The citizen-facing screens of the Sewa super app, presented as complete journeys — from a citizen's first launch through identity, services, payments and credentials — with a closing chapter of proposed additions.
Prerequisite the condition that makes a step appear
Success what the citizen sees right after the CTA
Conditional step shown only when its prerequisite is met
01
Home
The landing screen: greet the citizen, orient them among 200+ services, and route them to anything — a new application, their wallet, a payment, help — in one or two taps.
◆ Prerequisites
Signed in with a valid session. Guests land on the same surface read-only, with sign-in offered where an action needs identity.
Entry
App open (valid session) · consent completed on first run · Home tab from anywhere
Exit / expected outcome
Services · Wallet · GovPay · Fuel quota · Assistant · Support — or straight into an in-progress application
Part A
Options & rationale
Three ways a national super app can spend its most valuable surface: on tasks, on status, or on breadth. The choice decides who feels at home on day one.
OPT 1Task-first landing
One question — "what do you need today?" — a large search, and four big task doors. Discovery is demoted below the fold.
OPT 1
9:41▸▸▮
SEWA△
What do you need today?
⌕Search or speak…🎙
✎Apply for a service
▭My documents
◈Pay a bill or fine
☏Get help · 1919
💬 Ask the assistant — in Sinhala, Tamil or English
⌂ Home⊞ Services▭ Wallet◯ Profile
OPT 2Status-first landing
The app opens on consequences: what's expiring, what's moving, what's owed. A triage stack leads; the catalog is dense and last.
OPT 2
9:41▸▸▮
SEWA⌕△
Needs attention · 3
Emission cert — 28 days left
WP CAB-4521
Renew
NIC renewal — day 6 of 14
In review
Track
Traffic fine — LKR 2,500
due 24 Jul
Pay
Shortcuts
▦ Present DL↻ Renew licence+ Pin
All services
▤Identity
✈Travel
♡Health
⋯All
⌂ Home⊞ Services▭ Wallet◯ Profile
OPT 3Browse-first hub
A balanced hub: greeting, search, quick actions, featured services, and the journey categories — everything one glance away. The direction the design takes.
OPT 3
9:41▸▸▮
SEWA△
Good morning, Nimal
What can we help you with today?
⌕Search services…
Quick actions
✎Apply
▭My Wallet
◈GovPay
⛽Fuel Quota
💬Assistant
?Support
Featured services
Renew your NICFast-track · 14 days
Apply for PassportNo office visit
ServicesSee all
▤Birth & Identity
✈Travel
♡Health
🎓Education
▥Work & Tax
⌂Land & Property
⌂ Home⊞ Services▭ Wallet◯ Profile
Rationale
OPT 1Task-first landing
Design logic
One job per zone: ask, then act. Four doors cover the whole catalog in task language; nothing competes for attention.
Serves best
First-time and low-digital-literacy citizens; assisted use over a shoulder.
Costs
200+ services hide behind one door; no surface for government campaigns or featured services; repeat tasks take an extra hop.
Evidence
GOV.UK task-first start pages; cognitive-load research on choice reduction.
SLDS build
Card, Search Input real; voice input CONTRIBUTE.
Risks
Task labels must translate cleanly ×3 languages; four doors become a bottleneck as the catalog grows.
OPT 2Status-first landing
Design logic
The landing behaves like a control panel — deadlines, day-counts and dues first, discovery last. Muscle-memory shortcuts for repeat tasks.
Serves best
Returning users doing one known thing — the majority of sessions after month one.
Costs
Dense first contact; assumes credentials and applications already exist — a new citizen sees an empty control panel.
Badge (8 states), Chip, List Item real; needs-attention stack CONTRIBUTE.
Risks
An unbounded stack becomes anxiety UI; the empty state needs as much design as the full one.
OPT 3Browse-first hub
Design logic
Balance breadth and speed: a greeting, one search, six quick actions, a featured band for campaigns, and the six life-journey categories — every audience finds its path in one glance.
Serves best
The broadest mix a national app must serve at once: first-timers exploring, repeat users jumping via quick actions, the state promoting services.
Costs
Nothing on the surface shows what's already in motion; the six-category grid leaves the vehicle journey one tap deeper; small tile labels run tight for Sinhala/Tamil.
Evidence
National portals with large catalogs converge on hub landings; recognition over recall across mixed literacy.
SLDS build
Service Card, Icon Card, Search Input, Bottom Tab Bar — the highest reuse of SLDS components of the three.
Risks
Hub surfaces drift toward clutter — the quick-action and featured slots need governance rules.
Comparison & recommendation
Dimension
Opt 1 · Task-first
Opt 2 · Status-first
Opt 3 · Browse hub
First-time orientation
Highest — four doors
Low — assumes history
High — labeled paths
Repeat-task speed
Medium — via search
Highest — shortcuts
High — quick actions
Catalog reach (200+ services)
Behind one door
Dense, last
Two taps to anything
Campaign / featured surface
None
None
Built in
In-progress visibility
None
Leads the screen
Absent — resolved in v4
New-citizen day one
Calm
Empty panel
Full and inviting
Verdict
The browse-first hub is the right landing for a national super app — and it is the direction the design takes.
Only the hub serves all three audiences at once — first-timers, returning users, and the state as publisher — while giving 200+ services a two-tap reach. Opt 1's search prominence and Opt 2's status visibility survive as refinements: the search bar stays high, and a compact in-progress strip joins the hub in the proposed upgrade below.
Part B
Final design
The Home screen as designed, and a proposed upgrade that folds the review findings in — same skeleton, five precise changes.
V3 · AS DESIGNEDFinal design
HOME · V3
9:41▸▸▮
SEWA△
Good morning, Nimal
What can we help you with today?
⌕Search services…
Quick actions
✎Apply
▭My Wallet
◈GovPay
⛽Fuel Quota
💬Assistant
?Support
Featured services
Renew your NICFast-track · 14 days
Apply for PassportNo office visit
ServicesSee all
▤Birth & Identity
✈Travel
♡Health
🎓Education
▥Work & Tax
⌂Land & Property
💬
⌂ Home⊞ Services▭ Wallet◯ Profile
V4 · PROPOSED UPGRADESame skeleton, five changes
HOME · V4
9:41▸▸▮
SEWA△3
Good morning, Nimal
What can we help you with today?
⌕Search services…
1
NIC Renewal — day 6 of 14 · in review
Continue where you left off
Track
Quick actions
✎Apply
▭My Wallet
◈GovPay
⛽Fuel Quota
💬Assistant
4☏Support · 1919
Featured services
Renew your NICFast-track · 14 days
Apply for PassportNo office visit
ServicesSee all
▤Identity
✈Travel
♡Health
🎓Education
▥Work & Tax
⌂Land
2🚗Vehicle
⋯All 200+
⌂ Home⊞ Services▭ Wallet◯ Profile
1In-progress strip above the fold — the single strongest reason a citizen re-opens a government app; the visible home of "save and come back anytime".
2Vehicle & Transport joins the services grid — the credential wallet's hero journey was one tap deeper than every other category.
3The bell opens a notifications inbox — a badge that leads somewhere keeps its promise.
4Support is wired to a help hub with 1919 — a visible route to a human is a trust feature, not a footnote.
5Two-line label space reserved on every tile — Sinhala and Tamil labels run up to 45% longer than English.
States
Success · Signed-in landing
Greeted by name, session valid — every tile live, the in-progress strip showing anything in motion. One tap resumes exactly where the citizen left off.
Guest
Browsing as guest — sign in to unlock Wallet, GovPay & personalised services.
Same layout, read-only; guarded tiles route to sign-in and return here.
Offline
⚠ Offline — saved services readable; your Wallet still works fully.
