Ma Certif’ Pro Santé
Designing from scratch a national e-service for a million health professionals who never asked for it.
- Role
- UI / Product designer, from-scratch design of the professional-facing screens
- Period
- 2026 · MVP in preparation
- Context
- French Digital Health Agency (ANS), via Atos / Eviden
- Tools & stack
- DSFR (no theming) · RGAA · Navigable HTML prototypes · Driver.js
Deliberately blurred: the service is not live yet, and its screens are not mine to show.
Mandate
The national e-service for periodic certification of health professionals: about 1.075 million people, 7 professions. No application existed; I designed the professional-facing screens from scratch.
Challenge
Field-based, mobile users who never asked for this legal obligation and may log in once a year. Behind it: 52 frameworks, 2,951 actions, zero uniform structure.
Solution
Pure, unthemed DSFR. An action-oriented dashboard instead of an accounting one, theme-based onboarding, and a parameterisable MVP common core: 45 frameworks integrable in V1.
Results
MVP in preparation for 2026. The audit of the existing prototype surfaced eight structural comprehension problems; every screen answers one. Not live yet, screens blurred.
The full story, decision by decision
This service’s users are mostly field-based and mobile, with little screen time, and they never asked for this legal obligation. They will visit the app rarely, sometimes once a year. Designing for them is not “making a dashboard”: it is making an imposed constraint understandable in three seconds, on a phone, between two shifts.
All in pure, unthemed DSFR: the direct application of the criterion born on the Design System mission.
The decisions
52 frameworks, one interface
The founding hypothesis. Every profession has its own framework of actions, written by its national professional council on a common methodological base (HAS). The project rested on an implicit hypothesis: common base, therefore homogeneous frameworks, therefore one interface for all.
What I demonstrated. By crossing the ANS-consolidated data with the 52 source PDFs, the hypothesis proved false: 52 frameworks, 2,951 actions, zero uniform structure. Depth varies from 3 to 5 levels depending on the profession, and the “2 actions per axis” rule everyone believed universal is not: some professions require 3, others count in points, others impose hour minimums. Consequence: impossible to hardcode the rules engine: the database had to parameterise validation profession by profession.
The choice. Rather than waiting for the 52 councils to harmonise (a 12-to-18-month effort), a pragmatic MVP common core: two minimal structural criteria with parameterisable tolerances, and a classification of the 52 frameworks into 5 statuses, materialised in an arbitration file. Result: 45 frameworks integrable in V1, 6 deferred to V2, and one framework discovered entirely missing from the consolidated data, flagged and fixed.
What it changed. The project moved from an implicit “one UI for all” to an explicit MVP scope and a parameterisable base. Not a narrowing: a numbered, arguable reading of what had been an unverified hypothesis.
From accounting logic to progression logic
The old prototype showed cold fractions, a misleading time bar (it conflated elapsed time with progress) and no visible action on arrival. The redesign: a primary CTA on arrival, a countdown instead of fake progress, axes named in plain words, a genuine moment of celebration when the cycle completes. And above all: a theme-based onboarding, so nobody is ever left alone facing 2,951 possible actions.
One side panel, two states
Rather than stacked panels, a single panel with two states (detail / edit). Attachments are all or nothing: nothing is saved before “Save”, and the guard dialog only appears if you close with changes in progress. Simpler to maintain, cleaner for accessibility.
The semantics of states before the pattern
An empty state is not an error, which is not a loading state. A reference framework still being written by the profession is a legitimate empty state: no red alert, no fake spinner. Every DSFR component choice is defended in meetings on accessibility and meaning, never on taste. Same logic for the guided tour: triggered automatically on first login, because an opt-in tour is never seen.