Enterprise · Security & Compliance · Research & Strategy · 0-1

Document Discovery: search and audit across an org

A security and compliance foundation that grew into a multi-million dollar add-on.

Project Overview

As enterprise customers stored more sensitive IP in Lucid, they needed stronger data governance and compliance tooling to adopt and expand with confidence. But admins had no visibility into the documents their users created or the content across their workspace.

I led this 0-to-1 initiative from research through delivery, defining and shipping a V1 document discovery experience for a new Document Admin role. The solution enabled admins to search account-owned content by user, date, and keyword—providing the visibility needed for security and legal workflows.

Launched to a beta group, the feature received strong customer feedback and established the foundation for Lucid’s Enterprise Shield add-on, which has since surpassed $xxM in iARR.

Timeline

March 2022 – July 2022

Document discovery (Beta version)

My Role & Contribution

Sole UX designer on a 0-to-1 initiative.

  • Owned design end to end — from ideation through Alpha and Beta delivery.
  • Drove discovery and synthesis, reframing document discovery from a single feature into a problem space spanning access control, retention, and legal hold
  • Scoped and sequenced V1 under tight constraints — deciding what to build first and why

Teams & Collaborators

  • PM: Co-led discovery research, scoping, and prioritization
  • Customer Success — Recruited admins with documented document management or retention needs for research
  • Internal IT, Security & Legal — Consulted as subject matter experts during discovery, and partnered with Security and Legal throughout development to ensure the feature met data privacy and compliance requirements
  • Engineering — Collaborated throughout design and delivery to assess technical effort and scope tradeoffs

Problem Space

The same requests kept coming from enterprise customers: "I need visibility into what my users are creating," "I need to spot-check documents for PII before it turns into a liability." Neither was easy to do in Lucid.

By early 2022, the volume and urgency had grown — especially among customers in highly regulated industries, where governance wasn't optional. We treated it as a signal, not a series of one-offs, and stood up a second enterprise team dedicated to the problem.

The bet: data governance capabilities were essential to making Lucid enterprise-ready, and worth building for every customer with these needs, not just the one asking.

Research

Before any design could happen, the problem space had to be defined from scratch. There was no existing feature and no shared understanding of what "document discovery" even meant in the context of Lucid's product. We ran a multi-method discovery effort across three streams:

Competitive & market research

Benchmarked in two directions:

  • the industry leaders in document governance and compliance (Google Vault, Microsoft 365, Slack, Box) to learn from the mature standard,
  • and canvas-based competitors to understand what document management and governance mean in a visual-collaboration product like Lucid.

External admin interviews

Talked to 7 admins across pharma, financial services, healthcare, aerospace & defense, enterprise tech, and media & entertainment.

The goal was to deeply understand their needs and use cases around document discovery, management, and retention — and to help define what those concepts meant specifically in the context of Lucid.

Internal subject matter expert interviews

Consulted internal IT, Security, and Legal teams to deepen our understanding of these roles and the tools they already use to accomplish similar goals.

Key personas

From the synthesis, we identified three distinct admin personas with meaningfully different needs. The personas made clear that "document discovery" wasn't a single feature — it was a problem space spanning access control, retention, and legal hold.

Key needs identified from discovery research

Across the three personas, the needs converged into four capability areas.

Document Visibility

Before admins can do anything else, they need to see what's in their account and who owns it.

  • Pull account-owned documents by user, content, or other criteria
  • Open and audit what's inside a document

Document Controls

Once admins find what they're looking for, they need to act on it.

  • Revoke external access to protect company assets
  • Reassign ownership or adjust access to handle day-to-day requests
  • Redact PII and other sensitive content within a document
  • Bulk-export documents for legal and audit review

Legal Hold

During an active investigation, admins need to secure the relevant records before anything is lost.

  • Quickly pull documents tied to a specific user or project under investigation
  • Prevent those documents from being deleted until the investigation closes

Retention Compliance

Retention isn't one-size-fits-all: each company sets its own policies by data classification, and they classify Lucid content in different ways.

  • Set retention periods for Lucid content, compliant with company policy
  • Maintain a central holding account for documents that must be preserved

Key Decisions

Research surfaced four distinct capability areas. Given the constraints — one scrum team, three engineers, and a deadline to deliver to the customer by end of quarter — we prioritized ruthlessly.

We ranked capabilities in order of admin impact and urgency:

We scoped V1 entirely to Document Visibility, with a clear goal: get a solid, tested foundation in front of customers quickly and use their feedback to sequence what came next.

Solution

We added a Document Discovery page to the admin panel, allowing document admins to search across the account by users, creation date, and keywords.

Callout #1 — A new admin role

Viewing document content is a highly sensitive permission — only a few people in an organization should have it, and their actions need to be auditable. Rather than granting it to all existing admins, we introduced a dedicated Document Admin role to enforce that boundary.

Callout #2 — Keyword search scope

We deliberately extended keyword search beyond document titles to include document content. Admins need to cast as wide a net as possible — naming conventions vary across users, and sensitive information is often buried inside a document, not surfaced in its title. Additional criteria let admins narrow from there.

Impact

The feature shipped within the quarter. Early beta feedback validated the direction.

Direct feedback from beta customers

A foundation that kept growing

Following V1, we deepened search so admins could pull exactly the documents they needed — filtering by multiple users, team folders, ownership type (owned vs. accessible), and whether a document had external shares.

Later releases went beyond discovery into action: document ownership transfer, external link revocation, external user removal, relocation to team folders, and bulk classification labeling — giving admins progressively more control over account content.

Document Discovery was Lucid's first real step into compliance — and it changed how the company thought about the space. The foundation it laid was reused for content inspection and beyond, and it made the case that advanced security and compliance were worth monetizing. That thinking became the Lucid Enterprise Shield add-on, launched in Q3 2024 and past $xxM+ iARR by Q3 2025.

View other projects