The Situation
BlueCat had spent a decade establishing itself in enterprise DNS and IP address management. DNS Edge (now rebranded to Edge) was its first move into real-time network threat detection: a new product category that required a fundamentally different kind of UX, and one that had never existed inside the company before.
I was brought in as the first design hire to lead Edge from zero, while simultaneously establishing BlueCat's design function across its existing product suite.
Showing users real-time network data and letting them do something about it is how we will really add value.
CTO, BlueCat
The Problem
Edge had to serve two audiences at once, in two completely different contexts.
Network operations centers (NOCs) run large-format screens that display threat data continuously, visible to everyone in the room, read at a glance, no active interaction required. Individual analysts work differently; they need to move fast, identify suspicious activity, drill down to what matters, and take action before the window closes.
These two needs pulled against each other. Designing for both collective awareness and individual action, in a single interface, was the problem we had to solve. It's also one of the more interesting design problems I've encountered.
The Work
Two decisions defined how we resolved the tension.
The first was a large-format map view with floating UI elements, which made network threats visible at room scale. Threat markers appeared on the map in real time, readable from across a room without any interaction required. It gave NOC teams continuous situational awareness without demanding their active attention.
The second was the Command Builder, which gave individual analysts the speed they needed to act. Modeled on the command-line tools that network security engineers already used fluently, it let analysts drill down to a specific threat and take action in seconds. It met users in their existing mental model rather than asking them to learn a new one.
To get there, we conducted customer visits and calls, including a site visit to the Natural History Museum of New York, observing analysts in their actual operational environment. Understanding how they assessed threats, what information they needed, and how fast they needed to move shaped both decisions directly.
Beyond the product itself, I managed a third-party vendor team of one UI designer and two UI developers, hired a full-time UX designer, and established the BlueCat Design System, which rolled out across products in the years that followed. I also spent time actively building design culture in an engineering-led organization, giving talks at company events and writing a column called BadUX in the monthly Tech and Product newsletter, because shipping great work and advocating for how it gets done are different jobs, and both needed doing.
The Outcome
Once the designs were in shape, we validated them directly with users through a pilot release across four customer accounts. The pilot returned an average satisfaction score of 4.2 out of 5, and customers actively requested a broader rollout and beta access.
I left BlueCat to pursue my master's degree before the full launch, but the design system established during the engagement continued to be used across the product suite in the years that followed, and DNS Edge itself later became part of BlueCat's Cisco SolutionsPlus partnership.
This was the second time I'd worked on the problem of making network threat data legible to expert users under pressure; the first was at Blue Coat Systems, where I contributed to a new network visibility product for enterprise security analysts before the company was acquired by Symantec for $4.65B. The map view and Command Builder reflect something I'd been learning across both engagements: expert users in high-stakes environments don't need their complexity simplified; they need it organized. The interface that earns their trust is the one that respects what they already know and gives them what they need to act.