Modernizing authentication for a financial platform

Balancing stronger account security with a clear, intuitive customer experience.
Project Overview
Role: Senior Experience Designer
Platforms: Web and native apps
Partners: Product, Engineering, UX Writing, InfoSec
Focus: Authentication, MFA, edge cases, vendor integration, cross-platform flows
Note: Nalume is a fictional financial institution. This experience was reconstructed using Harbor, an original design system, to illustrate my design process while protecting confidential product details. Names, interface details, content, data, and selected implementation logic have been generalized.
A consumer financial platform was modernizing its authentication experience and preparing to introduce stronger account-security protections.
What initially appeared to be a login redesign was really a connected system of sign-in, verification, security enrollment, recovery, and customer communication. The greatest challenge was adding protection without creating new barriers for legitimate customers—particularly people with long-standing accounts that didn't have all the information required by the updated experience.
As the primary designer during the later phase of the initiative, I helped turn these overlapping requirements into a clear, cohesive experience across responsive web and mobile.
I began by auditing the key entry points into the authentication experience and mapping the different states a customer might encounter.
The flows revealed where experiences shared a common path, where they diverged, and which exceptions required additional guidance. This shifted team discussions away from reviewing isolated screens and toward understanding the experience as a complete system.
The journey maps also gave Product, Engineering, Security, and Content a shared reference for discussing requirements, identifying gaps, and deciding how the experience should respond at each point.
I mapped the experience as a connected system to avoid designing each screen in isolation.

Standard password login flow, designed to conform to the 3rd party authentication platform.

Passwordless (passcode) second factor login flow.

One of the most important challenges involved solving for existing customers whose accounts didn't contain all of the contact information required by the stronger security experience. Some accounts were created long before a piece of information was required on the application form, or users may have changed their information. A single default path could have prevented those legitimate customers from successfully signing into their accounts. The question became: How might we prevent legitimate customers from being locked out, while keeping their accounts safe?
I worked with Product and Engineering to clarify the conditions behind these exceptions and design a progressive path that allowed customers to verify their identity, provide missing information when needed, and understand what to do next.
I also designed error, validation, and recovery states to give customers useful guidance without revealing unnecessary security information.
Because the experience was powered partly by a third-party identity platform, the team coudn't customize every interaction.
I worked closely with Engineering to understand which parts of the experience were configurable and where the platform imposed firm boundaries. Within those constraints, I focused on the elements that would have the greatest effect on clarity and trust: visual hierarchy, content, validation behavior, and continuity with the broader design system.
This collaboration helped us avoid proposing interactions that could not be implemented while still creating an experience that felt connected to the rest of the product.
The design considerations went beyond the sign-in screens. Customers also needed to understand why the experience was changing and what might be required of them.
I worked with cross-functional partners within the product design team and communications for both email and in-product guidance. Treating these touchpoints as part of one journey helped reduce surprises and made the transition feel more intentional.

Some of the error and recovery states.

The resulting experience supported the move to a more modern authentication platform and established a foundation for stronger account-security capabilities across web and mobile.
Just as importantly, the work turned a complicated set of technical rules, customer states, and platform constraints into a system the team could more easily understand, discuss, and implement.

You may also like

↑Back to Top