Flow logo
FlowIndependent design concept. Not affiliated with Microsoft Power Automate.
Windows 11 · AI Workspace Intelligence · Concept

"You open your laptop. Your workspace is already ready. You didn't do anything. Flow just knew."

This is the moment Flow is designed to create. Every morning. Without being asked.

Windows has always been built on one promise: your computer does what you tell it to. Flow is built on that same promise.

3.3%
Of M365 users pay for Copilot, despite it living on every keyboard.
Recon Analytics, 2026
8%
Choose Copilot when given a real choice between AI tools.
Recon Analytics, Jan 2026
−24.1
Copilot accuracy NPS, Sep 2025. Was −3.5 in July.
Recon Analytics, 2025

Flow was designed before Microsoft began removing Copilot branding in March 2026.

Flow and Copilot

Flow doesn't replace Copilot. It's powered by it.

Flow is the trust layer that sits between the user and Copilot's capabilities. The stack below shows the technical relationship. The journey shows why that layer exists: building the habit that pulls users toward Copilot willingly, instead of pushing them forcibly.

Windows Shell
trust earned here
Flow
powered by
Copilot AI Engine

Flow is the interaction layer. Copilot is the engine.

Five stage trust journey from skeptical user to willing Copilot adoption
Flow operates in the gap between skepticism and adoption.
01Why this, why now

Microsoft didn't have a model problem. It had a trust problem.

Copilot had the most aggressive distribution of any software feature in Windows history: a dedicated keyboard key, a pinned Start menu slot, a taskbar button, and a right-click entry in File Explorer. Distribution at that scale still didn't translate to voluntary adoption. When users had access to alternatives, 8% chose Copilot. The failure wasn't reach. It was that every forced touchpoint arrived before trust was established. Once the first interaction disappointed, every subsequent sighting of the Copilot icon became a negative signal. More placement accelerated the damage. Flow is designed around the opposite sequence: trust first, then presence.

Diagram of a Windows screen with the Copilot icon called out in eight places: Notepad, Photos, Snipping Tool, Start menu, taskbar, keyboard key, Edge sidebar, and File Explorer right-click. Caption: 8 forced touchpoints, 3.3% paid conversion.
Eight forced touchpoints across the OS. None of it moved paid conversion past 3.3%.
Close-up photo of a laptop keyboard with the dedicated Copilot key circled

A key on the keyboard

The first dedicated key Windows added in 30 years, for an app users hadn't tried.

Photo of the Windows 11 Start menu with Microsoft 365 Copilot pinned among the apps

Pinned in Start

Microsoft 365 Copilot pre-pinned, beside Word, Excel and PowerPoint.

Screenshot of the File Explorer right-click menu showing an Ask Copilot entry

Right-click in File Explorer

"Ask Copilot" wedged into the context menu users open hundreds of times a day.

Seen in the wild. Real Windows 11 surfaces, mid-2025.
What Copilot is

Reactive. Placement-first. Brand-led.

Copilot sits in a sidebar and waits to be asked. Every interaction starts from zero. The user carries the context. The AI provides the response.

Result: 35.8% of paid holders use it regularly
What Flow is

Proactive. Context-first. Earned.

Based on your calendar and the apps you have open, Flow prepares the next workspace before you need to switch. You confirm or dismiss. Nothing happens automatically.

Result: The workspace is ready before you ask
Two mind maps side by side, divided by the word 'Instead'. Left, 'The problem' in red: 'Context switching fails the user' branches to Every switch starts from zero, No context, AI appears before it's earned its place, Forced before trust, Surveillance fear (user feels monitored, not helped), Too many surfaces, User doesn't know which tool to use, and Output unreliable (fixing AI output takes longer than doing it). Right, 'Why Flow works' in iris: 'User trusts Flow' branches to Scoped (only what you granted, nothing outside), You decide what Flow can see, Permission first, Workspace ready before you ask, Proactive, Transparent (see what's coming before it happens), and Ambient (one surface, earned, gone when done).
The same user, two design sequences. Every Copilot failure mode has a Flow inversion.
Important distinction

"This isn't an argument that Copilot is a bad product."

Enterprise Copilot, when given organisational context, demonstrably helps. The problem is that consumer trust doesn't recover on a product timeline. Microsoft's March 2026 response confirms this. They didn't fix Copilot, they started removing the name from surfaces where it had failed. That points to a trust problem that product improvements alone cannot resolve. The underlying AI capability needed a different surface, one that hadn't already spent its trust budget.

Market timing

Three things happened simultaneously in early 2026

Mar 20, 2026Pavan Davuluri commits to removing unnecessary Copilot entry points.
April 2026Microsoft begins removing Copilot branding from Notepad, Snipping Tool, and Photos.
May 2026Agent Workspaces ships in Insider. Context-aware AI confirmed as the direction.
02Research foundation

The problem has been documented for 20 years. The design pattern to address it hasn't been built at OS level.

