Designing manager experience for Tello’s access reviews, where busy, non-expert managers can quickly review access, make decisions, and move on.
In many organizations, managers are responsible for reviewing employee access to applications, data, and internal systems on a recurring basis. These reviews help prevent unnecessary permissions from accumulating over time and are often required for security audits and regulatory compliance. Although managers understand their teams, they typically have limited knowledge of identity governance, making periodic access reviews both time-consuming and mentally demanding.
The goal of this project was to design a review experience that reduced cognitive load, supported informed decision-making, and generated an auditable record—without requiring managers to become security experts.
Through stakeholder interviews and secondary research, I set out to understand:
Interviewed IT administrators, compliance specialists, and product stakeholders to understand business goals, regulatory requirements, and operational constraints that would shape the review experience.
Reviewed industry regulations (SOX, SOC 2, ISO 27001) together with existing identity governance platforms to understand compliance expectations, common review workflows, and opportunities to simplify complex administrative tasks.
Technical access data is difficult for managers to interpret.
High-risk access is hard to distinguish from routine permissions.
Large reviews encourage rushed or blanket approvals.
Decisions are rarely documented well enough for future audits.
When managers don't have enough information to judge whether access is appropriate, they tend to approve it rather than risk removing something important.
Rather than evaluating technical permissions, managers rely on information they already understand, such as an employee's role, recent activity, and day-to-day responsibilities.
Managers are more likely to complete reviews when repetitive work is minimized, while every decision still needs to be documented for future audits.
Problem statement
Managers are responsible for reviewing employee access, but they often lack the technical knowledge and time needed to make confident decisions. They need a process that provides clear context, minimizes repetitive work, and automatically records every decision for audit purposes.
help managers make confident access decisions?
reduce the effort required to complete reviews?
create an audit trail without adding extra work?
The design process started with defining the overall experience of how managers would navigate the review, make decisions, and move through the product efficiently before any visual design work began.
The journey map illustrates how managers progress through an access review, highlighting key actions, feelings, and opportunities to improve the overall experience.
| Trigger | Orientation | Review | Decision | Submit | |
|---|---|---|---|---|---|
| Action | Receives review notification via email | Lands on review dashboard, scans 12 reports | Scans permissions for each direct report | Approves, revokes, or flags each access item | Reviews summary and submits the review |
| Task list |
|
|
|
|
|
| Feeling adjective |
|
|
|
|
|
| Improvement opportunities |
|
|
|
|
|
The flow outlines the manager’s path through the review process, including key decisions, alternate paths, and error recovery.
The sitemap outlines the product structure, with the Manager Review workflow representing the primary scope of this project. Other sections are included for context.
The final manager experience, built from the design system. Each screen below carries one primary job—keeping the reviewer in a “get in, decide, get out” flow.
See every direct report’s access, usage, and anomaly flags at a glance.
Drill into one person’s access and grant/revoke history for the audit trail.
Track every review cycle’s progress, dates, and exportable evidence.
Approve or flag each integration per person, auto-saved as you go.
Revoke an integration in one tap, with instant confirmation.
Resolve AI-flagged risks before the review even begins.
These ideas weren’t included in the original project scope. They’re improvements I identified after mapping the user journey and noticing recurring friction points, and they would be my priorities for a future iteration.
Save commonly used approval or revocation reasons and apply them to multiple users at once, instead of typing the same justification over and over during large access reviews.
When a manager isn’t familiar enough with a user’s role or access, they can reassign the review to someone better equipped to make the decision.
Include an estimated completion time in Slack and email reminders, giving managers a better sense of the effort before they begin.
Let managers save frequently used filters, making it easier to focus on anomalies, overdue items, or other priorities during recurring reviews.