
Case study
Appsmith Access Control
Designing enterprise permissions people can reason about
Appsmith ↗Choose your depth
The problem, my contribution, outcomes, and strongest screens.
My role
Lead product design · Enterprise UX · Information architecture
Product focus
Granular access governance across people, groups, nested resources, actions, and audit history.
Overview
I led the experience design for granular access control across users, user groups, permission groups, application resources, and audit logs. The work connected least-privilege configuration with the evidence administrators need to investigate access later.
The problem
Enterprise administrators needed resource-level control without turning every permission change into a specialist task. The relationships between people, groups, nested application resources, and allowed actions had to remain understandable at organisational scale.
What I drove
- Modelled people, user groups, permission groups, resources, and actions as one connected governance system.
- Translated least privilege, data protection, and public exposure into clear product value and concrete controls.
- Designed an expandable resource matrix, group assignment, search, invitations, and explicit saving.
What changed
- Made complex permission scope inspectable before administrators changed access.
- Connected least-privilege controls with the audit evidence needed to investigate incidents later.
Impact
What the work was designed to move
Business impact
A connected governance model strengthened enterprise readiness across users, groups, permissions, resources, and audit history.
Customer impact
Administrators can prevent risky access, understand permission scope, and trace incidents without reconstructing context.
Revenue impact
Supports enterprise adoption and expansion by making granular access control a credible, operable product capability.
Highlights evidence
3 essential screens from the final experience.



Continue reading