Specifying the journeys and choosing a provider
Lesson 1 of the module "Specifying and choosing" in the course "Design authentication and permissions for a product".
Lesson objective
By the end of this lesson, you will be able to specify your product's seven authentication journeys (sign-up, sign-in, forgotten password, SSO, two-factor authentication and passkeys, invitation, account deletion) with their states, errors and messages, and choose between building authentication and using a provider.
Where it fits
Specifying and choosing
How do you bring journeys and permissions together in a spec, and should you build authentication or buy it?
Lessons in this module
- Specifying the journeys and choosing a provider (this lesson)
- Exit kit and action plan
What you will learn in the course
This lesson is part of the course Design authentication and permissions for a product
- Distinguish authentication, authorization and session, and specify session durations, sign-out and access revocation.
- Specify password rules and account recovery journeys following current recommendations (NIST SP 800-63B-4, CNIL, OWASP).
- Choose strong authentication factors (TOTP app, passkeys), plan their rollout and specify the fallback journeys.
- Specify delegated sign-in (OpenID Connect, social login) and enterprise SSO (SAML, OIDC, SCIM provisioning) for a B2B product.
- Design a permission model (roles, attributes, scope) as a roles × actions matrix, enforced on the server side according to least privilege.
- Specify isolation between customers, invitations, the audit log, support access and account deletion.
- Specify your product's complete sign-in journeys, with states and errors, and choose between building and using an authentication provider.
Related courses
- Git for PMs: ship as a team without putting production at riskAdvanced · ~3 hr 30 min
- Explain how a web product works, from browser to serverAll levels · ~2 hr 30 min
- Design and test an API integration as a PMJunior · ~3 hr