Two halves of one argument. The journey map plots every surface in the portal against the moment it actually matters, and against how loud the app is today. The redesign throws the prototype away and asks what the app would be if it were derived only from what is true about the business.
The chart starts where the portal does. Access begins when the deposit clears — typically six to eighteen months out, sometimes far less. Before is split into four sub-phases separated by gates, and the columns are gates, not durations: a late booking passes two or three of them at once.
The journey map
The green steps are how much a guest needs that thing — four levels only, off / low / medium / high. The grey slab behind is what the app does today. Where a flat grey slab runs under green steps that rise and fall, the app is at a constant volume when the need is anything but.
How much the guest needs it — editorial judgement, not measuredHow loud the app is today (tab = tall, three taps deep = short)Not built
Why the grey layer is so flat
The prototype’s before / during / after control reaches exactly one screen. state.phase is read inside screens.today at app.js:367 and nowhere else that renders; NAVTABS is a constant; thirteen of fourteen screens are byte-identical across phases. There is no notion of sub-phases at all, which is why every grey slab runs perfectly flat across all four Before columns.
To be fair to it: payment and traveller details are correctly scoped to before — but by accident, because they are only reachable from the pre-trip checklist inside coverBefore. Right behaviour, arrived at in a way nothing else can inherit.
The four gates before departure
A gate is only useful if the system can tell it has been passed. Two of these are state — something happened, and it can happen at any time. Two are date — counted back from departure off the booking. Mixing them is deliberate: the early half of Before is driven by what the guest has done, the late half by how close the flight is.
Gate — opens the phase
Sub-phase
The one thing being asked
Typically
1
Deposit cleared State
Welcome The portal exists, and almost nothing is due.
Tell us who is travelling. Full names as printed, passports, nationalities. This is the only real ask, and it blocks everything downstream.
6–18 months out. Can be weeks.
2
Details in → flights ticketed State
Trip-ready The long, quiet middle. The phase the portal has nothing for today.
Get yourself trip-ready. Vaccinations, visas, insurance, and choosing what fills the free days — everything with real lead time, prompted early with a margin rather than on an exact date.
Opens as soon as details land. Often months.
3
Balance notice Date — T−90 or T−60
Balance One job, loudly, with nothing competing for the screen.
Settle the balance. Plus the last call on anything with lead time, because after this the itinerary hardens.
2–4 weeks. Varies by agent.
4
Documents released State
Final approach The portal changes character — from admin to travel kit.
Pack, download, go. Bag limits, weather, vouchers saved offline, contacts on the phone.
Last ~2 weeks.
5
Wheels up Date — departure
During No sub-phases. The day is the unit.
What is happening today, and who do I call.
The trip.
6
Homecoming Date — return
After No sub-phases, but the longest tail.
Keep the trip, and eventually plan the next one.
Indefinite.
Why gate 2 is a state and not a date
Traveller details do not block the balance — they block ticketing the intra-Africa flights, which happens far earlier. Once those tickets are issued the names are frozen and a correction costs money. So the moment details land, the portal should change what it says about them: from “we need these” to “these are locked — tell us immediately if anything is wrong.” That is a genuine state change the system already knows about, because the item carries a reference.
Be generously early, never precisely late
Across Southern and East Africa — and especially Angola or the DRC — entry and health lead times vary enormously and move without warning. The wrong answer is to hold a precise per-country database and quote exact deadlines from it: it will rot, and when it rots it fails in the direction that hurts — telling someone they have fourteen days when the queue has quietly become thirty.
So the rule is a margin, not a date. State an exact date only when it comes from the booking or from a regulation — the balance date is contractual, yellow fever is valid ten days after the needle, the flight leaves when it leaves. Everything else gets a generous window: “worth starting in the next month or two”, prompted early enough that being wrong by weeks costs nothing. Coarse and early beats precise and brittle, and it removes an operational commitment nobody wants to own.
The During column is the download manifest
Connectivity fails exactly where the trip is best — bush camps, long drives, borders. So the app has to work as an offline artefact from wheels-up, and everything it needs must already be on the phone. That set is not a separate design question: it is the During column of the chart, read downwards. Anything scoring medium or high there has to be cached at gate 4, and gate 4’s real job is making that download a moment the guest actually completes rather than a pill that claims it already happened.
The uncomfortable half: three things peak During and need signal to work — reserving a table, asking the travel designer, and adding anything to the trip. They will fail precisely when they are wanted. Those need to compose offline and send when a bar appears, and to say so plainly rather than spinning.
The long middle is worked, not waited
With an eighteen-month lead, gate 2 can run for a year — but it is not silent. The travel designer is in touch, and automated nudges can carry the rest: “your trip is nine months away, here is what is worth starting”. So the question is not whether anyone comes back. It is what those nudges land on, and today the two things worth landing on — destination content and choosing what fills the free days — are both buried two taps inside the Trip tab. Every outbound message should have a screen behind it that is worth the tap.
Seven things that are true regardless of design
Not preferences. Facts about the product and the operation, which any design has to survive.
Access starts at the depositTypically six to eighteen months out, sometimes six weeks. The app has no pre-sale life, and the lead time is wildly variable.
Nobody from the company is on the tripThe lodges guide; we do not travel with the guest. There is no camera, no on-the-ground staff, no live feed.
Connectivity fails where the trip is bestBush camps, long drives, borders. The app has to work as an offline artefact.
We ticket the flights inside AfricaSo passports are needed early, and at ticketing the names freeze and corrections cost money.
