← Back to homepage

One feature. Four gaps.

Explore an illustrative Sorno review, the context behind each issue, and what the team needs to resolve.

Interactive example

Required two-factor authentication

Project goal: Require 2FA for password and Google sign-in.

4 open in this project

Uses sample data; no tools are connected.

↳ Missing workflow

No recovery flow for a lost phone

The designs cover entering a verification code, but not recovering access without the authentication device.

Figma · Authentication designs
Normal verification
Enter codeVerification succeedsAccess
Lost phone
Cannot access codeRecovery flow missing

Reviewed flows: enrollment, code entry, invalid-code feedback, and successful verification.

Why it matters Users who lose their authentication device have no designed path to regain access.

Next step

Resolve the recovery-policy conflict, then add the agreed recovery flow.

Explore the evidence. Follow the work as it changes.

The wider project context

Same sample project

Catch conflicts across projects.

The authentication and mobile sign-in projects both depend on the same required-2FA policy.

Shared requirement: Verify before access.

Authentication project

Required behavior
VerifyAccess
Verification required
⇄

Mobile sign-in project

Current implementation
Sign inAccess
! Verification missing

Mobile sign-in still bypasses the verification required by the shared policy.