Fortinet
FortiClient
Lead Designer
5 Mins
FortiClient scanned endpoints for risk, then went quiet. The user never knew. I mapped their journey and rebuilt the moment that mattered: tell them the instant a scan finds something, and guide them to fix it fast.
FortiClient lets a user run a vulnerability scan. But it stopped where it mattered. When the scan finished, nothing told them. To see the result, the user kept the app open the whole time, or remembered to reopen it and dig back to the scan tab.
I mapped Sophie, our everyday user, before any notification existed. Her mood fell across the flow: neutral at the start, unaware when it finished quietly, frustrated hunting for the result, confused trying to fix it.
Before
I mapped Sophie’s journey end to end before any notification existed. The break was obvious: the product saw the risk but never told the user, and never guided them once it had. Every low point sits where she goes looking for what the system already knew.
100%
of scans finished silently
No signal reached the user at completion. Stage 2 of the mapped journey.
3 steps
to see any result at all
Reopen the client, find the scan tab, dig into the summary. Every single scan.
0
guidance from finding to fix
A severity list with no plain-language path to remediation. Stage 4.
5 of 5
journey stages broke the same way
At every stage the product knew more than it told the user.
The reframe
The product knew the user was at risk and never said so. The fix was not a better screen. It was a moment: announce the result the instant a scan finds something, then guide the user straight to the fix.
I turned each painpoint into a buildable opportunity. Four painpoints, one through line: the product knew the user was at risk but never said so, or guided them to act.
My first popup let users submit a ticket to IT straight from the notification. Helpful, I thought, especially when an everyday user could not fix the problem alone. So I tested it with the IT team.
At 10,000+ employees the flaw was instant: if everyone could fire a ticket from every scan, IT drowns. I would have traded one problem for another. I cut it.
For risks with no quick fix, I chose to still inform the user rather than hand them an escalation button that collapsed at scale. Knowing what to leave out, and testing that with the people it would hit, is what kept the feature trustworthy.
One system answered all four opportunities: a proactive popup, a result the user can act on, plain language fixes, and an admin harness to control what surfaces.
01
Notify proactively, when a scan starts and when it finishes, without making the user babysit the app.
02
Guide them to act. Link to the result and explain the fix in plain language.
Answers: no notification on completion
The scan complete popup
A system popup announces the result the moment a scan ends, outside the app, where attention has moved. It leads with the stakes: “11 critical and 8 high vulnerabilities detected!” and “Your system has been analyzed for security vulnerabilities, categorized by risk level. Address critical vulnerabilities now to protect your computer.”
Answers: hunting for the result
One step to the scan summary
The popup links straight to the FortiClient Vulnerabilities Scan Summary, sorted by severity and broken down per app, for example Firefox 119.0, macOS 13.5.2, Adobe XD, each row with a status tag and inline actions.
Answers: confusion remediating
Plain language fixes
Update and Uninstall tutorial modals walk the user through the actual fix, turning “you are at risk” into a clear next step.
From the signal after launch
Snooze, against over alerting
A snooze control was the first lever against over notification, the start of tuning frequency rather than constant interruption.
Admin side, the configurable scope
EMS configurable scan harness
In EMS, security teams configure the scan and notification harness centrally, controlling what surfaces across endpoints. This is the configurable half of the scope, built.
The popup closed the awareness gap the map exposed. A scan once finished quietly. Now the user learns the result within a minute, and is guided straight to the fix.
The loudest post-launch signal was over-notification: users getting too many alerts rather than too few. Proof the moment was landing, and the pointer to what to tune next.
End user impact
<1 min
Time to awareness after a scan
From a silent finish to informed almost instantly.
Over-alerting
became the top post-launch feedback
Adoption ran high enough that over-alerting, not silence, became the complaint.
Business impact
60–67%
Workflow improvement
The 3–5+ touchpoint loop collapsed to 2 clicks, and the waiting disappeared. The math is the flow itself.
$600K+/yr
Operational cost saved
This feature’s share of the $1M+/yr notification initiative.
From 3–5+ touchpoints to 2 clicks
The waiting and the hunting disappear. The scan announces itself and action starts from the popup: a 60–67% cut in touchpoints, read straight off the step count.
The journey map did more than list painpoints. It put me in the user’s head, and that set the form. One thing became clear and fixed: only a true popup would work. You start a scan, click once, and get on with your day. You are looking at your screen, not at the scan. A quiet badge inside the app would never be seen. A system popup meets attention where it actually is. The map is what surfaced that. Without it I would have designed a tidier screen no one would look at.
The second lesson came after launch. The over notification feedback proved the alert worked, and pointed to the next problem: tuning frequency so the alert stays trusted instead of tuned out.
Let's discuss how I can drive measurable UX impact at scale.
2026 Victor Isichei
Full-Stack UX Designer