Alert Triage Agent/
Helping analysts respond faster to what matters most.
Data security analysts face hundreds of alerts a day. Alert fatigue and fragmented workflows make responding to real threats in real time nearly impossible.
I designed Alert Triage Agent to analyze, validate, and aggregate risk factors, leaving the analyst to do what they do best: Respond with human judgement.
What do you do when customers don't want AI-first, even when AI works?

We shipped a queue triaged entirely by an agent that outperformed existing methods, but customers weren't adopting it at the rate we expected. I rebuilt the experience around clearer entry points, a faster deployment flow, and a queue that let the agent work alongside existing risk signals.
This resulted in raising deployment completion from 23% to 44% and entry-point exposure 2.5x WoW.
Contact me for the full case study.


Purview Agents/ Scaling agentic workflows to more data security jobs.
Purview's first agent solved the reactive problem of alert fatigue, but customers were moving toward posture management, wanting agents that could prevent incidents before they happened.
I led a cross-disciplinary team scaling agents to five more agentic capabilities across Purview, guided by a Jobs-To-Be-Done framework I developed to decide which capabilities deserved to be an agent.
Is an agent a single task, a whole workflow, or something entirely new?



Five capabilities went live across two agents: secret remediation and activity narratives for Alert Triage Agent, and data discovery, SharePoint oversharing analysis, and credential search for the new Posture Agent.
It resulted in reduced deployment friction and gave marketing one coherent story to tell.
Contact me for the full case study.
Agentic Data Security/
Bridging natural language queries with agentic workflows.
Thousands of activity logs and data assets are generated across a tenant every day. It's a data security professional's job to make sense of all of it and protect what matters without slowing anyone down.
I prototyped five workflows that turn a natural-language query into an agent-driven security outcome, giving customers a trustworthy way into an entirely new kind of experience.

How do you get customers to try a new way of working after you've lost their trust?


Telemetry showed customers whose first AI experience was a bad chat interaction never tried another AI feature, so I designed toward a baseline chat good enough to rebuild that trust, entry points that met customers somewhere familiar, and a way to make one query feel like immediate progress, making the new agentic experience feel like continuing something already in motion.
This is currently in development, building on a chat foundation already proven successful in Intune.
Contact me for the full case study.
.gif)
.gif)









