← All Projects

Turning an activity table into an identity graph

Security and backup teams can see that an identity was compromised — but had to read a table, row by row, to find out what it actually touched. I redesigned that table as a graph: the identity at the center, everything it touched plotted around it by type.

Identity Resiliency — Identity Activity Analysis swimlane graph
RoleUX Designer
ScopeIdentity activity as a node-based attack graph
DomainIdentity Security · B2B Backup & Cyber Recovery
StakeholdersSecurity & backup teams · Security Scientist · Visual team · Engineering
DesignersUX Designer · Visual team

The problem

Security teams can see that an identity was compromised — but not the path of what it did next.

They waste time rebuilding the story from rows in a table, so recovery is slow and trust stays broken longer.

What’s wrong with the table

Existing

Time-ordered table

The old screen was a long list of changes in time order. You could find a single event, but not see what happened next — or how far the damage spread.

Existing Identity Activity Analysis — time-ordered activity table for John Adams

Preferred

Node-based graph

Same details, drawn as a map: the identity in the middle, everything it touched around it. You see the path and the blast radius before digging into any single row.

Preferred Identity Activity Analysis — type swim-lane attack graph

This screen sits on top of backup recovery that cannot be tampered with. Its job is to answer “what changed, when, and by whom” before anyone trusts a restore plan.

Who this is for

Two jobs. One shared picture.

Opens every day: alerts when a login or account looks stolen.

Problem: they know something is wrong, but not what the attacker did next or how many systems are at risk.

Needs: a clear path of damage so they can tell Backup Admin what is safe to restore.

Opens every day: the backup console when it’s time to restore systems.

Problem: they can roll systems back, but can’t tell which backup point is still clean. Guess wrong, and the stolen account comes back with the same access.

Needs: a clear “before the damage” moment so restore does not bring the attacker back.

Both roles need the same picture. Neither can move to recovery without it.

Inspiration

n8n workflow graph — AI agent flow with distinct node types and connected tools
n8n
Wiz Security Graph — attack path with visually distinct entities
Wiz Security Graph

AI Explorations

Scenarios from the Security Scientist

Scenario 1 visualization — attack path with Initial Access, Privilege Escalation, Persistence stages

Scenario 1

One-way timed sequence

  • Easy at a glance — role elevation → new admin → app registration reads as one line.

  • Equal weight on every node — nothing signals which step actually matters.

  • Breaks when actions branch — only works while everything chains in one line.

Scenario 1 research table — activity, changes, actor, activity type, restore recommendations
Scenario 2 Identity Investigation UI — John Admin timeline for MFA, policy, group, and OAuth app changes

Scenario 2

Action-first timeline

  • Edges carry the color — MFA, guest privilege, OAuth secrets read without opening every node.

  • Nodes stay thin — you see what happened, not the full detail.

  • Same ceiling as Scenario 1 — nest or multiply the actions and it breaks.

Scenario 2 research table — MFA, guests, long-lived secrets
Scenario 3 Identity Investigation UI — clustered deletions and impact summary

Scenario 3

Clustered bulk deletes

  • Bulk deletes across types — users, apps, MFA, secrets, and devices.

  • One readable cluster — a hundred deleted devices don’t become a hundred identical rows.

Scenario 3 research table — bulk delete across object types

Realisation

Flows aren’t always linear

  • Not always linear — a compromised identity can fan out into many activities at once.

  • Parallel, not sequential — one login can spawn MFA disable, a role change, and new tokens together.

  • One origin, many forks — the graph has to stay readable no matter how far it fans out.

Activity Graph — John Admin branching into multiple parallel identity actions with severity-coded edges
Multi-branch activity graph — one identity, parallel paths

Design system

A working kit for iteration

I built a basic design system to support quick iterations and early explorations — shared with the visual team, engineering, and senior stakeholders so decisions stayed aligned before polish.

Identity Resiliency design system — actors, nodes, activity chips, flow lines, and detail cards
Component sheet — Magnify to inspect detail

Design process

Iterations

Iteration 1 — Identity Activity Analysis graph organized by timeline and activity

Iteration 1

Timeline + activity

  • Hard to find a node — once branches grew, locating a specific step in the path got slow.

  • No layout rule for engineering — freeform branches had nothing stable to build against.

  • Auto-plot scattered events — the same events landed in random spots every run; nothing was reproducible.

Iteration 2 — type swim lanes activity graph with Investigation Builder

Iteration 2

Type swim lanes

  • Y = identity type, X = time — a fixed grid instead of freeform branches.

  • Empty lanes drop away — density matches what actually happened, not the full taxonomy.

  • Stable to plot — engineering and auto-layout can place nodes without scattering.

AxisContents
YIdentity types (active only)
XTime
NodesObjects in their lane
EdgesActions
Pre final Identity Activity Analysis — type swim-lane graph before visual enhancements

Pre final

Approved structure, before visual polish

  • Type lanes, metrics, and action chips locked as the approved structure.

  • Interaction model first — visual polish comes after the structure holds.

Final Identity Activity Analysis after visual enhancements — Alice Smith type swim-lane graph

Final

Final design after visual enhancements

Outcome

First node-based identity graph from scratch

Built the first node-based graph system for Active Directory, Entra ID, and Okta recovery — identity at the center, everything it touched plotted by type so security and backup teams can see spread without reading a log table row by row.

Closing

Learning

Confidentiality note: This project is under NDA. Design is complete and moving into development.
Interface redrawn and figures synthesized for case study presentation.
The core architectural logic and UX constraints remain true to production.

More work View all work