CHARGEUR is a load-state system for an armoured vehicle crew. We redesigned the commander, gunner and fleet surfaces so a mismatch becomes impossible to miss—and every person reads the same operational truth.
The idea in 30 seconds
Chargeur helps a tank crew see what ammunition is loaded, whether it matches their request, and how much is left.
They choose an ammunition type on a tablet. The gunner needs to know the right one is loaded.
An automatic loader works out of sight. Sensors report what is loaded; the crew relies on a screen.
Chargeur shows “requested” and “loaded” on both crew screens, so a mismatch is clear before anyone acts.
Outside the tank: A supply officer sees what is left across the fleet and who needs more.
On a training exercise in Champagne, Victor 4, a three-man crew in their third year on the ALT-3 tank, engaged a simulated target.
The commander requested an armour-piercing round. The amber light confirmed it. The gunner fired a shaped charge instead.
In the debrief, the crew couldn't explain it. The interface had confirmed readiness, and they trusted it.
That incident report reached our team six weeks later. It was the fourth near-miss that year.
A specialist defence agency brought us into a European armoured-vehicle programme after four near-miss reports. The engineering brief asked for a visual refresh of the existing panel.
The evidence pointed somewhere else: hardware state existed, but the interface collapsed “system ready” and “requested round loaded” into the same signal. This was not a styling problem. It was a broken contract between machine and crew.
Our remit expanded from one panel to the shared state model across commander, gunner and resupply.
Here's the thing about the ALT-3 autoloader: it's genuinely impressive. A sealed carousel with 30 rounds, OFL (armour-piercing, for punching through plate), OCC (shaped charge, for penetrating fortifications), and OE (high-explosive, for everything else). The commander picks a type, the carousel spins, and in eight seconds there's a round ready to fire.
The crew never touches the ammunition. Not during a mission, not during an engagement. They push a button, they wait, and they trust.
And that is the thing: trust. Three different round types, three different tactical purposes, and the only thing standing between the right call and a wrong shot is a small amber light on a panel designed before most of the crew was born.
That trust is the entire design problem.
Reconstructed context image · The product had to remain readable in low light, vibration and a workspace where the operator cannot change posture to accommodate the interface.
Each site visit required a 3-week advance request, approved by both Agency's security officer and the base commander. Four visits over four quarters. Every observation had to count.
For the first three months, the entire project ran over Figma shares and video calls bridging IST and CET. Every design decision had to be documented well enough to survive a handoff none of us would be in the room for.
Prototype testing moved from A3 laminated printouts (lo-fi) to a ruggedized Android tablet running a web prototype (mid-fi) to a hardware simulator (final). Each medium introduced fidelity gaps.
4 site visits. 11 interviews. 3 years of incident reports. That's where we started.
Before CHARGEUR, crews relied on a primitive software console that suffered from critical UX failures:
Victor 4 asked for an armour-piercing round and got a shaped charge. The amber light still said ready. Nobody in that crew had a way to catch it before the trigger.
"The commander's on the radio and I'm just… hoping." The commander picks the round. The gunner pulls the trigger, with no screen, no status, nothing.
How many are left is a simple question the panel could not answer, so crews guessed and called counts over the intercom. Four incident reports in three years came down to guessing wrong.
The supply officer's job was to keep eight vehicles armed and running. His tool was a shared Excel spreadsheet. Columns for each vehicle. Rows for round counts. Updated by radio, whenever someone remembered to call in.
The pre-mission loading sequence took 34 minutes. Two crew members physically handled each round: one to retrieve, one to confirm the type label verbally before handing it to the loader. Every round was announced aloud: "OFL, slot three." "OCC, slot four." A ritual. A verbal design that the software had never matched.
We sat in the corner and counted. Fourteen rounds without incident. On round fifteen, an OE, there was a two-second pause before the verbal confirmation. The crew member had picked up an OCC. He caught it. Set it down. Retrieved the correct round.
That pause was 2 seconds. In the field, under stress, that pause might not happen. That's how close-call errors work: invisible to the person who catches them.
