Making complex access decisions easier to manage
I designed and tested an MVP that helped internal teams manage account-level access without relying on a complicated permissions model.
Note: To respect confidentiality, names, business details and visuals have been anonymized.
The challenge
As part of a broader move from a manual service to a digital workflow, the project needed a clear way to manage access across related accounts and contacts. A typical hierarchy of roles and permissions would have added complexity without fitting the real need: access had to be managed at the account level, person by person.
My contribution
Building on my earlier research and service-blueprinting work, I designed an access-management MVP around one clear rule: a contact either has access to a specific account or does not. I created flows for viewing contacts, assigning and removing access, and checking access from both contact and account views. I also included single and bulk editing, importing contacts between accounts, and transitional tools for sharing selected contact details while the digital workflow was introduced gradually.
How I approached it
I kept the access model deliberately simple and iterated through regular team feedback and two rounds of usability sessions. I first explored grouping users to manage access together, but mixed feedback in the first round showed that it added complexity. I replaced it with bulk editing, giving users a more direct way to update access across several people. In the second round, participants found the revised model easier to understand and could complete the main tasks.
What changed
The prototype gave the project a practical, tested model for managing access in the new workflow. It created a clearer link between approved access and downstream work, reduced the need to rebuild information manually, and was later taken forward into implementation.