JupiterOne · AI risk & compliance platform

A million-entity security graph, made legible and AI-native.

The graph held millions of assets, identities and relationships, but the interface in front of it had stopped keeping up.

Role
Head of Product Design, Design Manager, PM
Company
JupiterOne
Scope
Full platform re-architecture
31.6%
improvement in account retention
56.9%
increase in product stickiness (DAU/MAU)
app.us.jupiterone.io/vulnerabilitiesLive prototype
JupiterOne vulnerabilities screen
Vulnerabilities after the rebuild: findings unified across sources, prioritised, and paired with a remediation plan. Live prototype, click through it.
In short
Problem
A decade of fast growth left the product inconsistent, slow at graph scale, and visually unable to carry the AI-native capabilities the company needed next.
My role
I led the rebuild, and the design system project end to end as its designer and PM, which we first designed in Figma and shipped in code alongside engineering.
Key decision
Rebuild the foundation first and let every surface inherit it, so the product became consistent by construction and ready for AI, with no risky big-bang cutover.
Outcome
31.6% improvement in account retention, 56.9% increase in product stickiness (DAU/MAU), and a design system a model can build against, collapsing the design-to-dev handoff.
Before

A mature product that had outgrown its foundations.

The same control had been rebuilt a dozen different ways, with no shared source of truth. Every workflow behaved a little differently, performance buckled as graphs grew into the millions of entities, and nothing on screen suggested the intelligence underneath.

The decision

Rebuild the foundation without taking the product offline.

Security teams live in this product every day, so a big-bang rebuild was never an option. I redesigned the foundation first and let every surface inherit it, shipping in slices so nothing went dark for a customer mid-quarter.

Consistency
by construction.

A token-based design system, so every screen behaves the same way, everywhere, by default.

The foundation

We changed the machinery, not just the surface.

A token-based system decided spacing, type, colour, iconography and interaction once, and every screen inherited it. The bigger shift was underneath: once the system was consistent enough to be read rather than interpreted, I packaged it as a Claude skill and started designing straight into code, opening pull requests alongside engineers instead of handing mockups across a boundary. What the team could build, and how fast, both changed.

J1 Design System
Design system The tokens, type and components the whole product, and the Claude skill, are built from.
What it enabled

The foundation is what let us build the rest.

With the machinery in place, the product could finally look as intelligent as the graph underneath it, and the AI work became possible because the foundation could carry it.

The graph, made legible.

The data model was the most valuable thing in the product and the least legible part of the interface. In the Graph Canvas you build a query and watch the traversal happen, so the shape of a relationship is visible while you are still forming the question.

app.us.jupiterone.io/query-builder
After Building a query and traversing relationships visually, rather than reading the result as a list.

AI a security team could trust.

Organisations were adopting AI faster than they could account for it: models, agents, keys and the identities attached to them, already in the environment and mostly outside anyone's inventory. The same graph could hold all of it.

A security team can't act on an answer it can't verify, so the assistant is built to be checkable. You can ask why, trace any conclusion back to the evidence in the graph, and see where confidence comes from, which shaped what it surfaces, how it shows uncertainty, and what it does when it is wrong.

app.us.jupiterone.io/assistantLive prototype
The assistant sits in context on every surface: ask a question, and trace the answer back to the evidence in the graph.
app.us.jupiterone.io/controls
After Compliance posture unified across frameworks, with the underlying evidence one step away.
app.us.jupiterone.io/ai-asm/dashboard
After AI assets, identities and exposure scored across the graph, with the highest-risk relationships surfaced first.
Responding to customers

What I learned: a new way of responding to customer feedback.

A customer flagged in Jira that coverage read two opposite ways across CCM: the main screen measured the share of controls passing, the requirement screen measured the share failing, so the same data pointed in opposite directions and you couldn't trust it at a glance.

I picked it up and shipped the fix myself. Every screen now reads coverage the same way: one bar that names passing, failing and not-measured side by side. I also redesigned and shipped the new navigation and more. I like working in Visual Studio Code because I can iterate quickly on customer feedback.

app.us.jupiterone.io/compliance/frameworks
CCM before: coverage shown as a lone pass rate, framed differently from other screens
app.us.jupiterone.io/compliance/frameworks
CCM after: one consistent status bar naming passing, failing and not measured
github.com/JupiterOne · PR #1795
The merged pull request that shipped the fix, one status-bar language across CCM
Before Coverage shown as a lone pass rate. On the requirement screen the same data was framed as failure, so the numbers seemed to disagree.
What customers said
NO
N.O.
Head of Security

"I honestly like the new look and feel of the UI very much, for the most part. Great job."

PA
P.A.
Security Lead

"It looks like the whole place got a revamp. It's a new world."

TR
T.R.
Platform Engineer

"There's a lot of good things happening recently. I'm seeing all these changes. It's getting better."

EB
E.B.
CISO

"The assets UI looks a lot cleaner already, which I really like."

MF
M.F.
Security Engineer

"I like the new UI. It abides by my dark setting, which is nice, because before, part of it was dark and part of it was light."

DV
D.V.
Head of Platform

"You deployed this whole new application, and it's a huge improvement. It looks better and it works better."

The results
31.6%
improvement in account retention
56.9%
increase in product stickiness (DAU/MAU)

Currently

the J1 design-system skill is shared across the organisation

anyone can prototype against the real design system, not only designers

the design-to-dev handoff is largely gone

Go to next →