{"site":{"name":"Koji","description":"AI-native customer research platform that helps teams conduct, analyze, and synthesize customer interviews at scale.","url":"https://www.koji.so","contentTypes":["blog","documentation"],"lastUpdated":"2026-09-28T15:48:36.464Z"},"content":[{"type":"documentation","id":"18944fbe-a6ba-4c68-92c9-b3af81985aa9","slug":"off-script-participants-ai-interviews","title":"When Participants Go Off-Script: How AI Interviews Stay On-Brief","url":"https://www.koji.so/docs/off-script-participants-ai-interviews","summary":"Two distinct behaviours get called going off-script: ordinary topic drift, which is common and often the most valuable data in an interview, and deliberate redirection of the AI, which belongs to the prompt injection risk class OWASP defines as user prompts altering model behaviour in unintended ways. Koji bounds conversations with an explicit out-of-scope field in the brief, three interview modes (structured, exploratory, hybrid), and required questions scored on coverage. A derailed interview surfaces automatically through low coverage and low-confidence extractions, and the quality gate means it generally does not consume a credit.","content":"Two completely different things get called going off-script in an AI interview, and conflating them leads teams to the wrong fix. The first is ordinary topic drift - a participant answers a question you did not ask, tells a story, or wanders somewhere interesting. That is common, usually valuable, and something you want your interviewer to handle gracefully rather than suppress. The second is deliberate redirection - someone typing instructions at the AI to see what happens. That is rare in research, but it belongs to a real and well-documented class of vulnerability, and it deserves a different answer.\n\nKoji treats them differently, and so should you.\n\n## Ordinary drift is often your best data\n\nStart by noticing that a participant leaving your script is frequently a finding rather than a failure.\n\nWhen someone answers *why did you cancel* by talking for two minutes about an unrelated billing surprise, the script did not fail - your model of the problem did. The classic interviewing methodologies are built around this. The Mom Test principles that ship with Koji's methodology frameworks explicitly favour talking about the participant's life over your idea, asking about the past rather than hypothetical futures, and digging for specifics when someone says always or never. Every one of those invites the participant somewhere you did not plan to go.\n\nSo the goal is not a participant who never deviates. The goal is an interview that can follow a productive digression and still come back and cover what you needed. That is a coverage problem, not a control problem.\n\n### When drift is a problem\n\nDrift stops being useful in three situations: when it consumes the interview so your required questions never get asked, when it walks into territory you have deliberately excluded for legal or ethical reasons, and when it is not really drift but avoidance of a question the participant does not want to answer.\n\nThe first two are what the controls below are for. The third is a question-design problem - see [Question Specificity and the Length Contract](/docs/question-specificity-answer-length).\n\n## What actually bounds the conversation\n\nThree mechanisms do the work, and they are worth understanding separately because they fail in different ways.\n\n### The brief's out-of-scope field\n\nA Koji research brief carries an explicit out-of-scope field alongside the problem statement, the decision the research will inform, and the success criteria. This is where you write down what the interview must not pursue - *we are not researching pricing sensitivity*, or *do not discuss the pending litigation*.\n\nThis field is underused and it is the cheapest control you have. An interviewer that knows your boundaries can decline a topic gracefully and move on, which is a far better participant experience than one that either follows the participant anywhere or refuses without explanation. If a topic is genuinely off limits, write it in the brief rather than hoping it does not come up.\n\n### Structured, exploratory and hybrid modes\n\nKoji studies run in one of three interview modes, and this is the main dial for how much wandering you want.\n\n**Structured** follows your key questions closely. Use it for validation, for anything you intend to compare across participants, and for regulated topics.\n\n**Exploratory** follows interesting threads. Use it for discovery, when you do not yet know what the real problem is.\n\n**Hybrid** starts structured and goes exploratory on interesting topics - which is what most discovery work actually wants.\n\nChoosing exploratory and then complaining that participants went off-topic is the most common self-inflicted version of this problem. The mode is a commitment about what you value.\n\n### Required questions and coverage\n\nEach structured question in your plan is marked required or not, and coverage - how well the key questions and topics were actually covered - is one of the dimensions the analysis scores. Together these are what stop a pleasant, rambling conversation from quietly producing nothing.