Ten-plus countries, lead times that moveSouthern and East Africa, up to Angola and the DRC. Entry and health requirements differ by months, depend on routing, and change without telling anyone.
Consultants do not write per-client proseAnything that needs authoring per trip will not get authored. Everything the guest sees is either derived, curated once, or chosen from a list.
Every trip has a named human on itThe travel designer is the single largest asset the app has, she is in touch through the wait, and it is not a feature anyone else can copy.
Seven principles that fall out of those
One job per gate
If you cannot say what a screen is for in one sentence, it is the wrong screen. Six gates, six sentences. Everything that is not this gate’s job is below the fold or in another tab.
The device is the medium; the network is a bonus
From wheels-up the app is an offline object. That makes the download a designed moment, not a background nicety — and it means anything that needs signal must say so and degrade honestly rather than spin.
Lead time is the organising axis, not category
A restaurant with a three-month waiting list and a private guide are the same kind of thing. A walk-in bistro and a lodge game drive are the same kind of thing. Sort everything the guest must decide by when it needs deciding, and the categories stop mattering.
Be generously early, never precisely late
Quote an exact date only when it comes from the booking or a regulation. Everything else gets a window with a margin in it — prompted early enough that being wrong by a fortnight costs nobody anything. Precision you cannot maintain fails in the direction that hurts.
Never ask for what can be derived
The booking knows the stops, dates, nights, countries, routing, inclusions, free days and due dates. The only legitimate asks are passports, preferences and choices.
The long middle needs a reason to return that is not a task
Tasks run out in the first month. If gate 2 can last a year, the thing that brings someone back is the trip itself — where they are going and what it will be like.
Demote, never delete
A gate changes what is loud, never what exists. Everything stays reachable, because a guest mid-trip may still want to see what they paid.
The shell: three tabs, and one of them moves
A four-tab bar is what apps look like, not what this app needs. There are only two things that exist at every gate — what is happening now, and the trip itself. Everything else is either the current gate’s work or the paperwork, and those two never overlap in time.
So: Now and Trip are permanent. The third slot is whatever this gate needs — Get ready, then Wallet the moment documents are released, then Share once home. And the travel designer is not a tab at all: she is a face in the header at every gate, because a person should not be filed under a section.
Gates 1–3
NowTripGet ready
Gates 4–5
NowTripWallet
Gate 6
NowTripShare
What is on the screen, gate by gate
Wireframes, not designs. Dark blocks are the hero, green is the one job, dashed is present but quiet.
1WelcomeDeposit paid
Get the passports. Nothing else is due.
magicsafariEM
Kenya & TanzaniaSeptember 2027 · in 14 months
Passport details — 1 of 4 inWe ticket your flights inside Africa, so we need these before anything else
Your route4 places · 12 nights · map
Where you’re stayingFour properties, with the reasons they were chosen
September in the MaraWhat the trip is actually like in your month
Elise Malan — say hello
NowTripGet ready
Deliberately absentPacking · payment · vouchers · contacts · weather · and any countdown in days — at fourteen months it is months.
2Trip-readyDetails in
Start the things with lead time. At your own pace.
magicsafariEM
In 9 monthsFlights ticketed — your names are locked in
Three things worth startingYellow fever — allow a couple of months · Kenya travel authorisation — plenty of time, don’t leave it late · Insurance — now, while the deposit is at risk
Two open days in the SerengetiWorth deciding early — the good ones go
Three tables worth booking nowThe rest can wait until you’re there
September in the MaraStill the reason to come back
Ask Elise anything
NowTripGet ready
Deliberately absentPacking · vouchers · the balance (not due) · same-day dining · anything with a deadline that has not started counting.
3BalanceBalance due
Pay. Nothing competes with this.
magicsafariEM
£18,400 due 12 JulyYour balance · 34 days
When this clearsYour documents are released and the trip goes onto your phone
Still outstanding: yellow fever certificateLast call — it must be dated ten days before you fly
Your route · your stays · September in the Mara
Ask Elise anything
NowTripGet ready
Deliberately absentPacking (two weeks early) · recommendations · everything demoted to one quiet line, because a payment screen with five other cards on it is a payment screen that does not get used.
4Final approachDocs out
Get the trip onto the phone. The most important interaction in the product.
magicsafariEM
Save your trip to this phone48 MB — 12 documents, 4 guides, offline maps, every address and number. You will not have signal in the Serengeti.
14 days to goLHR 19:40, 3 Sept · check-in opens tomorrow
Packing20 kg soft bag — the light aircraft will not take a hard case. 8–24°C, dry.
Your documents — 12, ready
Save the duty line to your contacts
NowTripWallet
Deliberately absentPayment (done) · book-ahead recommendations (too late to be useful) · destination reading, demoted into Trip where it is still findable.
5On the groundWheels up
Today, offline. No sub-phases — the day is the unit.
magicsafariEM
No signal — everything here is savedAnything you send will go when you are back online
Tonight, without bookingThree places you can walk into
Help — camp, Elise, 24/7 duty line
NowTripWallet
Deliberately absentPacking · payment · visas · every pre-trip surface. And nothing on this screen is allowed to require a network to be useful.
6HomeHomecoming
Keep it, and share it. While the high lasts.
magicsafariEM
12 nights, 4 placesKenya & Tanzania · home 15 September
Share where you wentOne link — the route and the places, no photos needed. It answers the question everyone is asking you this week.
Your trip, keptEvery night, every property, every reference. It does not expire.
