Automated Scan Notification

Expand
Company

Fortinet

Product

FortiClient

Role

Lead Designer

Read time

5 Mins

Problem
A scan finished silently. To learn the result, the user had to keep the app open or keep checking back.
Approach
Mapped the journey, tracked the frustration, and turned each painpoint into a concrete opportunity.
Impact
Awareness in under a minute, from never. 60–67% fewer touchpoints, saving $600K+ a year.

Introduction

FortiClient scanned endpoints for risk, then went quiet. The user never knew. I mapped their journey and rebuilt the moment that mattered: tell them the instant a scan finds something, and guide them to fix it fast.

The Problem

FortiClient lets a user run a vulnerability scan. But it stopped where it mattered. When the scan finished, nothing told them. To see the result, the user kept the app open the whole time, or remembered to reopen it and dig back to the scan tab.

I mapped Sophie, our everyday user, before any notification existed. Her mood fell across the flow: neutral at the start, unaware when it finished quietly, frustrated hunting for the result, confused trying to fix it.

Before

Expand

What the research found

I mapped Sophie’s journey end to end before any notification existed. The break was obvious: the product saw the risk but never told the user, and never guided them once it had. Every low point sits where she goes looking for what the system already knew.

100%

of scans finished silently

No signal reached the user at completion. Stage 2 of the mapped journey.

3 steps

to see any result at all

Reopen the client, find the scan tab, dig into the summary. Every single scan.

0

guidance from finding to fix

A severity list with no plain-language path to remediation. Stage 4.

5 of 5

journey stages broke the same way

At every stage the product knew more than it told the user.

The reframe

The product knew the user was at risk and never said so. The fix was not a better screen. It was a moment: announce the result the instant a scan finds something, then guide the user straight to the fix.

Painpoints to Opportunities

I turned each painpoint into a buildable opportunity. Four painpoints, one through line: the product knew the user was at risk but never said so, or guided them to act.

Painpoint

Has to keep the FortiClient app open to track scan status.

Opportunity

Show a scan initiation icon on the endpoint once a scan starts.

Painpoint

No user notification when the scan finishes.

Opportunity

Give a clear popup of the completed result and a remediation guide.

Painpoint

Frustrated by navigating to the scan feature just to see the result.

Opportunity

Add a direct link to the result from the popup.

Painpoint

Confusing to understand the vulnerability and how to fix it.

Opportunity

Give a clear, actionable guide to the result in the app and the popup.

The Hard Call

My first popup let users submit a ticket to IT straight from the notification. Helpful, I thought, especially when an everyday user could not fix the problem alone. So I tested it with the IT team.

At 10,000+ employees the flaw was instant: if everyone could fire a ticket from every scan, IT drowns. I would have traded one problem for another. I cut it.

For risks with no quick fix, I chose to still inform the user rather than hand them an escalation button that collapsed at scale. Knowing what to leave out, and testing that with the people it would hit, is what kept the feature trustworthy.

The Solution

One system answered all four opportunities: a proactive popup, a result the user can act on, plain language fixes, and an admin harness to control what surfaces.

01

Notify proactively, when a scan starts and when it finishes, without making the user babysit the app.

02

Guide them to act. Link to the result and explain the fix in plain language.

Expand

Answers: no notification on completion

The scan complete popup

A system popup announces the result the moment a scan ends, outside the app, where attention has moved. It leads with the stakes: “11 critical and 8 high vulnerabilities detected!” and “Your system has been analyzed for security vulnerabilities, categorized by risk level. Address critical vulnerabilities now to protect your computer.”

Answers: hunting for the result

One step to the scan summary

The popup links straight to the FortiClient Vulnerabilities Scan Summary, sorted by severity and broken down per app, for example Firefox 119.0, macOS 13.5.2, Adobe XD, each row with a status tag and inline actions.

Answers: confusion remediating

Plain language fixes

Update and Uninstall tutorial modals walk the user through the actual fix, turning “you are at risk” into a clear next step.

From the signal after launch

Snooze, against over alerting

A snooze control was the first lever against over notification, the start of tuning frequency rather than constant interruption.

Admin side, the configurable scope

EMS configurable scan harness

In EMS, security teams configure the scan and notification harness centrally, controlling what surfaces across endpoints. This is the configurable half of the scope, built.

Validated Impact

The popup closed the awareness gap the map exposed. A scan once finished quietly. Now the user learns the result within a minute, and is guided straight to the fix.

The loudest post-launch signal was over-notification: users getting too many alerts rather than too few. Proof the moment was landing, and the pointer to what to tune next.

Users have reported receiving too many vulnerability alerts.
Kunal Marwah · VP of Product Design, Fortinet

End user impact

<1 min

Time to awareness after a scan

From a silent finish to informed almost instantly.

Over-alerting

became the top post-launch feedback

Adoption ran high enough that over-alerting, not silence, became the complaint.

Business impact

60–67%

Workflow improvement

The 3–5+ touchpoint loop collapsed to 2 clicks, and the waiting disappeared. The math is the flow itself.

$600K+/yr

Operational cost saved

This feature’s share of the $1M+/yr notification initiative.

The user flow

From 3–5+ touchpoints to 2 clicks

BeforeAfter
Open FortiClient
Run the scan
Wait, app open
Reopen the client
Hunt for the result
Act on findings
Run the scan, then walk away
3 steps eliminated
Popup announces the result. Act.

The waiting and the hunting disappear. The scan announces itself and action starts from the popup: a 60–67% cut in touchpoints, read straight off the step count.

Workflow mapping

Reflection

The journey map did more than list painpoints. It put me in the user’s head, and that set the form. One thing became clear and fixed: only a true popup would work. You start a scan, click once, and get on with your day. You are looking at your screen, not at the scan. A quiet badge inside the app would never be seen. A system popup meets attention where it actually is. The map is what surfaced that. Without it I would have designed a tidier screen no one would look at.

The second lesson came after launch. The over notification feedback proved the alert worked, and pointed to the next problem: tuning frequency so the alert stays trusted instead of tuned out.

Let's discuss how I can drive measurable UX impact at scale.

2026 Victor Isichei

Full-Stack UX Designer