Overview

Barasingha, a cybersecurity solutions provider, wanted to develop a tool to help enterprises monitor and mitigate data leakage risks on WhatsApp. Designed for IT and compliance teams, the platform allows policy creation, detects high-risk behavior, and enables action on violations—without compromising employee privacy. It offers real-time alerts, trend analysis, and department-level insights to safeguard sensitive communication.

Team

Team

1 designer

1 designer

2 developers

2 developers

Director

Director

Founder

Founder

Tools

Figma

Figma

Clarity

Clarity

Claude

Claude

Duration

4 months

My Role

  • Collaborated with founder and PM to understand and gather requirements.Conducted workshops with PM and dev to prioritize identified opportunities.

  • Conducted research to identify user needs and validated designs through usability testing.Collaborated with legal team for identifying correct language and disclaimers.

  • Created wireframes and high fidelity mockups for dev handoff.

  • Collaborated with director and founderto brainstorm implementation strategy and identify features for MVP.

  • Developed a figma UI library to maintain design consistency in the future and to visually align with existing suite of products.

20+

scam attempts prevented by MVP

The Problem

WhatsApp is widely used across enterprises—especially by employees in sales, support, logistics, and manufacturing—for fast, informal communication with clients, vendors, and colleagues.While convenient, this has led to:

Accidental data leakage, such as sharing payment details, invoices, or internal designs.

Impersonation scams, where attackers pose as leadership or clients to request sensitive information

The Goal

Design a data leakage protection tool that enables enterprises to:

Monitor WhatsApp activity on official numbers while preserving employee privacy.

Define and enforce custom compliance policies with automated actions for violations

Track and analyze violations in real time to identify risky users, departments, and behavioral trends.

HOW IT WORKS

The Solution

01

Real time Dashboard

Live overview of employee connectivity, policy violations, trends, and team-level insights from a single dashboard

02

Violation Monitoring

03

Policy Creation

04

Employee Management

HOW IT WORKS

The Solution

01

Real time Dashboard

Live overview of employee connectivity, policy violations, trends, and team-level insights from a single dashboard

02

Violation Monitoring

All policy violations in one place with powerful filters and detailed chat-level investigation

03

Policy Creation

Easily configure, assign, and manage security policies with guided workflows and audit-ready controls

04

Employee Management

Assign WhatsApp numbers, handle reassignments, and ensure every violation is accurately linked to the right employee

01

Real time Dashboard

Live overview of employee connectivity, policy violations, trends, and team-level insights from a single dashboard

HOW IT WORKS

The Solution

01

Real time Dashboard

Live overview of employee connectivity, policy violations, trends, and team-level insights from a single dashboard

02

Violation Monitoring

All policy violations in one place with powerful filters and detailed chat-level investigation

03

Policy Creation

Easily configure, assign, and manage security policies with guided workflows and audit-ready controls

04

Employee Management

Assign WhatsApp numbers, handle reassignments, and ensure every violation is accurately linked to the right employee

01

Real time Dashboard

Live overview of employee connectivity, policy violations, trends, and team-level insights from a single dashboard

Diving into the process

Research

Before the MVP, direct user research wasn’t possible. Instead, I aligned with the Product Manager and Company Director on business goals, and leveraged insights from sales distributors who work closely with IT admins and compliance teams. After launch, I gathered direct feedback from IT admins to validate and refine the product.

Key insights

01

Admins prefer outcomes, not constant monitoring

IT teams did not want to sit inside the tool all day. They preferred summaries and alerts via email or WhatsApp, enabling action only when needed.

02

Monitoring state needed clarity

Admins needed clear visibility into when users were connected, disconnected, and what data could or could not be monitored.

03

Policy creation needed to be fast and scalable

Admins wanted policy templates, not complex rule-building from scratch

04

Multilingual complexity

Employees often communicated in regional languages—sometimes written using English alphabets—requiring broader language detection.

