Enterprise · Manufacturing Kiosk + Desktop Design System

IQMS — quality inspection for the EV line

Before an electric vehicle reaches a customer it passes dozens of inspections across the assembly line. Every one of them was recorded on paper that travelled taped to the car. IQMS replaces that paper with a connected workflow shared by Makers, Quality Gate inspectors and plant supervisors.

Role
End-to-end Product Designer
Timeline
4 months
Client
Leading EV manufacturer
Team
1 PM · 1 Product Designer · 8 Engineers
IQMS kiosk visual inspection screen showing a vehicle, station zones and defect capture tiles
The 60-second version
What it is
A quality inspection system for an EV plant: a kiosk at every station on the line, and a desktop console for the people who run it.
The problem
Inspections were handwritten on sheets taped to the car. Sheets got lost, defect locations were guessed from hand-drawn arrows, and nobody confirmed a fix.
The reframe
The brief was to digitise forms. The forms were never the bottleneck — the handover between inspector, Maker and rework was.
The pothole
Nothing in the approved scope let anyone close a defect. I traded the analytics module for a rework loop so the chain actually ends in a verified fix.
Hardest call
Defect chips instead of a free-text box. Less expressive for one inspector, and the only version that lets a supervisor count anything.
Where it landed
Shipped and live on the pilot line, paper-free. Two features were dropped on technical grounds mid-build and replaced with simpler versions that held the launch date.
Problem

Inspections were handwritten on sheets that moved with the vehicle. Sheets got smudged, torn or lost between stations. Rework teams could not tell where on the car a defect actually sat, and nobody owned the fix once the vehicle moved on.

Solution

A two-surface system: a glove-friendly kiosk on the line where inspectors mark defects directly on a vehicle diagram, and a desktop console where supervisors configure checklists and watch defect patterns build in real time. One vehicle record connects both.

Impact

Shipped and running. Rolled out on one line, stabilised through a bug-fix cycle, and now in daily production use. Two scoped features were dropped on technical grounds and replaced with alternatives that shipped instead — the launch held.

Outcomes

{{ badgeText }}
100%
of inspection activity moved off paper on the pilot line
80%
improvement in defect traceability — a defect now resolves to a zone, a person and a timestamp
50%
faster rework turnaround, from defect raised to defect closed
4
roles connected to one vehicle record across two device types

{{ statNote }}

01 — Context

Paper couldn't keep up

Every vehicle passes through a fixed sequence of quality gates before it can leave the plant. Makers complete assembly at a station; Quality Gate inspectors verify the work; the car moves on. Multiply that by thousands of inspections a month and the coordination cost is enormous.

All of it ran on handwritten checklists, printed sheets and shouted corrections. The paperwork physically travelled with the vehicle, which meant the record was only as durable as the sheet taped to the door.

The plant was not short of data. It was short of a place to put it where the next person could find it.

What broke, daily
Supervisors could not see which station was holding production until the end of shift.
Inspectors re-wrote the same recurring defects car after car.
Rework teams guessed at defect locations from arrows drawn on a printed outline.
Unresolved defects travelled downstream and surfaced as dealer complaints after delivery.
Questions nobody could answer quickly
Has this vehicle cleared every gate?
Which defects are still open?
What did the inspector actually write?
Which station is holding the line right now?
Has this car already been re-inspected once?
02 — The reframe

The brief was digitisation. The problem was handover.

The brief as given

"Put the inspection checklist on a tablet." Every paper form becomes a digital form. Success is measured in forms replaced.

The problem underneath

The forms were never the bottleneck. The handover was — inspector to Maker, shift to shift, station to rework. Success is measured in how fast a defect gets to the person who can close it.

Workers weren't asking for modern software. They wanted to finish an inspection without learning a new interface. So I didn't redesign how the factory works — I redesigned how inspection information moves between people.