How was it?Beside the trip, not instead of it
Thinking about the next one?Loud for a few weeks, then it goes quiet
NowTripShare
Deliberately absentEverything operational. Also absent: any request to upload photographs, which is not a thing a guest will do for their tour operator.
Behind each tab
Now is the screen above. These are the other three — what is inside them, and what changes as the gates pass.
TripPermanent · the durable record
One tree at every gate: route → stop → how you get there · where you sleep · day by day · what is around · the guide. The structure never changes. What changes is how much of each item is filled in — which makes Trip a direct read of which gate you are at, without ever saying so.
Gates 1–2Route, places, properties, guides. Days are outline-level — “Day 8, Serengeti, free”. No times, no references, and it says so plainly: flight times confirm when we ticket. Free days are visibly marked, because they are the hook into Get ready.
Gate 2, once ticketedFlight numbers and times land on the transport items. The itinerary stops being provisional. Nothing else moves.
Gate 3Unchanged. Nothing about paying belongs in here.
Gate 4Every item grows its voucher, reference and supplier. Each stop shows whether it is saved to this phone.
Gate 5Today pinned to the top, past days collapsed, every item one tap from its voucher. Entirely offline.
Gate 6Past tense and complete. This is “the trip, kept” — there is no separate screen for it — and it grows a Share affordance.
Get readyGates 1–3 · the work
Never a fixed checklist. Every row is the same five things — what it is, why it matters, by when, what to do, and where it has got to — and the list is sorted by what bites first, not by category. Two rows can be months apart and still sit next to each other if that is how the dates fall.
Gate 1One live row: passports, one line per traveller, with the reason attached — we ticket your flights inside Africa. Below it, dimmed, the things that are coming later, so the shape of the next year is honest rather than a surprise.
Gate 2The full list. Choices sit above admin — free days and book-ahead tables expire in a way that jabs and insurance do not. Then health, entry and insurance, each with its own derived deadline.
Gate 3The balance pins to the top and everything else keeps its place below, with a last call flag on anything that still has lead time to run.
After gate 4The tab is gone. It collapses to a single line inside Trip — everything’s done, with the record of what was done — because demote never means delete.
WalletGates 4–5 · the offline set
Appears the moment documents exist, and has one rule: everything in it must work with no signal. If something in Wallet needs a network, it is in the wrong tab.
DocumentsVouchers and e-tickets grouped by stop, in travel order, flattened from the items so one can never go missing.
ReferencesBooking refs, supplier names, confirmation numbers — the things you get asked for at a check-in desk.
ContactsLodges, ground handlers, the duty line, the designer. As real phone links, not in-app calling, so they work on GSM with no data — which is the case that actually matters.
Addresses & directionsEvery stay, cached, with a map that already downloaded.
PassportsThe party’s details, offline. Genuinely useful at a border, and the app already holds them.
The packageWhat is saved, how large, when it last synced, and a re-sync when there is signal. The one honest place to admit the app is a cache.
Gate 6The tab gives way to Share and the contents fold into Trip, which is now the record.
ShareGate 6 · the only outward-facing surface
A read-only version of the trip on a link. It exists because everyone lands and gets asked the same question, and answering it well is the only organic referral channel in the product.
What goesThe route, the places, the properties, the month, and the reasons each one was chosen.
What never goesPrices, references, documents, traveller details. Exact dates only if they turn them on — an itinerary is a statement about when a house is empty.
The mechanismIt carries the travel designer’s name and a way to reach her. That is the whole commercial point; without it this is a nicety.
Beside itFeedback, and the next-trip prompt while the window is open.
Three workflows, end to end
The screens say what is visible. These say what actually happens — including the piece the current prototype is missing entirely, which is that a guest asking for something is a request with a lifecycle, not a button that fires a toast.
The request lifecycle, used by two of the stories below
Anything a guest asks for — an experience, a table, a correction to a passport — runs the same five states, and the state is visible in the app the whole way. Today none of this exists: the buttons are there, the request is not.
Requested→Priced & checked→You approve→Booked→In your trip
Guest acts on steps 1 and 3. The travel designer acts on 2 and 4. Step 5 is automatic — it writes into the itinerary, and at gate 4 into the offline package. Skipping step 3 is the tempting mistake: availability and price are not knowable at request time, so a one-tap “book” would be a promise the operation cannot keep.
Gate 2 · the upsell
The open day in the Serengeti
This is the gap between screen 1 and screen 3, and it is the only place in the whole flow where the app can make money on its own.
The system already knows everything it needs. Day 8 is leisure:true. It has the date, the place, the lodge, the party — two adults and a nine-year-old — and a pool of nearby things carrying a price, a duration, a minimum age and a lead time.
It is a prompt, not a browse. On Now, one line inside the lead-time list: “15 September is open in the Serengeti.” It sits in date order against everything else, so a balloon safari that books out three months ahead ranks above a bush walk you can arrange at reception.
Tap through to the day, not to a catalogue. The day as it currently stands — breakfast, free, dinner at camp — then two to four things that actually fit: right place, right date, open in September, minimum age nine or under, close enough to the lodge.
Each option argues for itself. What it is, how long, price per person, “books out around three months ahead”, and what it displaces — “back by 14:00, nothing else moves”. That last line is the one nobody builds and everybody needs.
The button is “Ask Elise to hold this”, not “Add to trip”. A supplier has to be contacted, and a price confirmed. This enters the request lifecycle above.
It rides the invoice. Approved before gate 3, the cost is added to the balance that is already going out. There is no second payment, no second card entry, and no second decision.