User Personas

Primary

IT Admin

Responsible for enforcing policies, monitoring risk, and responding to incidents

Needs

  • Detect risks in data sharing

  • Create and manage policies at scale

  • Maintain audit trails for investigations

Secondary

Compliance Head

Oversees organizational risk and regulatory exposure

Needs

  • High-level visibility into risk trends

  • Confidence in enforcement and reporting

  • Documentation for audits and legal cases

Design decisions & Iterations

#1

MVP scoping — what we deliberately left out

Three scoping calls traded flexibility for audit clarity and on-time delivery.

01.

No policy editing

Editing introduced versioning & audit ambiguity. MVP policies could not be edited — only deleted and recreated (team assignments editable)

Audit clarity over flexibility.

02.

Keyword based monitoring

MVP focused on keyword detection with media monitoring tied to keywords. Architecture left open for future policy expansions.

Faster delivery, clearer explainability

03.

No star/end dates for policies

Time-bound policies added enforcement & reporting complexity disproportionate to MVP value.

Deprioritised to reduce risk

#3

Designing for number recycling

Company-owned WhatsApp numbers are frequently reassigned. Without safeguards, violations could be wrongly attributed to the new employee. I introduced a time-bound identity mapping:

Violations were only associated from the moment a number was officially assigned.

This ensured audit-safe attribution, prevented historical mislabeling, and preserved employee trust.

Violation

19 Dec 2024

Number

+91 90123•••

Employee

by assignment date

#3

Dashboard: practical over performative

Most IT admins aren't visualization experts. I replaced an early stacked bar graph for violations by team with a tabular view for readability. It's the most critical metric — but placing it first would push other summaries out of the viewport, so I positioned it last to preserve balance. The final dashboard leans on tables, donut proportions and time-series.

Before

Single page policy for policy building

After

Policy building broken down into multiple steps

#3

Policy creation: from overwhelming to structured

The initial wireframe explored a single-page policy building model, exposing every control at once. As the logic expanded, it became cognitively heavy and hard to scale. I moved to a multi-step flow — a pattern enterprise security competitors rely on — separating rules, scope, and actions so admins configure progressively instead of all at once.

Before

Single page policy for policy building

After

Policy building broken down into multiple steps

#3

Balancing multilingual monitoring with performance

Employees communicate across many languages — often writing regional languages in English letters. Monitoring everything by default was ideal, but carried real performance cost.

English monitored by default

Admin-selected Indian languages, opt-in

Support for transliterated text

Reflected how India actually chats, without taxing the system.

Barasingha policy screen

Transliteration toggle

handles regional languages typed in Latin script.

#4

Introducing policy templates

Sales insights showed IT teams preferred ready-made policy templates over building from scratch. I designed a side-drawer–based template explorer (non-overlay) that allowed admins to browse and compare templates without losing context. The layout dynamically adjusted so existing policies remained visible.

1

Templates cards stay visible so context is not lost and use can select others to view

2

A side drawer, not an overlay — browse & compare in place.

Feedback from users confirmed the interaction enabled confident, flexible decision-making without overwhelming users

Barasingha policy screen

2

1

Transliteration toggle

handles regional languages typed in Latin script.

#5

Preserving context without mimicking chat

Admins investigating violations needed visibility into the exact message that triggered the policy, and in some cases, the ability to review an employee’s chat history. An early concept displayed this within a WhatsApp-style interface. I rejected this because it blurred the boundary between monitoring and participation and increased perceived invasiveness.

I designed a distinct interface to support audit where:

The violatory message was clearly highlighted

10 messages before and after were shown for context

Full chat access was structured and purposeful within the violation flow

Before

Whatsapp like interface

After

Distinct interface to support audit

Learnings

Systems thinking is important to provide a cohesive experience across multiple touch-points during and post purchase.

Involving dev team in design process through workshops can elevate their enthusiasm for the project, leading to smoother collaboration.