Seeing the system behind secure email.

Workshare Protect helped law firms prevent sensitive information from leaving through email. I led a discovery workshop with technology leaders from major firms in New York to understand the challenges they faced around data protection, generating insights that could inform future product features.

Workshare Protect research workshop with a document security workflow on the wall

The project in 30 seconds

Data protection was a significant challenge for IT teams at many of New York’s largest law firms, several of which used Workshare Protect. Before deciding what to prioritise next, we needed a deeper understanding of the problems those firms were facing. We brought technology leaders from several firms together to map the wider system, surface shared risks and understand the problem before jumping to solutions.

Company
Workshare
My role
Senior Product Designer
Team
CEO, product team and technology leaders from major law firms
Timeline
July 2018
My contribution
Research framing, workshop facilitation, systems mapping and product planning
The challenge
Understand a fragmented security workflow across some of the largest law firms in New York to help inform a product roadmap.
OutcomeThe work confirmed shared risks, mapped the wider workflow and gave Workshare a stronger basis for planning Workshare Protect’s next evolution.

An email could have several different histories

Workshare Protect was a data loss prevention tool. It could check email and attachments against a firm’s security policies, warn a sender, block a message, remove hidden information or convert a document to PDF. The purpose was straightforward: to reduce the chance that confidential material left a firm accidentally. The actual email workflow was less straightforward.

A lawyer might press Send in Outlook. At that point, several plugins could start work. One might archive the message, another add a signature, and Workshare might clean or convert its attachments. Further checks could run on the server. If those steps happened in the wrong order, the archived copy might not match what the recipient received. An email could even be stored as “sent” when a later security policy had blocked it from leaving.

That mattered beyond a confusing interface. For a law firm, the archive is part of the record of what it communicated. A different document in the archive creates uncertainty for administrators and for anyone later trying to establish what was actually disclosed. Meanwhile, asking a lawyer to understand the order of several security prompts made the system harder to use and more fragile.

Workshare had heard proposed fixes from customers. Some wanted blocked email returned to the outbox whilst others imagined a single tool that could coordinate the competing plugins. My brief was to understand the underlying problems across firms before the company committed to a solution.

Getting beyond each firm’s preferred fix

The CEO asked me to lead a workshop in New York with technology leaders from major law firms. We had three hours with people whose environments, policies and installed tools were not identical. The value of the session was in seeing which concerns were shared and which depended on a firm’s particular setup.

I prepared the discussion around two problems: differences between the archived and delivered email and the instability created when multiple plugins acted after Send. I also wanted to know where firms considered the source of truth to be, how they handled email sent from mobile devices, and what their administrators needed to see when a policy intervened.

The participants arrived with ideas about solutions. I made space for those ideas without letting them define the problem too early. Each person first wrote down concerns independently. We then grouped the issues, discussed why they mattered and prioritised them. A later exercise asked how a future approach could fail, which helped reveal expectations that might otherwise have stayed unclear.

I adjusted the prioritisation during the session. Some people waited to see where others placed their votes before making their own choices. That risked turning the exercise into a negotiation over visible totals. I changed the voting to focus on individual issues and adjusted the order so we got a clearer view of what people considered important.

Bringing the system into view

The workshop confirmed that the two starting concerns were real. Alongside the discovery, I worked through the whole flow: what happened on the desktop, what the server checked or changed, what was archived, and what the recipient finally saw. The project’s workflow maps covered attachment scanning, warnings, hard blocks and server-side processing. These workflows gave the team a way to discuss dependencies and pain points across the entire journey.

When we returned to London, we began planning the next version of Workshare Protect. The direction included making the desktop tool lighter for senders, giving administrators better oversight through analytics and exploring quarantine. Some of those product streams were already under way. The workshop helped us understand how the pieces needed to work together for customers and brought that system view into the next round of planning.

What this work established

The work gave Workshare a stronger basis for product planning. We brought leaders from different firms into one conversation, confirmed the significance of the archived-versus-delivered email problem and the competing plugin problem, and mapped the wider workflow that any improvement would have to respect.

Workshare moved from a set of proposed feature fixes toward a clearer, system-level understanding of the problem and a stronger basis for planning the next evolution of Protect.