What we audit
Three axes do most of the work. Regulation falls out of these, not the other way around.
Stakes
Worst-case error cost — dollars, time, harm, legal exposure.
Reversibility
Time to irrecoverable — undo windows, dispute paths, cancel-before-pickup.
Cadence
Actions per user — frequency and habituation risk.
What you get
Scored rubric
3-axis × surface, one number per cell. Every screen gets stakes, reversibility, and cadence scores.
3–5 prioritized findings
One paragraph each: evidence, proposed fix, P-level (P0 ships this sprint, P1 next quarter monitored, P2 backlog).
One-page exec summary
The read for someone who has eight minutes between meetings.
When not to apply
The audit assumes the product has users with a worst-case to model. Skip it if either of these is you:
- Pre-PMF products — go run a usability test, not this audit.
- Pure-engagement consumer products (social, gaming, content) — the stakes axis is engagement-defined, not harm-defined.