Interfaces that pass review first time

One library, one set of rules, and a linter that catches the drift long before it reaches a design review.

unsloppable/Halden/Staged rollout

Staged rollout

Synced 4 minutes agoShare
  1. Change noticeSent to 34 surface owners00:00
  2. Soak in stagingTwo builds, no contrast regressions+2d
  3. Review callRecorded, decisions attached to the token+3d
  4. Board sign-offThree approvals required, two in+5d
  5. Adoption target94% of screens on the new value+8d
This rollout34Surfaces1,290Instances0Blocked
All checks passing24 / 196KCommands
In production at
HaldenCorristerVantryNorthmoorOstleyBrenlow

Pass reviewthe first time

Every component arrives carrying the decisions review already made: contrast ratios, focus order, spacing, the copy measure. Nothing is left for the board to send back.

94%
Screens approved at first review
1,840
Review hours returned each year
11 days
Cut from the average release cycle
First-pass approvals+68 pts

One consolefor the whole system

Five views onto the same system: what shipped, what drifted, what the review decided, and what the codemod is doing about it.

A token change ships on a schedule: notice, a two-day soak, the review call, board sign-off, then an adoption target.

Read the spec
unsloppable/Halden/Staged rollout

Staged rollout

Synced 4 minutes agoShare
  1. Change noticeSent to 34 surface owners00:00
  2. Soak in stagingTwo builds, no contrast regressions+2d
  3. Review callRecorded, decisions attached to the token+3d
  4. Board sign-offThree approvals required, two in+5d
  5. Adoption target94% of screens on the new value+8d
This rollout34Surfaces1,290Instances0Blocked
All checks passing24 / 196KCommands

Four movesfrom audit to enforcement

The first two weeks are audit and argument. Everything after that is the linter doing the arguing for you.

  1. 01

    Audit the estate

    We read every repo and score each screen against the library you already have.

  2. 02

    Draw the graph

    Tokens, components and surfaces become one graph, with a named owner on every node.

  3. 03

    Review once

    The board settles the open questions on one recorded call instead of forty threads.

  4. 04

    Hold the line

    The linter fails the pull request that drifts, before a reviewer ever opens it.

The controlsyour board expects

Single sign-on, scoped approvals, a signed trail behind every token change, and the procurement pack written before your security team asks for it.

Single sign-on

SAML and SCIM, with roles mapped from your directory.

Pinned releases

Every release is versioned; nothing moves under a running build.

Signed audit trail

Which token changed, when, and who approved the change.

Scoped approvals

Only the design board can merge a change to tokens.

Procurement pack

Security review, DPA and sub-processor list, already written.

Contrast budgets

Contrast and focus order fail the build, not the review.

The install base

Already running at this scale

312
Design organisations on the system
41,600
Screens under continuous audit
4.1M
Component instances held in step

Priced plainly.

Seats, not screens. Reading the library costs nothing; you pay at the point the linter starts blocking merges.

Studio

One team, one repo, the library and the audit both read-only.

$0/ seat
Start free
  • The full component library
  • One repo audited nightly
  • Contrast and focus checks
  • Community support

Company

A design practice running several products against one system.

$48/ seat
Book a walkthrough
  • Every repo audited nightly
  • Codemods and the linter
  • Review room with recordings
  • Adoption reporting
  • Single sign-on

Enterprise

Estates where the design board answers to a risk committee.

Bespoke/ term
Talk to us
  • Private component registry
  • Your own linter rules
  • A named design partner
  • Signed audit trail and DPA

Annual terms above twenty seats, with invoicing and a security review as standard. Nothing is metered by usage.

Before you sign.

The questions procurement sends after the demo, answered here rather than in another call.

01Where does the audit run?
In our cloud by default, in your own VPC on the enterprise term. The audit reads code and never stores a screen.
02Who owns the component code?
You do. The library publishes into your registry under your licence, and it keeps building the day the contract ends.
03How long until first release?
Two weeks for the audit and the graph, a third for the first codemod. Most boards hold the review call in week two.
04Can we bring our own rules?
Yes. The linter takes your rules as configuration, and your board can add one without waiting on our release train.
05What happens if we leave?
The registry exports, the codemods are yours to keep, and the audit trail leaves as a signed archive. Nothing needs rewriting.
06Who runs the rollout?
Your design board does. Enterprise terms carry a named partner from us; every other plan gets weekly office hours.
We stopped arguing about spacing in review. The decision arrives with the component, so the meeting is about the work.
Elena PriorVP of Design · Halden

Pass review.

The library and one audited repo cost nothing. The linter is where the money starts.