[UXR] Duo Content Privacy and Controls
Context and Goals
Problem(s)
Building off of UX work on user access controls for DUo features - https://gitlab.com/gitlab-org/ux-research/-/issues/3379#note_2445313048 - this issue proposes extending that UXR to assess customer expectations and requirements for controlling access to both GitLab and external context used by AI features.
GitLab Duo is being repackaged to include basic AI functionality (Duo Nano) in Premium and Ultimate subscriptions. The research indicates that organizations strongly value access controls for AI features (95% want some form of control), but current plans may not fully address customer needs for context-based privacy controls. This presents several challenges:
- Different behavior of "Always Off" settings between self-managed instances (where it functions as a kill switch) and GitLab.com (where it only controls context access)
- Lack of clarity around how project/group owners can prevent AI from accessing their context without purchasing Duo
- Gap in understanding around customers' mental models regarding context privacy versus user access controls
- Potential compliance risks when users with Duo access can use AI on any project/group where owners have not explicitly banned AI use (and may not have the ability to do so).
This complexity is particularly challenging as we move to make Duo Nano available by default in Premium and Ultimate subscriptions, potentially exposing more GitLab context to AI without clear privacy controls.
In addition, GitLab is moving to incorporate external context (via MCP or otherwise). How do customers seek to control and authorize external context injection into GitLab Duo features?
Goal(s)
The goal of this research is to:
- Understand customers' mental models and expectations around AI context privacy on GitLab (what data AI can access) versus user access controls (who can use AI)
- Understand customers' mental models and expectations around governance control for integration of external context into GitLab Duo features
- Identify specific privacy requirements and concerns for project/group owners regarding GitLab Duo access to their code/data, as well as regarding GitLab Duo access to customer-configured external context sources
- Identify and validate potential controls for context-based privacy that would allow group/project owners to restrict Duo access to their contexts
- Assess the impact of different approaches to context privacy on adoption and usage
- Understand how organizations with different compliance requirements approach context-based AI privacy
- Identify necessary controls and their placement in the product to address key security and governance needs around access to both GitLab context and external context.
This work will inform the ongoing effort to create a comprehensive and user-friendly approach to AI privacy and access controls that meets diverse customer needs.
What Next
This research will inform:
- Design and implementation of context-based privacy controls for GitLab Duo
- Information architecture improvements for AI settings
- Documentation updates to clarify differences between Duo feature access and context privacy
- Implementation guidelines for feature teams implementing AI privacy controls
- Prioritization of controls improvements based on user needs
Intended Impact Type
- Changes in strategy/plan
- Changes in product/design
This research will primarily drive decisions about how to structure, organize, and present AI context privacy controls across GitLab, influencing both the UX and the underlying architecture for AI configuration.
Research Scope and Support Needs
Research Question(s)
Context Privacy Mental Models
- How do customers conceptualize the difference between "who can use AI" and "what data AI can access"?
- What are the key privacy concerns regarding AI accessing project/code data?
- How do project/group owners expect to control whether AI can access their GitLab contexts?
- How do project/group owners expect to control whether AI can access their external context?
Privacy Control Needs
- What level of granularity do organizations need for context-based privacy controls (instance, group, project)?
- How should context privacy controls interact with user access controls?
- Is there a need for different privacy settings for different AI features (chat vs. code suggestions)?
- Is there a need for different privacy settings for different context sources (internal vs external)?
Implementation Approaches
- Should context privacy controls be available to all Premium/Ultimate customers, regardless of Duo purchase?
- Should external context sources be available to all Duo customers, regardless of Duo level?
- Do different Gitlab tiers (ie free, Premium, Ultimate) expect different levels of context privacy controls?
- Do different Gitlab tiers (ie free, Premium, Ultimate) expect different context sources to be available?
- How should context privacy controls be presented in the UI to align with users' mental models?
- How should the system handle conflicts when a user has access to AI but is working in a context where AI is restricted?
Governance & Compliance
- What compliance requirements drive the need for context-based privacy controls?
- What organizational policies would context privacy controls need to support?
- How do organizations audit and track which data has been exposed to AI?
Deployment-Specific Considerations
- How should context privacy controls differ between GitLab.com, self-managed, and dedicated deployments?
- What are the expectations for inheritance/hierarchy of privacy controls across instance, organization, group, and project levels?
Hypotheses
- Customers have different mental models for user access controls versus context privacy controls, and expect both to be available
- Project/group owners expect to have control over whether their code can be accessed by AI, regardless of whether they have purchased Duo
- Organizations with strict compliance requirements need fine-grained, hierarchical context privacy controls that can be enforced at multiple levels
- The current difference in "Always Off" behavior between self-managed and GitLab.com creates confusion and doesn't meet customer needs
- Context privacy controls should be a core governance feature available to all Premium/Ultimate customers, not tied to Duo purchase
Target User Group
- GitLab administrators responsible for configuring and managing GitLab instances
- Security and compliance professionals who oversee AI governance
- Group/project owners concerned about code privacy and AI exposure
- Organizations with varying compliance requirements (regulated industries, private IP-sensitive companies)
- Mix of GitLab.com, self-managed, and dedicated customers
Relevant Works
- Duo Repackaging Research
- Unified AI Settings Epic
- Current GitLab Duo documentation on controlling availability
Priority and Support Levels
Priority Level
P1 (Must do)
This research addresses critical security and compliance concerns that could impact adoption of repackaged Duo features. The mismatch between current planned controls and customer needs identified in preliminary research suggests this is a high priority issue that could affect a large number of users and block important product decisions.
UXR Support Level
Gold
This research requires UX Research expertise to effectively explore mental models and validate proposed solutions. It involves multiple methodologies and touches on complex governance requirements that need careful research design.
Research DRI
[To be assigned]
Supporting UX Researcher
[To be assigned]
Research Documents and Methods
- Recruitment screener: [To be created]
- Research plan: [To be created]
- Interview script: [To be created]
The research will likely employ a mixed-methods approach:
- In-depth interviews with administrators and security/compliance professionals
- Usability testing with interactive prototypes of proposed privacy controls
- Surveys to validate findings across a broader customer base