Duo Security is an access security company that helps businesses make sure only the right people, not hackers, can log into their apps and systems, through things like two factor login checks and device trust checks.
Users found the onboarding experience unnecessarily long, and the push notification opt-in rate was lower than desired.
* This onboarding flow was designed 5+ years ago and hadn't been revisited since.
We removed non-actionable screens and brought push notification activation earlier in the flow, within the settings encouragement step, while keeping the practice step optional.
This project put one problem in the middle and the whole team on it from the start, with AI as the shared language between functions.
A few of the wins from this project, more details on the following slides.
We used the Amplitude MCP to surface behavioral patterns in the data, then validated the finding by hand.
Engineering helped set up Xcode and gave me access to the app's repositories, so I could prompt Claude to design and iterate directly in code, moving faster between ideas and working screens.
A full screen-by-screen audit of the onboarding flow, checking each step for purpose and necessity.





Reordered to surface permissions earlier, made Practice Push optional, and removed screens with no meaningful action.
Changes were kept as lightweight as possible. The priority was improving the flow, not a full visual redesign.
After finalizing the screen changes, we used the Jira MCP to have Claude generate a full epic and task breakdown directly from the design decisions — no manual ticket writing.
The actual shipped build — screen recordings captured directly from engineering's Android and iOS implementations.
* Backup steps not shown in this recording.
* Recording starts after the welcome screen.
Shipped behind a remote feature flag, comparing funnel metrics across app versions.
Coming back to the question from the start: what's worth carrying into how we normally work.