Transforming compliance into confidence
PURPOSE
Modern enterprise app publishing requires strict oversight of which APIs and data scopes each app can access. The existing permission review process was entirely manual: fragmented across spreadsheets, forms, and subject-matter expertise. Our goal was to redesign and partially automate this governance workflow through a conversational AI assistant, reducing review time while enforcing least-privilege access.
MY ROLE
As UX Strategy & Systems Design Lead, I defined the Copilot’s information architecture, conversation logic, and probabilistic decision framework. Partnering with Technical Architects, Security and Privacy SMEs, and Engagement Managers, I transformed scattered tribal knowledge into a structured, auditable guidance system.
TEAM
1 designer (myself)
3 Copilot developers
2 Technical Architect SMEs (~2 h/week)
Rotating Security and Privacy reviewers
4-week agile sprints (Phase 2 maturity)
Timeline: 12-week proof-of-concept phase.
OUTCOME
A production-ready prototype that guides developers through permission selection, flags potential compliance risks, and recommends safer alternatives, cutting manual review loops and improving throughput consistency.
ROLEUX Lead
CLIENTGlobal Fortune 50 Technology Company
DATE2025