← Back to Portfolio

Case Study — CX Audit Report System

When a paywall isn't actually a paywall

A gap between what an interface implies and what a system actually enforces, caught and fixed.

While building the CX Audit Report System, I designed a paid-unlock flow where a client's full findings stay hidden until payment. This is the mechanism that gates it.

Before

What a visitor saw

audits.practicalife.com/report-xxxxx

Key Observations

Sample finding text sits here describing a customer experience gap, written out in full sentences that read like real findings.

🔒 Unlock after payment

What was in the page's code

view-source:audits.practicalife.com
<!-- .locked-content is only styled with a CSS blur --> <div class="locked-content blurred-content"> <p>Sample finding text sits here describing a customer experience gap, written out in full sentences that read like real findings.</p> </div> // readable in plain text, no payment required

To a visitor, this section was locked. In the page's own code, it wasn't. The full findings sat there in plain, readable text, one right-click away.

The insight

The locked sections were hidden with a CSS blur, visually gated but not actually removed from the page. Anyone who right-clicked and chose "View Source," or simply copied the page, could read the full findings in plain text, no payment required. The blur worked on the eye. It did nothing to the data. I traced the bug to that gap, not "the page looks unlocked," but "the thing meant to make it inaccessible never touched accessibility at all." The fix was to stop treating visibility and access as the same control: pull the real content out of the public file entirely, and only release it from a separate, private source after payment confirms.

After

What a visitor sees

audits.practicalife.com/report-xxxxx

Key Observations

Sample finding text sits here describing a customer experience gap, written out in full sentences that read like real findings.

🔒 Unlock after payment

What's in the page's code now

view-source:audits.practicalife.com
<!-- real findings live in a private file, not here --> <div class="locked-content blurred-content"> <p>[Redacted Until Locked]</p> </div> // copy or paste it, and this is all anyone gets

Same screen. Different reality underneath. The real findings no longer exist in the page at all until payment is confirmed.

This wasn't a cosmetic fix. It closed a gap between what the interface implied and what the system actually enforced, the same gap I get paid to find in other people's products.

The findings are gated to the business that paid for the audit, not the public, not a competitor, not anyone who happens to have the link. Copy the "locked" section now and paste it anywhere, and all that comes with it is a note that it's redacted until unlocked. Nothing else.

See the live audit demo →