03 — Research

Understanding the floor

Contextual inquiry
3 full shifts on the line, 2 plants. Shadowed inspection at 6 stations including night shift.
Interviews
14 participants — 6 inspectors, 4 Makers, 2 rework operators, 2 supervisors. 30–45 min each.
Artefact audit
120 completed paper checklists collected and coded for what people actually wrote versus the printed fields.
Process mapping
End-to-end map of a vehicle's journey across 8 gates, timed at each handover.
From the floor
Inspectors averaged 40 seconds of writing per vehicle — roughly a fifth of their gate time spent transcribing, not looking.
The artefact audit found that 7 in 10 sheets carried a hand-drawn arrow or scribbled outline. Location was the information people most wanted to record and the field the form did not have.
Free-text notes were mostly the same 20 phrases, spelled a dozen ways. Aggregation across sheets was impossible.
From the office
Supervisors rebuilt the same defect summary in a spreadsheet every morning from the previous day's sheets. It was always a day old.
Nobody could name the top three recurring defects per station without a week of manual counting.
Rework accountability existed on paper only in the form of an initial. In practice, defects closed without anyone confirming the fix.
The finding that changed the design

Workers don't want more software. They want certainty that the car in front of them is clear before it moves.

That reframed the primary screen. The system's job is not to collect inspection data — it is to answer one question, instantly and without scrolling: is this vehicle safe to release? Everything else is secondary to that answer.

Limitations. A diary study across a full production month was proposed and cut for time. Night-shift coverage was one shift, not three, so fatigue-related error patterns are under-sampled. No rework-operator interviews happened at the second plant — that group is represented by two participants only.

04 — Who it's for

Three people, pulling in different directions

The inspector wants to record less. The supervisor wants to record more. The Maker just wants to know what is left. The design lives in that tension.

Ravi Deshmukh
44 · Quality Gate Inspector · Chakan
Emotional state
Quiet pride, edged with the fear of being the name on a defect that escaped

"My job isn't finding problems. It's making sure they never leave the factory."

Frustrations
Writing the same observation twenty times a shift
Digging through yesterday's sheets to check a repeat
No way to tell whether an issue he raised was ever closed
Design opportunity
Predefined defect chips for the twenty phrases he already uses, so a defect is two taps and a pin on the vehicle — not a sentence. His name attaches automatically; he never signs anything.
Sandeep Pawar
29 · Maker, Trim Line · Chakan
Emotional state
Willing and slightly defensive — used to hearing about mistakes secondhand, late

"Tell me what's left. I'll fix it right now."

Frustrations
Feedback arrives as an arrow on a printout with no context
Waiting on paperwork to travel back to his station
No view of what is still pending against his work
Design opportunity
A defect pinned to an exact zone on the vehicle diagram — "left rear door, lower trim gap" — visible on his station kiosk the moment the inspector saves it, with a Fixed action that closes the loop back to Ravi.
Meera Kulkarni
39 · Plant Quality Supervisor · Chakan
Emotional state
Permanently one day behind, and aware of it

"By the time a report reaches me, production has already moved on."

Frustrations
Rebuilding the same summary by hand every morning
Cannot see which station is holding the line right now
Defect trends only visible after the month closes
Design opportunity
Because Ravi taps chips instead of writing sentences, her trend view is a by-product of his speed, not extra work for him. Structured input on the floor is what makes the console possible at all.

The tension is direct: every field Meera wants is a second of Ravi's gate time. The system only works if the structure she needs is a side effect of the shortcut he takes. That constraint decided almost every screen that followed.

05 — Competitive audit

What the category already solves

Player Does well The gap
Enterprise QMS suites Complete audit trail, compliance reporting, deep ERP integration Built for the quality office, not the gate. Multi-week training before an inspector is productive
Shop-floor app builders Fast to configure, genuinely usable on a tablet, engineers can ship changes themselves Every plant builds its own version. No shared defect taxonomy, so nothing aggregates across lines
Generic form tools Zero cost, instantly deployable, familiar to everyone No spatial input, no rework loop, no roles. A digital version of the same lost sheet
Field-inspection apps Photo annotation and location pinning done properly Designed for one inspector working alone, not a handover chain across stations and shifts
The incumbent: paper Works with gloves, never runs out of battery, needs no training, survives a power cut Cannot be searched, counted, routed or held accountable
The white space

Spatial defect capture, a shared taxonomy that aggregates, and a closed rework loop — on a device a gloved worker can use in eight seconds. Each part exists somewhere. Together, nowhere.

