Team & user management
I didn't build a feature. I built the system that runs every client.
One self-serve module — Users, Roles, and Teams — that hands full environment control to every client, across five lines of business, with zero modification.
One module, three pillars — Users, Roles, and Teams — handing full environment control to the client. No backend access required.
A platform for everyone. Configured for no one
One unified platform. Multiple LOBs, multiple clients — all running on the same base system.
But every client had different role structures, different hierarchies, different terminologies. And there was no way to handle any of it from the client's side.
Every change needed us. That was the problem
The old reality
- All user creation, role setup, and permission configuration handled by our CSI from the backend.
- Every role change or new user meant a support request to our team.
- Dev team permanently queued with client-specific customisation tasks.
- Smart platform. Zero client autonomy.
One CSI managing all client environments — setup, updates, and customisation for every client, on every LOB.
Dev team allocated to permission changes that should never have needed engineering effort.
Give the platform to the client. All of it
A self-serve User Management module — three features that hand full environment control to the client. Our CSI's only job at onboarding: create one admin.
Users
Self-servedCreate and manage users individually or in bulk. Assign roles, regions, and teams. No backend needed.
Roles
Client-configuredDefine role hierarchy, name roles their way, set permissions per role. Fully client-configured.
Teams
Geography-awareFor clients across regions and countries. Create teams by location, assign managers, scope submissions.
Create, manage, and audit — no backend
Screen 1 — Users landing page
One view of every user — role, region, team, and status at a glance.
Screen 2 — User creation pop-up
Region and country captured at creation — feeds directly into smart team filtering later.
Screen 3 — User profile page
Full profile — permissions visible and auditable without backend access.
Define the hierarchy. Name it your way
Screen 4 — Roles landing page
Every role named and structured the client's way.
Screen 5 — Role creation pop-up
Permissions set once at role level — all assigned users inherit instantly.
Structure around geography and role
Screen 6 — Teams landing page
Every team — geography, manager, and workload visible at a glance.
Screen 7 — Team creation pop-up
Teams built around geography and role — not tracked in spreadsheets.
Screen 8 — Team detail · Members
Manager owns the roster — no ticket needed to make changes.
Screen 9 — Team detail · Assigned submissions
Submissions scoped to the team — no noise from other regions.
One flow I added that no one asked for
Inline Reassignment on Delete
Deleting a user blocked until their work was manually reassigned elsewhere. A broken, multi-step dead end.
Brought reassignment inside the delete flow. The system surfaces active submissions and prompts inline reassignment before confirming deletion.
One guided flow completes both tasks — reassign and delete — without leaving the page.
Delete confirmation — inline reassignment
Reassignment lives inside the delete flow — one action completes both tasks.
One system. Every client. Forever
Row 1 — Client impact
Row 2 — Design impact
Designing generic systems is the hardest UX work
Generic systems need invisible flexibility
It has to work for every client without feeling built for someone else. That takes ruthless abstraction and thoughtful defaults.
Requirements don't design themselves
The inner details weren't in any brief. They came from understanding what a manager actually needs to do their job.
Critical flows must respect user intent
The intent is to delete — not to be blocked. Help them complete it safely instead of standing in the way.
Data collected early pays dividends later
Region and country at creation felt minor. They became essential for smart team filtering down the line.
"This system was designed to never need changing, no matter how many new LOBs or clients join. That's the real measure of system design — not how well it works today, but how gracefully it scales to every scenario you haven't built yet."