NSF SECURE Center’s User Profile Redesign
V.2 of the NSF SECURE Center's User Profile. A core UX touch point for users of the SECURE Center's Shared Virtual Environment (SVE). The profile is the home-base for SVE users, allowing them to control and limit visibility of identifying and institutional information, engage in the community forum, and mentorship programs.




Project Background
The NSF SECURE Center Shared Virtual Environment (SVE) is a shared digital environment to support U.S. academic institutions, non-profit research centers, and small and medium businesses as they work to solve real-world research security challenges in the U.S. Research Ecosystem.
The SVE provides access to new tools and information to assist community members adapting to a rapidly changing research security landscape. The SVE also brings together trusted community members to share experiences, provide insights from their work, and shape future solutions through discussion forums and a center run mentorship program.
My Profile is the central source of truth for user data in the SVE. It lets users view, manage, and understand how they are represented across the platform, including the Discussion Forums and Mentorship Program. The V.1 profile was given a low priority during the initial MVP build of the SVE. After user feedback and consistent advocacy from platform product owners, National Design was brought in to redesign the profile.
Objectives
The V.2 profile redesign would be a full visual and UX overhaul of the current profile experience. Based on user feedback and requests, V2 would include several new functional requirements:
- My Profile will display and manage user identity across the SVE. It does not assign or modify access. It surfaces access context governed by the SVE Access Model. Access changes happen through administrative workflows outside this feature.
- My Profile will display governed content; it does not author it. Role and stakeholder definitions are owned and approved by other teams, and My Profile shows the approved copy as-is.
- My Profile will only display forum context; values are owned by the Discussion Forums spec and Access Model. All fields are system-governed and read-only. “Discussion Forums” is the category; specific forums (Community Forum, Research Security Professionals, Mentorship) appear within it.
- Account Email and Contact Email are both new in V2. V1’s single editable “Organization Email” splits into Account Email (system, used for authentication) and Contact Email (user-managed). Stakeholder Type carries “Staff” for SECURE Center employees.
Process
The V2 Profile redesign was a condensed sprint. After our platform product owner received approval from leadership, National Design was approached to make three rapid explorations for presentation within the following week.
Working closely together with Hope Terpilowski, we together created three initial iterations, based on the feedback to the V1 profile and the new requirements. We were given no constraints regarding the solution vision outside of that the V2 design should conform to the Secure Design System (and limit the introduction of new components).
The direction shown here, showcases our third and final iteration. It was also the most extreme break from previous versions of the profile that we’d subconsciously trying to elevate. New functionality in the V2 profile included:
- A field level approach to editing, not section level – V1 edited a whole section at once; V2 edits one field at a time. Field-level granularity is what makes the per-field behaviors possible, inline validation on the specific required field, the per-field public-visibility indicator, and Request Change on name fields only. A section-level model couldn’t carry those cleanly.
- The profile is a single scrolling page, not tabbed – A tabbed layout (Profile / Forums / Mentorship) was the original proposal. With only two sections beyond the core profile, the designers found tabs weren’t user-friendly. The navigation cost outweighed the benefit at scale. A single scrolling page keeps a user’s full identity visible in one place and lets new sections be added by extending the page rather than adding tabs as the ecosystem grows.
- Name changes use Request Change, not Save – First and last name are vetted identity fields that propagate across Discussion Forums, the Mentorship Program, and the future Directory. Because users are vetted before they gain SVE access, a name change can’t silently overwrite a vetted identity, it must go through a review process similar to the initial vetting to verify the person is still the same individual. Routing through Request Change keeps the approved name authoritative until that review clears, and keeps name identity inside Access Model governance rather than letting the profile bypass it.
- The public-visibility (eye) indicator ships in V2, even though the public profile doesn’t – The public profile view is deferred to LATER with the Directory, but the read-only eye indicator showing each field’s designated visibility ships now. Surfacing the visibility model early sets expectations and means no rework when the public view lands. The conscious tradeoff: users see a visibility state for a surface that doesn’t exist yet in this release.
- Access context is display-only – My profile shows roles, organization type, stakeholder type, and assignments, but never assigns or modifies them. Access is governed by the SVE Access Model and changed through administrative workflows. Keeping My Profile read-only on these avoids two systems both claiming to own access state, and keeps the profile a representation layer rather than an access-control surface.
- Mentorship Participation drives Role and Badge; users don’t self-assign – Participation (Mentor / Mentee / Both) is program-determined and is the single source of truth. A user’s Mentorship Role and the badge they display are derived from it and must match. Deriving both from one governed value prevents mismatches and stops users from self-declaring a verified status they haven’t earned.
The V2 Profile went live in August of 2026.