FINTECH · B2B2C

Reducing Login & Sign-Up friction

Redesigned authentication using CPF as a decision engine — reducing first-access friction and operational support load.

AuthResearchUX
Mobile mockups — CPF-first login and sign-up flow.

CONTEXT

The product

  • CompanyOnze
  • IndustryFintech • Private pension
  • ProductOnze app
  • UsersEmployees onboarding into pension benefits via their company
  • StakesAuthentication friction was devaluing the first interaction users had with the brand — and adding recurring load on customer support.
Role
Senior Product Designer
Team
Product • Engineering • Customer Support
Scope
Login & Sign-up
Year
2025

THE PROBLEM

Where the flow was breaking down

Most authentication issues weren't technical failures — they came from misalignment between what users expected and how the system behaved. Three specific friction points emerged from the support ticket audit Product had run, confirmed by my own review of the existing flow.

  • Single entry point with no routing logic between new and returning users

  • Generic error messages blocked recovery and pushed users to support

  • "Login vs sign-up" binary choice failed for low-digital-literacy users

  • No employer-employee validation before account creation

01

Confusion between login and sign-up

Users had to choose a path without knowing their account status — sporadic usage and dependency on company onboarding made this error-prone.

02

Vague error messages

Security policy prevented the system from specifying whether a CPF or password was wrong — necessary for security, but it left users stuck without a recovery path.

03

Unclear company validation

Sign-up required a corporate email or HR-provided token, but the flow gave no clarity on what was needed or how to obtain it.

BUSINESS SIGNAL

Authentication friction was devaluing the first interaction users had with the brand — and adding recurring load on customer support.

MY CONTRIBUTION

What I owned end-to-end

  • I led design end-to-end — translating Product's support audit into strategy, from problem framing through solution validation

  • I worked cross-functionally with Product, Engineering, and Customer Support to align user needs with security and technical constraints

  • I reframed CPF from a static input into a decision engine that auto-routes users — eliminating the binary login/sign-up choice

  • I validated the proposed flow with 31-participant usability testing in Maze, then iterated based on qualitative findings before implementation

PROCESS

How I got there

W 1–3

Discovery

W 4–6

Design

W 7–8

Validation

FLOW REVIEW

Additional review of the existing authentication flow during design discovery

SOLUTION

Three frictions, three architectural fixes

BEFORE

User decides

User opens app

Login or Sign-up?

Wrong choice → support ticket

Decision lives with the user — who often doesn't know their account status, as explored in the "Problem" section.

AFTER

System decides

User enters CPF

System validates against database

Auto-routes to login or sign-up

Decision lives with the system — using the unique identifier already at hand.

PROBLEMSOLUTION

Users self-identified as new vs returning — sending many to the wrong path

CPF validates against database. System routes automatically to login or sign-up — no user decision needed.

Generic error messages blocked recovery (security policy)

Separated CPF and password into distinct steps. Specific feedback per step. Valid CPF not in database → guides user to HR.

Token flow opaque about what HR provides and how to obtain it

Inline examples (employee ID, CPF digits) + explicit routing to HR — sets the right expectation that this comes from the company.

BEFORE

original login flow

AFTER

CPF-first entry screen

VALIDATION

What the testing showed

PARTICIPANTS

31

in moderated usability testing (Maze)

TASK SUCCESS

100%

across all 31 participants

FLOW ERRORS

0

in the primary authentication flow

WHAT USERS SAID

"The decision to separate CPF from the password is something we see a lot in other apps today, and I think it makes total sense."

PARTICIPANT #1

"I really liked that we don't have stacked fields but rather one field per page. Scrolling through long forms is terrible on mobile devices, and this approach makes it clearer what the customer is doing."

PARTICIPANT #2

LEARNINGS

What this taught me

Many authentication issues stem not from system failure but from misaligned mental models. Restructuring the entry point — making the system route, not the user decide — addressed a root cause that copy and tooltips couldn't reach.

Usability and security need to evolve together. Releasing this alongside the MFA rollout wasn't coincidence — it was deliberate sequencing to ensure clarity and security improved in lockstep, rather than one degrading the other.

Want to dig into the architectural reframe behind this case?

Happy to walk through the trade-offs and what didn't make the case.

CONTINUE READING

More cases