Strategy question
A global law firm says it will not expand Harvey beyond one practice group until Command Center has stronger identity and access management. How would you decide the MVP and sequencing across SSO, SCIM, RBAC, audit logging, and granular access controls, and what trade-offs would you make with Engineering and Security?
- Harvey
- Strategy
- Hard
Practice this question out loud. An AI interviewer asks it, follows up like a real interviewer would, and scores your answer. Type or speak.
Start a mock interview on this question · Mock interview from a job description
What this question tests
Whether you can sequence a hard enterprise security requirement into a defensible MVP, balancing what actually unblocks the customer against what engineering and security can realistically deliver.
How to approach it
- Clarify what stronger identity and access management means to this specific firm: ask which of SSO, SCIM, RBAC, audit logging, and granular access controls are explicit blockers versus general improvements they'd like.
- Treat SSO and audit logging as the most likely hard blockers for a global law firm's security review, since those are typically baseline enterprise identity requirements, while granular access controls are often a deeper, slower-to-build capability.
- Sequence the MVP as SSO plus baseline audit logging first, RBAC with role templates for common law firm structures second, granular access controls as a later phase once usage patterns from RBAC inform what granularity is actually needed.
- Make the trade-off explicit with Engineering and Security: shipping RBAC before granular controls trades some customization for speed, and is defensible if audit logging already gives visibility into any access RBAC does not yet restrict.
- Validate the sequencing directly with the firm before committing engineering time, since expanding beyond one practice group is the actual business goal, not just passing an internal checklist.
What a strong answer includes
- Identifies SSO and audit logging specifically as the likely true blockers, rather than treating all five capabilities as equally urgent.
- Explains why RBAC comes before granular access controls with a concrete reasoning, that audit logging provides interim visibility, not just because RBAC is simpler.
- Validates the plan with the actual customer before committing engineering resources, tying the roadmap to the real business outcome.
Common mistakes
- Treats SSO, SCIM, RBAC, audit logging, and granular controls as equally urgent with no sequencing logic.
- Never checks with the customer whether the planned MVP would actually unblock their expansion decision.
Likely follow-up questions
- What would you do if the firm insists on granular access controls before RBAC.
- How would you handle Security wanting a stricter audit logging standard than the MVP timeline allows.
More strategy questions
- How should Harvey price for law firms vs. in-house legal teams?Harvey · Strategy · Hard
- How would you grow Harvey adoption among conservative, risk-averse law firms?Harvey · Strategy · Hard
- You inherit Vault with strong customer interest but limited engineering capacity. How would you set Vault’s product vision and a 12-month roadmap across file management, AI search/Q&A, document extraction, secure sharing, and platform investments like permissions, indexing, and integrations? Walk through your prioritization framework, major bets, and what you would explicitly defer.Harvey · Strategy · Hard
- Harvey can fund only one major integration track next: deeper iManage support, broader SharePoint coverage, or cross-platform capabilities like sync, permissions mapping, and admin controls. How would you decide what to build first, and what tradeoffs would you make across customer demand, implementation effort, security risk, and strategic leverage?Harvey · Strategy · Hard
- Harvey’s Command Center needs to serve three jobs for enterprise admins: understanding adoption, managing users and access, and enforcing governance. How would you define the product strategy and first 12-month roadmap for Command Center, and what framework would you use to make trade-offs across those three areas for Harvey’s largest legal customers?Harvey · Strategy · Hard
- You inherit a platform where teams lack visibility into request failures, latency regressions, customer-impacting incidents, and model-quality degradation. How would you define the product scope for observability, decide what to ship first, and ensure the work improves customer outcomes rather than just adding internal tooling?Harvey · Strategy · Hard
More questions from Harvey
Learn the skill behind it
Chapters of the AI PM course that teach what this question tests.
- Chapter 4: Discovery and strategy for AI products
- Chapter 9: Prove it paid off: outcomes, economics, and pricing
- Chapter 14: Get the job: the AI PM interview loop