Skip to content

Crest — User Journeys ​

ProductCrest — Personal Finance App
Document version0.12 (Draft) — local-first: anyone uses the app on their own device with no login (local mode); invited people can connect for sync and sharing (connected mode)
Date2026-10-05
Based onBusinessRequirements.md v0.22
StatusDraft — pending review

This document describes, step by step, how each type of person uses Crest to reach a goal. Users use Crest through the Crest app, a web app (PWA) that opens in the browser and can be added to the phone's home screen; "open Crest" below means tapping its home-screen icon or opening its link. Anyone can use the app with no login (local mode, the data stays on the device). People who have been given access can also connect (connected mode) for sync between devices, shared spaces, and a server backup. A journey that needs connected mode says so. Native Android and iPhone apps may follow later from the same code. The access-request form, activation, and password reset are pages on the public website, and the Super Admin works in a separate web portal. Every journey links back to the requirement IDs (FR-*, NFR-*) and business rules (BR-*) in the Business Requirements Document. Where the two documents disagree, the Business Requirements Document wins. Report the difference so this document can be fixed.

Terminology. As in the Business Requirements Document, the word "account" is never used on its own.

  • User: a person who can log in to Crest. Managed by the Super Admin.
  • Financial account: cash wallet, bank, e-wallet / online payment, or credit card. Belongs to one space.
  • Local mode / connected mode: using the app with no login (data only on the device) / while logged in (data also on the server).
  • Space: holds financial accounts, categories, budgets, and goals, plus its members. Every user has a private Personal space and can create or join shared spaces. In a space, a person is an Owner (manages the setup) or a Member (adds transactions, edits only their own).

Unless a journey says otherwise, it takes place in the space currently selected in the space switcher. For someone with only a Personal space, that is the only space and the switcher is hidden. Unless a journey says otherwise, it works the same in local mode and connected mode.


Contents ​

  1. How to read a journey
  2. Actors
  3. Journey map
  4. Access & identity journeys (UJ-01 to UJ-08; connected mode)
  5. Super Admin journeys (UJ-09 to UJ-15)
  6. Onboarding and device journeys (UJ-16, UJ-38, UJ-50 to UJ-52)
  7. Everyday money journeys (UJ-17 to UJ-26)
  8. Planning & insight journeys (UJ-27 to UJ-31)
  9. Setup & maintenance journeys (UJ-32 to UJ-37, UJ-39)
  10. Sharing journeys (UJ-42 to UJ-49)
  11. Future: contribution journeys (UJ-40, UJ-41)
  12. Requirements traceability

1. How to read a journey ​

Each journey uses the same structure:

FieldMeaning
ActorWho performs the journey (see §2)
GoalWhat they want to achieve
TriggerWhat makes them start
PreconditionsWhat must already be true
Main flowThe normal, successful path. U = user action, S = system response
Alternative & error flowsVariations and what happens when something goes wrong
OutcomeWhat is true when the journey ends
CoversRequirement and business rule IDs this journey implements
PhaseRelease phase from the roadmap (BRD §11)

2. Actors ​

ActorDescriptionUses
VisitorSomeone who has not used Crest yetPublic website
Local userAnyone using the Crest app with no login (local mode). Their data is only on their deviceThe Crest app (PWA), mostly on a phone
RequesterA visitor or local user who has submitted an access request, to be given access to connected modeEmail
Invited userApproved by the Super Admin; has not set a password yetEmail, activation page on the public website
UserActive user, logged in (connected mode), managing money (personas Dina, Budi, Sari; the couple Andi and Rina; Boss and staff Jojo and Maria)The Crest app (PWA), mostly on a phone
Space OwnerA user who manages a space: its financial accounts, categories, budgets, and members. Every user is the Owner of their Personal spaceThe Crest app (PWA), mostly on a phone
Space MemberA user in someone's shared space who adds transactions and sees everything in that space, but edits only their own entriesThe Crest app (PWA), mostly on a phone
Super AdminThe app owner, or another user given the Super Admin role; manages access and users, never sees other users' financial data. Also uses Crest as a normal userSuper Admin portal (a separate web app), mostly on a computer
SystemCrest itself: the backend API, scheduled jobs, email, and notifications—

3. Journey map ​

The lifecycle of a person in Crest:

IDJourneyActorPhasePriority
UJ-01Request accessVisitor1bM
UJ-02Try to register or log in without approvalVisitor1bM
UJ-03Activate login from invitationInvited user1bM
UJ-04Log in and unlock CrestUser1bM
UJ-05Reset a forgotten passwordUser1bM
UJ-06Removed: no external authentication (FR-AUTH-5, BR-20)———
UJ-07Get logged out after deactivationUser1bM
UJ-08Delete myself and all my dataUser1bM
UJ-09Review and approve an access requestSuper Admin1bM
UJ-10Reject an access requestSuper Admin1bM
UJ-11Create a user directlySuper Admin1bM
UJ-12Deactivate and reactivate a userSuper Admin1bM
UJ-13Permanently delete a userSuper Admin1bM
UJ-14Help a user who cannot log inSuper Admin1bM
UJ-15First-time portal setup, daily check, and audit reviewSuper Admin1bM
UJ-16First-time setupLocal user1aM
UJ-17Log a daily expenseUser1aM
UJ-18Log incomeUser1aM
UJ-19Top up an e-wallet or withdraw cashUser1aM
UJ-20Pay with a credit cardUser1aM
UJ-21Pay a credit card billUser1aM
UJ-22Transfer between currencies with a manual rateUser2S
UJ-23Fix or delete a transactionUser1aM
UJ-24Find a past transactionUser1aM
UJ-25Log a transaction without internetLocal user, User1aM
UJ-26Set up a recurring transactionUser2S
UJ-27Set monthly budgetsUser1aM
UJ-28Get a budget alert and reactUser2S
UJ-29Create and track a savings goalUser2S
UJ-30Review spending in StatsUser1aM
UJ-31Check net worth across currenciesUser2S / C
UJ-32Add and organize financial accountsUser1aM
UJ-33Archive or delete a financial accountUser1aM
UJ-34Manage categoriesUser1aM
UJ-35Maintain exchange ratesUser2C
UJ-36Export and import transactions (CSV)User1a / 2M / S
UJ-37Change preferences and remindersUser1a / 2M / S
UJ-38Add Crest to the home screenUser1aM
UJ-39Get a new version of CrestUser1aM
UJ-40Record a yearly contributionSuper Admin4W
UJ-41Contribution comes due, lapses, and is renewedUser4W
UJ-42Create a shared spaceSpace Owner1bM
UJ-43Invite someone and accept the invitationSpace Owner, User1bM
UJ-44Add a transaction in a shared spaceSpace Member1bM
UJ-45Top up a shared fund from a Personal financial accountSpace Owner1bM
UJ-46See how a shared space's money is usedSpace Owner, Space Member1bM / S
UJ-47Pay yourself back from a shared fundSpace Member1bM
UJ-48Leave a space or remove a memberSpace Member, Space Owner1bM
UJ-49Hand over ownership or delete a shared spaceSpace Owner1bM
UJ-50Start using Crest with no loginVisitor, Local user1aM
UJ-51Save and restore a backup fileLocal user, User1aM
UJ-52Connect to Crest and upload this device's dataLocal user1bM

4. Access & identity journeys ​

UJ-01 — Request access ​

ActorVisitor (e.g. Dina, who heard about Crest from a friend)
GoalGet access to connected mode (sync between devices, shared spaces, server backup)
TriggerGets the Crest request link from the owner or a friend, or opens the Crest app and taps Request access under More → Connect to Crest
PreconditionsNone. The person can already use Crest on their own device with no request (UJ-50)

Main flow

  1. U opens the request link → S shows the Request access page on the public website. (In the app, the Connect screen's Request access link opens the same page.)
  2. S shows the form: full name, email, country, optional reason/message, a checkbox to accept the Privacy Policy and Terms of Use (both linked, in the visitor's language), and a checkbox confirming they are 18 or older.
  3. U fills in the form, accepts the privacy policy, and taps Submit.
  4. S validates the fields (valid email, required fields filled, consent given) and runs bot protection.
  5. S stores the request with status Pending, emails the Super Admin (UJ-09), and shows: "Thanks! Your request has been received. We'll email you when it has been reviewed."
  6. U closes the page and waits for an email.

Alternative & error flows

  • A1 — Missing or invalid fields: S highlights the fields and does not submit.
  • A2 — Privacy Policy and Terms of Use not accepted, or age not confirmed: Submit stays disabled. (FR-REQ-6, BR-44)
  • A3 — Email already has a pending request or is an active user: S shows the same confirmation message as step 5 and creates nothing new, so it doesn't reveal whether the email exists. (FR-REQ-4)
  • A4 — Email was rejected less than 30 days ago: S shows the same neutral confirmation, creates nothing new, and sends no email. (BR-14)
  • A5 — Too many submissions from one device/IP, or bot suspected: S blocks the submission and asks the visitor to try again later.
  • A6 — No internet: S shows "You're offline. Please try again when connected." The form keeps what was typed.

Outcome: An access request exists with status Pending. No user has been created yet. Covers: FR-REQ-1, FR-REQ-1a, FR-REQ-2, FR-REQ-3, FR-REQ-4, FR-REQ-6, FR-ADM-13, NFR-3, BR-14, BR-44 Phase: 1b


UJ-02 — Try to register or log in without approval ​

ActorVisitor or Requester
GoalUse Crest right away
TriggerLooks for a "Sign up" button, or tries to log in before being approved
PreconditionsVisitor is not an Active user

Main flow

  1. U looks for a sign-up option → S has none. Crest needs no sign-up to use: U just opens the app and starts (UJ-50). Under More → Connect to Crest, S offers only Log in and Request access.
  2. U tries to log in with an email that isn't an Active user → S shows a generic error: "Email or password is incorrect." with a Request access link beneath it.

Alternative & error flows

  • A1 — Email is Invited (approved, not activated): Same generic error. The invitation email is the only way to set a password (UJ-03). If the link expired, the person contacts the Super Admin (UJ-14).
  • A2 — Looks for "Continue with Google / Apple": There is none. The only way in is Crest email and password. (FR-AUTH-5, BR-20)

Outcome: No connected access without Super Admin approval. Crest itself is usable right away on the device (UJ-50). Covers: FR-AUTH-1, FR-AUTH-5, BR-8, BR-20 Phase: 1b


UJ-03 — Activate login from invitation ​

ActorInvited user
GoalSet a password and start using Crest
TriggerReceives the "Your Crest access is approved" email
PreconditionsUser status is Invited; activation link sent less than 72 hours ago

Main flow

  1. U opens the email and taps Activate my login.
  2. The link opens the activation page on the public website. S checks the link is valid, unused, and not expired, then shows the user's email (read-only) and a password field.
  3. U enters a password that meets the password rules and confirms it.
  4. S saves the password, marks the link as used, changes the user status to Active, and shows "You're all set" with an Open Crest button.
  5. U opens the Crest app and connects (UJ-52): logs in (UJ-04) and decides what to do with any data already on the device. If the device has no data, first-time setup starts (UJ-16), which also shows how to add Crest to the home screen (UJ-38). The activation email links to the install page too.

