Authentication & Onboarding Diagnosis

Understand what’s blocking sign-in and onboarding.

For agencies, fractional CTOs, and SaaS teams with users stuck at sign-in or onboarding. I trace one failing journey and help your engineers decide what to repair or investigate next.

Tony St. PierreCognito, MFA, sessions, and account recovery

Recognize the problem

Sign-in succeeds. The user still can’t get in.

Or recovery, invitations, or signup fail for only some accounts. When attempted fixes haven’t held, I build on your team’s observations and trace the affected journey.

I examine application state, sessions, identity configuration, and integrations together. The symptom alone doesn’t tell us which system is responsible.

For broken user journeys; general onboarding conversion optimization is outside this service.

Examples of suitable investigations

  • Users authenticate successfully, then land back on the login screen.
  • MFA enrollment or recovery fails for certain accounts.
  • Password resets complete, but users still cannot access the app.
  • Invitations, email verification, or signup leave application setup incomplete.
  • Migrated accounts behave differently from newly created accounts.
  • Sessions behave differently across browsers, devices, or web and mobile.

What you receive

Evidence your engineer can act on.

The brief connects the observed failure to a repair recommendation or the next useful check. Your team can use it to assign the follow-up work.

A specialist entry point into Production Problem Investigation, with the same fixed-scope package.

  1. Concise journey trace

    Where the flow starts, which relevant systems it touches, and where observed behavior diverges from expectations.

  2. Findings and evidence

    Reproduction conditions and attempts, relevant evidence, confirmed findings, and explanations ruled out—with the reasoning behind each conclusion.

  3. Confidence and uncertainty

    Confirmed behavior separated from hypotheses, with confidence and the evidence still needed.

  4. Repair recommendation

    The recommended change or next investigation step, the relevant code or configuration where identified, and checks to verify a repair.

  5. Technical handoff

    A shareable brief and closing readout. I walk your technical contact through the recommendation and questions for the engineer taking the next action.

If the cause remains unresolved, I state that clearly and document what was learned, what remains unknown, and the most useful next step.

Start with the step that fails.

I’ll confirm whether a focused investigation is useful before we schedule paid work.

Discuss the problem

Findings that support your next decision.

  • Agencies and delivery teams

    I take on the agreed investigation through one technical contact, with concise updates and a handoff for your developers. You keep control of the client relationship; I communicate with your client only as agreed.

  • Fractional CTOs

    I give you evidence to choose between a targeted repair, further investigation, or a broader change. Findings and uncertainty stay explicit, so you can assign work and explain the decision to leadership.

  • SaaS CTOs and technical founders

    I start with your engineers’ observations and attempted fixes, keeping the context I need focused on the failing journey. The handoff includes checks they can use to verify the next repair.

Tony St. Pierre

Your investigator

Application code and identity, considered together.

I’m Tony St. Pierre. I bring 16+ years of software development experience across production web and mobile applications.

  • Authentication and account access

    I’ve built identity and access controls spanning MFA, sessions, and account recovery. My AWS and Amazon Cognito work informs how I investigate remembered devices, migrated accounts, and onboarding transitions.

  • The application around the sign-in

    I work with React, Next.js, TypeScript/JavaScript, and React Native, including multi-tenant platforms and security-sensitive workflows.

AWS Certified Solutions Architect – Professional View my systems experience

How it works

One journey, from scope to handoff.

One technical contact, a short kickoff, and a closing readout.

  1. Scope the journey

    We agree the failing journey, environment, account types, relevant integrations, evidence, access, and start date. One journey may cross several components; those boundaries are scoped together.

  2. Investigate the behavior

    I trace relevant code and configuration, compare working and failing behavior where possible, and test likely explanations. I record the evidence and inconclusive results.

  3. Deliver the findings

    I deliver the brief and explain the recommendation, uncertainty, and repair checks in the closing readout. Your team can act on the findings; any implementation by me is separately scoped.

A scope that fits the cap

Before scheduling, I check whether the question can be usefully investigated within the 8-hour cap. If it needs a broader scope, we narrow the question or agree a separate quote first.

Repairs, authentication migrations, and complete onboarding redesigns are outside the diagnosis fee.

Emergency incident response, ongoing operational ownership, and unlimited follow-up are outside this package.

Access agreed before investigation

I use designated test accounts and synthetic data within agreed tooling and access. Any production validation requires explicit agreement, and sensitive values are redacted from findings.

Diagnosis does not authorize changes to customer accounts, MFA protections, customer sessions, or global identity settings.

Before we begin

A few practical questions.

Is this suitable for Cognito and custom application authentication?

AWS and Amazon Cognito are a particular focus, including the custom application behavior around them. I also assess problems involving other providers against my experience. Share your stack and provider if known; I’ll confirm fit before we agree the engagement.

Can you investigate a problem that only affects some users?

Yes. We agree the account types, environment, and integrations to investigate. I compare behavior using designated test accounts and synthetic data. Describe the affected group in your initial summary without identifying customers.

What if the issue cannot be reproduced?

I document reproduction attempts and use available redacted evidence to test explanations. For intermittent or production-only behavior, the next useful step may be gathering specific evidence. I explain what to observe and how, within agreed access.

What access is required?

Relevant code, configuration, redacted evidence, and designated test accounts in an agreed environment. We arrange access after scoping and explicitly agree any production validation. Please send only a summary in the initial email.

Are fixes included?

Repairs are separately scoped after diagnosis. Your team can implement the recommendation, or we can discuss a separate repair engagement. Expanded scope is quoted before additional work begins.

What happens if the cause remains uncertain?

Root-cause discovery is not guaranteed. You still receive the written brief and readout: established findings, remaining hypotheses, missing evidence, and the most useful next step. Further investigation needs a separate agreement.

Can you work through my agency?

Yes. We agree communication at kickoff. I work through your technical contact, share concise updates, and hand findings to your developers. Client-facing communication happens only as agreed.

Start with a summary

Tell me where the journey breaks.

A few lines are enough; fill in what you know. I’ll confirm fit, scope, and timing before paid work begins. Access and detailed evidence come after that agreement.

In your email, include:

  • Role and company
  • Failing journey or step
  • Who is affected (without identifying customers)
  • Application stack and identity provider (if known)
  • What you have already tried
  • Business impact and desired timing
Discuss the problem contact@tonystpierre.com

Please omit passwords, verification codes, tokens, cookies, customer data, and raw logs. Detailed evidence can be exchanged through agreed channels after scope and access arrangements are in place.