Ther is a vital subtlety here that is frequently (almost always?) missed. The things that the user does must refer to things that they have to do regardless of the system being used, not things that they are forced to do by the system. For example, if they are trying to do something that only a certain group of users are authorized to do, they must prove that they are part of that group of users, not "enter username and password".