Alternative & error flows

  • A1 — Link expired (more than 72 hours): S shows "This link has expired. Please contact the Crest admin for a new one." The Super Admin resends it (UJ-14).
  • A2 — Link already used: S shows "This link was already used." with a Log in button.
  • A3 — Link replaced by a newer one: The older link is invalid; S shows the expired message.
  • A4 — Password too weak or confirmation doesn't match: S explains the rule and keeps the user on the page.
  • A5 — User was deactivated or deleted after the invitation was sent: S treats the link as invalid.

Outcome: User status is Active and the user can log in. Covers: FR-AUTH-2, FR-AUTH-3, FR-APP-2, FR-APP-7, BR-10, BO-6 Phase: 1b


UJ-04 — Log in and unlock Crest ​

ActorUser
GoalGet into Crest quickly and securely
TriggerOpens Crest, or taps Connect to Crest (More)
PreconditionsUser status is Active

Main flow — first login on a device

  1. U taps Log in on the Connect screen, enters email and password. This is the only login method; there is no Google, Apple, or other external sign-in.
  2. S verifies them and opens Crest.
  3. S asks U to set a Crest PIN (4–6 digits) for the app lock. If U already has a PIN from another device, S asks for it once instead. If this device already had a local PIN (UJ-52), S offers to use it.
  4. U enters the PIN twice → S turns on the app lock.
  5. S continues with UJ-52 (upload or download of data).

Main flow — returning later

  1. U opens Crest → S asks for the PIN.
  2. U unlocks → S shows the dashboard.

Alternative & error flows

  • A1 — Wrong password: Generic error. After repeated failures S slows down further attempts.
  • A2 — New device or browser: U opens the Crest link, logs in with email and password, and enters the same PIN; it works on every device.
  • A2b — Five wrong PIN attempts: S logs U out on that device and clears the data kept there (the server has it); U logs in again with email and password.
  • A3 — Forgot the PIN: U logs out and logs in again with email and password, then sets a new PIN.
  • A4 — Forgot the password: UJ-05.
  • A5 — User is Deactivated: S shows "Your access has been suspended. Please contact the Crest admin." (UJ-07).
  • A6 — Local mode (no login): The app lock is optional, and its PIN stays on this device. A wrong PIN only slows down further attempts and never erases data. If U forgets it, U erases the app's data on this device and restores a backup file (UJ-51). (BR-49)

Outcome: User is in Crest. It locks again when reopened. Covers: FR-AUTH-4, FR-AUTH-5, FR-AUTH-6, FR-MOD-9, NFR-2, NFR-4, BR-20, BR-49 Phase: 1b


UJ-05 — Reset a forgotten password ​

ActorUser
GoalGet back in after forgetting the password
TriggerTaps Forgot password? on the login screen
PreconditionsNone (S never reveals whether the email exists)

Main flow

  1. U enters their email → S always replies "If this email belongs to a Crest user, we've sent a reset link."
  2. If the email is an Active user, S emails a single-use, time-limited reset link.
  3. U opens the link → the reset page on the public website opens in the browser → U sets a new password.
  4. S saves it, logs the user out of every device, and tells them to open the app and log in.

Alternative & error flows

  • A1 — Link expired or used: S offers to send a new one.
  • A2 — User is Deactivated: No email is sent; the on-screen message stays the same.
  • A3 — User asks the Super Admin instead: Super Admin triggers the reset email (UJ-14).

Outcome: User has a new password; old sessions are ended. Covers: FR-AUTH-7, FR-ADM-10, FR-APP-7 Phase: 1b


UJ-07 — Get logged out after deactivation ​

ActorUser (affected by a Super Admin action)
Goal— (the user did not start this)
TriggerSuper Admin deactivates the user (UJ-12)
PreconditionsUser is logged in on one or more devices

Main flow

  1. S ends every session of the user immediately.
  2. On next use of any device, S shows "Your access has been suspended. Please contact the Crest admin."
  3. Unsynced offline changes on the device are discarded, not uploaded. (BR-21)
  4. The app removes the synced data from the device and continues in local mode with an empty start. (BR-50)

Outcome: The user can't use connected mode. Their data is kept on the server (BR-11). Crest still works in local mode on the device, starting empty. Covers: FR-AUTH-9, FR-ADM-9, FR-MOD-11, BR-11, BR-21, BR-50 Phase: 1b


UJ-08 — Delete myself and all my data ​

ActorUser
GoalLeave Crest and remove all personal and financial data
TriggerSettings → Delete my Crest login and data
PreconditionsUser is logged in

Main flow

  1. U opens the delete option → S explains what will be deleted (login and the Personal space with all its financial accounts, transactions, budgets, goals, and categories), that transactions they added in shared spaces will stay there labelled "Former member", and that it can't be undone. S offers Export my data first (UJ-36).
  2. U optionally exports, then confirms by typing their email or password.
  3. S permanently deletes the user and all their data, logs out all devices (each one removes its synced data and returns to local mode, BR-50), sends a confirmation email, and records the event (without financial details).

Alternative & error flows

  • A1 — User cancels: Nothing changes.
  • A2 — User is the last Super Admin: S blocks the deletion. (BR-13)
  • A3 — User is the last Owner of a shared space: S lists those spaces and asks U to hand over ownership or delete each one first (UJ-49). If U deletes anyway, the longest-standing member becomes Owner; a space with no other members is deleted. (BR-33)

Outcome: User status is Deleted; no data remains except their transactions in shared spaces (labelled "Former member") and what the law requires. Their deleted data disappears from all backups within 90 days. (NFR-10)Covers: FR-AUTH-8, FR-DAT-1, FR-SPC-9, NFR-3, BR-11, BR-13, BR-33, BR-34 Phase: 1b


5. Super Admin journeys ​

All Super Admin journeys happen in the web portal, which requires two-factor authentication and times out after 30 minutes idle. Every action is recorded in the audit log. The Super Admin never sees financial accounts, transactions, budgets, or goals. (FR-ADM-1, FR-ADM-2, FR-ADM-14, FR-ADM-17, NFR-11, BR-12)

UJ-09 — Review and approve an access request ​

ActorSuper Admin
GoalLet a suitable person use Crest
Trigger"New access request" email, or the pending count on the portal overview
PreconditionsAt least one request is Pending

Main flow

  1. U logs in to the portal with password and authenticator code.
  2. S shows the overview: pending requests, active users, deactivated users, new users this month.
  3. U opens Access requests → S lists requests filtered to Pending, newest first, showing name, email, country, reason, and date.
  4. U opens a request and clicks Approve.
  5. S creates the user with status Invited, marks the request Approved, emails the activation link (valid 72 hours), and records the action in the audit log.
  6. S shows "Approved. Invitation sent to dina@example.com."

Alternative & error flows

  • A1 — Approve several at once: U ticks several Pending requests and clicks Approve selected; S processes each as in step 5. (FR-ADM-18, Could)
  • A2 — Invitation email bounces: S marks the delivery as failed on the user's row; the Super Admin can correct the email (FR-ADM-12) and resend.
  • A3 — Session timed out: S asks the Super Admin to log in again; the request remains Pending.

Outcome: An Invited user exists and has an activation link. Covers: FR-ADM-1, FR-ADM-2, FR-ADM-4, FR-ADM-5, FR-ADM-18, FR-ADM-13, FR-ADM-14, FR-ADM-15, FR-REQ-5, BR-8, BR-10, NFR-11 Phase: 1b


UJ-10 — Reject an access request ​

ActorSuper Admin
GoalDecline a request
TriggerReviews a Pending request and decides not to approve it
PreconditionsRequest is Pending

Main flow

  1. U opens the request and clicks Reject.
  2. S asks for an optional reason (internal note).
  3. U confirms.
  4. S marks the request Rejected, records it in the audit log, and sends the requester a short, polite email saying the request wasn't approved, without the reason. (FR-REQ-5)

Alternative & error flows

  • A1 — Rejected by mistake: U filters requests by Rejected, opens the request, and clicks Approve. S continues as in UJ-09 step 5. (FR-ADM-6a)
  • A2 — Reject several at once: U ticks several requests and clicks Reject selected. (FR-ADM-18, Could)

Outcome: Request is Rejected. The same email can request again after 30 days. Covers: FR-ADM-6, FR-ADM-6a, FR-ADM-18, FR-ADM-14, FR-REQ-5, BR-14 Phase: 1b


UJ-11 — Create a user directly ​

ActorSuper Admin
GoalInvite someone who never filled in the request form (e.g. a family member)
TriggerSuper Admin decides to invite someone personally
PreconditionsThe email doesn't already belong to a user

Main flow

  1. U opens Users → New user, enters name and email.
  2. S checks the email is not already used, creates the user as Invited, sends the activation link, and records it in the audit log.

Alternative & error flows

  • A1 — Email already belongs to a user: S shows the existing user and their status instead of creating a duplicate. (BR-9)
  • A2 — Email has a Pending request: S approves that request instead of creating a separate user, and tells the Super Admin: "This email had a pending request. It has been approved." (FR-ADM-7a)

Outcome: Invited user exists; the person continues with UJ-03. Covers: FR-ADM-7, FR-ADM-7a, FR-ADM-14, BR-8, BR-9 Phase: 1b


UJ-12 — Deactivate and reactivate a user ​

ActorSuper Admin
GoalSuspend someone's access without losing their data, and later restore it
TriggerSuspicious behaviour, a request from the user, or any other reason
PreconditionsUser is Active (to deactivate) or Deactivated (to reactivate)

Main flow — deactivate

  1. U searches the user list, opens the user, clicks Deactivate, and confirms.
  2. S sets the status to Deactivated, ends all the user's sessions (UJ-07), and records it in the audit log.

Main flow — reactivate

  1. U opens a Deactivated user and clicks Reactivate.
  2. S sets the status to Active and records it. The user logs in with their existing password; all data is still there.

Alternative & error flows

  • A1 — Target is the last Super Admin: S blocks the action. (BR-13)
  • A2 — The user is the only Owner of a shared space: Nothing changes in that space. Other members keep using it, but nobody can manage it (members, financial accounts, budgets) until the user is reactivated, or deleted (then BR-33 hands it over). The Super Admin isn't told about this, because they can't see spaces. (BR-43)

Outcome: Access is suspended or restored; data is untouched. Covers: FR-ADM-8, FR-ADM-9, FR-ADM-14, FR-AUTH-9, BR-11, BR-13, BR-43 Phase: 1b


UJ-13 — Permanently delete a user ​

ActorSuper Admin
GoalRemove a user and all their data for good
TriggerUser asks to be removed (e.g. by email), or a legal data-deletion request
PreconditionsTarget is not the last Super Admin

Main flow

  1. U opens the user and clicks Delete permanently.
  2. S warns that the user and all their data will be removed and that it can't be undone, and asks the Super Admin to type the user's email to confirm.
  3. U types the email and confirms.
  4. S ends all sessions, deletes the user and their Personal space, relabels their transactions in shared spaces as "Former member", hands over any shared space where they were the last Owner (or deletes it if no one else is in it), and records the deletion in the audit log (who, which user, when; no financial data or space details).

