Module
Back to courses
Tech for PMsJunior

Design authentication and permissions for a product

Specify sign-in, SSO, MFA and passkeys, and a safe roles × actions matrix for a multi-tenant product.

47 steps~2 hr 30 minLevel: Junior · Some basics are useful: introductory knowledge of the topic.

Specify who can get into your product and what each person can do there: sessions and tokens, passwords and account recovery following current recommendations, two-factor authentication and passkeys, sign-in with Google or Microsoft, enterprise SSO and provisioning, roles and permissions, isolation between customers, invitations, audit log and account deletion. You leave with your product's roles × actions matrix and its specified sign-in journeys, from sign-up to account deletion.

What you will be able to do

  • Distinguish authentication, authorization and session, and specify session durations, sign-out and access revocation.
  • Specify password rules and account recovery journeys following current recommendations (NIST SP 800-63B-4, CNIL, OWASP).
  • Choose strong authentication factors (TOTP app, passkeys), plan their rollout and specify the fallback journeys.
  • Specify delegated sign-in (OpenID Connect, social login) and enterprise SSO (SAML, OIDC, SCIM provisioning) for a B2B product.
  • Design a permission model (roles, attributes, scope) as a roles × actions matrix, enforced on the server side according to least privilege.
  • Specify isolation between customers, invitations, the audit log, support access and account deletion.
  • Specify your product's complete sign-in journeys, with states and errors, and choose between building and using an authentication provider.

Prerequisites

  • Know what a cookie, a status code (401, 403), a frontend and a backend are, and why a rule is checked on the server side, at the level of the course “Explain how a web product works, from browser to server”
  • Recommended: the course “Design and test an API integration as a PM”, which covers authentication of API calls (keys, OAuth 2.0 to a third-party service, scopes); this course covers how your users sign in and the permissions inside your product
  • Have access to your product (or to a product you know well) with at least two types of users
  • No code and no paid account: a spreadsheet and a free diagramming tool are enough; the tests happen in your own browser.
  • Explain how a web product works, from browser to server

Syllabus

What will I be able to specify by the end of this course, and in what order?

  1. Objective · By the end of this overview, you will know what you will be able to specify (your product's authentication and permissions), the two deliverables you will produce and which four modules get you there.

How do you verify users' identity, keep their session and give them access back without opening a security hole?

  1. Objective · By the end of this lesson, you will be able to distinguish authentication, authorization and session, explain what a session cookie and a token (JWT, refresh token) change, and specify your product's session durations, sign-out and access revocation.

  2. Objective · By the end of this lesson, you will be able to write password rules that comply with current recommendations (NIST SP 800-63B-4 and the CNIL, France's data protection authority), specify a forgotten-password journey that does not reveal which accounts exist, and spot the flaws in account recovery journeys.

  3. Objective · By the end of this lesson, you will be able to compare authentication factors (SMS, TOTP app, passkeys), choose the ones your product offers or requires depending on the role, and specify activation, recovery codes, recovery and the rollout plan.

When should you let Google, Microsoft or a company's directory authenticate your users, and what do you need to specify?

  1. Objective · By the end of this lesson, you will be able to explain what OpenID Connect adds to OAuth 2.0, decide whether your product offers social login and with which providers, and specify the account linking rules that prevent account takeovers.

  2. Objective · By the end of this lesson, you will be able to specify an enterprise customer's SSO (protocol, domain verification, enforced sign-in, role mapping), choose between just-in-time provisioning and SCIM provisioning, and plan for an employee leaving, break-glass accounts and identity provider outages.

How do you design clear roles and permissions, and guarantee that no customer sees another's data?

  1. Objective · By the end of this lesson, you will be able to build your product's roles × actions matrix, with the scope of each right (whole account, an area, their own items), choose between fixed roles, attributes and custom roles, and write the server-side enforcement rules (deny by default, least privilege).

  2. Objective · By the end of this lesson, you will be able to specify data isolation between the customers of a multi-tenant product, invitations and users who belong to several organizations, support access, the audit log and account deletion.

How do you bring journeys and permissions together in a spec, and should you build authentication or buy it?

  1. Objective · By the end of this lesson, you will be able to specify your product's seven authentication journeys (sign-up, sign-in, forgotten password, SSO, two-factor authentication and passkeys, invitation, account deletion) with their states, errors and messages, and choose between building authentication and using a provider.

  2. Objective · By the end of this lesson, you will have the course's templates, checklists and prompts (roles × actions matrix, session table, journey spec sheet, SSO checklist, journey security checklist), and you will have planned how to apply them to your product over 7 and 30 days.