Case Study · Secure Share
Designing a safer way for enterprise teams to share Confluence pages outside their organization without losing admin control.
Context
Enterprise teams keep important knowledge in Confluence and regularly need to share selected pages outside the organization. Without a secure path, users export, copy, or screenshot content and admins lose visibility. The real problem was balancing speed for users with expiry, revocation, and audit control for admins.
When secure sharing feels slower than an unsafe workaround, users avoid the secure path. The experience had to make the safe action feel like the easiest action.
Confidentiality and proof note
Due to NDA restrictions, this case study uses white-labelled recreations, anonymized impact themes, and outcome summaries instead of live screens or account data. The product logic and design decisions are preserved.
Why
Two audiences with opposite priorities. Rather than force both into one heavy interface, the design split their responsibilities, and that split was the core bet.
Shared principle
Fast for users, governed for administrators.
The split was not a guess. Several independent signals pointed the same way: users wanted the share action to stay fast and obvious, while admins wanted expiry, access control, revocation, and audit visibility to live in a policy layer they owned.
Converges to
Balancing speed and control
The end-user flow stayed on the basic job of creating a protected link, while expiry, access restrictions, revocation, and visibility lived in the admin experience.
Common sharing actions inherit safe rules automatically, so advanced options stay available without interrupting every share.
Knowing what was shared, who created it, when access expires, and whether it can be revoked carried as much weight as link generation itself.
Users handle the share action; admin policy defines the rules. Flip a policy switch and watch the sharing outcome rewrite itself.
Q4 Partner Rollout Plan
Confluence page · shared by a user
Share with
Admin policy
The user never sees these decisions. The share inherits them.
Sharing outcome
Secure link ready. The external collaborator can view the latest version of this Confluence page without needing a Confluence license. Access is password-protected. The link expires in 7 days. An admin can revoke access at any time. Viewing activity is logged for audit visibility. The shared page carries the workspace brand.
Without SecureShare
With SecureShare
The interaction looks simple on purpose. The design work was deciding which complexity belonged to users and which complexity belonged to policy.
Ownership
The team was small: a product manager, an engineering team, and design. I led the product design direction, and working with product and engineering I drove the separation of the everyday share flow from the admin policy layer, so the product stayed flexible without pushing security decisions onto every user.
Impact
The revamp reshaped external sharing for both sides: a fast protected path for users, inherited control for admins, and a clearer story for buyers during evaluation.
Before
After
The product story became easier to explain around secure external sharing, protected links, expiry, revocation, and admin visibility.
The experience gave admins clearer control over how shared content could be accessed, managed, expired, and revoked.
The marketplace-facing narrative was improved to communicate business value faster during evaluation.
Judgment
Security UX is not about showing more controls, it is about placing control at the right level: safe defaults for users, visibility and recovery for admins. The harder call was positioning. I pushed to frame the product around control rather than sharing, which changed both the product UX and how we told the story during evaluation.
Next Project
OAuth/OIDC SSO for Atlassian Data Center →