Alternative & error flows

  • A1 — Typed email doesn't match: Delete button stays disabled.
  • A2 — Target is the last Super Admin: Blocked. (BR-13)

Outcome: User is Deleted; only the audit entry and their shared-space transactions (as "Former member") remain. Deleted data disappears from all backups within 90 days. (NFR-10)Covers: FR-ADM-11, FR-ADM-14, FR-ADM-17, FR-AUTH-9, NFR-3, NFR-12, BR-11, BR-13, BR-33, BR-34 Phase: 1b


UJ-14 — Help a user who cannot log in ​

ActorSuper Admin
GoalGet a stuck person into Crest
TriggerSomeone contacts the Super Admin: "My link expired", "I can't log in", "I typed my email wrong"
Preconditions—

Main flow

  1. U searches the user by name or email → S shows status, created date, last login.
  2. Depending on the status, U takes one action:
Status shownProblemActionSystem response
InvitedActivation link expired or lostResend activation linkNew 72-hour link sent; old link invalidated
InvitedEmail address was wrongEdit email, then resendEmail updated, new link sent
ActiveChanged their email addressEdit emailNotice sent to the old and new address; the change takes effect once the user confirms from the new address (FR-ADM-12)
ActiveForgot passwordSend password-reset emailReset email sent (UJ-05)
DeactivatedSuspendedDecide whether to Reactivate (UJ-12)—
Not foundNever requested or was rejectedAsk them to request access (UJ-01) or create directly (UJ-11)—
  1. S records every action in the audit log.

Outcome: The person has what they need to get in. Covers: FR-ADM-8, FR-ADM-10, FR-ADM-12, FR-ADM-14, FR-AUTH-3 Phase: 1b


UJ-15 — First-time portal setup, daily check, and audit review ​

ActorSuper Admin
GoalSet up the portal once, then keep an eye on access
TriggerLaunch day; then routine checks
PreconditionsThe first Super Admin was created by the setup (seed) script

Main flow — first time

  1. U receives the Super Admin credentials from setup and logs in to the portal.
  2. S requires two-factor setup before anything else: shows a QR code for an authenticator app and asks for a code to confirm.
  3. U scans, confirms → S shows one-time backup codes and asks the Super Admin to store them safely (e.g. in a password manager). (FR-ADM-2a)
  4. U confirms they saved the codes → S shows the overview.

Main flow — daily check

  1. U logs in → S shows the overview counts.
  2. U handles pending requests (UJ-09 / UJ-10).

Main flow — audit review

  1. U opens Audit log → S lists actions (who, what, which user, when), newest first, filterable by action type and date.
  2. Entries are read-only; they can't be edited or deleted.

Alternative & error flows

  • A1 — Lost authenticator device: U logs in with a backup code, then sets up 2FA again on a new device. Each code works once. (FR-ADM-2a)
  • A1b — Lost device and backup codes: Someone with server access runs the setup script to reset the Super Admin's 2FA; the reset is recorded in the audit log. (FR-ADM-3a)
  • A2 — Give another user the Super Admin role: U opens an Active user → Make Super Admin → S updates the role and records it. The next time that user opens the portal, S requires them to set up 2FA first (steps 2–4). They keep using Crest normally with their own spaces. The last Super Admin can't lose the role. (FR-ADM-16, BR-41)

Outcome: Portal is secured and access requests are handled promptly. Covers: FR-ADM-2, FR-ADM-2a, FR-ADM-3, FR-ADM-3a, FR-ADM-14, FR-ADM-15, FR-ADM-16, NFR-11, NFR-12, BR-13, BR-41 Phase: 1b


6. Onboarding and device journeys ​

UJ-16 — First-time setup ​

ActorLocal user (e.g. Dina, opening Crest for the first time)
GoalGet Crest ready to track real money within a couple of minutes
TriggerThe welcome (UJ-50) is finished
PreconditionsThe device has no Crest data yet

S creates the Personal space on the device. Everything in this journey happens there. (FR-MOD-3) If the person later connects, it is uploaded into their Personal space on the server (UJ-52).

Main flow

  1. S asks for the language (English / Bahasa Indonesia), defaulting to the device's language.
  2. S asks for the base currency, suggesting one from the device's region (e.g. IDR for Indonesia). U can pick any ISO 4217 currency.
  3. S offers to turn on the app lock (optional; the PIN stays on this device, UJ-04 A6).
  4. S asks "Where do you keep your money?" and shows the four financial account types with examples:
    • Cash wallet
    • Bank (BCA, Mandiri, Chase…)
    • E-wallet / online payment (GoPay, OVO, PayPal…)
    • Credit card
  5. U adds the first financial account, e.g. BCA — Bank — IDR — opening balance 5,000,000.
  6. S creates it and asks "Add another?"
  7. U adds more, for example:
    • GoPay — E-wallet — IDR — 250,000
    • Wallet — Cash — IDR — 300,000
    • BCA Visa — Credit card — IDR — currently owed 1,200,000, credit limit 10,000,000
  8. U taps Done.
  9. S loads the default categories, optionally asks for the budget start day (e.g. payday on the 25th), and (from Phase 2, in connected mode) offers a daily reminder (UJ-37).
  10. If Crest isn't on the home screen yet, S shows how to add it (UJ-38).
  11. S opens the dashboard showing total balance and net worth, with a hint: "Tap + to log your first expense."

Alternative & error flows

  • A1 — User skips adding financial accounts: S lets them continue. The + button prompts them to add a financial account before the first transaction can be saved.
  • A2 — Financial account in another currency (e.g. PayPal in USD): Allowed (FR-FIN-5). If no exchange rate exists, the dashboard marks that financial account "not included in total — add a rate" (UJ-35).
  • A3 — User quits mid-way: Everything already saved is kept on the device; the next open continues where they stopped.
  • A4 — Person joined mainly to use someone else's shared space (e.g. Jojo): U can skip adding financial accounts and connect first (UJ-52). After connecting, S shows any pending invitation (UJ-43).

Outcome: The device has a Personal space with a base currency, language, at least one financial account, default categories, and a dashboard. Covers: FR-MOD-3, FR-SET-1, FR-SET-3, FR-FIN-1, FR-FIN-5, FR-FIN-8, FR-FIN-10, FR-CAT-1, FR-AUTH-6, FR-NOT-1, FR-APP-2, FR-DSH-1, NFR-8, BR-1, BR-3, BR-32 Phase: 1a


UJ-38 — Add Crest to the home screen ​

ActorUser (e.g. Dina on an iPhone, Budi on Android)
GoalOpen Crest like an app, with one tap
TriggerThe welcome on iPhone and iPad (UJ-50), the guide at the end of first-time setup (UJ-16), the install page on the public website, or More → Add to home screen
PreconditionsCrest is open in the device's browser

Main flow — iPhone and iPad (Safari)

  1. S shows a short illustrated guide: tap Share → Add to Home Screen → Add.
  2. U follows the steps → the Crest icon appears on the home screen.
  3. U opens Crest from the icon → it opens full-screen, like an app. iOS keeps the home-screen app separate from Safari: a connected user logs in once more, and data entered in Safari is not visible in the home-screen app. That is why the welcome asks iPhone users to add Crest to the home screen before entering data (UJ-50).

Main flow — Android and computers (Chrome, Edge)

  1. S shows an Install Crest button (or U uses the browser's Install option).
  2. U taps it and confirms → the Crest icon is added to the home screen or app launcher, and Crest opens in its own window.

Alternative & error flows

  • A1 — User skips it: Crest keeps working in the browser. The guide stays under More → Add to home screen, and S reminds U at most once a week.
  • A2 — iPhone user is not in Safari (e.g. Chrome on iOS): S explains how to add Crest from that browser's Share menu, or to open the link in Safari.
  • A3 — Push notifications (Phase 2): After Crest is on the home screen, S explains what notifications are for and asks Allow notifications? On iPhone this is only possible from the home-screen app. If U declines, reminders and alerts appear in the notification list inside Crest. (FR-APP-3, FR-NOT-3)
  • A4 — iOS older than 16.4: Crest can be added to the home screen, but push notifications are not available.
  • A5 — U already entered data in Safari: U saves a backup file in Safari (UJ-51), adds Crest to the home screen, and restores the file there. Safari clears the storage of sites it was not used on for about a week, so this should not wait.

Outcome: Crest opens from the home screen like an app. Covers: FR-APP-1, FR-APP-2, FR-APP-3, FR-MOD-6, FR-NOT-3, NFR-9, NFR-14, BO-6 Phase: 1a


UJ-50 — Start using Crest with no login ​

ActorVisitor (e.g. Dina, who got the Crest link from a friend)
GoalStart recording right away, with no sign-up
TriggerOpens the Crest app link, or taps Open Crest on the public website
PreconditionsNone

Main flow

  1. U opens the app → S loads it (about 3 MB the first time) and shows a short welcome: what Crest is, in two lines.
  2. S says in plain words: "Your data stays on this device. Crest can't see it, and can't get it back if it is lost. Save a backup file now and then." (FR-MOD-6)
  3. S asks U to tick one box: "I'm 18 or older and accept the Privacy Policy and Terms of Use" (both linked). Continue stays disabled until it is ticked. The answer is kept on the device. (FR-MOD-4, BR-44)
  4. On an iPhone or iPad in Safari, S asks U to add Crest to the home screen first and shows the steps (UJ-38), because Safari can clear the storage of sites it was not used on for about a week, and the home-screen app keeps its data apart from Safari. U can continue in Safari after a clear warning. (FR-MOD-6)
  5. S asks the browser to keep Crest's data. If the browser says no, Crest still works and Settings shows a note. (FR-MOD-7)
  6. S starts first-time setup (UJ-16).

Alternative & error flows

  • A1 — U does not accept: S does not continue and nothing is stored. U can close the page.
  • A2 — U opens Crest in a private or incognito window: S warns that the data will be erased when the window closes.
  • A3 — U already has a backup file (e.g. from another phone): The welcome offers Restore from a backup file (UJ-51) instead of first-time setup.
  • A4 — U has been given access and wants sync: U goes to More → Connect to Crest later, or taps I have access on the welcome (UJ-52).
  • A5 — No internet on the first visit: The app can't load. After the first load it works without internet (UJ-25).

Outcome: Crest is ready on the device. Nothing has been sent to Crest's servers, and no login exists. Covers: FR-MOD-1, FR-MOD-2, FR-MOD-4, FR-MOD-6, FR-MOD-7, FR-APP-1, NFR-3, NFR-4, BR-44, BR-46, BO-7 Phase: 1a


UJ-51 — Save and restore a backup file ​

ActorLocal user, or User (connected users can save a file too)
GoalKeep a safe copy of my data, or move it to another device
TriggerThe backup reminder, Settings → Backup, a new phone, the browser cleared Crest's data, or a forgotten PIN in local mode
PreconditionsTo save: there is some data. To restore: U has a Crest backup file

Main flow — save

  1. U opens Settings → Backup → Save backup file, or taps the reminder.
  2. S creates one file with all the data (financial accounts, transactions, categories, budgets, goals, exchange rates, and settings, but not the PIN) and opens the device's share menu (on a computer it downloads the file).
  3. U saves it to Files, sends it to themselves, or copies it somewhere safe. S remembers the date of the last backup, and the reminder resets.

