Interaction Discovery by Analysis of Ethical Properties

Abstract

This research explores current user experience design practice in the IT sector through empirical studies with practitioners. The focus is how interactions that are undesirable are identified, because they are contrary to the interests of the users. The practice area of interest is the discovery stage when designers are working to understand the user’s aims and identifying opportunities to achieve the desired outcomes.

Two research questions are explored: what methods are used in current software design practice to identify undesirable interactions during discovery activities, and how can designers be helped to structure their work in a way that assists them in identifying undesirable interactions.

Three empirical studies were conducted with user experience practitioners. The first used Ketso workshops to gather data on discovery goals, practices, and challenges. These informed the second study, which used interviews to gather data on attitudes and practices. Reflexive thematic analysis was used to analyse findings. Using findings from the first two studies and lessons from the existing literature, I developed a new method of anticipating undesirable interactions by identifying ethical properties that the design should preserve and considering how they might be lost. This Jeopardy Analysis method was evaluated in the third study through remote workshops with user experience design practitioners who were asked to apply it to an unfamiliar scenario and provide feedback on its use.

Findings about current practice from the first two studies indicate that user experience practitioners favour methods that build a shared understanding, but select them to suit the context. They tailor their approach, and actively explore and experiment with new methods. There was some recognition of the need to anticipate problems, but no methods were applied at the discovery stage, instead relying on usability testing.

The evaluation of the Jeopardy Analysis method found that it helped to challenge assumptions. Practitioners found framing the problem in ethical terms unfamiliar and difficult, but felt they could use it by themselves with more practice. The generic properties used for the evaluation were found to be too abstract, so the method step tailoring them for the domain would be an important part of its application.

The research contributes insights into the goals practitioners have for their discovery activities, and their current approaches to identifying undesirable interactions. It identifies practitioner interest in recent ‘consequence scanning’ approaches to anticipating problems that differ from current practice, and are associated with a more risk averse mindset. It contributes a novel Jeopardy Analysis method, and reports encouraging results from its initial evaluation.

Further work is needed to refine Jeopardy Analysis for use in industry, and to evaluate practitioner selection of ethical properties tailored to their domain and product. Its natural domain of use is seen as software applications supporting life in our increasingly digital society, where the general public are co-opted into our designs, and the ethical case for intervention is most compelling. Extension of Jeopardy Analysis to involve prospective users in co-analysis and design would further address the potential imbalances of power in current practices. It is suggested that teaching Jeopardy Analysis in higher education settings would contribute to learning outcomes in inclusive design, societal impact, the making of ethical choices, risk management, and the recognition of responsibilities.

Preface

The post-graduate research project that produced the Jeopardy Analysis Method (JAM) was motivated by a desire to understand why well-funded teams of talented engineers still delivered systems that had serious flaws in them. A full answer to that is still a research question, but if the reasons included a reluctance to anticipate problems, or an over reliance on testing with limited coverage, then an exploration of design discovery practice seemed a good starting point.

Beginning with an exploration of current practice, workshops and interviews were conducted with UX practitioners. The data from the workshops focussed on what the aims of a good discovery activity were, what people would like to be doing, and what got in the way. The interviews gathered more detailed information on what organisations did to share their understanding of the user needs, how projects were started and who drove that mobilisation to action, and what role anticipation had in their discovery process, if any. The interview transcripts were analysed, and the themes constructed in that analysis were then used as input to the design of the method.

A doctoral thesis is a strange document. It serves as both a description of a piece of academic research, and an artefact for summative assessment of the research student. The former needs to be detailed enough to understand the work and its findings, but the latter needs to meet the needs of the examiners and be concise enough to fit within their workload. That tension can result in some much needed context and background thinking being left out.

These pages are a version of the academic thesis. The text has been expanded where needed to better explain the ideas to an interested practitioner, and pruned of material that was only relevant for examination purposes. All the diagrams have been reworked from the LaTeX originals into a more web friendly form and their accessibility improved.

Table of Contents

Introduction

Background

The software usability approach set out by Gould and Lewis [130] in 1985, of a continual focus on users, empirical measurement of usability, and iterative redesign to resolve problems, is still the basis of most current practice as described by practitioners [129,53,363]. However, evaluations of usability testing methods have raised concerns about their reliability [183,242,327]. Even experienced usability professionals carrying out usability inspections will not find all the usability problems in the product [242]. Analysis of a design early in a product’s life, to identify undesirable interactions before it is built, is normal practice in the safety [87] and security [232] domains, but not in most other business contexts.

This research explores current user experience design practice in the IT sector through empirical studies with practitioners. The focus is how interactions that are undesirable are identified, because they are contrary to the interests of the users. The practice area of interest is the discovery stage when designers are working to understand the user’s aims and identifying opportunities to achieve the desired outcomes.

Undesirable interactions

In this research I focus on undesirable interactions that stem from incorrect and unchallenged assumptions at the design stage, that result in unwanted outcomes. These outcomes can range from the local, affecting a single user, to the global, affecting large numbers of users and potentially having consequences for wider society. I focus on outcomes within the scope of the application design, which will generally be those that directly affect its users.

Users are sometimes annoyed enough by undesirable interactions to comment on social media, as in the following example. Mobile phone applications are increasingly being used instead of paper ticketing, and train station barriers have been adapted to work with them. These applications also gather customer feedback, but sometimes ask for it when the phone is being used at a barrier, blocking the ticket code from being read [72]. Any assumption that users could always see the screen when using the application was invalid, as the phone is held screen-down to be scanned by the barrier.

Some examples are serious enough to attract media attention. In 2015, The Guardian reported that automatic image tagging at Google and Flikr was labelling dark skinned people as animals [178], and as recently as 2020 face recognition failures were still reported to be erasing black people from Zoom meetings and cropping them out of Twitter pictures [149]. Regardless of what technology was used to build these systems, the underlying problem was their discovery process as it did not adequately identify who the product was being built for.

Interaction discovery

Identifying undesirable interactions is not only a problem in software design, it is also a problem in drug design, where biological interactions might lead to adverse side-effects [253]. There it is called “interaction discovery”, and I have adopted the term to describe any methods that might be applied to a software design or product to identify unwanted interactions between it and its users, or with other software, or between the users themselves.

