Action Center

Action Center

From scattered security findings to a clear remediation workflow.

From scattered security findings to a clear remediation workflow.

Security

Remediation

Task Control

B2B SaaS

The Problem- Security teams had the data. They didn't have a place to act on it.

The Problem-

Security teams had the data.

They didn’t have a place to act on it.

01

Scattered Actions

Tasks spread across multiple pages with no unified workspace

Tasks spread across multiple pages with no unified workspace

02

No Priority Signals

No urgency indicators - everything felt equally important

No urgency indicators -

everything felt equally important

03

No Filtering

No way to filter by compliance framework, category, or application

No way to filter by compliance framework, category, or application

04

No Ownership

Unclear who should resolve what - no task assignment or tracking

Unclear who should resolve what - no task assignment or tracking

I identified the gap and pushed to centralize everything into one actionable screen.

I identified the gap and pushed to centralize everything into one actionable screen.

User Personas - Three audiences, one interface

User Personas

Primary Persona

SOC Analyst

Works on tasks over time - goes, comes back. Acts inside and outside Vorlon.

Key Features

• Side panel resolution (no context switch)

• Business-weighted priority

• App criticality rating

Job to be done

"Pick up where I left off, resolve subtasks, track progress - without losing context."

CISO

Needs a high-level security posture overview. Scans risk by category.

Key Features

• Task category summary & counts

• Open / completed / snoozed overview

• Compliance framework breakdown

Job to be done

"See organizational risk at a glance - open, resolved, and where we stand."

App SOC

Sole access to resolve specific app permissions. Needs to act fast.

Key Features

• Filter by specific application

• Filter by task category

• Quick inline actions

Job to be done

"Show me only my app's tasks, let me fix it quickly, and get it off my plate."

Competitive Research

Competitive Research

Analyzed leading security and AI SaaS platforms to identify gaps. Three key examples from a broader research:

Analyzed leading security and AI SaaS platforms to identify gaps. Three key examples from a broader research:

Key Insight

Key Insight

Each competitor solved a different part-but none combined discovery, prioritization, execution, and tracking in a single workflow.

Each competitor solved a different part-but none combined discovery, prioritization, execution, and tracking in a single workflow.

Analyze

Analyze

Competitor

✓ What worked

✕ What didn't work

+ Our advantage

Competitor X

Single-page views, combined filters, and one-click remediation

Work still starts from findings and different context pages

A central Action Center that consolidates tasks, execution, and tracking

Competitor Y

Direct 'Things to do' language and guided playbooks that clarify what to do now

Large cards work for a small number of actions, but not for dozens or hundreds of tasks

A scannable, filterable list with clear actions at scale

Competitor Z

Grouping by Missions with owner, effort, progress, and expected risk impact

Structure fits campaigns and broad goals, less suited for managing individual daily tasks

Combining focused tasks with grouping by root cause or outcome

Early Thinking- Task Logic & Structure

Early Thinking- Task Logic & Structure

Design Decisions

Design Decisions

The result: A proactive environment to identify, prioritize, and close security gaps- before they become alerts.

The result: A proactive environment to identify, prioritize, and close security gaps- before they become alerts.

Proactive over reactive

Proactive over reactive

The Action Center focuses on closing security gaps proactively - not just responding to alerts after the fact.

The Action Center focuses on closing security gaps proactively - not just responding to alerts after the fact.

Clear tasks in one center

Clear tasks in one center

Every finding becomes an actionable task with context, path, status, and history.

Every finding becomes an actionable task with context, path, status, and history.

Efficient at scale

Efficient at scale

Flexible table with search, bulk actions, and filters by app, priority, and security frameworks.

Flexible table with search, bulk actions, and filters by app, priority, and security frameworks.

Categorized workflow

Categorized workflow

Tasks grouped by system, admin, security, and hygiene for easier ownership.

Tasks grouped by system, admin, security, and hygiene for easier ownership.

Smart prioritization

Smart prioritization

Ordered by risk severity and business impact, not just technical score.

Ordered by risk severity and business impact, not just technical score.

Psychological Insight- Designing for How Analysts Think

Psychological Insight

01

Reduce Cognitive Overload

Reduce Cognitive Overload

Users face hundreds of tasks with complex details. A progressive disclosure pattern — table for scanning, side panel for deep-dive — prevents information overload while keeping all data accessible.