Main flow — restore

  1. U taps Restore from a backup file on the welcome (new device) or in Settings → Backup, and picks the file.
  2. S checks that it is a Crest backup and shows its date and a summary ("3 financial accounts, 214 transactions"). If the device already has data, S warns that restoring replaces everything on this device and offers to save the current data first.
  3. U confirms → S restores the data, recalculates balances, and opens Home.

Alternative & error flows

  • A1 — The file is not a Crest backup, or is damaged: S says so and changes nothing.
  • A2 — The backup comes from an older version of the app: S converts it. If it comes from a newer version, S asks U to update first (UJ-39).
  • A3 — Forgot the PIN (local mode): U chooses Erase this device and restore a backup file, typing a confirmation. Without a backup file the data cannot be recovered. (BR-49)
  • A4 — Backup reminder: If the last backup is more than 30 days old and data has changed, S shows a gentle reminder, at most once a week, that U can dismiss. (FR-MOD-8)
  • A5 — U is connected: The server has the data, so Restore is not offered. To restore a file, U logs out and keeps a local copy first (UJ-52 A6).

Outcome: The data is safe in a file, or restored on the device. Restoring the same file twice creates no duplicates. (BR-48)Covers: FR-MOD-5, FR-MOD-8, FR-DAT-1, NFR-14, BR-48, BR-49 Phase: 1a


UJ-52 — Connect to Crest and upload this device's data ​

ActorLocal user who has been given access (e.g. Dina, after her request was approved)
GoalUse Crest on several devices or in shared spaces, and keep what is already recorded
TriggerTaps Open Crest after activating (UJ-03), or More → Connect to Crest
PreconditionsThe user is Active. The device may or may not have local data

Main flow

  1. U opens More → Connect to Crest → S shows Log in and, for people without access, Request access (UJ-01).
  2. U logs in with email and password (UJ-04).
  3. S checks the user's Personal space on the server.
  4. If that space is empty and the device has data, S asks: "Upload 214 transactions from this device?" with Upload (the default) and Start fresh. U taps Upload. (FR-MOD-10, BR-47)
  5. S uploads the data. Every record keeps its ID, and the server checks each one against the same money rules the app uses before accepting it. S shows "Synced". If the device's currency differs from the user's base currency, S explains and asks U to review budgets (FR-SET-4).
  6. S sets up the app lock for the user (UJ-04 step 3), offering to reuse the device's local PIN.
  7. From now on changes sync automatically. S shows any pending shared-space invitation (UJ-43).

Alternative & error flows

  • A1 — The device has no data (a new device): S simply downloads the user's data. Nothing to ask.
  • A2 — The user's Personal space on the server already has data (a second device) and this device has local data: S never merges them automatically. U chooses Use my Crest data (S first offers to save this device's data as a backup file, then replaces it) or Keep this device's data local only (U logs out and carries on in local mode). (BR-47)
  • A3 — The upload is interrupted (e.g. the connection drops): Nothing is lost. The data stays on the device, S shows Waiting to sync and retries. Because every record has its own ID, retrying never creates duplicates. (BR-48)
  • A4 — The server rejects some records: S lists them ("1 transaction could not be uploaded") and offers to save them in a file. The rest is uploaded.
  • A5 — Login fails, or the user is deactivated: UJ-04 A1 and A5. The device's local data is not touched.
  • A6 — U logs out later: S asks whether to keep a local copy on the device (Crest continues in local mode and no longer syncs) or remove the data from the device. (FR-MOD-11)

Outcome: The user's data is on the server and syncs between their devices. Shared spaces are available. Covers: FR-MOD-9, FR-MOD-10, FR-MOD-11, FR-MOD-12, FR-AUTH-4, FR-SET-4, FR-SPC-1, BR-47, BR-48, BO-6 Phase: 1b


7. Everyday money journeys ​

UJ-17 — Log a daily expense ​

ActorUser (Dina buys lunch for 45,000 IDR with GoPay)
GoalRecord spending in a few seconds
TriggerJust paid for something
PreconditionsAt least one financial account exists

Main flow

  1. U opens Crest (unlocks) → dashboard.
  2. U taps + → S opens the entry screen with Expense selected, the amount keypad focused, date = today, and the financial account set to the one used last.
  3. U types 45000.
  4. U taps category Food & Drink (the most-used categories appear first).
  5. U checks the financial account is GoPay (or changes it) and optionally adds a note, e.g. "Lunch with team".
  6. U taps Save.
  7. S saves immediately (optimistic update), reduces the GoPay balance by 45,000, updates the Food & Drink budget progress, and returns to the dashboard with a brief "Saved" and Undo.

Alternative & error flows

  • A1 — Different date: U changes the date and time before saving (e.g. yesterday's forgotten coffee). The transaction's created_at is set to that moment.
  • A1b — Future date (planned payment): Dina enters next month's rent, 2,500,000, dated the 1st. S puts it under Upcoming. GoPay's balance stays as of now, with "after upcoming" shown underneath, and the rent counts toward next month's budget. On the 1st it becomes a normal transaction. (FR-TRX-9, BR-42)
  • A2 — Receipt photo: U attaches a photo before saving. (FR-TRX-6, Could)
  • A3 — Undo: U taps Undo within a few seconds; S removes the transaction.
  • A4 — Amount is zero or empty: Save is disabled.
  • A5 — Budget threshold crossed: S triggers a budget alert (UJ-28).
  • A6 — Offline: Saved on the device at once; in connected mode it syncs later (UJ-25).
  • A7 — Expense pushes a cash or e-wallet balance below zero: Allowed, but S shows the negative balance in red so the user can fix a wrong opening balance. (FR-FIN-10a, BR-23)
  • A8 — U belongs to shared spaces: The financial account picker groups financial accounts by space. The category picker always shows the categories of the chosen financial account's space, and switches automatically if U changes the financial account. (FR-CAT-4, BR-31) See UJ-44.

Outcome: Expense recorded; balance, budget, and dashboard updated. Target: ≤ 3 taps from the Home screen and ≤ 10 seconds median. (BO-2, NFR-7)Covers: FR-TRX-1, FR-TRX-6, FR-TRX-9, FR-BUD-2, FR-CAT-4, FR-FIN-3, FR-FIN-10a, NFR-4, NFR-7, BO-2, BR-3, BR-23, BR-31, BR-42 Phase: 1a


UJ-18 — Log income ​

ActorUser (Sari receives a 7,500,000 IDR freelance payment into Mandiri)
GoalRecord money coming in
TriggerGot paid
PreconditionsAt least one financial account exists

Main flow

  1. U taps + → switches the type to Income.
  2. U enters 7500000, chooses category Freelance, financial account Mandiri, and a note "Client A — Sept invoice".
  3. U taps Save → S increases the Mandiri balance and updates this month's income on the dashboard.

Alternative & error flows

  • A1 — Needs a new income category (e.g. "Client A"): U creates it inline from the category picker (UJ-34).
  • A2 — Regular salary: U sets it up as recurring (UJ-26).

Outcome: Income recorded; balance and dashboard updated. Covers: FR-TRX-1, FR-CAT-2, FR-DSH-1, FR-DSH-3, BR-3 Phase: 1a


UJ-19 — Top up an e-wallet or withdraw cash ​

ActorUser (Budi tops up OVO with 200,000 IDR from BCA, then withdraws 500,000 IDR cash at an ATM)
GoalRecord money moving between his own financial accounts without it counting as spending
TriggerMoved money between his own financial accounts
PreconditionsBoth financial accounts exist and use the same currency

Main flow

  1. U taps + → switches the type to Transfer.
  2. U enters 200000, From: BCA, To: OVO.
  3. U taps Save → S reduces BCA by 200,000 and increases OVO by 200,000. Income and expense totals don't change.
  4. For the ATM withdrawal, U repeats with From: BCA, To: Wallet (cash), 500000.

Alternative & error flows

  • A1 — Top-up fee (e.g. 1,000 IDR admin fee): U enters 1000 in the optional Fee field. S saves a separate 1,000 IDR expense in Fees from BCA, so BCA drops by 201,000 in total and OVO rises by 200,000. (FR-TRX-2e)
  • A2 — From and To are the same financial account: Save is disabled.
  • A3 — Different currencies: S switches to the cross-currency form (UJ-22).

Outcome: Both balances correct; no effect on income, expenses, or budgets. Covers: FR-TRX-2, FR-TRX-2e, FR-FIN-13, BR-2, BR-3 Phase: 1a


UJ-20 — Pay with a credit card ​

ActorUser (Budi buys groceries for 850,000 IDR with his BCA Visa)
GoalRecord spending made on credit
TriggerPaid by credit card
PreconditionsA credit card financial account exists

Main flow

  1. U taps + → Expense, 850000, category Groceries, financial account BCA Visa.
  2. U taps Save.
  3. S records the expense now (it counts toward this month's Groceries budget), increases the amount owed on BCA Visa by 850,000, reduces available credit, and lowers net worth.

Alternative & error flows

  • A1 — Purchase would exceed the credit limit: S saves it (it really happened) and highlights the card as over its limit. (FR-FIN-10a, BR-23)
  • A2 — Refund to the card: Budi returns a 150,000 IDR item. U taps + → Refund, 150,000, category Groceries, financial account BCA Visa, and optionally links it to the original purchase. S reduces the amount owed and reduces Groceries spending (and its budget use) by 150,000. It does not count as income. (FR-TRX-8, BR-24)

Outcome: Expense counted once, at purchase time; the card shows the higher amount owed. Covers: FR-TRX-1, FR-TRX-8, FR-FIN-4, FR-FIN-10, FR-FIN-10a, BR-18, BR-23, BR-24 Phase: 1a


UJ-21 — Pay a credit card bill ​

ActorUser (Budi pays his 3,400,000 IDR BCA Visa bill from his BCA savings)
GoalRecord the bill payment without counting the spending twice
TriggerCard statement or due-date reminder
PreconditionsCredit card financial account with an amount owed

Main flow

  1. S (optional, if a due day is set) sends a reminder a few days before the due date: "BCA Visa payment due on 5 Oct — 3,400,000 IDR owed." (FR-FIN-11, Could)
  2. U opens the BCA Visa financial account → taps Pay bill (a shortcut for a transfer to this card).
  3. S pre-fills: Transfer, To: BCA Visa, amount = current amount owed.
  4. U chooses From: BCA (bank), adjusts the amount if paying only part, and taps Save.
  5. S reduces BCA by 3,400,000 and reduces the amount owed on BCA Visa by 3,400,000. Expenses and budgets don't change, because the purchases were already counted (UJ-20).

Alternative & error flows

  • A1 — Partial payment: U changes the amount; the rest stays owed.
  • A2 — Overpayment: Allowed. The card shows a credit balance (the card issuer owes the user), which is used up by later purchases. (FR-FIN-10a, BR-23)
  • A3 — Card in a different currency from the bank: S switches to the cross-currency form (UJ-22).

Outcome: Bank and card balances are correct; spending is not double-counted. Covers: FR-FIN-10a, FR-FIN-11, FR-FIN-12, FR-TRX-2, BR-2, BR-18, BR-23 Phase: 1 (reminder: Could)


UJ-22 — Transfer between currencies with a manual rate ​

ActorUser (Sari gets paid 100 USD in PayPal and withdraws it to her BCA bank (IDR))
GoalRecord the move with the real rate and the real amount received
TriggerMoved money between financial accounts in different currencies
PreconditionsTwo financial accounts with different currencies (FR-FIN-5)

Main flow

  1. U taps + → Transfer, From: PayPal (USD), To: BCA (IDR).
  2. S notices the currencies differ and shows the cross-currency form: Amount sent (USD), Exchange rate, Amount received (IDR).
  3. S pre-fills the rate with Sari's saved USD rate if she has one, e.g. 1 USD = 16,000 IDR (saved 12 Sep). (FR-TRX-2d, Could)
  4. U enters Amount sent: 100.00.
  5. U enters the rate PayPal actually used: 16,250 → S calculates Amount received: 1,625,000 IDR.
  6. U checks her BCA app, sees 1,620,000 IDR actually arrived, and edits Amount received → S recalculates the effective rate: 16,200.
  7. S asks: Save this rate as my USD rate? (optional). U taps Not now.
  8. U taps Save.
  9. S stores one transfer with: 100.00 USD sent, 1,620,000 IDR received, rate 16,200. PayPal −100.00 USD; BCA +1,620,000 IDR. No income or expense is recorded.

Alternative & error flows

  • A1 — User knows the amount received but not the rate: U enters amount sent and amount received; S calculates the rate. (FR-TRX-2b)
  • A2 — Separate transfer fee (e.g. 2.00 USD charged by PayPal): U enters it in the optional Fee field; S saves a separate 2.00 USD expense in Fees from PayPal. (FR-TRX-2e, Could)
  • A3 — Rate or amount is zero or empty: Save is disabled.
  • A4 — User later changes their saved USD rate: This transfer does not change. (BR-16)
  • A5 — User edits this transfer later: S opens the same form. Changing any of amount sent, rate, or amount received recalculates the third. Only this transfer changes. (FR-TRX-3a)

Outcome: Both balances match reality in their own currencies; the rate used is stored with the transfer. Covers: FR-TRX-2, FR-TRX-2a, FR-TRX-2b, FR-TRX-2c, FR-TRX-2d, FR-TRX-2e, FR-TRX-3a, FR-FIN-6, BR-1, BR-2, BR-15, BR-16 Phase: 2


UJ-23 — Fix or delete a transaction ​

ActorUser
GoalCorrect a mistake
TriggerNotices a wrong amount, category, date, or financial account
PreconditionsTransaction exists

Main flow — edit

  1. U taps the transaction in the list → S opens it in edit mode.
  2. U changes the amount (or category, date, financial account, note) and taps Save.
  3. S recalculates the affected balances, budgets, and dashboard figures.

Main flow — delete

  1. U swipes the transaction (or opens it) → Delete → confirms.
  2. S removes it and recalculates balances and budgets.

Alternative & error flows

  • A1 — Editing a transfer: Changing the amount updates both financial accounts.
  • A2 — Editing or deleting a transaction created by a recurrence: S asks Only this one or This and all future ones. (FR-TRX-5a)
  • A3 — Editing a cross-currency transfer: Same form as creating it; see UJ-22 A5. (FR-TRX-3a)
  • A4 — Transaction in a shared space added by someone else: A Member sees it read-only (no Edit or Delete) with "Added by Rina". An Owner can edit or delete it; the transaction then shows "Edited by Boss". (FR-SPC-7, BR-36)

Outcome: The record and all derived figures are correct. Covers: FR-TRX-3, FR-TRX-3a, FR-TRX-5a, FR-SPC-7, FR-FIN-3, FR-BUD-2, BR-3, BR-36 Phase: 1a


UJ-24 — Find a past transaction ​

ActorUser (Budi wants to know how much he spent at the pharmacy this year)
GoalFind specific transactions quickly
TriggerQuestion about past spending
PreconditionsTransactions exist

Main flow

  1. U opens Transactions (of the current space, here Personal) → taps the search box and types "pharmacy".
  2. S matches notes and categories and shows results as he types.
  3. U adds filters: date range This year, category Health, financial account Any.
  4. S shows the matching list with a total for the filtered results.

Alternative & error flows

  • A1 — No results: S shows "No transactions match" with a Clear filters button.
  • A2 — Filter by amount: e.g. more than 1,000,000 IDR.
  • A3 — Transaction is in another space: U switches space first; search covers the current space only.

Outcome: User sees exactly the transactions they need. Covers: FR-TRX-4 Phase: 1a


UJ-25 — Log a transaction without internet ​

ActorLocal user or User (Dina pays cash at a market with no signal)
GoalRecord spending without internet
TriggerPaid while offline
PreconditionsCrest has been opened once on this device, so its files are saved on it

Main flow

  1. U opens Crest → S opens from the files and data on the device and unlocks with the PIN if it is on (this works offline). In connected mode S shows an Offline indicator; in local mode nothing changes, because the app never needed internet.
  2. U logs the expense as in UJ-17.
  3. S saves it on the device and updates balances at once. In connected mode it marks the transaction Waiting to sync.
  4. In connected mode, when the connection returns, S uploads it automatically and removes the marker.

Alternative & error flows

  • A1 — Same transaction edited on two devices while offline (connected mode): When both sync, the change the server receives last wins. If one device deleted it, the delete wins. (BR-21)
  • A2 — User was deactivated while offline (connected mode): Sync is refused and the unsynced changes are discarded (UJ-07). (BR-21, BR-50)
  • A3 — The browser cleared Crest's data (e.g. on iPhone after a long time unused), or the device is lost: In connected mode, everything already synced is safe on the server and reloads at the next login; only changes not yet synced are lost. In local mode the data is gone unless U saved a backup file (UJ-51), which is why S warns U before they start and reminds them to save one. (NFR-14, FR-MOD-6, FR-MOD-8)

Outcome: Nothing is lost while the device keeps its data; in connected mode it syncs once online. Covers: FR-TRX-7, FR-APP-4, FR-MOD-12, NFR-5, NFR-14, BR-21, BR-46 Phase: 1a (sync: 1b)


UJ-26 — Set up a recurring transaction ​

ActorUser (Sari pays a 150,000 IDR phone plan every month on the 3rd)
GoalStop logging the same transaction every month
TriggerLogs a regular bill or salary
Preconditions—

Main flow

  1. U creates the expense as in UJ-17 and turns on Repeat.
  2. U chooses Monthly, on day 3, with no end date.
  3. S saves it and shows it under Recurring.
  4. On each due date S creates the transaction automatically. In connected mode the server does it, even if the phone is off or offline, and sends a notification: "Phone plan 150,000 IDR recorded." In local mode the app creates any missed occurrences, dated on their due dates, the next time Crest is opened, and shows them in the list.

Alternative & error flows

  • A1 — Amount changes one month: U edits that occurrence and chooses Only this one; for a permanent price change, This and all future ones. (FR-TRX-5a)
  • A2 — Stop the recurrence: U opens Recurring → the item → Stop. Past transactions stay.
  • A3 — Recurrence on day 29, 30, or 31 in a shorter month: S uses the last day of that month. (BR-25)
  • A4 — Recurring transfer (e.g. monthly savings to another bank): Supported the same way.
  • A5 — Recurring transaction in a shared space (e.g. Andi sets the monthly electricity bill in Family): It belongs to Andi and shows "Added by Andi" each month. If Andi leaves Family, it stops. (FR-TRX-5c, BR-40)

Outcome: Regular transactions appear automatically. Covers: FR-TRX-5, FR-TRX-5a, FR-TRX-5b, FR-TRX-5c, FR-NOT-1, BR-25, BR-40 Phase: 2


8. Planning & insight journeys ​

UJ-27 — Set monthly budgets ​

ActorUser (Budi wants to control household spending)
GoalSet spending limits per category
TriggerStart of a month, or after seeing overspending on the dashboard
PreconditionsCategories exist; U is an Owner of the current space (always true for the Personal space)

Main flow

  1. U opens Budgets → S shows expense categories with last month's spending as a hint.
  2. U sets limits, e.g. Groceries 3,000,000, Food & Drink 1,500,000, Transport 800,000 (in the space's currency; for the Personal space, the base currency).
  3. S saves them and shows progress bars: spent, remaining, and days left in the budget period.
  4. S repeats the same budgets every month until the user changes them.

Alternative & error flows

  • A1 — Budget month starts on payday: Periods run from the chosen start day (e.g. 25th to 24th). (FR-SET-3, BR-4)
  • A2 — Expenses in another currency: Converted into the space's currency with the viewing user's saved rate and added to the budget. If the rate is missing, they're left out and the budget shows "Some USD spending isn't counted — add a rate." (FR-BUD-7, BR-22)
  • A3 — Category archived: Its budget stops; past progress stays in history.
  • A4 — Shared space: Boss sets Kitchen's budget, e.g. Vegetables 2,000,000 and Gas 300,000 per month. Jojo sees the budgets and their progress but can't change them. (FR-BUD-1)
  • A5 — Budget on a parent category: A Food & Drink budget of 1,500,000 includes spending in its sub-category Coffee. (FR-BUD-8, Could)

Outcome: Budgets exist and progress updates with every expense. Covers: FR-BUD-1, FR-BUD-2, FR-BUD-7, FR-BUD-8, FR-SET-3, BR-4, BR-22, BO-3 Phase: 1a


UJ-28 — Get a budget alert and react ​

ActorUser
GoalKnow before overspending
TriggerA new expense takes a budget to 80% or 100%
PreconditionsBudget exists; notifications allowed (UJ-38)

Main flow

  1. U logs an expense that takes Food & Drink to 82% of its budget.
  2. S sends a push notification: "You've used 82% of your Food & Drink budget with 9 days left."
  3. U taps it → S opens the budget detail with the transactions for this period.
  4. U decides to cut back, or raises the budget for this month.
  5. At 100% S sends one more alert: "Food & Drink budget reached."

Alternative & error flows

  • A1 — Push notifications off, not allowed, or (on iPhone) Crest not added to the home screen: No push notification; the budget bar turns amber at 80% and red at 100% inside Crest. (FR-NOT-3)
  • A2 — Several expenses cross the threshold together (e.g. after an offline sync): S sends one alert per threshold, not one per expense.
  • A3 — Budget in a shared space: Every member of the space gets the alert, e.g. both Boss and Jojo when Kitchen's Vegetables budget reaches 80%. A Member can't raise the budget; they tell the Owner outside Crest. (FR-BUD-3)

Outcome: User reacts before or right when the budget runs out. Covers: FR-BUD-3, FR-NOT-2, FR-NOT-3 Phase: 2


UJ-29 — Create and track a savings goal ​

ActorUser (Dina wants 12,000,000 IDR for a trip by June)
GoalSave toward a target
TriggerDecides to save for something
PreconditionsIdeally a financial account used only for savings, e.g. "BCA Tabungan"

Main flow

  1. U opens Goals → New goal: name "Bali trip", target 12,000,000 IDR, target date 1 June.
  2. S asks "Which financial account holds this money?" and lists the financial accounts in the current space → U picks BCA Tabungan. (Goals are created by the space's Owners, and the financial account must be in the same space.)
  3. S shows progress = BCA Tabungan's current balance (e.g. 3,000,000 of 12,000,000) and how much to save per month to reach the target on time.
  4. Each payday U records a normal transfer, e.g. BCA → BCA Tabungan 1,500,000 (UJ-19). S updates the goal progress automatically; nothing extra to enter.
  5. When the balance reaches the target, S congratulates her and marks the goal complete.

