← AppleFeature deep dive

Security
Compliance

Let people prove their own devices — and let managers see the whole chain.

Apple employees were bringing their own devices onto the corporate network, and no one could tell whether those devices were safe. I designed the internal dashboard that closed that gap from both ends at once.

my devices — status at a glance
People and DevicesEnroll New DevicesMy DevicesMy TeamMy Organization
Name
Group
Title
Security Compliance

This here is some text that describes what the security compliance page actually is. Eventually this will be text that makes sense in context but right now this is just a placeholder.

My Devices

Total Devices: 4
All Devices Currently in Compliance
Catherine's iPadDevice KindLast Seen/Enrolled Date
More Details
Catherine's iPhoneDevice KindLast Seen/Enrolled Date
Item 1 is okayDescription of itemCall to Action
Item 2 is okayDescription of itemCall to Action
Item 3 is okayDescription of itemCall to Action
Item 4 is okayDescription of itemCall to Action
Close
Catherine's DesktopDevice KindLast Seen/Enrolled Date
More Details
Catherine's LaptopDevice KindLast Seen/Enrolled Date
More Details
My Devices - No Errors Expanded
Thu Jul 09 2015
01The problem

Visibility versus autonomy.

A personal device is only as safe as its owner keeps it — and nobody with responsibility for the network had any way to know whether a given device met policy. Employees wanted to be trusted with their own hardware. Security needed assurance. Managers sat in the middle, accountable for a team’s posture with no instrument to read it.

For the individual

A clean, self-service way to see and fix their own devices.

For the manager

A view across everyone who rolls up to them — reports, and their reports, all the way down.

?The question that shaped everything

What does “compliant” even mean?

I assumed there’d be one answer. There wasn’t. Compliance meant different things to different teams — a policy mandatory for one org was irrelevant to another, and the bar moved with your role and the data you touched.

So I couldn’t hard-code “compliant.” I designed a platform that expressed compliance relative to who you are — many policy types per user type, not one rulebook for everyone. That flexibility became a first-class requirement.
02The individual experience

Calm when it’s fine. Clear when it’s not.

For the individual, the experience was deliberately reassuring. “My Devices” showed each enrolled device and, in the happy path, a clean no-errors state. When something was out of compliance, the same view expanded to surface exactly which device and which policy needed attention — remediation by following the interface, not filing a ticket.

enroll a new device
People and DevicesEnroll New DevicesMy DevicesMy TeamMy Organization
Name
Group
Title
Security Compliance

This here is some text that describes what the security compliance page actually is. Eventually this will be text that makes sense in context but right now this is just a placeholder.

Enroll New Devices

Enroll Mobile Devices
Reasons to Register Desktop Devices
Reason 1
Reason 2
Reason 3
Link>
Enroll Desktop Devices
Reasons to Register Mobile Devices
Reason 1
Reason 2
Reason 3
Link>
FLOWEnrollment

Frictionless at the exact moment it matters.

The moment a device first comes onto the network is exactly when you want compliance to be effortless. Enrolling a new device was its own guided flow, so it started right.

STATESSee it, then fix it

One view, from “all good” to “here’s the fix.”

A person could sit with a multiple-non-compliance state, expand a single offending item, and understand what to do next without leaving the page — the detail was always one tap away, never a maze.

device detail — a policy needs attention
People and DevicesEnroll New DevicesMy DevicesMy TeamMy Organization
Name
Group
Title
Security Compliance

This here is some text that describes what the security compliance page actually is. Eventually this will be text that makes sense in context but right now this is just a placeholder.

My Devices (Non-Employee)

Total Devices: 4
2 Devices Needs Attention
Catherine's iPadDevice KindLast Seen/Enrolled Date
More Details
Catherine's iPhoneDevice KindLast Seen/Enrolled Date
Item 1 that needs attentionDescription of itemCall to Action
Item 2 that needs attentionDescription of itemCall to Action
Item 3 that needs attentionDescription of itemCall to Action
Item 4 that needs attentionDescription of itemCall to Action
Close
Catherine's DesktopDevice KindLast Seen/Enrolled Date
More Details
Catherine's LaptopDevice KindLast Seen/Enrolled Date
More Details
My Devices - Errors Expanded
Thu Jul 09 2015
my devices — the calm self-service view
People and DevicesEnroll New DevicesMy DevicesMy TeamMy Organization
Name
Group
Title
Security Compliance

This here is some text that describes what the security compliance page actually is. Eventually this will be text that makes sense in context but right now this is just a placeholder.