If they never choose, the day stays open and quietly stops being an ask. At gate 4 it turns into “15 September is free — here is what you can do on the ground”, walk-in tier only.
The commercial argument for putting this at gate 2 is not that guests plan early. It is that an upsell approved before the balance costs nothing to collect. After gate 3 the same yes needs a fresh payment, which is friction on both sides and a reason for the consultant not to bother. The window between gate 1 and gate 3 is the one place where extra revenue is nearly free to take.
Gate 2 and gate 5 · the same pool
A table with a waiting list, and a table without one
The guest never sees a section called Restaurants. They see things worth deciding now and, months later, tonight — and the same venue can appear in either, depending on one thing.
Every venue and every experience carries a lead time — how far ahead it needs booking. Months, weeks, days, or just walk in. It is the same attribute the jabs and the visas carry, and it is the only thing that decides where something shows up.
Months puts it in Get ready at gate 2, beside the balloon safari and the yellow fever appointment: “three places on your route worth booking now”.
Two paths, because guests differ. “We’ll book it” enters the request lifecycle — and usually no money moves, which makes it far lighter than the experience flow. Or “book it yourself” with a link, for people who would rather not ask.
Once held it is in the itinerary on that evening, and at gate 4 it goes into the offline package with its address and number.
Walk in means it never appears at gate 2 at all. It surfaces on the night, under tonight, without booking, where the useful content is an address and directions that already work with no signal.
This replaces the auto-versus-manual split in the decisions doc with something simpler and truer. That model said restaurants are ambient and activities are committing. But a three-month table commits exactly as hard as a private guide, and a lodge bush walk commits no harder than a bistro. One pool, one attribute, and the categories stop mattering — and it is the same attribute already doing the work everywhere else on this page.
Gate 5
No signal in the Serengeti
The app opens with no bars and behaves normally. Today, vouchers, contacts, addresses, guides and the map all render from the gate-4 package. Nothing spins.
The banner is honest, not apologetic — “no signal, everything here is saved”. It is a statement of capability, not an error.
Asking for something still works. Tap to reserve tomorrow’s table in Arusha and the composer opens, the request is queued, and the app says it will send when there is signal. The request lifecycle simply starts late.
Camp wifi at seven and the queue flushes. The guest does not manage this and is not asked to.
The honest limit. If they need help now and there is no data, the duty line has to be a real phone link, because GSM works where data does not. Any design that routes urgent help through in-app chat fails at exactly the moment it matters.
Three surfaces peak during the trip and genuinely need a network: reserving a table, asking the designer, and adding anything to the trip. All three have to compose offline and send later, and all three have to say so. That is not a nicety — it is the difference between an app that is trusted on the ground and one that gets closed after the second spinner.
Every other screen
The six above are the Now tab, one per gate. These are everything else the app needs — conceptual only, content and ordering rather than design. This is deliberately the conservative option — see Starting over for three structurally different shells, one of which I would build instead. Two things worth flagging: a restaurant and an experience share one detail page, because under a lead-time model they are the same object; and there is no separate “trip, kept” screen, because gate 6 Trip already is it.
How they hang together
Header → Ask the designer (thread + request cards) · Settings
NOWsix gate variants
→ Get ready list · Balance · Open day · Recommendation · Document · Contacts
TRIP → Trip overview
→ Stop detail
→ Stay detail → Document
→ Item detail → Document
→ Recommendation detail
→ Destination guide
→ Share (gate 6)SLOT Get ready g1–3 → Requirement · Traveller form · Travellers · Balance · Open day · Recommendation
Wallet g4–5 → Documents → Document · Contacts · Offline package
Share g6 → Feedback
Getting in
1First openEmailed link
Prove it is you, then get out of the way.
Your trip to Kenya & TanzaniaSeptember 2027 · 12 nights
Enter your email to confirmWe will send you a link — no password to remember
Booked through Magic Safari · Elise Malan
NotesNo account creation and no password. Once a year is not often enough to remember one, and the booking is already the identity. Everyone on the booking gets their own link.
Trip — the durable record
2Trip overviewTrip tab root
The whole trip on one screen.
Dates · nights · countries
Route strip40px — a dot per stop, travelled part filled, “day 6 of 12”. Map behind a toggle.
Stop 1 — Nairobi2 nights · Hemingways · tap through
↓ flight · 1h 20mLegs sit between the stops, tappable
Stop 2 — Masai Mara4 nights · Angama
Share this tripGate 6 only
NotesIdentical at every gate — this is the screen that makes the app feel like a possession rather than a tool. The full map is a toggle, not a permanent 300px: it earns its space once, at gate 1.
3Stop detailFrom Trip or Now
Everything about one place.
Masai Mara12–16 Sep · 4 nights · one line of essence
Stop pagerSwipe or tap to the next place
Where you are stayingAngama Mara — photo, nights, room, board → stay detail
Day by dayGrouped by date. Each item tappable. Free days marked.
15 Sep is openGates 1–3: prompt to decide. Gate 5: what you can do today.
While you are hereRecommendations, filtered by lead time for this gate
Destination guide →
NotesAt gates 1–2 items carry no times and no references, and the screen says so rather than showing blanks.
4Stay detailFrom stop detail
The property. The richest page in the app.
