AI Assistant Chat
Project Overview
The platform holds a lot of data, assets, detections, traffic, vulnerabilities, sensitive data findings. Getting answers from it meant knowing where to look, which tab to open, which filter to set. The AI assistant changes that entirely: ask a question in plain language, get a structured answer with tables, related context, and links, all without leaving the chat.
// My Role
I led the design of the full assistant experience, conversation UI, response patterns, table rendering, and contextual side panel.
This was a company-wide strategic initiative, AI was where the market was heading and we needed to move fast. I owned the design end-to-end: the chat interface, how the AI surfaces structured data inside a conversation, and the contextual panel that shows related findings alongside the answer.
// Problem
Analysts knew the answers were in the platform, finding them meant navigating across tabs, filters, and features they didn't always know existed.
The platform was rich with data, but fragmented across multiple surfaces. An analyst investigating a compromised component might need to cross-reference traffic data, check for sensitive data detections, review IoC findings, and look at asset context, each living in a different part of the UI. There was no unified way to ask a question and get a complete answer. Time that should have gone into investigation went into navigation.
Fragmented
Answers spread across multiple tabs, views, and features
No
Single place to search or query across the entire system
High
Exploring the syytem cost before analysts could even begin investigating
// Research
I mapped the questions analysts actually ask, then designed the assistant around those exact mental models.
Before designing a single prompt, I worked with the team to understand the questions SecOps analysts ask most often: what components have active detections? which assets are exposed? where is sensitive data flowing? I mapped those question patterns, identified what data each answer requires, and used that to define both the assistant's capability scope and the response formats, plain text for summaries, tables for lists, contextual links for related findings.
20+
Analyst question patterns mapped before design began
3
Response formats defined: text summary, inline table, contextual panel
Full
System access, assistant can query across every platform data source
Key Insight
Analysts don't just want an answer, they want the answer with enough surrounding context to trust it and act on it. A table of detections is useful. The same table with related asset context, traffic data, and a direct link to the full view is what actually moves an investigation forward.
Design Opportunity
How might we give SecOps analysts a way to ask any question about their environment and get a structured, contextual answer, without knowing in advance which part of the platform holds the answer?
Early Concepts
Early explorations focused on the chat interface itself, how to render tables inside a conversation, how to handle long responses, how to show loading states for queries that take time. But the bigger insight came from watching how analysts used responses: they immediately wanted to go deeper. The contextual panel, a side view that surfaces related findings, linked data, and direct navigation, emerged as the answer to that behavior.
AI integration acting as a static sidebar widget that merely invited user input, lacking a natural conversational flow.
What does the AI's output look like? It's just plain text with no data or tables, which doesn't add any value.
// Final Product
A conversational interface with inline tables, full system access, and a contextual panel, shipped and in production.
The assistant lets analysts ask questions in plain language and receive structured answers, summaries, inline tables, and contextual data pulled from across the entire platform. A contextual panel sits alongside the chat and surfaces related findings, linked assets, and navigation shortcuts based on what the assistant surfaces. The result is a single UI that replaces the multi-tab investigation flow entirely.
Chat interface
Natural language queries with structured responses, text summaries and inline tables
Inline table rendering
Tables built dynamically inside the conversation, sortable, scannable, linked
// Impact
Analysts can now get a full investigation view in one conversation, no tab switching, no filter hunting.
The assistant shipped and is actively used by SecOps teams. What previously required navigating across multiple views, cross-referencing detections, traffic data, asset context, and sensitive data findings, now happens in a single conversation. The time between question and actionable answer collapsed significantly.
1 UI
To query the entire platform, no prior knowledge of where data lives
Instant
Structured answers with related context, no navigation required
Shipped
In production and actively used by security analyst teams
Key Learning
AI in a security product isn't just a search upgrade, it's a new investigation paradigm. Design for the workflow, not just the query.
The contextual panel was as important as the chat itself, what surrounds an answer determines whether analysts can act on it.
Inline tables inside a conversation work when they're scoped and linked, a table that goes nowhere is just a list. A table that connects to the full view is a navigation shortcut.

