Designing a governed, explainable AI assistant for threat & exposure management
Security analysts spent ~45 minutes per incident synthesizing exposure data across fragmented dashboards. I led the 0→1 design of Interpres's first AI assistant, which cut time-to-insight to 27 minutes and raised analyst trust from 62% to 81%.
60-second read
Analysts spent about 45 minutes per incident synthesizing exposure data across fragmented dashboards.
Replace open-ended prose with a deterministic reasoning chain that is evidence-linked and confidence-scored.
Led the 0 to 1 design end to end: interaction model, evidence layer, safety and uncertainty states, design system.
Time to first insight 45 to 27 minutes. Analyst trust 62% to 81%.
01 · Shipped
A working 0→1 prototype, designed and validated in two weeks, that moved into Beta with real analysts, not a concept deck. It became the entry point to their workday, and a factor in closing new business.
02 · The problem
Security teams work across fragmented tools: alerts in one, exposure graphs in another, control coverage elsewhere. Even where the underlying data was rich, synthesis was entirely manual. Across 12 analyst interviews and 3 SOC manager sessions, the gap wasn't intelligence. It was structured, contextual reasoning.
“I don't trust automated suggestions unless I see the source.”
“Switching tools breaks my thinking.”
03 · What failed
First pass
Open-ended prose responses. In a security context that was unacceptable: hallucination risk, slow to scan under time pressure, and analysts finished reading unsure what to actually do next.
What replaced it
A deterministic reasoning structure, rendered as structured response cards instead of prose, with a “Why this matters” block on every answer.
04 · What I cut
Multi-step autonomous execution. The assistant could have chained patch, policy update, and notify with no human between them. I scoped it to one action, one confirmation, every time, trading speed for trust, on purpose.
05 · Across the stack
I owned the interaction model end-to-end. Not a chat surface bolted onto dashboards, but how the AI reasons, grounds itself in evidence, and earns trust at each layer.
06 · In use
07 · Live recreation
Not a screenshot. A working recreation of the reasoning structure, the evidence layer, and the two states that matter most: uncertain and requires confirmation. Send the query, then take either branch.
08 · The guardrail
Every action that touches a live control stops here. One action, one confirmation, every time. The dialog states the blast radius in the analyst's terms, not the system's.
The version I killed would have chained this with two more actions and no stop. Click through it.
09 · Response
“Feels like a junior analyst who already knows our environment.”
Senior SOC Analyst
“For the first time, I can brief leadership using language they understand.”
CISO
In cybersecurity, ambiguity is risk. Design must reduce it.