Security & Compliance

DashboardUsersEntitiesProject TaxonomyDRL ItemsWork PlansProjectsPermissions
jc
Jonathan CastilloSuper Admin
All ProjectsAmazon - 2022 - SOC 2 T2
DashboardGeneral InformationCalendarDocument Request ListWork PlanDocument RepositoryMeeting ScheduleProject TeamAudit History
Column Options
Document Request List18
Export
Search
Create DRL Item
open4

Employee Termination Requests

HRS-09

Evidence indicating that logical/physical access removal was requested and completed.

jc
cf
sp
2
123456
Upload(4)

Quarterly Access Review

ITS-04

Quarterly review of privileged accounts and access scopes across systems.

mk
at
0
01284
Upload(2)

Q3 Bank Reconciliation

FIN-07

Reconciliation of all primary banking accounts for the Q3 reporting period.

jc
sp
1
218220
Upload(3)

Change Management Log

SEC-11

Change tickets and approvals for production deployments in the audit window.

cf
mk
2
1964
Upload(5)
in progress0
Drag Card Here
ready for audit team2

Incident Response Playbook

IRM-01

Documented playbook for tier-1 security incident handling procedures.

cf
sp
4
03214
Upload(5)

Privileged Access Logs

ITS-18

Just-in-time access logs and full approval trail for Q3.

mk
at
2
164312
Upload(6)
comment for audit team2

Policy Acknowledgments

CMP-03

Signed policy acknowledgment forms for all active employees.

mk
at
3
01421100
Upload(4)

Vendor Payments Audit

FIN-15

Annual vendor payment audit trail with approver signatures.

at
sp
2
328244
Upload(6)
comment for client1

Performance Reviews

HRS-17

Performance review records for all employees in scope.

jc
at
2
289412
Upload(5)

Lead Product Designer · 2022 · Security & Compliance

Unblocking compliance throughput by making status visible — not by adding more table features

A status board where pipeline health is glanceable — and updating state is the same gesture as moving work forward.

Audit, IT, and ops teams were burning the day reconstructing document-request progress from a dense DRL table — status buried as one column among many across SOC, ISO, and similar engagements. As Lead Product Designer I owned the redesign of how that work was seen and moved. Constraint: same underlying data, strong pressure to “just improve the table.”

Login — The entry point for audit teams and clients, in the same visual language as the Kanban.

01 · The problem

Teams rebuilt the pipeline in their heads every day

Clients ran dozens of document request lists at once across SOC, ISO and similar audits: open, in progress, waiting on audit, waiting on the client, blocked, approved. The list view made operators reconstruct progress from filters and saved views. Priorities weren’t visible, blockers took scanning to find, and new teammates had no fast way to learn what mattered.

Teams spent more energy maintaining a mental model of the work than doing it, and the pressure was to “just improve the table.”

Compliance list view — The same data as the Kanban, but status sits in a column, so operators read row by row to reconstruct progress.

02 · What I found

Every column was useful. The format hid the one that mattered.

Sitting with operators through their daily reviews made the failure clear. Every column held something useful, but the format buried the first thing they needed, which was status. The interface described records. It didn’t show a pipeline.

A list assumes people read record by record. These teams read their work as a pipeline, so the interface had to be one too.

Process

Same data, different shape of work

Status moved from a buried column to the primary spatial axis.

Before

Dense list

Progress reconstructed from filters and saved views

After

Status board

Pipeline readable at a glance; drag updates state

03 · Key decisions

Three calls that made status visible

Decision 1

Replace the table with a status board

Document requests became Kanban stages (Open, In Progress, Ready for Audit Team, comment states, Completed) so status is spatial and readable from across a room.

Instead of
Sticky headers, better filters and a denser, more usable list.
Why
The work moves as a pipeline. A better table would still make people rebuild that pipeline themselves.
Trade-off
A bigger change to defend than the safer ask of another table improvement.

Decision 2

Make moving a card the status update

Dragging a card to a new column updates its status. Cards carry what operators used to dig out of table rows.

Why
Updating state should be the same gesture as moving the work forward.

Decision 3

Keep filters, but make them secondary

Filters are still there, but the board already does most of the job filtering used to do.

Why
Nobody should need a saved view to answer “where are we blocked?”
Compliance Kanban — A status board replaces the dense list view; moving a DRL Item card between columns updates its workflow status.

04 · Outcome

Same data, a different working day

Nothing about the underlying data changed. What changed was how teams worked: how they prioritized, how they stayed aligned, and how quickly someone could answer “where are we blocked?”

The evidence is behavioral rather than a metric. Prioritization and alignment shifted without a training program, because the structure finally matched how compliance work moves.

05 · Reflection

Workflows are a design surface

A Kanban board isn’t a widget. It’s a claim about how work moves. Operators didn’t need more features; they needed a structure that matched their work.

Replacing the table meant making that claim explicit, and defending it when the safer ask was one more table improvement.