Apply and pay wait for signal; nothing on the surface pretends otherwise.
Nothing in progress
The strip simply isn't there — the hub reads exactly as the final design. Empty is the default, not an error.
02
Onboarding & Sign-in
The first minute a citizen spends with the state online: arrive, choose a language, prove identity without a password, agree to what's shared, and land ready to act.
◆ Prerequisites (journey)
App installed and opened. First run for the full path; a returning citizen with a valid session skips straight to Home.
Entry
App icon · a shared deep link to a service · an SMS prompt to register
Exit / expected outcome
Home, verified and consented — or Home read-only as a guest
Part A
Approaches & rationale
The structural options considered for this journey. Sign-in and consent each carry a genuine design decision, explored below; the remaining screens follow a single settled pattern, noted at the end.
Sign in + code — three ways in
The decision: how a citizen proves who they are without a password.
V1Tabbed login
A Login / Register tab pair with OTP-first mobile entry, SLUDI beneath a divider, guest as a text link — the pattern local bank and telco apps use.
V1
9:41▸▸▮
SEWA
Sri Lanka citizen services
Login
Register
Enter your registered mobile number. We will send a one-time password to verify your identity.
Mobile number
☏+94 7X XXX XXXX
Send OTP
or
🛡 Sign in with SLUDI
Continue as Guest
V2Choose your door
A hub of three doors — mobile, SLUDI, guest — then the one-question rail behind it. Guest is a first-class door.
V2 · 1/2
9:41▸▸▮
SEWA
All of government. One app.
▤
Sign in with mobile number
SMS code · no password · most used
›
🛡
Sign in with SLUDI app
Fingerprint or face · no SMS
›
◯
Browse as guest
Look around first · read-only
›
New to Sewa? Any door sets up your account when it's needed.
Government officer? Officer portal →
V3One calm surface
Zero navigation — the number stays put (editable) as the code section appears beneath it. Nothing ever disappears.
V3 · 1/1
9:41▸▸▮
SEWA
Sign in
▤ +94 77 123 4567 edit
✓ Code sent by SMS — arrives shortly
4
Resend in 0:38 · didn't get it?
Confirm & continue
other ways in
🛡 SLUDI app
Browse as guest →
Rationale
V1Tabbed login
Design logic
A familiar tabbed Login/Register with OTP-first mobile entry — the pattern citizens know from local bank and telco apps. Passwordless from day one.
Serves best
Returning users of conventional local apps, at home on first contact.
Costs
The citizen must self-classify (login vs register) before typing — the most common first-run stumble; guest is a small text link; the SLUDI path lands directly on Home, ahead of the consent gate.
Evidence
Its companion code screen is genuinely strong — resend cooldown and a 3-attempt lockout are already modelled there and carry forward everywhere.
SLDS build
TabBar, Input, Button real — the cheapest to assemble as-is.
Risks
Tab labels wrap two-line in Sinhala/Tamil; self-classification and the ungated SLUDI shortcut are the two structural gaps the alternatives resolve.
V2Choose your door
Design logic
Make the only real decision explicit — how to get in. Guest elevated to a full door because browse-before-trust is the adoption strategy.
CONTRIBUTE a composed auth surface; Inset Text, Button real.
Risks
A silent send-failure must show inline; lock to portrait so the keyboard never buries the code.
Comparison & recommendation
Dimension
V1 · Tabbed
V2 · Doors
V3 · Surface
First-contact clarity
Medium — must self-classify
Highest — doors explain themselves
High
Guest visibility
Text link
First-class door
Persistent, below fold
Consent gate on SLUDI
Bypassed
Enforced on every door
Enforced
Error-recovery legibility
Strong code screen (cooldown + lockout)
Same rigor, one question at a time
Inline, denser
Officer-portal entry
None
Yes — footer
None
Build cost
Lowest — exists
Medium
Medium, hardest a11y QA
Verdict
The tabbed, OTP-first login is the direction the design takes — familiar from every local bank and telco app, passwordless from day one, and the cheapest of the three to build.
Its code screen already models resend cooldown and attempt lockout — rigor the other options simply inherit. The doors study contributes guest prominence and the officer-portal entry; the calm surface remains the right shape for kiosk/assisted sign-in and payment re-authentication. Both survive as the upgrade below.
V3 · AS DESIGNEDFinal design — Login
LOGIN · V3
9:41▸▸▮
SEWA
Sri Lanka citizen services
Login
Register
Enter your registered mobile number. We will send a one-time password to verify your identity.
Mobile number
☏+94 7X XXX XXXX
Send OTP
or
🛡 Sign in with SLUDI
Continue as Guest
V4 · PROPOSED UPGRADESame skeleton, four changes
LOGIN · V4
9:41▸▸▮
SEWA
Sri Lanka citizen services
3
Login
Register
Mobile number
☏+94 7X XXX XXXX
Send OTP
New to Sewa? The code checks — we'll set up your account if needed.
or
1🛡 Sign in with SLUDI
2◯ Browse as guest — read-only
Government officer? Officer portal →4
1SLUDI routes through first-run consent — every door passes the same gate before Home; no shortcut around it.
2Guest becomes a visible action, not a small link — browsing before trusting is how a national app earns adoption.
3Wrong-tab dead ends removed — the code decides: a new number flows into account setup, so choosing "Login" first never punishes.
4Officer portal gets a quiet footer entry — field officers find their door without polluting the citizen flow.
Data consent — three ways to ask
The decision: how a citizen understands and grants what's shared, PDPA-clean, before first landing.
V1Single agree list
One intro line, four consent categories as checkbox cards — all ticked on arrival — and a single Agree button. The fastest possible gate.
V1
9:41▸▸▮
Data consent
Sewa only shares what's needed, only with your permission. You can review or revoke any of these at any time in Profile → Consent.
✓
Identity data (NIC, biometrics)
Shared with SLUDI · Required
✓
Vehicle & licence records
Shared with Dept. of Motor Traffic
✓
Location (nearest office)
Used only when you request it
✓
Notifications & reminders
SMS / push about your applications
Agree & continue
V2One at a time
A four-step stepper — each category its own screen (what / with whom / why), with two equal-weight buttons.
V2 · 2/4
9:41▸▸▮
Your data, your choice2 of 4
🚗
Vehicle & licence records
What: revenue licence, insurance & emission status
With: Dept. of Motor Traffic (via NDX)
Why: keep your wallet current & renewable
Allow
Not now
What happens if I say no?
Privacy policy v2.1 · 01 Jul 2026
V3Single ledger
One scannable list — required locked, optionals off with an inline what/kept/never expander. Reads like its own audit log.
V3
9:41▸▸▮
Data consentv2.1
Required to use Sewa
Identity — NIC & biometricsLocked ✓
Optional — off until you choose
Vehicle & licence records
Dept. of Motor Traffic · what / kept / never
Location — nearest office
Notifications
⛨ Every share is logged — view anytime in Profile.
Continue with my selections
Only required — continue
Rationale
V1Single agree list
Design logic
One agree moment — all four categories visible on a single screen, recipient named per category, one button to proceed. Minimal friction into the app.
Serves best
The onboarding funnel — nothing slows the first landing.
Costs
Optional categories arrive pre-ticked, so consent is assumed rather than given; there is no per-category detail layer, no decline path, and no policy version shown.
Evidence
Its recipient-per-category copy ("Shared with Dept. of Motor Traffic") is the strongest line in the screen — both alternatives keep it verbatim.
SLDS build
Checkbox, Button real — assembles as-is.
Risks
Pre-ticked optionals sit poorly with PDPA's freely-given standard and may force a re-consent campaign later; unticking is possible but nothing explains the consequence.
V2One at a time
Design logic
Consent as a sequence of real decisions — each category gets a full screen and two equal-weight buttons. Comprehension over speed. Optionals start off.
