AI and automation, products, and company sites for remote clients. Designed and built by one person.

Say hello
Obed Johnson

Engineering · 4 March 2026

Design the failed login path first

A sticky note with a new password on a laptop

Every login demo I have seen shows the same thing. A valid email, the right password, a session, and a dashboard. That path almost never breaks, so it is the last one I worry about.

The trouble is on the way back in. A code expires while someone looks for their phone. An old attempt is still open in a second tab. They signed in with a personal account, switched to the work one, and the return URL now points at a workspace they can't open. Single sign-on hands them back to the app without the state it was holding.

So I sketch that sequence first: what gets stored, what is allowed to expire, and what the person sees when the round trip doesn't finish. Each failed return gets a screen that says what happened in plain words and offers one next step. A generic error, or a silent bounce back to sign-in, is usually the moment someone decides the product is broken.

Permissions go on the same sketch. A session can be valid and still not be allowed onto the page it was sent to. “You don't have access to this workspace” is a different message from “That code didn't work”, and I don't let the two share a screen.

If MFA or SSO is in scope, I don't count the login as done until each of those branches has a screen, a sentence, and a way forward. The happy path can stay short.