All systems nominal.

TEMPER: ground control for one autonomous survey aircraft.

Self-initiated concept. All data is simulated. Best viewed on desktop.

← WorkConcept · Operator interface

A drone ground-control interface designed for the minute things go wrong

Tempering is the step that makes steel hold up under stress. TEMPER applies the same idea to an interface: ground control for one autonomous survey aircraft, designed around the minute the link drops and the battery hits reserve, not the twenty minutes when nothing happens. A self-initiated concept, built live, with simulated data.

Client
Self-initiated
Role
Designer and engineer — interaction model, interface, simulator
Scope
48-hour sprint · 2026

Most control software is built like an engineering console

The operator of an autonomous aircraft spends most of a mission watching nothing happen. Then, inside a minute, the link degrades, the battery crosses reserve, and they have to decide what to do. Tired, on the clock, sometimes in bad light.

Most ground-control software isn’t designed for that minute. It’s designed like an engineering console: every value exposed at the same size, color used as decoration, warnings that pile up until they’re wallpaper. It works when nothing is wrong, which is exactly when it isn’t being tested.

TEMPER starts from the other end. Design the bad minute first, then make sure the quiet twenty minutes stay out of its way.

Six rules, each one visible on the screen

  1. Rule 01

    One-second read

    In one second an operator should be able to answer: is everything okay, and if not, what’s wrong? Master status and vitals live in a rail that never moves. A status edge across the top carries the same state into peripheral vision.

    Warning state. Master status, vitals and the status edge read before anything else.
  2. Rule 02

    Color means status, nothing else

    Green is nominal, amber is caution, red is warning. Structure is graphite. When everything is fine the vitals stay grey, the way a dark cockpit only lights what needs attention. SteelForge’s lime appears here only as nominal: the brand color becomes a meaning.

    Link and battery, nominal then warning. Color arrives only with a problem.
  3. Rule 03

    Shape and text back up color

    Every alert carries a shape (circle, triangle, octagon) and a plain-language label that says what it means and what to do: “Link weak: 2 of 5 bars.” Strip the color out and the screen still works, for colorblind operators and washed-out displays alike.

    The same alert stack, in color and with color removed.
  4. Rule 04

    Alerts escalate, they don’t pile up

    Three alerts at most, sorted by severity. Caution is steady amber. Warning fills the status cell red and pulses once, never a strobe. When the operator acts, warnings resolve instead of lingering.

    Nominal, caution, warning. The cell escalates by fill, not by motion.
  5. Rule 05

    Big, forgiving targets

    Primary actions are at least 56px tall and spaced for gloved or unsteady hands. Return to base can’t be undone, so it asks for a deliberate press-and-hold instead of a modal. Letting go early cancels. In a warning it becomes the recommended action, by contrast rather than by color.

    Return to base, partway through a hold.
  6. Rule 06

    Night mode protects dark adaptation

    Every step drops in luminance, nothing renders pure white, the map dims, and a brightness control sits in the rail. It draws on public human-engineering guidance for low-light displays (MIL-STD-1472 in spirit; this is not a compliance claim).

    Warning state at night.

Four states, one layout

Nothing moves between states. The same rail, the same stack, the same buttons, so what changes is the only thing the operator has to read.

NominalSurvey in progress. Nothing lit.
CautionLink weak. One amber item; nothing else changes.
WarningBattery at reserve. The cell fills; Return to base is recommended.
NightSame screen, every step down in luminance.

Every product has a bad minute

You don’t need an aircraft to have this problem. Every product has a moment when its user is stressed: the outage, the failed payment run, the deploy at six on a Friday, the deadline at midnight. It’s the moment users remember, and the one most interfaces are least designed for.

The rules carry straight over. Keep vitals in one place that doesn’t move. Spend color on meaning, not decoration. Say what’s wrong in plain language, and what to do next. Escalate instead of stacking. Make the irreversible action deliberate without burying it in a modal.

Design for that moment and the calm ones take care of themselves. It never works the other way round.

Next stepCS-01 / 06

Where is your product’s bad minute?

Tell me where your users get stressed. You get a read on what to fix first, what it would take, and what it would cost, before anyone signs anything.