← Back
Enterprise Open Source Discover Financial Services 2023 – 2024

Operational Data Store Framework

Discover ODS

Design Thinking facilitation, internal user research, and UX strategy that shaped Surveyor from a proof of concept into Discover's open-source Operational Data Store framework. A 2.5-week audit process reduced to minutes.

Discover ODS – Surveyor platform
Organization Discover Financial Services R&D
My Role DT Facilitator · UX Designer · Strategist · Researcher
Methods DT Facilitation · User Interviews · Usability Testing · Design QA · Dev Collaboration
Outcome 2–3 weeks → minutes. Now open-sourced at discoverfinancial/ods-framework
The Problem

The data existed. The path to it didn't.

Every few months, an audit team would send what seemed like a simple question: Which products are running open source software outside our compliance guidelines? Or: What applications depend on this specific library? Answering required assembling teams of SMEs, identifying disconnected data sources, extracting, normalizing, and synthesizing. Steps that would have to be repeated again the next time there was an audit — creating an unreliable, lengthy, and costly process.

The problem wasn't knowledge or skill. The data existed spread across dozens of disconnected systems, but no one had built a way to answer these questions without manually reassembling it every single time.

Audit Response Times Before Surveyor

FDIC What open source software is used and in which versions? 3 weeks
PCI What software is outside our compliance guidelines? 2 weeks
Day 0 What products depend on this asset? (e.g., Log4j) 3 weeks
IP Review What is impacted by open source licensing changes? 2 weeks
Average response time across all scenarios 2.5+ weeks
Problem Framing: The Four Hills

Before the first screen, the team needed shared language for what success looked like.

These weren't just user stories. They were the product's value proposition translated into language that business stakeholders, engineers, and executives could all align around.

HILL 01 Guidance

Guidance Author

A Guidance Author needs a tool that lets them set and communicate preferred software versions across the organization in minutes, not meetings.

HILL 02 Awareness

Director / Risk Control Owner

A Director or Risk Control Owner needs visibility into non-compliant software across all their products without launching a multi-week investigation.

HILL 03 Plan

Product Owner & Architect

A Product Owner and their Architect need a way to evaluate their software posture and define remediation plans without pulling in specialized data teams.

HILL 04 Attestation

Product Owner

A Product Owner needs to formally attest to their remediation plan against software that falls outside corporate guidance.

Internal Research

The research confirmed what we suspected and surfaced new unexpected information.

With the Hills defined, I conducted internal user interviews with people who had been pulled off their day jobs to answer these audit questions. Not the audit team — the people on the receiving end. People who had spent weeks doing work that felt like it shouldn't exist.

Emotional cost

Participants described the anxiety of being responsible for an audit answer they weren't fully confident in. The pressure wasn't about the data — it was about being the person who had to stand behind it.

The ghost data problem

Everyone knew the data they needed existed somewhere. The frustration was knowing the answer was in the different systems but having no clean path to retrieve it without a 3-week detour.

The design brief this created

Surveyor needed to be functional, feel fast, and be accessible to non-experts — trustworthy enough that a Product Owner could stake their name on the output.

Participant Voice: Susan Devlin, Payments & Technology

"I am a huge advocate for this solution! Over the past 10 years the management overhead and continuous upgrades required for applications which use open source software has increased exponentially. Especially if you are in a heavily regulated industry like Payments!"

Susan's team received a last-minute FDIC evidence request for all open source libraries used in their product area. Before Surveyor: 24+ hours, every Product Family's BT Manager manually extracting library lists from Git. With Surveyor: an accurate list of 820 libraries deployed in production in 45 minutes.

24+ hrs

Before Surveyor (manual extraction)

45 min

With Surveyor (820 libraries, production-accurate)

820

Open source libraries surfaced instantly

Usability Testing

Two rounds of testing. One goal: find the friction before it calcifies.

Round 01

Pre-Alpha Testing

WHO

3 moderated sessions with teammates + self-conducted design QA

WHAT

Guidance-setting and attestation flows reviewed before any external user ever saw them.

WHY IT MATTERED

Catching friction early, before it gets built into the mental model of the product team and before developers have already committed to an approach.

Round 02

Alpha Testing

WHO

2–4 target users per flow, recruited from the actual prospective user base

WHAT

Moderated sessions, synthesized findings, research playback led directly with the team and developers.

WHY IT MATTERED

Test objectives: Can a non-expert complete guidance and attestation flows without assistance? Where do they hesitate? What would make them more confident?

Outcomes

Key Decisions Shaped

NEEDS

Language clarity across multi-step workflows

Task sequencing to reduce cognitive load at key decision points.

WHY IT MATTERED

Feedback mechanics during high-stakes steps like formal attestation. This is the kind of decision that gets missed when engineers design for engineers.

Developer Collaboration

Not design review: Real-time collaboration with people building something genuinely complex.

One pattern repeated throughout the project: developers making design decisions under time pressure, and those decisions not holding up under user testing. I made it a standing practice to be available when developers hit UX forks — to collaboratively reason through choices about hierarchy, affordances, and feedback states before those choices became entrenched in the build.

The pattern

Developers hit a UX fork under time pressure. Without a designer available, they guess. The guess ships. User testing surfaces the problem. The fix costs more than the conversation would have.

The practice

I stayed available for real-time UX collaboration throughout the build — hierarchy decisions, affordance choices, feedback mechanics, error states. I remained a thought partner through all phases.

The output

A better product. Trust built across disciplines. Engineers who started asking UX questions earlier in the process, before decisions were load-bearing.

From Surveyor to Open Source ODS

Discover ODS became a platform modeled after Surveyor.

Surveyor's adoption across Cybersecurity, Business Technology, Payment Services, and Risk Management validated the core hypothesis: if you give people a single, queryable source of truth for their software estate, they will use it. The natural evolution was to open-source the framework and starting projects. Discover ODS became a vendor-independent, integration-flexible operational data store built on CycloneDX SBOM standards capable of powering domain-specific applications across any organization facing the same class of software observability problems.

Surveyor

The proof of concept. A single queryable source of truth for Discover's software estate — replacing manual, multi-week SME-assembled audit responses.

Discover ODS

The open-source framework that made Surveyor possible — vendor-independent, integration-flexible, and built on CycloneDX SBOM standards. Available at discoverfinancial/ods-framework.

My role in the evolution

As the project matured, my role shifted toward strategy and communication — shaping the language used to socialize both projects to audiences ranging from engineers to C-suite to the open-source community.

Impact

Tasks that took 2–3 weeks now take minutes.

2–3 wks

Reduced to minutes

Any Discover employee, without specialized domain expertise, can now produce audit-ready findings.

4 towers

Enterprise adoption

R&D, EP Tech, Cybersecurity, and GPN Tech. Product maintenance, zero-day response, audit acceleration, OSS compliance.

Open source

discoverfinancial/ods-framework

Publicly available for adoption by any enterprise managing software supply chain risk at scale.

Reflection

Sometimes the highest-value design work is making a technically sophisticated idea legible.

I came into Surveyor as a facilitator and left as a strategist, researcher, and communicator. The work that produced Surveyor wasn't a linear design process. It was a sustained collaboration between people with very different skills and seniority, held together by a shared conviction that software observability shouldn't require two and a half weeks and a team of specialists.

Key Insight

It's not always the screens. Sometimes the highest-value design work is making a technically sophisticated idea legible — to users, to stakeholders, to the teams who need to build and advocate for it.

It should take minutes. And now it does.