The earliest opportunity to start interaction-discovery is when designers are beginning to understand the user’s aims, identifying opportunities to achieve the desired outcomes, and visualising solutions that will provide a positive user experience. During this stage user researchers are planning and conducting research activities to gathering the information needed. These early design activities are described by Torres [363] as discovery.

Definitions vary, but the term discovery is widely adopted by practitioners, and by the GDS in its training material [131]. Discussion of discovery as a distinct activity is less common in the academic literature, due to the limited research into design practice in industry. Reviews of practitioner oriented ‘grey literature’ [246], and recent case studies, show a variety of prefixes in use distinguishing the aims, such as design discovery [44] and product discovery [53], or the methods, such as lean discovery [57] and continuous discovery [363]. For the purposes of this study, those distinctions are not significant, as practitioners may select from several authors when tailoring their own approach.

Usability inspection [251] methods such as heuristic evaluation and cognitive walkthroughs, which require expert evaluators, and usability inquiry methods, that involve current or prospective users to gain insights into how they will use it, require at least a detailed design and usually a prototype of some kind, so cannot be applied until sufficient discovery has been completed. Methods that try to anticipate problems, such as “consequence scanning” [45], are now emerging but do little to frame the problem or provide the scaffolding that I believe, based on my own past experience of safety analysis, that practitioners will need in order to identify undesirable interactions and address them early enough, before they are embedded in the design and expensive to resolve.

With current methods of framing [172], discovery activities do not usually consider whether any interactions implied by the design might be harmful or place the user in jeopardy unless the problem is potentially a safety or security issue. Finding that undesirable interactions are often not considered in advance, the present work aims to integrate the anticipation of undesirable interactions into discovery.

Ethical properties

The ethical property that engineers are most familiar with is safety, and whole professions exist to establish and assess it. Other whole-system properties are important enough that the law demands them, such as equity and proportionality, or are associated with particular circumstances, such as dignity in healthcare. Considering different experiences of a design, centred on these properties, is general enough to use early in the design process, and refinable enough to build into detailed service blueprints.

Study scope

This thesis concerns UX design practices used in industry. Safety and security issues may overlap with UX and share a common basis, as I discuss later, but generally their impact means they require different methods. In framing the research questions, I focus on interactions that the intended users will consider undesirable. There are circumstances where designers and users will disagree on which these are, but recognising the imbalance of power between them I have taken the side of the user. Malevolent use belongs to the security domain. Knowingly reckless or malevolent design [136,137] is likely to be unethical if not illegal, and would not be avoided by further methods of discovery. My focus is the inadvertent and accidental.

Assumptions about how long software would remain in use led to urgent work before 2000 to correct leap-year calculations and date formatting [103], and that kind of problem will continue to appear. However, I do not address legacy issues as it would be unusual for a design to include an explicit ‘sunset clause’ setting a finite life for its use, and I wish to focus more on challenging assumptions about ‘who’, and ‘why’, and ‘how much’ rather than ‘when’ as the important questions.

Assumptions can be embedded in data, and can result in unfair outcomes. For example, when predictive models are applied to policing and probation services [30,49], feedback loops could reinforce previous patterns [241]. Using research data from a context shaped by historical unfairness requires particular care, and skills from other disciplines, so is outside the scope of this thesis.

The problem addressed by this research concerns emergent properties and non-functional qualities, the need to be resilient and adaptive under change, the need for new structuring schemes to separate concerns about correctness and efficiency and desirability [95], and the need to adapt methods to support rapid non-classical styles of software development: five of the key areas for software engineering research highlighted by Finkelstein and Kramer [113].

Motivation

Professional challenges

The programme of study that produced this thesis followed twenty five years of professional practice as a scientist, consultant, and senior engineer. While researching better systems for air traffic management and collision avoidance, and assessing the effectiveness and safety of fighter aircraft, I encountered challenges that existing approaches struggled to cope with. My hope was that techniques developed to provide a better experience might usefully be applied to improving safety. During the study described here, it became apparent that the reverse might be the case: that safety thinking might contribute to improving usability.

As an independent observer, my flight test reports were often different from those made by the company, because our observations are a product of our current focus of attention [124]. The test engineers were focussed on whether their functional tests were passed, whereas my focus was how it worked and how it might not work when, for example, flown by a less experienced pilot. I was concerned with the non-functional properties of the system, and whether the non-functional goals had been met. Primarily, these were safety goals, but in some contexts safety can be inseparable from effectiveness and usability.

Understanding the consequences of human-computer interactions starts with one-to-one interactions of one user with one feature but how one interface works creates expectations of other interfaces, and if those expectations are not met then misunderstandings or harmful misuse may result. These second order interactions can be important when our intentions are communicated more widely to third parties, and contribute to their situation awareness. In the past, dependencies like this were addressed through the training that specialist operators received. Mass participation has brought them into the mundane software used by the wider population, for example on social media platforms when bookmarking behaviour is confused with approval [230].

So, the challenge was to find a way of discovering unwanted interactions that could be applied early enough in the product life to avoid rework, which would scale up to more complex designs developed at greater pace, and which all the members of a cross-disciplinary team could participate in and understand. The nature of this challenge is further developed in Chapter 3.

Knowledge gap

The knowledge gap that is explored by this study is what current software design practice does to identify unwanted interactions, and how that might be addressed as part of the design discovery activity when the team is developing its broader understanding of the problem to be solved.

The mechanistic view of safety that was developed for hazardous industries assumes that harmful events have causes that can be readily identified and prevented. It aims for robustness, where failures are to be eliminated, and safety is achieved when tolerably few things go wrong. Many modern systems are too complex for that assumption to hold [194], so a more proactive approach has developed that aims for resilience, where success is maximised, and safety is achieved when as many things as possible go right [154].

A proactive approach to avoiding unwanted outcomes tries to anticipate them by looking for patterns of failure rather than individual events, and assumes that both success and failure arise from the same working practices through pragmatic adjustments and variations in performance rather than by ‘unusual’ mistakes. That makes it as important to understand how organisations get things right as how they “drift into failure”, as Dekker puts it [89]. Software engineers do not necessarily have the ethnographic study skills to form that understanding. Some user experience practitioners and user researchers have the necessary skills, but often lack the time and resources, so may benefit from a supporting framework to reduce the overhead of creating a bespoke approach for their organisation and help them to reflexively study a process that includes their own work.