Serves best
First-timers and low-literacy citizens, at the moment comprehension matters most.
Costs
Four screens; friction for returning users — needs a skip for veterans.
Ritual fatigue → "don't ask again" per category; required identity is explained, never silently forced.
V3Single ledger
Design logic
One scannable surface — the agree list's shape, corrected: required locked, optionals off, each with an inline what/kept/never expander. Reads like the log it will generate.
Serves best
Confident users; auditors; fast re-consent when the policy version changes.
Costs
A wall of toggles can be skimmed; less teaching than the stepper.
List Item, Toggle real; CONTRIBUTE disclosure expander.
Risks
Must not read like T&Cs — every toggle needs plain what/kept/never, not legalese.
Comparison & recommendation
Dimension
V1 · Agree list
V2 · Stepper
V3 · Ledger
Comprehension at the gate
Low — agreement assumed
Highest — one decision at a time
Moderate
Speed / friction
One tap
Four screens
One screen
Consent posture
Pre-ticked — assumed
Strongest — freely given
Strong — chosen
Detail available before deciding
One line per category
Full what / with / why
Inline expanders
Re-consent on version change
Re-agree blindly
Heavy
Light
Build load
Lowest — exists
Medium
Medium
Verdict
The single-screen agree list is the direction the design takes — one glance, recipient named per category, the fastest gate a first run can have.
Its recipient-per-category copy ("Shared with Dept. of Motor Traffic") is the strongest consent line in the app and stays verbatim. The upgrade below makes the same screen consent-clean: optionals off, a detail layer, a version stamp, and no route around the gate. The stepper remains the assisted-mode fallback if field testing shows comprehension gaps; the ledger's toggle idiom returns in Profile as the consent manager.
V3 · AS DESIGNEDFinal design — Data consent
CONSENT · V3
9:41▸▸▮
Data consent
Sewa only shares what's needed, only with your permission. You can review or revoke any of these at any time in Profile → Consent.
✓
Identity data (NIC, biometrics)
Shared with SLUDI · Required
✓
Vehicle & licence records
Shared with Dept. of Motor Traffic
✓
Location (nearest office)
Used only when you request it
✓
Notifications & reminders
SMS / push about your applications
Agree & continue
V4 · PROPOSED UPGRADESame screen, consent-clean
CONSENT · V4
9:41▸▸▮
Data consentv2.1 · 01 Jul 3
Required to use Sewa
Identity data (NIC, biometrics)
Shared with SLUDI · verifies who you are
Locked ✓
Optional — off until you choose 1
Vehicle & licence records
Dept. of Motor Traffic · what / kept / never2
Location (nearest office)
Only while you use the map
Notifications & reminders
SMS / push about your applications
Continue with my selections
Only required — continue
1Optional categories start OFF — consent is given, never assumed; the required category stays locked and explained.
2A one-tap detail layer per category — what is shared, what is kept, what never happens — before deciding.
3Policy version and date on the screen — re-consent triggers only when this changes.
4The gate covers every sign-in route — including SLUDI — before first landing. No path skips it.
The other onboarding screens — structurally settled
These screens follow a single settled pattern. The reason is noted for each.
SplashA brand + routing moment, not a layout decision. One pattern: wordmark, auto-advance, and a quiet connectivity/session check that sends the citizen to the right next step.
LanguageA three-item native-script list is the settled convention. The only real variable — apply the choice the instant it's tapped — is adopted as a rule, not offered as an option.
Intro slidesThree skippable slides; carousel-vs-scroll is styling, not information architecture. One pattern: the trust (SLUDI) slide leads, Skip is always present.
Create accountSLUDI supplies identity read-only; the citizen confirms address and sets a PIN + biometric. Two short steps — no divergent structure to weigh.
Verify IDA status screen while checks resolve. Its one real design question — a mismatch recourse path — is a requirement, not a variant, so it's built into the journey.
Part B
The resolved journey
The recommended path, from first launch to a ready home screen.
▶
Start
→
1
Splash
always
→
2
Language
first run
→
3
Intro
first run
→
4
Sign in
if not authed
→
5
Code
mobile door
→
6
Create account
new number
→
7
Verify ID
new account
→
8
Consent
first landing
→
◼
Home
1 · SPLASH
9:41▸▸▮
S
SEWA
Sri Lanka's citizen services
Loading…
1Splash
◆ Prerequisite
App opened. Always shown — it is also the first moment to check connectivity and session.
Entry
App launch
Exit
Language (first run) · Home (valid session) · Sign in (expired)
✓ Success — auto-advance
After ~2s the app routes the citizen to the right next step — no tap needed. A returning citizen with a live session lands on Home directly.
Offline → app still opens, saved content onlyUpdate required → store prompt
2 · LANGUAGE
9:41▸▸▮
Choose your language
You can change this anytime.
English
සිංහල
Sinhala
தமிழ்
Tamil
Continue
2Language selectFirst run
◆ Prerequisite
No language set yet. Shown once on first run; afterwards it lives in Profile. The choice is the app's promise that the whole journey will speak the citizen's language.
Entry
Splash, first run
Exit
Intro slides
✓ Success — the moment of choice
The instant a language is tapped, the screen itself switches to that language — including the Continue button. Proof, before anything else, that the app keeps its language promise.
Screen-reader → options announced in own scriptNo default pre-selected beyond English hint
Native script first (සිංහල, தமிழ்), English label beneath. Reserve +45% width here — Sinhala/Tamil option rows run longer.
3 · INTRO
9:41▸▸▮
🛡
Verify once, use everywhere
Your SLUDI Digital ID links your NIC to every service. Prove who you are once — no repeated forms.
Next
Skip
3Intro slidesFirst run · skippable
◆ Prerequisite
Citizen has never completed onboarding. Three slides, always skippable. Never shown again once past.
Entry
Language
Exit
Sign in (Next on last slide, or Skip)
✓ Success — either way
Next on the final slide and Skip both land on Sign in. Skipping is a first-class choice, not a penalty — the citizen in a hurry loses nothing.
Swipe or button — both advanceTrust slide leads, not sells
Lead with the SLUDI trust story, not feature bragging — institutional legitimacy is the thing a first-time citizen needs reassured.
4 · SIGN IN
9:41▸▸▮
SEWA
All of government. One app.
▤
Sign in with mobile number
SMS code · no password · most used
›
🛡
Sign in with SLUDI app
Fingerprint or face · no SMS
›
◯
Browse as guest
Look around first · read-only
›
Government officer? Officer portal →
4Sign in
◆ Prerequisite
Not authenticated. One screen: OTP-first mobile entry; the same code path sets up new accounts, with SLUDI and guest beneath.
Entry
Intro, or any guarded action that needs sign-in
Exit
Code (mobile) · Verify (SLUDI) · Home read-only (guest)
✓ Success — code sent
The code screen opens with the number shown and editable. A returning citizen with a valid session never sees this screen at all.
Offline → sign-in needs signal; guest still worksSLUDI app missing → install or use mobileGuarded action → returns to intent after sign-in
As designed, upgraded: guest visible as an action, SLUDI routed through the consent gate, officer portal in the footer.
5 · CODE
9:41▸▸▮
←Mobile number+94 77… ✎
Type the code
Sent by SMS just now · fills in automatically on Android
4
9
2
Resend in 0:42 · didn't get it?
Confirm
Lights up when all 6 digits are in
5Enter the codeMobile door
◆ Prerequisite
A code was sent to a mobile number. Only on the mobile-number path — the SLUDI-app door confirms with biometrics instead and skips this.
Entry
"Send code" on Sign in
Exit
New number → Create account · existing → Verify/Home
✓ Success — verified
Six correct digits confirm instantly. A new number flows into account creation; a known number goes straight to Home (re-consent only if the policy changed).
