FINTECH · B2B2C
Reducing Login & Sign-Up friction
Redesigned authentication using CPF as a decision engine — reducing first-access friction and operational support load.

CONTEXT
The product
- CompanyOnze
- IndustryFintech • Private pension
- ProductOnze app
- UsersEmployees onboarding into pension benefits via their company
- StakesAuthentication friction was devaluing the first interaction users had with the brand — and adding recurring load on customer support.
- Role
- Senior Product Designer
- Team
- Product • Engineering • Customer Support
- Scope
- Login & Sign-up
- Year
- 2025
THE PROBLEM
Where the flow was breaking down
Most authentication issues weren't technical failures — they came from misalignment between what users expected and how the system behaved. Three specific friction points emerged from the support ticket audit Product had run, confirmed by my own review of the existing flow.
Single entry point with no routing logic between new and returning users
Generic error messages blocked recovery and pushed users to support
"Login vs sign-up" binary choice failed for low-digital-literacy users
No employer-employee validation before account creation
01
Confusion between login and sign-up
Users had to choose a path without knowing their account status — sporadic usage and dependency on company onboarding made this error-prone.
02
Vague error messages
Security policy prevented the system from specifying whether a CPF or password was wrong — necessary for security, but it left users stuck without a recovery path.
03
Unclear company validation
Sign-up required a corporate email or HR-provided token, but the flow gave no clarity on what was needed or how to obtain it.
BUSINESS SIGNAL
Authentication friction was devaluing the first interaction users had with the brand — and adding recurring load on customer support.
MY CONTRIBUTION
What I owned end-to-end
I led design end-to-end — translating Product's support audit into strategy, from problem framing through solution validation
I worked cross-functionally with Product, Engineering, and Customer Support to align user needs with security and technical constraints
I reframed CPF from a static input into a decision engine that auto-routes users — eliminating the binary login/sign-up choice
I validated the proposed flow with 31-participant usability testing in Maze, then iterated based on qualitative findings before implementation
PROCESS
How I got there
W 1–3
Discovery
W 4–6
Design
W 7–8
Validation
FLOW REVIEW
Additional review of the existing authentication flow during design discovery
SOLUTION
Three frictions, three architectural fixes
BEFORE
User decides
User opens app
Login or Sign-up?
Wrong choice → support ticket
Decision lives with the user — who often doesn't know their account status, as explored in the "Problem" section.
AFTER
System decides
User enters CPF
System validates against database
Auto-routes to login or sign-up
Decision lives with the system — using the unique identifier already at hand.
Users self-identified as new vs returning — sending many to the wrong path
CPF validates against database. System routes automatically to login or sign-up — no user decision needed.
Generic error messages blocked recovery (security policy)
Separated CPF and password into distinct steps. Specific feedback per step. Valid CPF not in database → guides user to HR.
Token flow opaque about what HR provides and how to obtain it
Inline examples (employee ID, CPF digits) + explicit routing to HR — sets the right expectation that this comes from the company.
BEFORE
original login flow
AFTER
CPF-first entry screen
VALIDATION
What the testing showed
PARTICIPANTS
31
in moderated usability testing (Maze)
TASK SUCCESS
100%
across all 31 participants
FLOW ERRORS
0
in the primary authentication flow
WHAT USERS SAID
"The decision to separate CPF from the password is something we see a lot in other apps today, and I think it makes total sense."
"I really liked that we don't have stacked fields but rather one field per page. Scrolling through long forms is terrible on mobile devices, and this approach makes it clearer what the customer is doing."
LEARNINGS
What this taught me
Many authentication issues stem not from system failure but from misaligned mental models. Restructuring the entry point — making the system route, not the user decide — addressed a root cause that copy and tooltips couldn't reach.
Usability and security need to evolve together. Releasing this alongside the MFA rollout wasn't coincidence — it was deliberate sequencing to ensure clarity and security improved in lockstep, rather than one degrading the other.
Want to dig into the architectural reframe behind this case?
Happy to walk through the trade-offs and what didn't make the case.
CONTINUE READING



