Multi-User Firewall Policy Management

B2B Platform as a Service

B2B Platform as a Service

Timeline

2 Months

Company

Aviatrix

Team

1 Product Manager, 4 Developers

Platform

Web

Timeline

2 Months

Company

Aviatrix

Team

1 Product Manager, 4 Developers

Platform

Web

What were the design principles?

The design was guided by three principles: safety, structure, and scalability. Changes should never directly impact live traffic, so all edits begin in a draft state that can be reviewed before deployment. As policies grow in size and complexity, users need a structured way to organize, delegate, and collaborate, which led to the introduction of rulesets, policy groups, and attachment points. Finally, the experience needed to scale with user maturity, allowing teams to work in either a simple view or a more advanced organizational view depending on their needs.

How did you get up to speed in such a complex domain?

I approached the domain by first building a strong mental model of how firewall policies were structured and managed. I spent time with product managers and engineers, reviewed technical documentation, and mapped out existing workflows to understand not just how the system worked, but why users worked the way they did. Rather than becoming an expert in cloud networking, my goal was to understand the concepts and constraints deeply enough to make informed design decisions and ask the right questions.

What research informed this solution?

We mapped how policies were created, reviewed, and managed at scale, identifying collaboration bottlenecks, ownership challenges, and the risks associated with editing live traffic. These insights helped shape a solution that aligned with real enterprise security workflows while remaining scalable for larger teams.

Challenge

Distributed Cloud Firewall policies lacked the structure needed for large security teams to manage delegation, and collaboration at scale. At the same time, changes applied directly to live traffic, making updates difficult to coordinate, and execute safely.

Solution

Introduced a draft-based policy workflow that allowed teams to create, review, and collaborate on changes. Added an organizational layer with rulesets, policy groups, and attachment points to support ownership and delegation.

Impact

Enabled teams to safely collaborate on firewall policies without impacting live traffic. Users can now work in parallel, review changes before deployment, and manage large policy sets through clearer ownership and organization.

VPC Protection Workflow

Product Enablement System