Designing account-level access controls
Supporting the transition from a manual service to a digital workflow through a simple, account-level access model.
Note: To respect confidentiality, names, business details and visuals have been anonymized.
The challenge
As part of a broader shift from a manual service to a digital workflow, the team needed a clear way to manage which contacts could access specific accounts. The workflow operated within strict regulatory and accuracy requirements, so access needed to be clear, reliable, and easy to review. A traditional hierarchy of roles and permissions would have added complexity without matching the actual need: access was managed account by account, person by person.
My contribution
I designed the MVP for account-level access controls, building on earlier research and service-blueprinting work. I defined the access model, created the main user flows and prototype, and tested and refined the design through team feedback and usability sessions.
How I approached it
I designed the MVP around one simple rule: a contact either has access to a specific account or does not. I created flows for viewing contacts, assigning and removing access, and checking access from both account and contact views, with options for single and bulk editing, importing contacts between accounts, and transitional sharing tools. I tested an early concept for grouping contacts, but feedback showed it added unnecessary complexity. I replaced it with bulk editing, and a second round of usability testing found the revised approach easier to understand and use for the main tasks.
What changed
The prototype gave the team a tested approach for managing account-level access in the new workflow. It created a clearer connection between approved access and downstream work, reduced reliance on manually rebuilding information, and provided a foundation that was later taken forward into implementation.