Aims and objectives

Aims

This study aims to understand how practitioners anticipate usability problems, and to explore a means of facilitating that anticipation that would be suitable for practical application in a typical Agile workplace.

Motivating question

Some industries have products independently assessed before their delivery to the ultimate customer and address shortfalls by imposing limitations on how they are used. The motivating question (MQ) that underlies this study arises from my participation in these evaluations, where I observed that experienced teams still deliver products that have undesirable interactions:

How can the software design process be improved to reliably deliver systems that maximise usability while minimising undesirable interactions

(MQ)

This research is an exploration of how teams establish a shared understanding of the product, what they do to identify undesirable interactions prior to the testing of a solution, and the role that the ethical properties of the design might play in their discovery.

Research Questions

The motivating question (MQ) is too broad for a single study, so the research questions focus on understanding current practice (RQ1) and exploring how that might be modified (RQ2) to anticipate and avoid problems.

Current practice RQ1

Within the broader question of what current practice is, my focus is how practitioners identify interactions with potential usability issues:

What methods are applied in current software design practice to identify interactions with the user that the intended users will consider undesirable

(RQ1)
Future practice RQ2

The initial literature review identified that discovery was under-researched, and discussions with practitioners had not identified any one dominant approach, so the future practice question needed to be flexible enough to reflect that. This was done by thinking more generally about the structures that designers create for themselves:

How can designers be helped to maintain a structure for their work that assists identification of undesirable interactions

(RQ2)

The information on current practice needed to address RQ1 was gained through two studies. Study 1 involved Ketso workshops with practitioners, and Study 2 involved practitioner interviews (Chapter 5).

After investigating current practice, RQ2 was explored by developing the Jeopardy Analysis method (Chapter 6) and then evaluating its usefulness to practitioners in Study 3 (Chapter 7).

Contributions to knowledge

This thesis makes an original contribution to knowledge in three principle areas: insights into how practitioners view discovery and conduct it in the workplace, the development of a novel approach to identifying potential harms by applying safety and resilience techniques to the ethical properties of the design, and an initial evaluation of this Jeopardy Analysis method. A conceptual map of the contributions from each study is given in Figure 1.1. The contributions are described in section 9.3.

A map of the studies and how they relate to contributions to knowledge
Figure 1.1Conceptual map of contributions from each study

Thesis structure

The conceptual links between the chapters are mapped out in Figure 1.2.

The research is introduced and motivated in Chapter 1, and the research questions stated.

A review of practice as described in publications and relevant recent literature is given in Chapter 2. Relevant findings are summarised and put in context.

In Chapter 3 the nature of the problem is further analysed and examples used to set out general categories of poor user experience that current methods often fail to pickup at the design stage. The challenges of doing effective discovery in an Agile working environment are identified.

The general approach and detailed methods used to explore the research questions are described and justified in Chapter 4.

Current practice is explored in Chapter 5. The use of Ketso community engagement workshops with retail practitioners is described, and key themes in their ideas about successful discovery methods are identified. These themes are further explored in structured interviews with practitioners from the civil service, design agencies, and contractors selling services into the public sector.

The jeopardy analysis method (a usability counterpart to hazard analysis in the safety domain or threat analysis in security) is introduced and developed in Chapter 6. The reasons for a focus on the ethical properties of the design are set out and explained.

The use of user jeopardy workshops is evaluated in Chapter 7. Application of the technique to a pre-prepared scenario is compared to a session using a problem suggested by the participants themselves.

A synthesis of all the findings and a discussion of the implications for each of the identified challenges is provided in Chapter 8.

The summary conclusions of the study, its contributions to knowledge, and my recommendations for further work are set out in Chapter 9.

A map of the thesis structure and how chapters relate to each other
Figure 1.2Structure and conceptual map of the thesis

Literature review

Challenges of discovery

Research design and methods

Current UX practice

Jeopardy Analysis

Evaluation of Jeopardy Analysis

Discussion

Introduction

This chapter discusses the findings of my research, relates them to prior work, and makes suggestions for further study. The findings of each of the studies are discussed, and the research questions answered. The use of ethics as a unifying concept is discussed and related to ethical frameworks by illustrating the relationship between safety and usability and security, and mapping technical risks onto ethical properties. The idea of jeopardy analysis is then related to prior work and related practices, and its relationship with usability heuristics illustrated by mapping them onto ethical properties. Finally, limitations and reliability are discussed and further work suggested.

Discussion of findings

The first research question asked how current practice identified undesirable interactions:

What methods are applied in current software design practice to identify interactions with the user that the intended users will consider undesirable

(RQ1)

The question was refined for Study 1: Ketso workshops to focus on discovery goals and practices:

The question was refined for Study 2: Practitioner interviews to focus on shared understanding:

The second question, addressed by Study 3: Jeopardy workshops, was how practitioners might be helped to identify undesirable interactions:

How can designers be helped to maintain a structure for their work that assists identification of undesirable interactions

(RQ2)

The findings for each of these questions are discussed in the following sections.

Discovery goal findings
Research questions

In order to gain insights into the reasons for practitioners method choices, the question was split into three sub-questions aligned with the workshop design, as discussed in section 5.3.1. Three questions were explored in face-to-face Ketso workshops: what is done in practice (RQ1.1.1), what would improve practice (RQ1.1.2), and what are the challenges (RQ1.1.3). No clear trends were identified in what is done, reflecting a diverse experience of discovery. Challenges centred around pressure on timescales.

Current practice themes

Two kinds of themes were identified in answer to the first sub-question. Firstly, the goals that the participants had in choosing discovery Methods, the Mindsets they saw as beneficial, and the Outcomes that they sought. Secondly, the practices that they considered to work well in Empowering them to succeed and in being Knowledge-led in their approach. These were summarised in Table 5.5 and Table 5.6.

