← Back to all work
Case Study · Enterprise Security

Comply

A tool that helps security teams find and fix compliance gaps and software vulnerabilities across every computer in a company.

RoleLead Designer
TeamPM, Engineering, QA
ChallengeRestructure a setup-first tool around what teams needed to accomplish

What it is, and who it's for

Companies have to follow security rules — some for their own protection, some required by regulations specific to their industry, like healthcare or payment data. Comply is the part of Tanium that checks every computer in a company against those rules and reports where it falls short, alongside checking for known software vulnerabilities that could be exploited by an attacker. It's used by security and compliance teams responsible for proving their organization meets these standards and for closing any gaps before they become a real problem.

Comply overview dashboard
Comply Overview. Select to enlarge

A team can check results two ways: against compliance rules or against known software vulnerabilities. Compliance results show which computers pass or fail each rule. Software vulnerability results show which computers are vulnerable checked against a continuously updated list.

Compliance findings view
Compliance Findings. Select to enlarge

Ordering the product around what people actually needed

Comply was originally organized around configuring the tool and running scans, not around understanding what came back. Working with my product manager and the product team, we instead structured the product around the tasks teams actually needed to accomplish their goals:

From the redesign two key design patterns emerged — pivot views for analyzing the data from multiple viewpoints and a content-rich side panel for details about each issue. These were the first introduction of these design patterns in the platform. Due to their success with users they became core patterns throughout the site over time.

Vulnerability findings view
Vulnerability Findings. Select to enlarge
Vulnerability detail panel showing known exploit activity
Vulnerability Detail. Select to enlarge

Takeaways

This redesign laid the groundwork for future product work such as in-product remediations that work in direct correlation with resolving issues uncovered by a team's analysis. By shifting the product to be focused on users' tasks and goals, we empowered users to understand, find, and resolve the most impactful problems across their company.

Remediations view, showing top patches by CVE severity
Remediations. Select to enlarge
Remediation detail panel for a specific patch
Remediation Detail. Select to enlarge