Users face hundreds of tasks with complex details. A progressive disclosure pattern — table for scanning, side panel for deep-dive — prevents information overload while keeping all data accessible.

02

Preserve Context

Preserve Context

Page switching breaks concentration during complex investigations. A continuous side panel flow — from task overview through subtasks to resolution — lets users complete work without losing their place.

Page switching breaks concentration during complex investigations. A continuous side panel flow- from task overview through subtasks to resolution — lets users complete work without losing their place.

03

Match Mental Models

Match Mental Models

Similar actions can have different intentions. Snooze returns a task later while Dismiss requires a reason — distinct behaviors that match how users think about deferring vs. closing work.

Similar actions can have different intentions. Snooze returns a task later while Dismiss requires a reason-

distinct behaviors that match how users think about deferring vs. closing work.

Design Decision: Cards vs. Table-

Architecting the core framework for density

Cards vs. Table-

Cards View

Rejected

+ More visual and approachable for quick overview

+ More visual and approachable for

quick overview

+ Breaks consistency- rest of the platform uses tables

+ Breaks consistency- rest of the platform

uses tables

- Visually rich but low density

- Good only for small task volumes

- Extremely hard to scan at scale

- No efficient bulk action capability

Table View

Chosen - Phase 1

+ Fast scanning at volume

+ Fast scanning at volume

+ Sorting & filtering native

+ Sorting & filtering native

+ Bulk selection built-in

+ Bulk selection built-in

+ Scales to hundreds of tasks

+ Scales to hundreds of tasks

+ Clear priority visibility at a glance

+ Clear priority visibility at a glance

+ Flexible - users sort by any column they need

+ Flexible - users sort by any column

they need

Table view was chosen for the initial release due to development constraints and its strength in density, scanning, and bulk actions. But I set a goal to develop a cards view in the future and let users toggle between the two - different users have different needs, and some may prefer a visual, card-based layout. There's no single right answer- what matters is giving users the choice.

Table view was chosen for the initial release due to development constraints and its strength in density, scanning, and bulk actions. But I set a goal to develop a cards view in the future and let users toggle between the two - different users have different needs, and some may prefer a visual, card-based layout. There’s no single right answer- what matters is giving users the choice.

Task Complexity- Every task is more than a single action

Each task type required a unique side panel design- permissions, affected applications, exceptions, timelines, and different available actions. The full flow had to support a user starting a task, working through its subtasks, and completing it- all without losing context or progress.

Subtasks

Each task contains multiple subtasks. Some are independent, some are dependent on each other and must be completed in order.

Subtasks

Side Panel Actions

Permission Requests

External Actions

Subtasks

Each task contains multiple subtasks. Some are independent, some are dependent on each other and must be completed in order.

Subtasks

Side Panel Actions

Permission Requests

External Actions

User Flow- From table to action- without leaving context

User Flow

Scan table → Open Side Panel → Resolve subtasks → Done. No page switches.

Scan table → Open Side Panel → Resolve subtasks → Done. No page switches.

Subtasks vary: independent, dependent, in-system, external, or permission-required - each with a distinct resolution path, all within the same panel.

Subtasks vary: independent, dependent, in-system, external, or permission-required - each with a distinct resolution path, all within the same panel.

Pending Tab Flow

Pending Tab Flow

Completed & Snooze Tabs Flow

Completed & Snooze Tabs Flow

System Logic- Rules that drive the experience

System Logic

Snooze ≠ Dismiss

A snoozed task returns automatically. The security gap doesn't disappear - it's deferred to a date, but will keep coming back until resolved.

Cross-Tab Presence

One task can appear across Pending, Completed, and Snoozed tabs simultaneously - each showing relevant subtasks for that state.

Task Lifecycle

Every subtask flow accounts for start → progress → complete. Users can leave and return without losing context or progress.

Task Lifecycle- From open gap to resolved

Task Lifecycle

Three states track every action. Pending is the daily workhorse. Completed provides the audit trail, and Dismissed tasks return automatically - a gap is still a gap.

Three states track every action. Pending is the daily workhorse. Completed provides the audit trail, and Dismissed tasks return automatically -

a gap is still a gap.

