Skip to main content

Brenden Bice

U.S. Air Force: F-35

secure, role-based access for maintenance operations

Torque - F-35 Jet Maintenance Access Authorization

Year

2020

Tools

Whimsical, Balsamiq, Figma

Deliverables

Role-based access model

Authorization workflows

Progressive request flows

Wireframes & prototypes

High-fidelity interface design

Product Team

My Team

1 Product manager
7 Developers

2 Product designers (lead/junior)

My Role

Lead product designer

Research lead

Research

4 Field studies

31 Individual interviews
7 Focus groups

Summary

Torque is an 11-application platform used to coordinate F-35 maintenance. Before maintainers, supervisors, and pilots could use it, the system had to establish who they were, which unit or units they belonged to, what work they performed, and which permissions they required.

I led the design of a configurable access-authorization system spanning identity setup, progressive data collection, role and permission assignment, supervisor validation, security approval, notifications, and reauthorization. The system standardized onboarding across bases while allowing each maintenance unit to preserve its local organizational structure.

Problem

F-35 maintenance organizations varied substantially in how they structured units, sections, roles, shifts, and approval responsibility. Some airmen also worked across multiple maintenance units.

 

A rigid global model would not fit local operations, while unrestricted customization would weaken security, consistency, and auditability. The product therefore needed to make onboarding fast and low-touch while enforcing granular access, multi-stage approval, and a traceable record of changes.

Research & Process

Across field research at four Air Force bases, a junior designer and I interviewed 31 airmen and facilitated seven focus groups. We identified three primary user types and mapped the variations within them, including branch, rank, role, unit, section, shift, access level, and approval responsibility.

I translated these findings into a configurable information architecture that mapped the digital system to existing maintenance structures without reproducing every local inconsistency. I explored the model in Whimsical, tested progressive request flows through Balsamiq wireframes, and iterated the final workflows and interfaces in Figma.

Progressive access-request model
Mapping identity, service status, branch, rank, role, unit, section, shift, and access level into the minimum information required for authorization.

Authorization state and notification model
Defining initial authorization, cross-unit validation, approval, rejection, notification, and reauthorization across multiple responsible roles.

System Design

The final model combined a configurable role-and-permission architecture with a standardized authorization process. Local maintenance units could define their organizational structure while the platform retained consistent rules for requesting, validating, approving, changing, and auditing access.

Role and permission architecture

Defined several dozen permissions across the 11-application Torque suite and mapped them to operational roles that could be configured for each maintenance unit.

Progressive access request

Designed a conditional request flow that collected only the attributes relevant to each user. Military status, branch, rank, role, unit, section, shift, and access level progressively determined the remaining questions and requested permissions.

Two-stage authorization

Routed requests first to a supervisor who could validate the operational need for access, then to a unit security manager responsible for final approval.

Cross-unit access

Supported users assigned to multiple units or sections by introducing additional validators and approvers without requiring separate disconnected accounts.

Reauthorization and personnel changes

Created a distinct workflow for role, section, unit, and personnel changes so existing users could update access without repeating the entire initial onboarding process.

Identity Integration

Defining initial authorization, cross-unit validation, approval, rejection, notification, and reauthorization across multiple responsible roles.

Results

Deployment scale:

Workflow performance:

Pilot deployment: