Designing a safer, clearer way to manage credentialsVeras

Designing a safer, clearer way to manage credentials

Cut credential-related support tickets by 40%.

Background

Credential management had grown increasingly risky as Veras added more integrations and user roles, leaving administrators uncertain about who had access to what.

Support tickets tied to credential errors and permission mistakes were rising, and each one took significant time to resolve safely.

My goal was to redesign credential management into an experience that made access easy to grant, easy to audit, and hard to get wrong.

The problem

As integrations multiplied, credentials became scattered across disconnected screens with no consistent way to see who could access what.

  • Permissions were granted through inconsistent, easy-to-misuse flows
  • There was no clear audit trail for sensitive access changes
  • Expired or unused credentials were rarely cleaned up
  • Administrators lacked confidence that access matched intent

Understanding the problem

I partnered with security and support teams, reviewed incident reports, audited access-related tickets, and analyzed usage patterns across customer accounts.

Three themes emerged:

01Access decisions were made without full visibility

Administrators often granted broad permissions because narrower options weren't clear or convenient.

02Mistakes were easy to make and hard to catch

Small errors in credential setup could go unnoticed until they caused a real problem.

03Accountability was difficult to trace

There was no reliable way to see who changed what access, or when.

Giving administrators full visibility

I consolidated credential and access information into a single view, making it clear at a glance who had access to what and why.

Building safer defaults

I introduced scoped permission templates and safer default settings, reducing how often administrators needed to configure access from scratch.

Making every change auditable

I added a clear activity log for credential changes, so administrators could trace exactly who granted or revoked access, and when.

Testing & iteration

I built a functional prototype to validate the new permission model with security and support teams before implementation.

Feedback surfaced edge cases around bulk access changes and legacy integrations, which shaped how the final audit log and permission templates worked.

Outcome

The redesigned credential experience gave administrators clearer, safer control over access.

  • Cut credential-related support tickets by 40%
  • Gave administrators a clear audit trail for every access change
  • Made it easier to spot and clean up unused or risky credentials
  • Increased administrator confidence in day-to-day access decisions