Skip to content
CV

MSP security console

Whitelabel MSP Tool (B2B)

The product

US B2B tool for MSPs: web SaaS plus a Chrome extension. Admins and MSPs see employee activity, manage DLP, passwords, and which sites people visit — a dense security CRM, not a consumer app.

I was outstaffed into the US product team. I did not own the roadmap. I owned the argument: every operator task should be short, a new feature must not break tenants that already have conflicting rules, and a cheap test beats a feature race.

Slice Ownership

Rules wizard. Users freeze on an empty page → got an idea, pitched, prototyped, tested, shipped; the pattern stayed exclusive to that page.

Owned the weekly PDF fight: argued for several A4 pages for a fuller picture. Lost, but ~6 months later they did it the way I said.

Pitched idle-in-$ — analytics that idle employees cost X dollars — then walked it back myself, because the experiment was too expensive for a small number of client managers.

Console

A work tool. Time-to-complete for each task had to be short.

I inherited a developer-built admin. Figma existed, but it was crooked. I rebuilt it on a component system and pushed engineering to use those components. The look barely changed. Information architecture and task structure were the real change. Design QA sat on top of that.

Onboarding started with company name, connecting the client’s Microsoft enterprise applications, then more setup. I did not measure time-to-complete or drop-off. The team was happy with admin performance — qualitative, not a dashboard number.

Share of MSPs who finish setup is high because sales and customer success walk them through. That is not a design conversion metric, and I do not claim it as mine.

North star in the room: “this needs to be faster.” Second-order question I kept asking: if we ship this feature, what happens to tenants that already have conflicting rules?

What shipped

A wizard I shipped. A PDF fight I lost, then won six months later.

New MSP admins froze on an empty Rules page. I proposed and shipped a wizard to cut that learning curve. I wanted wizards — and a master search — on every dense page. People often arrived and thought “what am I supposed to do?” Only Rules got the pattern.

Weekly PDF to the client-company manager: MSP results and steps they could take inside to improve security. I usually cut. Here management wanted form over function — everything on one A4. The content does not fit one sheet. I argued for two or three pages. Killed. About six months after the feature existed, they shipped it the way I said. The constraint was visible up front.

Dozens of iterations of the same pages to tighten flow. Copy review, marketing review, occasional marketing design, work with a marketing designer. Planning, design QA, getting the component system into engineering.

AI bets

Cheap revise loops. Most stayed prototype or got killed.

The rules UI is atypical and hard for MSP newcomers. I prototyped in Cursor: type instead of clicking the whole editor. Product docs were connected, so the model understood the logic. Output was a draft for a revise process — not final rules. After a few text passes, someone would know how to do it in the real UI without correcting later. Cheap quick win, not perfect. Stayed a prototype.

Separate experiment in the live console: paste a Slack thread, get a suggested set of cybersecurity rules.

LLM search for incidents — “what did user X do on Tuesday at 14:00?” Made sense out loud. Killed. I pushed gradual AI. Resistance was “this is new for developers, we do not want to spend time learning it,” plus “who pays for tokens?” At the product’s user count, caps would not have been a million-dollar burn. Could also have been a pain reliever for no mobile web: if text works, Slack from a phone. Displacing the MSP as the middleman between security and the client — I would have red-lit that myself.

Questions

Most of these were killed. From another country and a designer seat I did not see everything they saw — or I saw it at a different angle. I still do not know who was right. A careful test would not have hurt.

  • Employee portal vs a Chrome extension that nags. Hypothesis: show who is at risk of becoming a low performer, idle time drops. Killed as “we are already too present on their machines” — they meant pop-up count. I meant a qualitative shift, not another popup.
  • Idle time of observed users in dollars, for a recession-era client manager. Killed: needs client input / a CRM integration. Too expensive for a test aimed at ~2 people per company. I saw that and backed off.
  • Company policy as a five-minute informal clip, not a newspaper in email and not a grey Big Brother tone. People learned changes by bumping into “oh, that’s blocked now.” Killed: the company’s role was to stay strict.
  • Wizards and master-search on every dense page, not only Rules. Freeze was common. Pattern did not spread.
  • Point solutions of AI (“even your dog can use it”) instead of racing competitors on feature count. Feature count does not sell a dense admin. Cut on tokens and eng learning cost.
  • Policy change confirmation as a GitHub review: old on the left, new on the right. Intuitive for technical MSPs. Killed.
  • What-if before push, like a competitor: this user, time, site, device → allow / warn / block. Live-test a rule so you do not break someone’s work. Small, high-leverage. Killed.

The loop

Two years in the product. I left when the job became screens without a loop.

Day to day: hundreds of hours of US C-level demos, moderated tests, PostHog and AI-PostHog (how deep people went, how long sessions lasted), whether a design actually mapped onto the technical constraints. Hundreds of 1:1s with product managers. Weekly contact with the CEO and other C-level. Vibe-coding and agents before Figma had decent AI; Figma Make; a pile of prototypes before Make.

The interesting part lasted while there was still logic, interviews, tests. It wore thin when the task became “go make the design” without talking through the product. I left when the role narrowed to execution-only without a product loop. I want to own what we build and why — not only the file after the decision.