My Devices

Total Devices: 4
All Devices Currently in Compliance
Catherine's iPadDevice KindLast Seen/Enrolled Date
More Details
Catherine's iPhoneDevice KindLast Seen/Enrolled Date
More Details
Catherine's DesktopDevice KindLast Seen/Enrolled Date
More Details
Catherine's LaptopDevice KindLast Seen/Enrolled Date
More Details
manager — team tree, report expanded to devices
People and DevicesEnroll New DevicesMy DevicesMy TeamMy Organization
Team Name

Team Totals

FILEVAULT
100%
9 of 9 devices
CRASHPLAN
100%
9 of 9 devices
MDM
100%
9 of 9 devices
SECUREPRINT
100%
9 of 9 devices

Detailed Team View

File VaultCrashPlanAutomationSccmSecureprint
Bob ‘Jamie’ Team
Jane Jones
Bill Jones
Mike Jones
Marc Jones
Manager - Team View Expanded Devices
Thu Jul 09 2015
THE HARD PARTReporting chains that fold back on themselves

Real org charts nest. A flat table falls apart.

The single hardest problem was showing a manager their chain of reportees when that chain had depth — managers who have managers reporting to them, each with their own reports. I got there through trial and error; several approaches broke down under the nesting.

What held was a tree structure paired with an overall compliance viewat the top: the tree let a manager expand the org level by level down to an individual’s devices, while the summary gave the one-glance read on the whole team. Once the tree clicked, the entire management experience resolved.

Two non-negotiables

A user can always see their own data; a manager can always see their direct reports andthose reports’ reports.

03From wireframe to shipped

The same structure, in production skin.

The wireframes settled the information architecture; the final pass dressed it in the visual language of the platform it lived on. Calm surfaces, system type, and status carried by color — the same two experiences, individual and manager, taken to a polished Apple-style interface.

device compliance — the individual, shipped
Device Compliance
My Devices+ Enroll
💻MacBook ProUp to dateCompliant
📱iPhone 6All policies met
📟iPad AirUp to dateCompliant
📱iPhone 6● No errors — all policies met
Passcode enabledPass
OS up to datePass
Storage encryptedPass
FINAL UIThe individual

My Devices, in the platform’s own skin.

Same happy-path-first structure as the wireframe — a calm device list, a device expanded to its policy checks — now rendered in system type and colors, with compliance status you can read at a glance.

FINAL UIThe manager

Team View, drilling down to a single fix.

The overall read sits up top; the nested tree expands the org level by level down to one person’s devices — with a clear, one-tap path to send an update request to anyone out of compliance. This is where the data-driven design had to hold up under real org depth.

team view — nested drill-down + update request
Device Compliance · Team
Overall compliance
78%
24 people
5 need attention
Alex Morgan12 reports92%
Priya Shah4 reports61%
Jordan LeeMacBook ✓iPhone · needs fixSend update request
Sam Rivera8 reports88%
Where it landed

Two jobs, both done.

The design did the two things it was scoped to do: it gave individuals a self-service path to see and fix their own compliance, and it gave managers a real instrument — the tree plus the overall view — where before they’d had nothing. The rollout paired the platform with manager training and prominent intranet placement, so the tool met people where they already were.

Honest ending: the platform was being implemented as my contract wrapped, so I never saw the outcome data. The success metrics were defined — a measurable rise in device compliance, and utilization from both the management and individual sides — but I left before the numbers came in.

What it taught me

The right IA is the one that survives the real world.

This was my real education in data-driven design — making a large, relational dataset legible and actionable. The reporting tree taught me the lasting lesson: start from the true structure of the data, then design the drill-down.