
Case study
Enterprise Access Governance
Designing enterprise permissions people can reason about
at Appsmith ↗Choose your depth
The problem, my contribution, outcomes, and strongest screens.
My role
Lead product design · Enterprise UX · Information architecture
Product focus
Granular access governance across people, groups, nested resources, actions, and audit history.
The Short Version
I led the experience design for Appsmith’s access control: users, user groups, permission groups, application resources, and the audit log behind all of it. The goal was least-privilege configuration that still gave administrators the evidence to investigate access after the fact.
The Mess
Enterprise administrators needed resource-level control without every permission change turning into a specialist’s afternoon. People, groups, nested application resources, and the actions allowed on each one had to stay understandable even at organisational scale.
My Part in This
- Modelled people, user groups, permission groups, resources, and actions as one connected governance system.
- Translated least privilege, data protection, and public exposure into clear product value and concrete controls.
- Designed an expandable resource matrix, group assignment, search, invitations, and explicit saving.
What Got Better
- Made complex permission scope inspectable before administrators changed access.
- Connected least-privilege controls with the audit evidence needed to investigate incidents later.
Impact
What Actually Moved
For the Business
A connected governance model strengthened enterprise readiness across users, groups, permissions, resources, and audit history.
For the Humans
Administrators can prevent risky access, understand permission scope, and trace incidents without reconstructing context.
For the Spreadsheet
Supports enterprise adoption and expansion by making granular access control a credible, operable product capability.
Highlights evidence
3 essential screens from the final experience.
Continue reading