Oasis Parcel is a pioneering privacy-first data governance tool providing Data-Protection-As-A-Service. Traditionally, data protection mechanisms have existed for larger enterprises in very coarse-grained forms. However, the Oasis Labs’ platform on which Parcel is built allows for fine-grained access controls that allow end-users, not only the service provider, to control of data created inside the system - empowering developers and service providers to build new kinds of secure and compliant infrastructure.
Currently, Parcel is still in Beta, but General Availability is expected soon. The Beta, however, is already used by numerous projects including the following customers: Nebula, The Music Fund, Castalise, Castalise, etc.
MY ROLE
Lead designer – discovery and ideation, lo-fi design exploration, interaction design and prototyping
TEAM
Naheed Vora, Product Manager Charlie Jacobson, Product Manager Nikhil Sharma, Full-stack Engineer Luka Jeran, Front-end Engineer Xi Zhang, Front-end Engineer
+ back-end engineers
To lead the Data-Protection-As-A-Service market with blockchain technology, we are building Oasis Parcel, a privacy-first data governance tool that isolates and protects your most sensitive data. Our goal is to empower developers and companies by helping them build secure and compliant infrastructure.
Parcel GA has been recently released, used by a few of our customers including Nebula, The Music Fund, Castalise, and many more.
MY ROLE
Lead and solo designer – discovery and ideation, lo-fi design exploration, interaction design and prototype
TEAM
Naheed Vora, Product Manager Charlie Jacobson, Product Manager Nikhil Sharma, Full-stack Engineer Luka Jeran, Front-end Engineer Xi Zhang, Front-end Engineer
+ many more back-end engineers ❤️
PROBLEM
From invasive ad targeting to massive data breaches, users are more concerned than ever with keeping their data private and secure. Parcel allows users to manage their data, increasing their trust and decreasing your liability and risk. Parcel provides a set of privacy-first, data governance APIs designed to give application users better control over how their data is used without sacrificing functionality. Using the Parcel suite of tools allows developers to securely store sensitive data, define and enforce usage policies over data, and share tamper-proof logs of access history with their users. The Parcel Portal is a web app that allows developers to setup their application and manage data usage on their application.
Often, organizations accumulate disparate collections of data that go unshared and under-utilized due to data privacy, access control, and general security concerns. Consequently, these emerging “data silos” hinder the ability for organizations to realize deep, actionable insights from data across individuals, departments, or other subgroups in an organization.
Parcel is designed to address this problem and help organizations derive greater value from their data with our blockchain enabled Parcel platform, which allows them to securely manage and share their data internally or externally.
We believed there was an opportunity to best utilize our unique decentralized blockchain network and technology. To prove this, we’ve conducted customer research and tested various hypotheses. Eventually, we narrowed down the scope and problem space we wished to focus.
“We want to give our users more control over their data in a way that it’s as least disruptive as possible. This is to differentiate our product since the data security market is emerging and the number of people concerned about their data is increasing.” — NEBULA GENOMICS
“Traditional security framework is insufficient. We'd like to make clear to our consumers that they don't need to worry about data security.” — HU.MAN.AI
“Pharma companies mount on a wealth of non-exploited data. Violating data privacy and patient consents collected during clinical trials could cost pharma companies millions of dollars in legal settlements.” — CASTALISE
H H H
Onboarding checklist
After sign-up, users are taken through our quick start guide that contains a checklist allowing them to easily understand what they can do in Parcel after they first land. We wanted to give them an ability to check or close each of these items once complete. It’s a basic tracking on “closing” of items. Often developer-facing products can be boring and formal but we wanted to add a few elements to welcome and engage new users.
Create my app
App creation is one of the most important flows of Parcel because this is where we need to make sure our developer users understand: • what they can create with Parcel, • what "permissions" are (one of the main features of Parcel), • how Parcel is related to Steward, • how their app info is going to be displayed to their end-users —an identity who grants their data to app developer— on Steward, • and how they need to tailor their app info for their end-users.
Permissions
Above is Parcel App Create flow where user can create permissions. Here, the user is creating 2 analysis permissions, ML and Genome analysis.
Steward users, once chose to manage their app data on Oasis blockchain network, can either allow or deny to each permission.
Above is the Parcel App Create flow where users can create permissions. Here, the user is creating 2 analysis permissions, ML and Genome analysis.
Steward users, once they have chosen to manage their app data on Oasis blockchain network, can either allow or deny to each permission.
My app page
My app page contains 3 sections respectively "Overview", "User data", and "Audit history". In "User data" section, you can find all user data that is uploaded to the app. "Audit history" is an unforgeable record of all accessed user data. As you see above, you can monitor all data that is either Genome analyzed or ML analyzed.
H H
USER DATA
A data table with all user dataset uploaded as to this app. Dataset is either permission granted or revoked.
AUDIT HISTORY
All data access activity history. Only app admin can view these logs on Parcel.
USER DATA
A data table with all user dataset uploaded as part of this app. Dataset is either permission granted or revoked.
AUDIT HISTORY
A single source of all data access activity history. Only app admin can view these logs.
RESEARCH
An extensive study on our customer research showed that there's a clear need for secure data sharing and management. A majority of our customers we'd talked to raised the issue of not being able to efficiently manage data, utilize sensitive data, anti-tamper data access history, etc.
