where you were raised. In much of the West, the default is trust: people mostly do right, systems mostly hold, and caution can look like paranoia. Where I am from, caution is the baseline. That gap is the whole reason Sóra exists.

So when we sat down to pick a problem worth three rounds of sprints, we skipped the easy ones. We wanted the one that kept us up: how do you help someone make an informed decision about a stranger, before that stranger becomes a risk? Women and vulnerable people carry that question every day, mostly on instinct alone. What would it take to put a real tool in their hands?

Then someone said it out loud: a LinkedIn for past crimes. Verified records, biometrics, global access. And the room went quiet, because it was equal parts brilliant and terrifying. Half of us heard alarm bells immediately. Good. That is exactly the sound a speculative project is supposed to make. Our job was not to look away from it. It was to walk straight toward the discomfort and ask: could this be built responsibly, and should it be built at all?


Approach: ethics before pixels

So we did the ethics review first. Not last, not as a box to tick on the way out - first, before a single screen existed. Because if the answer to "should this exist" was no, I would rather learn it with a whiteboard than a working prototype.

We put the concept through four lenses, and picked them precisely so no single worldview got to be comfortable:

  • Cultural relativism - I led this pass, asking how the tool reads across cultures and life stages, because "safety" and "privacy" mean wildly different things depending on who and where you are.
  • Kantian ethics - were we treating people as ends in themselves, or as data points to be screened?
  • Friedman's envisioning cards - who are the stakeholders we are not picturing, and what values would this product quietly push into the world?
  • Tarot Cards of Tech, plus a "write the Black Mirror episode" exercise - where we sat down and deliberately imagined the worst, most dystopian version of the thing we were building.

That last one was the most useful hour of the whole project. Imagining the abuse cases on purpose forced questions we would otherwise have skated right past. What happens to someone with a cleared record? Who gets to scan whom, and with whose consent? What does this become in the wrong institution's hands? Those questions did not slow the design down. They were the design. They pushed us toward restorative-justice options for people trying to clear or amend their records, and toward hard limits on which organizations could touch the sensor at all.

We also hit a wall and named it out loud: this subject is far too sensitive to recruit real people to interview. You cannot ethically ask strangers to walk you through their criminal records for a class project. So instead of faking it, we said so, leaned hard on secondary research, and let the speculative methods carry the weight where real users could not.


A two-sided Product

A two-sided system. Sóra was never one app. It was a digital app married to a small physical sensor for organizations, each with its own consent model. Designing both meant staring at the same moment - a single scan - from two sides of the glass, with different rights and different risks on each.

Why a small sensor, and not a big machine. Here is a debate I did not expect to have. A large, expensive screening machine has a hidden virtue: the price tag itself gates out casual and bad-faith users, because only serious institutions can afford one. Tempting. We went the other way, and on purpose.

Because the people most exposed to this kind of risk are also the least resourced - and the risk is not abstract where I am from. Often the danger walks in through the front door as a new hire. Employ the wrong person and they do not just do the job badly; they empty the till, walk off with the client list, bleed the business quietly for months. In cultures where trust is expensive and hard to verify, "employ honest people" is not an HR nicety. It is how a small business survives the year. That owner - the one who cannot afford to guess wrong about who they let in - is exactly who Sóra was built for.

A big, costly machine "protects" that owner by pricing them out of protection entirely, locking safety behind hardware only large institutions can buy while the corner shop that needs it most goes without. So we chose a small, affordable sensor, and moved the safeguard off the price tag and into the design instead: identity verification, per-touchpoint consent, and hard limits on who can use it. Take away the cost barrier and you have to build a better one. That was the trade, made with eyes open.

[The cleanest hard data here is cybercrime, so treat it as directional. Small businesses are ~3x more likely to be targeted than larger firms, and cybercrime cost U.S. small businesses ~$2.4B in 2021 (CISA); cost is the #1 barrier to adopting security tools, cited by ~two-thirds of SMBs; by one estimate only ~14% are equipped to defend themselves (Accenture). It is cyber data, but the wall between cyber and physical crime is thinner than it looks - both usually come down to a trust failure, and the most common one is the wrong person given access from the inside. That is the crime Sóra is really about.]


What I designed

This is where a dangerous idea meets a cursor. Everything below was an attempt to answer one question in interface form: how do you build something this powerful without building something this reckless?

Organization onboarding & ID verification. I owned how organizations enter the system and prove who they are. The trap here is trust asymmetry: the organization needs to confirm an identity, but the person should never be stripped bare in the process. So I designed onboarding around scanning a government ID to kill manual entry, then wrote distinct consent models into every touchpoint - what an org can ask for, what the user has to approve, and what happens by default when those two collide. Consent was never a checkbox at the end. It was the load-bearing wall.


Depth on the criminal records profile. I led the detail pass on the single most sensitive screen in the product, and it is the work I thought hardest about. A record is not a yes or a no. So I designed for three truths - a clean profile, a profile with some activity, and the full drill-down on each individual offense - so the screen could hold nuance instead of handing down a verdict. The whole target was clarity without condemnation: enough to make a careful decision, shaped so it could never read as a sentence on someone's character.


Where it landed

We took Sóra to Communitech in Waterloo, and the reaction split exactly where it should have. Some people told us flat out: this should not be built - a tool like this is bad for safety and security, end of discussion. Others leaned in with the harder question: if you were going to attempt it, how would you do it responsibly? Both reactions in the same room, at the same time. Honestly, that was the most truthful outcome the project could have produced. A concept like this should divide a room.

Sóra stayed speculative, and that is the honest word for it. But the questions did not stay behind at the demo table. They are the ones I now carry into any product that asks a person to trust it with something that matters.


Reflections

The biggest design decision was whether to design it at all. Sóra taught me that on a high-stakes product, your first job is not the interface - it is the interrogation. The work I am proudest of here is not a screen. It is the week we spent deciding whether the screens deserved to exist.

__

Consent is an architecture, not a screen*.* On most products, consent is a modal you swat away. On Sóra, consent had to live in the bones - in who can see what, when, and why, and in the deliberate choice to make the tool reachable and then guard it by design instead of by price. Once you have designed for a genuinely dangerous idea, you never treat permission as an afterthought again.

__

Context decides what "safe" even means. Sóra exists because I was raised somewhere that safety is active, not assumed. Building it put words to something I now bring everywhere: there is no neutral, universal user. "Look face" was never paranoia. It is design research.