Gemini for data protection

Early AI experiences for Cloud data protection

ROLE

Lead UX Designer

TIMELINE

2024

PROJECT SKILLS

AI, Strategy/ visioning, Systems thinking

01 - OVERVIEW

Defining early Gemini-powered experiences for complex Cloud data protection on an accelerated timeline

I worked on early stage AI capabilities for Cloud data protection, which later evolved into Gemini Cloud Assist. Trusted Infrastructure, a suite of data protection products and services which I led UX for, was identified as a high-impact area for early AI integration due to the sensitivity and complexity of security workflows. This effort was part of a high-priority horizontal initiative with a deliverable timeline aligned to Google Next. We had two months to define and deliver a private preview experience while the underlying Gemini platform was still evolving.

I worked directly with our director and a product manager, who was also a backend engineer, to conceptualize the experience from scratch.

Because I was moved to another high-priority project after launching this project’s private preview, my impact was measured less as traditional metrics (i.e. long-term adoption) and moreso as establishing the foundation for future AI experiences. I:

IMPACT
  • Led design and delivered private preview launch for three 0→ 1 foundational Gemini workflows across 3 Cloud data protection products in 2 month timeline aligned to Google Next conference that solved areas of friction within our current experiences

  • Created reusable golden prompt taxonomy that standardized responses from disparate data sources dependent on user intent

  • Helped craft Platform Security Gemini story across Cloud Security for VP/ GM script at Google Next conference

  • Defined long-term Gemini roadmap for data protection workflows

Define foundational Gemini experiences for Cloud data protection by identifying and delivering design solutions for high-value AI-assisted journeys ahead of Google Next private preview

GOAL
02 - SOLUTIONS

I delivered 3 foundational early AI flows across the Trusted Infrastructure portfolio. However, for the sake of this case study, we will focus on the Confidential Computing solution.

CONFIDENTIAL COMPUTING ASSISTANT

Lowered barrier to adopting Confidential Computing with increased awareness and understanding

03 - PHASE I APPROACH

UNDERSTANDING THE TECHNOLOGY

Google Cloud Assist as a collaborative AI assistant

To get up to speed quickly, I immersed myself in PRDs and technical documentation to understand the current capabilities and technical boundaries. I also participated in weekly, Cloud-wide Gemini working sessions focused on knowledge sharing and early ideation.

At this stage, Gemini functioned primarily as a collaborative AI assistant, i.e. supporting design, operations, troubleshooting, and cost optimization. Given the maturity of the technology, I identified two high-level jobs to be done within our space: (1) help users correctly configure data protection, and (2) reduce friction in complex security workflows.

Cloud data protection workflows are complex. Configuring an organization’s security posture often requires awareness and understanding, which the users who are primarily focused on shipping features, not configuring protection correctly.

This made it a strong opportunity for Gemini to act as a contextual guide—helping users make informed decisions in the moment and reducing the cognitive burden of complex security workflows.

OPPORTUNITY
IDENTIFYING CRUCIAL USER JOURNEYS

Identifying high-value areas for AI contextual guidance

Because we needed to move quickly, we didn’t have time for full-scale foundational research. I focused on quickly identifying where AI could provide meaningful value by auditing and identifying high-friction decision points within Trusted Infrastructure workflows by looking back in past research and speaking to sales representatives and product managers who speak with customers regularly. We identified three core journey areas:

APPROACH

We validated these core journeys with our director and a UXR who used to work in the space. For the sake of this case study, we will focus on the Confidential Computing solution although the design process was the same across all journeys.

04 - GOLDEN PROMPTS

Defined persona-driven golden prompts to ensure consistent, safe Gemini responses across key journeys

After defining the critical user journeys, we were asked to develop “golden prompts” which are predefined prompt responses designed to produce consistent Gemini responses. For common, predictable questions, we authored curated, hard-coded responses that served as a first line of support before the system queried backend data sources.

To create these, I partnered closely with the PM to identify which personas would interact with Gemini through each journey and anticipate the types of questions they would ask. This helped ensure the prompts were grounded in real user intent and aligned with common tasks.

Created a reusable prompt taxonomy to standardize Gemini responses across data sources

RESPONSE TAXONOMY

To ensure consistency across disparate data sources, I created a reusable prompt taxonomy that mapped common user intents to standardized Gemini response structures. This taxonomy defined how prompts should be framed, what context should be included, and how answers should be formatted, regardless of the underlying source. Over time, this structure helped the LLM better interpret intent, route questions appropriately, and generate answers that were aligned in tone, depth, and actionability across different entry points.

