2024 – Present · Microsoft Purview
2024 – Present · Microsoft Purview
Microsoft Purview · Data Security Posture Management for AI · Microsoft Ignite 2025
The Problem
By 2024, enterprise data security had fundamentally changed. AI agents — Copilot instances, third-party bots, automated pipelines — were proliferating faster than security teams could track them. Purview already had a strong data governance foundation, but AI agents were a genuinely new kind of object: not quite a user, not quite an application, capable of touching sensitive data across dozens of systems in ways no existing entity type accounted for.
When something went wrong — an agent oversharing a sensitive file, an agent quietly exfiltrating data through a connected tool — security teams had almost no way to reconstruct what actually happened. The tool had a visibility problem and an accountability problem at once.
My Role
I collaborated with another designer on the team on a proposal to bring Purview into the AI governance space. Across the platform, I focused specifically on the Agent Details experience — the page dedicated to a single AI agent, showing its scope of access, who and what it interacts with, and a full step-by-step trail of its recent flagged interactions. Our PMs brought us into the conversation early, while they were still compiling customer pain points, so we were converting raw findings into ideas and explorations from the start rather than being handed a finished spec.
Origin
Research/input. We started from a very basic premise: simplify AI governance by making Purview's existing data more understandable in the AI context, and give security teams real visibility into which agents and AI tools were actually in use across their org.
Insight. Purview already had a lot of the right signals in place — the relevant data was mostly already being captured. It just wasn't being served effectively for a security admin trying to reason about an agent's behaviour. The gap wasn't data collection, it was presentation.
Decision. Agent activities took that hypothesis further: rather than stop at inventory-level visibility (which agents exist, what's their risk score), we proposed going down to the most granular level — the individual steps an agent took inside a specific flagged interaction. The goal I was designing toward was full accountability for every agent, and no guesswork when investigating a security incident.
Design Process
A large part of this work was mapping how views related to each other before any single screen was finalised — deliberately separating "Build view" (how an agent is configured — its knowledge sources, tools, connected agents) from "Runtime" (what the agent actually did during a specific interaction), since conflating configuration with behaviour was an early source of confusion. We also had to decide how alerts, activities, and individual events related to each other structurally — settling on alerts being specific to an agent rather than grouped generically by alert type, so an admin investigating one agent could see everything relevant to it in one place.
The graph-and-drawer pattern that became the centre of the Agent Details experience went through many iterations — different ways of representing an agent's connections (users, knowledge sources, tools, other agents) as a navigable map, paired with a side drawer that could drill from a high-level activity down into individual steps.
Structural mapping, early on — deciding how Build view and Runtime should relate, how alerts/activities/events should be structured, and reviewing reference material (including a competitor tool walkthrough) before committing to a direction.
Iterating on the graph-and-drawer pattern — testing how the agent connection map (users, knowledge sources, tools, agents) paired with a drill-down drawer across several different states and data densities.
The Agent Details Experience
Agent Overview. Every agent gets a dedicated page: its status, access scope, owner, and the knowledge sources and tools it's connected to, alongside a risk level and a sensitive-activity trend over time. The intent was that a security admin could land here and immediately understand whether this specific agent needed attention, without cross-referencing three other tools first.
The shipped Agent Overview page — access scope, owner, connected knowledge sources and tools, risk level, and a sensitive-activity trend, with recommended next actions surfaced directly on the page.
Outcome
DSPM for AI was announced at Microsoft Ignite 2025, positioning Purview to govern AI agents alongside traditional data assets. Much of what's next in this space is still in progress and not yet public, but the direction set by this proposal — agent-level accountability, down to the individual step of a flagged interaction — carried through into what shipped.