Participants indicated a preference for data-driven approaches. These are widely used for marketing purposes [208] and to drive innovation [313] and are well represented in the literature [29,237] but analysis of the motivations for them is lacking. By identifying co-incident themes of certainty in how to proceed, having evidence to justify decisions to continue or terminate work, and a desire to be user-centred and have a validated understanding of the user, my findings provide possible reasons for the preference but further evidence and analysis are required to understand the commercial drivers for the collection of user data.

Knowledge sharing was a felt by the participants to be an important part of successful discovery and something that their organisations were good at. Effective knowledge sharing was found by Kuusinen et al [195] to be improved within teams that adopted agile practices but wider sharing with customers and colleagues across the company required more active motivators. This effect can be seen in my participating organisations. The Empowering theme included use of agile rituals such as stand-up meetings as a positive aspect of discovery but the Communication theme discussed below also identified cross-organisational communication as one of their challenges.

Aspiration themes

Three themes were identified in the things that the participants aspired to and felt would improve practice, in answer to the second sub-question. These would support their professional Curiosity, be further Empowering, and make better use of Knowledge, as summarised in Table 5.7.

Aspirations for deeper and broader discovery, and more continuous discovery processes, were linked to their desire for more flexible schedules and the time pressure they felt. A need for more discovery is consistent with the findings of a grey literature review by Münch et al [246] which gave inadequate discovery as a common reason for product failure. The aspirations for future practice discussed by the participants align with the aims of the emerging professional of research operations discussed by Metzler [235]. Efforts by the DesignOps and ResearchOps communities to develop a more scalable and sustainable approach to UX are ongoing, but case studies are beginning to appear in the literature, such as the Arizona University library case described by Blakiston et al [33].

Challenges and obstacles themes

Four themes were found in the challenges and obstacles to successful discovery discussed by participants, answering the third sub-question. Problems with Communication, local constraints on human and material Resources, obstacles resulting from human Behaviour, and problems embedded in an organisational Process were mentioned, summarised in Table 5.8.

Many of the challenges and obstacles cited were those that might be expected in any large organisation and were not necessarily specific to UX or discovery activities. Availability of the necessary skills and knowledge, and having the right mindset, were two that might be addressed by training and continuing education. A study by Cajandar et al of life-long learning processes in UX [54] found that practitioners thought methods were too complex and took too long to learn, that time pressure limited them to approaches they knew well, and that tool choice was sometimes limited by company policy on license purchases as well as current availability of licenses.

Methods versus tactics

The breadth of factors participants discussed suggested a diverse experience of discovery, and an ad hoc definition of success with no widely shared criteria within the organisation. This is consistent with previous work by Gray [133], that identified a flexible approach, and may reflect organisational procedures that embed tailored parts of published methods rather than adopting them as a whole or using an associated toolset, so reducing any ‘brand awareness’ of the method. Tactics that could be selected and combined according to the circumstances were preferred to a standardised method. In the descriptions of the practices they aspired to, there was a strong theme of empowerment and autonomy, and interestingly a desire to spend more time with stakeholders but also to be less constrained by their objectives. A desire to conduct both a broader and deeper discovery was expressed, which suggests that exercising greater autonomy and achieving the desired ‘user-led’ process might require a more time efficient approach.

Time pressure

A frequently discussed factor was time pressure. A focus on customer value and agility, leading to shorter development cycles as found by Clarke et al [65], implies a need for agility in user research and other discovery activities, so the mention of inefficient processes as an organisational challenge may also be related to a feeling of insufficient time. Currently, discovery and development are often separate streams of activity such as the dual-track approach described by Cagan [53]. Better integrated forms of continuous discovery that avoid sharp peaks in demand, such as described by Torres [363], were not in use by the participating organisations at the time of the workshops.

Challenging assumptions

An interesting omission from the data was vocabulary associated with rigour and challenge. This was missing from both of the sessions, and was not a point of difference between the participants with retail and academic backgrounds. If challenge is not considered an important part of discovery, that might be because it is more strongly associated with later stages of development, but more specific questioning was needed to determine how the emerging narrative is challenged during discovery, and this was included in Study 2: Practitioner interviews under research question RQ1.2.3.

Tailoring the workshop format

The standard Ketso pack assumes up to eight people per workspace, but my experience with the first session suggested this would be too many, so in order to limit the number of people around each one to three or four an additional workspace was purchased. The number of leaves written by the participating design professionals, who were experienced in similar activities if not with Ketso, was sufficient that freedom to arrange them as they wished might have been curtailed if we had not done so. It also allowed everyone to read each other’s ideas the right way up while seated, without walking around the table, so saving time.

For a complete cycle of questions starting with a definition of done, covering what works or does not, and revisiting the definition of success, a period of 90 minutes was barely sufficient to allow proper discussion. If the availability of meeting spaces is limited, the ease with which the felt workspace can be folded and packed up without disturbing the leaves could be exploited to hold a follow-up discussion session at another time or with the workspace mounted vertically on a convenient wall space rather than on a table.

Discovery practice findings
Research questions

Five question areas were explored in the interviews: how the next piece of work was chosen (RQ1.2.1), how information was gathered (RQ1.2.2), how their understanding was shared and challenged (RQ1.2.3), how much was enough to proceed (RQ1.2.4), and how that was translated into design choices (RQ1.2.5).

From audio recordings, interview transcripts were prepared, and a reflexive thematic analysis (see section 4.5) used to address the question of how practitioners achieve a shared understanding of the problem (RQ1.2) and how undesirable interactions are identified (RQ1).

The analysis identified key themes in the interview conversations structured around these questions, as discussed below. The answers to these specific questions were dependent on the role of the participant (see Table 5.10).

In answer to the first question on mobilisation, the business analyst was driven by what was next in the product backlog. The civil servants by one of three things: stakeholder initiatives, requirement changes or policy changes, or technical changes in the technology employed. The agency was driven by tenders they could bid for. The digital media designer had been driven by user generated data from experiments, the company having allowed any experiment to be applied to up to 1% of the users. The system supplier was driven by requirement changes and problem reports from customers.

In a study of new product development, Katzy et al linked mobilisation to recognition of an opportunity [179]. Kreuzer et al identified that digital technology has accelerated opportunity recognition by dissolving boundaries between companies and their customers, and thereby enabling more continuous interaction either directly or via the data their product use generates [193]. That effect was apparent in the statements from the digital media designer, but not from the other participants.

