← All selected work

01 · Data security + governed agents

Making enterprise data safe for agent action.

One permission-aware experience for connecting, viewing, querying, copying, and governing data, with a supervised agent embedded at the point of work.

Role
Staff UX Designer · UX strategy lead
Scope
Cross-product and cross-organization
Partners
Product, engineering, security, platform teams
Talk track
18–20 minute case study

Insight layer

Governed data became a reusable path from signal to action.

Across the broader enterprise data ecosystem, I also led feedback and insights experiences that demonstrated what the foundation should enable. Teams could collect signals, define an audience, visualize patterns, and embed learning back into products without losing ownership or quality context.

Enterprise insight loopGeneralized from delivered work
01Collect
Capture structured signals
02Segment
Define the right audience
03Understand
Find patterns and themes
04Act
Embed insight in products
05Learn
Measure and improve
35→68

Experience NPS

A clearer end-to-end workflow materially improved user confidence.

228→309

Product adoption

More product teams embedded the shared feedback capability.

182→214

Teams onboarded

Standards and enablement helped the ecosystem scale beyond one team.

AI evolution

From AI assistance to permission-aware agent management.

Earlier work used AI to draft, visualize, and summarize. Later, I carried those lessons into a governed agent model: explicit task delegation, visible data sources, scoped tool access, review before execution, and recovery when a model or tool call was wrong.

Discover

Find the signal

Use AI to organize large volumes of feedback while preserving traceability to source data.

Decide

Explain the recommendation

Show assumptions, scope, and constraints so teams can judge whether an answer fits.

Enable

Scale the pattern

Turn prompt behavior, review states, accessibility, and failure recovery into reusable specifications.

Sanitized Data Copy Assistant database selection experience
Data Copy Assistant A governed database-selection experience with environment, classification, access status, and duration visible at the point of choice.

The mandate

The organization did not need another isolated tool. It needed a coherent governance experience spanning roughly 19,700 applications and more than 500 databases, without asking teams to learn a different trust model each time.

Developers moved between database viewers, copy tools, approval systems, schema workflows, and security controls. Each product had its own vocabulary and rules. I reframed the work from a set of feature projects into a platform-level experience architecture.

01 · Fragmentation

Many tools, no shared journey

Connections, access, masking, exports, and monitoring behaved differently across surfaces.

02 · Risk

Policy lived outside the experience

Users could not always understand why an action was blocked, approved, expired, or audited.

03 · Scale

Every team solved the same rules

Without shared specifications, engineering teams repeatedly interpreted common behavior.

Governed data agent

One agent, orchestrated across five governed tasks.

I designed and evaluated an agent embedded where users already had task context: connecting a source, copying governed data, viewing and querying data, managing schema change, and creating a protected sandbox. It could explain policy and translate intent into a query, while people controlled execution and the platform remained the source of truth.

Agent orchestration modelPublic-safe reconstruction
01Connect
Prepare a data source
02Copy
Move governed data
03View + query
Intent to query
04Manage schema
Review safe change
05Sandbox
Create protected space
The original assistant name, prompts, generated queries, internal interfaces, and system details are excluded.
Delegate

Assign a bounded task

Give the agent explicit intent, permission scope, data context, and a visible stopping condition.

Orchestrate

Select the right tool

Test planning, tool choice, generated-query review, confirmation, progress, and return-to-task behavior.

Architect

Define the contract

Specify MCP-compatible capabilities, inputs, outputs, permission checks, audit events, and recovery.

When the agent was wrong

If a generated query referenced an unavailable field or data outside the user's approved scope, the experience surfaced the failed plan, tool constraint, and source mismatch. It preserved the request for revision; it did not silently repair or execute the query.

UX architecture

One trust model, expressed across products.

I mapped the actors, systems, permissions, decision points, and failure states across Data Viewer, Data Copy, Database Connection, schema drift, and clean-room workflows. The resulting architecture gave separate teams a shared backbone.

Platform relationship mapReconstructed and generalized

People

Developer

Data owner

Security reviewer

Platform operator

Shared decisions

Identity and purpose

Access level and duration

Masking and exceptions

Audit and revocation

Product surfaces

View and query

Copy and monitor

Connect and reuse

Detect and remediate

Public-safe reconstruction based on journey architecture; internal names, systems, and identifiers removed.

Specification system

I made UX intent executable.

Specifications became the operating contract between design and multiple engineering teams. They defined reusable field logic, environment behavior, validation, permission states, exception handling, and accessibility expectations.

Sanitized data categorization and governance dashboard
Governance at a glance Categorization, sensitivity, and coverage were organized into one scannable operational view. Exact values are softened for public presentation.
Database connection behavior modelSanitized UX specification
Connection patternPurposeEntry pointsField rulesValidationReuseError states

Context-aware connection creation

Show only the inputs required by the selected data source and environment. Preserve the user's current task when a connection must be created in context.

EnvironmentControls available authentication and access duration.
Source typeDetermines required fields and validation sequence.
PermissionExplains approval, expiration, and restricted actions.
Visual rebuilt from authored specifications. Browser chrome, internal URLs, side navigation, names, and implementation details are intentionally excluded.
Consistency

Shared behavior

Common patterns reduced relearning across viewing, copying, and schema workflows.

Clarity

Policy in context

Requirements and blocked states explained what happened and what users could do next.

Durability

Reusable rules

Teams could implement new connectors and environments from the same UX contract.

Cross-functional leadership

Alignment was part of the product.

I connected product visions and technical constraints across Data Security, database platform teams, governance partners, and delivery teams. Workshops and decision records surfaced ownership gaps early and turned disagreement into explicit product rules.

Secure data workflowGeneralized journey
01Declare purpose
Source, target, use case
02Evaluate access
Identity, policy, duration
03Apply controls
Masking, approvals, validation
04Execute safely
Progress, errors, recovery
05Review and audit
History, results, revocation
Journey synthesized from Data Copy, Data Viewer, schema management, and clean-room materials.

Evidence, trade-offs, reflection

I tested the trust model, not only the screens.

People

Distinct users, shared controls

Data engineers, analysts, application teams, and governance owners entered with different expertise but needed the same answers about access, purpose, ownership, and risk.

Research + testing

Evaluate complete tasks

I used workflow evaluation, usability signals, adoption data, and partner reviews to test whether people could move from intent to a governed outcome without losing context.

Trade-off

Consistency without rigidity

A single universal form would simplify implementation but overload users. I chose a shared trust model with contextual inputs and progressive disclosure by source, environment, and task.

Reflection

Measure agent quality over time

The next step is longitudinal evaluation across recommendation accuracy, correction effort, blocked actions, and successful recovery, not adoption alone.

Impact

From feature delivery to platform leverage.

~19.7K

Applications in scope

The governance experience had to make a large, distributed application estate understandable and actionable.

500+

Databases governed

Shared rules connected classification, access, ownership, and remediation across a broad data estate.

10×

Early adoption signal

Unique users for an early viewing workflow grew from 2 to 22 during the measured rollout period.

Next case

Real-time Data Streaming Platform

View case study ↗