Abdullah Sheikh · Product Designer
Case 01 · Secure.com · AI experience design

Making an AI security analyst feel like a colleague, not a chatbot.

I designed Mindy as a second cursor that lives in the product. She notices what you're looking at and offers to help once. Say yes and her specialist agents build the investigation on her canvas, and every decision comes back to you.

Why it mattered
Secure.com's bet is AI teammates, because security teams can't hire enough analysts. Most tools bolt AI on as a chat panel.
What I did
Designed it end to end and built a working prototype in our production React app in about 10 days, with Claude Code. Try it on this page ↓ · Watch the film ↓
Where it is now
The CEO made it the direction for our AI agents. Our security, engineering and product teams tried it hands-on, and engineering is building it in phases. Not shipped to customers yet.
Role
Product Designer II, end to end
Owned
Interaction model, the coded prototype, the voice-agent wiring and the film
Team
Just me, with feedback from one external advisor
Stage
Explored in July 2026, now in engineering

The film is pre-recorded with choreographed beats on an earlier internal build, so a few names are blurred, and the incident is made up. Every other clip here is on a fictional client, Zephyr.

secure · mindy · a week with mindy
A Week With Mindy. One threat across four days, on one canvas. Sound on. Your side of the conversation is in the captions. I also have a longer cut where I walk through it myself, and I'm happy to share it and talk through the work. Just email me.
The problem

Security teams are getting an AI workforce. I wanted to work out where the analyst fits in.

In ISC2's 2025 study, 29% of security professionals said they can't afford the skilled staff they need.1 Yet in most tools, AI is a chat copilot bolted to the side. My user, an analyst on a lean SOC team, needed a teammate they could watch work and correct.

I kept thinking about Navi from Ocarina of Time. She points, and you look where she looks, but she's also gaming's most famous nag. Shigeru Miyamoto called her advice system "the biggest weakpoint of Ocarina of Time."2

1998 · Navi
The Legend of Zelda: Ocarina of Time. Navi, glowing yellow, hovers by an enemy while yellow targeting arrows ring it
Navi flies to the target, so you look where she looks. Ocarina of Time, Nintendo, 1998.
2026 · Mindy
Close-up of Mindy's ring around the vulnerability row you lingered on, with her arrow beside it asking: Want me to dig in?
Mindy rings the row worth a look and asks once.

So the goal was to keep the companion and lose the "Hey! Listen!"

The turning point

My first version was a tour guide, and it felt like a tutorial.

My first builds flew you across modules to the right row ("Take me there →"). An external advisor said it felt like a tutorial with no story, but liked one thing: Mindy was always with them. So I killed the tour and kept the presence.

Trade-offs: what I rejected and what it cost
Rejected · polish the tourBetter copy and faster flights would still be a tutorial.
Chosen · drop the guidance, keep the presenceBoth scenarios and the canvas came out of this one cut.
Before · the tour
secure · mindy · v1 guided tour
The real v1. She steers you there, module by module. 2× speed · fictional client data.
After · the teammate
secure · vulnerabilities
She stays beside you. Press "/", say yes, and she gets to work.
The experience

The canvas, up close.

secure · mindy / canvas
Four specialists (Pentest, CSPM, Asset Intelligence and Risk) build the board, then fly home. 1.5× speed.

She has a team, but you only deal with her. Her canvas works like a detective's mind palace:3 clues stay pinned until you thread them together.

The game that gave me the idea
The Sinking City's Mind Palace screen: clue cards pinned in a dark space, three of them threaded into one deduction
The game's version. The Sinking City, Frogwares, 2019, from the official trailer.
secure · mindy / canvas · the whole week
Mindy's canvas inside the product, with the navigation on the left and her thread list on the right: the backend kill chain across the top, linked by labelled connections, and the morning debrief's charts, attack-path graph, email and ticket below
The whole week on one canvas: Tuesday's kill chain on top, Wednesday's debrief below. Fictional client data.
How I got there

Five decisions about how an AI should behave next to you.

Decision 01 · initiative

She offers once and never takes the wheel.

The tensionNoticing first makes her a teammate. Interrupting made Navi infamous.
Chosen · a dwell watchWhen a row sits on screen for a few seconds, she rings it and offers once. Say no and she won't ask again.

The few seconds aren't a tested number. The pause makes her noticing feel real, like a colleague who looked before speaking. Nothing ever moves your view for you.

Trade-offs: what I rejected and what it cost
RejectedScrolling for you (it takes over your screen) · timers (they follow her schedule instead of your attention) · asking twice.
CostShe can't offer anything on rows you never look at.
secure · vulnerabilities
You linger on a row. She rings it and asks "Want me to dig in?" Once.
Decision 02 · being wrong

She can recommend, but the action is always yours.

