Security Center
Designing Auth0’s first security observability product, so customers of any size could see an attack on their login traffic and respond to it themselves.
Customers found out about attacks after they happened
Companies use Auth0’s Identity as a Service platform to handle sign-up and login for their own customers and workforce. That often makes every customer’s Auth0 tenant a target for bad actors using bots, brute-force attacks, and stolen credentials, and Auth0 already offered protections against each of them.
What customers lacked was an integrated way to see an attack while it was happening. In the cases that reached Auth0’s own team, the pattern was the same. A customer noticed something was wrong (often weeks after it started), contacted Auth0, and waited while we investigated their traffic and changed their configuration for them. Most of those calls could have been avoided if the customer had known the attack was underway and what the right response was. Threat intelligence tools existed, but they were costly and needed direct integration.
Security Center was the Identity Security team’s most important initiative through 2021 and 2022. The goal was to help customers respond to and mitigate attacks in real time, and give them the tools to prepare for the next one. I was the lead designer for Security Center, working with a product manager and our engineering teams. I led all of the user research and design revisions from the first concept through launch, and maintained and iterated on the feature after it shipped.
Proving the need for another monitoring tool
Testing with non-Auth0 customers
Security Center started from a few anecdotal requests and our own assumptions. Security dashboards weren’t new in developer tools, and many large customers had already built their own. So I began with generative research outside Auth0’s customer base to learn how companies actually handle security incidents related to their identity or authentication systems, then took what we learned to Auth0 customers of different sizes and industries to verify. Their processes and expectations matched, which gave us the confidence to invest in this observability platform.
Bring product and engineering into the research
Security was a domain where I didn’t have every answer, so I asked my product and engineering partners to contribute learning objectives, plan the studies, and join the sessions as observers. I took the engineers’ open questions to customers directly. Across six rounds of research over a year and a half, that gave the team shared ownership of the direction. It also let engineers shape the architecture for streaming and visualizing data before they built it, which reduced surprises and tech debt later.
Design for a range of expertise, not one kind of enterprise
We expected enterprise customers to have similar security expertise, but my research findings showed a wider range. Teams with established security practices, like fintech companies, already had their own monitoring and cared more about automation and integrations. Smaller teams, or those with less expertise, like education, relied on Auth0 to keep them safe and valued monitoring most. Alerts mattered about equally to all of them, because nobody lives in a dashboard. More than 80 survey responses backed up what we heard in interviews, and it shaped the order we built things in.
From seeing an attack to acting on it
Research pointed to five needs: seeing what was happening in their traffic, being alerted to risk, clear direction on what to do, a way to automate the response next time, and ways to reduce exposure before an attack. I turned them into a longer-term product vision with my product manager, and we pitched it to executive leadership. In the end, the roadmap investment was approved which gave the wider product group a shared multi-year direction.
The first releases focused on monitoring which included a threat overview for each tenant, individual detection charts for risk signals like bot detection, brute-force protection, suspicious IP throttling, breached password detection, and MFA. Each chart indicated whether the related protection was turned on and linked to its settings, so a customer can go from spotting a spike to changing a configuration in one place, and then monitor the impact of that change.
We shipped iteratively, working towards an early alpha and working through various stages of our release cycle towards general availability. As we collected more feedback, we heard that some detection metrics could be noisy depending on traffic volume. So I also iterated on alerting thresholds, so customers could be notified when a signal like MFA success rate crossed a level they defined. This shipped after I left Auth0, but the charts and patterns we defined for security observability also became the foundation for data visualization across Auth0’s dashboard.
Fewer attacks that needed Auth0 to step in
Security Center launched in early 2023, included in Enterprise plans at no extra cost. Because it was a value add rather than a product of its own, its impact shows up indirectly. It helped influence higher-value deals and grow the share of Auth0’s revenue that came from attack protection. Our engineering team also received fewer tickets asking them to resolve threats on a customer’s behalf, which freed their time for other work. It became a way to show Auth0’s security capabilities to industry analysts and in public demos, and became the foundation of the platform’s longer term Identity Security strategy.
The lesson I took from Security Center built on learnings from early in my career with McAfee Gamer Security. Research works best when the whole team does it together and critically analyzes the results against our internal biases. When product managers and engineers hear customers directly, they are empowered to make better and more informed decisions, and the team owns the direction instead of waiting to be convinced of it.