Module
Module 5 of 5Lesson 1 of 2~19 min

Specifying the journeys and choosing a provider

Lesson 1 of the module "Specifying and choosing" in the course "Design authentication and permissions for a product".

Lesson objective

By the end of this lesson, you will be able to specify your product's seven authentication journeys (sign-up, sign-in, forgotten password, SSO, two-factor authentication and passkeys, invitation, account deletion) with their states, errors and messages, and choose between building authentication and using a provider.

Where it fits

Specifying and choosing

How do you bring journeys and permissions together in a spec, and should you build authentication or buy it?

Lessons in this module

  1. Specifying the journeys and choosing a provider (this lesson)
  2. Exit kit and action plan

What you will learn in the course

This lesson is part of the course Design authentication and permissions for a product

  • Distinguish authentication, authorization and session, and specify session durations, sign-out and access revocation.
  • Specify password rules and account recovery journeys following current recommendations (NIST SP 800-63B-4, CNIL, OWASP).
  • Choose strong authentication factors (TOTP app, passkeys), plan their rollout and specify the fallback journeys.
  • Specify delegated sign-in (OpenID Connect, social login) and enterprise SSO (SAML, OIDC, SCIM provisioning) for a B2B product.
  • Design a permission model (roles, attributes, scope) as a roles × actions matrix, enforced on the server side according to least privilege.
  • Specify isolation between customers, invitations, the audit log, support access and account deletion.
  • Specify your product's complete sign-in journeys, with states and errors, and choose between building and using an authentication provider.