Almost every onboarding flow in software is designed for the same person: someone who chose to be there, who is curious, who has energy to explore. We optimize for activation, for the aha moment, for getting them to value fast.

Beneficiary onboarding breaks every one of those assumptions. The person arriving did not sign up. They are very likely grieving. They may be opening BlockWill for the first time, on a phone, in the middle of the hardest week of their life, because someone they loved set this up and the moment to use it has come. There is no aha moment to chase. There is a person who needs to be treated with care and then helped to do one important thing.

This is the story of how we designed that flow, and the decisions we made differently because of who it is for.

Start by naming the emotional state

The first design move was not a screen. It was writing down, honestly, what this person is feeling when they arrive. Shock. Confusion about what BlockWill even is. Possibly suspicion, because an unfamiliar platform is emailing them about a death. Maybe guilt, maybe urgency, maybe exhaustion.

We wrote that emotional state at the top of the design brief and kept returning to it. Every screen had to pass a simple test: would this feel okay to receive on the worst day of your life? That single question killed a lot of patterns that are normal everywhere else in software. No progress bars celebrating completion. No confetti. No upsells. No "you're almost there" cheerfulness. The tone is calm, plain, and quiet.

Lead with the person, not the platform

The first thing a beneficiary sees is not our logo or a feature tour. It is the name of the person who designated them, and a short, human line explaining what is happening: that this person set up BlockWill so that certain things would reach you, and that you are now able to access them.

That ordering is deliberate. The trust the beneficiary needs in this moment is not trust in BlockWill. It is recognition that this came from someone real, someone they knew. So we put that recognition first and let our brand stay in the background. We are the messenger, not the message.

Make the path obvious and singular

A curious new user benefits from options. A grieving first-time user needs the opposite: one clear path, one action at a time, nothing optional competing for attention. We stripped the beneficiary flow down to a single forward path with no side doors.

Each step does exactly one thing and tells the person what comes next. Verify who you are. Here is what has been left for you. Here is how to open it. We removed every secondary link, every "explore more" temptation, every choice that did not need to be made right now. If something can wait, it is not on the screen.

Security that does not feel like an interrogation

The tension at the heart of this flow is real. Inheritance access has to be secure. A beneficiary genuinely does need to verify their identity, because releasing an estate to the wrong person is catastrophic. But verification, done thoughtlessly, feels like being interrogated at the worst possible moment.

So we softened the framing without weakening the security. The verification step (a one-time code to a known contact method, established during the original setup) is explained in one plain sentence about why it exists: to make sure this only opens for you. The language is reassuring rather than bureaucratic. The same cryptographic check is happening underneath, but the person experiences a short, explained step rather than a wall of requirements. Security and compassion were not traded off against each other. They were designed to coexist.

Pace the information

A beneficiary often inherits a lot at once: documents, messages, instructions, sometimes a full vault. Dumping all of it on the first screen would be overwhelming and, frankly, unkind. So the flow reveals things in a humane order. Identity first. Then a gentle overview of what exists. Then access, one item at a time, with the personal messages (DigiWish) surfaced with particular care, because a letter from someone you lost is not a file to be processed. It is a moment.

We also made it completely fine to stop. The flow saves state and lets the person leave and return. No countdowns, no pressure to finish in one sitting. Grief does not keep a schedule, and the product should not pretend it does.

What we measured, and what we refused to measure

We deliberately did not optimize this flow for speed or completion rate. A fast beneficiary onboarding is not a success if it felt cold. Instead we paid attention to whether people could complete the essential task without contacting support in distress, and to the qualitative signal of how the experience felt. The metric we care about is not activation. It is whether someone, later, would say that the hardest day was made a little less hard rather than a little harder.

What this taught us about the rest of the product

Designing for the worst day changed how we think about the whole platform. It is easy to design for the happy, motivated user. Designing for someone at their most vulnerable forces a discipline that improves everything: plain language, single clear paths, security explained rather than imposed, and a refusal to manipulate attention. The beneficiary flow is the clearest expression of what BlockWill is supposed to be, which is infrastructure that shows up well on the day it actually matters.

Frequently Asked Questions

What is a beneficiary in BlockWill?

A beneficiary is a person designated by a BlockWill user to receive access to part or all of their digital estate, such as documents in SecureVault or messages in DigiWish, when an inheritance event is confirmed through VaultRelay.

Does a beneficiary need to set up an account in advance?

No. Beneficiary onboarding is designed for first-time users who arrive at the moment of inheritance. They are guided through a short verification step and then access what was left for them, without needing to have signed up beforehand.

How does BlockWill verify a beneficiary's identity?

Through a verification step established during the original owner's setup, typically a one-time code sent to a known contact method. It confirms the person is who the owner designated, so the estate only opens for the right person.

Why is beneficiary onboarding designed differently from normal onboarding?

Because the user is usually grieving, did not choose to sign up, and is often using BlockWill for the first time under difficult circumstances. The flow removes celebratory and promotional patterns, leads with the person who designated them, and offers a single calm path rather than an exploratory one.

Can a beneficiary take their time?

Yes. The flow saves progress and allows the person to leave and return. There are no countdowns or pressure to finish in one sitting.

What does a beneficiary actually receive?

It depends on what the owner configured. It can include documents from SecureVault, time-released messages from DigiWish, and instructions, revealed in a paced order with personal messages surfaced with extra care.

Is the security weaker because the flow is gentle?

No. The same cryptographic verification runs underneath. Only the framing and language are softened. Security and compassion were designed to coexist, not to trade off against each other.


Further reading: