Farhan Shaikh

ARIA · UX Designer · 2026 · Synthetic data

Making AI risk legible to people who aren't AI experts

ARIA is a freemium B2B product that passively parses enterprise logs to surface AI risk — no agents, no proxies. That constraint is the product: nothing to deploy means no approval chain to wait on, and time-to-first-value is measured in minutes instead of quarters. The v3 prototype below is live — functional routing, realistic sample data, the full flow.

Landscape

I researched the adjacent players — Microsoft Defender for Cloud Apps, Skyhigh Security, Forcepoint ONE SSE. All of them assume deployment: agents on endpoints, traffic through proxies, gateways rewired. The gap was a tool that tells you where you stand before you install anything — and that gap is the product ARIA became.

The pitch — three steps, three minutes

The marketing site makes the promise the product has to keep: upload your logs, ARIA listens and scores, get a defensible risk report. No professional services, no onboarding.

Landing
ARIA landing page — 'Know which AI tools your team is using, before it becomes a liability'
The full front door
Full landing page — the three-step story from upload to score to report, with supported log sources

A dashboard that answers “am I okay?” first

The Risk Dashboard leads with one number — the Enterprise Risk Score — and why it moved, before anything else. Four finding tiles carry the headline counts (active AI users, unsanctioned apps, exfiltration sequences, autonomous agents); everything below is drill-down, not competition.

Risk Dashboard
ARIA Risk Dashboard — enterprise risk score of 72 with what changed and key finding tiles

A taxonomy people can hold in their head

Every AI tool ARIA detects is Sanctioned, Unsanctioned, or Inventory — three words an admin can defend in a meeting, instead of a scoring formula nobody remembers. The catalog makes the status the loudest column, and tagging an app sanctioned is how shadow IT officially stops being shadow.

AI App Catalog
AI App Catalog — every detected tool with risk score, users, and Sanctioned/Unsanctioned status
User Activity
User Activity — all active AI tool users ranked by combined usage and risk, with activity trends

Assessments you can trust because they don't move

ARIA's assessments are immutable: every run is preserved with its score, sources, and author — re-running produces a new assessment beside the old one, never a silent rewrite. The person who cited a report is never contradicted by the tool a week later, and the history itself becomes the risk-over-time story.

Reports — assessment history
Reports — the immutable assessment history with per-run risk scores, sources, authors, and status

Upload without fear

The new-assessment flow does the technical work itself: drag in CSV, JSON, NDJSON, or LOG files and ARIA auto-detects the source from filename and headers. The privacy posture is stated where the anxiety happens — raw logs stay on your network; only selected fields are sent.

New assessment
Create New Assessment — drag-and-drop log upload with automatic source detection and the privacy note in place