Case Study: Enterprise tooling

Simplifying incident response: A unified interface for faster resolution

Problem: Incompatible systems and poor UX create operational friction
Enterprise tooling accumulates rather than gets designed, layering new systems on old ones into a fragmented ecosystem of disconnected workflows. In high-stakes incidents, that fragmentation, worsened by poor UX, slows teams down. Critical data and actions are scattered across disparate systems, technical and non-technical ops personnel alike struggle to collaborate efficiently, and time-to-resolution increases exactly when speed matters most.

Solution: Design for urgency not happy path
Escalation is business as usual. In a crisis, usability is a force multiplier, not a nice-to-have. By replacing fragmented tools with one unified, easy-to-use interface, we cut friction and training barriers to make it just as intuitive for non-technical ops as it is for technical engineers. Guardrails are built in, not bolted on, so speed never comes at the cost of safety, and every team can act fast and consistently when time matters.

Deliverables: Detection, validation, and action in a single, continuous workflow
We redesigned the detection and response workflow, powered by a single unified interface that serves as the entry point into the broader tooling ecosystem. The new workflow spans three connected screens, each addressing a distinct stage of the response process:

  1. Personalised dashboard: A single home base where operators can search, select, and manage every detection policy in one place, replacing the need to navigate across disconnected tools.

  2. Prompt configurations & result: Operators can view a live detection verdict, review the model’s performance & reasoning, and directly adjust or enforce action within a single screen.

  3. Validation: Before any classifier change reaches production, the system validates it end-to-end so operators can deploy with confidence, not guesswork.

The three screens enable first-line operators to directly adjust detection classifiers and deploy them safely in a single workflow, rather than as disconnected steps. This allows them to act with speed and precision when it matters most. View prototype

 

My role

Reflection

Results: Built in under 3 months, delivering speed and precision
This unified workflow was itself built and shipped as a zero-to-one effort in less than 3 months, reflecting the same urgency principle it was designed to support. The results fell into two categories: speed and precision.

  • Speed
    By consolidating investigation, detection, and response into a single workflow, teams saw a meaningful reduction in time-to-mitigation during live incidents. A key driver was the ability to deploy fine-tuned classifier adjustments directly within the response workflow—removing the delay of a separate handoff step.

  • Precision
    Because classifier tuning is now embedded in the response workflow, teams could iterate on detection logic more frequently and closer to real incidents. This produced incremental improvements to detection precision, gains that build over time through faster, more frequent tuning cycles, rather than a one-time jump from the interface itself.