
Product Strategy and Design
Building Policy Composer for Identity Governance
As companies connect more apps, roles, and users to their identity platform, access rules multiply faster than anyone can track by hand. Organizations need a structured way to make sure access always matches policy, not just once a year during an audit, but continuously. Policy Composer brings together policy definition, testing, and automated enforcement into a single, unified experience. I led product strategy and design for Policy Composer, the rule-building engine inside Cymmetri's identity governance suite.
DURATION
Jan 2023 - Aug 2023
MY ROLE
Product Strategist & Designer
METHODS
Stakeholder Interviews, Systems Mapping, Wireflow Mapping, Prototyping

The Problem
Access changes faster than governance processes can keep up. Compliance and security teams are left managing critical questions about who has access to what, whether that access is still appropriate, and how a rule actually gets enforced — without a unified way to define, test, and monitor policy across the organization.

Insights
From our stakeholder interviews and workflow mapping, Compliance and security teams knew exactly what access should look like. What they lacked was an intuitive way to turn that knowledge into a working rule, test it safely, and trust the result before it turned into real access.

Goal
These insights from our research team made us think about how identity governance could help the business find customers who need the feature where-

Solution
What we did back then was a simple logic form, I explored a new path with claude code where I built a visual composer to create, evaluate and fix the policy before publishing it.
Lowering the Barrier to Policy Creation by Introducing a Policy Composer
I designed two ways to build a policy — one manual, one AI-assisted — and a simulation step that catches mistakes before a policy ever goes live.

Generating Policy with AI
If an employee, describes the policy in plain language, how can the canvas build the logic?
Build from Scratch
For admins who already know the exact rule, blocks connect by hand, one condition at a time
Failure State
What happens when a policy contains missing logic, disconnected rules, or incomplete decision paths?
Recovery from Failure State
If this policy fails to execute because of missing or broken logic, how can the system help users fix it?
Thinking in Systems
Policy management isn't a linear process. Rules need to be drafted, tested, approved, and continuously refined as new access scenarios emerge and once published, they have to keep checking real activity against themselves, indefinitely. I designed a decision-based workflow that captures the full lifecycle of a policy: from the moment an access event is detected, through drafting and simulation, to publication and ongoing enforcement.

Learnings and Reflections
01
The previous version was precise, every field mapped exactly to the underlying logic, nothing was simplified away. But precision alone didn't make it easy to see what a policy actually did.
02
Rebuilding this with Claude Code wasn't about adding AI for its own sake. What changed is that the logic is now something you can look at, not just fill in.
OTHER PROJECTS

Designed the 0→1 product experience for an AI career platform to guide your career decisions

Redesigned Google's in-product lessons so users could learn how to use their products better
View all work
User Research
Got something complex?
UX Strategy
Let's untangle
Learning Design
it together!
Experience Design
Feel free to reach out to me personally via sending a message, or schedule a time to say hello!
Made with care and strategy in Framer
All rights reserved @ Priyanka Ghosh 2026