Answering the second question on engagement and discovery, the responses were consistent with what had been seen in Study 1: Ketso workshops where a range of methods were employed. The agency had a preference for qualitative methods, while the civil servants collected a broader range of quantitative usage data as well as qualitative data about the context, so used mixed methods. The system supplier was reliant on a documented requirement, but this could be quite vague so was supported by interviews with the customer to refine it. The digital media designer had a preference for quantitative methods, and commented that ideally quantitative and qualitative methods should be used together to produce combined insights, but knew of only one big technology company doing that.

A recent case study of user research in the National Health Service by Duda and Chearman [98] described how a new website was brought into use in five weekly sprints. The first sprint was based on the statement of work between the agency and the NHS, reflecting typical public sector mobilisation patterns described above, and included production of a user research plan. Repeated use of card sorting [86] and feedback from remote interviews was supplemented by analytical data from the previous website, in line with the mixed methods described by my civil service participants.

Responses to the third question on sharing included some of the same ideas as the Empowering theme identified in Study 1: Ketso workshops. The agency and civil service participants made regular use of team presentations and agile rituals such as sprint reviews to share insights and challenge findings from user research. They also tried to involve the whole team in user research activities, either as observers or scribes, so that they would have personal experience of the context and not be surprised by the findings. Use of open display, or the online equivalent, of the research outputs was also favoured. The business analyst had a similar approach but made more use of artefacts, ranging from sketches to short reports, to communicate findings. The digital media designer was less specific, but highlighted the need for user researchers to be present in design critique sessions to challenge departures from the findings. The system supplier used requirement documents, supplemented by prototype demonstrations and meetings, to share understandings with the customer and colleagues.

Challenges and barriers to effective knowledge sharing are well represented in the literature [123,10], but descriptions of the practices adopted in practice are lacking. Regular briefings to colleagues, as used by several of the interview participants, was one of the practices described by Hemon et al in a case study involving a large multi-national software developer [146]. Another they describe as “backlog grooming” resembles the practice followed by the business analyst participant, of incrementally refining work-to-be-done as information becomes available.

The forth question on iteration and how much discovery is enough gained similar answers from most of the participants, though articulated in slightly different ways as having a clear question, or knowing your next action, or understanding what the MVP or Minimum Viable Service (MVS) would be. For the system supplier, the important criteria was reaching a point where the client was happy with what was proposed. For the digital media designer, where change was driven by micro-experiments, the question did not arise in quite the same way as discovery was a less distinct activity.

The question of how much is enough is directly addressed by Hall [141], who also notes that unless it is based on recent user research specific to your current goals then prior knowledge may embed incorrect assumptions. Her advice, that the highest priority questions should be addressed, accords with the approach taken by most of the participants. Similar advice is offered by Gothelf and Seiden [129] but framed in terms of hypotheses about what design features will result in the desired outcome.

The final question on how choices are made and captured identified that designers are not always aware that other options were available, so choices are sometimes made by default, but it was felt to be part of UX research and design roles’ responsibilities to interrogate assumptions and challenge choices made if there were alternative options. The agency participant felt that people with an agile mindset were more conscious of making choices. Tactics adopted included involving the whole team to identify the riskiest assumption, and briefing choices made as part of regular team briefings. The system supplier had the interesting insight that they were well aware of their own choices at the design stage, but less aware of choices made by the development team while building it that might also impact the user experience.

Unconscious processes in design have been discussed in the literature, for example by Badke-Schaub and Eris [18], but not specifically the question of whether designers are aware of making a choice. Nor was any recent prior work found that documented how UX practitioners capture their design choices.

Shared understanding

The first key theme T1 identified that whatever methods were chosen to suit the context, the process of discovery was consistently driven by a need to build a shared understanding, and the challenges that practitioners experienced were linked to factors that frustrated that aim. Three supporting themes to T1 were identified.

Development of supporting theme T2 showed discovery activity was tailored to the context and had no fixed process, supporting findings by Gray [133] that practitioners considered mindset more important than process, and that the generated artefacts were diverse in content and had life-spans varying from single-use ephemeral sketches to high quality research outputs retained for the project duration. Participants occasionally referred to a discovery ‘phase’ but made it clear that discovery activity was ongoing and not confined to any one stage of the work.

Supporting theme T3 found a strong desire to challenge assumptions, and recognition that the equality of outcome needed to provide equity in the provided service did not mean uniformity, so design choices were made that focused on user groups with particular needs and prioritised removal of barriers over efficiency. The mention of personas was limited to contexts where the abstraction was useful for presenting inconvenient truths or including challenging user behaviours.

Supporting theme T4 captured the challenges of time constraints and funding mechanisms, and tactics used by practitioners to cope with them by prioritising discovery effort.

Anticipation mindset

The second key theme T5 drew out the implications for efforts to anticipate problems of current discovery practice and its integration into development. It found a growing awareness of the need to anticipate, and some early adoption of techniques based on patterns in previous failures, but found these to be passive and lacking in depth. The significance of impact on the user was not always appreciated, and there was a preference for responding to problems rather than avoiding them, and a belief in some practitioners that anticipation was impractical. A conflict was identified between the desire to conduct more experiments and the impact that an unconstrained empirical approach can have on design. Concerns were raised about design being disenfranchised and that if the risks of an experimental approach were not better managed that design would be reduced to a multivariate test, treating all experimental outcomes as equal regardless of the possible harm.

Ethical safety

The final key theme T6 developed the relationship between achieving a shared understanding and the approach needed to anticipate problems. It found that design choices were often locked in too early, not consistently documented or recognised as choices, and that usability was sacrificed to meet business objectives or to prioritise throughput. Addressing these problems was linked to the performance of individuals in the Product Owner role and the boundary-role played by business analysts. Recruitment choices were significant enough to be regarded as design choices, and the diversity of routes into UX presented opportunities for a multidisciplinary approach that would cope better with complexity by actively negotiating understanding across the team. Remote working was found to be well established and was also felt to have a role in breaking artificial barriers within the company. These interactions within the organisation reflect the importance of boundary roles in innovation described by Tushman [369], and the importance of negotiation in boundary spanning behaviour is consistent with the role of persuasion described by Vesalainen et al [377]. The benefits to information flow of remote working, as seen by my participant, were not identified in a recent study by Franken et al [115], but it is perhaps too soon to expect the available literature to reflect the full breadth of experience of the rapid increase in remote working seen in 2020.

