Supply needs speed without sacrificing identity, booking integrity or money controls.
Staff view
Tenant + landlord + booking + money + risk + ticket. Add a named owner, SLA, last customer-visible response and audit trail.
The internal operating surface is a third product, not the public product with admin flags.
02 / One object. One owner.
One object. One owner.
One object. One owner. One system of record. Everything else is a view or a satellite.
In this design, ownership means responsibility for meaning, allowed changes and correction—not unrestricted access.
Objects of record · one possible owner mapping
Object
Meaning
Typical owner
Person
Tenant or landlord identity
Trust / Identity
Account
Managed landlord organisation
Account Management
Listing
Property and availability
Supply / AM
Conversation
Marketplace communication
Marketplace
Application
Intent to rent
Booking Operations
Booking
Accepted stay
Booking Operations
Payment Hold
Funds secured before release
Finance
Payout
Settlement to landlord
Finance
Ticket
Exception outside the happy path
Customer Care
Risk Case
Identity / integrity / fraud review
Trust & Safety
Campaign
Acquisition / lifecycle experiment
Marketing
Event
Record of a committed change
Producing domain owner
03 / A booking is a sequence of commitments.
A booking is a sequence of commitments.
Illustrative sequence. Exact checks and release conditions need product, legal and provider evidence.
A timeout is not proof of payment failure. Provider callbacks need verification, deduplication and reconciliation. An exception keeps its booking reference; it does not create another booking.
04 / Attach the organisation to the same truth.
Attach the organisation to the same truth.
The tool is a work surface. Ownership belongs to an object and an accountable team.
CRM owns pipeline. Admin owns platform state. Tickets own exceptions. Internal chat owns coordination. Email owns delivery. None of them gets to invent a second Booking.
“Admin” here means a permissioned interface to the platform—not a separate database or an unrestricted write path. Knowledge, analytics, identity/SSO and telemetry are shared capabilities.
Channels are how work arrives. They are not where operational truth lives.
Prefer the in-platform thread for tenant–landlord booking context. Overflow phone, email or hypothetical WhatsApp interactions must attach to Person / Booking. Before a booking exists, use Person / Listing / Application instead.
Phone interactions need identity confirmation before sensitive action. A chatbot can retrieve and cite knowledge or create a ticket; it cannot confirm a booking or release money. Internal chat coordinates work and links to the recorded decision.
06 / Staff need a product too.
Staff need a product too.
Staff see more context, not a different truth.
A staff user should not need six tools open to answer one customer correctly.
Show the current state, its source, freshness and permitted next action together. Sensitive documents and elevated controls appear only to the appropriate role.
07 / Separate capability from authority.
Separate capability from authority.
Capability map only. Boxes do not specify a deployment layout or a provider.
Edge + identity
DDoS and bot defence; abuse limits. Separate tenant, landlord and staff roles. Staff SSO and MFA; no shared admin account.
Authorization
Least privilege and explicit scopes. Elevated actions require stronger authority. Assist/classification has no direct payment-write permission.
Data classes
Separate public listings, PII, identity documents, payment tokens / financial state and staff-only notes. Access and retention follow purpose.
Money boundary
A bounded service checks an authorized instruction before payout or refund. The model cannot grant that authority.
Audit
Every material action records actor, before/after state, reason and timestamp. Preserve evidence of retries and correction.
Vendor boundary
CRM, tickets, mail and chatbot receive identifiers, events and bounded views—not independent transactional truth.
08 / Same objects. Different questions.
Same objects. Different questions.
Different questions should not manufacture different bookings.
Marketing, Operations, Finance and leadership consume a governed metrics layer. Define what “confirmed” means, how late or corrected events are handled, and which owner can change that definition.
Example measures · design choices, not historical results
Audience
Questions made measurable
Leadership
Confirmed bookings; time-to-book; availability; conversion; tickets per booking; loss; hold-to-payout cycle; acquisition cost per booking; retention; unit economics / take-rate
Design response. Use platform-state outcomes, with conversion and risk together.
Smell
Executive dashboards disagree
Failure. Sales, Marketing and Finance define booking differently.
Design response. Governed definitions derived from platform events.
10 / What I would improve first.
What I would improve first.
Design bets to test against observed work, not a prescribed implementation. Start with one exception path and find where an operator loses the current answer.
One Booking ID everywhere
Mail, tickets, CRM, chatbot and analytics resolve to the same object.
Staff OS as a product
Make ownership, evidence and allowed actions visible together.
Channel gate
Identify → attach → enrich → route.
Exception-first ticketing
Create a ticket when work leaves the normal state machine.
Canonical knowledge
One answer, one owner, one review date.
Event-derived telemetry
Report product outcomes, not channel guesses.
Assist without delegated authority
Summarise, classify, retrieve, draft, suggest routing and flag anomalies.
Risk against conversion
Measure prevented loss and added friction together.
No approval means no change. AI does not independently release payouts, materially refund, pass KYC, ban users or finalise booking-state mutations. Validate permissions, idempotency and state preconditions at the write boundary.
Assist can make the operator faster. It does not make accountability disappear.
One record per object. Explicit authority. Useful exceptions. Measures with meaning. These are the design principles I would carry into discovery—and test against the people doing the work.