Wrong code → clears, 2 tries left3 wrong → 15-min block, account safeDidn't arrive → resend / change number / 1919Old & new NIC formats accepted
6 · CREATE ACCOUNT
9:41▸▸▮
←Set up your account1 of 2
🛡From your SLUDI ID — please confirm it's you.
Nimal Kumara Perera🔒
200XXXXXXXXV · b. 1990🔒
Confirm your address
District ▾ · DS division ▾
Next — set a PIN
6Create accountNew number
◆ Prerequisite
Verified number not yet linked to a Sewa account. SLUDI supplies identity read-only; the citizen only confirms address, sets a PIN, and opts into biometrics. Skipped entirely for anyone who already has an account.
Entry
Code verified, new number
Exit
Verify ID
✓ Success — account created
After confirming address and setting a PIN + biometric, the citizen sees "Account ready" and moves to identity verification. The PIN set here is what later unlocks the app — created once, on purpose.
SLUDI detail wrong → report & pause for correctionPIN mismatch → re-enter, no lockoutBiometric optional → skippable
Identity is shown, never typed — the citizen confirms rather than enters. Address uses district / DS-division pickers, not free text.
7 · VERIFY ID
9:41▸▸▮
🛡
Identity verified
✓NIC matched with SLUDI
✓Biometric confirmed
✓Address on file confirmed
Continue
7Verify identityNew account
◆ Prerequisite
A new account awaiting SLUDI cross-check. Confirms NIC, biometric and address before the citizen is trusted into the app.
Entry
Account created
Exit
Consent (on success) · recovery (on mismatch)
✓ Success — checks pass one by one
Each check resolves visibly to a tick, then "Identity verified" unlocks Continue. Progressive, not a single silent spinner — the citizen watches trust being established.
Mismatch → retry / correct at SLUDI / call 1919Slow check → honest "still checking", not fake successOffline → held, resumes on signal
A real mismatch branch is essential — SLUDI data can be wrong, and a citizen must never hit a dead end with no recourse.
8 · CONSENT
9:41▸▸▮
Your data, your choicev2.1
Required to use Sewa
Identity — verifies who you areLocked ✓
Optional — off until you choose
Vehicle & licence records
Location — nearest office
Notifications & reminders
Continue
Only required — continue
8Data consentFirst landing
◆ Prerequisite
First landing, or the policy version changed. Every sign-in route — mobile, SLUDI, returning — passes through here before Home. No path skips consent.
Entry
Verify ID · or a returning user on a new policy version
Exit
Home — the journey's expected outcome
✓ Success — landed, ready
Whatever the citizen chose, Continue lands them on Home, greeted by name, with their choices saved and revocable in Profile. Optional categories start off — consent is given, never assumed.
Decline optional → explained consequences, still proceedsEvery share logged → history in ProfileRequired-only → one-tap fast path
Optional toggles default OFF by law and by design. Each carries a plain "what / with whom / why" the citizen can expand before deciding.
The same journey, four honest shapes
Returning · valid sessionSplash → Home. Everything else skipped. The daily case: open the app, you're in.
Returning · expired sessionSplash → Sign in → Code → Home. Identity already known; no account setup, no re-verification.
New citizenThe full eight steps shown above — the only time a citizen sees account creation and ID verification.
GuestSign in → Home (read-only). No consent gate until they try something that needs their data — then sign-in, with return to what they were doing.
03
Main Surfaces
The app's standing rooms: browse the full catalogue of services, and manage your own account. (The Wallet, the third main surface, is documented with the credential journey in section 04.)
◆ Prerequisites
Reachable from the bottom navigation at any time. Browsing is open to guests; profile requires sign-in.
Entry
Services / Profile tabs · Home's "See all" · a Home quick action
Exit / expected outcome
A service detail opened · a setting changed · an application tracked
Part A
Options & rationale
Browsing 200+ services is the one genuine design decision here — how a citizen who doesn't know a service's name still finds it. The profile screen follows a settled pattern, shown after.
Services browse — three ways through 200+ services
The decision: how the catalogue organises itself for a citizen who may not know what the service is called.
OPT 1Category groups
Life-journey groups with counts, each opening into its services with fee and time visible per row. The direction the design takes.
OPT 1
9:41▸▸▮
←Services
⌕Search services…
▤Birth & Identity3 services
▤
Birth Certificate
Dept. of Registrar General
LKR 200
3–5 days
▭
NIC Renewal
Dept. Registration of Persons
LKR 2,000
14 days
✈Travel2 services
✈
Passport Application
Dept. of Immigration
LKR 10,000
21 days
OPT 2Search-first
A large search with recents and popular services beneath — the catalogue only appears when asked. Fastest when the citizen knows the name.
OPT 2
9:41▸▸▮
←Services
⌕Try "birth certificate"…🎙
Popular now
▭NIC Renewal14 days
✈Passport Application21 days
▦Revenue Licence3 days
Your recent
▤Birth Certificateviewed
Browse all categories →
OPT 3Category grid
A full-screen tile grid of the life journeys — pick a category, then drill into its list. Maximum orientation, one extra hop everywhere.
OPT 3
9:41▸▸▮
←Services
⌕Search…
▤Birth & Identity3 services
✈Travel2 services
♡Health2 services
🎓Education2 services
▥Work & Tax3 services
🚗Vehicle3 services
Rationale
OPT 1Category groups
Design logic
One scroll shows the whole catalogue's shape — groups with counts, services with fee and time on every row. Orientation and transparency in the same gesture.
Serves best
Citizens who know roughly what they need but not its official name; first-time explorers.
Costs
Long single scroll as the catalogue grows; alphabetical order within groups buries the popular services.
Evidence
Grouped directories out-perform flat lists for unfamiliar vocabularies; fee/time-per-row is transparency by default.
SLDS build
List Item, Search Input real; grouped-list header CONTRIBUTE.
Risks
Ministry names must wrap, never truncate — attribution is a legitimacy signal.
OPT 2Search-first
Design logic
The fastest path is typing (or saying) what you want; the surface stays nearly empty until asked, with popular and recent as safety nets.
Serves best
Repeat users; anyone arriving with a name in mind; voice-first low-literacy users.
Costs
Unforgiving when the citizen doesn't know the term; search quality becomes the whole experience — synonyms in all three languages must work.
Evidence
Search-dominant catalogues need strong query understanding before they beat browsing; government service names are notoriously unguessable.
An empty-result dead end is a trust failure — every miss needs suggestions and a human route.
OPT 3Category grid
Design logic
Choose a world first, then see its services — the grid gives maximum orientation with big targets and short labels.
Serves best
Very-low-literacy users; icon-led navigation; small catalogues.
Costs
Every service is two hops away; fees and times hide until the second screen.
Evidence
Icon grids test well for recognition but add a navigation layer flat lists don't need.
SLDS build
Icon Card real; category tile CONTRIBUTE.
Risks
Category names are the hardest strings to translate — a wrong guess costs two screens, not one.
Comparison & recommendation
Dimension
Opt 1 · Groups
Opt 2 · Search-first
Opt 3 · Grid
Unknown-name findability
Highest — shape visible
Low
High
Known-name speed
Medium
Fastest
Slowest
Fee & time transparency
On every row
On results
Two hops deep
Catalogue growth
Long scroll
Scales best
Grid crowds
Low-literacy friendliness
Good
Needs voice
Best icons
Verdict
Category groups with search on top is the direction the design takes — the catalogue's shape stays visible while typing stays available.
Search-first's strengths are absorbed rather than adopted: the search field already leads the screen, and the upgrade adds what a miss or a hurry needs — filters, popular-first ordering, and an empty state that never dead-ends. The grid remains the right pattern for a future assisted mode.
