Skip to main content
UI Coach Logo
Advanced

Multi-Team Admin Platform

Design an organization administration system for teams, inherited permissions, shared billing, and auditable access changes.

Desktop web4 hours plus

The brief

Understand the problem

Background

A research platform is used by separate laboratories inside one university. Central administrators pay for the account, lab owners manage their own members, and some datasets are shared across teams.

User context

Evelyn administers six laboratories with 240 members. She must move a researcher between teams, preserve approved dataset access, and remove permissions inherited from the former lab.

Product problem

Organization-wide and team-level settings overlap, making it easy to grant excessive access or remove a permission that another legitimate role still provides.

Objective

Create information architecture and workflows that make membership, role inheritance, billing scope, and sensitive changes understandable before commitment.

What to design

Define the experience

Required experience

  • Navigate from the organization to a specific team
  • Inspect a member's effective access and its sources
  • Move the member while reviewing permission changes
  • Confirm the change and inspect the resulting audit event

Screens and states

  • Organization overview
  • Team and member directory
  • Effective permission detail
  • Change review and audit log

Core user flow

Follow the critical path

  1. 01

    Evelyn opens the organization and selects the departing laboratory

  2. 02

    She reviews the researcher's direct, team, and shared-project access

  3. 03

    A transfer preview shows which permissions remain, end, or need approval

  4. 04

    Evelyn confirms the move and verifies the audit entry

Product rules

Requirements and constraints

Requirements

  • Distinguish organization, team, project, and direct access sources
  • Preview effective permission changes before saving
  • Support role comparison without relying on color
  • Record actor, time, scope, and reason for sensitive changes
  • Separate billing administration from data access

Constraints

  • Team owners cannot grant organization-level roles
  • At least two organization owners must remain active
  • Restricted project names may be hidden from administrators without clearance

Reality check

States worth considering

The member belongs to several teams
A custom role is edited during transfer
The final organization owner tries to leave
A pending invitation uses the same email
The member has an active legal hold

Finish line

What to deliver

  • Four desktop screens plus a role inheritance model
  • Annotations for destructive-action review and restricted data

If you want more

Optional extensions

Add bulk team transfer with a dry-run report
Design an emergency access review

Optional direction

Visual resources

Use these as a starting constraint if you want one. They are not part of the required solution.

Font pairing
Abril FatfaceRoboto

Abril Fatface & Roboto

Clear interface writing gives people the confidence to understand what changed and decide what to do next.

Icons
Illustrations

Keep practicing

Advanced
Enterprise

Enterprise Role Builder

Design an administrator workflow for composing a least-privilege role from permissions, conditions, and resource scope.

Desktop web4 hours plus
Information ArchitectureTrust and Safety
Advanced
Enterprise

Delegate a Sensitive Task to a Virtual Assistant

Design a remote-assistance workspace that defines scope, grants minimum access, and records completion without exposing an entire business account.

Desktop web4 hours plus
Trust and SafetyInformation Architecture
Advanced
Enterprise

Deprecate a Design System Component

Design a governance workflow for retiring a shared component while giving product teams evidence, migration guidance, and a fair exception path.

Desktop web4 hours plus
Design SystemsInformation Architecture
Advanced
Enterprise

Auditable Admin Data Export

Design an administrator export flow that scopes sensitive records, estimates impact, and controls secure delivery.

Desktop web4 hours plus
FormsTrust and Safety
Advanced
Enterprise

Data Retention Policy Builder

Design a governance tool for defining how long each data class is kept, archived, reviewed, and deleted across regions.

Desktop web4 hours plus
Information ArchitectureTrust and Safety
Advanced
Enterprise

Multi-Organization Workspace Switcher

Design a workspace switcher that makes organization, role, environment, and unsaved work clear before context changes.

Desktop web2 to 4 hours
NavigationInformation Architecture