Angama MaraPhoto gallery
4 nights · Tented suite · All meals & drinks
Why this oneThe rationale from the proposal, carried forward rather than thrown away
What your rate includesAnd, separately, what it does not
Things to do hereLodge-run — game drives, the hide, the walk
Check-in 14:00 · Check-out 10:00
Address · map · phoneCached from gate 4
Your voucherGate 4 onward
NotesActivities hang off the stay, not the stop — swap the property and its activities go with it. This is the one page where the pre-booking proposal and the portal should say the same thing.
5Item detailFrom stop or Now
One flight, transfer, activity or meal.
Airlink 4Z 132Nairobi → Mara airstrip · 15 Sep, 10:20
Duration · terminal · operator
20 kg soft bag onlyLight aircraft — surfaced here, not just in packing
ReferenceGate 4 onward; before that, “confirmed, documents follow”
What is included
Your e-ticketOpens offline
If something goes wrongWho to call, in order of nearest first
NotesThe “if something goes wrong” block is the one nobody builds. It needs no new data — the supplier and duty numbers are already on the item.
6Destination guideFrom stop detail
The reading. The nudge-landing page.
The Masai MaraOne opinionated paragraph, not a brochure
Four factsLanguage · currency · time · plug
September hereReal climate figures for the actual month
Three highlightsIllustrated
Worth knowingThe honest caveat
Entry & health for Kenya →Links into the requirement detail
NotesFully offline from gate 4. During the long middle this is where every outbound nudge should land, which makes it worth more than its current two-taps-deep position suggests.
Get ready — gates 1–3
7Get ready listSlot tab root
What to do, in the order it bites.
3 of 7 doneA line, not a celebration
Worth deciding nowOpen days and tables that book out. These expire — admin does not.
Needs doingYellow fever · Kenya authorisation · Insurance — each with a window, not a date
DoneCollapsed
Everything else can waitHonest about what is not yet relevant
NotesDerived per trip, never a fixed list. Choices rank above admin because a good table goes and a jab does not. At gate 3 the balance pins to the top.
8Requirement detailFrom Get ready
One thing to do, and why it applies to you.
Yellow feverCertificate required
Why this applies to your tripBecause of your routing, not your destination — the distinction that catches people out
What to doTwo or three steps, plainly
Allow a couple of monthsA window with margin. The only hard rule: valid ten days after the needle.
Per travellerWhere nationality changes the answer
Check on Sherpa →We surface the question and the authority
Ask Elise
NotesNever asserts an entry outcome. Never quotes a queue length it cannot maintain.
9Traveller detailsFrom Get ready
The one real ask of gate 1.
Sarah ThorntonAdult · 2 of 4 travellers complete
Scan your passportOr type it — name exactly as printed, DOB, nationality, number, expiry
Dietary & allergies
PreferencesBed, seating, drinks — these sharpen the recommendations in the same visit
Locked after ticketingBecomes read-only with “something wrong? tell Elise”
NotesThe reason travels with the ask. This is the only request with no visible deadline, so it needs a why instead.
10TravellersFrom Get ready
Who is going, and who is holding it up.
4 travellers
Sarah Thornton ✓ · Mark Thornton ✓
Adult 2 — nothing yet · Child 1 — nothing yet
Nudge themSend the link to whoever has not filled it in
NotesOne person usually does the admin for a family. This lets them chase without going through the consultant.
11BalanceGet ready · gate 3
Pay, with nothing competing.
£18,400 due 12 July34 days
What this covers
Extras added sinceThe balloon safari you approved in March — the payoff of upselling before this screen
Price breakdownOptional expand
Pay
When this clearsDocuments release and the trip goes onto your phone
NotesThe extras line is the whole commercial argument for gate 2, made visible. After this screen an upsell needs a second transaction.
12Open dayFrom Get ready or stop
One free day, and what could fill it.
15 September is openMasai Mara · day 8
Your day as it standsBreakfast · free · dinner at camp
Balloon safari3h · from £420pp · books out months ahead · back by 14:00, nothing else moves
Guided walk with a Maasai guide2h · £95pp · a week’s notice
Leave it freeAnd what that looks like — which is a real answer
NotesOptions are filtered by place, date, season, minimum age and distance from the lodge. “What it displaces” is the line that makes this decidable.
13Recommendation detailTable or experience
One page for both. The lead time is the only difference.
PhotoName · type · where
Why it is hereOne curated line — not a scraped description that restates the name
FactsDuration / price / minimum age · or cuisine / price band
Books out months aheadOr: “walk in” — this is what decides which gate it appeared at
What it displacesOnly when it takes a day
Ask Elise to hold thisOr “book it yourself” with a link
Address · phone · directionsWorks offline from gate 4
NotesOne page, not two. Under a lead-time model a three-month table and a private guide are the same object; the category only changes which facts render. At gate 5 the reserve action queues offline.
Wallet — gates 4–5
14WalletSlot tab root
Everything that must survive with no signal.
Saved to this phone48 MB · 12 documents, 4 guides, maps · synced 2 hours ago
Documents (12) →
Contacts →
Addresses & maps →
PassportsThe party’s details, offline — genuinely useful at a border
ReferencesThe numbers you get asked for at a desk
NotesOne rule: if something in here needs a network, it is in the wrong tab. The sync line is the honest place to admit the app is a cache.
Flattened from the itemsSo a document can never go missing from this list
NotesGrouped by stop rather than by type, because that is how they get used.
16Document viewerFrom anywhere
The voucher itself.
Angama MaraAccommodation voucher
QR / barcodeIf there is one
Reference · dates · guests · what it covers
Supplier name and phone
Email · add to phone wallet
NotesMust render entirely offline. This is the screen the whole gate-4 download exists to serve.