V3 · AS DESIGNEDFinal design — Services
SERVICES · V3
9:41▸▸▮
←Services
⌕Search services…
▤Birth & Identity3 services
▤
Birth Certificate
Dept. of Registrar General
LKR 200
3–5 days
▭
Marriage Certificate
Dept. of Registrar General
LKR 200
3–5 days
▭
NIC Renewal
Dept. Registration of Persons
LKR 2,000
14 days
✈Travel2 services
✈
Passport Application
Dept. of Immigration
LKR 10,000
21 days
V4 · PROPOSED UPGRADESame list, four changes
SERVICES · V4
9:41▸▸▮
←Services
⌕Search services…🎙
1AllFreeUnder 7 daysVehicle
▤Birth & Identity3 services
2▭
NIC Renewal · most applied
Department of Registration of Persons
LKR 2,000
14 days
▤
Birth Certificate
Department of the Registrar General — wraps, never truncates 3
LKR 200
3–5 days
No match? Near-suggestions shown — or call 1919. Never a dead end. 4
1Filter chips — free / fast / by journey; the catalogue narrows without typing.
2Popular-first ordering within groups — the services most citizens need stop hiding behind the alphabet.
3Ministry names wrap, never truncate — departmental attribution is a legitimacy signal.
4An empty result never dead-ends — near-match suggestions, voice retry, and the 1919 route.
Profile — settled structure
A settings list under the citizen's identity card: one sound pattern, shown as designed with its proposed refinements.
V3 · AS DESIGNEDFinal design — Profile
PROFILE · V3
9:41▸▸▮
Profile
◯
Nimal K. Perera
200XXXXXXXXV · +94 77 XXX XXXX
✎
🛡
SLUDI Digital ID
Verified · Active since Jan 2026
✓ Verified
🌐LanguageEnglish
△Notification preferences›
🔒Biometric login
🛡Consent & data sharing›
🔒Lock app now›
?Help & support›
Sign out
V4 · PROPOSED UPGRADESame list, five changes
PROFILE · V4
9:41▸▸▮
Profile
◯
Nimal K. Perera
200XXX•••••V — masked 3
✎
1▥
My applications
1 in review · 1 approved · 1 needs action
›
🌐Language · සිංහල · தமிழ்›2
△Notification preferences›
🔒Biometric login
🛡Consent & data sharing›
?Help & support · 1919›4
Sign out 5
1My applications gets a first-class row with status counts — the retention loop's missing entry point, mirrored on Home's strip.
2Language becomes changeable here — shown in all three scripts, opening the same selector as onboarding.
3The NIC is masked on a glanceable screen — the full number only behind a tap and re-auth.
4Help & support is wired — FAQs, office locator, and the 1919 line; never a dead row.
5Sign-out asks once — a confirmation protects shared-phone households.
States
Success · Service found
A tap on any row opens the service detail with fee and time already known — the citizen arrives informed.
Search · No match
Nothing for "rewenu laisan" — did you mean Revenue Licence?
Suggestions + browse + 1919. Never empty-handed.
Offline
⚠ Offline — showing the saved catalogue.
Fees and times dated; applying waits for signal.
Guest on Profile
Profile invites sign-in with one line and the guest's browsing intact — no scolding, no dead end.
Part B
The resolved journey — finding a service
From "I need something from the government" to a confident start, whichever way the citizen arrives.
▶
A need
→
1
Search or browse
always
→
2
Service detail
always
→
3
Sign in
if guest
→
◼
Apply · §07
1 · FIND
9:41▸▸▮
←Services
⌕"birth certificate"…
Results
▤
Birth Certificate
Registrar General · LKR 200 · 3–5 days
›
▭
Marriage Certificate
Registrar General · LKR 200
›
or browse by life journey below
1Search or browse
◆ Prerequisite
A need, named or not. Search serves the citizen who knows the term; the category groups serve the one who doesn't. Open to guests.
Entry
Services tab · Home search · a featured card · the assistant's deep link
Exit
A service detail opened
✓ Success — the right service, fee and time already visible
Every result row carries its fee and processing time, so the tap into detail is already an informed one.
No match → suggestions + 1919, never a dead endOffline → saved catalogue, dated
2 · DETAIL → APPLY
9:41▸▸▮
←Birth Certificate
LKR 2003–5 days
What you'll need
☐ Your NIC · ☐ birth date & place
Prefer an office? DS Colombo 03 · till 4:30 →
Apply now
2Detail, then the hand-off
◆ Prerequisite
A service opened. Applying requires sign-in — a guest is gated at "Apply now" and returns here after signing in.
Entry
Any result or category row
Exit
The application flow — section 07 — with readiness answers carried in
✓ Success — a confident start
The form opens with SLUDI details pre-filled; browsing has become applying without a single re-entered fact.
Knows the nameSearch → detail → apply. Two taps from need to form; fee and time visible the whole way.
Doesn't know the nameBrowse the life journeys — the catalogue's shape does the naming; groups and counts orient before any tap.
GuestReads everything, gated at Apply — signs in and lands right back on the same service, nothing lost.
04
Vehicle & Credentials — incl. Wallet
Hold the citizen's verified identity and signed credentials in one place — and let them prove any of it in seconds, offline, at a roadside stop or a counter.
◆ Prerequisites (journey)
Signed in and verified. Credentials arrive from NDX registries once a vehicle or licence is linked; the wallet works with no signal because credentials are signed on the phone.
Entry
Wallet tab · a service that issues a credential · a renewal reminder
Exit / expected outcome
A credential presented and verified offline · or renewed before it lapses
Part A
Approaches & rationale
The structural options considered for this journey. The wallet home and the credential-presentation screen each carry a genuine design decision, explored below; capture, sync, licence and fuel-quota screens follow a single settled pattern, noted at the end.
Wallet — the home of credentials
The decision: organise identity, documents and credentials so a citizen finds and acts on them — especially before they expire.
V1Card stack
Identity hero card on top, then everything grouped by type — vehicle, licence, certificates. All visible.
V1
9:41▸▸▮
Wallet
🛡SLUDI DIGITAL ID✓ Verified
◯
Nimal K. Perera
200XXXXXXXXV
Vehicle credentials
▦Revenue Licence · Dec 2026›
◍Emission · Aug 2026›
🛡Insurance · Mar 2027›
Driving licence
🚗Driving Licence · 2031›
Certificates
▤Birth CertificatePDF
V2Needs-attention first
Grouped by urgency — what's expiring leads, then what's ready to present, then identity. Explicit buttons.
V2
9:41▸▸▮
Wallet
✓ Works without signal — signed on this phone
Needs renewal soon
◍Emission Certificate28 days
RenewDetails
Ready to present
🚗Driving LicenceValid
Show QRDetails
My identity
🛡SLUDI ID · ✓ Verified›
V3Filter shelf
A filterable list with status rails and a per-row QR — plus select several and present one combined code.
V3
9:41▸▸▮
WalletOffline ✓
AllVehiclePersonal
☑Emission · 28d left▦
☑Revenue Licence▦
☑Motor Insurance▦
☑Driving Licence▦
☐SLUDI ID · pinned▦
Present 3 selected — one QR
Rationale
V1Card stack
Design logic
Everything visible, grouped by type, with the identity card as the anchor. Nothing hidden behind a filter.
Serves best
Citizens with a handful of credentials; first-timers who want to see it all at once.
Costs
Expiry is buried in row text — the renewal moment (the wallet's whole value) doesn't lead.
Evidence
Mirrors physical-wallet mental models; recognition over recall.
SLDS build
Card, List Item, Badge real; CONTRIBUTE credential card with expiry states.
Risks
Grows long with many credentials; no expiring/expired treatment unless added.