The tensionWarmth makes people stop checking. In security, that's dangerous.
Chosen · she drafts, you decideShe drafts the email in front of you, and it only goes out when you say "Send it." Both stay on the card as a receipt.

Being confidently wrong loses more trust than admitting doubt. I learned that when I wired her to a live model. Every number she gives has to come from the view you're looking at.

What she got wrong in the live build, and what I changed
You askedWhat she didWhat I changed
"The critical count in my filtered view"Gave the whole dashboard's totalExact counts now come from the filtered view you're on
"Attack paths and vulnerabilities, side by side"Drew attack paths by severity, a different questionYour ask beats the component library. If nothing fits, she draws it
The morning brief, with one source slowSaid the system was running slow, over several linesShe never talks about loading. One "one sec", or nothing
The overnight numbersLeft the stats blank, though the data was thereBlank values are refused before they render

The film's build doesn't fully hold to this yet: one Send also forced MFA enrollment, and she routed a patch on her own. In the rebuild on this page, sending and filing are separate asks.

Trade-offs: what I rejected and what it cost
RejectedAn always-confident persona · a dramatic "I was wrong" afterwards · actions the AI owns.
CostHedging doesn't demo as well as confidence. I went with trust anyway.
secure · mindy / morning debrief
"Yeah, draft it." It only goes out on "Send it." A second okay files the ticket.
Decision 03 · her body

She's an orb and an arrow, drawn by the product itself.

The tensionA teammate has to point, but a face invites the Clippy problem.
Chosen · one entity, two statesAn orb while she thinks, an arrow when she points. The app draws her, like Figma's multiplayer cursors.
Trade-offs: what I rejected and what it cost
RejectedA chat panel (it can't point) · a face or mascot · a crossfade (it looks like two characters) · OS-level computer use.
CostShe can't point outside Secure.com.
secure · mindy
Orb ↔ arrow. The morph tells you she's switched from thinking to pointing.
Decision 04 · the wait

I wanted the 6 to 30 second wait to be the best part.

The tensionWith a spinner, a colleague just turns into a loading screen.
Chosen · fill the wait with real progressA pulse within half a second as the real request goes out, then skeletons shaped like the result and a milestone per real step.

A show that wows on run one gets annoying by run forty, so her spec fades it after a few runs. That part isn't built yet.

Trade-offs: what I rejected and what it cost
RejectedSpinners · fake progress bars (they lie) · a cursor faking activity.
CostReal milestones take more to build than a spinner.
secure · mindy / canvas
Mindy's canvas in the prototype while her team works: each specialist's tinted cursor sits on its card with a label saying what it's doing, like pulling the CVE record and flagging internet-facing assets
In the prototype: each specialist's cursor says what it's doing while its card fills in. Fictional client data.
Decision 05 · when it breaks

When something breaks, she says so and keeps going.

The tensionAn agent that hides a failure, or fills the gap with a made-up number, is worse than no agent.
Chosen · own it out loudIf a fetch fails she says so and never shows a number. After two failures she asks whether to keep at it or come back later.

All of this is built in the prototype.

Trade-offs: what I rejected and what it cost
RejectedSilent retries (you can't tell she's stuck) · a generic error toast · giving up after one try.
CostMore words on screen when things go wrong.
Try it

Browse the list for a few seconds.

A small rebuild of the real offer from the prototype, on fictional data. When she speaks up, press / and answer her in your own words, yes or no.

What it changed

It set the direction for how Secure.com's AI agents work with people.

She only builds views from production design-system components, and a coded catalog of them became the contract between design, product and engineering.

"Compare it against last month." The chart redraws in place.
"What can it reach?" The product's own attack-path graph builds on her canvas. Fictional data.
"Yes, file it." The ticket goes on the record.
The trust ladder
  1. She stays quiet by default.
  2. She proposes.
  3. You verify.
  4. Your confirmations feed back into her (designed, not built yet).
  5. Your part shrinks to reprioritizing.

Every decision stays on its card as a receipt, so you can always audit her work.

To be honest, it hasn't shipped to customers yet, and nobody outside Secure.com has used it.

What I took from it

The part of Navi worth keeping was the company.

Zelda director Eiji Aonuma defended Navi: "Going on an adventure by yourself is lonely and dull."4 He was right about the company, Miyamoto about the advice. Every movement starts from something you did and ends where you're already looking.

What I'd do differently: test with analysts outside the company before leadership.

What I'd test first: how often a linger leads to a yes (target: at least 1 in 3), and whether she still feels present once the show fades.

¹ ISC2 2025 Cybersecurity Workforce Study. ² 1999 strategy-guide interview with Shigeru Miyamoto (Shmuplations translation). ³ The Sinking City, Frogwares, 2019. ⁴ Eiji Aonuma, Kotaku interview, 2011. Game screenshots © Nintendo and Frogwares, and Navi's voice and sounds © Nintendo, shown for comparison.