This taxonomy, of course, would be scalable and updated with new technologies and advancements such as context-aware responses or multi-turn conversations.

DEFINING THE EXPERIENCE

Using guiding principles to shape the experience

I formed guiding design principles from feedback and best practices.

  • Actionable guidance, not just explanation - We made sure that guidance was useful and actionable, while differentiating these insights from tooltips.

  • Transparency to build user trust - Due to the complex nature of the security area, we had to ensure that we had user’s trust with our responses. We made sure to add our sources or reasoning for responses.

  • Progressive disclosure for complexity - To ensure users had a digestible response, we gave concise responses where users could continue multi-turn conversations to explore a single topic in more depth.

  • Helpful instead of overwhelming - We intentionally limited entry points to high-value moments in the user journey to avoid overuse and ensure they remained meaningful and effective. Because many of our user journeys lived in other team’s UIs, we had to ensure that our experiences did not clash with new AI components on those pages.

Applied standardized Gemini patterns to integrate AI consistently across data protection workflows

DEFINING THE INTERACTION

The horizontal Gemini team introduced a set of standardized design system components tailored for different AI interaction scenarios which supported a different level of user intent, such as passive guidance, informational responses, contextual insights, and actionable recommendations.

Drove cross-Cloud alignment by sharing Trusted Infrastructure patterns and iterating on feedback

CROSS-CLOUD ALIGNMENT

Given the rapid pace and parallel cross-org workstreams, we held weekly GCP Gemini UX syncs to share learnings and align on emerging patterns across Cloud. These were critical for maintaining a cohesive experience, since multiple teams were designing simultaneously with evolving guidance.

I used these forums to present the Trusted Infrastructure interaction patterns, including our prompt structures, response formatting, and entry-point behaviors. This created an opportunity to gather early feedback, validate alignment with broader Cloud direction, and refine our approach based on patterns emerging from adjacent teams.

For example, during one of the iterations, I was given the feedback that perhaps I should make some of the interactions more actionable as I could be using a tooltip for the kinds of information I added into the Gemini component. I quickly pivoted afterwards.

ADVANCING TECHNOLOGY

Iterating due to quickly advancing technology and capabilities

01 - BASIC

General, informative response crafted from aggregate data sources

Ability for users to explore concepts in more depth, asking follow-up questions due to the system remembering conversation history

02 - MULTI-TURN
03 - CONTEXT-AWARE

Personalized responses based on who the user is and their environmental needs

GOOGLE NEXT

Shaped the Gemini security narrative for Google Next through cross-product demos and executive messaging

We delivered these experiences as a private preview announced at Google Next 2024. As a subject-matter expert for the Trusted Infrastructure space, I worked with 3 other lead designers in other Cloud Security spaces to shape the Platform Security and Compliance Gemini story for Next ’24, contributing to key VP and GM scripts. We not only created demo storylines and screens, but crafted messaging for cross-product positioning.

Defined the long-term vision for Gemini in data protection

ONE-YEAR VISION & ROADMAP

After the private preview launch, I facilitated lightweight brainstorming sessions (due to limited eng bandwidth) with cross-functional partners to define long-term Gemini opportunities. With a new onboarded team which included a new Product Manager and Back-end Tech Lead, we discussed where the technological capabilities where going, identified areas of friction and opportunity within Trusted Infrastructure, and ideated on solutions and prioritized near vs long-term capabilities.

The result of the sessions was to evolve our capabilities to be a proactive security partner for Cloud Admins by focusing on context-aware guidance, automated compliance, and agentic capabilities. We prioritized features that personalize and optimize the data protection experience based on what we know about the user, as well as how to accelerate the deployment of secure, standard-aligned cloud architectures (such as in horizontal initiatives such as App Design Center).

LOOKING BACK
NEXT STEPS

After the Google Next milestone and private preview launches, I was moved to another high-priority project but as the new team turned over, an L6 PM gave the feedback that my work was “foundational to their vision and next launches”.

If we had more time, I would have loved to be able to do more foundational user research to understand gaps within the Trusted Infrastructure program holistically during our discovery phase to validate our direction.

WHAT I’D DO DIFFERENTLY