Enter the password to view this case study.
Microsoft Defender · Collaboration · 2023
A collaborative investigation surface where multiple security analysts can pin, annotate, and connect evidence during active threat response.
The problem: active threat investigation is collaborative work done with solo tools. Analysts on the same incident duplicated effort, lost each other's findings, and coordinated over chat while the actual evidence lived somewhere else entirely.
My role: product designer for the concept, a swarm-driven pinboard where multiple analysts pin, annotate, and connect evidence together during live response.
Evidence-first collaboration, the board holds live artifacts from the investigation itself, not screenshots and links to them.
Presence and attribution built in, you always know who pinned what, and why they thought it mattered.
The board lives inside the incident, so swarming never means leaving the investigation context.
Outcome: strong leadership buy-in on the concept, and enough conviction that the data science team built the first working prototype from it. The full concept walkthrough is below.