Some of the main research takeaways: 1. Enterprises do not trust their partners when it comes to sharing sensitive data. 2. Restricting use of the data once shared is a necessary function for some enterprises to share data externally. 3. Enterprises are worried about insider threats from cloud provider platforms. 4. We can reduce time for multiple stakeholders to collaborate with sensitive data from 4 weeks to less than a week.
OPPORTUNITY
The opportunity for Parcel was specific: we could be a blockchain data management and sharing tool. Many of our customers wanted to share sensitive data without exposing it and track the history of data access. We prioritized a few key features that would be most valuable and feasible, that would make Parcel address the main user's pain points. • Ability to share and analyze data in a privacy-preserving environment. • User permissions (aka consents) to allow or deny data access and the status of user permissions. • Immutable audit record to track and monitor the status of all user data and actions taken. • Invite and collaborate with the team to manage the app and user data.
Exploration and iteration
Initially, I explored many different ways to help users understand the concept of Parcel and permissions while users create an app. My design consideration and iteration include layouts, features, and UIs such as a progress bar, a tooltip box, a modal dialog, permission preview, and permission templates. As part of my process, I weighed the pros and cons of my designs.
We want to support multiple permissions per app but this is technically not feasible in the time span we have. So we decided to support single permission per app at the moment.
(Considering we're only supporting single permission, it may seem appropriate to have "app info" and "permissions" sections in one page (because with single permission the whole page won't be heavy-weight). But I resorted to 2 separate sections because eventually we'll support multiple permissions in the future and also there's no engineering tradeoffs between these 2 ideas.)
APP CREATE FORM DESIGN
Throughout the project, requirements changed and new constraints were uncovered. From early on, I thought the permissions section should present enough information about what permission is, how it works, and how it'll be displayed to Steward end-users especially because it's not a widely known concept even in the tech domain. I explored variations of layouts, UIs, and features as you see below, to make the most intuitive UX for Parcel new users.
Permissions Interactions
Part of this project was also taking into consideration the entire permissions creating and reviewing experience. It can easily be a confusing feature considering it's not a familiar concept.
So it's critical to have UX/UI that has been carefully crafted to guide users into doing things, such as choosing permission templates, understanding use cases, and reviewing permission UI displayed on the Steward user side.
One of the biggest goals here was to prevent user churn and increase user understanding at the same time.
OUTCOME
This was a really exciting and fun project for me to work on as it provides real value, involved a ton of research, and detailed interaction work. However, shifting priorities and changing roadmaps have delayed the launch of this feature. Still, I learned some important takeaways from this project related to product and business processes.
Data security & privacy entails difficult UX problem
We're not designing an existing product that has been widely used by the public. We're not suggesting a better solution when there's already one. What we've been trying to build is something that we don't even know yet and there are no industry standards established yet for this kind of product – it's like there are so many promising paths in front of us but which path we are willing to take is really up to our decision and we're responsible for the result, whether we succeed or fail. It's been an obscure adventure for me, designing data privacy and security product and the main lesson I learned is that UX in this area requires extra thoughtful design. I needed to diversify my approach, not just the end-to-end product design but also granular UIs or micro-interactions.
I want to share some UX lessons I learned in this area:
1. Embrace inefficiency
Every designer knows the phrase, "Less is more". The underlying aim of this is to reduce the operational and cognitive costs of the users. Though, in the security and privacy realm, sometimes "More is more". Occasionally I need to make the screens or pages filled with extra information or extra steps that users really need for making decisions and feel safe. One of the design decisions I made was a loading page with a secured file transfer animation and a locked file visual to intentionally indicate the data process is being secured.
2. Let users control
We're living in an era where technology does more tasks than before. Industries are incorporating artificial intelligence (AI) to automate processes and improve efficiency, which often improves the user experience as well. But in the data security & privacy world, let's not think about this and give users more control. And of course, let's keep privacy as the default setting and let users take action or do tasks by themselves.
3. Privacy is less about copy.
Of course, it's still important to care about the tone and the voice of our product. It helps us keep the consistency within products. But I realized it doesn't influence much about how users feel safe and secure. Nothing would make a user want to not trust you than repeatedly saying “Trust us". So, show them rather than tell them, actions speak louder than words.
4. Familiarity in the user interface
Many studies have shown that more than 40% of global consumers don't trust online services to protect their data. It's not a time to explore how to make UIs interesting or fancy. It's rather a time to stick with the familiarity because the sense of familiarity gives the users confidence in completing a task. It's similar to e-commerce checkout experience. Users need to feel secure and comfortable either when dealing with money or their sensitive data and familiarity opens up a comfort zone.
Once again, I learned there's no immutable answer to UX problems, what you need as a UX-er is flexibility and openness, an attitude of learning new things, and the ability to break with tradition if necessary. Sometimes we should be brave enough to break the basic UX rules that are proven to work in other industries and come up with a new one that particularly works for your product.
AND MORE...
Parcel General Availability is expected soon! When it happens, it'll be time to :
• Actively gather user feedback, • Synthesize user feedback and translate it into design takeaways, • Re-prioritize work items that have been in our backlogs, • And make it more scalable, more multi-device friendly.