{"id":8107115,"date":"2026-04-17T08:19:23","date_gmt":"2026-04-17T15:19:23","guid":{"rendered":"https:\/\/agilealliance.org\/?p=8107115"},"modified":"2026-04-24T13:16:25","modified_gmt":"2026-04-24T20:16:25","slug":"case-study-when-a-security-rollout-became-a-design-problem","status":"publish","type":"post","link":"https:\/\/agilealliance.org\/case-study-when-a-security-rollout-became-a-design-problem\/","title":{"rendered":"Case Study: When a Security Rollout Became a Design Problem"},"content":{"rendered":"\n<p><em>This Agile case study is drawn from the Agile Experience Report&nbsp;&#8220;<a href=\"https:\/\/agilealliance.org\/resources\/experience-reports\/your-security-team-needs-design\/\" title=\"\">Your security team needs desig<\/a>n&#8221; by Kelsey van Haaster and Emma Lundgren.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>When ThoughtWorks tightened password security, leaders expected an easy rollout. But internal surveys showed password manager use varied widely by region, and many employees found the tools unnecessary or hard to use.<\/p>\n\n\n\n<p>The company offered a corporate password manager for employees and families, but setup confusion, support tickets, licensing issues, and accidental password exposure followed.<\/p>\n\n\n\n<p>A small volunteer team treated the rollout as a design problem instead of a policy one. In three months, they cut setup time from 40 to 19 minutes, reduced major errors and support tickets, and increased usage to nearly 3,000 people.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Challenge<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">A technically sound security decision collided with real user behavior<\/h3>\n\n\n\n<p>The existing expense policy for password managers was poorly understood and applied inconsistently across regions. Centralizing on a single corporate tool was meant to remove friction, but it exposed how complex and confusing the setup experience had become. Instructions were scattered, the process was harder than it appeared, and many users stopped after the first account-creation step because they believed they were finished.<\/p>\n\n\n\n<p>The consequences were concrete: increased support workload, licensing issues, and real security risk, including exposed passwords. The team also faced clear constraints: users were distributed globally, parts of the experience depended on a third-party vendor, and earlier rollout problems had already shown that internal assumptions about user behavior were unreliable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Approach<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Start with the actual user experience<\/h3>\n\n\n\n<p>Instead of issuing more instructions or policies, a three-person volunteer team applied the Double Diamond framework, Stanford d.school design thinking, and hypothesis-driven problem solving. Their working principles were straightforward:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Focus on root causes rather than symptoms.<\/li>\n\n\n\n<li>Observe users directly in the process.<\/li>\n\n\n\n<li>Keep documentation light but useful.<\/li>\n\n\n\n<li>Make work visible and remove unnecessary complexity.<\/li>\n<\/ul>\n\n\n\n<p>They did not try to redesign everything. They concentrated on what they could see, control, and test quickly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Implementation and Iteration<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Identify failure points, then redesign the flow<\/h3>\n\n\n\n<p>The team began with an expert walkthrough, followed by one-on-one setup sessions with users in Australia. After four interviews, clear patterns emerged. They simplified the journey from five user types to one primary path with minor variations.<\/p>\n\n\n\n<p>The two most impactful changes were:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Reducing instruction sets from seven to one.<\/li>\n\n\n\n<li>Moving a critical step earlier in the process so users were less likely to stop halfway through setup.<\/li>\n<\/ul>\n\n\n\n<p>These were small, targeted adjustments made close to where users were failing.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Results and Impact<\/h2>\n\n\n\n<p>Over three months, the average setup time dropped from 40 minutes, with help, to 19 minutes, with the fastest completion at seven minutes. Critical mistakes decreased, including cases where users put passwords in the wrong place. Usage grew to nearly 3,000 people, many of them first-time password manager users, and support tickets declined, freeing the Identity Team for other work.<\/p>\n\n\n\n<p>The project also changed some internal views about what design could contribute to security work and how useful design thinking tools could be in solving this kind of problem.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Lessons Learned<\/h2>\n\n\n\n<p>This case points to three clear lessons:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Technical correctness does not equal usability.<\/strong> A policy-focused rollout created confusion that a design-focused approach helped reduce.<\/li>\n\n\n\n<li><strong>Direct observation beats assumptions.<\/strong> Surveys flagged the problem; watching users revealed where it lived.<\/li>\n\n\n\n<li><strong>Simplification is powerful work.<\/strong> Fewer instructions and a better flow achieved more than additional explanation would have.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Key Agile Takeaways<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What Agile looked like in action<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The effort relied on short cycles, rapid feedback from real users, and small testable changes.<\/li>\n\n\n\n<li>The team favored simplification over added process or documentation.<\/li>\n\n\n\n<li>A small volunteer team owned the problem and adjusted its approach as it learned more.<\/li>\n\n\n\n<li>The report explicitly connects the work to the principle that simplicity and maximizing the work not done are essential.<\/li>\n<\/ul>\n\n\n\n<p><em>Read the original Experience Report\u00a0&#8220;<a href=\"https:\/\/agilealliance.org\/resources\/experience-reports\/your-security-team-needs-design\/\" title=\"\">Your security team needs design<\/a>&#8221; by Kelsey van Haaster and Emma Lundgren.<\/em><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>See how ThoughtWorks used design thinking to simplify a confusing password manager rollout, reduce setup errors and support tickets, and improve password security across a global workforce.<\/p>\n","protected":false},"author":8033092,"featured_media":8107304,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_tec_requires_first_save":true,"_EventAllDay":false,"_EventTimezone":"","_EventStartDate":"","_EventEndDate":"","_EventStartDateUTC":"","_EventEndDateUTC":"","_EventShowMap":false,"_EventShowMapLink":false,"_EventURL":"","_EventCost":"","_EventCostDescription":"","_EventCurrencySymbol":"","_EventCurrencyCode":"","_EventCurrencyPosition":"","_EventDateTimeSeparator":"","_EventTimeRangeSeparator":"","_EventOrganizerID":[],"_EventVenueID":[],"_OrganizerEmail":"","_OrganizerPhone":"","_OrganizerWebsite":"","_VenueAddress":"","_VenueCity":"","_VenueCountry":"","_VenueProvince":"","_VenueState":"","_VenueZip":"","_VenuePhone":"","_VenueURL":"","_VenueStateProvince":"","_VenueLat":"","_VenueLng":"","_VenueShowMap":false,"_VenueShowMapLink":false,"_tribe_blocks_recurrence_rules":"","_tribe_blocks_recurrence_description":"","_tribe_blocks_recurrence_exclusions":"","ep_exclude_from_search":false,"_jf_limit_responses":"","footnotes":""},"categories":[883,908],"tags":[2185],"content_source":[],"class_list":["post-8107115","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mindset","category-process","tag-case-study"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/posts\/8107115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/users\/8033092"}],"replies":[{"embeddable":true,"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/comments?post=8107115"}],"version-history":[{"count":5,"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/posts\/8107115\/revisions"}],"predecessor-version":[{"id":8107688,"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/posts\/8107115\/revisions\/8107688"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/media\/8107304"}],"wp:attachment":[{"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/media?parent=8107115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/categories?post=8107115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/tags?post=8107115"},{"taxonomy":"content_source","embeddable":true,"href":"https:\/\/agilealliance.org\/wp-json\/wp\/v2\/content_source?post=8107115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}