Case Study
Applying B = MAP
Passkey adoption stalled despite being "easy." Shifting to motivation-driven messaging drove a 30% lift and 6M enrollments.

A passkey sign-in prompt tested "easy" in usability testing and still went mostly ignored. The fix wasn't a better button — it was recognizing that ease was never the problem. Applying B.J. Fogg's Behavior Model to the content strategy drove a 30% lift in adoption and, six months later, +6M passkeys created across CVS.
Password recall was CVS's number one cause of digital sign-in errors — roughly three-quarters of all sign-in errors and about a third of customer support comments, by Adobe Analytics and Medallia's own measurement. Underneath that was a second, quieter cost: three separate CVS business units — Retail, Pharmacy (Caremark and Specialty), and Aetna — each maintained their own authentication codebase, tripling the engineering cost of every future sign-in change.
I led design and research for CVS's passkey (passwordless) sign-in end to end: facilitating the technology-evaluation workshop that selected passkeys over magic links, OTP, MFA, and SSO; designing and shipping the MVP; and then, once adoption stalled, running the research phase that diagnosed why and rebuilt the content strategy around it.
01When "easy" isn't the problem
The MVP tested well and still underperformed — because ease of use was never what was missing.
The MVP passkey prompt shipped after a perception-and-comprehension usability test that rated it easy to use. But post-launch, rejection rates ran 83% on CVS.com, and 70% of CVS Specialty users stayed on email and password rather than switch. Two lines of business, two different entry points into the same idea — neither one giving users a reason to care.

The diagnosis came from B.J. Fogg's Behavior Model, B=MAP: a behavior only happens when Motivation, Ability, and a Prompt converge at the same moment. The MVP had solved Ability — biometric sign-in is objectively less effortful than typing a password — but the heading, "Go Passwordless," named the mechanism, not a reason to want it. Comprehension testing confirmed users were left with only a partial mental model of what a passkey even was. Ability without Motivation doesn't move behavior; B=MAP predicts exactly this failure mode.
02Rewriting for Motivation, Ability, and Prompt
Three separate levers, three separate fixes — validated individually before they were validated together.
"Go Passwordless" became "Tired of resetting your password?" — reframed around the pain users already feel and the fear it'll happen again, in their own words from comprehension testing rather than internal terminology.
One dense, feature-first paragraph became three scannable cards — Simple, Secure, Private — each an icon plus one plain-language sentence, reducing working memory load to parse.
The prompt moved from a generic sign-in screen to firing during password reset — when the user was already re-authenticating via one-time passcode, satisfying security review while reaching peak motivation.

The Prompt change carried its own constraint: security review required the passkey offer to appear only once identity was already verified, not before. Sequencing it into the password-reset flow — after the one-time passcode step, before the new password screen — satisfied that requirement while putting the offer in front of someone at the exact moment they were most motivated to never do this again.

03Proving it before shipping it
An 80-participant, between-subjects usability study, run before the redesign ever reached production.
Rather than ship on conviction, I validated the rewritten content against the original in an unmoderated, between-subjects study: 80 participants split into two groups of 40, recruited via UserTesting.com to matching criteria — signed into CVS.com in the past 30 days, reset a CVS.com password in the past 30 days, iPhone users. One group saw the existing content, the other saw the redesign; both were given the same task: "You don't remember your password. Using this website, find another way to access your account."
| Self-reported measure | Existing | Redesign |
|---|---|---|
| Ease of use | 3.4 / 5 | 4.8 / 5 |
| Trust ("passkeys are more secure than passwords") | 3.0 / 5 | 4.4 / 5 |
| Likelihood to recommend | 3.8 / 5 | 4.8 / 5 |
A separate four-item comprehension battery — whether participants believed they could use a passkey across devices, whether they'd still need a password afterward, whether passkeys were more secure — showed the same pattern, every difference statistically significant at p < .01 or better.

04What shipped, what it did
Six months after rollout: password reset traffic down 18%, password-related support comments down 10%, password-triggered sign-in errors down 66.96%, and locked accounts down 27.18%. Sign-in success rates improved on both properties — CVS.com from 82.17% to 93.31% (+11.14 points), CVS Specialty from 85.6% to 93.57% (+7.97 points) — and the original problem-statement metric, the share of traffic navigating to password reset after a failed attempt, fell from 6% to 3%.
The pattern this research produced didn't stay a CVS.com fix. It scaled to all three lines of business it was originally built to unify — CVS.com, Caremark, and Specialty Pharmacy — replacing what had been three separately maintained sign-in implementations with one shared approach, and cutting the engineering cost of every future authentication change from three updates to one.
This is the shape of it. The full case study goes deeper into the original technology evaluation (why passkeys beat magic links, OTP, MFA, and SSO), the accessibility and inclusive-language work baked into the MVP, and the developer handoff behind the shipped redesign — happy to walk through it in detail.