Alternative & error flows

  • A1 — Behind schedule: S shows the new monthly amount needed.
  • A2 — No dedicated financial account: U skips step 2 and records contributions to the goal manually (e.g. "+500,000"). Progress = sum of contributions. (FR-BUD-6, Could)
  • A3 — Money taken out of the linked financial account: Progress goes down, because it follows the balance.

Outcome: User sees progress toward the goal without entering the money twice. Covers: FR-BUD-4, FR-BUD-5, FR-BUD-6 Phase: 2


UJ-30 — Review spending in Stats ​

ActorUser (Sari at the end of the month)
GoalUnderstand where the money went, and see the transactions behind each number
TriggerEnd of month or payday
PreconditionsAt least a few weeks of transactions

Main flow

  1. U glances at Home → S shows total balance, this month's income, expenses, and net (income − expenses). (FR-DSH-1)
  2. U opens the Stats tab → S shows the Categories chart for this month (budget period), with the total in the middle. Below it, S lists the transactions of the largest category. (FR-DSH-5, FR-DSH-6, FR-DSH-7, FR-DSH-11)
  3. U taps the Food & Drink slice → S highlights it, shows its amount and share, and the list below changes to Food & Drink transactions, grouped by day, with count and total.
  4. U switches to Calendar → S shows the month as a heatmap. U taps the darkest day (a Saturday) → the list shows that day's transactions. (FR-DSH-8)
  5. U switches to Trend → S shows the last 6 months. U taps August → S shows the change vs July, and the list shows August's largest expenses. (FR-DSH-3, FR-DSH-4, FR-DSH-9)
  6. U switches to Accounts and taps GoPay → the list shows what went out from GoPay. (FR-DSH-10)
  7. U taps Open in Activity → S opens Activity already filtered the same way, where U can edit or search further. (FR-TRX-4)
  8. U goes to Budgets and lowers or raises next month's limits (UJ-27).

Alternative & error flows

  • A1 — Period: U switches Week / Month / Year, or steps back to an earlier period; every chart and the list follow.
  • A2 — Selection has no spending (e.g. an empty day): The list shows "No spending here."
  • A3 — Transactions in other currencies: Converted with the viewer's saved rates and marked as estimates; missing rates show a warning (UJ-31).
  • A4 — Too few transactions: S shows an empty state that encourages logging.
  • A5 — Shared space: Stats covers only that space, and the Accounts tab becomes Members: tapping a member lists the transactions they added (UJ-46).
  • A6 — Refunds and transfers: Refunds reduce the category's spending; transfers never appear in Stats. (BR-2, BR-24)

Outcome: User knows where money went, has checked the transactions behind it, and adjusts budgets. Covers: FR-DSH-1 to FR-DSH-11, FR-NAV-1, FR-TRX-4, FR-BUD-1, FR-SPC-11, FR-SPC-15, BO-3 Phase: 1a


UJ-31 — Check net worth across currencies ​

ActorUser (Sari has IDR banks, a USD PayPal, and an IDR credit card)
GoalSee everything she owns minus everything she owes, in one number
TriggerCurious about overall financial position
PreconditionsFinancial accounts exist; base currency is IDR

Main flow

  1. U opens Financial Accounts → S groups them by type with a subtotal per group:
    • Cash: 300,000 IDR
    • Bank: BCA 12,000,000 IDR + Mandiri 4,500,000 IDR
    • E-wallet: GoPay 250,000 IDR + PayPal 320.00 USD
    • Credit card: BCA Visa owed 2,100,000 IDR
  2. S converts PayPal with her saved rate (e.g. 1 USD = 16,200 IDR, updated 3 days ago) and shows ≈ 5,184,000 IDR with the rate date.
  3. S shows Net worth ≈ 20,134,000 IDR (assets − credit card owed), labelled as an estimate.

Alternative & error flows

  • A1 — No saved rate for USD: S leaves PayPal out of the total, shows "PayPal not included — add a USD rate", and links to UJ-35.
  • A2 — Old rate (e.g. months old): S shows the rate date so the user can decide to update it.
  • A3 — User belongs to shared spaces: The Personal dashboard's total net worth adds every shared space where Include in my totals is on. Andi and Rina (both Owners of Family) each see Joint BCA included. Jojo (a Member of Kitchen) doesn't see Kitchen fund in his total unless he turns it on. (FR-SPC-13)

Outcome: One clear net-worth figure; each financial account still shows its own currency. Covers: FR-FIN-3, FR-FIN-4, FR-FIN-5, FR-FIN-7, FR-FIN-9, FR-SPC-13, BR-17 Phase: 2 (net worth: Should; conversion: Could)


9. Setup & maintenance journeys ​

UJ-32 — Add and organize financial accounts ​

ActorUser (Budi opens a new Jago bank account and gets a second credit card)
GoalKeep the list of financial accounts complete and easy to scan
TriggerNew bank, e-wallet, or card
PreconditionsU is an Owner of the current space (always true for the Personal space)

Main flow

  1. U opens Financial Accounts → Add. The new financial account is created in the current space.
  2. U chooses type Bank, name "Jago", currency IDR, opening balance 0, provider "Bank Jago", color, last 4 digits "8812".
  3. S saves it and places it in the Bank group.
  4. U adds a Credit card: "Mandiri Mastercard", owed 0, credit limit 15,000,000, statement day 20, due day 5.
  5. U drags financial accounts to reorder them within a group.

Alternative & error flows

  • A1 — User types a full card number into "last 4 digits": S accepts only 4 digits. (BR-19)
  • A2 — Rename or change color later: Edit anytime.
  • A3 — Change currency: Possible only while the financial account has no transactions. After that the currency field is locked; to switch, archive it and create a new financial account. (FR-FIN-14, BR-26)
  • A4 — Move a financial account to another space: Not possible. U creates a new financial account in the other space with an opening balance, and archives the old one if needed. (FR-SPC-17, BR-37)
  • A5 — U is a Member of the current space: Add isn't shown; only Owners manage financial accounts.

Outcome: All financial accounts listed, grouped, and easy to tell apart. Covers: FR-FIN-1, FR-FIN-2, FR-FIN-8, FR-FIN-9, FR-FIN-10, FR-FIN-11, FR-FIN-14, FR-SPC-17, BR-19, BR-26, BR-37 Phase: 1a


UJ-33 — Archive or delete a financial account ​

ActorUser (Dina closed her old OVO)
GoalRemove a financial account she no longer uses
TriggerClosed a bank, e-wallet, or card
PreconditionsFinancial account exists

Main flow — archive (recommended)

  1. U opens the financial account → Archive.
  2. S hides it from pickers and the main list, keeps all its transactions in history and reports, and moves it to an Archived section.

Main flow — delete

  1. U opens the financial account → Delete.
  2. S warns that all its transactions will be deleted, suggests Archive instead, and lists other financial accounts that have transfers with it, e.g. "12 transfers with BCA will become expenses in BCA. BCA's balance will not change."
  3. U confirms → S deletes the financial account and its transactions. On each other financial account, every transfer with the deleted one becomes an ordinary expense or income named "Transfer to deleted financial account" (or "from"), so their balances stay the same.

Alternative & error flows

  • A1 — Balance isn't zero when archiving: S warns: "This still holds 12,500 IDR. Archive anyway?"
  • A3 — Unarchive: U opens Archived → Restore.

Outcome: The list is clean; history is kept (archive) or removed (delete). Covers: FR-FIN-2, FR-FIN-15, BR-6 Phase: 1a


UJ-34 — Manage categories ​

ActorUser
GoalMake categories match their life
TriggerA default category doesn't fit
Preconditions—

Main flow

  1. U opens Settings → Categories → S lists the expense and income categories of the current space. Each space has its own list, starting from the defaults.
  2. U adds "Pets", renames "Shopping" to "Clothes", and changes colors.
  3. U archives "Education" → S hides it from pickers; past transactions keep it.
  4. (Could) U creates sub-categories, e.g. Food & Drink → Coffee.

Alternative & error flows

  • A1 — Delete a category: S warns that its transactions will become Uncategorized; U confirms. (BR-5)
  • A2 — Create inline: From the category picker during UJ-17/UJ-18 (Owners only in a shared space).
  • A3 — Shared space: Boss sets up Kitchen's list: Vegetables, Meat, Gas, Office snacks. Jojo picks from it but can't change it. Boss's Personal categories are never shown to Jojo. (FR-CAT-2, FR-CAT-4)

Outcome: Categories fit the space; no transactions are lost. Covers: FR-CAT-1, FR-CAT-2, FR-CAT-3, FR-CAT-4, BR-5, BR-31 Phase: 1a


UJ-35 — Maintain exchange rates ​

ActorUser (Sari, base currency IDR, holds USD in PayPal)
GoalKeep converted totals realistic
TriggerRate is missing or outdated (prompt from UJ-31), or she checks the news
PreconditionsHolds at least one financial account in a non-base currency

Main flow

  1. U opens Settings → Exchange rates → S lists each currency she uses with its saved rate and the date updated, e.g. USD → IDR: 16,000 (12 Sep).
  2. U taps USD and types 16,200 → S saves it with today's date.
  3. S updates net worth and dashboard totals. Past transactions and transfers don't change.

Alternative & error flows

  • A1 — Save from a transfer: In UJ-22 step 7, U taps Save this rate instead.
  • A2 — Rate is zero or negative: Not allowed.

Outcome: Converted totals use the user's latest rate. Covers: FR-FIN-6, FR-FIN-7, FR-TRX-2d, BR-15, BR-16, BR-17 Phase: 2


UJ-36 — Export and import transactions (CSV) ​

ActorUser
GoalTake data out (backup, spreadsheet) or bring history in from another app or bank statement
TriggerWants the data in a spreadsheet, is leaving, or is moving from a spreadsheet. To back up everything, use a backup file (UJ-51)
Preconditions—

Main flow — export

  1. U opens Settings → Export → chooses which space (the current one, or all spaces U belongs to) and a date range (default: all time).
  2. S creates a CSV (space, date, type, amount, currency, financial account, category, note, added by; transfers include the sides U can see and the rate) and opens the device's share menu (on a computer, it downloads the file).
  3. U saves it to Files, sends it to themselves, or opens it in a spreadsheet.

Main flow — import

  1. U opens Settings → Import → picks a CSV file.
  2. S shows the first rows and asks which column is date, amount, description, and (optionally) category.
  3. U maps the columns and chooses the target financial account.
  4. S shows a preview: "128 transactions will be imported. 3 rows could not be read."
  5. U confirms → S imports them and recalculates balances.

Alternative & error flows

  • A1 — Unreadable rows: S lists them with the reason; U can download them to fix.
  • A2 — Possible duplicates (same date, amount, description): S flags them and lets the user skip them.
  • A3 — Different date or number formats (e.g. 1.000,50 vs 1,000.50): U picks the format during mapping.

