2023 Q3 - KR3: Secure Usability Benchmarking - Overview
#### What's this epic all about? (Background and context)
The UXR Team recently published a [handbook page](https://about.gitlab.com/handbook/engineering/ux/ux-research-training/usability-benchmarking/) which formalizes the process for benchmarking a group of features. This process is going to be carried out in the Secure section following the handbook page as well as previous benchmarking studies.
#### What are the overarching goals for the research?
The goal of this research is to deeply understand the workflow and pain points which users go through for the priority JTBD in Secure. After completing this study, we hope to gain a significant amount of information on which areas our users struggle with, in additional to which types of errors commonly occur. These insights will come across stage groups, and provide a holistic view of the ~"devops::secure" stage.
The direct output of this study will be a report similar to [past benchmarking reports](https://www.figma.com/proto/mF555KKsf1m1UyyXbWxXu2/Benchmarking-Slides?node-id=70%3A1445&scaling=scale-down&page-id=40%3A124&starting-point-node-id=943%3A12915), which contain information on the each major task's completion %, severity score, effort level, and time on task in addition to qualitative feedback from the users.
#### What research questions are you trying to answer?
JTBD we are testing:
* When I am triaging vulns, I want to address business-critical risks, So I can ensure there is no unattended risk in my orgs assets.
* When committing changes to my project, I want to know if I introduced any business-critical vulnerabilities, So that I can address them prior to sending my code for review.
* When I am configuring a CI/CD security scan, I want to specify which assets need to be scanned and under which circumstances, So that I can ensure my assets are secure prior to or at their release.
More questions will be defined down the line, but starting research questions include:
- How many critical errors do users experience when using Secure features?
- How long does it take for users to complete the priority JTBD(s) for Secure?
- How likely are users able to complete the priority JTBD(s) for Secure?
#### What persona, persona segment, or customer type experiences the problem most acutely?
We will narrow down the user personas more later, but for now we can start with these descriptives:
- Gitlab Users
- New users (if possible)
- Users with Ultimate plan only
- No specific title/role requirements
- No specific experience requirements
#### What business decisions will be made based on this information?
This benchmarking will result in a list possible problems which the design team will be able to look at and create solutions for. This benchmarking will also help stakeholders developer a deeper understanding of the user's workflows as a whole, which will influence future design strategies.
#### What, if any, relevant prior research already exists?
#### What timescales do you have in mind for the research?
Ideally, all participants will be run by Aug 15th.
I will be OOO from Aug 15-30th, so the synthesis of some of the final participants will be done the first week of september.
#### Who will be leading the research?
@moliver28 will be the primary DRI.
Other PMs in Secure will provide their perspective as the process is defined.
#### Relevant links (opportunity canvas, discussion guide, notes, etc.)
#### TODO Checklist
* [X] `8/1/2022` Configure environment and fill with data
Finalize Tasks
* When I am triaging vulns, I want to address business-critical risks, So I can ensure there is no unattended risk in my orgs assets.
* When committing changes to my project, I want to know if I introduced any business-critical vulnerabilities, So that I can address them prior to sending my code for review.
* When I am configuring a CI/CD security scan, I want to specify which assets need to be scanned and under which circumstances, So that I can ensure my assets are secure prior to or at their release.
* [X] `8/2/2022` Create test environment
- https://ux.gitlabdemo.cloud/users/sign_in
* [X] `8/4/2022` [Draft of procedure & metrics to collect](https://docs.google.com/spreadsheets/d/1M2paUEBJqPv_k0mYLviMkT8N4aePhf0MSvNmL6MW4s4/edit?usp=sharing)
* [x] `8/8/2022` Create & work on draft Script
* [x] `8/12/2022`-`8/31/2022` @moliver28 OOO
* [x] `9/1/2022` Finish test environment with realistic dummy data
- https://gitlab.com/gitlab-org/ux-research/-/issues/1985
* [x] `9/2/2022` Draft Script
* [x] `9/6/2022` Finalize Screener
- [Draft Screener](https://docs.google.com/document/d/15IHA-_aJ5RFpxtIQicQtgYQaHPKfd8m_tRvU6tI6lec/edit?usp=sharing) (Gitlab Only)
* [X] `9/7/2022` Open Recruitment Issue
- https://gitlab.com/gitlab-org/ux-research/-/issues/1997
* [x] `9/6/2022` Finish Script
* [x] `9/7/2022` Last day to work on test environment
* [x] `9/8/2022` Pilot sessions + changes from pilot
* [x] `9/7/2022` Create recruitment issue and calendly link
* [x] `9/14/2022`-`10/12/2022` Participant sessions
* [x] `10/12/2022` Finish Data Collection, begin summarization
- [Dovetail Project](https://gitlab.dovetailapp.com/projects/6ed2aGabl3T0XHDdwIjQhJ/readme)
* [x] `10/14/2022` Finish Data Summarization
* [x] `10/19/2022` Host workshop on insight with stakeholders
* [x] week of 10/28 Meet with UXRs who recently finished other benchmarking studies to assess any cross stage findings
* [x] `10/28/2022` Finalized report
* [Secure Benchmark Report](https://docs.google.com/presentation/d/1qJ6u0llZfwcwu60axRHVirQCdRhTKvroXvvDc9Awc3A/edit?usp=sharing)
epic