Access
Control

Copilot

DESIGNING TRUST
DESIGNING TRUST
DESIGNING TRUST
DESIGNING TRUST

Creating a conversational AI that interprets policy, explains risk, and builds confidence through clarity.

01

What if developers didn't need to wait for an expert to make the right decision?

Developers often needed expert guidance before publishing applications, but the knowledge required to make compliant decisions was fragmented across documentation, policies, and a small group of subject matter experts.

This project explored how an AI Copilot could transform that expertise into on-demand guidance, helping developers evaluate permissions, understand risk, and move forward with greater confidence.

As UX Strategy & Systems Design Lead, I defined the Copilot's information architecture, conversation framework, and decision-support experience, translating complex governance policies into guidance developers could actually use.

Team1 Designer · 3 Developers · Security, Privacy & Architecture SMEs

  • ROLEUX Lead

    CLIENTGlobal Fortune 50 Technology Company

    DATE2025

02

The knowledge existed. Access to it didn't.

Context
  • The expertise needed to make compliant publishing decisions already existed within the organization. The challenge was that it lived across documentation, policies, chat threads, and a small group of specialists.

    Developers often entered the process unsure which permissions were appropriate, while reviewers spent valuable time answering the same questions repeatedly. As application volume increased, the gap between available expertise and developer needs became increasingly difficult to sustain.

Lattice-shaped abstract mountain full of lines and connecting dots.
Success metrics
  • Approval cycleunder 10 business days from 20-30 days

Re-review rateReduced from 32% to 10%

Critical risk permissionSelection reduced from 35% to 10%

Developer self-serviceHigher self-service accuracy every step

03

We studied how experts evaluated risk.

We started by understanding how decisions were made
  • Through workshops with Security, Privacy, and Architecture SMEs, we mapped the questions, tradeoffs, and escalation paths that shaped real permission reviews.

    Rather than documenting policies alone, we focused on understanding how experts determined whether a request was safe, risky, or required further investigation.

What we found
  • Expertise didn't scaleCritical decisions depended on a small group of specialists with limited availability.

    Knowledge was fragmentedPolicies and guidance were spread across multiple sources, making answers difficult to find and harder to trust.

    Trust had to be earnedPrevious AI prototypes struggled with accuracy, making explainability and reliability essential.

    Risk wasn't always obviousDevelopers needed clearer guidance on how different permissions affected security and compliance outcomes.

We transformed expertise into a repeatable system
  • Although individual scenarios varied, most reviews followed a surprisingly consistent pattern. Experts evaluated risk, impact, and available alternatives before determining the appropriate path forward.

    Those patterns became the foundation for the Copilot's reasoning framework. Permissions were organized into clear risk categories, escalation paths were defined, and guidance was structured around helping developers understand both the recommendation and the reasoning behind it. The goal was to make their expertise available more consistently.

Simplified User Flow
Simple flow detailing the logic of the Governance Copilot.
Designing the system was only half the challenge
  • A correct answer wasn't enough. Users also needed to understand why it was correct.

    Throughout prototyping and testing, we refined how recommendations were explained, when confidence should be surfaced, and where human review remained essential.

    In governance workflows, trust matters as much as accuracy.

04

The hardest part wasn't finding information. It was knowing what to trust.

Information alone wasn't enough.
  • Early versions of the Copilot focused on helping developers find answers faster. While useful, we quickly discovered that access to information wasn't the core problem.

    Developers also needed context, recommendations, and a clear understanding of risk. Simply presenting policy details often increased uncertainty rather than reducing it.

    As the product evolved, we shifted from information retrieval toward guided decision support. The Copilot learned to explain risk, recommend safer alternatives, and surface additional context only when it helped users move forward.

Finding answers was the starting pointThe initial proof of concept focused on retrieving information from fragmented documentation.

More information didn't always create claritySurfacing every possible risk and policy detail increased transparency, but also increased cognitive load.

Guidance proved more valuable than completenessThe Copilot began prioritizing safer recommendations and opinionated defaults, helping users move forward with confidence.

Context came before recommendationsBefore suggesting permissions, the Copilot gathered the information experts would normally ask for during a review.

Additional detail appeared only when neededSupporting artifacts, comparisons, and explanations were surfaced contextually rather than all at once.

05

The right decision became easier to make.

Expertise became available at the moment it was needed
  • The Copilot helped transform a process that depended heavily on expert availability into one that provided immediate guidance to developers.

    By making governance knowledge easier to access, understand, and apply, the system reduced unnecessary review cycles, improved consistency across teams, and allowed specialists to focus on the requests that genuinely required human judgment.

    Our Copilot demonstrated that AI could play a meaningful role in high-trust enterprise workflows by extending the reach of experts, not replacing them.

Outcomes

Faster DecisionsDevelopers received guidance earlier in the process, reducing review delays and unnecessary rework.

Fewer Re-ReviewsBetter recommendations helped teams submit more complete, policy-aligned requests on the first attempt.

Consistent Governance Shared evaluation logic reduced variation across reviewers and approval outcomes.

Scalable ExpertiseKnowledge that once depended on a handful of specialists became available to a much broader audience.

06

Confidence is a design problem.

Good decisions require understandable reasoning
  • “At enterprise scale, design’s highest value isn’t aesthetic polish, it’s structuring probabilistic systems so people can act with confidence.”

    This project reinforces that accuracy alone isn't enough.

    People need to understand why a recommendation was made, when they should trust it, and when human judgment should take over.

    The most successful version of the Copilot was the one that made complex decisions easier to understand.