🗒️ Overview


The Catalog Issues page is a critical surface in Traceable where security teams monitor vulnerabilities and compliance issues detected across API endpoints through Live Traffic, AST, and Compliance policies.

As customers scaled their API footprint, the Issues page became increasingly noisy and difficult to act upon. This project focused on redesigning the experience to help users understand their security posture at a glance, prioritize critical issues, and take action at scale.

☹️ What was the problem?


The Issues page was meant to help teams assess risk, prioritize fixes, and track progress. But it fell short on all three resulting in the following key problems:

<aside> 1️⃣ No clear sense of priority

The page didn’t answer a basic question “What should I fix first?”. Issues weren’t ordered by severity, there were no trend signals, and teams couldn’t tell if security was improving or getting worse.

</aside>

image.png

<aside> 2️⃣ Confusing issue data representation

Issues were grouped by default, but this wasn’t obvious. As a result, metrics showed thousands of issues while the table showed only a few rows, making the data feel unreliable and confusing.

</aside>

image.png

<aside> 3️⃣ Too much manual work

Users couldn’t take action at scale. Marking issues, reducing noise, or creating Jira tickets had to be done one-by-one, which didn’t match real security workflows.

</aside>

<aside> 4️⃣ Rigid severity model

Severity was fixed per issue type. But in reality, the same issue can be low risk for internal APIs and high risk for public ones, something the product couldn’t handle.

</aside>