Solving for application classification mismatch

Solving for application classification mismatch

Solving for application classification mismatch

Role

Role

Lead Designer

Lead Designer

Team

Team

PM, Engineer and Designer

PM, Engineer and Designer

Duration

Duration

2 weeks

2 weeks

Problem

The platform ran two classification systems side by side — a legacy model and a newer one. Applications harvested into the platform sometimes arrived carrying both, and the two didn’t always agree.
When they disagreed, the platform resolved the conflict by assigning the higher of the two classifications. No explanation or notification was given, and there was no path to challenge it. An application could be marked sensitive without its owner knowing why.
The platform ran two classification systems side by side — a legacy model and a newer one. Applications harvested into the platform sometimes arrived carrying both, and the two didn’t always agree.
When they disagreed, the platform resolved the conflict by assigning the higher of the two classifications. No explanation or notification was given, and there was no path to challenge it. An application could be marked sensitive without its owner knowing why.

How we found out

Tickets from the

last 60 days

Understanding the two classifications

Before designing anything, I needed to understand where each classification actually came from, because the source determines what a user can do about it.
Before designing anything, I needed to understand where each classification actually came from, because the source determines what a user can do about it.

Classification 1 (C1)

Classification 1 (C1)

Comes from the columns under the application.

Comes from the columns under the application.

Classification 2 (C2)

Classification 2 (C2)

Comes from a completed assessment and a sample data upload.

Comes from a completed assessment and a sample data upload.

When a mismatch happens, the platform resolves the conflict by assigning the higher of the two classifications.

The questions that shaped the design

Working through the flow surfaced four questions the interface had to answer:

Q1. What is the owner supposed to do when a mismatch occurs?

Verify the assigned classification.

Q2. Why does it matter to them?

A sensitive classification can trigger downstream security obligations. An SSP, for example, carries consequences for how the application must be operated.

Q3. What if they disagree with the assigned classification?

They need to give the information that would change it, and that information differs depending on which classification is in play.

Q4. How would they even know there's a mismatch?

Email notification. A passive state change isn’t otherwise surfaced on a page most owners rarely visit.

Beyond the interface

Before

The existing classification page displayed the plan classification alongside every table included in the classification. It was accurate but static — a readout with no reasoning and no action.

The redesign

I started from the flows rather than the layout, mapping what "change this" means in each state.

Below is the redesigned classification page.

Feedback and outcomes

  1. The AI explanation was well received. It was the most positively received element with both compliance and application owners, and it addressed the ticket pattern the PMs had been absorbing.
  2. Follow-on discussion. Once explainability was addressed, discussion shifted to notification design and automating the resolution process.

Results

Close to 20 tickets came in over one to two months after the new classification model was introduced, most asking why an application had been marked sensitive. Since the redesign, PMs have not received that question — owners can see the reasoning and their next step on the page itself.
Close to 20 tickets came in over one to two months after the new classification model was introduced, most asking why an application had been marked sensitive. Since the redesign, PMs have not received that question — owners can see the reasoning and their next step on the page itself.

Other projects

Other projects

Other projects