Mismatch rate: 4 confirmed mismatches in 22 incidents, 18% of all reported training incidents involved the wrong round type
Blind handoff: In 100% of observed engagements, the gunner had zero visibility into which round type was chambered
Mental count errors: Crew estimates were off by an average of 2.4 rounds when compared to actual counts post-mission
Existing workarounds: Every crew had invented at least one unofficial method, tally marks on tape, verbal call-outs, or a written log
Every workaround was a design that already existed, just not in the software.
These are different things.
The commander panel is a single-screen tablet interface that answers three questions at a glance: What's loaded? How much is left? Is the system ready? The top bar shows telemetry (barrel temp, hydraulics, target distance) and autoloader status. The center shows the chambered round type in massive, named text with a material colour for OFL, OCC and OE. A neutral verification state confirms the match without spending warning colour on normal operation. The right column shows three clickable ammo inventory cards. Tap one to request a type switch.
And when something doesn't match? The panel doesn't just turn yellow and leave you guessing. It tells you exactly what went wrong, shows both the requested and the chambered type, and gives you two clear options: abort and recycle, or confirm the override. No alarm bells, no noise. Just the truth, and a choice.
If Victor 4 had had this screen, they would have stopped. That's all we needed to hear.
The supply officer needed to see his entire fleet at once, which vehicles are running low, how urgently, and what to send them. So we built Fleet Command: a tactical map with diamond-shaped vehicle markers (neutral for nominal, amber for low), plus an inline priority queue at the bottom showing urgent vehicles with a one-click ASSIGN button to dispatch resupply.
When three vehicles are low and you've got one resupply truck, you need priorities. The queue sorts them: most critical first, one click to dispatch. When a critical vehicle clears back to neutral, the supply officer sees it happen. For the first time, the loop actually closes.
We built 67 components around one rule: colour never carries meaning alone, and it only appears when it helps an operator distinguish material, verify a choice or resolve an exception. The same critical-ops foundation later informed PRAHARI, but Chargeur keeps a quieter, guided-workflow personality.
OFL, OCC and OE are always named. Colour accelerates recognition; it never replaces the label.
Chambered type and match state outrank telemetry, history and secondary actions.
A mismatch names expected and actual values before presenting two explicit paths.
Compact information density, generous action targets and no precision gestures in critical paths.
| Problem | Before | After |
|---|---|---|
| Mismatch detection | No match verification. Amber light = "ready," regardless of type | Explicit type-match confirmation. Mismatch triggers named alert with forced choice |
| Ammo count | No count display. Crew estimates from memory | Real-time count bars by type. Low-ammo threshold triggers amber warning |
| Gunner visibility | Zero. Gunner fires without knowing ammo type | Synchronized display. Gunner sees type + switch status in real-time |
| Fleet awareness | Radio estimates logged in Excel spreadsheet | Real-time tactical map with per-vehicle ammo state and one-click resupply |
| Type switch feedback | No progress indication. Commander waits, hopes | 4-second animated progress bar. Both commander and gunner see switch state |
Six commanders, four sessions each. We deliberately loaded the wrong round every time. With the new panel, every single one of them caught it. Every one chose the right action, abort or override. Nobody fired on a mismatched round.
With the old panel? Four out of six missed it completely and pulled the trigger.
Three weeks in, we were laying out UI zones without fully understanding how the autoloader actually worked, 30 slots, each with a type and a position, in a carousel that rotates. We were designing from layout intuition instead of from the data. Once we mapped the state machine properly, the screens basically designed themselves. Should've been day one work.
The engineering lead saw every new interface element as an implicit dig at the autoloader he'd spent years building. It took us weeks to find the right framing: "Your hardware is trustworthy enough that when it shows a mismatch, the crew should take it seriously." The mismatch alert became a vote of confidence, not a criticism. That conversation should have happened in week one.
Col. Bergeron in procurement saw any new UI as new training cost. Fair enough. We had to prove that training six commanders on a new panel was cheaper than 22 incidents' worth of debriefs, remediation, and paperwork. The math worked. But getting that math together took four weeks we really didn't have.
Engineers don't move on design rationale. They move on incident reports.