Outcome: Data exported, or history imported, without errors. Covers: FR-DAT-1, FR-DAT-2, NFR-3, NFR-8 Phase: Export 1a; import 2


UJ-37 — Change preferences and reminders ​

ActorUser
GoalMake Crest fit their habits
TriggerAnytime
Preconditions—

Main flow

  1. U opens Settings and can change:
    • Language: English / Bahasa Indonesia — app switches immediately.
    • Base currency: used for totals and budgets. Changing it shows a warning, then asks the user to review their budgets, already converted with saved rates where available. (FR-SET-4, BR-22)
    • Theme: Light / Dark / System.
    • Budget start day: e.g. 25 → the next period starts on the 25th.
    • Daily reminder: on/off and time, e.g. 21:00 "Don't forget to log today's spending." (needs connected mode)
    • App lock: turn on, or change the PIN.
    • Notifications: permission and which notifications to receive (connected mode).
    • Backup: save or restore a backup file (UJ-51).
    • Connect to Crest (or Log out): UJ-52.
  2. S saves each change at once.

Outcome: Crest is set up the way the user wants. Covers: FR-SET-1, FR-SET-2, FR-SET-3, FR-SET-4, FR-NOT-1, FR-AUTH-6, FR-APP-3, NFR-8 Phase: 1a (reminder: 2, needs connected mode)


UJ-39 — Get a new version of Crest ​

ActorUser
GoalAlways use the latest version without doing anything special
TriggerThe owner publishes a new version
Preconditions—

Main flow

  1. The owner publishes the new version on the server. No app store is involved. The app learns about it from a small public file on its own address, so this works in local mode too.
  2. The next time U opens Crest, S loads the new version.
  3. If Crest is already open, S shows "A new version of Crest is available" with a Reload button.
  4. U taps Reload → Crest restarts on the new version.

Alternative & error flows

  • A1 — U ignores the message: The new version is used the next time Crest is opened.
  • A2 — The open version is too old to work safely: S shows "Update required" and reloads; U can't continue on the old version. An update never changes the data: on the device in local mode, on the server in connected mode. (FR-APP-5)
  • A3 — U is offline: U keeps working with the version already loaded (UJ-25); the update loads when back online.

Outcome: Everyone runs the latest version within a day, without installing anything. Covers: FR-APP-5 Phase: 1a


10. Sharing journeys ​

These journeys need connected mode (UJ-52). They use the two examples from the Business Requirements Document (§6, §8.4):

  • Family space: Andi and Rina, both Owners, sharing Joint BCA.
  • Kitchen space (Boss as Owner, Jojo as Member) with Kitchen fund, and Operations space (Boss as Owner, Maria as Member) with Operations fund.

UJ-42 — Create a shared space ​

ActorSpace Owner (Andi, setting up money he shares with Rina)
GoalHave one place for the couple's joint money
TriggerAndi and Rina decide to track their joint bank in Crest
PreconditionsAndi is Active

Main flow

  1. U opens the space switcher → New shared space.
  2. U enters name Family, currency IDR, budget start day 25.
  3. S creates the space with Andi as Owner, gives it the default categories, and switches to it. Because Andi now has more than one space, the space switcher appears at the top.
  4. S shows a short checklist: Add a financial account → Invite people → Set budgets.
  5. U adds Joint BCA (Bank, IDR, opening balance 8,000,000) in Family (UJ-32).
  6. U continues with the invitation (UJ-43).

Alternative & error flows

  • A1 — Money already tracked in a Personal financial account: Financial accounts can't be moved between spaces. Andi creates Joint BCA in Family with today's balance as the opening balance, and archives the old one in Personal if he had it there. (FR-SPC-17, BR-37)
  • A2 — Boss sets up staff funds: Boss creates two spaces, Kitchen (with Kitchen fund, cash) and Operations (with Operations fund, e-wallet), so that Jojo and Maria can each be invited to only one of them.

Outcome: A shared space exists with its own financial accounts and categories; Andi is its Owner. Covers: FR-SPC-2, FR-SPC-3, FR-SPC-11, FR-SPC-12, FR-SPC-17, FR-CAT-1, BR-30, BR-37 Phase: 1b


UJ-43 — Invite someone and accept the invitation ​

ActorSpace Owner (Boss) and the invited user (Jojo)
GoalGive Jojo access to Kitchen, and nothing else
TriggerBoss wants Jojo to record kitchen spending
PreconditionsBoss is an Owner of Kitchen; Jojo is an Active Crest user (he requested access and was approved, UJ-01 and UJ-09)

Main flow

  1. U (Boss) opens Kitchen → Members → Invite, types Jojo's email, and chooses the role Member.
  2. S shows "If this email belongs to a Crest user, they'll receive an invitation" and lists it under Pending invitations (expires in 14 days).
  3. S notifies Jojo in Crest and by email: "Boss invited you to the space Kitchen as a Member."
  4. U (Jojo) opens Crest → S shows the invitation with what it means: "You'll see all financial accounts, transactions, categories, and budgets in Kitchen, and everyone in Kitchen will see what you add. Your Personal space stays private."
  5. U (Jojo) taps Accept → S adds him to Kitchen as a Member (Include in my totals: off), shows the space switcher, and notifies Boss.

Alternative & error flows

  • A1 — Couple: Andi invites Rina to Family with the role Owner, so they have equal rights. (FR-SPC-6)
  • A2 — Invitee declines: S removes the invitation and tells the Owner it was declined.
  • A3 — No answer in 14 days: The invitation expires; the Owner can invite again. (FR-SPC-5)
  • A4 — Owner cancels a pending invitation: It disappears for the invitee.
  • A5 — The email isn't a Crest user yet: S shows the same neutral message and sends nothing. Boss asks Jojo to request access first (UJ-01), then invites him again. (FR-SPC-4, BR-39)
  • A6 — Jojo is already a member: S says so and sends nothing.

Outcome: Jojo is a Member of Kitchen only. He can't see Operations or anything in Boss's Personal space. Covers: FR-SPC-4, FR-SPC-5, FR-SPC-6, FR-SPC-13, FR-NOT-4, BR-39 Phase: 1b


UJ-44 — Add a transaction in a shared space ​

ActorSpace Member (Jojo buys vegetables for 85,000 IDR with cash from Kitchen fund)
GoalRecord shared spending so the Owner can see it
TriggerJust paid from the shared fund
PreconditionsJojo is a Member of Kitchen

Main flow

  1. U opens Crest → switches to Kitchen (or stays in Personal and picks Kitchen fund in step 3).
  2. U taps + → Expense, types 85000.
  3. U picks financial account Kitchen fund → S shows Kitchen's categories (Vegetables, Meat, Gas, Office snacks).
  4. U picks Vegetables, adds the note "Pasar pagi", and taps Save.
  5. S saves it with "Added by Jojo", reduces Kitchen fund by 85,000, and updates Kitchen's Vegetables budget. Boss sees it right away in Kitchen.

Alternative & error flows

  • A1 — Couple: Rina records Groceries 450,000 from Joint BCA in Family; Andi sees "Added by Rina". (FR-SPC-7)
  • A2 — Picks the wrong space's financial account: The entry form always shows the space name next to the financial account, e.g. "Kitchen fund · Kitchen", to prevent private spending ending up in a shared space.
  • A3 — Fixing a mistake: Jojo can edit or delete his own entry. He can see Boss's entries but not change them. (BR-36)
  • A4 — Owner wants to be told about every entry: Boss turns on Notify me when someone adds a transaction for Kitchen. (FR-SPC-16, Could)

Outcome: The expense is in the shared space, visible to every member, with who added it. Covers: FR-TRX-1, FR-CAT-4, FR-SPC-7, FR-SPC-11, FR-SPC-16, BR-31, BR-36 Phase: 1b


UJ-45 — Top up a shared fund from a Personal financial account ​

ActorSpace Owner (Boss)
GoalGive Jojo more money for the kitchen
TriggerKitchen fund is low; Jojo asked Boss on WhatsApp and Boss agreed
PreconditionsBoss is an Owner of Kitchen and has a financial account in Personal

Main flow

  1. Jojo asks for money outside Crest (in person or by chat). Crest has no in-app request. (BR-38)
  2. U (Boss) gives Jojo 500,000 in real life, e.g. by bank transfer or cash.
  3. U taps + → Transfer, From: Boss's BCA (Personal), To: Kitchen fund (Kitchen), 500000, and taps Save.
  4. S records one transfer with two sides:
    • In Boss's Personal space: Boss's BCA −500,000, to Kitchen fund (Kitchen).
    • In Kitchen: Kitchen fund +500,000, from Boss.
  5. Jojo sees "+500,000 from Boss" in Kitchen. He doesn't see Boss's BCA or its balance.

Alternative & error flows

  • A1 — Couple: Andi moves 2,000,000 from his Personal BCA to Joint BCA each payday. Rina sees "+2,000,000 from Andi".
  • A2 — Boss says no: Nothing is recorded in Crest.
  • A3 — Different currencies: The cross-currency form applies (UJ-22).

Outcome: Kitchen fund's balance is correct, and Boss's private finances stay private. Covers: FR-TRX-2, FR-SPC-14, BR-2, BR-35, BR-38 Phase: 1b


UJ-46 — See how a shared space's money is used ​

ActorSpace Owner (Boss), or any member (e.g. Rina)
GoalUnderstand who spent what, and on what
TriggerEnd of the month, or before deciding to top up a fund
PreconditionsU is a member of the space

Main flow

  1. U (Boss) switches to Kitchen → S shows Kitchen's dashboard: Kitchen fund balance, this month's spending, and budget progress.
  2. U opens Spending by category → Vegetables 1,650,000, Meat 900,000, Gas 280,000.
  3. U opens Spending by member → Jojo 2,730,000, Boss 100,000. (FR-SPC-15, Should)
  4. U taps Jojo → S lists Jojo's transactions this month with notes.
  5. U (Boss) switches to Operations to review Maria's spending the same way.

Alternative & error flows

  • A1 — Couple: Rina opens Family and filters transactions by Added by: Andi to see how the joint money was used.
  • A2 — Member view: Jojo sees the same Kitchen dashboard (including Boss's entries in Kitchen), but never Operations or Boss's Personal space.
  • A3 — Export for records: Boss exports Kitchen to CSV, including who added each transaction (UJ-36).

Outcome: Everyone in a space has the same clear picture of its money. Covers: FR-SPC-7, FR-SPC-11, FR-SPC-15, FR-DSH-1, FR-DSH-2, FR-TRX-4, FR-DAT-1, BR-30 Phase: 1 (spending by member: Should)


UJ-47 — Pay yourself back from a shared fund ​

ActorSpace Member (Jojo)
GoalRecord that he paid for ingredients with his own money and took it back from the fund
TriggerKitchen fund's cash ran out at the market, so Jojo paid 200,000 himself
PreconditionsJojo is a Member of Kitchen and has a cash wallet in his Personal space

Main flow

  1. U records the expense Vegetables 200,000 in Kitchen, paid from Kitchen fund, with the note "Paid with my own money", so the spending counts in Kitchen.
  2. Later, when he takes the money back from the fund, U records a transfer From: Kitchen fund (Kitchen) To: Jojo's wallet (Personal), 200000.
  3. S shows Boss "Kitchen fund −200,000, to Jojo" in Kitchen. Boss doesn't see Jojo's wallet.

