Skip to content
All work

Enterprise engagement · Enterprise SaaS · Security & Governance

SecureVault — Enterprise Identity & Access, without the friction

An AI-powered Identity & Access Management platform designed for the four humans caught inside every access decision

Enterprise UXAI interaction designIADesign systemWCAG 2.2 AA
Access latency
2.6d → 11m
Manual approvals
−74%
Usability score
SUS 84
Task success
92%

Overview

Modern organisations run hundreds of SaaS tools. Every joiner, mover and leaver triggers a cascade of permission changes — and those changes were handled by Slack DMs, email chains and manual approval tickets.

I owned end-to-end UX: discovery, research, information architecture, cross-role workflows, AI interaction design, prototyping, usability testing and the enterprise design system across 240+ screens.

Business problem

Slow for employees, painful for IT, invisible to compliance

IT teams spent 30–40% of weekly capacity on manual approval tickets. Employees waited an average of 2.6 business days for tools they needed on day one.

Compliance could not answer basic audit questions — who has access to what, why, and since when — without weeks of reconciliation, while permission sprawl quietly expanded the blast radius of every credential.

  • 2.6 day average request-to-access latency
  • $1.2M average annual cost of over-provisioning
  • 68% of audits flagged excessive privileges

Research & discovery

Every existing tool assumes the admin, never the employee

Market analysis, a competitive teardown of Okta, Microsoft Entra, SailPoint and JumpCloud, 11 stakeholder interviews with CISOs, IT Directors and Compliance leads, and 15 diary studies with employees.

The consistent gaps across competitors: shallow AI, weak self-service, and dashboards built for auditors rather than humans. Journey mapping surfaced 14 friction points and a service blueprint exposed six silent handoffs.

Personas

Four roles, one broken workflow

Each persona was grounded in real transcripts, with distinct goals, tools and success metrics — and the journey map became the north star in every sprint.

  • Priya, Security Admin — least privilege by default, fast drift detection
  • Marcus, IT Manager — automation he can trust across 200+ tickets a week
  • Elena, Employee — the tools to do her job on day one
  • David, Compliance Officer — a single, defensible source of truth

Information architecture

Requests, Roles, Risks

I restructured the product around three mental models; everything a user does maps to one of them. The previous prototype exposed 47 top-level nav items, collapsed into 9 semantic categories through tree-testing with 25 participants — success rate rose from 41% to 89%.

Flows were designed role by role — employee self-service, admin approval, compliance audit, security investigation — and rehearsed against real transcripts before wireframing.

Canonical flow: Request → AI match → Risk score → Approval → Provision → Audit log.

AI design

AI only differentiates when it earns trust

Three AI surfaces, designed around transparency and reversibility. Peer-based ML suggests the smallest sufficient role for a new hire; anomaly models rank alerts by blast radius rather than volume; plain-language access requests are mapped to a role, routed to the right approver and scored for approval likelihood.

An immutable, queryable audit ledger lets compliance ask “who accessed prod between March 4–6?” and get an answer in seconds, mapped to SOC 2, ISO 27001 and HIPAA.

  • Every AI action shows confidence and rationale
  • One-click override on every suggestion
  • Audit queries: 3 days → under 60 seconds

Design system

One token system, WCAG 2.2 AA

12 semantic colour roles, four elevation levels, an 8pt spatial grid and a type scale tuned for data density, readable in light, dark and high-contrast. Sixty primitives — data tables, permission graphs, risk badges, approval chains — each shipping with keyboard maps, ARIA patterns and motion tokens.

Audited with a screen-reader partner: every interactive surface keyboard reachable, every data visualisation with a tabular fallback and non-colour status cues. Documentation was adopted by three downstream teams.

Results & reflection

The hardest problem was not AI — it was trust

Access latency dropped from 2.6 days to 11 minutes median, manual approvals fell 74%, audit prep collapsed from three weeks to two hours, and IT admin NPS climbed to +58. Usability testing returned 92% task success across four role types and a SUS score of 84.

Every decision — copy, confidence, reversibility, defaults — had to earn the right to be automated. Enterprise UX is not about hiding complexity; it is about revealing it responsibly.

Next case study

FinSight AI — From fragmented finance to real-time intelligence

Fintech · Enterprise analytics

Contact

Let’s talk about the problem, not just the solution.

I’m open to senior product design, UX leadership, design systems, and AI-native product opportunities.

Get in touch