Farhan Shaikh

Aurascape · UX Designer · 2025–Present · Synthetic data

Designing controls for AI you can't see

Aurascape is an AI-native security platform that gives enterprises visibility and control over every AI interaction — both the AI people use (commercial tools, embedded copilots, shadow AI nobody approved) and the AI people build (agents, MCP-connected systems, custom applications). It sits alongside existing SSE, CASB, and DLP tooling rather than replacing it. The buyers are security teams and CISOs, and their fears are concrete: sensitive data leaving through a prompt, an agent taking an action nobody authorized, or discovering a tool six months after the whole company adopted it.

I joined in 2025 as a UX designer, working across nearly every surface of the platform — and maintaining the design system underneath them all. The map below is the product's full navigation; the six accented areas are the ones this case study walks through. Every frame uses synthetic data.

Secure End Users

12
  • Boards
  • Overview
  • Apps & Users
  • Risks
  • Conversations
  • Policy
  • Access
  • Protection
  • Traffic Control
  • Conversation Data
  • Notification Templates
  • Reports

Secure Copilot

5
  • Boards
  • Copilot Readiness
  • Assets
  • Policy
  • Asset Labels

Secure Custom Agents

6
  • Conversations
  • Policy
  • Access
  • Protection
  • Conversation Data
  • Notification Templates

Secure MCP

8
  • Boards
  • MCP
  • MCP Explorer
  • Conversations
  • Policy
  • Access
  • Protection
  • Notification Templates

Secure AI Spend

6
  • Boards
  • Overview
  • AI Spend Management
  • Notifications
  • Settings
  • Notification Templates

Discovery

2
  • App Catalog
  • MCP Server Catalog

Settings

23
  • General
  • Client
  • Global Config
  • Client Profile
  • Profile Assignment
  • Client Updates
  • Users & Devices
  • Directories
  • Devices
  • Integrations
  • My Integrations
  • Integrations Catalog
  • Threat Prevention
  • Data Storage Config
  • Content Repositories
  • Data Security
  • Bring Your Own Key
  • Administrators
  • Audit Log
  • Copilot Readiness
  • Custom Agents
  • MCP
  • AI Configuration

Help

4
  • Documentation
  • Privacy Policy
  • Get Support
  • Feedback
The full platform at sidenav level — my work spans nearly every surface shown

featured in this case study

The six areas below follow the product the way an admin experiences it: first see what AI is already in the building, then watch how it's actually being used, then write the rules that govern it — and finally, manage who gets to do any of this.

App Catalog

It starts with inventory: every AI application the organization touches, cataloged, scored, and scannable at two densities.

App Catalog default view — the full AI application inventory as a dense, scannable table
Slim cards
App Catalog slim-card view — the same inventory at a denser reading level
Custom app creation
Creating a custom app entry for internal tools the catalog doesn't know yet

MCP Catalog

The same inventory discipline for the AI being built: MCP servers get their own catalog, with dashboards that extend the platform's existing visual language to a brand-new entity type.

MCP Catalog dashboard — usage, risk, and adoption metrics for MCP servers

MCP Explorer

Drilling into a single server: a five-column explorer for a surface that didn't exist a year ago — including deliberate empty states for every stage before there's any data to show.

MCP Explorer default view — five columns drilling from server to tool to call
First column empty
MCP Explorer with only the first column populated
All columns empty
MCP Explorer fully empty — designed before any data exists

Conversations

Then the live evidence: what employees actually say to AI and what comes back — every conversation a row, every detection tied to the exact span that triggered it, and sensitive values masked so reviewing risk doesn't re-expose it.

Conversations table, default view — every AI conversation in the org as a scannable activity ledger
View details
View Details panel expanded — drilling from a table row into the full conversation evidence
Pattern highlighting
Data-pattern highlighting on hover — the detection tied to the exact span in the conversation
Masking & redacting
Summary panel with masking and redaction applied — reviewing sensitive content without re-exposing it

Protection Policy

Seeing isn't controlling. Policy authoring turns what the catalogs and conversations reveal into rules — a scannable list of every active policy, and a single form that holds the full breadth of what a rule can do.

Protection policy list — every active rule as a full card with users, applications, data, and action at a glance
New policy — every option
New Protection Policy sidecar with every section expanded — applications, user criteria, data security, threat prevention, action, and notification in one form

Settings — Administrators

Finally, who runs all of this: administration with role-scoped permissions, where what an admin can see and change is shaped by the role they hold.

Administrators settings, super-admin default view
Invite — super admin
Invite admin sidecar for a super admin — full permission scope
Invite — limited role
Invite admin sidecar for a limited role — permissions scoped down

How this ships

Every surface above was handed to engineering as lanes of states — default, hover, click, error, empty — so what ships is the complete behavioral spec, not a single happy path. This is one section's full board.

Zoomed-out view of the Protection Policy board: five lanes of states — default, error, dropdowns, conditionals, tooltips — as handed off to engineering