Expanding an open-source cloud security tool into an intuitive SaaS heavyweight.
Intro
Prowler is the most widely used open-source cloud security platform with over 45M downloads and 14K stars on github. Their success is a direct result of a talented team who has built vital scanning capabilities that help organizations identify cloud vulnerabilities, active misconfigurations, and compliance drift.
Reuniting from our last time working together (Prowler: 5 Weeks To Deliver) we continued to advance the product's design language, simplify scalable workflows, and evolve their Agentic AI Agent into a user-first experience.
⁄/
TLDR
Mainstream competitors gained market interest due to their enterprise-oriented features. However, these platforms simply lacked the transparent, developer-forward, principles Prowler bakes into their unique offerings.
I came onboard to help shape the tooling into a more approachable product experience while preserving the technical depth that makes Prowler universally trusted. The result is a diverse suite of seamless integrations that simplify configuration, deepen risk prioritization, and scale an Agentic AI Assistant designed as a companion rather than forced functionality.
Data Visualization
Opportunity:
Upgrading the primary visual landscape.
Advancing an organization’s view into its scan data was a primary goal. Matching data dispaly with the querie type and data output. Interactive state changes and tooltips improve interpreted meaning and context for users.
Dashboards should show a story
Dashboard views distill a security engineer’s perspective into risk severity and trend categories. This paradigm was applied consistently across dashboard types, allowing each layout to reveal a focused perspective. Users start with a high-level overview and drill into details for specific objects.
Customization for the right tool
Prowler’s team had built extensive support for global compliance frameworks and multiple cloud providers, creating an opportunity to introduce greater user customization. Compliance and service watchlists allow teams to tailor monitoring to their unique infrastructure rather than rely on cookie-cutter defaults that may not fit the needs of a diverse user base.
Semantic Tokens Into A Design System
Problem:
Consistency breaks without systematic guidelines.
A crucial part of building Prowler’s new look and feel was empowering development to implement components and themes efficiently. Cross-team communication and collaboration is vital to establishing a tokenized language that's easy to maintain, meet baseline accessibility standards, and could scale across the full hierarchy of design components.
Findings List V2
Problem:
Individual Findings was a redundant view.
The Findings Page was an area I wanted to continue improving. User feedback showed that identifying security findings across multiple resources was a repetitive experience when working with real scan data. Introducing Findings Groups into the hierarchy made it easier to identify a check and quickly drill into each impacted resource.
Shaping new rules foro pagination
Findings Groups simplified the overall user experience but introduced a new challenge for pagination. To preserve visibility into each nested relationship, I proposed linking row limits to groups. When a group is expanded, the window of impacted resources reveals all associated findings within an expanding viewport, rendered with infinite scrolling.
Easier Onboarding
Problem:
Individually linking cloud accounts is tiring.
User feedback highlighted frustrations with the manual process of individually linking cloud accounts. For organizations with large, complex infrastructures, swift account setup is essential to broader adoption.
And we research...
To overcome this problem, I had to understand the underlying technical composition. Alongside competitive research, I dug into AWS documentation to understand how an IAM scan role could be automated across an organization’s accounts.
A strategic extention to the existing workflow
The flow for linking cloud accounts needed to accommodate a growing list of cloud providers as Prowler’s team continuously expanded access. I added a new branch while refining the existing flow, allowing users to authenticate their Organization (and/or Org. Unit), view and manage associated cloud accounts, then validate connections and schedule scan routines.
Repeatable onboarding schema
The technical workflow for linking an account is orchestrated between Prowler and the cloud console, requiring users to switch between platforms to enter and execute authentication details. A universal progress bar sets expectations for each step without becoming overly specific, allowing the same pattern to be learned and applied across account onboarding, regardless of linking method or cloud provider: Link Provider → Authenticate → Validate → Schedule Scan.
2.b
3.b
4
1
2
3
Streamlining user needs
Connecting multiple cloud accounts in one step opened up opportunities for other bulk actions. Users wanted an easier way to schedule scans across multiple accounts, so this became a fast follow-up that gave organizations the ability to schedule Prowler scans during periods of low traffic.
Agentic AI
Opportunity:
Agentic AI becomes a useful tool, not a mandate.
Lighthouse AI is Prowler’s latest innovation in cloud security. This agentic AI defender supports seamless MCP integrations and a customizable LLM engine. Seeing its potential as an assistant for less technical users, I wanted to explore a more approachable way to access complex AI tooling.
Outlining guiding principles helped keep the design focused on a people-centric tool rather than conflating Lighthouse AI with an unrealistic promise of autonomy.
AI as a tool...
Must be purposeful and transparent, giving guidance and never feel obscure.
Must compliment the product's landscape and never feel intrusive or force an interactive burden.
Must never assume to take action without human oversight to confirm the direction.
A dedicated workspace
To preserve token usage, Lighthouse AI was given dedicated real estate for security analysis workflows. To help users kick off investigations, UI prompts surface common starting points and evolve contextually as the investigation deepens, provider resources are defined, and compliance frameworks are identified.
Distinguishing AI observations from conversation
Lighthouse AI is able to do more than just answer questions. A key UX challenge was making a clear distinction between the security data it observed and the conversation surrounding it. I gave data-driven insights their own visual treatment, helping users distinguish between what Lighthouse AI observed from how it interpreted those observations.
Additionally, agentic actions require human approval, giving users control over when automation executes for safer security operations.
Showcase: Ideas Into An Interfaces
Outcome
This work continued Prowler’s advancement toward becoming the most widely adopted cloud security platform, turning complex security data into something people can understand, reason about, and act on.
Their dedication and innovation was recognized at Black Hat Asia 2026, winning the Startup Spotlight. Prowler is a team of passionate people who continue pushing cloud security forward without losing sight of its community or its commitment to open source. For the second time around, I’m happy to have worked with such a great team.