skip to content

Your keyboard promises a never-empty suggestion strip; how do you decide the quality floor below which a degraded suggestion is worse than the safe default?

level: principalimportance: should knowfreq 36%

answer

  1. never empty is about rendering only
  2. a tapped wrong word costs most
  3. floor stated against the top rung
  4. budget the traffic spent degraded
  5. abstain below a minimum score

basics

~20 s

Price a wrong tap against a missed one. Express the floor as an acceptance rate the lowest rung must hold against the top rung, plus a budget for how much traffic may sit below the top rung; under the floor, render the neutral default.

solid answer

~50 s

"Never empty" is a promise about rendering, not about quality, and the two get confused precisely during an incident. A suggestion a user taps and then has to undo costs more than a generic one they ignore: it spends a correction and it teaches the user to stop looking at the strip, so acceptance stays depressed after the scorer recovers. I would turn the commitment into two numbers and one rule. A **floor**: the lowest rung's acceptance rate, measured against the top rung's, below which that rung is a defect rather than a fallback. A **budget**: the share of keystrokes that may be served below the top rung over a rolling window, spent like an error budget. An **abstain rule**: when no candidate clears a minimum score for this prefix, render the neutral default instead of a high-variance guess. The floor is signed by whoever owns the product metric, because it trades user-visible quality for availability.

go deeper

for a junior

Know that the strip always showing something is a product rule, and that the suggestion behind it can be far weaker than the usual one.

for a middle

Explain how each rung is measured separately, so you can say what the fallback actually delivered rather than that it delivered something.

for a senior

Quantify the degraded path: acceptance per rung, the share of traffic below the top rung, and a rule for when to abstain rather than guess.

for a principal

Own the trade: state the floor and the degraded-traffic budget together, argue who signs them, and accept the capacity a higher floor implies.

## The promise is about rendering "The strip is never empty" is an interface guarantee: the row of candidates always has something in it, so the layout never jumps and the user never sees a hole. It says nothing about whether the candidates are worth looking at. Teams slide from one to the other during an incident — the strip is full, therefore we are fine — and that slide is what a stated floor prevents. ## What a degraded suggestion actually costs The costs are asymmetric, and the asymmetry is the whole argument: - A suggestion the user **ignores** costs almost nothing. It occupied space they were not going to use. - A suggestion the user **taps and then has to undo** costs a correction, a broken sentence, and a small amount of trust. - Lost trust does **not** recover when the scorer does. Acceptance is a learned habit: users who were burned glance at the strip less often, so the metric stays depressed for a while after the incident and the recovery looks like an unexplained slow regression. That lag is why a floor is worth stating in advance. It is also why the answer is not simply "always render something": a rung whose suggestions are wrong often enough to be tapped by mistake can cost more than the blank space it replaced. ## Three numbers that make a floor operable 1. **A relative acceptance floor per rung.** State each rung's acceptance rate as a fraction of the top rung's, measured continuously. If the global frequency-list rung is expected to hold, say, 40% of the personalised rung's acceptance and it is measured at 15%, it is not a degraded service — it is a defect in the fallback path, and it should be fixed or removed from the ladder. 2. **A budget for time spent degraded.** The share of keystrokes served below the top rung over a rolling window, treated exactly like an error budget: normal while unspent, a reason to stop shipping when exhausted. Without it, a permanently elevated degraded share never triggers anything, because a level that does not change never crosses a threshold. 3. **An abstain threshold.** When even the cheap rung has no candidate above a minimum score for this prefix, render the neutral default — the safe, obviously-generic candidates — rather than the top of a flat distribution. A flat distribution dressed as a confident suggestion is the case where tapping is most likely to be wrong. | rung | what the floor commits to | what breaching it means | |---|---|---| | personalised scorer | the product's normal quality | an incident on the model or feature path | | cached prediction | close to the top rung, with older inputs | entries are too old or too coarsely keyed to be useful | | frequency list | a stated fraction of the top rung | the fallback is not worth rendering; fix or drop the rung | | constant default | recognisably generic, never wrong-looking | it is being mistaken for a personalised suggestion | ## Who signs the number The floor is not a serving decision, because it spends user-visible quality to buy availability and capacity headroom. It belongs to whoever owns the product metric, with the serving team supplying the measurements. The practical form is a standing commitment reviewed on a cadence — what quality we promise while degraded, how often we permit being degraded — rather than a judgement made under pressure during an incident, which is the one time it will be made badly. ## What a lower floor buys, and what it costs A low floor is genuinely useful: it lets the system lean on the cheap rungs more, which means less headroom has to be held for the personalised path and more load can be shed before anything user-visible breaks. A high floor forces the opposite — the top rung must be available nearly always, which is bought with capacity and with engineering effort on the feature path. Stating the floor and the degraded-traffic budget together is what makes that trade explicit instead of accidental, and it is the honest answer to "how available does the scorer need to be?": as available as the floor and the budget jointly require, and no more. ## The failure mode a floor prevents Without a stated floor, every rung looks acceptable because it renders. The ladder grows a rung nobody has measured, the degraded share drifts up, and the product's quality erodes in a direction no single alert covers, because each individual response was a success. The floor turns that erosion into a measurable, ownable number.

  • Why is the damage from a bad suggestion not over when the incident is?
    Acceptance is a learned behaviour. Users who tapped wrong suggestions look at the strip less, so acceptance stays depressed after the scorer is healthy and the recovery reads as a slow, unexplained regression. Measuring only during the incident understates the cost, which is the argument for a floor agreed in advance rather than best effort.
  • What stops the floor from being set so high that the fallback never fires?
    Capacity and availability. A floor only the personalised rung can meet means every wobble in the scorer becomes a late or empty strip, and you must buy headroom to make that rare. The floor is therefore chosen together with the degraded-traffic budget, in one decision: how often we will be degraded, and how bad degraded is allowed to be.
  • How do you tell a fallback rung that is merely degraded from one that is a defect?
    By measuring its acceptance rate against the floor stated for it. A rung performing within its floor is doing its job at a known, accepted cost. One performing far below is not a fallback at all — it renders something the user will not use and may tap by mistake, so it should be repaired or removed from the ladder rather than left as reassurance.

saying these in an interview costs you the question

  • Treats a filled strip as proof the promise was kept
  • States no floor at all and calls best effort enough
  • Assumes users ignore a wrong suggestion at no cost
  • Leaves the quality floor to the serving team alone
  • Thinks acceptance recovers the moment the scorer does