V2Needs-attention first
Design logic
Urgency is the organising idea — what expires leads, with explicit Renew / Show QR / Details buttons.
Serves best
The renewal case (revenue licence, emission) — the reason a citizen re-opens the wallet.
Costs
When nothing is expiring, the top group is an "all clear" state, not content.
Evidence
Task-first Guided Hand; renewal nudges drive retention in wallet apps.
Urgency framing must not become anxiety UI — cap and calm the empty state.
V3Filter shelf
Design logic
A dense filterable list with status rails and per-row QR — plus a combined multi-credential presentation.
Serves best
Multi-vehicle households, small-business owners, roadside stops needing several documents at once.
Costs
Density and filters assume orientation; combined-present needs a data-minimisation disclosure.
Evidence
Efficiency & flexibility (Nielsen #7); faceted lists for larger sets.
SLDS build
Chip, List Item real; CONTRIBUTE combined-VP presenter, status-rail row.
Risks
Combined QR only safe once officer reason codes exist (verifier must say which credential failed).
Comparison & recommendation
Dimension
V1 · Card stack
V2 · Attention
V3 · Filter shelf
Renewal prompting
Weak — in row text
Strongest — leads
Medium — status rail
First-time legibility
Highest — all visible
High
Needs orientation
Many-credential handling
Long scroll
Grouped
Filtered + combined present
Offline clarity
Implicit
Stated proudly
Badge
Build load
Lowest
Medium
Highest
Verdict
The identity-first card stack is the direction the design takes — the SLUDI card as anchor, credentials grouped by type beneath it, everything visible without a filter.
It mirrors a physical wallet, and its grouping survives any number of credentials a typical household holds. The attention-first study contributes what the stack lacks — expiry urgency — as the upgrade below; the filter shelf and combined presentation remain the graduation path for heavy wallets once officer-side per-credential results exist.
V3 · AS DESIGNEDFinal design — Wallet
WALLET · V3
9:41▸▸▮
Wallet
🛡 SLUDI DIGITAL ID✓ Verified
◯
Nimal Kumara Perera
NIC 200XXXXXXXXV · Colombo
ShareDownload
Vehicle credentials+ Add
▦Revenue Licence · valid until 31 Dec 2026›
◍Emission Cert. · valid until 14 Aug 2026›
🛡Motor Insurance · valid until 02 Mar 2027›
⛽Check fuel quota (provisional)
Driving licence+ Add
🚗Driving Licence · valid until 09 May 2031›
Downloaded certificates
▤Birth Certificate · BC-2026-78432PDF
V4 · PROPOSED UPGRADESame stack, five changes
WALLET · V4
9:41▸▸▮
WalletOffline ✓ 3
🛡 SLUDI DIGITAL ID✓ Verified
◯
Nimal Kumara Perera
Show only to officials — never send by message 4
Needs renewal soon 1
◍
Emission Certificate
28 days left · until 14 Aug
Renew
Vehicle credentials
▦
Revenue Licence · Dec 2026
Details · ▦ QR2
🛡
Motor Insurance · Mar 2027
Details · ▦ QR
🚗
Driving Licence · May 2031
Details · ▦ QR
⛽Fuel quota — provisional, indicative only 5
Downloaded certificates
▤Birth CertificatePDF
1Expiring-soon surfaces to the top with a Renew action — the renewal nudge is the wallet's whole retention case; "valid until" alone hides the deadline.
2Tap opens a credential detail; QR is an explicit button — issuer, validity and history become visible instead of jumping straight to a code.
3Offline capability stated on the surface — signed credentials work with no signal; the wallet should say so proudly.
4A caution on sharing the national ID — "Share" on an identity card needs a defined, warned meaning.
5The fuel-quota caveat travels with the feature — provisional stays provisional wherever it appears.
Credential QR — presenting proof, offline
The decision: pure machine speed, a human-readable pass, or a consent ritual with a citizen record.
V1The beacon
Maximum scannability, minimum chrome — a giant self-renewing code, auto-brightness, one disclosure line.
V1
9:41▸▸▮
←Driving LicenceNo signal needed ✓
Fresh code · renews itself
B1234567 · Valid
Shares your licence status only · full brightness
V2The pass
A document both humans and machines read — name and validity on top, the code below, with a switcher.
V2
9:41▸▸▮
←Present passOffline ✓
DRIVING LICENCEValid ✓
Nimal K. Perera
B1234567 · classes B, B1 · to 2031
Fresh 52s · renews itself
Scanner learns licence status only. Nothing else is visible.
Switch credential ▾
V3The ritual
Consent before, evidence after — a pre-flight of what's shared, the code, then a citizen-owned log.
V3 · pre-flight
9:41▸▸▮
←Show Driving Licence?
SHARESLicence status + that it's yours
WITHWhoever scans — usually an officer
KEEPSA record in your history
WORKSWith no signal ✓
Nothing shared until the code is scanned.
Show the code
Not now
☐ Don't ask again for this credential
Rationale
V1The beacon
Design logic
The scan is a physical event in bad conditions — spend every pixel on decode speed and self-renewal.
Large-text mode grows words, never the code; "not an ID" line carries legal weight.
V3The ritual
Design logic
Presentation is a data-sharing act — informed pre-flight, then the code, then a receipt into a citizen log.
Serves best
First-time presenters; privacy-conscious citizens; disputes ("here is my log").
Costs
Two extra taps while an officer waits — the "don't ask again" escape is load-bearing.
Evidence
PDPA informed, purpose-bound sharing; the review's citizen mirror for "all checks logged".
SLDS build
CONTRIBUTE disclosure card + presentation log.
Risks
Ritual fatigue — collapse after first consent; be honest about local vs department logs.
Comparison & recommendation
Dimension
V1 · Beacon
V2 · Pass
V3 · Ritual
Scan speed under pressure
Fastest
A beat slower
Fast after pre-flight
Citizen understands sharing
One line
High — card is the disclosure
Highest — explicit
Human readability
Minimal
Designed for it
Minimal at code stage
Audit / dispute evidence
Dept-side
Dept-side
Citizen-owned log
Taps to scannable
One
One
Two (first time)
Verdict
The dark full-screen stage with a bright, short-lived code is the direction the design takes — and its "signed offline, no live lookup" line is exactly the right promise, kept verbatim.
Decode speed is dignity at a roadside stop, and the dark stage maximises it. The upgrade below removes the one hostile moment — asking a nervous citizen to tap refresh while an officer waits — and adds disclosure, brightness and a citizen-side record. The pass study remains the fuel-quota and counter mode; the ritual's pre-flight wraps a citizen's first-ever presentation.
V3 · AS DESIGNEDFinal design — Present credential
QR · V3
9:41▸▸▮
←Present credential
Active for 47s — signed offline, no live lookup needed
Revenue Licence
RL-2026-33210 · WP CAB-4521
QR expired — tap to refresh
Hold steady for the verifying officer to scan
V4 · PROPOSED UPGRADESame stage, five changes
QR · V4
9:41▸▸▮
←Driving LicenceNo signal needed ✓
Fresh code — renews itself, just hold steady 1
Shares your licence status only2
B1234567 · Valid
Screen at full brightness · restored after 3
Logged to your presentation history 4
1The code renews itself — tap-to-refresh made a nervous citizen perform a step while an officer waited; expiry becomes invisible.
2A plain disclosure line — exactly what leaves the phone, said in one sentence on the presentation surface.
3Auto-brightness, restored on exit — sun glare is the roadside's default lighting.
4A citizen-side presentation log — the citizen's half of "all checks are logged"; evidence in any later dispute.
5An expired credential never renders a code — it renders the renewal path instead; a dead QR in an officer's face helps no one.