17ContactsFrom Wallet or Now
Who to call, nearest help first.
24/7 duty lineBig, first, and a real phone link
Elise MalanYour travel designer · chat or call
Your lodgesIn trip order — the ones you actually reach for
Ground handlersPer country
Emergency numbersPer country
NotesEvery number is a plain phone link, not in-app calling, because GSM works where data does not — and that is exactly the moment this screen matters.
After, and always
18ShareSlot tab · gate 6
Answer the question everyone is asking you.
PreviewWhat your friend actually sees
Copy link
What is includedRoute ✓ · properties ✓ · month ✓ · exact dates ✗
Planned by Elise MalanAlways included — this is the mechanism, not a credit
Never sharedPrices · references · documents · traveller details
NotesExact dates are off by default: an itinerary is a statement about when a house is empty.
19FeedbackFrom Share or Now
Short, and beside the trip rather than instead of it.
How was it?A handful of questions
Per propertyWhere it is worth asking
Anything you would change?
Thank youAnd a way back to the trip
NotesAsked of someone who has just landed, so it has to be short and it must not be the only thing on the screen.
Offline — will send when you have signalDuring the trip
NotesThe request lifecycle lives here and is visible the whole way. This is the single biggest thing the current prototype is missing: the buttons exist, the request does not.
21SettingsHeader · every gate
Small on purpose.
Units°C / °F · kg / lb — derived from nationality, overridable
NotificationsHow often we get in touch before you travel
Language
Sign out
NotesThe notification control matters more than it looks: eighteen months of nudges is the fastest way to get muted.
Moving around
The inventory says what the screens are. This is how you get between them — which is where the design actually lives, because a trip is linear and a tabbed app is a tree. Stop 2 to stop 4 should be one gesture, not back–scroll–tap.
The proposal already solved this, and we should copy it
Your journey at a glance is not a menu. It is a jump list into one continuous document — every card is href="#leg-<id>", so choosing a place is a scroll, not a drill-in. Four things are worth lifting straight across:
The date gutter. Dates run down the left margin of the timeline, so when am I where is answered without opening anything. The portal currently buries dates inside the card.
“While you are here”, folded into the stop card. The glance already lists that stop’s booked experiences, which means you often do not need to open the stop at all.
Legs as badges between the stops, carrying the arrival date. The portal has the legs; it does not put the date on them.
Cards jump, they do not push. Nothing in the proposal costs you a back button.
The one structural change: Trip is a scroll, not a list
Collapse Trip overview and Stop detail into one continuous, chaptered scroll with a sticky stop pager — exactly the shape of the proposal. Route and map at the top, then a chapter per place.
Today Trip tab → route list → stop → item four levelsProposed Trip tab → (scroll or pager) → item three
It removes a whole level of hierarchy, makes stop-to-stop free, and — the part that is worth more than the ergonomics — the guest sees the same structure before and after they book. The document they were sold and the app they travel with are recognisably the same object.
At gate 5 the scroll simply opens at today. Length stops mattering because the pager puts any place one tap away.
Seven rules that answer most of it
Lateral is replace, never push
Moving stop→stop, day→day or item→item does not touch the back stack. Back from stop 4 goes where you came from, not to stop 3. The prototype already gets this right — gotoStop() replaces rather than pushes, unlike every other navigation function in the file. Generalise it.
Three levels, hard
Tab → chapter → detail. If something wants a fourth, it is a sheet, not a page. Every level you add is a back button somebody has to press.
Documents are sheets, not destinations
You open a voucher to look at it and immediately return. A half-sheet over the current screen keeps the context you needed it for — a full push loses your place in a day you were reading.
Every detail page carries its own next and previous
From an item, the next item. From a recommendation, the next one. Never make someone go back in order to move sideways — that is the single most common friction in itinerary apps.
Tapping the current tab resets it
The universal escape hatch from any depth, and it costs nothing to implement.
Deep links get a synthetic parent
Arriving at a requirement from a nudge email, Back must go to Get ready — not out of the app. With eighteen months of outbound messages, most sessions will start deep.
Now never owns content
It is a lens over Trip and Get ready, not a place things live. Tapping anything on Now lands you at the real thing. The moment Now has its own detail screens you are maintaining two of everything.
Airbnb, and where it stops being useful
Worth stealing
Transfers cleanly
Floating back button over the hero. No top bar eating the photograph. The prototype already does this.
Sticky bottom action bar on detail. Airbnb keeps price + Reserve pinned. Here: the voucher from gate 4, Ask Elise to hold this at gate 2.
“Show all 12” rather than pagination. Expand in place; never send someone to a second page.
The half-sheet. Right for documents, and for tonight’s dining while you are mid-day.
Dates as section headers down a scrolling itinerary.
Do not copy
Wrong shape
Search and browse. Airbnb’s whole IA is a funnel from many to one. This app has one trip. Any pattern that assumes choosing between options is wrong here.
Wishlists and saving. Nothing to collect.
Airbnb’s own Trips tab. It is a thin list of reservations and it is the weakest screen in their app. Our trip is far richer — the proposal is the better reference for the trip itself.
Reviews and ratings everywhere. The property was chosen for a reason by a named human; a crowd score undercuts that.
Genuinely open
Is a day a page? Today is Now. Other days are sections inside the chapter. But on the ground you want tomorrow constantly, and it has no home — a sheet, an anchor, or a real screen. Unresolved.
What happens to past stops during and after the trip? On day 12 you do not want to scroll past days 1–11. But afterwards the trip is a record and nothing should be hidden. Collapse-with-memory is the obvious answer and obvious answers here are often wrong.
The pager breaks past about six stops. A horizontal row of chips works for four places and fails for ten. Some itineraries are ten.
Sheet or page for a recommendation? From Now at gate 5 it wants to be a sheet, because you are mid-day. From Get ready at gate 2 it wants to be a page. Same content, two presentations — probably fine, possibly a smell.
Does the route map earn a full screen? Inline it is decorative; full-screen it is useful roughly once. A tap-to-expand is the cheap answer.
How long is too long? Six stops with day-by-day for each is a very long scroll, and the sticky pager is the only thing standing between that and unusable.
Starting over, properly
An admission first. The gates are genuine first-principles work. The screen inventory is not — it is the same nouns as the existing app, re-sequenced. Trip, stop, item, guide, documents, contacts. That is what an itinerary app looks like, which is exactly why it deserves suspicion.
So: forget screens. What does a person actually do with this?
Seven real moments of use
Months outA ninety-second visit, almost always prompted by an email. Is there anything I need to do? — then, if the answer is no, maybe five minutes of daydreaming.
Last fortnightWhat do I pack, have I got everything, what time do I leave?
Morning, on the groundWhat is happening today, what time, do I need to be ready?
At a desk or a gateShow them the thing. Ten seconds, one-handed, probably offline, possibly stressed, definitely not browsing.
Evening, on the groundWhat is tomorrow, and where are we eating?
Something is wrongWho do I call. Panic mode. No patience, possibly no data.
HomeWhere did we stay on night four, and show my sister where we went.
Not one of those is “browse my trip”. They are questions with answers. Six of the seven want one specific thing, immediately. Only the daydreaming one wants a document to wander through — and that is the one the existing app is actually built for.
Which points at the real finding
Daydreaming and operating want opposite shells. Before you go, the app should be a rich browsable object you enjoy opening — photographs, places, reading, a sense of the thing coming. From the moment you are moving, that object is in the way: you want a single answer, one-handed, offline, now.
The existing app has one shell trying to be both, and it is why every version of it feels slightly wrong. The gate model already says the app changes at gate 4. The honest conclusion is that it should change shape, not just contents — a magazine before you fly, a dashboard once you are moving.
Three shells worth building and testing
AThe timelineOne dimension
No tabs. The whole app is time.
↑ Deposit paid · Mar 2026Scrolled past — done
↑ Details in · flights ticketed
— now —Always opens here
Yellow feverWorth starting · allow a couple of months
Balance due12 July
Documents released
You fly3 Sep, 19:40
Day 1 — Nairobi
Day 2 … Day 12
Home · share · the next one
Why it might be rightEverything the guest cares about has a position in time, so time is the only dimension the product genuinely has. Nothing is ever “in another section”. Deep links from emails land in place with no synthetic parent. The long middle is visibly a long empty stretch, which is honest and oddly motivating.
Why it might notOn the ground you want only today, and a timeline invites scrolling past it. Documents ordered by time is wrong when the question is “the Angama voucher”. And you lose the feeling of owning a beautiful thing.
BTabsThe conservative one
Now · Trip · moving slot. Everything above on this page.
Balloon safari, 05:30Day 6 · Serengeti
Your voucher
Rest of today
Tonight, without booking
Help
Trip · Wallet one tap away
NowTripWallet
Why it might be rightFamiliar, findable, and each surface can be optimised for its own job. Handles the daydreaming case well because Trip is a real, rich object.
Why it might notIt makes a linear thing into a tree. Now and Trip overlap conceptually and will drift. And it is the shape you land on by not deciding — which is the strongest argument against it.
COne answerDashboard
The app opens on the single most likely question, answered.
06:14 · no signal · everything saved
Balloon safariPickup at reception, 05:30 — twenty minutes
Show your voucherOne tap. Renders before anything tries the network.
▾ swipe for the next thingThen: rest of today · tomorrow · call the camp
▴ pull up for everythingThe full trip, when you actually want it
Why it might be rightZero navigation for six of the seven moments. Works one-handed, stressed, offline. Brutally clear about what matters now, which nothing else on this page is.
Why it might notWhen it guesses wrong it is infuriating, and it will guess wrong. Everything else becomes hard to find. And it destroys the daydreaming case entirely — there is nothing to wander through.
The hybrid I would actually build
C over B, switched by gate. Through gates 1–3 the app is B — a browsable object, because the job is anticipation and there is nothing urgent. From gate 4 it opens as C: one answer, full screen, offline-first — and pulling up reveals B underneath, unchanged. Lock screen to home screen, essentially.
That gives the daydreaming case a magazine and the operational case a dashboard without maintaining two apps, and it makes gate 4 do real work rather than just swapping a tab label.
The map, specifically
You are right — it does not earn the space
A route map is beautiful exactly once, at gate 1, when it says this is the shape of your trip. After that it is three hundred pixels repeating something the guest already knows. It also answers a question nobody asks twice: they are not lost at the country scale, they are being driven.
Replace the daily job with a route strip. Forty pixels: a line, a dot per stop, the travelled part filled, today marked. It carries sequence, progress and where I am — ninety per cent of what the map was doing — at a seventh of the height, and it fits at the top of any screen.
Keep the map as a toggle and a tap. List ⇆ map on the trip, and tap-to-expand full screen. Present, not permanent.
The map that is genuinely useful is local, not national. Where the lodge is relative to the airstrip; where dinner is relative to the hotel. That is the one worth caching at gate 4, and it is not the one currently built.
