Home / Projects

Agent Groups: Group Creation and Policy Management (Compliance)

Agent Groups: Group Creation and Policy Management (Compliance)

Overview

As environments scale, users need a reliable way to organise agents across their assets so they can understand what is deployed where, identify gaps in coverage, and ensure assets are being monitored and protected as expected. Organising agents effectively helps users quickly spot misconfigurations, reduces uncertainty when investigating issues, and supports confident decision making across complex environments.

Role

Senior UX Designer

Contributions

Shaping strategyUser research and testingEnd to end design

Company

Rapid7

01. Project introduction

What are agents?

Agents are small software programs installed on devices and servers. They collect security data, help enforce controls and give teams visibility into what is happening across their environment.

As organisations grow, the number of agents increases. This makes them harder to keep track of. Users need a clear way to see which agents are installed, where they are running and whether they are working properly. Without that visibility, it is difficult to trust that the environment is fully covered.

Why users want to organise agents

Users want a simple way to view and organise their agents so they can make sure everything is covered and working as expected. This helps them quickly spot missing agents, outdated versions or configuration issues.

Having this visibility also makes it easier to apply policies and manage agents at scale. Instead of manually checking systems or reacting to problems, teams can stay in control and reduce day-to-day effort.

02. The Problem

Agent management had become fragmented and difficult to scale due to several gaps in the existing experience:

Together, these issues made agent management reactive and fragile, particularly in large or fast-changing environments.

03. Discovery and Research

User journeys

To better understand user needs, I mapped end-to-end user journeys across the agent lifecycle, from deployment and configuration through to monitoring and troubleshooting. Because agents act as a primary data collection layer, it was important to understand how they differed from other collectors in terms of lifecycle, ownership, and control. I mapped all product areas related to Data Collection to ensure consistency throughout as all data connecting objects need to be unified.

This work helped:

User journeys across Data Collection
User journeys across Data Collection

Competitor Landscape

A review of the competitive landscape showed that leading security platforms provide significantly more flexibility and automation in agent and asset management. Rather than relying on static tables and manual configuration, competitors enable dynamic grouping, policy inheritance, and real-time updates.

Common patterns across competitors included:

This analysis reinforced an industry expectation for dynamic, automated agent management and highlighted the limitations of static, manual approaches.

Competitor analysis Competitor analysis Competitor analysis
Rapid7's main competitors in the agent management space are Crowdstrike, SentinelOne and Tenable

Use Cases and User Stories

Consolidating use cases and user stories helped ground the work in real user behaviour:

Product Audit

To inform a unified approach, I conducted a cross-product audit of how groups were defined, configured, and used across siloed products. Each product had evolved independently, resulting in inconsistent patterns and duplicated concepts.

The audit:

This ensured the experience supported both initial setup and long-term management at scale. This work created a shared baseline that enabled informed decisions about what to standardise, what to keep flexible, and how to unify without adding complexity.

Group creation patterns across products
So many siloed products had different patterns for creating a group. A unified pattern had to be decided upon.

User Interviews and Insights

I conducted research sessions with seven of our top customers to understand how they deploy, organise, monitor, and troubleshoot agents at scale.

Key Insights:

1. Navigation and Information Architecture

UX Insight: Create a central page where KPIs act as contextual filters, surfacing live system states.

2. Agents and Identity

UX Insight: Clarify identity logic and introduce intelligent detection and filtering.

3. Error Handling and Support

UX Insight: Redesign error messaging with clearer ownership, cause, and next steps, supported by automatic log collection.

4. Groups and Tagging

UX Insight: Use groups for control and tags for filtering and reporting, with clear inheritance visualisation.

5. Policies and Controls

UX Insight: Rename controls to policies and introduce a transparent, hierarchical policy model.

6. Installation and Deployment

UX Insight: Introduce unified installer flows with visible states and pause functionality.

04. Conceptualisation

Although the core user needs were clear, conceptualising the solution required significant cross-team collaboration due to inconsistent grouping patterns across siloed products. The work extended beyond interaction design into defining foundational platform concepts.

Key areas of focus included:

To reduce cognitive load and backend complexity, policy precedence was defined at policy creation rather than during agent movement. This ensured predictable behaviour and removed the burden from users during day-to-day management.

Structuring groups across the platform
Working with product leads to agree on how to structure groups across platform
Former Prevention Groups experience
Former Prevention Groups experience

05. Solution

The final solution aligned agent management with the unified platform while contributing scalable patterns for future use.

Key elements included:

Together, these changes delivered a more coherent, scalable agent management experience.

Newly established policy prioritisation pattern
Agent groups solution screen Agent groups solution screen Agent groups solution screen

06. Results and Learnings

Overall, the project validated the direction of the solution while providing clear guidance for future platform-level improvements.

Get in touch

I am always happy to discuss new opportunities or anything design related!

Contact Now