Background
Credential management had grown increasingly risky as Veras added more integrations and user roles, leaving administrators uncertain about who had access to what.
Support tickets tied to credential errors and permission mistakes were rising, and each one took significant time to resolve safely.
My goal was to redesign credential management into an experience that made access easy to grant, easy to audit, and hard to get wrong.
The problem
As integrations multiplied, credentials became scattered across disconnected screens with no consistent way to see who could access what.
- Permissions were granted through inconsistent, easy-to-misuse flows
- There was no clear audit trail for sensitive access changes
- Expired or unused credentials were rarely cleaned up
- Administrators lacked confidence that access matched intent
Understanding the problem
I partnered with security and support teams, reviewed incident reports, audited access-related tickets, and analyzed usage patterns across customer accounts.
Three themes emerged:
01 — Access decisions were made without full visibility
Administrators often granted broad permissions because narrower options weren't clear or convenient.
02 — Mistakes were easy to make and hard to catch
Small errors in credential setup could go unnoticed until they caused a real problem.
03 — Accountability was difficult to trace
There was no reliable way to see who changed what access, or when.
Giving administrators full visibility
I consolidated credential and access information into a single view, making it clear at a glance who had access to what and why.
Building safer defaults
I introduced scoped permission templates and safer default settings, reducing how often administrators needed to configure access from scratch.
Making every change auditable
I added a clear activity log for credential changes, so administrators could trace exactly who granted or revoked access, and when.
Testing & iteration
I built a functional prototype to validate the new permission model with security and support teams before implementation.
Feedback surfaced edge cases around bulk access changes and legacy integrations, which shaped how the final audit log and permission templates worked.
Outcome
The redesigned credential experience gave administrators clearer, safer control over access.
- Cut credential-related support tickets by 40%
- Gave administrators a clear audit trail for every access change
- Made it easier to spot and clean up unused or risky credentials
- Increased administrator confidence in day-to-day access decisions