
Securing 125,000+ advertisers without slowing them down
Moloco's first multi-factor authentication, designed 0-to-1.
Role:
Senior Product Designer (sole designer, end to end)
Team:
1PM & 2 ENG
Timeline:
3 months
The problem
Moloco's Campaign Manager let advertisers manage large budgets and live campaigns, but the platform had no dedicated account-security layer, leaving advertiser data and spend exposed. The real challenge wasn't "how should MFA work." It was where security should enter a workflow used by people actively managing live campaigns, without making the product feel harder or less trustworthy.
The tension
More security protects advertisers, but every added step introduces friction into highfrequency, high-stakes work. The design job was to balance protection against flow

The hardest decision
I began with a pattern analysis of how trusted platforms handle authentication, then worked with security engineers to map every edge case: lost devices, expired codes, lockouts, and account recovery. My first instinct was to make MFA mandatory everywhere. Research and operational constraints pushed me toward a model that protected sensitive actions without re-challenging users mid-workflow. I designed the full flow, enrollment, verification, error states, and recovery, and ran my own QA alongside engineering rather than waiting for handoff.

The system
Login, then a risk and trusted-device check, then a challenge only if needed, then verification, then recovery. Enrollment and device management live in a separate, calm settings flow. [diagram + verification and enrollment screens]
Impact
Launched Moloco's first MFA experience end to end, protecting 125,000+ advertisers with zero disruption to existing campaign workflows.
What I'd change today
If scope and time permit, I'd explore adaptive, risk-based authentication, using signals to challenge only when risk is elevated, rather than a uniform experience for every user.