“Day 6 of 12” is the thing people actually feel. The strip should carry it.
Seven interactions that actually matter
Cold open to voucher in one gesture
The highest-stakes interaction in the product: one-handed, at a desk, possibly no signal, mildly stressed. It should be the first thing on screen from gate 4, and it must render before anything attempts a network call. A lock-screen widget or icon long-press should go straight to it. Three taps through a tab bar is a failure.
The app knows what time it is
Before about six in the evening, today. After it, tomorrow — because that is when people actually ask. Costs nothing, uses data already present, and no itinerary app does it.
Swipe between days, never back-and-forward
Days are a sequence. Treating them as a stack means two gestures to move one day.
The panic path is a phone link
Anything that looks like trouble reaches the duty line in one tap, as a real tel: link. GSM works where data does not, and that is precisely the moment.
Queue and say so
Anything needing signal composes offline, tells the guest plainly, and sends when a bar appears. Nothing spins. Offline is a state, not an error.
Progress is visible without asking
Day 6 of 12. Three places done, one to go. People feel a trip as a fraction, and nothing in the app currently says so.
One prompt at a time, months apart
Through the long middle the app should ask for one thing, then go quiet. A list of seven outstanding items eighteen months out is a reason to close it and not come back.
What to test
Eight variations, and what each would settle
Shell A vs B vs the hybrid — the only structural question here. Everything else is detail by comparison.
Now opens on today vs on the next action — is the guest oriented by time or by task? Answering this probably answers the shell question too.
Map vs route strip vs neither — does anyone miss it? Cheapest test on the list, and I would run it first.
Documents as a tab vs attached to items vs a persistent gesture — the desk moment either works or it does not, and it is binary.
One chaptered scroll vs a stop pager vs swipe-between-stops — three ways to be lateral; they will not feel the same.
A task list vs one task at a time — does a list of seven read as helpful or as homework?
Recommendations pushed vs pulled — prompt on Now, or a section people go and look at. This has direct revenue consequences and is worth real rigour.
Time-of-day awareness on vs off — cheap, and if it works it is the kind of thing people tell other people about.
Now compare it
Written after the above, not during. The shape of the trip survives almost entirely; the shape of the app around it does not.
What we built
From scratch
Shell
Four fixed tabs — Today, Trip, Packing, Info — identical in every phase.
Three tabs. Now and Trip are permanent; the third moves Get ready → Wallet → Share. The designer lives in the header, not a tab.
Phase model
state.phase — three values, read inside one screen.
Six derived gates, a pure function of the booking, readable by every screen.
Packing
A permanent tab, equally prominent on the morning you fly home.
One card at gate 4, with real weather for the real dates. Invisible before and after.
Info
A drawer holding the designer, entry rules, documents, contacts and good-to-know.
Deleted. Contacts and documents become Wallet because they are offline-critical; destination facts go into Trip where the place is.
The to-do list
Three fixed rows: deposit ✓, add details, pay balance.
Lead-time ordered and derived per requirement — jabs six weeks, e‑visas by queue, balance by contract, packing a fortnight. Sorted by what bites first.
Dining vs activities
Two pools, two rules — restaurants auto, activities manual and off by default.
One pool, one attribute: lead time. A three-month table and a private guide surface together at gate 2; walk-ins surface on the night.
Offline
A “Saved offline” pill and a documents-only save row. A claim.
A designed download at gate 4 with a size, a manifest and a done state — plus honest degradation for the three things that genuinely need signal.
Countdown
“Days to go”, always.
Months when it is months. “423 days to go” is not information.
After
One feedback button on an otherwise empty screen.
The record, then the link, then the window. Feedback rides along beside them.
What survives untouched — and it is the expensive half
A chapter is a place. The trip model — stops holding their own transport, stay, days and reading — is right, and it is what the whole thing hangs on.
Derived, not configured. Near-zero per-trip authoring, with the admin showing which tier a value came from. This is the reason the product can scale across three brands.
Surface the question, route the answer. Sherpa for visa outcomes rather than asserting them. With ten-plus countries this becomes more right, not less.
The day-by-day, sliced by date. Including the detail that “rest of today” means the same date, not the rest of the stop.
Activities hang off the stay, not the stop. Learned the hard way in the proposal build; still correct.
The design system. Tokens, flush sheets, no monospace, multi-brand from one --brand.
Three things worth arguing about
Every request costs a human. The lifecycle above turns each guest ask into a task on a travel designer’s desk, and the whole upsell case depends on her turning them round quickly. At volume that is the binding constraint, not the interface — and if requests sit for a week, guests stop making them and the gate-2 revenue argument collapses.
Eighteen months is a long time to be nudged. The long middle only works if outbound messages are rare and each one is worth the tap. Get the cadence wrong and the portal becomes the thing people mute before they have even travelled.
Three tabs versus four is a judgement, not a finding. The gate-dependent third slot is the part worth defending; whether Now and Trip are two tabs or one scrolling surface is genuinely arguable.
Read from airbnb-app.app.js and airbnb-app.data.js at the current build, plus guest-portal-config-decisions.md, and operating detail supplied by Philip on lead times, ticketing, connectivity and footprint.
Step heights and orderings are editorial judgement.
Grey heights are mechanical: a tab scores highest, then a card on the home screen, then one tap from a tab, then anything two or more taps deep.
Screens are wireframes and the trip shown is illustrative. Entry and health requirements are described by shape only; the portal routes actual answers to Sherpa rather than asserting them.