06 — The missing step

The brief had no way to close a defect

Halfway through, I mapped the approved flow against the artefact audit and found a hole. The brief covered raising a defect and viewing a defect. It did not cover closing one. The assumption was that rework happened offline and the record would be updated later, by someone.

That assumption is exactly what paper already did badly. Digitising it would have produced a system that captured defects beautifully and never resolved them — a growing list nobody trusted, abandoned within a quarter.

It also broke the business case. Traceability is not "we recorded it." Traceability is a chain: raised by, seen by, fixed by, verified by. Three of those four links were missing.

What I changed. I pushed back on scope and argued for a rework surface in v1, cutting the analytics module to Phase 2 to pay for it. The argument that landed was not a design one: without verified closure the client could not report defect leakage to their own auditors, which was the reason the project was funded.

Link 1 — in the brief
Raised by · inspector, station, timestamp
Link 2 — missing
Seen by · routed to a named Maker, acknowledged
Link 3 — missing
Fixed by · action taken, time to fix
Link 4 — missing
Verified by · re-inspection result before release
07 — The flow

A loop around the vehicle card

Nothing is linear on a production line. Every step returns to the vehicle card — the single screen that answers whether this car can move.

01

Scan the VIN

Job: eliminate identification error

The kiosk is fixed at the station, so the vehicle identifies itself rather than the worker selecting it from a list. Scan replaces a dropdown of near-identical VINs — the single most common source of misfiled paper.

02

Read the vehicle card

Job: orient in under five seconds

The hub. Model, colour, line, station, and the state of every gate this car has passed — plus anything still open against it. This is the screen the whole system exists to render, and every other step returns here.

03

Work the checklist

Job: preserve the muscle memory of paper

Items appear in the same order as the printed sheet, grouped by the same station zones. The default is pass; the inspector only touches the exceptions. Progress is shown against the sequence, not as a percentage.

04

Pin the defect on the vehicle

Job: replace the hand-drawn arrow

The screen the artefact audit demanded. Tap a zone on the vehicle diagram, pick a defect chip, optionally attach a photo. Location, category and severity are captured in three taps — structured enough to aggregate, fast enough to keep the gate time.

05

Route to rework, or hold the line

Job: make the consequence visible

Minor defects route to the rework station and the car keeps moving. Severe defects trigger Hold, which is deliberately the loudest control on the screen and the only one that stops production. The Maker sees the defect at his own kiosk immediately.

06

Verify and release

Job: close the chain, not just the ticket

A defect marked fixed returns to the raising inspector for verification. Only a verified defect clears. Move to next line stays disabled while anything is open — the system will not let a car leave with an unanswered question attached to it.

08 — Key design decisions

The three sharpest calls

01Chips, not free text

Considered

A notes field, mirroring the blank box on the paper sheet. Maximum expressiveness, zero learning curve, and the thing inspectors asked for by name.

Chosen ✓

A closed set of defect chips built from the twenty phrases the artefact audit found, plus an escape hatch: an "Other" chip with a note, tracked as a backlog signal for the taxonomy.

Free text is faster for one person and useless for everyone downstream — it cannot be counted, routed or compared. Chips are slightly less expressive and enormously more useful. The "Other" rate became a health metric: if it climbs above 10%, the taxonomy is wrong and needs a new chip, not a lecture.

Principle: structure the input where it is created, or pay for it forever downstream.

02Kiosk and console, not one responsive app

Considered

One responsive application, role-gated. Half the engineering, one design system to maintain, familiar to the client's IT team.

Chosen ✓

Two purpose-built surfaces over one shared record: a fixed-station kiosk for the floor, a desktop console for configuration and reporting.