Gloria Mark · CHI 2005 + CHI 2008 · 24 knowledge workers · 700+ hours observed
23 min
To regain full focus after one interruption.
Mark, Gudith & Klocke, CHI 2008
57%
Of all work segments interrupted before completion.
CHI 2005
11 min
Average time in a task before switching.
CHI 2005
2.26
Intervening tasks before returning to original work.
CHI 2005
Timeline of a single interruption: working on the original task at T=0, an interruption at T+1min, two intervening tasks, then full focus restored only at T+23min, a 23 minute 15 second recovery gap. Caption: Flow prepares the next workspace during this window, not after it.
One interruption costs 23 minutes. Flow does its work inside that gap, before the cost lands.

"Systems should provide fully customizable, individual, project-specific views. Interrupted tasks should be easily recoverable by preserving the state of the task when interrupted and by providing cues for reorienting."

Gloria Mark et al., CHI 2005. The pattern hasn't been applied at the OS level. Twenty years later.
1,200
App switches per day for the average knowledge worker.
9%
Of annual work time lost to reorientation, about 4 hours per week.
Source: Harvard Business Review, August 2022
Active usage: when both tools are available
ChatGPT Enterprise83.1%
Microsoft Copilot (paid)35.8%
Source: Recon Analytics, 150,000 U.S. respondents, January 2026
Primary research

"Informal conversations revealed the same pattern"

Six to eight conversations with colleagues across design, development, and research roles. Every person described the same experience: losing focus at context switches, manually rebuilding workspaces from scratch, feeling like the OS was working against their workflow rather than with it. The signal was consistent enough to treat as a design input — and it matched the peer-reviewed data exactly. That alignment was the validation.

03Design decisions

Every decision traces back to one of three behavioral failures.

Live prototype
Flow — running on Windows 11
A working prototype demonstrating the core interaction model. Built with React, Vite, and Microsoft Fluent UI v9. Not production code, but real enough to click through.
Open prototype →

All screens are from the working prototype running on Windows 11. Built with React, Vite, and Microsoft Fluent UI v9.

Behavioral failure addressed

Forced placement → Earned placement

Copilot

Copilot placed itself on every keyboard, every taskbar, every app. When trust was already broken, each new touchpoint compounded the irritation.

Flow

Flow surfaces only when triggered by a real calendar event after a 3-day learning period. The prediction card earns its appearance through accuracy, "based on 14 past switches," not through forced position.

Permission-first onboarding Privacy & Control screen No branding on the card
Behavioral failure addressed

Reactive model → Proactive context

Copilot

Copilot waits to be asked. Every interaction requires the user to explain their context in a prompt. The burden is on the user.

Flow

Based on your calendar and open apps, Flow prepares the next workspace 12 to 14 minutes before a context shift. You didn't type anything.

Flow prediction card in the bottom-right of a Windows 11 desktop, 12 minutes before a Design Review. Figma, Notion and Miro queued, with Switch, Snooze and Dismiss.
Base card: the only proactive surface. Bottom-right, 12 min before the shift. Prototype on Windows 11 · Fluent UI v9.
Collapsed Flow pill reading Design Review, 2:00 PM

Dismissed → pill

Collapses to a glanceable pill. No persistence, no push.

Recovery card reading you dismissed this earlier, Design Review starts in 5 min, Switch now

Recovery card

Reappears once, closer to the event. Never nags.

Coming up card for Client Sync starting in 4 min with a Got it button

Back-to-back

Two events close together. Informs, doesn't re-prompt.

Collapsed pill reading Thanks, noted after wrong-prediction feedback

Wrong prediction

One tap teaches the model in real time. "Thanks, noted."

Card reading Design Review was cancelled, no action needed, Dismiss

Event cancelled

Calendar changed. Flow tells you, asks nothing.

Five states. One surface.

Every interaction earns the next. Nothing is automatic.

Behavioral failure addressed

Intrusive branding → Ambient presence

Copilot

Copilot appeared in Notepad, Paint, Photos, Snipping Tool, taskbar, and keyboard. Every additional placement was a reminder of the last failure.

Flow

Flow has one surface: a bottom-right card appearing 12 to 14 minutes before a context shift. When dismissed, it collapses to a 4-character pill. No persistence. No push.

No sound DND sync One touchpoint
The trust system, not just the card

The prediction card is what users see. What makes them trust it is the rest of the system: a permission model that is asked for, made visible, and reversible at every step. These screens are the same prototype.

Flow Privacy and Control screen split into two columns: Flow CAN see (Calendar events, App usage patterns, File names in granted folders, Active window titles, all toggled on) and Flow CANNOT see (File contents, Browser history, Keystrokes, Personal messages, all restricted). Below, granted folders with Revoke access buttons and a Delete all Flow data control.

Privacy & Control: the trust contract, made literal

Two columns the user can read in five seconds: exactly what Flow can see, and what it provably cannot. Every folder is revocable; all data is local and deletable. Trust is shown, not declared.

Flow welcome screen: Windows that knows what you need next, with a note that Flow only sees what you choose to share and nothing is uploaded to the cloud, and a Get started button.

Permission-first onboarding

The first promise on the first screen: nothing leaves the device. Trust is set before a single prediction.

Onboarding step 2 of 3, folder access: the user chooses which folders belong to a context: Documents and Design Projects checked, University unchecked, with a note that Flow reads file names and structure only, never contents.

