Project type
SaaS, B2B, Internal enterprise tool
My role
End-to-end, UX Research, UX/UI Design; collaborated with senior Product Designer.
Duration
1 month
Tools
Figma, Claude Design
View prototype

Periodic Access Reviews

Designing manager experience for Tello’s access reviews, where busy, non-expert managers can quickly review access, make decisions, and move on.

Tello — My Access Review list and ongoing access review screens
Overview

In many organizations, managers are responsible for reviewing employee access to applications, data, and internal systems on a recurring basis. These reviews help prevent unnecessary permissions from accumulating over time and are often required for security audits and regulatory compliance. Although managers understand their teams, they typically have limited knowledge of identity governance, making periodic access reviews both time-consuming and mentally demanding.

The goal

The goal of this project was to design a review experience that reduced cognitive load, supported informed decision-making, and generated an auditable record—without requiring managers to become security experts.

My Team — team access overview User Details — Access User Details — Grant/Revoke Access My Access Review Ongoing Access Review — AI recommendation resolved

Empathize

Research

Through stakeholder interviews and secondary research, I set out to understand:

  • The information managers need to confidently determine whether access should be retained or removed.
  • The friction points that discourage managers from completing periodic reviews, and ways to reduce effort without compromising review quality.

Stakeholder interviews

Interviewed IT administrators, compliance specialists, and product stakeholders to understand business goals, regulatory requirements, and operational constraints that would shape the review experience.

Secondary research

Reviewed industry regulations (SOX, SOC 2, ISO 27001) together with existing identity governance platforms to understand compliance expectations, common review workflows, and opportunities to simplify complex administrative tasks.

Define

Common pain points

Complex permissions

Technical access data is difficult for managers to interpret.

No clear priorities

High-risk access is hard to distinguish from routine permissions.

Repetitive reviews

Large reviews encourage rushed or blanket approvals.

Limited audit evidence

Decisions are rarely documented well enough for future audits.

Target users

Persona card for Marco Reyes, Marketing Manager and primary user, with goals and frustrations. Persona card for Dana Whitfield, IT Manager and primary user, with goals and frustrations.

Research insights

Managers approve access when they lack enough context

When managers don't have enough information to judge whether access is appropriate, they tend to approve it rather than risk removing something important.

Managers need context to make confident decisions

Rather than evaluating technical permissions, managers rely on information they already understand, such as an employee's role, recent activity, and day-to-day responsibilities.

Reducing effort improves completion

Managers are more likely to complete reviews when repetitive work is minimized, while every decision still needs to be documented for future audits.

Problem statement

Managers are responsible for reviewing employee access, but they often lack the technical knowledge and time needed to make confident decisions. They need a process that provides clear context, minimizes repetitive work, and automatically records every decision for audit purposes.

How might we…

help managers make confident access decisions?

reduce the effort required to complete reviews?

create an audit trail without adding extra work?

Ideate

Mapping the experience

The design process started with defining the overall experience of how managers would navigate the review, make decisions, and move through the product efficiently before any visual design work began.

User journey

The journey map illustrates how managers progress through an access review, highlighting key actions, feelings, and opportunities to improve the overall experience.

User journey map across five stages — Trigger, Orientation, Review, Decision and Submit — with rows for action, task list, feeling adjective and improvement opportunities.
TriggerOrientationReviewDecisionSubmit
Action

Receives review notification via email

Lands on review dashboard, scans 12 reports

Scans permissions for each direct report

Approves, revokes, or flags each access item

Reviews summary and submits the review

Task list
  • Open email
  • Click review link
  • Log in to platform
  • View report list
  • Understand scope
  • Find starting point
  • Open each report
  • Decode permission names
  • Check last login
  • Choose approve/revoke
  • Add justification
  • Flag for IT
  • Check summary
  • Submit review
  • Receive confirmation
Feeling
adjective
  • Surprised
  • Reluctant
  • Rushed
  • Uncertain
  • Overwhelmed
  • Lost
  • Confused
  • Cautious
  • Slow
  • Tentative
  • Responsible
  • Unsure
  • Relieved
  • Done
  • Satisfied
Improvement
opportunities
  • Clearer email subject
  • Time estimate in notification
  • Progress indicator
  • “Start here” prompt
  • Plain-language labels
  • Last-login data inline
  • Decision templates
  • Inline usage context
  • Change summary view
  • Easy revisit option

User flow

The flow outlines the manager’s path through the review process, including key decisions, alternate paths, and error recovery.

User flow diagram: Start, Email Notification, Log In, Review Dashboard, Select Report, View Permissions, decision points for action taken and more reports, Confirm and Submit, error/retry, Success, End.

Sitemap

The sitemap outlines the product structure, with the Manager Review workflow representing the primary scope of this project. Other sections are included for context.

Sitemap tree for Smart Access Reviews with Auth, Manager Review (My Reviews, Review Detail, Active Review, Review History), Admin/Compliance (Review Cycles, Reports & Audit, Progress Tracker), and Settings.

Design system

Design system board: application shell preview, colour tokens, Inter type scale, and a component inventory (buttons, badges, toggles, avatars, inputs, spacing and radius) extracted from the Tello prototype.
Prototype

Key functions

The final manager experience, built from the design system. Each screen below carries one primary job—keeping the reviewer in a “get in, decide, get out” flow.

My Team

See every direct report’s access, usage, and anomaly flags at a glance.

Tello My Team screen shown in an iPad frame.

User Details

Drill into one person’s access and grant/revoke history for the audit trail.

Tello User Details screen shown in an iPad frame.

My Access Review

Track every review cycle’s progress, dates, and exportable evidence.

Tello My Access Review screen shown in an iPad frame.

Ongoing Access Review

Approve or flag each integration per person, auto-saved as you go.

Tello Ongoing Access Review screen shown in an iPad frame.

Revoke Access

Revoke an integration in one tap, with instant confirmation.

Tello Revoke Access screen shown in an iPad frame.

AI Recommendations

Resolve AI-flagged risks before the review even begins.

Tello AI Recommendations screen shown in an iPad frame.
Nice to haves

What I’d build next

These ideas weren’t included in the original project scope. They’re improvements I identified after mapping the user journey and noticing recurring friction points, and they would be my priorities for a future iteration.

Decision templates

Save commonly used approval or revocation reasons and apply them to multiple users at once, instead of typing the same justification over and over during large access reviews.

Delegation and reassignment

When a manager isn’t familiar enough with a user’s role or access, they can reassign the review to someone better equipped to make the decision.

Smart nudges with a time estimate

Include an estimated completion time in Slack and email reminders, giving managers a better sense of the effort before they begin.

Saved views and filters

Let managers save frequently used filters, making it easier to focus on anomalies, overdue items, or other priorities during recurring reviews.