
Turning tangled network policy into a visual, natural-language security model.
Average task success on the first attempt in usability testing.
Average satisfaction across attitude, impact, navigation and content clarity.
Designers mentored through the testing programme.
Project Overview
Project Overview
The user problem
It is very difficult to ascertain that data is transiting a cloud environment as intended, even without the activities of a hostile actor. Security analysts, architects, testers, and compliance and executive stakeholders all needed to visually discover, classify, protect and monitor sensitive data, and to enforce policy across the OCI network and multi-cloud without hand-writing IP rules and firewall configs.
The business objective
Build a smart security system that acts as an intelligent gatekeeper for cloud traffic: label resources in plain terms like "mobile banking app" or "biographical data," then let customers set simple rules between labels via policy, rather than navigating interconnected security tables. Anything that doesn't match a rule is blocked, keeping the system secure and manageable as it grows.
My role and scale of ownership
I owned UX end to end for ZPR: I ran the kickoff workshop to align product and tech on deliverables and timeline, led discovery and IA, ran the usability testing programme (protocol, recruiting, sessions, analysis and reporting) while mentoring four other designers, drove insight-led iteration through a mid-project change in vision, and created the UX debt repository used to prioritise fixes through handover.
How I got from insights to product value
Discover
Ran a kickoff workshop to align product and tech on UX deliverables and timeline, securing buy-in for the process and clearing fears that research would derail delivery.
Define
Defined four core use cases, the information architecture and the user journey map, surfacing flows and blind spots the team hadn't considered.
Design
Explored low-fidelity concepts across four journeys, adapted to a mid-project change in vision, then validated the direction through usability testing.
Deliver
Logged UX debt to prioritise fixes, and handed over canvas templates, navigation, components and page variations to engineering.
Execution
Execution
Users, needs and the solution
The tool needed to serve security analysts, security architects, security testers, compliance and office managers, and a chain of executive stakeholders up to the CIO and VP of IT. Across those personas, the needs converged on a handful of jobs: visually discover, classify, protect and monitor sensitive data; describe intent for data movement in natural language rather than code; enforce policy across the OCI network and multi-cloud; define the perimeter of what needs securing; map sensitive data to the right storage resources; and manage attributes, data zones and policies as first-class resources.
The solution we designed is a smart security system that acts as an intelligent gatekeeper for cloud traffic and visualises data flows. Instead of complex IP rules and network firewalls, resources carry clear labels, like "mobile banking app" or "biographical data," and customers set simple rules between labels, like "mobile banking app can access biographical data," via policy. Anything that doesn't match a rule is blocked, which keeps the system secure and easier to manage as it grows. A set of resources sharing an attribute becomes a data zone, and a policy applied to that zone extends and enforces protection across the OCI network and cloud services, on-premises and multi-cloud.
Project planning and kickoff workshop
I discussed UX deliverables, milestones and outputs with product and tech during project kickoff, then ran a workshop to align everyone on that plan and the current timeline. It secured buy-in for the UX process: product and tech contributed to planning by reviewing dates, misconceptions about time spent on task were cleared, fears that UX activities could derail delivery were eliminated, and the team aligned on deliverables.
Out of that workshop came four main use cases that shaped every flow after: data discovery, where the system identifies sensitive data against user-defined criteria and suggests attributes to classify it; manual creation, where users classify resources with attributes and create the policies that allow communication; managing day 1, where a user visualises the attributes and policies just created; and managing day 100, where a user navigates a wide range of policies and attributes created by them or others.
Defining information architecture and the user journey
Defining the IA enabled discussions about structure, helped dev build the initial application structure, ensured a shared understanding across the team, and helped prioritise work. It also closed blind spots we would otherwise have missed, namely deep links to ZPR table views from within the service, and access to a protected resource's details page from external services.
Mapping the user journey surfaced flows that could have been missed otherwise, such as saving an interrupted setup, and set the foundations for the IA discussions that followed.
Information architecture and user journey map.
Exploring solutions: low-fidelity concepts
We explored four journeys in parallel: system-assisted classification for data discovery, manual tag creation, a view mode for two tags, and two approaches to progressive disclosure for aggregate policies, showing and hiding policy detail. A later, iterated pass tackled the day 100 view at scale (100 tags), including earlier explorations of audit and risk views.
Low-fidelity concepts across the four core journeys, plus an iterated day 100 view.
A change in vision
Midway through, the vision shifted: complexity increased with two additional hierarchical levels, VCNs and gateways, while scope for the MVP narrowed to view mode only, with creation flows descoped. We re-explored the day 1 view (two tags) with the new security attribute in place to reflect this.
Day 1 concept revised for the security attribute, VCNs and gateways.