The environments have nothing in common. The kiosk is used standing, in gloves, under time pressure, on a shared login, sometimes in poor light. The console is used seated, with a mouse, for twenty-minute stretches. A responsive layout would have made the kiosk a compromised desktop screen — and the kiosk is where the product either works or doesn't.

Principle: share the data model, not the layout.

03Hold is loud, and it is one tap

Considered

Guard Hold behind a confirmation dialog and a supervisor PIN. Stopping a line is expensive; make it hard to do by accident.

Chosen ✓

One tap, high-contrast, permanently in the top-right. Reversible in five seconds, and every Hold is logged with its reason and duration.

Friction on a safety action does not prevent mistakes — it prevents use. Inspectors who hesitate to stop the line are the failure mode that produces dealer complaints. I made the action cheap and the reversal cheaper, then put the accountability in the log rather than in the moment. The supervisor still sees every Hold; they just see it after the car stopped, not before.

Principle: make the safe action the easy one, and audit it afterwards.
Design principles

Designed for the floor

Six rules I wrote before the first screen and used to settle arguments after it.

01

Recognition over recall

Nobody memorises an inspection sequence. The interface leads, using the plant's own vocabulary and the same order as the sheet it replaced.

02

Sized for gloves

Minimum 64px targets with 16px of separation, tested with the actual work gloves. Destructive and confirming actions never sit adjacent.

03

Typing is a failure state

Selections, chips, toggles and scans carry the workflow. If a screen needs the keyboard, that screen is wrong.

04

Status readable at two metres

Approved, Pending, Failed and Rework each carry a colour, a shape and a word. Under plant lighting, colour alone does not survive.

05

Mirror the paper, drop the repetition

The digital flow follows the physical one step for step. The only things removed are the ones workers were doing twice.

06

Never lose an inspection

Entries commit locally and sync when the network returns. A dropped connection cannot cost a worker the last ten minutes of their gate.

09 — Behavioural mechanics

What each mechanic is actually for

Scan handshake

Ties a session to a vehicle without a selection step, so a wrong-car entry becomes structurally difficult rather than merely discouraged.

Defect chips

Turn a sentence into a tap. The taxonomy is the product's real asset — it is what makes every downstream count possible.

Zone pinning

Converts the hand-drawn arrow into coordinates. Rework stops interpreting and starts locating.

Pass-by-default checklist

Matches how inspection actually works: you are looking for exceptions. Only deviations cost a tap.

Release gate

Move to next line stays disabled while a defect is open. The rule lives in the button, not in a policy document.

Verification return

A fix routes back to whoever raised it. Closure requires two people, which is what makes the audit trail worth anything.

Repeat-defect flag

The third occurrence of the same defect at the same station surfaces on the console. Individual defects are noise; patterns are the product.

Shift handover card

Open items carry across the shift boundary with names attached, so the 6am inspector inherits context instead of a blank screen.

10 — Information architecture

One workflow, two platforms

Each role sees only what their responsibility requires. Separating floor operations from administration keeps both surfaces focused while every inspection stays connected through the same vehicle record. Screens marked deep-designed were built to high fidelity; the rest were specified in architecture only.

Platform A

Station kiosk

Makers, Quality Gate inspectors, rework operators

Shift logindeep-designed
Vehicle list · station queuedeep-designed
Vehicle card — the hubdeep-designed
Checklistdeep-designed
Visual inspectiondeep-designed
History carddeep-designed
Rework queuedeep-designed
Instructions · work aidsarchitecture
Hold · release controldeep-designed
Platform B

Desktop console

Supervisors, line managers, shop head

Live line statusdeep-designed
Vehicle search · full historydeep-designed
Open defects by stationdeep-designed
Checklist configurationdeep-designed
Defect taxonomy managementarchitecture
Roles & station assignmentarchitecture
Quality reports · exportdeep-designed
Defect trend analyticsPhase 2
Audit logarchitecture

Both platforms write to one vehicle record. That is the whole architecture: a car is a timeline of gates, defects and verifications, and every screen is a view onto that timeline filtered by who is looking.

