CRITICAL story-biometric-session-authentication-organization-admin-001 8 pts
8
Story Points
Critical
Priority
Biometric Session Authentication
Feature

User Story

As a Organization Administrator
I want to use Face ID or fingerprint to unlock the app after my first BankID/Vipps login
So that I can access the app quickly without re-entering credentials every session, making it practical to log multiple short activities throughout a busy day

Acceptance Criteria

  • Given I have completed initial BankID or Vipps authentication, When I open the app in a new session, Then I am presented with a biometric prompt (Face ID or fingerprint) instead of a login form
  • Given biometric authentication is enabled, When I successfully authenticate with Face ID or fingerprint, Then I am taken directly to the role-based home screen within 2 seconds
  • Given biometric authentication is enabled, When I fail biometric authentication 3 times, Then I am offered a fallback option to use my password or re-authenticate via BankID/Vipps
  • Given I am on a device that does not support biometrics, When I complete initial login, Then biometric setup is skipped and standard session token resumption is used
  • Given I have enabled biometric auth, When I tap 'Cancel' on the biometric prompt, Then I am offered the option to authenticate with password instead
  • Given biometric authentication succeeds, When my session is resumed, Then I land on the correct role-specific home screen for my assigned organization context

Business Value

Biometric login is identified as a MUST HAVE for all four partner organizations (NHF, HLF, Blindeforbundet, Barnekreftforeningen). Peer mentors like those at HLF who register 380+ activities annually need near-zero friction for repeated app access. Removing password re-entry as a daily barrier directly increases activity registration rates, reducing the systemic underreporting problem all organizations currently experience. This is core to the product's value proposition.