The other screens in this journey — a single settled pattern each
These screens follow a single settled pattern. The reason is noted for each.
Add vehicleA short capture form — registration + chassis, with a plain reason for chassis (anti-fraud). One pattern; the only variable is scan-from-book, offered as an enhancement.
Sync from NDXA fetch-status screen resolving to signed credentials. Settled; its real design work is the partial-result and not-found states, built into the journey.
Add driving licenceCapture the number, verify with Motor Traffic, generate a signed credential. One pattern; the mismatch branch is a requirement, not an option.
Fuel quotaA provisional quota display with a remaining-litres bar and an absolute reset date. Settled; drawn below with its caveat.
V3 · AS DESIGNEDFinal design — Fuel quota
FUEL · V3
9:41▸▸▮
←Fuel quota
Provisional feature — quota figures are indicative and subject to change.
🚗
WP CAB-4521
Toyota Aqua · 2019
This week's quota remaining
6.5 L of 20 L
13.5 L used this week · resets Monday
How to redeem
Present your Vehicle Credential QR at any participating fuel station. The remaining quota updates automatically after each fill.
1The reset day becomes an absolute date — "resets Mon 27 Jul", never a weekday the citizen must calculate.
2The provisional caveat travels — wherever the quota is promoted (Home, Wallet), the same one-line caveat appears with it.
3Multiple vehicles get a selector — the single-vehicle assumption ends the day a household adds a second.
Part B
The resolved journey
The recommended path, from an empty wallet to a credential presented and verified offline.
▶
Start
→
1
Wallet
always
→
2
Add vehicle
if none yet
→
3
Sync (NDX)
on add
→
4
Present QR
on request
→
◼
Verified
1 · WALLET
9:41▸▸▮
Wallet
✓ Works without signal
🛡 SLUDI DIGITAL ID · ✓ Verified
Nimal K. Perera · 200XXXXXXXXV
Vehicle credentials
+Add a vehicle to fetch its credentials›
1Wallet — home of credentials
◆ Prerequisite
Signed in & verified. Identity is always present; credential groups appear as they're added.
Entry
Wallet tab · a renewal reminder · a service handoff
Exit
Add vehicle · present a credential · renew
✓ Success — the wallet always has something true
Even empty of vehicle credentials, the verified SLUDI ID is present and presentable — the wallet is never a blank screen.
Offline → full wallet still worksEmpty → clear "add" promptGuest → gated, sign-in returns here
As designed, upgraded: the identity-first stack with the v4 renewal states on every credential.
2 · ADD VEHICLE
9:41▸▸▮
←Add vehicle
We'll fetch your Revenue Licence, Emission & Insurance from the issuing departments.
Registration number
WP CAB-4521
Chassis number
MR0FR22G701234567
Chassis confirms ownership — anti-fraud.
Fetch vehicle details
2Add vehicleConditional
◆ Prerequisite
No vehicle linked yet. Skipped for citizens who already have their vehicle credentials in the wallet.
Entry
"Add a vehicle" from Wallet
Exit
Sync from NDX
✓ Success — after "Fetch"
Moves to the NDX sync screen, which shows each registry being contacted — the citizen sees the state working for them.
Not found → check number / manual pathChassis mismatch → explained retryScan-from-book → enhancement
3 · SYNC
9:41▸▸▮
←Vehicle credentials
WP CAB-4521
Toyota Aqua · 2019
Synced credentials
▦Revenue LicenceSigned
◍Emission CertificateSigned
🛡Motor InsuranceSigned
Add to Wallet
3Sync from NDXConditional
◆ Prerequisite
A vehicle was just added (or a re-sync requested). Fetches each credential from its registry and signs it to the phone.
Entry
"Fetch" from Add vehicle
Exit
Credentials in Wallet, ready to present
✓ Success — signed & stored
Each credential lands with a Signed chip; "Add to Wallet" files them. From here they present offline forever, until expiry.
Partial → "no active insurance found", fix pathRegistry offline → retry, keep what syncedOffline → queues, syncs on signal
4 · PRESENT
9:41▸▸▮
←Driving LicenceOffline ✓
Renews itself · sharing status only
B1234567 · Valid
Hold steady for the officer to scan
4Present credential QR
◆ Prerequisite
A valid (not expired/revoked) credential is in the wallet. First presentation runs the one-time consent pre-flight.
Entry
"Show QR" from a wallet card
Exit
Officer scans → verified offline · logged to history
✓ Success — a live, scannable code
A bright, self-renewing code the officer scans in seconds — no signal needed on either side. The presentation is logged to the citizen's own history.
As designed, upgraded: the dark stage with the v4 self-renewing code and citizen log.
5 · VERIFIED
9:41▸▸▮
✓
VALID
Verified offline by signature · no live lookup
5Verified — the outcome
◆ Prerequisite
An officer scanned the presented code. The check runs entirely on the officer's device against the credential's signature.
Entry
Officer scan of the citizen's QR
Exit
Back to Wallet · presentation recorded in the citizen's history
✓ The outcome both sides trust
A clear VALID with the plain assurance "verified offline by signature" — no network, no doubt. (Officer-side reason codes for INVALID live in Section 04.)
Expiring soonEmission · 28 days left. The card surfaces to the top with a Renew button; a reminder is sent — the renewal nudge is the wallet's retention case.
No signalPresent anyway. Signed credentials verify offline on both sides; the wallet says so proudly rather than blocking.
Fuel quotaPresent the vehicle credential at a station. The provisional quota bar updates after each fill; caveated as indicative.
Part B
The renewal loop
The wallet's second story: a credential approaches expiry, the citizen renews without re-entering a fact, and the wallet quietly holds the new one.
▶
28 days left
→
1
Nudge
wallet · Home · SMS
→
2
Renew & pay
§07 ceremony
→
3
Re-sync
automatic
→
◼
Valid again
RENEW · HAND-OFF
9:41▸▸▮
←Renew Revenue Licence
Everything below comes from your wallet — nothing to re-enter.
Vehicle
WP CAB-4521 · Toyota Aqua
Current licence
RL-2026-33210 · expires 31 Dec 2026
Renewal fee
LKR 1,000.00
Continue to payment
2Renew & pay — the hand-off
◆ Prerequisite
A credential inside its renewal window. The nudge (wallet card, Home strip, SMS) lands here with vehicle and licence pre-filled from the wallet.
Entry
Renew on the wallet card · Home's attention strip · the SMS reminder
Exit
The payment ceremony — then back to the wallet, automatically
✓ Success — the wallet updates itself
Payment confirmed → the new licence syncs from the registry and replaces the old card; the citizen is told once, and the receipt files itself.
Pay-later fork at LKR 1,000 — the fee qualifiesRegistry slow → old credential stays valid until its datePayment failed → nothing lost, nudge stays
My vehicles — settled structure
The small management surface behind multi-vehicle households: one list, add and remove.
PROPOSED DESIGN · NEWMy vehicles
VEHICLES · NEW
9:41▸▸▮
←My vehicles
🚗
WP CAB-4521 · Toyota Aqua
3 credentials · emission expiring soon
›
🛵
WP BV-7719 · Honda Dio
2 credentials · all valid
›
+Add a vehicle
Fuel quota and credentials are shown per vehicle
1One row per vehicle, health at a glance — credential count and the nearest expiry, feeding the wallet's attention group.
2Removing a vehicle confirms and explains — its credentials leave this phone; re-adding re-syncs them.
3Quota and presentation become per-vehicle — the selector the fuel-quota screen was promised.
05
Officer Verification
The field officer's side of the trust model: sign in under RBAC, scan a citizen's presented QR, and get a Valid / Invalid answer in seconds — entirely offline, with a reason the officer can act on and a citizen can understand.