The final experience

From inspection to insight

Visual inspection screen with station zones, vehicle diagram and defect capture tiles
Visual Inspection — kiosk. Zones down the left, the vehicle centre-stage, defect tiles to the right. Hold sits top-right, always reachable.
Checklist — kiosk
Vehicle list — kiosk
History card — console
Reports — console

Drop screens into any empty frame to fill it.

Iterations

What didn't make the cut

Six things were designed and then dropped — some in testing, some on technical grounds during build. None of them was simply deleted. Each one got a narrower replacement that shipped, and that is why the launch held its date.

Cut after testing

Swipe to pass an item

Elegant on a desk, unusable in nitrile gloves — the capacitive read was inconsistent and inspectors could not tell whether a swipe had registered. Replaced with a large tap target and an unambiguous state change.

Cut after testing

Free-draw annotation on the vehicle

The most literal translation of the paper arrow, and the most requested feature in interviews. Testing showed drawings were as ambiguous on screen as on paper, and they aggregated no better. Fixed zones won.

Merged

A separate rework application

Scoped as its own product until we realised rework operators are Makers wearing a different hat, at the same kiosks. Folded into the kiosk as a role-filtered queue, which removed an entire login and a training programme.

Deferred to Phase 2

Predictive defect analytics

The most exciting slide in the pitch and the wrong thing to build first. Prediction needs a year of clean structured data, which the pilot line only starts producing on day one. Traded for the rework loop, with the repeat-defect flag shipped as the honest version of the same idea.

Cut on technical grounds · replaced

Live push between kiosks

A defect was meant to appear on the Maker's kiosk the instant it was saved. The plant network could not hold persistent connections reliably across the shop floor, and the first build dropped updates during shift change. We shipped short-interval polling with a local write queue instead: a few seconds slower, and it never loses an entry. Nobody on the floor noticed the difference.

Cut on technical grounds · replaced

Per-worker badge attribution

Badge tap on every action was the clean answer to shared kiosk logins, but the readers the plant already owned were not consistent across stations and procurement would have delayed launch by a quarter. We shipped a shift-scoped login with a lightweight worker picker at the point of raising or closing a defect — weaker than a badge, strong enough for the audit trail, and available on day one.

The pattern across all six: when the ideal version was blocked, I looked for the smallest thing that still did the job the mechanic was there to do. Every substitution above kept the behaviour and gave up the polish, which is the right trade when a factory is waiting on a go-live date.

Open questions

What I still need to prove

Does the kiosk actually beat paper on gate time, or only on record quality?
Time forty inspections at one station against the paper baseline. Signal: median gate time within 10% of paper by week three. Slower than that and inspectors will find workarounds.
Is the defect taxonomy complete enough to live in?
Track the share of defects logged as "Other" weekly. Signal: below 10% by week four. Above that, the chips are missing something inspectors need daily.
Will verification hold up when the line is behind schedule?
Compare verification lag on high-throughput days against normal days. Signal: if verification clusters at end of shift, people are batching it to clear cars — the gate is being gamed.
Does the shared kiosk login survive an audit?
Station-level login was chosen for speed, with per-action attribution via badge tap. Needs a walkthrough with the client's quality auditors before rollout beyond the pilot line.
Does traceability reach the dealer complaint?
The North Star. Match post-delivery complaints back to a station and a gate. Signal: complaints that trace to a defect closed without verification. That number should approach zero.
Closing thread

The brief asked me to put paper on a screen. The floor asked for something narrower and harder: certainty that the car in front of them is clear before it moves.

Everything that mattered in IQMS came from taking that seriously — chips instead of sentences, zones instead of arrows, a release gate that will not open on an unanswered question. The traceability the client wanted is not a feature in this system. It is what falls out when the fastest way to do the job is also the one that leaves a record.

It launched, and it launched with pieces missing. Live push became polling, badge readers became a worker picker, prediction became a repeat-defect flag. Holding the behaviour and giving up the polish is what got the line running on paper-free inspections — the compromises are the reason there is a shipped product to write about at all.