01

Pending

02

Completed

03

Dismissed

01

Pending

Quick filters

CISO snapshot by category, rapid filter for SOC analyst

Advanced filtering

By application, security frameworks, or inline from the table

Task priority

Priority level on each task for focused triage

Pending

Completed

Dismissed

01

Pending

Quick filters

CISO snapshot by category, rapid filter for SOC analyst

Advanced filtering

By application, security frameworks, or inline from the table

Task priority

Priority level on each task for focused triage

Priority System- Multi-layered, context-aware prioritization

Priority System

Priority = observation severity × business-critical app rating. The same vulnerability ranks differently across applications. But priority doesn't stop at task level - subtasks have their own urgency too, and the task's overall priority rolls up from them.

Priority = observation severity × business-critical app rating. The same vulnerability ranks differently across applications. But priority doesn’t stop at task level - subtasks have their own urgency too, and the task’s overall priority rolls up from them.

Task Level- Business-weighted scoring

Apps rated by criticality at onboarding, auto-weighting task priority.

Subtask Level- Color dot + hover detail

Subtasks show colored priority dots. Full detail on hover — no clutter.

Roll-up- Priority cascades up

Task priority computed from subtasks. Resolving urgent ones impacts the score.

Impact- Changed the entire information architecture of Vorlon

Impact

Users- Daily Active Centerpiece

All users adopted this screen. Many made it their home screen, turning Vorlon into a day-to-day tool rather than an occasional check.

All users adopted this screen. Many made it their home screen, turning Vorlon into a day-to-day tool rather than an occasional check.

Customer Success- Accelerated Onboarding

Customer Success used it in demos and onboarding to show immediate value. Made it easy to generate reports demonstrating Vorlon's security contribution.

Customer Success used it in demos and onboarding to show immediate value. Made it easy to generate reports demonstrating Vorlon’s security contribution.

Sales- The Go-To Demo

Became the go-to demo screen, making Vorlon's value tangible to prospects within the first 5 minutes. Helped close enterprise deals.

Became the go-to demo screen, making Vorlon’s value tangible to prospects within the first 5 minutes. Helped close enterprise deals.

Business- Strategic AI Enablement

Shifted the entire information architecture toward actionability. Enabled adding AI-specific tasks - agent management, AI tool permissions - which helped Vorlon advance its AI security strategy across the organization.

Shifted the entire information architecture toward actionability. Enabled adding AI-specific tasks - agent management, AI tool permissions - which helped Vorlon advance its AI security strategy across the organization.

What I Learned

What I Learned

01

Owning a real problem- from discovery to solution

Owning a real problem- from discovery to solution

This feature wasn't on any roadmap. I identified recurring user complaints, researched competitors, and arrived with a complete solution.

This feature wasn’t on any roadmap. I identified recurring user complaints, researched competitors, and arrived with a complete solution.

02

Prioritizing under constraints- phased delivery

Prioritizing under constraints- phased delivery

With limited dev time, I focused Phase 1 on what was most critical: the table view for density and scale. Phase 2 will introduce a cards view toggle - giving users the choice without compromising the initial launch.

With limited dev time, I focused Phase 1 on what was most critical: the table view for density and scale. Phase 2 will introduce a cards view toggle - giving users the choice without compromising the initial launch.

03

Cross-functional feedback loops shaped the feature

Cross-functional feedback loops shaped the feature

This feature touched every department- sales, customer success, marketing- so I ran continuous feedback loops throughout the process. That collaboration got stakeholders invested and made the end result sharper and more accurate.

This feature touched every department- sales, customer success, marketing- so I ran continuous feedback loops throughout the process. That collaboration got stakeholders invested and made the end result sharper and more accurate.

Task Lifecycle- From open gap to resolved

Three states track every action. Pending is the daily workstream, Completed provides the audit trail, and Dismissed tasks return automatically- a gap is still a gap.

01

Pending

Quick filters

CISO snapshot by category, rapid filter for SOC analyst

Advanced filtering

By application, security frameworks, or inline from the table

Task priority

Priority level on each task for focused triage

02

Completed

Subtask status visibility

Subtasks shown as completed, open, or dismissed

Filtering by application

SOC analyst filters by app to track closed gaps

03

Dismissed

Dismiss accountability

Who excluded, when, and why- team transparency

Subtask visibility

Expand/collapse subtasks-

completed, open, or dismissed

Reopen options

Reopen a subtask or the entire task anytime

© 2026 Roni Lorentz