Designing for Security and Usability: Figma's Modern Endpoint Strategy | Figma Blog (opens in new tab)
Figma argues that effective endpoint security must balance strong controls with a smooth employee experience. Excessive friction encourages unsafe workarounds and noncompliance, while self-service remediation and data-driven rollouts make security easier to adopt. Its strategy combines automated device quarantine, application allowlisting, and just-in-time access controls to protect systems without unnecessarily disrupting productivity.
Security and usability must work together
- Strict policies alone do not guarantee safety.
- Complicated password rules, for example, can lead employees to reuse passwords or write them down.
- Security controls should help employees work securely rather than create incentives to bypass them.
- Employee trust and participation make the overall security program more effective.
Endpoint Security Baseline and self-service remediation
- Figma’s Endpoint Security Baseline (ESB) enforces controls such as:
- Keeping browsers updated
- Disabling remote login
- Preventing kernel extensions from running
- Kernel extensions can execute code at a low system level and potentially exfiltrate data, disable protections, or steal credentials.
- Using OSQuery, the ESB detects risks such as unauthorized kernel extensions.
- Noncompliant devices are quarantined and blocked from privileged services including AWS, GitHub, and Google Workspace.
- The system attempts automatic fixes before contacting the user.
- If user action is required, Slack provides instructions and self-service remediation.
- Access is restored immediately once the device returns to a safe state.
Data-driven rollout of Santa
- Santa is an open-source macOS binary allowlisting tool that permits only approved applications to run.
- Figma first used Santa’s Monitor Mode to observe application usage before enabling Lockdown Mode.
- The rollout revealed that:
- Most non-engineering employees used a small set of standard applications.
- Engineers frequently created new binaries during development.
- Engineers also relied on numerous productivity tools that required review.
- Figma built automated approval for developer-created binaries and reviewed commonly used tools.
- The resulting allowlist meant 90% of devices would experience no blocked applications.
- A Slack-based self-service approval workflow handled less common applications.
- Santa was gradually deployed to experienced engineers, improving security with minimal disruption.
Just-in-time access with Opal
- Figma identifies two problematic access models:
- A “Wild West” approach with few safeguards and excessive production access
- A heavily process-driven model that slows employees and encourages unsafe alternatives
- Overly restrictive access processes can lead to practices such as using development environments for production work or deploying shadow IT.
- Figma introduces just-in-time access with Opal to seek a middle ground: controlled access that employees can request when needed, without permanent privileges.
Figma’s approach recommends making security automated, observable, and self-service wherever possible. Strong controls are most effective when they protect sensitive systems while allowing employees to resolve issues and obtain legitimate access quickly.