The term ethical safety was synthesised as a way to describe how harm might be avoided by anticipating problems on the basis of design ethics and the ethical properties that the system should have. Achieving ethical safety was associated with a multidisciplinary approach, actively seeking a shared understanding, and developing a mindset that recognised the imbalance of power between designers and users and sought to address it by anticipation of problems. The term ethical safety is used in nursing ethics to refer to a practitioner’s independence to act according to their professional values [275] and to preserve respect for patients [203]. My generalisation to usability is in keeping with that use.

Evaluation findings
Research questions

The question was refined into two sub-questions RQ2.1 and RQ2.2 using the hypothesis developed in Chapter 6 that consideration of ethical properties of a design provides a stable basis of analysis that can be applied before discovery activities are complete:

Addressing RQ2.1, participants answering the second debrief question (Q2) said they thought it had helped them challenge their assumptions. Addressing RQ2.2, participants answering the third debrief question (Q3) thought that it did help them to uncover latent issues in the scenario.

Identifying underlying assumptions, and challenging them, is a key part of critical thinking. In terms of Bloom’s taxonomy [34], the aspects of critical thinking needed to uncover design issues are analysis of which components might interact, synthesis of what would happen to the system as a whole as a consequence, and evaluation of whether that is tolerable or not. Question RQ2.1 focuses on the analysis step, and asks if thinking about ethical properties assist that analysis, while question RQ2.2 focuses on the synthesis step.

Participant successes and struggles

When the use of different levels of abstraction in design was explored by Kokotovich and Dorst [190], they associated higher levels of abstraction with higher levels of expertise and ability to innovate. When they evaluated the ability of a multi-disciplinary team of students to move from ‘novice’ levels of abstraction to higher levels, they found that their participants did not move far from conventional views of the problem or develop higher level abstractions and were generally unsuccessful in stepping back from it. My choice of somewhat abstract ethical properties as the basis of the method was intended to concentrate on the essence of what was required, and give room for a more creative analysis of the problem. My participants relative success in doing so may be a result of the facilitation they received, and my prior decomposition of the abstract goal into more concrete questions, or their greater professional expertise in design compared to student participants.

The use of abstract ethical properties was problematic, to the extent that the participants found them difficult to relate to practical issues, but when translated into more concrete questions by the facilitator they were able to address most of the latent concerns in the scenarios without further prompting.

The generic properties chosen are potentially overlapping concepts, and to some extent this was done deliberately to prime the discussion for the next step, but it did appear to make it harder for the participants to associate concerns with properties or to suggest other properties that might be relevant to their domain.

The richest coverage was expected for concerns where there is an established regulatory requirement such as accessibility and data protection, or concerns where the participants might have direct personal experience. The team in the first evaluation had personal experience of part-time working and low-wage jobs paid by the hour, so fully covered all the concerns related to people on different types of contract experiencing a four day week differently. Both teams did well in covering the first equity related concern in their scenarios, namely health and accessibility.

The least well covered concern was Accountability Jurisdiction. Where the data is held, and therefore in whose jurisdiction it falls, may be less relevant to companies that predominantly draw customers from their home market, or may be delegated to information governance specialists within the company. Working from home might have been expected to raise awareness of these issues, and related concerns about applications like Zoom [2], but designers themselves may not have direct responsibility for them or discretion to choose. For delegated concerns, and those related to particular life-experience, the diversity of the team is important. This reinforces the current practice finding that ethical safety requires a multidisciplinary approach (see section 8.2.2).

The Proportionality property was intended to explore areas where the user contributes disproportionately compared to the benefit they receive in return. One aspect of this is how often actions need to be repeated, and the related issue of how long data is held. Neither team addressed these directly. The additional user burden of repeating information already provided, particularly if the request interrupts the intended action, may be unwelcome and in the case of compliance interactions such as cookie consent dialogues, Soe et al found that it can be a vehicle for unfair nagging and other dark patterns [329]. Repetition is not always addressed by usability heuristics [251], considered in information architectures [298], or included in measures of user burden [339], but without considering how often a question should be asked the related issue of how long the answer should be kept is poorly served. The participants did, partly or indirectly, consider what might be involved in correcting data and identified that having to erase all cookie data from your browser might seem a disproportionately costly way of changing your mind about one website, so a little more nudging from the facilitator might have surfaced the Repetition concern and with it Longevity, but this may be an example of issues that need explicit training to raise awareness of them.

Student practitioner use of Value Sensitive Design (VSD), as described by Chivukula et al [63] and reviewed in section 2.5.2, suggested that facilitation might be needed. The participants were unfamiliar with the method and did need the abstract prompts to be translated into more concrete questions, but once that was done no active facilitation was needed for them to consistently identify latent issues.

The property that the participants said they found most difficult, but also the most interesting from the point of view of things they were not currently thinking about so much, was Agency. Considering ways in which the user might lose confidence in their ability to influence outcomes or control the course of events, took more thought and had no obvious mapping onto things they were already doing, whereas Equity felt similar to accessibility concerns and Proportionality reminded them of data protection rules.

Ethics as a unifying concept

Hartmann used the values that a culture embodies as a unifying concept for the social sciences [144]. Applying this idea to UX design, the common ground between safety, security, and usability can be seen as the ethical properties that underlie these different views, as illustrated in Figure 8.1. The advantage of considering ethical properties when shaping the design is that they can be agreed early in the process and are likely to change only slowly over time.

TODO
Figure 8.1Ethics as common ground for safety and security and usability

I have contrasted ‘probability’ in the safety domain with ‘possibility’ in the usability domain, as it should not be necessary to quantify the likelihood of a usability problem to address it, though businesses may need to be convinced of that to justify corrective action. Similarly, judging quality of ‘experience’ can be a qualitative assessment rather than a quantitative assessment against a threshold for ‘tolerability’. How easily practitioners are able to relate properties to potential design features requires more evaluation, so this diagram will evolve as further research identifies other distinctions between the domains.

