A permissions gap was costing deals
Asana’s task model made collaboration easy, but it treated every field the same. Share a task and its budgets, salaries, and strategic metrics came with it. Enterprise prospects chose competitors with finer controls; existing customers kept their most valuable work outside Asana.

I led the work end to end: customer research, usage analysis across every enterprise account, the permission model, and the field-level visibility experience. The system had to work for teams of ten and 300,000 — and across custom fields, rules, and AI teammates.

Field-library controls beat task-by-task permissions
Custom fields carry the business-critical data, but Asana's whole model is built on sharing tasks across projects. Without finer-grained permissions, a field couldn't be both private and collaborative — it had to pick one.

Four constraints became our decision framework: scale across thousands of fields, compatibility with rules and AI teammates, zero regressions across existing work, and trust — no permission could change without making the consequence clear.

I explored three directions: a low-friction reveal, a full-screen surface with room to explain tradeoffs, and a split view that exposed every field at once. Each made a different bet on speed, context, and the risk of an accidental change.


Across 20 customer and internal usability sessions, three signals held: plain language beat permission jargon, an eye communicated visibility better than a padlock, and admins expected to manage access from the field library — not task by task.
Security, Platform, AI, and Product leaders used the same four constraints to evaluate the finalists. I turned their competing requirements into a decision framework and recommended clarity over launch completeness.
We shipped the low-friction reveal in the field library: admins opened visibility controls only when needed, saw the consequence before confirming, and then returned to work. Compared with the full-screen and split-view concepts, it gave up some feature breadth but preserved the clearest mental model.

99% adoption — and a foundation for AI
| Metric | Goal | Beta | 3 months post-launch |
|---|---|---|---|
| Adoption rate | 30%+ | 40% | 99% |
| CSAT | 80%+ | 80% | 90% |
| Unblocked enterprise use cases | ✓ | ✓ | ✓ |
| Scalable permissions foundation | ✓ | partial | ✓ |
99% adoption within three months — on a foundation that now underwrites Asana's AI teammates and automation rules too.
Simple defaults beat more explanation
Simple defaults did more work than explanation. Iterating with customers and internal teams produced a permission model people could use without training.
I onboarded teams one by one. Documentation and a cross-team workshop up front would have gotten us to full adoption faster.