Security
Compliance
Let people prove their own devices — and let managers see the whole chain.
Apple employees were bringing their own devices onto the corporate network, and no one could tell whether those devices were safe. I designed the internal dashboard that closed that gap from both ends at once.
Visibility versus autonomy.
A personal device is only as safe as its owner keeps it — and nobody with responsibility for the network had any way to know whether a given device met policy. Employees wanted to be trusted with their own hardware. Security needed assurance. Managers sat in the middle, accountable for a team’s posture with no instrument to read it.
A clean, self-service way to see and fix their own devices.
A view across everyone who rolls up to them — reports, and their reports, all the way down.
What does “compliant” even mean?
I assumed there’d be one answer. There wasn’t. Compliance meant different things to different teams — a policy mandatory for one org was irrelevant to another, and the bar moved with your role and the data you touched.
Calm when it’s fine. Clear when it’s not.
For the individual, the experience was deliberately reassuring. “My Devices” showed each enrolled device and, in the happy path, a clean no-errors state. When something was out of compliance, the same view expanded to surface exactly which device and which policy needed attention — remediation by following the interface, not filing a ticket.
Frictionless at the exact moment it matters.
The moment a device first comes onto the network is exactly when you want compliance to be effortless. Enrolling a new device was its own guided flow, so it started right.
One view, from “all good” to “here’s the fix.”
A person could sit with a multiple-non-compliance state, expand a single offending item, and understand what to do next without leaving the page — the detail was always one tap away, never a maze.
Real org charts nest. A flat table falls apart.
The single hardest problem was showing a manager their chain of reportees when that chain had depth — managers who have managers reporting to them, each with their own reports. I got there through trial and error; several approaches broke down under the nesting.
What held was a tree structure paired with an overall compliance viewat the top: the tree let a manager expand the org level by level down to an individual’s devices, while the summary gave the one-glance read on the whole team. Once the tree clicked, the entire management experience resolved.
A user can always see their own data; a manager can always see their direct reports andthose reports’ reports.
The same structure, in production skin.
The wireframes settled the information architecture; the final pass dressed it in the visual language of the platform it lived on. Calm surfaces, system type, and status carried by color — the same two experiences, individual and manager, taken to a polished Apple-style interface.
My Devices, in the platform’s own skin.
Same happy-path-first structure as the wireframe — a calm device list, a device expanded to its policy checks — now rendered in system type and colors, with compliance status you can read at a glance.
Team View, drilling down to a single fix.
The overall read sits up top; the nested tree expands the org level by level down to one person’s devices — with a clear, one-tap path to send an update request to anyone out of compliance. This is where the data-driven design had to hold up under real org depth.
Two jobs, both done.
The design did the two things it was scoped to do: it gave individuals a self-service path to see and fix their own compliance, and it gave managers a real instrument — the tree plus the overall view — where before they’d had nothing. The rollout paired the platform with manager training and prominent intranet placement, so the tool met people where they already were.
Honest ending: the platform was being implemented as my contract wrapped, so I never saw the outcome data. The success metrics were defined — a measurable rise in device compliance, and utilization from both the management and individual sides — but I left before the numbers came in.
The right IA is the one that survives the real world.
This was my real education in data-driven design — making a large, relational dataset legible and actionable. The reporting tree taught me the lasting lesson: start from the true structure of the data, then design the drill-down.