Experience NPS
A clearer end-to-end workflow materially improved user confidence.
01 · Data security + governed agents
One permission-aware experience for connecting, viewing, querying, copying, and governing data, with a supervised agent embedded at the point of work.
Insight layer
Across the broader enterprise data ecosystem, I also led feedback and insights experiences that demonstrated what the foundation should enable. Teams could collect signals, define an audience, visualize patterns, and embed learning back into products without losing ownership or quality context.
A clearer end-to-end workflow materially improved user confidence.
More product teams embedded the shared feedback capability.
Standards and enablement helped the ecosystem scale beyond one team.
AI evolution
Earlier work used AI to draft, visualize, and summarize. Later, I carried those lessons into a governed agent model: explicit task delegation, visible data sources, scoped tool access, review before execution, and recovery when a model or tool call was wrong.
Use AI to organize large volumes of feedback while preserving traceability to source data.
Show assumptions, scope, and constraints so teams can judge whether an answer fits.
Turn prompt behavior, review states, accessibility, and failure recovery into reusable specifications.
The mandate
The organization did not need another isolated tool. It needed a coherent governance experience spanning roughly 19,700 applications and more than 500 databases, without asking teams to learn a different trust model each time.
Developers moved between database viewers, copy tools, approval systems, schema workflows, and security controls. Each product had its own vocabulary and rules. I reframed the work from a set of feature projects into a platform-level experience architecture.
Connections, access, masking, exports, and monitoring behaved differently across surfaces.
Users could not always understand why an action was blocked, approved, expired, or audited.
Without shared specifications, engineering teams repeatedly interpreted common behavior.
Governed data agent
I designed and evaluated an agent embedded where users already had task context: connecting a source, copying governed data, viewing and querying data, managing schema change, and creating a protected sandbox. It could explain policy and translate intent into a query, while people controlled execution and the platform remained the source of truth.
Give the agent explicit intent, permission scope, data context, and a visible stopping condition.
Test planning, tool choice, generated-query review, confirmation, progress, and return-to-task behavior.
Specify MCP-compatible capabilities, inputs, outputs, permission checks, audit events, and recovery.
If a generated query referenced an unavailable field or data outside the user's approved scope, the experience surfaced the failed plan, tool constraint, and source mismatch. It preserved the request for revision; it did not silently repair or execute the query.
UX architecture
I mapped the actors, systems, permissions, decision points, and failure states across Data Viewer, Data Copy, Database Connection, schema drift, and clean-room workflows. The resulting architecture gave separate teams a shared backbone.
Developer
Data owner
Security reviewer
Platform operator
Identity and purpose
Access level and duration
Masking and exceptions
Audit and revocation
View and query
Copy and monitor
Connect and reuse
Detect and remediate
Specification system
Specifications became the operating contract between design and multiple engineering teams. They defined reusable field logic, environment behavior, validation, permission states, exception handling, and accessibility expectations.
Show only the inputs required by the selected data source and environment. Preserve the user's current task when a connection must be created in context.
Common patterns reduced relearning across viewing, copying, and schema workflows.
Requirements and blocked states explained what happened and what users could do next.
Teams could implement new connectors and environments from the same UX contract.
Cross-functional leadership
I connected product visions and technical constraints across Data Security, database platform teams, governance partners, and delivery teams. Workshops and decision records surfaced ownership gaps early and turned disagreement into explicit product rules.
Evidence, trade-offs, reflection
Data engineers, analysts, application teams, and governance owners entered with different expertise but needed the same answers about access, purpose, ownership, and risk.
I used workflow evaluation, usability signals, adoption data, and partner reviews to test whether people could move from intent to a governed outcome without losing context.
A single universal form would simplify implementation but overload users. I chose a shared trust model with contextual inputs and progressive disclosure by source, environment, and task.
The next step is longitudinal evaluation across recommendation accuracy, correction effort, blocked actions, and successful recovery, not adoption alone.
Impact
The governance experience had to make a large, distributed application estate understandable and actionable.
Shared rules connected classification, access, ownership, and remediation across a broad data estate.
Unique users for an early viewing workflow grew from 2 to 22 during the measured rollout period.
Next case