Prowler scan overview: findings by status and severity, attack surface, findings over time and new findings
The Challenge

A free tool that had to become a paid product

DevOps teams already knew and trusted Prowler. The company wanted to grow into a paid SaaS, but its two existing interfaces didn't show enough value to make anyone pay.

Problem

Scan results were hard to read, and nothing in the product showed why it was worth paying for.

01

Two disconnected interfaces. An outdated internal UI, and a quick Grafana integration that pushed users out of Prowler.

02

Hard-to-read data. Large tables you had to scroll sideways, and scan results shown as plain text with no history.

03

No visible value. A new user couldn't see what the product did for them, so it was hard to turn leads into customers.

Research

Learning how a security scan works

I took part in interviews with DevOps engineers and security users. Before designing anything we had to learn the vocabulary and how Prowler's data fits together:

01

A scan runs checks. Prowler goes through a cloud account and tests it against hundreds of checks, like "is this storage bucket public?" or "is two-factor login on?"

02

Every result is a finding. It passes or fails, and carries a severity (critical to low), a service, a region and an account.

03

Checks add up to compliance. Standards like SOC 2, PCI-DSS or GDPR are sets of checks, so a compliance score is the share of those checks that pass.

What it meant for design

Engineers need to know what to fix first. Auditors and compliance officers need to know how close the company is to a standard. One product had to answer both questions.

The Solution · 01 Findings

One row per finding, details on demand

I designed the findings list. The old table was wide and had to be scrolled sideways. In the new one each finding is a row that collapses to the key facts: enough to decide whether it matters.

Opening a row shows the affected resources, an explanation of the risk and remediation steps the user can copy as code. Searchable tags help people find a finding fast. We also left room in the layout for future integrations, such as sending a finding to Jira or Slack.

Decision

Collapsed rows answer "does this matter?". Expanded rows answer "how do I fix it?".

Findings list with one finding expanded: risk, recommendation, reference commands and tags
02 Overview Dashboard

From a text list to a picture of risk

The old overview listed scan results as text, with no context and no history. I designed a dashboard where every chart leads somewhere:

  • A pass/fail chart and a bar chart of failed findings by severity. Click either and you land on a findings list filtered to that slice.
  • A list of new findings sorted by severity, with a link to see them all.
  • A Findings Over Time graph, with tooltips on each point, to show whether things are getting better or worse.
  • A map of failed findings by service and region.
  • Badges that tell new findings apart from ones that were already there.
Overview dashboard: findings by status and severity, attack surface, findings over time, findings by region, failed findings by account and by service
03 Services

Which services need attention

I designed a services view with a card for each cloud service. A service with failed findings turns red, and one click opens the findings for that service. It's the shortest path from "something is wrong somewhere" to "here it is".

Services view: a card for every cloud service, red for services with failed checks
04 Compliance

How close are we to the standard

For compliance I designed a card per framework with a progress bar showing the share of passing checks, color-coded so weak spots stand out. This view matters most to regulated businesses and governments, who work against these frameworks every day.

Compliance view: a progress card per framework with the share of passing checks
Outcome

What happened for the client

After launch, Prowler closed its first large SaaS deal with a sports merchandising company with more than $3 billion in annual revenue. Multinational cloud companies showed interest, and Prowler raised another round of funding.

These are the client's results, and the work of a whole team. I was one designer on it, working next to the lead. DockYard's own write-up of the project has more.