Crit on a two-factor enrollment flow found 3 copy sins: a euphemistic link, a warning that opens with praise, and a screen that never names what it enrolls you in.
Tuesday’s crit took on a flow most rooms would wave through: enrollment day for mandatory two-factor authentication. On the deadline, our customers will get enrolled at sign-in using the phone number on file. The happy path is fine. The interesting design lives in the roughly 5 percent of users it fails: landlines, prepaid phones, invalid numbers, and people who work in places where a mobile phone isn’t allowed through the door. The presenting PM had mapped fallbacks for all of it, which is exactly why the room could spend its energy where it mattered. The words.
First finding: the escape hatch says having trouble setting this up. A designer pointed out that the users who need that link aren’t having trouble. They don’t have a phone, and they know it. The euphemism forces them to diagnose themselves into a vague category before they can get help. His fix: say the situation plainly (I don’t have access to a mobile phone), and better still, split the paths, because trouble and no-phone are different problems with different answers.
Second finding, my favorite: the warning banner for the least secure fallback opened with the phrase while email setup is convenient. The room’s verdict was immediate. Cut the compliment. If the sentence exists to warn, the risk goes first. Praising the option you’re about to warn against buries the one thing the user needs to weigh, and it reads like the interface hedging its own advice.
Third finding, the deepest: the opening screen says verify your phone number while it’s actually enrolling you in two-factor authentication. Verification and enrollment are different consents. A user who thinks they’re confirming a phone number hasn’t agreed to a new sign-in ritual, and the surprise arrives at the worst possible moment, which is their next sign-in with a client in the waiting room. Name the thing the screen is doing, on the screen, before it does it.
Security copy has one job: say the true thing first. The situation before the euphemism, the risk before the reassurance, the enrollment before the verify button.
One more beat worth keeping: a panelist asked whether users could register a second method as a backup, the way Google offers try another way when one channel fails. The answer was off-screen (it needs engineering scoping), but the question widened the design space in a way pure copy critique never would. Good crit rooms do both. They tighten the words on the screen and loosen the assumptions behind it.
We talk about microcopy like it’s polish. In a security flow it is the product. Every pixel in this flow worked before the crit; several sentences didn’t, and the sentences are what users obey, mistrust, or misread at 8am. The room made the flow more honest in an hour, which is a good week’s work for anyone.
The teachable part
Audit your security and consent copy for 3 sins: euphemism in the link, reassurance ahead of risk in the warning, and enrollment that never names itself.