PlexTrac is an industry-leading penetration testing and reporting platform for red, blue, and purple team collaboration. Over the course of 18 months I led the end-to-end redesign and expansion of its user management system across multiple efforts from the user list landing page to entirely new product features including user details, user groups, and an audit log through an extensive user research-driven workflow.
Research began in December 2022 with a broad audit of the existing UI and internal brainstorming based on accumulated client feedback. This was followed by multiple rounds of user interviews across three customer segments: SSPs, MSSPs, and Enterprise, to hear firsthand about their existing pain points, frustrations, and desired features. A second, more focused round of interviews was conducted in Q3 2023 as scope expanded to include additional features.
Smaller, focused firms helping clients with specific aspects of their security infrastructure. Prioritized an intuitive overall experience above all else.
Larger firms offering a full suite of managed security services. Vocal about the need for user groups and bulk authorization workflows.
Large corporations with internal security operations. Focused on RBAC improvements, advanced permissions, and scalable user setup workflows.
"User management has been the biggest pain point we've had with the platform... We have well over a thousand people in there right now, we don't know when people leave, we've got potential security violations, it's just horrible."
— Morgan, SSP
"User group should be something that you are assigned to, and then authorized to multiple projects."
— Joey, MSSP
"Like playing a game of whack a mole, which roles give access to do what?"
— Drew, Enterprise
"After I add this person, set role, then I have to go into clients, add them to this client, then the next client... It's time consuming, that's a lot of steps just to add a new user."
— Steve, Enterprise
The legacy user list was built by a single developer before PlexTrac had a dedicated design team. It featured horizontal and vertical scrolling, an awkward workflow, and didn't match the design system used elsewhere across the platform. Research made it clear this was the highest-priority pain point. After presenting findings to leadership, interim improvements were approved to address the most critical issues ahead of the larger User Groups initiative.

The original interface ran on a large table with both horizontal and vertical scrolling. Actions were buried and inconsistent, the authentication column was disconnected from the rest of the workflow, and the overall visual language was out of step with the rest of the platform.

The redesign standardized the table to match platform-wide component styles, introduced a reactive contextual actions menu, and added an authentication method column. Certain actions are now contextual and surface only when relevant to the user's current state (locked, MFA enabled, disabled, etc.).




Bulk actions were already a pattern elsewhere in the platform but had never been applied to user management. Selecting multiple users reveals a bulk actions dropdown mirroring the individual user actions: edit authorizations, change authentication, reset password, disable, delete, unlock, and enable, saving administrators significant time on repetitive tasks.


Disabled user rows are visually grayed out with a status flag in the user flags column. Locked accounts, triggered after 5 failed login attempts, are highlighted in the table to draw immediate administrator attention. Both states are filterable from the user list.


While PlexTrac has always offered multiple methods for organizations to require multi-factor authentication, that functionality was limited in scope and unintuitive to manage. As part of the redesign we cleaned up the workflow for changing a user's authentication method, moving it into the actions column, and added a dedicated authentication method column to the table so an account's setup is visible at a glance. We also gave administrators the ability to disable a user's MFA directly, a highly requested action that previously forced them to turn MFA off for the entire environment just to reset a single user.

Before this feature, the only way to manage a user's client access was to navigate to each individual client page and add or remove them one at a time. For organizations managing hundreds of clients and users, this was painfully slow and often fell to high-seniority staff because of the sensitivity of the work. This initiative introduced a user details side drawer, accessible directly from the user list, consolidating basic user information and full authorization management in a single place.


The user details tab pulls everything an administrator might need to do to a single user into one place. The upper section holds basic information such as first name, last name, email, and metadata like user ID and last login, while the lower section gathers every account action that used to live scattered in the actions column: change authentication provider, disable MFA, reset password, unlock, disable or enable, and delete. Consequential actions confirm before they run and report back once they finish. For example, changing a user's authentication provider is shown below, selecting a new provider from the dropdown, confirming the change, and the success notification that follows.



The authorizations tab is where a user's client access lives, every client they can reach and their role for each one. An administrator can select any number of clients at once and change their role in a single action, rather than opening each client one at a time. This flips the whole authorization model from "manage access per client" to "manage access per user." With clients selected, the Actions menu drives the rest. Choose Change client role, pick the new role, confirm, and the update applies to every selected client at once.






Below is a functional prototype of the user details and authorization side drawer. Try it out!
User Groups was the largest net-new feature in the user management project, a long-standing request from enterprise and MSSP customers who needed a way to manage clusters of users collectively. The use case centered on large organizations wanting to group users by division, team, or role, and assign shared client authorizations to the entire group at once. It was designed with a 3-step creation wizard, full group management capabilities, and deep integration with the existing user creation and client authorization workflows with the groups list itself living on a new tab of the expanded Users & Groups page in the Administrator Dashboard.

Creating a new group opens a wizard that walks administrators through three steps: adding users, selecting authorizations, and finalizing the group with a name and confirmation.
Existing groups can be edited or deleted from the groups list, with bulk selection and deletion supported. Users can also be added to a group from their user details side drawer, and from the client details page, administrators can now authorize users or groups together in a single updated workflow.



Below is a functional prototype of the user groups creation and management flow. Try it out!
As PlexTrac's enterprise client base grew, the need for a dedicated audit log became a compliance and security obligation. This was a net new feature designed in multiple phases starting with an MVP focused on security-related user actions, followed by a fast follow for robust filtering, search, and export, with future phases planned for expanded event tracking.

The MVP audit log tracks five categories of security-relevant events: login attempts and related activity, password change events, user account actions (create, disable, delete, unlock), roles-based access and permissions changes, and authorization events. Each entry surfaces the user's identifier, the event type, and a timestamp.
The audit log can be filtered by date range, showing only events between two selected dates. This compounds with a search bar that filters by user name, email, or specific event type, letting administrators drill down precisely during any audit or security investigation.

Data in the audit log is archived to an external database after 90 days. For data still within the active window, administrators can export the current filtered results as a CSV scoped exactly to whatever date range and search criteria are active at the time of export.


Have a project or role in mind? I'd love to hear from you.




