Published · 5 min read

Accident investigators still use a model James Reason set out in his 1990 book Human Error. Defences are layers, each with holes that open and close as conditions change. A hole in one layer is usually caught by the next. Harm gets through only when holes in several layers line up at once, and investigations tend to find the last hole and stop. The model's current name, Swiss cheese, came later.
A signup page conversion audit is a structured read of a signup page for whatever stops a visitor who arrived wanting to sign up: an ask that comes before the value is clear, a step whose outcome nobody states, a worry left unanswered, an option they expected and cannot find. Each is a hole in one of their reasons to keep going.
Each sits in a different layer.
The usual approach is to find the broken element, repair it, and leave small defects alone because none loses anyone by itself. The layered model disagrees with the second half.
Each problem above is survivable alone, because another reason to continue catches most visitors. An invented case: a visitor unsure what the trial involves meets a required phone field, and the Google sign-in they use everywhere is not offered. They would have pushed past any one of those, and together they leave. Field analytics blame the phone field, where the typing stopped, though the other two holes were open first. One r/GrowthHacking poster wrote in July 2026: "Then I actually looked at where people stopped, and the story was completely different from what I expected."
So you only need to close one hole on the path, and the cheapest often does it: a sentence saying what happens after the button. Rebuilding the whole page instead opens holes you never mapped.
The conversion friction entry covers losses multiplying across steps in sequence. Within one page the reasons to continue overlap, so a loss needs several to fail for one person at once.
You need a phone, a notepad and a few minutes.
When Nudgent audits a signup page, each hole is scored under the question it weakens: value after the ask against Motivation Strength, an unstated next step against Comfort Level, a missing expected option against Decision Clarity. Findings are ranked so the cheapest hole on the path goes first, per the methodology.
We have no current signup-page audit to show this on. The nearest case is our own homepage, a landing page, audited on 18 September 2026. Its top three findings surrounded one ask, the URL field in the hero: no privacy promise beneath it (Comfort Level), hero and header buttons labelled differently (Decision Clarity), no named user quotes (Trust Signal).
The model has limits. Its holes are not independent: one slow page load can open several at once. And any read of the page, ours included, shows where holes are without showing which combinations lined up for real visitors. That needs behaviour data, and even session recordings and rage-click flags show where someone stopped more readily than what they doubted.
Your analytics can show the field where a visitor stopped. What in your stack records which other holes were open when they got there?
Whether the page answers what a visitor needs before the form asks for anything: the value before the ask, the likely worries (a card charge, a sales call), an obvious next step, enough safety for a work email, and a sign it was made for someone like them.
Someone who starts typing wanted to sign up, so what stops them is usually a field landing on a doubt they arrived with, like a phone field while they still wonder whether sales will call. Analytics blame that field, though it was often the last of several reasons that failed together.
It depends on what the page has already said. A card field is survivable once the page says what the trial includes, when the first charge lands and how to cancel; before that, it tends to be the last hole. Test every field by asking whether you can say what it is for in a sentence the visitor would accept.