2020Enterprise mobile product, identity experience, and incident response

MYID Mobile App

A mobile identity and incident-response product that helps people understand a security event and take the right next step.

MYID mobile application interface presentation
Core Infinite / ProjectMobile + UI/UX
Client
MYID
Status
Active mobile product
Disciplines
Mobile, UI/UX
Services
Mobile Apps, Product Design

A mobile app that helps people complete identity checks, respond to incidents, and receive security notifications within an organization.

What we made, why it mattered, and how it came together.

MYID Self Verify brings identity self-service, suspicious-activity response, notifications, risk information, MFA, and security learning into one organization-aware mobile app.

The product is built for moments when clarity matters. A person can receive an alert, review the available activity details, decide whether the activity was theirs, and then close the incident or protect the account by ending sessions and changing the password.

The same experience adapts to different organization settings and sign-in methods, so people can manage their account without needing to know how those services are connected.

Manage ID

Everyday account care

People can update identity details, credentials, recovery information, and MFA from one place.

Protect ID

Security posture

Risk, password health, device context, recent activity, and optional response tools stay connected.

One flow

Incident response

An alert moves from understandable evidence to a clear decision and the right follow-up action.

Adaptive

Organization-aware

Branding, sign-in, menus, and available actions change with the organization's setup.

Turn a security alert into a clear and confident next step

An incident screen must show enough detail for a person to decide without burying them in security tooling. Time, activity, source, destination, network, and location information need a clear reading order.

The app also has to adapt to each organization's sign-in, password, recovery, MFA, and incident tools while still feeling like one product.

Some actions can reset credentials, end sessions, or isolate a device. Their consequences must be clear before a person agrees to them.

What we had to balance

Urgency versus enough context to decide

Enterprise complexity versus mobile self-service

Organization differences versus a familiar experience

Faster response versus informed consent

Useful incident detail versus personal-data protection

Our approach

Organize the product around what the person needs to do

Manage ID handles everyday identity care. Protect ID brings together risk and response. Alerts take urgent activity straight into a focused review flow.

Critical moments are written as a sequence of understandable decisions: what happened, what details are available, what each choice does, and what comes next. The technical setup stays out of the way.

  • Explain the event in plain language before showing account and network details.
  • Make confirm and deny clearly different in wording and consequence.
  • Hide actions that are not available for the organization.
  • Keep identity care, protection, learning, and urgent response connected but distinct.
  • Ask for clear confirmation before automatic or high-impact actions.
  • Treat notification, identity, device, and incident data with care.

Employees and account holders

People who need to sign in, maintain identity details, manage MFA, and respond to account alerts.

People reviewing an incident

Users who need clear evidence, a simple decision, and guided protection under time pressure.

Security teams

Teams that need a person's response to connect with the wider incident process.

Identity administrators

Teams supporting different sign-in, directory, MFA, password, and organization settings.

The experience, step by step.

  1. Recognize the organization

    Branding, sign-in, menus, password behavior, and available identity actions load from the organization's setup.

  2. Sign in the right way

    The app presents the password, company sign-in, OTP, recovery, or optional biometric path available to that person.

  3. See what matters now

    The home screen brings notifications, password status, MFA, identity care, protection, and learning into one clear view.

  4. Receive an alert

    Remote and local notifications keep urgent account or incident state available when the app is reopened.

  5. Review the details

    The warning view shows the activity, time, source, destination, network, location, and deeper context when available.

  6. Confirm or deny

    A confirmed activity can be closed. A denied activity can end active sessions and lead directly to a password change.

  7. Keep the identity healthy

    Manage ID and Protect ID connect account details, password, recovery, MFA, risk, devices, and learning.

  8. Choose future protection

    Automatic response can be enabled only after the user sees what it may do and agrees to those consequences.

How the different parts work together.

Each feature supports the wider experience instead of standing on its own.

Organization-aware access

Organization settings control sign-in, branding, menus, password rules, and the identity actions that are available.

  • The organization's existing sign-in service
  • Enterprise directory and account recovery
  • Password, account unlock, and recovery
  • MFA enrollment and management
  • A web route when the organization requires it

Incident review

An alert connects the user's decision to the incident details and the correct follow-up action.

  • Plain-language suspicious-activity summary
  • Time, source, destination, network, and location context
  • A path to deeper activity details
  • Deny with session ending and password change
  • Confirm with incident closure and response note

Manage ID

Routine identity work is grouped away from urgent incident response.

  • Password updates and recovery
  • Account unlock
  • Email and phone details
  • Security questions
  • MFA setup and management

Protect ID

Protection brings together recent activity, account posture, device context, and response choices.

  • Account risk
  • Recent activity
  • Password health
  • Device context
  • Optional automatic response

Notifications

Remote alerts, local presentation, saved alert details, and the in-app notification list point back to the same response flow.

  • Remote push notifications
  • Local high-priority alerts
  • Incident and account-lock handling
  • Time-ordered notification history
  • The alert restored when the app reopens

Light and dark themes

Clear color roles keep text, actions, alerts, fields, icons, and loading easy to read in both themes.

  • Action Blue #478DE0 on light surfaces
  • Charcoal #353535 for text and dark backgrounds
  • Action Gold #FEC92D on dark surfaces
  • Separate roles for fields, dividers, tips, and loading

Key decisions

What we chose and why.

Keep urgent alerts

DecisionSave incident and account-lock details when a notification arrives.

