Security Hub — one place to see how protected you are
- Role
- Lead designer
- Platform
- iOS and Android
- Type
- White-label mobile banking
- Contributed
- IA strategy, competitive benchmarking, moderated usability testing, screen design, handoff
Context
Security controls in the app had accumulated across successive releases, each one placed wherever the feature that needed it happened to live. Device authorisation sat in one part of the app, card controls in another, notification and alert preferences somewhere else again.
In banking, a customer who cannot find their security controls tends to conclude they do not have any.
The design problem
How do you consolidate scattered controls into a single destination when the platform is multi-tenant — every institution enables a different subset of features, so the hub can never assume a fixed set of contents?
Approach
Competitive benchmarking
Audited how comparable banking and fintech apps structured their security surfaces — what they grouped together, what they named things, what they surfaced at the top level versus buried in settings. The useful finding was less about layout than vocabulary: institutions use wildly different words for the same control, and customers do not necessarily recognise any of them.
Information architecture
Defined the hub as five categories, grouped around what a customer is trying to accomplish rather than which back-end system owns the setting. Those two structures disagree more often than you would expect, and the system-shaped version is the one that tests badly.
Moderated usability testing
Ran moderated sessions with internal participants, using the prototype to test whether people could locate a named control and whether they understood what changing it would do.
Iterative screen design
Worked the mockups through successive rounds across all five categories, resolving the empty and partial states that the multi-tenant model makes unavoidable.
Constraints that shaped the design
- Multi-tenant configuration. Any category could arrive empty or partially populated depending on what the institution had enabled. The hub had to degrade without looking broken — no orphaned headings, no categories that open onto nothing.
- Design system. List rows carry no icons, so hierarchy and scannability had to come from grouping, labelling and spacing alone.
- Tooling. Prototyped in Adobe XD.