Shafeen Alam
← All work
Interpres Security/Explainable AI decision support/Flagship

Designing a governed, explainable AI assistant for threat & exposure management

Security analysts spent ~45 minutes per incident synthesizing exposure data across fragmented dashboards. I led the 0→1 design of Interpres's first AI assistant, which cut time-to-insight to 27 minutes and raised analyst trust from 62% to 81%.

Role
Design Lead, AI/UX
Timeline
2 weeks, 0→1 (2024)
Team
PM, Eng, CTO
Scope
Strategy, conversational AI, data viz, design system
Interpres Assistant chat interface with a structured response card
Assistant chat with a structured response card

60-second read

Problem

Analysts spent about 45 minutes per incident synthesizing exposure data across fragmented dashboards.

System decision

Replace open-ended prose with a deterministic reasoning chain that is evidence-linked and confidence-scored.

My contribution

Led the 0 to 1 design end to end: interaction model, evidence layer, safety and uncertainty states, design system.

Impact

Time to first insight 45 to 27 minutes. Analyst trust 62% to 81%.

01 · Shipped

A working 0→1 prototype, designed and validated in two weeks, that moved into Beta with real analysts, not a concept deck. It became the entry point to their workday, and a factor in closing new business.

70%
of analysts opened it daily
45→27 min
time to first insight
2
customer wins enabled during Beta

02 · The problem

Security teams work across fragmented tools: alerts in one, exposure graphs in another, control coverage elsewhere. Even where the underlying data was rich, synthesis was entirely manual. Across 12 analyst interviews and 3 SOC manager sessions, the gap wasn't intelligence. It was structured, contextual reasoning.

“I don't trust automated suggestions unless I see the source.”
“Switching tools breaks my thinking.”

03 · What failed

First pass

Open-ended prose responses. In a security context that was unacceptable: hallucination risk, slow to scan under time pressure, and analysts finished reading unsure what to actually do next.

What replaced it

A deterministic reasoning structure, rendered as structured response cards instead of prose, with a “Why this matters” block on every answer.

Exposure Control gap MITRE technique Recommended action

04 · What I cut

Multi-step autonomous execution. The assistant could have chained patch, policy update, and notify with no human between them. I scoped it to one action, one confirmation, every time, trading speed for trust, on purpose.

05 · Across the stack

I owned the interaction model end-to-end. Not a chat surface bolted onto dashboards, but how the AI reasons, grounds itself in evidence, and earns trust at each layer.

A · Model
Deterministic reasoning enforced over open-ended generation.
Lower hallucination risk, faster scanning
B · Data
Every response evidence-linked, source-tagged, schema-bound.
78% evidence validation rate
C · Orchestration
Chat blended with structured cards and suggested follow-ups.
Question → visual workflow
D · Tool / Agent
AI could filter, search, and map exposures, with every action traceable.
8% “AI Uncertain” rate
E · Performance
Streaming layouts and status messaging under real latency.
Responsive on large datasets
F · Safety
Confidence indicators, recovery paths, role-based gating.
Trust by explicit calibration

06 · In use

Why This Matters explainability panel with confidence score and a persona selector for Analyst, Responder, CISO
Explainability panel with a confidence score and a persona selector, since an analyst, a responder, and a CISO each need the same finding framed differently.
Confirmation dialog warning that an action will modify firewall policy, with Confirm and Cancel
Human-in-the-loop. Any action touching a live control stops for explicit confirmation before it executes.
AI Uncertain state offering recovery paths: refine your question, or try an alternative query
The “AI Uncertain” pattern. Low confidence surfaces recovery paths instead of a guessed answer.
Still working on it fallback state with options to continue waiting or stop
Fallback for slow queries. The system stays legible instead of stalling silently.

07 · Live recreation

Not a screenshot. A working recreation of the reasoning structure, the evidence layer, and the two states that matter most: uncertain and requires confirmation. Send the query, then take either branch.

Interpres Assistant · recreation Interactive
Recreation · not live data

08 · The guardrail

Every action that touches a live control stops here. One action, one confirmation, every time. The dialog states the blast radius in the analyst's terms, not the system's.

The version I killed would have chained this with two more actions and no stop. Click through it.

Human-in-the-loop
Recommended action: enable attachment sandboxing for Finance OU.

09 · Response

62→81%
Analyst trust
78%
Evidence validation
4–6
Follow-ups per chain
8%
AI uncertain rate

“Feels like a junior analyst who already knows our environment.”

Senior SOC Analyst

“For the first time, I can brief leadership using language they understand.”

CISO

In cybersecurity, ambiguity is risk. Design must reduce it.

The CTEM platform → Next case study → Back to all work