Omkar Khadamkar Signal Work with me

Security product designer

Let AI draw the screen. Never let it guess the risk.

AI acts. People decide. I design that moment, and I measure whether it works.

Choose a piece
Why

Two changes, one line that must not move

Both are good, as long as risk is never guessed and people keep the calls that matter.

1 AI builds the screens

What AI may generate

Layouts, charts, summaries, colours. They can change every time.

Three generated screens for one alert. Only the label stays the same.

What it must never guess

The words and colours that say how serious something is. Fixed, and the same on every screen.

  • Critical follows written rules, can't be dimmed
  • High needs attention soon
  • Needs attention no ranking yet
  • Resolved with the evidence attached

2 AI agents take actions

AI agents are becoming security's reflex. An agent can earn the right to act alone, one action at a time, like a promotion. It never earns the right to guess how serious something is. The design job is deciding what reaches a person, and when. One afternoon, made up but typical:

1 / 8
Three clocksThe same afternoon on three lanes, on a logarithmic time scale: the agent acts in under a second and within a minute; people decide within minutes; the law gives hours, with a 24-hour reporting deadline.AgentPeopleThe law1 s1 min1 h24 h24-hour deadlinetime since the click · log scale
  1. Person2:14:07 pm · the click

    An employee opens an invoice that isn't one.

    The link leads to a fake login page.

  2. Agent+0.2 seconds

    An AI agent blocks the page before it loads.

    The reflex, as it should be.

    What the employee sees

    This page was blocked. It looked like a fake login page. If it's a mistake, tell us in one click.

  3. Agent+40 seconds

    It finds the same email in 37 inboxes and pulls it back.

    Still reflex: routine, reversible and logged.

    What the incident responder sees

    High Phishing email · 37 inboxes · pulled back by rule · undo available

  4. Person+6 minutes

    An analyst checks the agent's work, and overrides one call.

    One was a real invoice. The agent was sure, and wrong. The screen shows why it decided, so the fix is one click.

    What the SOC analyst sees

    Needs attention 1 of 37 was pulled on the agent's own judgement, not a rule. Restore it?

  5. Person+19 minutes

    The agent wants to cut the laptop off the network. It waits for a person.

    It stops someone's work, so it needs a yes. The evidence is on screen, so the yes takes seconds.

    What the security lead sees

    Critical Rule R-114: a password was typed into a fake page. Isolate this laptop? Confirm or decline.

  6. The law+2 hours

    Did personal data leave? If so, a legal clock is already running.

    Laws like NIS2 give hours, not weeks. The clock and the evidence sit side by side.

    What the privacy officer sees

    High Early-warning deadline in 21 h 46 min · evidence pack ready

  7. The lawNext day

    The auditor signs off in minutes, not weeks.

    Every step above carried its evidence, so the record already exists.

    What the auditor sees

    Resolved 6 actions · 6 with evidence attached · 2 approved by people

  8. Your turn

    Machines took the fast steps. People took the ones that mattered.

    The agents' share keeps growing. The people's few calls must never get lost in it. Every screen above is a design decision.

3 Across the whole of a company's security

8 parts of a company × 9 decisions = 72 moments a person decides

Each dot is one screen where a person makes a call. Filled: the afternoon you just read. Hollow: the same moment elsewhere, still to be designed well.

Eight parts of a company's security by nine decisions a person makes. Use the arrow keys to move between cells; the panel below explains each one.
Parts of a company ↓ · Decisions →AuthorApproveOverrideExceptClassifyRespondNotifyAttestInterrupt
Endpointlaptops, phones and servers
Accesswho can reach which apps and websites
Datawhere sensitive data goes
Identitywho each person and AI agent is
Exposureweak spots, before attackers find them
Detectionspotting and stopping attacks
AIthe company's own AI agents and models
Governanceproving it to auditors, boards and regulators
Detection × Override

Someone disagrees with the AI about an attack alert.

in the afternoon abovethe same moment elsewherein products I've shippedPoint at, tap or arrow to any dot.
Now · work

The work, with its limits

Each links to its method, including results that went against me.

Work with me

Work with me

For founders and CTOs of security vendors. Start with a fixed-price pilot, then keep going if it works.

Pune, your time zone · Security UX since 2020 · Patent pending, US 2025/0036264

Start here · the pilot

Understand, redesign, prove

  1. Understand: the five issues that matter most, ranked.
  2. Redesign: a clickable prototype.
  3. Prove and hand over: three to five real users try the prototype on real tasks; dev-ready spec and design tokens your tooling can read.

Length and fixed price set after a first call, to fit your scope · 50% on acceptance, 50% on handover

How the pilot works
Next

What I'm learning in the open

Unfinished questions, shared early. Nothing here is for sale yet.

  • Rev 02

    AI drift, the field notes

    AI-generated UI looks finished long before it is correct. These are field notes on the difference — four ways it goes wrong, and a fix for each.

  • Exploring

    Letting an agent act alone

    The screen where a security lead decides which actions an AI agent may take without asking first, based on its track record.

  • Exploring · future add-on

    When another AI asks your product

    An engineer's AI agent will ask your product questions directly, with no screen at all. Its answers are a design job too.

  • Forming

    Analyst Circle

    Monthly sessions where security analysts, the people who investigate alerts, react to prototypes before vendors ship them.

  • Live · issue 1

    Signal, the public edition

    A short brief on how security products are designed, across all eight areas, with sources.

  • Sketching

    The block page nobody designs

    Most people meet security as an interruption: a blocked website, a data-leak warning, a forced re-login. It's the most-seen security screen and the least designed.

Later

Where security software is heading

Forecasts, with how sure I am. I'll score them in public as they resolve.

By 2029, AI agents do most of the work inside security products. The scarce skill is designing where a person reviews, overrides and audits them.

Hypothesis · being tested Evidence so far

Two forces are already pushing it there.

1 The areas are merging

In the grid above, Access, Data and Identity are separate rows. Inside real products they overlap, and the hardest calls sit where they do. No single product owns them, so no single team designs them.

Already visible: vendors are merging detection, data and access tools into one console. The screens between products are where the next design work is. Evidence so far

2 Laws now set the clock

  1. NIS2 (EU)24 h · 72 h · 1 month

    Early warning, notification, final report. Applies as each country writes it into law. source

  2. EU Cyber Resilience Act24 h

    Makers warn early on an actively exploited weakness. source

  3. India DPDP

    Consent managers begin: one year after notification on 13 Nov 2025. source

  4. India DPDP

    Most duties, including breach reporting: eighteen months after notification on 13 Nov 2025.

Each deadline is a screen someone has to use under pressure. Summaries, not legal advice. Evidence so far
Signal

What moved this fortnight

A fortnightly brief on security product design across the whole estate. Three recent items below. Issue 1 is out on LinkedIn.

  • Microsoft Learn (source)

    Microsoft previews an integrated SOC in Defender: XDR, SIEM and AI in one portal, so one case can mix native and ingested evidence.

    DetectionOverrideAnalyst

  • Futurum (source)

    Wiz extends its partner network with MCP-powered agent integrations: a product's answer to another company's agent is now a design surface.

    AI agentsAuthorFounder

  • Help Net Security (source)

    Sophos: 46% of MSPs say customers rely on them to act as their CISO, and 55% still do part of their security reporting by hand.

    GovernanceAttestMSP

Read Signal #1: Who checks the agent?