Case · UK & EU B2B payroll SaaS
SSO was live. Activation was not.
Role-based onboarding and permission clarity after SSO. Admins saw empty states. End users bounced between docs and support. No signed-off metrics on this case.
Admin 1
- WorkspaceOwn setup
- Invite laterAfter value
Operator 1
- Run cycleNow
- First sittingNot a tour
Finance 1
- Approve payCan run
- RolesDeferred
Permissions
Missing access is a sentence, not a dead end.
Copy that names who can grant the role. Empty states that point at the next setup task, not a generic illustration.
Can run now
- FinanceRun cycleYes
- AdminSSO liveYes
Invite later
- Invite rolesAfter value
Workflow
Admin and champion run in parallel. Not one generic checklist.
Funnel analysis, session replays, and eight stakeholder interviews across finance and IT buyers. Seeded templates per vertical. Progress tied to real setup tasks.
- SSODone
- Link bankDone
- Run test cycleNow
- Invite rolesAfter value
This cycle
- ShawReadyOk
- PatelHoldHold
Hesitation
The product opened. Nobody knew who they were.
Admins landed in a blank workspace
SSO had succeeded. First-run had not. The happy path assumed an admin who already knew the product.
“You don’t have access”
Roles existed for sales and security. New users had no path to the person who could grant them.
Growth and compliance wanted different first weeks
Conflicting KPIs and noisy legacy segment data. The onboarding had to hold both without becoming a tour.
System
Integration health in the product. Identity at the edge.
Experiment flags. Entra and Okta edge cases. Event taxonomy aligned to growth dashboards. Status visible where operators need it, not in a status page they never open.
- SSOEntra / OktaOk
- BankLinkedOk
- PayrollProviderWatch
Refined product
Role paths. Permission copy. Health in-product.
- SSODone
- Link bankDone
- Run test cycleNow
- Invite rolesAfter value
- PatelThis cycleHold
Illustrative · narrative case · no signed-off metrics