Ethical frameworks

As Lindberg et al found [212], practitioners are not in the habit of thinking about ethics yet, and find it hard to integrate into their practice, but practical means of addressing the issues are being actively discussed. The ethical field guide [258] produced by social change venture the Omidyar Network explores eight technical risk zones identified by the Institute for the Future [140,259,163]. These risk zones and their defining question are mapped onto the four generic ethical properties I derived in section 6.3 in Table 8.1. Many of them involve more than one property, and accountability is prominent.

Table 8.1Mapping of IFTF risk zones onto properties
Zone How might we ... Property
Surveillance protect privacy? Agency
Proportionality
Accountability
Disinformation promote truth? Accountability
Exclusion enable equity? Equity
Proportionality
Algorithmic Bias promote fairness? Equity
Addiction promote healthier behaviours? Agency
Accountability
Data Control enable transparency? Agency
Proportionality
Accountability
Outsized Power promote choice? Agency
Proportionality
Bad Actors promote civility? Accountability

Protection of users from surveillance has three related questions, as discussed by Andrew and Baker [7]: did I say you could have that, do you need it, and did you tell me you took it? These might need distinct interactions so it is useful to separate them. The same applies to data control. As discussed by Shu et al, measures to counter disinformation on social media have become necessary [323], so Twitter now inserts an accountability nudge and asks its users if they “Want to read the article first?” if they try to retweet a linked article they have not yet accessed. Exclusion and bias are both aspects of equity, but for exclusion it is useful to distinguish hard exclusion where access is impossible and soft exclusion where there is no desire to participate, as this may be because the pre-conditions of participation are disproportionate to the perceived value.

Contributions and further work

Summary of the research

Informed by a review of prior literature and a thematic analysis of current practice resulting from two empirical studies, an interaction-discovery process was developed that considers the ethical-properties that the design should preserve, maps these onto concepts that are meaningful in the problem domain, and uses the resulting provocations to anticipate and explore jeopardies implied by the design, as summarised in Figure 6.1. This was evaluated in a third empirical study.

Concept mapping and goal structuring were used to identify topics for an initial literature search (Chapter 2). Recognising a social context in which the ubiquity of software makes its use non-discretionary, the topic of design ethics was identified as important to the study. Within the wider practice of UX, the central role of user research in design practice was identified. A strong theme of knowledge sharing in Agile practice [195,263] led to the adoption of Wenger’s work on communities of practice [384] as a useful theoretical lens through which to understand the relationships between the roles in a multi-disciplinary team. The role of designers as choice-architects was explored, noting that they may be entangled in their own purposeful stories. While studies were found that involved practitioners, few were focussed on discovery or described current practice within the UK, and specific advice on suitable approaches for participants from the design community was lacking.

The description of the problem was refined and challenges identified using examples from daily software use (Chapter 3). A contrast between negative sentiment toward technology companies and positive sentiment about their products was reported in a public attitudes report by Doteveryone [238]. The threat to public confidence in the software profession has so far not led to the ‘revolt’ predicted by Wooldridge [391] but tech workers report negative impacts on their social interactions with friends [338]. Analysis of reported software project outcomes was used to demonstrate the lack of progress in addressing requirement shortfalls, and the distinction was made between market-driven strategic technical-debt and practice-driven tactical debt. The conflict between working quickly enough to maintain progress but carefully enough not to miss the potential for harm, while taking on larger and more complex projects, was identified and related to Rasmussen’s dynamic safety model [285]. Examples of poor quality advice, tactless prompts, conflicting interests and motivations, and ways that well intentioned features supporting one use case may negatively impact another potentially more important one were provided.

The researcher perspective, methods used, and reasons for their selection were described (Chapter 4). My professional background was summarised, the epistemological, ontological, my methodological positions stated, and reasons for adopting a qualitative approach set out. Data collection methods were described, and details provided of the reflexive thematic analysis [40] approach used. The evaluation of the jeopardy analysis method was described, using guidance on design science research [356] and cognitive work analysis [378].

An initial understanding of the goals, methods, and mindsets employed in the current practice of discovery, from the perspective of practitioners, was obtained in Study 1: Ketso workshops by a thematic analysis of statements generated in collaborative idea generation workshops. Findings from the first study informed the questions in Study 2: Practitioner interviews. Analysis of the interview transcripts enriched this initial understanding of priorities and aspirations and suggested how the approach might need to change in order to successfully anticipate problems (Chapter 5). Using those findings, criteria were explored for an anticipation method based on the ethical properties that should be preserved (Chapter 6). A method was constructed and evaluated online with practitioners in Study 3: Jeopardy workshops (Chapter 7). Main findings from these three studies were discussed and related to prior work, and further work identified (Chapter 8). The answers to the research questions are summarised in the next section. Identified threats to validity, and how they were addressed, and limitations of the research were discussed in section 8.5. Questions arising from this study that require further work are discussed in section 9.4.

Answers to the research questions

Motivating question

The motivating question MQ was

How can the software design process be improved to reliably deliver systems that maximise usability while minimising undesirable interactions

(MQ)

The purpose of the motivating question is to acknowledge the wider context of the research. Analysis of current practice for RQ1 found that up-front design thinking is sometimes concerned with possible solutions, informed by pre-conceived ideas about the problem as imagined, rather than an inquiry into the problem as experienced. That analysis provided further insights into what could be done differently and an enhancement to discovery practice was developed in response to RQ2. The resulting user jeopardy analysis method progresses the aims of the motivating question by:

  • identifying ‘undesirable’ as the loss of ethical properties

  • considering all user outcomes, not just those desired

  • supporting model-based approaches to usability testing

Progress in answering the MQ links findings to further work, as set out in section 9.4.

RQ1 – Current Practice

The first research question RQ1 was

What methods are applied in current software design practice to identify interactions with the user that the intended users will consider undesirable

(RQ1)

In Study 1: Ketso workshops and Study 2: Practitioner interviews, it was found that practitioners chose methods that build a shared understanding, and their challenges related to factors frustrating that aim. Method selection was context dependent, processes were tailored by the team to suit their circumstances, and communities of practice within companies actively explored and experimented with new methods and shared their experiences of using them. There was a growing recognition of the need to anticipate some kinds of problems, but in general agility in responding to a problem identified in testing was preferred to anticipation. Predominantly, no methods are applied at the discovery stage to identify undesirable interactions. Usability testing, once a testable product is available, is preferred.

