Gemini for data protection
Early AI experiences for Cloud data protection
ROLE
Lead UX Designer
TIMELINE
2024
PROJECT SKILLS
AI, Strategy/ visioning, Systems thinking
01 - OVERVIEWDefining early Gemini-powered experiences for complex Cloud data protection on an accelerated timeline
I worked on early stage AI capabilities for Cloud data protection, which later evolved into Gemini Cloud Assist. Trusted Infrastructure, a suite of data protection products and services which I led UX for, was identified as a high-impact area for early AI integration due to the sensitivity and complexity of security workflows. This effort was part of a high-priority horizontal initiative with a deliverable timeline aligned to Google Next. We had two months to define and deliver a private preview experience while the underlying Gemini platform was still evolving.
I worked directly with our director and a product manager, who was also a backend engineer, to conceptualize the experience from scratch.
Because I was moved to another high-priority project after launching this project’s private preview, my impact was measured less as traditional metrics (i.e. long-term adoption) and moreso as establishing the foundation for future AI experiences. I:
IMPACTLed design and delivered private preview launch for three 0→ 1 foundational Gemini workflows across 3 Cloud data protection products in 2 month timeline aligned to Google Next conference that solved areas of friction within our current experiences
Created reusable golden prompt taxonomy that standardized responses from disparate data sources dependent on user intent
Helped craft Platform Security Gemini story across Cloud Security for VP/ GM script at Google Next conference
Defined long-term Gemini roadmap for data protection workflows
Define foundational Gemini experiences for Cloud data protection by identifying and delivering design solutions for high-value AI-assisted journeys ahead of Google Next private preview
GOAL02 - SOLUTIONSI delivered 3 foundational early AI flows across the Trusted Infrastructure portfolio. However, for the sake of this case study, we will focus on the Confidential Computing solution.
CONFIDENTIAL COMPUTING ASSISTANTLowered barrier to adopting Confidential Computing with increased awareness and understanding
03 - PHASE I APPROACHUNDERSTANDING THE TECHNOLOGYGoogle Cloud Assist as a collaborative AI assistant
To get up to speed quickly, I immersed myself in PRDs and technical documentation to understand the current capabilities and technical boundaries. I also participated in weekly, Cloud-wide Gemini working sessions focused on knowledge sharing and early ideation.
At this stage, Gemini functioned primarily as a collaborative AI assistant, i.e. supporting design, operations, troubleshooting, and cost optimization. Given the maturity of the technology, I identified two high-level jobs to be done within our space: (1) help users correctly configure data protection, and (2) reduce friction in complex security workflows.
Cloud data protection workflows are complex. Configuring an organization’s security posture often requires awareness and understanding, which the users who are primarily focused on shipping features, not configuring protection correctly.
This made it a strong opportunity for Gemini to act as a contextual guide—helping users make informed decisions in the moment and reducing the cognitive burden of complex security workflows.
OPPORTUNITYIDENTIFYING CRUCIAL USER JOURNEYSIdentifying high-value areas for AI contextual guidance
Because we needed to move quickly, we didn’t have time for full-scale foundational research. I focused on quickly identifying where AI could provide meaningful value by auditing and identifying high-friction decision points within Trusted Infrastructure workflows by looking back in past research and speaking to sales representatives and product managers who speak with customers regularly. We identified three core journey areas:
APPROACH
We validated these core journeys with our director and a UXR who used to work in the space. For the sake of this case study, we will focus on the Confidential Computing solution although the design process was the same across all journeys.
04 - GOLDEN PROMPTSDefined persona-driven golden prompts to ensure consistent, safe Gemini responses across key journeys
After defining the critical user journeys, we were asked to develop “golden prompts” which are predefined prompt responses designed to produce consistent Gemini responses. For common, predictable questions, we authored curated, hard-coded responses that served as a first line of support before the system queried backend data sources.
To create these, I partnered closely with the PM to identify which personas would interact with Gemini through each journey and anticipate the types of questions they would ask. This helped ensure the prompts were grounded in real user intent and aligned with common tasks.
Created a reusable prompt taxonomy to standardize Gemini responses across data sources
RESPONSE TAXONOMYTo ensure consistency across disparate data sources, I created a reusable prompt taxonomy that mapped common user intents to standardized Gemini response structures. This taxonomy defined how prompts should be framed, what context should be included, and how answers should be formatted, regardless of the underlying source. Over time, this structure helped the LLM better interpret intent, route questions appropriately, and generate answers that were aligned in tone, depth, and actionability across different entry points.
