Case Study

Signal | Human Risk Intelligence

Incident investigation built around the person behind the alert, so analysts can read intent, not just severity.

SignalDLP · v1.0.0
Risk Score
Elevated
78th
pctl
0/100
baseline 33 · peer avg 28 ▲ +41 · 24h
Intent Classification model v2.8
0% ACCIDENTAL DELIBERATE
Confidence · Deliberate
!
Likely deliberate exfiltration
Retry after block, rename to strip classification, and external personal address raise intent probability. Not yet conclusive.
Share activity 24hpeak 14:30
0006121824
ROLE

Product Design & System Architecture (Independent Concept)

Deliverables

System rules & component states · Single-screen deep dive · Interactive prototype

Focus

B2B Enterprise UX · Dense data interfaces · Human-centered security

Process

Used Claude artifacts for rapid HTML prototyping of dense data layouts, testing information hierarchy in working code before high-fidelity execution in Figma. Tools generate options; judgment selects, refines, and ships.

The product

The Screen

One incident. One analyst. Every relevant signal, in a single view.

Dense data interfaces are hard to evaluate in static mockups. Real numbers, real proportions, real overflow behavior reveal problems that Figma frames hide. The intent gauge, the weighted signals list, and the timeline each went through 3-4 functional iterations in HTML/React with Claude artifacts before any high-fidelity work in Figma. AI accelerated the cycle; the design choices remained mine.

The problem

Security teams don't lack data. They lack the story behind it.

Three fields the analyst still has to fill in. Press Signal.

Severity · High Q2-Pricing-Forecast.xlsx DLP-R-019 · external-share-restricted 14:32:07 PDT · DLP/email-gateway
Who
Daniel ReyesSenior Financial Analyst · Finance FP&A · tenure 4y 2m · risk 74/100, 78th pctl, +41 vs peer
Intent
68% deliberateRetried 2s after the block, renamed the file to strip its classification tag, sent it to a personal address. Not yet conclusive.
Response
Notify manager, then escalate2 of 4 actions recommended · 1 permanent · playbook PB-DATA-019

Existing tools show a file name, a severity level, and a policy violation. What they don't show is who the person is, whether this was a mistake or intentional, and what the right response actually looks like. Analysts are expected to make consequential decisions about real people, with almost no human context.

Drawn from public research on alert fatigue and SOC analyst workflows (CISA, Gartner).

Core Insight

An alert that says "HIGH RISK" without explaining why, or who, forces analysts to guess. Signal replaces the guess with a structured human profile, a behavioral timeline, and an intent model that makes the story legible before any action is taken.

Design Decisions & Trade-offs

Decision

Spectrum, not binary

The intent gauge shows a confidence percentage rather than a binary label. Reality is a spectrum. A 30% deliberate score requires a different response than 80%. Showing the number forces precision.

Trade-off

Transparent signals vs. cognitive load

Showing the individual signals that built the score adds complexity. But hiding them would make the system feel like a black box. Analysts need to be able to disagree with the model, so we showed the reasoning.

Trade-off

Action weight and consequence

Notify manager and Escalate to Insider Threat are both recommended, but one is reversible and one is permanent. So irreversible actions carry a distinct red treatment, sit outside “Run all recommended”, and require two-step confirmation.

Information architecture

What the screen is actually doing

Every column in the layout carries a distinct job. The left column answers who. The center column answers what happened. The right column answers how certain we are and what to do next. Together they replace a single alert with a complete picture.

The three columns of the Signal screen
The three columns

Who: Human context

Identity + Attribute Grid:

Six attributes that frame how to read everything else. Clearance and tenure aren't description, they're calibration.

Risk Score + Tags:

The number means nothing without the baseline. +41 above peer average is what makes 74 alarming.

Share Activity Chart:

The peak at 14:30 aligns exactly with the incident timestamp. The visual makes the connection before the analyst has to look for it.

Exfiltration Vectors Grid:

USB at 0B doesn't mean safe, it means that route was blocked.

Related Incidents:

Three incidents over 90 days turn this from a suspicion into a documented pattern.

Identity and attribute grid Risk score with baseline and tags Share activity chart, peak at 14:30 Exfiltration vectors grid Related incidents list

What happened: Incident timeline

Summary Layer:

Computed risk fields sit above the timeline, so the analyst starts with severity, scope and containment before reading the event stream.

Evidence Layer:

The file becomes the anchor object. Metadata, classification, and ownership explain why this specific action triggered the incident.

Timeline Layer:

Events from multiple systems are normalized into one sequence, with color used as a fast severity cue.

Summary layer: computed risk fields Evidence layer: the file as anchor object Timeline layer: events normalised across systems

What to do: Response

Intent Score:

The model output is exposed as an interpretable score, not a black box.

Weighted Signals:

Every contributing signal is shown with its positive or negative weight, so the analyst can challenge weak evidence and override the model.

Recommended Actions:

Response options are ranked from the same evidence model, so the investigation context becomes concrete next steps without taking the decision away from the analyst.

Intent gauge and weighted signals Weighted signals breakdown Ranked response actions
Design system

The system behind the screen

A screen this dense can’t be drawn, it has to be generated. Four rules produce every panel above, three of them the earlier trade-offs turned into something the system enforces.

01 · Spectrum, not binary

Severity is a scale, and colour never carries it alone

Four severity tokens, each shipping with a number and a text label, so the screen still reads for a colour-blind analyst and inside a pasted screenshot.

Cleared Neutral Elevated Critical
02 · Transparent signals

No number appears without its inputs

Every aggregate sits beside the weighted signals that produced it. If a number can’t be decomposed, it doesn’t earn a place on the screen.

Aggregate score Weighted signals Source event
03 · Component contract

Components carry states, not variants

Four repeating components, one declared state set each. Stale matters most: a signal from forty minutes ago shouldn’t look as authoritative as a live one.

Default Hover Focus Expanded Contested Stale
04 · Action weight

Irreversibility is a property of the action

Escalate to Insider Threat opens an HR file on a named employee and can’t be undone. The flag sits on the action, and the treatment follows from it.

Notify managerReversible · bulk-eligible
Escalate to Insider ThreatNo bulk · 2-step confirm
What it cost

A fifth severity step, or an action reversible only inside a time window, means changing the contract rather than adding a colour. Worth it here, where a wrong-looking screen has a person on the other end of it.

What This Proves

Signal demonstrates that enterprise security tools can communicate in human terms without sacrificing technical depth. Designing for data-dense B2B environments doesn't mean accepting visual chaos. It means building structure that holds under pressure. The intent model, the behavioral timeline, and the action hierarchy all speak the language of the domain: they show that good design isn't decoration. It's operational clarity.

If the work made sense to you,
let's talk.

guybsn@gmail.com