You choose what Flow sees

Access is granted per folder, by the user, never assumed. File names only, never contents.

Flow Settings: prediction timing slider at 12 min, confidence threshold at 70%, snooze duration, and an Auto-Switch toggle that stays locked until 10 confirmed predictions, currently 7 of 10.

Earned automation

Auto-Switch stays locked until 10 predictions are confirmed. The system has to be right before it acts on its own.

Flow sidebar showing an unrecognised state: Flow doesn't recognise this yet, you're working in something outside your set up contexts, with options to add to an existing context or create a new one.

Honest about its limits

When Flow doesn't know, it says so, and hands control back. No confident wrong guesses.

04What this proves

AI trust isn't a capability problem. It's a design pattern problem.

01

Context-first AI is buildable at OS level

Flow uses Windows accessibility APIs and calendar integration only: no screenshots, no keylogging, no content reading. The same local AI models Microsoft is already shipping (Phi Silica on Copilot+ PCs) are sufficient for the prediction layer. The infrastructure exists. The design pattern was missing.

02

Trust can be designed, not just declared

The trust gaps in Copilot's rollout trace back to design decisions made before the product shipped: no preview before action, no visible permission model, no recovery path for bad predictions. Flow's permission model is a design system: onboarding grants explicit access, Privacy & Control makes it visible and reversible, wrong prediction feedback teaches the system in real time.

03

The platform arc is clear

The prediction card is Phase 1: ambient context for workspace switching. The sidebar is Phase 2: on-demand context access. Folder chat, where the user explicitly grants access to file contents for a specific folder, is Phase 3: active, scoped intelligence. Each phase extends the same permission model.

Windows 11 File Explorer open on a Design Review folder with an AI Chat panel docked to the right, asking 'Hi Alex, how can I help with this folder?' and offering Summarize, Find, Explain and Plan actions scoped to that folder.

Phase 3 concept. AI Chat in folder context. The user opens a specific folder and explicitly invokes AI assistance. Scoped to that folder only. File names and structure, never contents unless the user grants it. The same permission model, extended to active intelligence.

Flow prediction card on the Windows 11 desktop, 12 minutes before a Design Review.

PHASE 1 · AMBIENT

The prediction card

Context surfaces on its own, before the switch. The user confirms or dismisses.

Flow sidebar dashboard showing the current context, recent context switches, and quick workspace actions.

PHASE 2 · ON-DEMAND

The sidebar

Context on request. The same intelligence, pulled up when the user wants it.

Flow folder chat: the user has granted access to a specific folder and is asking questions about the files inside it, scoped to that folder only.

PHASE 3 · SCOPED

Folder chat

Active intelligence over file contents, but only inside a folder the user explicitly grants.

One permission model, extended three times. Each phase earns the next.
What I would validate next

Flow is a hypothesis, not a proof. These are the questions a real user study would answer.

Do users understand the permission boundary?
Can users accurately describe what Flow can and cannot see after completing onboarding? Is the Privacy and Control screen legible enough to build real confidence?
Does proactive timing feel helpful or intrusive?
At what point before a context shift does the prediction card feel useful rather than pressuring? Is 12 minutes the right window, or does it vary by user and task type?
Does earned automation increase trust over time?
Auto-Switch unlocks after 10 confirmed predictions. Does that incremental model actually build trust, or does it feel like a countdown the user didn't ask for?
How does this scale to enterprise policy?
Individual permission grants work for consumer. How does the model extend to IT-managed environments where admins set baseline permissions?
Why this matters to Microsoft

Flow addresses five things Microsoft is actively working on.

Trust in Windows AI
A permission-first architecture that makes proactive AI feel safe rather than surprising.
A less intrusive AI surface
One earned touchpoint instead of eight forced ones. Presence that compounds through accuracy, not placement.
Permission model for agentic workflows
The same scoped-access model that governs Agent Workspaces, designed from the user's perspective first.
Local AI that justifies Copilot+ hardware
Flow runs on Phi Silica and Windows accessibility APIs. No cloud dependency. The NPU investment becomes visible to the user.
Context bridge across Windows
Calendar, files, apps, and M365, unified into one context layer. The intelligence Windows has always had, made visible and actionable.

Microsoft began removing intrusive Copilot branding in April 2026.
Flow was designed before this happened.

"Default placement is not retention"

8% choose Copilot when alternatives exist.

"Privacy is a feature, not a disclaimer"

Showing what the AI can see builds trust. Footnotes don't.

"The underlying model capability was never the core issue"

Consumer Copilot fails because it has no context. Flow is the context layer.

About

Tanishq Sardar is a designer focused on human-centred AI systems and Windows UX. Flow was built as an independent research and design concept to explore what permission-first, context-aware AI could look like at the OS level. The prototype demonstrates the core interaction model — prediction card, sidebar, onboarding, and privacy controls — built to production visual standards using Microsoft Fluent UI v9.

Get in touch

If this work resonates, I would welcome a conversation — whether that is feedback, a question about the design decisions, or an opportunity to explore this further.

LinkedIn Portfolio Email