Security & Compliance page for core users
### Problem to solve <!-- What problem do we solve? Try to define the who/what/why of the opportunity as a user story. For example, "As a (who), I want (what), so I can (why/value)." --> The current landing page for the Security & Compliance page for core users has proven very effective, but now that SAST has moved to core, we don't currently have a way of enabling SAST easily in the UI. We need to offer this path in addition to the incentive to upgrade (and/or start a free trial) so that more users use SAST and see the value that GitLab's Secure features have to offer. ### Intended users * [Sasha (Software Developer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sasha-software-developer) * [Sam (Security Analyst)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sam-security-analyst) ### User experience goal <!-- What is the single user experience workflow this problem addresses? For example, "The user should be able to use the UI/API/.gitlab-ci.yml with GitLab to <perform a specific task>" https://about.gitlab.com/handbook/engineering/ux/ux-research-training/user-story-mapping/ --> * Give users a path to enabling SAST from the UI * Show the value in upgrading to Gold/ Ultimate ### Proposal Part 1 <!-- How are we going to solve the problem? Try to include the user journey! https://about.gitlab.com/handbook/journeys/#user-journey --> **1. Keep Security marketing/upsell page, _with_ the following changes:** * Update screenshots * Add an "info" alert which includes a link to the Configuration page (after Configuration page is built) ##### Current design ![image](/uploads/de5fc06f7bbdea835936245c8dbb286c/image.png) ##### **Proposed designs** ![image](/uploads/fedc16abb1a23472e9e1a6fa199ffe45/image.png) ![image](/uploads/2b9af13f3540f1884b01a85f7777ecbe/image.png) ![image](/uploads/74df842f9f8f197ccd0acfc9eba48121/image.png) ### Proposal Part 2 **2. Add a Configuration page, where user can enable SAST from within the UI. Clicking `Upgrade or free trial` text link takes user back to Security Dashboard page.** ![image](/uploads/9518c29dbac350b5529f2bbc5fcffd1a/image.png) ### What does success look like, and how can we measure that? <!-- Define both the success metrics and acceptance criteria. Note that success metrics indicate the desired business outcomes, while acceptance criteria indicate when the solution is working correctly. If there is no way to measure success, link to an issue that will implement a way to measure this. --> TBD ### What is the type of buyer? <!-- What is the buyer persona for this feature? See https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/buyer-persona/ In which enterprise tier should this feature go? See https://about.gitlab.com/handbook/product/pricing/#four-tiers --> Core, Starter, Premium (self-managed) and Free, Bronze, and Silver (Gitlab.com) accounts ### Is this a cross-stage feature? <!-- Communicate if this change will affect multiple Stage Groups or product areas. We recommend always start with the assumption that a feature request will have an impact into another Group. Loop in the most relevant PM and Product Designer from that Group to provide strategic support to help align the Group's broader plan and vision, as well as to avoid UX and technical debt. https://about.gitlab.com/handbook/product/#cross-stage-features --> /cc @gitlab-com/gitlab-ux/growth-ux @kcomoli (who designed the original page, see https://gitlab.com/gitlab-org/gitlab/uploads/01e49f6ee5a3c55d6b6a1662c15b1e4b/screenshot-2020-01-31-09-46-40.png) ### Questions/ Considerations * Do we/ can we consider A/B testing two design variations? ### Release notes Draft release post notes
epic