RQ2 – Anticipation of problems

The second research question RQ2 was

How can designers be helped to maintain a structure for their work that assists identification of undesirable interactions

(RQ2)

This was refined into two sub-questions

These were addressed in Study 3: Jeopardy workshops by observing design practitioners using the jeopardy analysis method (Chapter 6) and requesting their feedback after doing so. The participants reported that structuring their discussion of interactions around people and the design properties important to them did help them challenge design assumptions. They found the framing of the problem in ethical properties unfamiliar but felt they could use it by themselves with more practice. Latent issues in the scenarios were identified, and the participants engaged in rich discussions around them, without further prompting by the facilitator, beyond that already provided by the pre-scripted questions and their explanation. This initial evaluation suggests that thinking about usability issues as the loss of an ethical property could help practitioners uncover them, but generic properties are too abstract so they do need to be mapped onto domain specific terms, and therefore the provocation design step of the method (section 6.2.2) is important to its application.

Contributions

Contributions to knowledge
Practitioner view of discovery

Thematic mapping of responses to questions about the goals, tactics, current aspirations, and challenges of discovery practice provided insights into how UX practitioners view discovery activities in a workplace context. These included key features of the desired mindset [133], the methods used, and the outcomes sought. Success in the participating organisations required approaches that were knowledge-led and empowering. For them, their aspiration to greater curiosity meant broader, deeper, and more continuous discovery activity with more diverse user groups. Obstacles to successful discovery were identified in communication, culture, and business processes. Factors imposing material and human constraints were identified with implications for education, training, and operational management.

Current discovery practice

Analysis of interviews, building on my earlier insights, provided an enriched understanding of current practice. This identified that shared understanding was actively sought, that prototyping and Agile rituals played a part in more effective sharing, and that alignment with their colleagues and their end-users was valued by designers. The desire to challenge assumptions was associated with an empirical approach, where practitioners value anticipation of problems, but believe they do so by usability testing. The analysis also identified ‘consequence scanning’ approaches to anticipating problems that differ from current discovery practice, and are potentially in conflict with it, which were associated with ethical design advocacy and a more risk averse mindset.

Development of Jeopardy Analysis

Development of the Jeopardy Analysis method offers an interaction discovery practice that can help practitioners to identify some undesirable interactions, and addresses some potential weaknesses in existing ‘consequence scanning’ approaches. It helps anticipate usability issues, in a manner consistent with the aims of Value Sensitive Design, while focusing on positive system properties that are stable over product life-times. It supports time efficient but rigorous analysis that integrates conceptually with existing safety techniques and tools.

Evaluation of Jeopardy Analysis

Evaluating the Jeopardy Analysis method with UX practitioners has provided initial indications that this is a practical approach, and a suitable basis for further research into interaction discovery techniques for general application.

Practical contribution

A method guide, worksheets and explanatory material guiding practitioners through a generic user jeopardy identification process were used under supervision during the study, and were available for independent use from the project website for a limited time after completion of the research.

Dissemination and publication

A paper describing the results of Study 1: Ketso workshops was presented at the British HCI conference in 2021 [291]. Further papers covering the findings of Study 2: Practitioner interviews and Study 3: Jeopardy workshops were planned, but I decided the individual studies were too small to justify a journal paper. Engagement with the practice communities that participated in the research was expected to use professional meetups and the project website.

Further work

Refinements for industry use

Initial feedback was encouraging but further contact with practitioners is needed to refine the method and gather data on how it might be used in a workplace context with real projects and commercial pressures.

Constructing domain-relevant provocations

My proposed jeopardy analysis method includes an activity (Phase 1) of translating the ethical properties relevant to the design into domain-relevant language when choosing provocations that will evoke a creative response to them. For evaluation purposes, my provocations were neutral and aimed only to pose questions rather than to trigger personal dilemmas as Ozkaramanli and Desmet did [262] or use aesthetically, functionally or conceptually challenging features as employed by Raptis et al [284]. As such they remained somewhat abstract. The difficulty of translating abstract concepts of user jeopardy into concrete concerns applicable to their domain and product, that was expressed by participants in the study, indicates that more detailed evaluation of this aspect is required.

Anticipation and discovery mindsets

The analysis here used a snapshot of practice as described by practitioners in 2020. With the introduction of the Online Safety Act (2023) the regulatory framework is changing [192,390,346] and technologies such as VR may complicate platform governance [32] and the design practices adopted [341]. Ongoing work is needed to track the development of this topic during a period of potentially rapid change.

Jeopardy analysts

Participants found it difficult to translate abstract concepts of jeopardy into concrete concerns applicable to their domain and product. A more detailed evaluation of this aspect of the method is required, which should focus on whether the its use in the workplace requires team members with an aptitude for abstraction to adopt a `jeopardy analyst' role analogous to the boundary role of safety engineers in multidisciplinary teams.

Cross-disciplinary awareness

Poor coverage of some concerns, particularly those which might normally be delegated to specific departments within larger organisations, requires more investigation and it is suggested that the utility of targeted cross-disciplinary awareness training should be assessed in a workplace context, where jeopardy identification has been integrated into the design process for a real project.

Bowtie diagrams and jeopardy models

Visualising the path of a latent problem from threat to consequence in a bowtie diagram may assist its anticipation, its understanding, and its recognition when it occurs. An evaluation of this would ideally follow similar projects from their inception, through the complete life-cycle to product retirement, so that the through life costs and benefits could be assessed.

Teaching jeopardy analysis

As discussed in Chapter 7, teaching Jeopardy Analysis in higher education settings would contribute to learning outcomes in inclusive design, identifying societal impact, making ethical choices, risk management, and recognising professional responsibilities.

Concluding remarks

This research is intended to benefit practice and enrich understanding of its UK communities of practice. It was only possible with the participation and encouragement of practitioners in Manchester and the wider design community.

Glossary

Bibliography

Index

Work in progress sign