SPIFFE &
SPIRE
Mapping the journey from a curious onlooker to a committed adopter.
Leaking at every seam.
A real market, and a funnel that leaked at every seam.
People arrived interested — then left. Some bounced off a confusing front door; others stalled somewhere between “this looks promising” and “we’ve put it into production.”
83%
of IT executives were concerned about their service-authentication credentials.
66%
agreed their current approaches couldn’t scale to dynamic, hybrid-cloud strategies.
The team was building on hunches — no repeatable way to learn about users, knowledge trapped in silos, and an assumption that a small, vocal few spoke for everyone.
Two things, in order.
A repeatable research engine — a predictable way to learn about users, so decisions came from verified data instead of the loudest anecdote, and the team could keep asking after I was gone.
Use that engine to find where — and why — people fell off, then turn findings into changes that moved conversion at both ends of the funnel.
Not just deliver findings — leave behind a method the team could re-run.
A research pipeline, not a one-off study.
Framed around three questions a non-researcher could hold in their head — so the method would outlast me.
The method we left behind.
Not a one-off study — a loop the team could keep running without me: ask, define, synthesize, then run it again.
The loop outlives any single study — the team keeps asking after the researcher is gone.
Who are our users, really? What do they actually do? What motivates them to engage? How do they think about us — and the frameworks? And the business-critical one: what moves people into production?
11 new Zoom interviews (~540 minutes of fresh data), 100+ prior interviews re-mined and re-coded, and a 739-member Slack community treated as a first-class research surface.
A nine-step journey, in three phases.
The move that made the map usable was naming the emotional beats along it — intrigued, concerned, disengaged, engaged, advocate. That turned an abstract funnel into specific moments where we were losing specific people for specific, addressable reasons.
The Onlooker
Passive interest — kicking the tires. Intrigued → concerned → disengaged.
The Explorer
Genuine fit — evaluating seriously. Engaged → advocate.
The Test Driver
Installs and runs a proof of concept — and stalls at the boundary to production.
POC → production is the biggest drop-off on the map.
Who’s on the journey.
The Onlooker
“I have a passive interest and am just kicking the tires.”
A real problem to solve, but can’t yet push the idea inside their org. Lurks in Slack, skims the docs. Intrigued → concerned → disengaged.
The Explorer
“There’s a genuine fit — how does it land in our systems?”
Engages the team, asks pointed questions, evaluates seriously. This is where advocacy is born.
The Test Driver
“Install it, run a POC, evaluate against real requirements.”
Where fitting users stalled — at the boundary between proof-of-concept and production.
Three barriers — none of them the product.
So the highest-leverage design work stopped being about features and started being about equipping the user to succeed inside their own company.
Internal resource constraints
Couldn’t get their own org to commit time or budget — even when the fit was obvious.
→One-pagers & industry examples a champion can take to their boss.
Complexity of install & integration
Getting from download to a working POC was harder than it should be; the docs didn’t hold people’s hands.
→ Simplify install — package managers, friendlier docs.
Feeling out of the loop
No visibility into the roadmap, and feeling shut out of decisions — which erodes open-source trust fast.
→ Transparent community practices, anchored by CNCF.
The front door was the first thing the journey work rebuilt.
The clearest place this research turned into interface was the SPIFFE.io / SPIRE web experience — the literal front door where Onlookers were bouncing. A new visitor couldn’t answer “what is this and why do I care” fast enough, so they left; and SPIRE — the runtime you actually deploy — was badly under-represented next to SPIFFE.
That redesign is its own story — the before/after of the site, the objectives, and the A/B-validated numbers it moved.
The website half of this project — reshaping the front door around what a new visitor needs:
See the SPIFFE Website redesignThis page — the research engine and the mapped journey that told us where and why people fell off.
The website page— the redesign that acted on it, and the bounce & conversion numbers it moved.
A mapped journey — and a method that outlived the study.
A nine-step, three-phase adoption journey with the emotional beats named along it — so an abstract funnel became specific moments where we were losing specific people for specific, addressable reasons. Three strategic barriers, none of them the product, reset where design effort went.
The team left with a repeatable research methodand a shared, evidence-based picture of its users — decisions now started from “here’s what the Test Driver is stuck on,” not “here’s what someone said in Slack last week.”
Acted on first at the front door: the SPIFFE.io redesign moved bounce down 7% and download & community conversions up 12%, A/B-validated — the full before/after lives on the SPIFFE Website page.
What I carried out of this.
Adoption is organizational, not technical.
Great-fit users stalled on time, budget, buy-in — a missing one-pager for a skeptical boss. So the best design work equips the user to win inside their own company.
Leave the ladder behind.
The personas were useful — but I’m proudest of the method. For open source, where the community never stops talking, a durable listening practice beats any single study.
A leaky funnel, turned into a mapped journey and a repeatable way to learn.
Adoption is usually an organizational problem wearing a technical mask. The best design work often equips the user to win inside their own company — and leaves the team a method that outlasts the study.