Case study
OneTrust
Issues Management shipped after a year of engineering with no UX involvement. Its largest enterprise clients were running the work in JIRA and Excel instead.
The situation on arrival
Misclassified records across the platform, each one exposure at audit.
Misclassified issues per client.
Organizations on the platform, with adoption of Issues Management near zero.
What was stated
Adoption was low and clients were resistant to change. Change management was taking too long, and the largest accounts had gone elsewhere. Workday, John Deere, and Woolworths were tracking issues in JIRA and Excel. The read inside the business was that the product needed to be easier to adopt.
Issues was meant to connect Assets, Vendors, Audits, Ethics, and Incidents. The connections were half-formed. No migration path existed for the 420M records already in the system.
What was actually true
I ran six internal interviews with power users, including the Chief Trust Architect, InfoSec, and GRC specialists, then six validation sessions with enterprise clients, among them Workday, John Deere, and Woolworths. In parallel I diagrammed the current state across all 12 interconnected verticals, and my Staff UX Designer counterpart audited how those verticals actually connected.
Three independent lines pointed the same direction. Clients had not rejected the product on its features. They had built protective workarounds against a system that had cost them before. The JIRA and Excel setups were not habits and they were not preferences. They were insurance.
That reframed the problem. The barrier was the cost of change management, not the feature set. A migration that could not be reversed was a migration no compliance team would authorize, regardless of how good the destination was.
Change management takes too long. We're already using JIRA and Excel.
What changed
The migration became three stages, each one designed so a compliance team could stop and verify before committing.
Attribute mapping. Map data fields from Risk to Issues, handle required against optional, and flag conflicts before anything moves.
Workflow configuration. Map workflow stages with parent and child relationships, with save and draft so work can pause. One client asked what would happen with 100 workflows, which moved the pattern from horizontal mapping to a vertical accordion that holds any volume.
Execution. Select risks, migrate with full reversibility through a recycling bin, no data duplication. Any authorized user can resume where another left off, which matters for teams split across time zones.
Enterprise validation sessions, run with the clients who had walked away.
Organizations covered by the production-ready specifications.
Each independently reversible before commit.
The pivots that defined the design
Three decisions turned a broken modal experience into a migration system built for enterprise scale.
Pivot 1
Full-page vs. modal
There was too much data for a scrollable modal to hold. I moved the flow to dedicated full-page steps with a persistent stepper, so people kept their orientation and control through the whole migration.
Pivot 2
Save state, draft mode
Enterprise teams are distributed across time zones, so migrations needed to survive being paused. Any authorized user can pick a migration back up exactly where someone else left it.
Pivot 3
Accordion compression
One client asked what would happen with 100 workflows. That question moved the pattern from horizontal mapping to a vertical accordion that holds any volume without losing legibility.
What if we have 100 workflows?
Delivered
After the engagement ended, I returned to a gap the research had surfaced but the scope hadn't covered: clients hadn't left because the product failed them, they left because the cost of coming back felt too high. On my own initiative I built two live, interactive prototypes to show them what their data could actually look like inside the platform.
Neither prototype existed at OneTrust before this. Recognition before action, return instead of restart: not as a pitch, but as proof.
Where it stopped
I moved to EA Frostbite before engineering finished implementation. What I left behind was a full service blueprint of the migration ecosystem, the three-stage flow, a working prototype validated across six client sessions and documented on video, and a pattern library covering accordion compression, save state, and reversibility. Engineering continued the build after my transition.
Alongside this I coordinated four designers across verticals under shared conventions, co-led the client validation sessions with the Product Manager and Content Designer, and ran a parallel Ethics SpeakUp investigation workspace.