The takeout order is wrong. A flight’s cancelled. A package is delivered to the wrong address. The app crashes. No customer experience has a perfect track record.
You can try to minimize how frequently it happens, but you can’t remove all risk or completely shut out the outside world. What you need to design for is what happens the moment the experience breaks.
At Qualtrics' 2026 X4®, four teams shared how they plan for the breakdown. Some get ahead of the failure, others build the recovery in. Both approaches try to avoid a bad moment from turning into a lost customer.
1. Plan for failure before you ship (Bodine & Co)
Many teams design for the path where everything works, then get blindsided when things diverge from that path, or, when it falls off the path completely.
Kerry Bodine, CEO and Founder of Bodine & Co, argues that this is a choice, not bad luck. Both exceptional experiences and broken ones can be a result of the way systems are designed. They happen when we fail to anticipate possible failures or what could go wrong, and act on it before we launch.
Bodine uses a pre-launch exercise called consequence scanning. Based on a method developed by UK think tank Doteveryone. It helps teams map the consequences their product or service could have on a customer’s experience—good or bad, intended or not.
The point is to catch the ways it might go wrong, and who it might hurt, on a whiteboard rather than in front of customers. The mapped consequences sort into four buckets: the good you're chasing, the trade-offs you'll accept, the happy accidents you didn't plan, and the bad surprises you didn't see coming.
Bodine uses self-driving cars as her case study. The cars are capable of mapping potholes for the cities they drive through—a happy accident not intentionally planned for. Meanwhile, the same cars, during an electrical blackout, froze in an intersection—a bad surprise that no one saw coming.
This is where the exercise pays off. Asking "What are the edge cases? Who could be harmed if the system fails or behaves incorrectly?" before you ship is how you design for the experience you want, rather than the one you didn't see coming.
"Exceptional experiences do not happen by accident," Bodine said. The failures don't either.
2. Write the playbook before the incident (Chime)
Even a well-built experience drops someone eventually. The customer trapped in a chatbot loop. The case the system marks "resolved" that isn't. Chris Hernandez, Senior Manager of AI Operations at Chime makes the case that what usually fails first isn't the technology, it's the operations around it. That is, who owns it, how it's watched, and what happens the moment it misbehaves.
In testing, on a few hundred chats, the bot looks healthy. In production, across millions, the customers who ask for a human agent are looped back to the bot instead. The dashboard still glows green, because it counts each of these handoffs as a ‘case handled’ without a human, exactly what it was built to reward. Even though the experience is falling apart.
The fix is a written playbook that spells out, for every alert, who owns it and what they do next. Chime's own bot, Jade, runs against a list of things it should never say, like telling a customer to blow their savings on a vacation. Every conversation gets scanned, and each violation it catches drops into a Slack channel, opens a ticket assigned to a specific owner on a set deadline, and gets reviewed weekly by the team and monthly by leadership. Things still slip through. The difference is there's a plan for when they do.
The response, Hernandez said, has to be "written down before the incident, not invented during it."
3. Design for the failures you can't prevent (Personal Argentina)
In telecom, some breakdowns you simply can't design away. The network drops, a storm takes out power, a technician is late or doesn't show at all. As Martin Belogi, CX Senior Manager at Personal Argentina puts it, you will never hit every promise, so you had better plan for the miss.
The company started by fixing how it handles the failures it can't avoid. It cut the time to resolve an outage from two days to 12 hours. It lifted the share of service appointments it actually keeps from 60% to 90%. First-call resolution rose 12 points, repeat visits to customers' homes halved, and total contacts fell about 70%, from 60 million calls a year to 15 million.
Handling failure better, it turned out, paid off twice. These service improvements cut operating costs and customer churn dropped by roughly 20%.
The next step is to stop treating recovery as damage control and start designing for it on purpose. So that when the Wi-Fi fails or the queue backs up, the fix feels as considered as the sale. "We need to design the experience for when we fail," Belogi said. “Not just for when it works.”
4. Turn the breakdown into a better experience (FedEx)
For a delivery company, the experience is made or broken on the doorstep. "We know exactly when a package is delivered, and where. But we didn't know how it was delivered," said Amy Alfieri, FedEx's Director of Research and Digital Analytics.
So the team built a five-star survey for the moment of delivery, now gathering more than 500,000 responses a month, and pushed the results to every station across the US and Canada in real time. Drivers can correct a problem on the same day, and get recognized for the deliveries they get right.
Two fixes came straight out of that feedback. Picture Proof of Delivery answers the "where is it?" question with a photo of exactly where the package was left. And delivery preferences let customers say ‘ring’ or ‘don't ring’ the doorbell, so the drop matches what each household actually wants. The doorbell question still isn't fully solved, but scores have climbed as the fixes landed.
The break is part of the experience
Four teams, one idea underneath all of them—the breakdown isn't an exception to the experience, it's part of it, so it deserves the same design attention as everything else.
Anticipate what you can before launch. Write the recovery down before you need it. Fix the failures you can't prevent as fast as you can, and purposefully design for the ones you can't avoid. The programs that hold on to customers have their share of breaks. The difference is they’ve designed for failure and are ready for when things do go wrong.