Governance Hub — Kaili Miyamoto
Protected
This case study is password protected

Enter the access phrase to read the full study — or request it.

That phrase isn't right — try again.
← Work Governance Hub Next →
Microsoft · Governance Hub

A dozen compliance emails a week, collapsed into one place to look.

A shared dashboard for tracking policy compliance across the org — one view instead of scattered inbox alerts.

Led end-to-end design for an enterprise platform serving every Microsoft employee who owns a digital asset, driving alignment across global PM and engineering teams.

Role
Product Designer
Timeline
2026
Type
Compliance UX · Admin dashboard
Impact
0%
fewer compliance emails landing in inboxes.
72% →72%
org-wide compliance rate, after the dashboard shipped.

97% fewer alerts, and a rate that went up — both moved once the emails stopped being the only signal.

The short version

How this actually went.

I took over a project that had stalled. The design work came after the repair work.

Brought on

Took over a stalled project mid-flight.

Rebuilt relationships

Inherited eng and PM relationships in worse shape than the work.

Went back to the research

Settled what the hub had to answer before drawing anything.

Defined the system

New components, one language across the product.

Restructured the emails

One monthly digest, not one alert per violation.

Rebuilt the hub

Your own assets, sorted by what is due.

Designed the AI layer

Copilot explains consequences and suggests owners. Not shipped yet.

Iterated

Measured, then cut what reviewers didn't use.

The problem

Everyone got the emails. Nobody could see all of them.

Compliance ran on scattered inbox alerts. Three things kept it broken.

01
Scattered
Every policy gap arrived as its own email, to its own owner, with no shared view.
02
Unowned
Nothing showed who was responsible for what, so gaps sat unresolved.
03
Invisible
Leadership and teams couldn't see org-wide compliance status anywhere — only individual inboxes knew.
How we knew

We read the inbox before we designed anything.

A month of compliance alerts, and the people on the receiving end of them. Three findings shaped the build.

Volume
Every violation on every asset sent its own email. An owner with a couple of hundred assets got a stream of them, one item at a time.
Ownership
Nobody could say who owned a gap without forwarding the email to find out who it belonged to.
Visibility
No org-wide view existed. Leadership assembled status by asking teams one at a time, which is why they wanted a single number.
The email

Make the alert carry the answer.

People weren't going to stop getting emails, so the email had to stop arriving one asset at a time — a single monthly digest of everything you own, compliant and not, with one way in.

Before
The old alert: one asset, its policy violations and a deletion deadline
One email per violation, per asset.
After
The monthly digest: total assets, non-compliant assets, and every asset type broken out
One email a month, for everything you own.
The gap

The digest shipped first, and it worked: 97% fewer alerts. It still couldn't tell you where you stood.

The decisions that mattered

The research and the ask didn't agree.

Leadership wanted the single number they'd been assembling by hand. The people who actually close gaps needed the opposite: their own gaps, by name, with a next step. Those aren't the same view, and most of the design work was holding both without letting either win outright.

01

Deadlines first, owners on every row

A percentage is not something you can act on. So the hub opens on your own assets, sorted by what's due, and the rollup leadership asked for sits on top of that list rather than replacing it.

Sorting by policy type was the other option and it read cleanly, but it buried urgency two clicks down. A view that hides the thing you're behind on is a report, not a tool.

02

No automated nagging

The fastest way to move the rate was more pressure: escalate overdue items automatically, copy the manager, keep sending. I argued against it. Nobody was missing deadlines because they hadn't been told; they were missing them because nothing showed them where they stood. Adding volume to a channel people had already tuned out would have spent the last of the attention those alerts had.

The hub

One place that shows where you stand.

Every decision we made is visible on this one screen.

Governance Hub home in the browser, with the Digital Asset Governance drawer open
01
Only the assets you own

Alex sees his 145 assets, not the org’s.

02
Everything you own, counted

Actions, attestations, recommendations and the total, in one row.

03
Sorted by what is due

Deadlines drive the order, state sits beside it.

04
A next step per row

Add an owner or delete — suggested, never applied.

05
Copilot reads out the consequences

The assistant spells out what deleting breaks, before anyone confirms.

06
Requests start here

The asks people used to email, opened from the same screen.

Takeaway

The compliance rate didn't move because policy changed. It moved because people could finally see it.

Tracked before and after in the same compliance dashboard, org-wide.

What I'd change

The hub shows an owner where their own assets stand, but not why a gap is still open — you see red without seeing the blocker. A reason that travels with the gap is what I'd build next.

More work All projects →
{{ r.num }}
{{ r.name }}