Evaluative research
The usability testing goal was to evaluate the concept proposal and understand whether it matched users' mental models. I created the testing prototype, defined the testing protocol, recruited participants, gathered insights during sessions, analysed the data, wrote the final report, and mentored four other designers through the process.
Usability testing sessions, protocol and analysis.
Insight-driven iterations
Testing insights fed directly back into the product, its icon language, and its navigation, with each round of sessions producing concrete changes rather than open questions.
Concepts evolution
The security attribute and the day 100 view each went through several rounds of evolution, moving from early exploratory sketches to the validated, production-ready patterns used at handover.
Logging UX debt
I created a UX debt repository to document, monitor, systematically identify and address usability issues that accumulated over time. It helped design, product and tech track and prioritise issues that could detract from the overall experience, and supported more efficient resource allocation so teams could focus on the most critical areas for improvement.
Examples of logged, prioritised debt: manually bulk-tagging 2+ resources (P1), a resources-at-risk notification feature (P2), a WYSIWYG manual creation flow (P3), and the automatic data discovery flow (P4).
Handover
Engineering handover covered canvas template variations, navigation variations, components, and page, side panel and overlay variations, giving the team a complete, production-ready system to build from.
Canvas template variations handed over to engineering.
Navigation variations, components, and page, panel and overlay states.
Results & Business Impact
Results & Business Impact
Fewer configuration mistakes, easier to manage security
The visual, attribute-based model helped users discover, classify, protect and monitor sensitive data across cloud, on-prem and hybrid environments, bridging the gap between user intent and scalable, enforceable security: better security, fewer configuration mistakes, and a system that stays easier to manage as it grows.
Average task success on the first attempt.
Average satisfaction across attitude, impact, navigation and clarity.
Projected task success had the misleading gateway attribute stayed in, vs. 91.6% once removed.
Validated an architectural decision
Usability testing confirmed the gateway attribute was misleading users, directly driving the decision to remove it, and preserving a 91.6% task success rate against a projected 75% had it stayed.
From tables to visual intent
Shifted the experience from navigating technical policies in table formats to visualising and managing data and connections through intuitive, attribute-based controls.
"Once we could see the connections instead of just the rules, it was obvious what to fix."
Buy-in for the UX process
Product and tech contributed to UX planning, misconceptions about time spent on task were cleared, and fears that UX activities could derail delivery were eliminated.
A living UX debt backlog
The UX debt repository gave design, product and tech a shared, prioritised view of usability issues, supporting more efficient resource allocation toward the most critical areas.
Mentorship at scale
Mentored four other designers through the usability testing programme, from protocol design to session moderation and analysis.
Recommendations
Recommendations
What people say about working with me
“Inês is an exceptional user experience researcher and designer. Her dedication to creating a seamless and intuitive experience coupled with the relentless explorations and optimisation of the use of existing design patterns has not gone unnoticed.I worked with Inês on the development of an interface and user flow for a brand new product to support complex research processes for genomics data processing. Her work was crucial in triggering discussions on the technical implementation and her prototypes made several conversations much easier. Inês did not limit herself to just design a like-to-like user experience based on the product team prototypes, she wanted to understand the user needs and translate that into an interface that not only met the needs but exceeded expectations. Inês would iterate over and over again with feedback from product, from users, from engineers and from her own team, I've never seen Inês frustrated by this. Inês was a quick responder, acting fast with a basis for our work and then iterate over and over until we were all satisfied with the result. We worked at the transition between design systems, Inês embraced the challenge with both arms and always ensured constant feedback back to other teams about challenges or usability findings.Inês led the work without ego and made it truly a co-design experience while putting users at the centre. Inês was always prepared to cover for others and putting additional effort at the cost of her own personal time to drive the work forward. Moreover, the collaborative spirit and professionalism demonstrated throughout the design process have been invaluable for me personally. Inês was always very transparent in her communications and ensured she brought all stakeholders and cards to the table so that the best decisions could be made collaboratively.Inês is an inspiration for me and for the colleagues in her team, she truly cares about her work and doing better everyday.”
“Any software development team fervently hopes for a UX designer like Inês. I was very fortunate to work with her in the early stages of a project, where we were defining and adjusting the UI text for several different workflows. Frequently, our conversations led not only to the best placement of in-application content, but enhancements to the design itself.Inês' superpower is the ability to simultaneously hold deep technical nuance of the product, consistency of design standards, and the ability to improvise, while making it all look effortless. She is a great communicator, and conveys her ideas gently, thoughtfully, and thoroughly. She is also an excellent leader who brings people to her understanding by showing, not just telling.I would relish the opportunity to work with Inês again, and cannot overstate my informed opinion that she would be an incredible asset to any organization.”



