Product design question
Several top law firm customers say they will not expand Harvey without stronger identity and access management. How would you prioritize and scope SSO, SCIM, RBAC, and audit logging for the first two releases of Command Center, and how would you balance enterprise security requirements against implementation complexity and admin usability?
- Harvey
- Product design
- Hard
Practice this question out loud. An AI interviewer asks it, follows up like a real interviewer would, and scores your answer. Type or speak.
Start a mock interview on this question · Mock interview from a job description
What this question tests
Tests scoping enterprise identity and access management (SSO, SCIM, RBAC, audit logging) across two releases while balancing security rigor with admin usability.
How to approach it
- Clarify which unlock matters most to the blocking law firms first, SSO for login is usually the hard blocker; SCIM and granular RBAC often come after.
- Scope release one around SSO and basic audit logging, the two most commonly required for a firm's security review to pass at all.
- Scope release two around SCIM provisioning and matter-level RBAC, which firms need for ongoing access governance, not just initial approval.
- Design RBAC roles around how legal teams actually work, by matter and by role, rather than a generic admin/user split that will not satisfy firm security teams.
- Balance usability by defaulting to sensible role templates so admins are not manually configuring permissions from scratch.
- Validate the sequencing with the firms actively blocking expansion before committing, since their specific requirement may reorder release one and two.
What a strong answer includes
- Sequences SSO first as the hardest blocker to firm approval, rather than treating all four capabilities as one bundle.
- Designs RBAC around matter-level structure, the actual unit legal teams organize around, not a generic role system.
- Validates the release order directly with blocked customers instead of guessing priority internally.
Common mistakes
- Bundling all four capabilities into one large release instead of sequencing by blocking urgency.
- Designing RBAC generically without matter-level structure that law firms actually need.
Likely follow-up questions
- How would you handle a firm that requires custom role granularity beyond your templates?
- What would you cut if engineering capacity only allowed one of the two releases?
More product design questions
- How would you improve Harvey's Vault for bulk document review at large law firms?Harvey · Product design · Hard
- Design a citation system so lawyers can fully trust Harvey's outputs.Harvey · Product design · Hard
- Design a Workflow Builder that lets non-technical lawyers automate recurring tasks.Harvey · Product design · Medium
- A top law firm says Vault’s AI search is promising, but attorneys still avoid using it in high-stakes matters. How would you diagnose whether the trust gap comes from retrieval quality, citation and explanation UX, permissioning concerns, workflow fit, or change management, and how would you prioritize the first product changes?Harvey · Product design · Hard
- Lawyers will rarely ask for 'better queuing' or 'stronger isolation,' but they will care deeply about accuracy, latency, reliability, auditability, and security. How would you uncover those needs and translate them into clear infrastructure product requirements and prioritized engineering work? Be specific about discovery methods, requirement framing, and how you would separate must-haves from nice-to-haves.Harvey · Product design · Hard
- You have 4 weeks with a strategic customer in a new professional-services vertical to identify one workflow for an AI-agent pilot. How would you run discovery, score candidate workflows, and decide whether to solve the problem by configuring Harvey’s existing capabilities, building a reusable extension, or not pursuing a bespoke solution at all?Harvey · Product design · Hard
More questions from Harvey
Learn the skill behind it
Chapters of the AI PM course that teach what this question tests.
- Chapter 4: Discovery and strategy for AI products
- Chapter 7: AI UX and human oversight: design for a system that is wrong sometimes
- Chapter 14: Get the job: the AI PM interview loop