\n\nA digression that still ends with every required question answered is a good interview. One that does not is visible in the score rather than hidden, which is the point. See [Understanding Quality Scores](/docs/understanding-quality-scores) and the [AI interviewer tuning guide](/docs/ai-interviewer-tuning-guide).\n\n## The adversarial case\n\nNow the other half, which is smaller but should not be hand-waved.\n\n### What prompt injection is\n\nSome participants will try to talk to the system rather than answer the question. Most are just curious. The underlying risk class is well defined. The OWASP Gen AI Security Project lists it as LLM01:2025 Prompt Injection in its LLM Top 10 for 2025, and describes it plainly: \"A Prompt Injection Vulnerability occurs when user prompts alter the LLM's behavior or output in unintended ways.\"\n\nOWASP splits it in two. Direct prompt injections \"occur when a user's prompt input directly alters the behavior of the model in unintended or unexpected ways.\" Indirect prompt injections \"occur when an LLM accepts input from external sources, such as websites or files. The content may have in the external content data that when interpreted by the model, alters the behavior of the model in unintended or unexpected ways.\"\n\nAn interview participant typing instructions is the direct case. It is the one you will actually see.\n\n### Why interview text is untrusted input\n\nAny AI interview ingests free text from strangers, which makes that text untrusted input by definition. The reason to take the category seriously even when the attempts you see are playful is that the wider research on injection shows the attack surface is cheap to exploit and that obvious defences are not sufficient.\n\nIn *Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems* (Chang, Bao, Luo and Yu, arXiv, submitted 11 January 2026), the authors demonstrate end-to-end exploits costing \"as little as $0.21 per target user query on OpenAI's embedding models\", achieving \"near-100% retrieval across 11 benchmarks and 8 embedding models\". In one scenario a single poisoned email was enough to coerce a model into exfiltrating SSH keys \"with over 80% success in a multi-agent workflow\". They conclude that they \"evaluate several defenses and find that they are insufficient to prevent the retrieval of malicious text\".\n\nScope that honestly: their setting is retrieval corpora and agentic systems, not research interviews, and an interview transcript is not a retrieval corpus. The transferable lessons are narrower but real - untrusted text reaching a model is a demonstrated attack surface, cost is not a barrier, and a single input can be enough. None of that is a reason for alarm about interview data. It is a reason to keep the interviewer's job narrow and to treat what a participant types as content to be recorded rather than instructions to be obeyed.\n\n### What this means in practice\n\nThe structural defence is scope. An AI interviewer whose job is to ask the questions in a brief, record answers, and probe within bounds has very little surface worth attacking - it is not holding credentials, not calling tools on the participant's behalf, and not retrieving from a corpus a stranger can write to. Keeping the role narrow is worth more than any single filter.\n\n## What a derailed interview looks like in your report\n\nThe practical reassurance is that you do not have to detect this manually.\n\nAn interview that went badly off the rails scores poorly on coverage, because the required questions were not answered. Answers extracted from a conversation that never really addressed a question come back with low confidence flags, which is your signal to read the transcript - see [Answer Confidence Flags](/docs/answer-extraction-confidence-flags). And because Koji's quality gate means only conversations scoring 3 or above consume a credit, a genuinely wrecked interview generally does not cost you anything.\n\nSomeone testing the interviewer is usually obvious the moment you open the transcript, and [reading transcripts](/docs/viewing-interview-transcripts) takes seconds once a flag has pointed you at one.\n\n## How Koji handles this\n\n- Koji briefs carry an explicit out-of-scope field, so boundaries are configuration rather than hope.\n- Three interview modes - structured, exploratory, and hybrid - let you choose how much productive wandering you want rather than accepting a fixed behaviour.\n- Required questions plus a coverage dimension in the interview score mean a rambling conversation that missed the point is visible instead of silently counted.\n- Koji's AI probes within the bounds of your brief, so follow-ups pursue depth on your questions rather than following the participant indefinitely.\n- All six structured question types - open_ended, scale, single_choice, multiple_choice, ranking, and yes_no - give the conversation a spine to return to, and in text mode the closed types are answered through widgets that are not free-text at all.\n- Low-confidence extractions and low coverage scores surface a derailed interview automatically, and the quality gate means it usually does not consume a credit.\n\n## Common mistakes\n\n### Choosing exploratory mode and then wanting control\n\nIf comparability across participants matters, choose structured. Mode is the decision, not something to litigate afterwards.\n\n### Leaving out-of-scope empty\n\nIf there is a topic the interview genuinely must not pursue, writing it in the brief is the whole mechanism. An empty field is not a boundary.