This taxonomy, of course, would be scalable and updated with new technologies and advancements such as context-aware responses or multi-turn conversations.
DEFINING THE EXPERIENCEUsing guiding principles to shape the experience
I formed guiding design principles from feedback and best practices.
Actionable guidance, not just explanation - We made sure that guidance was useful and actionable, while differentiating these insights from tooltips.
Transparency to build user trust - Due to the complex nature of the security area, we had to ensure that we had user’s trust with our responses. We made sure to add our sources or reasoning for responses.
Progressive disclosure for complexity - To ensure users had a digestible response, we gave concise responses where users could continue multi-turn conversations to explore a single topic in more depth.
Helpful instead of overwhelming - We intentionally limited entry points to high-value moments in the user journey to avoid overuse and ensure they remained meaningful and effective. Because many of our user journeys lived in other team’s UIs, we had to ensure that our experiences did not clash with new AI components on those pages.
Applied standardized Gemini patterns to integrate AI consistently across data protection workflows
DEFINING THE INTERACTIONThe horizontal Gemini team introduced a set of standardized design system components tailored for different AI interaction scenarios which supported a different level of user intent, such as passive guidance, informational responses, contextual insights, and actionable recommendations.
Drove cross-Cloud alignment by sharing Trusted Infrastructure patterns and iterating on feedback
CROSS-CLOUD ALIGNMENTGiven the rapid pace and parallel cross-org workstreams, we held weekly GCP Gemini UX syncs to share learnings and align on emerging patterns across Cloud. These were critical for maintaining a cohesive experience, since multiple teams were designing simultaneously with evolving guidance.
I used these forums to present the Trusted Infrastructure interaction patterns, including our prompt structures, response formatting, and entry-point behaviors. This created an opportunity to gather early feedback, validate alignment with broader Cloud direction, and refine our approach based on patterns emerging from adjacent teams.
For example, during one of the iterations, I was given the feedback that perhaps I should make some of the interactions more actionable as I could be using a tooltip for the kinds of information I added into the Gemini component. I quickly pivoted afterwards.
ADVANCING TECHNOLOGYIterating due to quickly advancing technology and capabilities
01 - BASICGeneral, informative response crafted from aggregate data sources
Ability for users to explore concepts in more depth, asking follow-up questions due to the system remembering conversation history
02 - MULTI-TURN
03 - CONTEXT-AWAREPersonalized responses based on who the user is and their environmental needs
GOOGLE NEXTShaped the Gemini security narrative for Google Next through cross-product demos and executive messaging
We delivered these experiences as a private preview announced at Google Next 2024. As a subject-matter expert for the Trusted Infrastructure space, I worked with 3 other lead designers in other Cloud Security spaces to shape the Platform Security and Compliance Gemini story for Next ’24, contributing to key VP and GM scripts. We not only created demo storylines and screens, but crafted messaging for cross-product positioning.
Defined the long-term vision for Gemini in data protection
ONE-YEAR VISION & ROADMAPAfter the private preview launch, I facilitated lightweight brainstorming sessions (due to limited eng bandwidth) with cross-functional partners to define long-term Gemini opportunities. With a new onboarded team which included a new Product Manager and Back-end Tech Lead, we discussed where the technological capabilities where going, identified areas of friction and opportunity within Trusted Infrastructure, and ideated on solutions and prioritized near vs long-term capabilities.
The result of the sessions was to evolve our capabilities to be a proactive security partner for Cloud Admins by focusing on context-aware guidance, automated compliance, and agentic capabilities. We prioritized features that personalize and optimize the data protection experience based on what we know about the user, as well as how to accelerate the deployment of secure, standard-aligned cloud architectures (such as in horizontal initiatives such as App Design Center).
LOOKING BACKNEXT STEPSAfter the Google Next milestone and private preview launches, I was moved to another high-priority project but as the new team turned over, an L6 PM gave the feedback that my work was “foundational to their vision and next launches”.
If we had more time, I would have loved to be able to do more foundational user research to understand gaps within the Trusted Infrastructure program holistically during our discovery phase to validate our direction.
WHAT I’D DO DIFFERENTLY