Alternative & error flows

  • A1 — Jojo doesn't track his own money in Crest: He records only the Kitchen expense; the transfer isn't needed.
  • A2 — Transfer by mistake: Jojo can delete it, because he added it. (BR-36)

Outcome: Kitchen shows the real spending, and each person's private side stays private. Covers: FR-TRX-2, FR-SPC-14, BR-35, BR-36 Phase: 1b


UJ-48 — Leave a space or remove a member ​

ActorSpace Member (Maria) or Space Owner (Boss)
GoalEnd someone's access to a shared space
TriggerMaria leaves the job
PreconditionsMaria is a Member of Operations

Main flow — Owner removes a member

  1. U (Boss) opens Operations → Members → Maria → Remove, and confirms.
  2. S removes Maria's access immediately and notifies her. Her past transactions stay in Operations with "Added by Maria". Any recurring transactions she set up in Operations stop.

Main flow — member leaves

  1. U (Maria) opens Operations → Leave space, and confirms.
  2. S removes her access immediately; everything else is the same as above.

Alternative & error flows

  • A1 — Last Owner tries to leave: S blocks it and offers Make someone else Owner or Delete space (UJ-49). (FR-SPC-9)
  • A2 — Maria is later invited again: Her old transactions are still there under her name.
  • A3 — Maria's Crest login is deleted instead (UJ-08 or UJ-13): Her transactions stay, labelled "Former member". (BR-34)
  • A4 — Removing another Owner: In Family, Andi (Owner) can remove Rina (Owner) or make her a Member, as long as one Owner remains. (FR-SPC-6)

Outcome: Maria can no longer see Operations; its history is complete. Covers: FR-SPC-6, FR-SPC-8, FR-SPC-9, FR-TRX-5c, FR-NOT-4, BR-34, BR-40 Phase: 1b


UJ-49 — Hand over ownership or delete a shared space ​

ActorSpace Owner
GoalPass a space on, or close it
TriggerThe Owner is leaving, or the space is no longer needed
PreconditionsU is an Owner of the shared space

Main flow — hand over ownership

  1. U opens Members → picks a member → Make Owner.
  2. S changes their role and notifies them. If U wants, U can now leave (UJ-48).

Main flow — delete the space

  1. U opens space settings → Delete space.
  2. S warns that all financial accounts, transactions, categories, budgets, and goals in the space will be deleted for every member, suggests Export first (UJ-36), and asks U to type the space name.
  3. U types it and confirms → S deletes the space and notifies all members. Transfers that linked this space to other spaces become ordinary income or expense on the other side, so other balances don't change. (BR-6)

Alternative & error flows

  • A1 — Typed name doesn't match: Delete stays disabled.
  • A2 — Change a role back: An Owner can make another Owner a Member, as long as at least one Owner remains. (BR-33)

Outcome: The space has a new Owner, or it no longer exists. Covers: FR-SPC-6, FR-SPC-9, FR-SPC-10, FR-NOT-4, BR-6, BR-33 Phase: 1b


11. Future: contribution journeys ​

These journeys are for Phase 4, built only if running costs need to be shared. Crest never processes payments: users pay the owner directly, and the Super Admin records it. (§8.13, BR-27 to BR-29)

UJ-40 — Record a yearly contribution ​

ActorSuper Admin
GoalRecord that a user has paid for the next year
TriggerA user pays by bank transfer or e-wallet and lets the owner know
PreconditionsContributions are switched on

Main flow

  1. U opens Users → S shows each user's contribution status: Paid (until date), Due soon, In grace period, Read-only, or Exempt. U can filter by status.
  2. U opens the user (e.g. Budi) → clicks Record payment.
  3. S proposes a new paid-until date one year after the current one (or one year from today if lapsed).
  4. U confirms, optionally adding a note (e.g. "Bank transfer, 12 Mar").
  5. S saves it, restores full access if Budi was read-only, and records the change in the audit log.

Alternative & error flows

  • A1 — Family member who should never pay: U clicks Mark as exempt → S hides that user from the due lists. (FR-SUB-2)
  • A2 — Wrong date entered: U edits the paid-until date; the change is audit-logged.

Outcome: The user's paid-until date is up to date. Covers: FR-SUB-1, FR-SUB-2, FR-SUB-7, BR-27 Phase: 4


UJ-41 — Contribution comes due, lapses, and is renewed ​

ActorUser
GoalKnow when to pay, and never lose access to their data
TriggerPaid-until date approaches
PreconditionsContributions are switched on; user is not exempt

Main flow

  1. 30 days and 7 days before the paid-until date, S sends a reminder (email and in-app): "Your Crest contribution is due on 1 Jan. It covers running costs only." with the payment instructions set by the Super Admin.
  2. U pays the owner outside Crest.
  3. The Super Admin records it (UJ-40) → S shows the new paid-until date in Settings → Contribution.

Alternative & error flows

  • A1 — Not paid by the paid-until date: A 30-day grace period starts. Everything still works; S shows a banner with the payment instructions. (FR-SUB-5)
  • A2 — Grace period ends: Crest becomes read-only for U in every space U belongs to. U can still view and export, but can't add or edit anything. Other members of U's shared spaces are not affected. S explains why and how to pay. (FR-SUB-6, BR-28)
  • A3 — Pays while read-only: After UJ-40, full access returns immediately. Nothing was deleted.
  • A4 — Decides to leave instead: U exports the data (UJ-36) and deletes their login (UJ-08).

Outcome: The user always knows their status; data is never lost or locked away because of non-payment. Covers: FR-SUB-3, FR-SUB-4, FR-SUB-5, FR-SUB-6, BR-28, BR-29 Phase: 4


12. Requirements traceability ​

Every functional requirement in the Business Requirements Document is covered by at least one journey.

RequirementJourneys
FR-MOD-1, FR-MOD-2, FR-MOD-4, FR-MOD-6, FR-MOD-7UJ-50
FR-MOD-3UJ-16
FR-MOD-5, FR-MOD-8UJ-51
FR-MOD-9, FR-MOD-10, FR-MOD-11, FR-MOD-12UJ-52
FR-REQ-1, FR-REQ-1a, FR-REQ-2, FR-REQ-3, FR-REQ-4, FR-REQ-6UJ-01
FR-REQ-5UJ-09, UJ-10
FR-AUTH-1UJ-02
FR-AUTH-2, FR-AUTH-3UJ-03, UJ-14
FR-AUTH-4UJ-04, UJ-52
FR-AUTH-5UJ-02, UJ-04
FR-AUTH-6UJ-04, UJ-16, UJ-37
FR-AUTH-7UJ-05
FR-AUTH-8UJ-08
FR-AUTH-9UJ-07, UJ-12, UJ-13
FR-ADM-1, FR-ADM-2UJ-09, UJ-15
FR-ADM-2aUJ-15
FR-ADM-3, FR-ADM-3aUJ-15
FR-ADM-4, FR-ADM-5UJ-09
FR-ADM-6, FR-ADM-6aUJ-10
FR-ADM-7, FR-ADM-7aUJ-11
FR-ADM-8UJ-12, UJ-14
FR-ADM-9UJ-07, UJ-12
FR-ADM-10UJ-05, UJ-14
FR-ADM-11UJ-13
FR-ADM-12UJ-09, UJ-14
FR-ADM-13UJ-01, UJ-09
FR-ADM-14UJ-09 to UJ-15
FR-ADM-15UJ-09, UJ-15
FR-ADM-16UJ-15
FR-ADM-17§5 (all Super Admin journeys)
FR-ADM-18UJ-09, UJ-10
FR-FIN-1UJ-16, UJ-32
FR-FIN-2UJ-32, UJ-33
FR-FIN-3UJ-17, UJ-23, UJ-31
FR-FIN-4UJ-20, UJ-31
FR-FIN-5UJ-16, UJ-22, UJ-31
FR-FIN-6UJ-22, UJ-35
FR-FIN-7UJ-31, UJ-35
FR-FIN-8UJ-16, UJ-32
FR-FIN-9UJ-31, UJ-32
FR-FIN-10UJ-16, UJ-20, UJ-32
FR-FIN-10aUJ-17, UJ-20, UJ-21
FR-FIN-11UJ-21, UJ-32
FR-FIN-12UJ-21
FR-FIN-13UJ-19
FR-FIN-14UJ-32
FR-FIN-15UJ-33
FR-TRX-1UJ-17, UJ-18, UJ-20
FR-TRX-2UJ-19, UJ-21, UJ-22
FR-TRX-2a to FR-TRX-2dUJ-22 (2d also UJ-35)
FR-TRX-2eUJ-19, UJ-22
FR-TRX-3UJ-23
FR-TRX-3aUJ-22, UJ-23
FR-TRX-4UJ-24
FR-TRX-5, FR-TRX-5bUJ-26
FR-TRX-5cUJ-26, UJ-48
FR-TRX-5aUJ-23, UJ-26
FR-TRX-6UJ-17
FR-TRX-7UJ-25
FR-TRX-9UJ-17
FR-TRX-8UJ-20
FR-CAT-1UJ-16, UJ-34, UJ-42
FR-CAT-2UJ-18, UJ-34
FR-CAT-3UJ-34
FR-CAT-4UJ-17, UJ-34, UJ-44
FR-BUD-1UJ-27, UJ-30
FR-BUD-2UJ-17, UJ-23, UJ-27
FR-BUD-3UJ-28
FR-BUD-4, FR-BUD-5, FR-BUD-6UJ-29
FR-BUD-7, FR-BUD-8UJ-27
FR-DSH-1UJ-16, UJ-18, UJ-30
FR-DSH-2 to FR-DSH-11UJ-30
FR-NAV-1UJ-30
FR-DAT-1UJ-08, UJ-36, UJ-51
FR-DAT-2UJ-36
FR-NOT-1UJ-16, UJ-26, UJ-37
FR-NOT-2UJ-28
FR-NOT-3UJ-28, UJ-38
FR-NOT-4UJ-43, UJ-48, UJ-49
FR-SET-1UJ-16, UJ-37
FR-SET-2UJ-37
FR-SET-3UJ-16, UJ-27, UJ-37
FR-SET-4UJ-37, UJ-52
FR-APP-1UJ-38
FR-APP-2UJ-03, UJ-16, UJ-38, UJ-50
FR-APP-3UJ-38
FR-APP-4UJ-25, UJ-50
FR-APP-5UJ-39
FR-APP-6All end-user journeys (layout)
FR-APP-7UJ-03, UJ-05
FR-APP-8Not in the first release (native apps, when there is demand)
FR-SUB-1, FR-SUB-2, FR-SUB-7UJ-40
FR-SUB-3, FR-SUB-4, FR-SUB-5, FR-SUB-6UJ-41
FR-SPC-1UJ-16, UJ-52
FR-SPC-2, FR-SPC-3, FR-SPC-12UJ-42
FR-SPC-4, FR-SPC-5UJ-43
FR-SPC-6UJ-43, UJ-49
FR-SPC-7UJ-23, UJ-44, UJ-46
FR-SPC-8UJ-48
FR-SPC-9UJ-08, UJ-48, UJ-49
FR-SPC-10UJ-49
FR-SPC-11UJ-30, UJ-42, UJ-44, UJ-46
FR-SPC-13UJ-31, UJ-43
FR-SPC-14UJ-45, UJ-47
FR-SPC-15UJ-46
FR-SPC-16UJ-44
FR-SPC-17UJ-32, UJ-42

Crest is a personal project by Reizkian Y. Radityatama.