ReasonA serious alert should still be there after the app is backgrounded or reopened.

Show evidence first

DecisionPlace the available activity details before the confirm and deny actions.

ReasonUrgency is not enough. People need a basis for the decision.

Guide the deny path

DecisionConnect a denied activity to session ending and password recovery.

ReasonThe response should protect the account, not stop at a warning message.

Explain automatic response

DecisionRequire confirmation and accessible terms before automatic protection is enabled.

ReasonActions that can reset credentials or isolate devices need informed agreement.

Keep biometrics optional

DecisionOffer device biometrics as a convenient return path after the account is set up.

ReasonIt can reduce friction without becoming the only way back into the account.

Hide the setup

DecisionPresent sign in, unlock, update, verify, and manage MFA as familiar tasks.

ReasonPeople should not need to know how the organization connects its account services.

How the details support the experience.

Reading order

Evidence is broken into calm, scannable rows

The incident screen starts with a clear question, then organizes activity, time, source, destination, network, and location into labelled blocks before any decision is requested.

  • A plain-language question first
  • One label and value group per row
  • Network and location shown together
  • Actions placed after the evidence

Adaptive home

Organization policy shapes the actions, not the whole experience

Sign-in type, password status, notifications, MFA support, and organization settings decide which cards and alerts appear. The home screen stays familiar while irrelevant actions stay out of the way.

  • Clear password status
  • Visible notification count
  • MFA shown only when supported
  • Cards that adapt to narrow and wide screens

Color in daily use

Light and dark themes keep actions distinct

Blue leads actions on white, while gold leads actions on charcoal. Text, icons, fields, dividers, tips, and loading each have their own color.

  • Blue #478DE0 for light-theme actions
  • Gold #FEC92D for dark-theme actions
  • Charcoal #353535 for dark surfaces and light-theme ink
  • Theme-specific supporting colors

Guidance

Animation supports the copy instead of replacing it

Illustrated motion helps with biometrics, warnings, notifications, management, protection, and empty screens. Every important action still has a clear title and label.

  • Written guidance beside motion
  • Dedicated warning and empty screens
  • Text labels on critical actions
  • Reduced-motion behavior for looping illustrations

How the product works behind the scenes.

Shared mobile foundation

One app brings identity, alerts, and account care together

The app brings organization settings, saved account details, notifications, personal preferences, sign-in services, and incident actions into one mobile experience.

  • Shared Android and iOS code
  • Remote alerts and notification history
  • Local notifications
  • Optional device biometrics
  • Organization-driven routes and themes

Identity connections

Different setups support the same user goals

Sign-in, password, unlock, MFA, profile, incident, and session actions connect through the organization's setup while the app keeps the tasks familiar.

  • Organization-specific sign-in
  • Password and recovery actions
  • MFA management
  • Incident and session actions
  • Clear loading and error feedback

Incident actions

The user's decision carries through to the response

Deny can end sessions, record the response, and open password recovery. Confirm can close the incident and record the answer. Feedback and navigation follow the result.

  • Distinct confirm and deny effects
  • Visible success and permission feedback
  • Response notes tied to the incident
  • Next steps matched to the outcome

Keeping alerts in sync

Remote, local, and in-app alerts meet in one flow

Incoming alerts save the relevant details, refresh the visible history, and open the right response path when the user is signed in.

  • Background notification handling
  • High-priority local presentation
  • Time-ordered visible history
  • Saved alerts restored on the home screen

The details that keep the experience dependable.

Clear decisions

High-impact actions explain what happens next

Confirm, deny, password recovery, session ending, and automatic response use distinct wording and follow-up so a person can understand the consequence before continuing.

  • Evidence before action
  • Distinct labels and outcomes
  • Confirmation for automatic response
  • A visible recovery path

Privacy

Incident details stay out of public storytelling

Names, devices, network addresses, locations, incident identifiers, and organization settings are sensitive. Public case-study media uses redacted or fictional examples.

  • Redacted screenshots
  • No customer identifiers or tokens
  • Only the context needed to explain the flow
  • Restricted access to real incident records

Accessibility

Critical actions use words, structure, and more than color

Headings, labels, icon-plus-text detail rows, flexible layouts, and light and dark themes make the core flow easier to scan and understand.

  • Clear confirm and deny labels
  • Large-text support for evidence and dialogs
  • Status communicated beyond color
  • Reduced motion for looping illustration

Continuity

Urgent alerts remain available after the app moves to the background

Incident and account-lock details are saved before navigation so the home screen can restore the right path when the user returns.

  • Urgent alert details saved early
  • Notification history refreshed
  • Permission errors shown clearly
  • A useful next step after failure

A direct bridge between the person, their account, and the security response

MYID brings account care, notifications, incident evidence, response, password recovery, MFA, risk, learning, biometrics, and optional automatic protection into one mobile product.

Its clearest value is the flow. An alert can reach the device, remain available after the app moves to the background, open a clear decision, and connect the person's answer to the right account action.

What we delivered

  • Sign-in and available actions adapt to the organization's identity setup.
  • Remote alerts, local notifications, and notification history connect to incident and account-lock flows.
  • Incident views show useful context before a person responds.
  • Confirm and deny lead to different actions and follow-up.
  • Manage ID and Protect ID bring routine identity care and security posture into the same app.

Start a project

Tell us what you need to build.

Share the product, the current stage, and the support you need. We will reply with practical next steps.

Start a project