\n\n### Treating curiosity as an attack\n\nMost participants who poke at the AI are just interested. That is not a security incident and it usually does not invalidate their answers - read the transcript and judge the interview on coverage.\n\n### Discarding a whole interview because one answer went sideways\n\nJudge it per question. An interview where one answer is unusable and nine are excellent is a good interview. See the per-question denominator argument in [Partial Interviews and Breakoff](/docs/partial-interviews-breakoff-analysis).\n\n## Frequently asked questions\n\n### What happens if a participant ignores the question and rambles?\n\nUsually something useful. Koji's AI probes within the bounds of your brief and works to cover your required questions, so a digression that ends with everything answered is simply a good interview. If the rambling crowded out your questions, that shows up as a low coverage score rather than being hidden.\n\n### Can a participant manipulate the AI interviewer with instructions?\n\nSomeone can certainly try, and this is the direct case of what OWASP calls prompt injection - user input that alters the model's behaviour in unintended ways. The structural defence is scope: an interviewer whose job is to ask your questions, record answers, and probe within bounds is not holding credentials or calling tools on a participant's behalf, so there is little worth attacking. Attempts are also easy to spot in the transcript.\n\n### Does going off-topic ruin the interview data?\n\nRarely. Judge the interview per question rather than as a whole. The answers to questions that were properly covered remain valid, and answers extracted from a conversation that never really addressed a question come back flagged low confidence so you know which ones to check.\n\n### How does Koji know what is out of scope?\n\nBecause you tell it. The research brief has an explicit out-of-scope field alongside the problem statement and success criteria. Writing *we are not researching pricing* there lets the interviewer decline that topic gracefully and move on. If you leave the field empty, there is no boundary to enforce.\n\n### Should I use structured or exploratory mode to stay on track?\n\nStructured, if staying on track is the priority - it follows your key questions closely and is the right choice for validation and for anything you plan to compare across participants. Exploratory deliberately follows interesting threads. Hybrid starts structured and opens up on interesting topics, which suits most discovery work.\n\n### What if a participant asks the AI a question?\n\nThis is normal and usually harmless - people ask what the study is for or whether their answers are anonymous. Those are reasonable questions and are better handled in your intake and consent step, where the answers are yours rather than improvised. See [Intake Forms and Consent](/docs/intake-forms-and-consent).\n\n## Related Resources\n\n- [Structured Questions Guide](/docs/structured-questions-guide) - the six question types that give an interview its spine\n- [AI Interviewer Tuning](/docs/ai-interviewer-tuning-guide) - probing depth, modes and question mix as deliberate levers\n- [Understanding Quality Scores](/docs/understanding-quality-scores) - how coverage is scored per interview\n- [Can You Trust AI Interviewers?](/docs/ai-interview-hallucinations-bias-mitigation) - the AI's own failure modes, as distinct from the participant's\n- [Answer Confidence Flags](/docs/answer-extraction-confidence-flags) - the signal that tells you which transcript to open\n- [Intake Forms and Consent](/docs/intake-forms-and-consent) - answering participant questions before the interview starts\n","category":"Reports & Analysis","lastModified":"2026-09-27T03:40:58.642343+00:00","metaTitle":"Off-Script Participants: How AI Interviews Stay On-Brief","metaDescription":"Participants drift off topic and sometimes test the AI. How Koji keeps interviews on-brief with scope bounds, modes and coverage scoring.","keywords":["off-topic participants","AI interview control","prompt injection interview","interview scope","AI interviewer guardrails","interview coverage"],"aiSummary":"Two distinct behaviours get called going off-script: ordinary topic drift, which is common and often the most valuable data in an interview, and deliberate redirection of the AI, which belongs to the prompt injection risk class OWASP defines as user prompts altering model behaviour in unintended ways. Koji bounds conversations with an explicit out-of-scope field in the brief, three interview modes (structured, exploratory, hybrid), and required questions scored on coverage. A derailed interview surfaces automatically through low coverage and low-confidence extractions, and the quality gate means it generally does not consume a credit.","aiPrerequisites":["Familiarity with Koji research briefs","Understanding of the six structured question types"],"aiLearningOutcomes":["Separate ordinary topic drift from deliberate redirection of the AI","Use the brief out-of-scope field to set enforceable boundaries","Choose between structured, exploratory and hybrid interview modes","Explain prompt injection using the OWASP definition and scope its relevance to interviews","Recognise a derailed interview from coverage scores and low confidence flags"],"aiDifficulty":"intermediate","aiEstimatedTime":"11 min read"}],"pagination":{"total":1,"returned":1,"offset":0}}