LO
2021 – 2024 · Senior Product Designer

Safe.Global

Making shared control of money feel safe.

Safe holds funds no single person controls. I redesigned onboarding, signing and the design system so first-time teams trust it, not only power users.

Client
Safe (formerly Gnosis Safe), smart account wallet
Years
2021 to 2024
Role
Senior product designer, Berlin, hybrid
Products
Web wallet, mobile companion, design system, token launch apps
Safe entry screens before and after the redesign: Welcome to Gnosis Safe on the left, Unlock a new way of ownership and Create account on the right
Left: the first entry when I joined the team. Right: the same entry after my redesign.
SIGNERS THRESHOLD RESULT Signer A · signed Signer B · signed Signer C · not needed 2 of 3 signatures Executed on-chain, irreversible
The product in one picture. Most of my work made each step of this diagram visible to the person signing.
+9%
Onboarding completion, round one
+7%
Safes created, round two
+13%
Executed transactions after the flow redesign
1,000+
Design system Figma copies in month one

From power-user tool to platform

Safe is a multi-signature wallet: every transaction needs approval from a set group of signers. DAOs, protocols and treasury teams use it to hold shared funds.

When I joined, it was turning from a power-user tool into a platform. The audience widened to first-time teams and DAO treasurers, and the interface had not kept up.

Company scale today, not my result: $60B+ in assets, 60M+ accounts, $1T+ in volume (safe.global, 2026).

Every decision carried risk

In a product holding billions, a confusing screen means a lost signature or a signed mistake.

Feeling User action Interface Safe services Systems line of interaction line of visibility 1 Connect 2 Add signers 3 Threshold 4 Deploy 5 First transaction 6 Sign + execute "Is this safe?" Careful "If I lose a key?" "Did it work?" "Can I undo this?" "Who still signs?" Connects wallet Adds owneraddresses Picks 2 of 3 Pays now or later Enters recipientand amount Signers approve,one executes Welcome +wallet picker● tooltips Owner list,address check Threshold picker● tips by signer count Deploy screen● pay now / later● live status Transaction page● plain summary● fewer steps Signer status,execute button● every step visible Wallet detection Address + ENSvalidation Owner + thresholdconfig Relayer,gas estimate Transaction service,nonce queue Signaturecollection Wallet provider Address book Help center Chain: contract Support tickets Push notifications,chain execution ! ! fear point failure point: wrong address, irreversible error ● shipped change
Service blueprint, first visit to first executed transaction. Fear sat at every commitment point, and errors clustered where nothing could be undone.

Fear blocked completion more than complexity

FindingEvidenceChange
People knew the steps but feared losing fundsInterviews, moderated testsSecurity tips, tooltips at decision points
Nobody knew if deployment workedModerated tests, support ticketsLive deployment status
Paying gas before trying the product felt riskyResearch sessionsPay now / Pay later
Signers could not see what one signature coveredUnmoderated tests, analyticsTransaction page with grouped actions
Every change traces back to something users said or did.

What I built, and how

WebOnboarding

1. Fast user activation

Round one: trust at the decision points

Result: +9% onboarding completion, fewer support tickets.

Owner setup with threshold guidance and a live deployment preview. The tip changes with the signer count.
Round two: reach the product before paying

Problem: wallet features were hidden behind the payment for deploying the wallet on-chain. People hit a cost before they saw any value.

Fix: I fast-forwarded that decision in two steps, so users get into the UI faster:

Result: +7% Safes created.

Safe account type choice, shared or single, and the Pay now / Pay later deployment option
Step one: who will use the account. Step two: pay now or later. Deferring the fee turned a commitment into a trial.
WebModular redesignPower users

2. A modular transaction approach

The team wanted a full-screen container. I asked to document every transaction type and state first.

One signing event carries several action groups, each with its own status. A modal could not hold that. The fix: a dedicated, modular page. Blocks are grouped by meaning, every status and signer step is visible, and security shows before the signature.

Every action is a block, so batching fits the same system. Batching lets people do more in one signing event: power users get a better UI, and retail users get the same power.

Result: +13% executed transactions.

Transaction modal states: send token, external checks, confirm and execute, signer confirmations
Before: the modal. Every state, metadata block and signer step documented before any layout work.
Safe Confirm transaction page: send token details, external checks, a confirm step and the transaction status with create, confirmed and execute
After: the transaction as a full page. Details, external checks, the confirm step and the signer status in one view.
Created Awaitingsignatures k/n Ready toexecute n/n Executing Success Failed Replaced by rejection retry with reason shown same nonce irreversible from here, show everything before
The lifecycle every design state maps to. Everything a signer needs sits left of the red bracket.
Add actionalways visible Queue Reordergas, sequence Reviewone summary Sign oncek/n signers Executeall together Empty state: "Batch swaps, approvals, transfers"
Batch flow. The empty state teaches what batching does before anyone needs it.
Batching in the app: several token actions grouped into one signing event.
iOSCompanion app

3. Mobile as a signing companion, not a copy

Built for what people do away from the desk:

Created on webby Signer A Push to phone Reviewplain summary Signphone as signer Threshold2 of 3 met Executed Not on mobile, by choice: building batches and complex contract calls stay on web.
The mobile job in one line: get a pending signature to the right person fast.
FigmaDesign system

4. A design system to empower the ecosystem

Safe became a network of apps. Outside developers needed to build interfaces that match Safe. I adapted Material UI to Safe's standards:

The test: could a stranger build this correctly without talking to me? Result: 1,000+ Figma copies in month one.

Safe design system cover: Design your own smart contract wallet, available in Figma Community
The Safe design system, published in Figma Community.
TEST FOR EVERY COMPONENT: could a stranger build this correctly without talking to me? Material UIbase Safe tokenstheme, white-label Figma library1,000+ copies Contributionguide External apps proposals flow back into the system
From a borrowed base to a system outside teams build on, with a loop for their proposals.
Design system wallet modal components with auto layout and network variants
Wallet modal components with auto layout and network variants.
WebToken launch

5. Token launch under a fixed date

Safe Pass was the hardest. Boost logic had to read as simple, not intimidating.

boostlock duration → small lock medium lock large lock "you are here"
Illustrative: one chart answers the only question people had, how much more do I get if I lock longer. Shape only, not real tokenomics.
Safe Pass: locking, boost and delegation in one place.

What I chose, and what it cost

Iterate or rebuild

Options: full redesign, or targeted changes in rounds

Chosen: targeted changes in two rounds

Gave up: a visible "new onboarding" launch

One flow or persona branches

Options: separate flows for individuals, DAOs and developers, or one modular flow

Chosen: one modular flow. It tested better and avoided three flows of design debt.

Gave up: tailored messaging per persona at step one

Modal or page

Options: patch the modal, go full screen, or map states first

Chosen: map every state, then design the page

Gave up: speed to the first visual

Mobile parity or companion

Options: full parity with web, or a focused companion

Chosen: a companion built around signing

Gave up: complex actions on mobile, like building batches


Trust became the product

Unvalidated:

Learned:

Beyond crypto: shared control of money is the same problem in a family health account, a nonprofit treasury or a care team approving payments. Approvals, roles, visibility and recovery work the same way.

Role
Senior product designer: research, interaction, visual design, system
Ways of working
Iterative releases, state documentation, cross-team reviews, contributor docs
System
Material UI adapted → tokens → Figma library → contribution guide