◆ Prerequisites
An authorised officer signed in under RBAC on a bound device. The citizen presents a signed credential QR (Section 04). No network required on either side.
Entry
Officer portal (separate distribution) · footer entry from citizen sign-in
Exit / expected outcome
A logged Valid/Invalid result with reason · scan another · citizen sees the same outcome
Part A
Options & rationale
The verification result is the one screen here with a real design decision — everything an officer needs, readable at arm's length, in the second after a scan. Login and scan follow a single settled pattern, shown after.
Verification result — three ways to answer
The decision: how much the result says beyond a verdict, without slowing the officer down.
OPT 1Full-screen verdict
The verdict fills the screen — a giant VALID/INVALID readable across a car window — with the details listed beneath. The direction the design takes.
OPT 1
9:41▸▸▮
✓
VALID
Verified offline by signature · no live lookup
CredentialRevenue Licence · Insurance
CitizenN. K. Perera
VehicleWP CAB-4521
Scan another
OPT 2Verdict + reason
The same verdict, but an Invalid always carries a reason — expired, revoked, or signature mismatch — so the roadside conversation has an answer.
OPT 2
9:41▸▸▮
✕
INVALID
Emission certificate expired 14 Aug 2026
CitizenN. K. Perera
Checked at21 Jul · 15:04
Scan another
OPT 3Per-credential breakdown
When several credentials are presented at once, each gets its own line and its own verdict — so a valid licence isn't tarred by a lapsed emission cert.
OPT 3
9:41▸▸▮
2 OF 3 VALID
✓Revenue Licencevalid
✓Motor Insurancevalid
✕Emission Cert.expired
Scan another
Rationale
OPT 1Full-screen verdict
Design logic
One answer, unmissable at distance — the officer reads it through a windscreen in under a second; details wait below.
Serves best
The common single-credential stop; quick roadside and checkpoint checks.
Costs
An Invalid says nothing about why; multi-credential stops collapse into one verdict.
Without reasons, disputes escalate; the demo-toggle from the prototype must not ship.
OPT 2Verdict + reason
Design logic
Keep the glanceable verdict, but never leave an Invalid unexplained — expired, revoked, or signature mismatch, in plain words.
Serves best
Every Invalid: the officer knows what to do and the citizen knows what to fix.
Costs
A reason taxonomy must be defined and maintained across credential types.
Evidence
Error-message guidance (Nielsen #9); the review flagged missing reason codes as a field-dispute risk.
SLDS build
Badge, Panel real; reason-code chip CONTRIBUTE.
Risks
Reasons must be citizen-safe — no sensitive detail exposed to a stranger holding the scanner.
OPT 3Per-credential breakdown
Design logic
Multiple credentials, multiple truths — each line carries its own verdict and reason, so one lapse doesn't condemn the set.
Serves best
Combined presentations (licence + insurance + emission) — the norm at a vehicle stop.
Costs
More to read; the top-line summary must still be glanceable.
Evidence
Progressive disclosure; the combined-VP presentation (Section 04) requires it to be safe.
SLDS build
List Item, Badge real; per-credential result row CONTRIBUTE.
Risks
Needs a clear at-a-glance summary line or density defeats the purpose.
Comparison & recommendation
Dimension
Opt 1 · Verdict
Opt 2 · + Reason
Opt 3 · Breakdown
Glanceability at distance
Highest
Highest
Medium
Actionable on Invalid
No reason
Always a reason
Reason per item
Multi-credential stops
One verdict
One verdict
Per credential
Citizen fairness
Low
High
Highest
Speed to read
Fastest
Fast
Slower
Verdict
The full-screen verdict is the direction the design takes — the right instinct for a screen read at arm's length in the field.
Its "verified offline by signature · no live lookup" line is exactly right and stays verbatim. What it must gain is a reason on every Invalid (Opt 2) and per-credential results for combined presentations (Opt 3) — both folded into the upgrade below, along with removing the prototype's demo-toggle and making "all checks are logged" real.
As designed, upgraded: the full-screen verdict with the v4 reason codes, per-credential results, and real audit logging.
The answers an officer must be able to give
ValidSigned, current, matches the holder. Verified on the device against the signature — the same answer with or without signal.
Invalid · expiredReason shown, citizen mirrored. "Emission certificate expired 14 Aug" — the citizen sees the same line and a renewal path.
Invalid · revoked / signatureDistinguished, not conflated. A revoked credential and a forged one are different problems; the reason code names which.
Scan history — settled structure
The record behind "all checks are logged": the officer's own audit trail, on the device and synced to the department.
PROPOSED DESIGN · NEWOfficer scan history
SCAN LOG · NEW
9:41▸▸▮
←Scan historyToday · 14
✓
Revenue Lic + Insurance · valid
CAB-4521 · 15:04
✕
Emission · expired 14 Aug
KV-2210 · 14:47
✓
Driving Licence · valid
B7789 · 14:31
Syncs to the department when connected · read-only
1Every check appears, verdict and reason included — the officer's answerability mirror of the citizen's presentation log.
2Offline-first, synced later — checks log on the device at the roadside and reconcile to the department with signal.
3Read-only by design — history cannot be edited or deleted from the field.
06
Trust & Settings
The surfaces that keep the relationship honest: an assistant that helps in any language, consent that stays revocable, notifications on the citizen's terms, a lock that guards the phone in a pocket, and a payment gateway that never asks a citizen to guess what they owe.
◆ Prerequisites
Signed in (the assistant also serves guests read-only). The app lock appears only when enabled and the app resumes after inactivity.
A question answered · a preference changed and kept · a bill paid by reference
Part A
Options & rationale
The assistant is the one genuine design decision here — how much the helper does, and in whose language. The four settings surfaces follow settled patterns, shown after.
AI-GIC assistant — three ways to help
The decision: a guide that answers, a voice that listens, or a hand that acts.
OPT 1Chat guide
A conversational guide that answers questions and points to the right service — informational by design. The direction the design takes.
OPT 1
9:41▸▸▮
←AI-GIC Assistant
Hi, I'm the Sewa assistant. Ask me about any government service and I'll point you the right way.
How do I renew my Revenue Licence?
Under Services → Vehicle & Transport. Once issued it also lives in your Wallet as a credential.
Try asking
What documents do I need for a passport?
Track my application
Ask a question…
›
OPT 2Voice-first helper
A microphone leads; the citizen speaks in Sinhala, Tamil or English and hears the answer back. Typing is the fallback, not the default.
OPT 2
9:41▸▸▮
←AssistantEN · සිං · த
🎙
Hold and speak — any language
"මගේ රෙවනිව් ලයිසන් එක අලුත් කරන්නේ කොහොමද?"
Answers are read aloud and shown as text.
Type instead
OPT 3Do-it-with-me
The assistant doesn't just point — it starts the task in the chat, with an explicit confirm gate before anything is submitted or paid.
OPT 3
9:41▸▸▮
←Assistant
Renew my revenue licence
I can start that. WP CAB-4521 · fee LKR 1,000 · uses your wallet credentials. Shall I?
Start renewalNot now
Nothing is submitted or paid without your explicit confirmation.
Ask or instruct…
›
Rationale
OPT 1Chat guide
Design logic
Informational by design — the assistant explains and routes, the flows themselves do the acting. A safe, legible scope for a government AI.
Serves best
Citizens who don't know which service they need; the "where do I even start?" moment.
Costs
Typed-text-only excludes low-literacy users; suggestions that only insert text still leave the work to the citizen.
Evidence
Informational scope keeps liability and error-cost low while trust in the AI is still being earned.
SLDS build
Card, Input real; chat surface CONTRIBUTE.
Risks
Wrong answers about fees or eligibility damage trust — answers must cite their service page.
OPT 2Voice-first helper
Design logic
Speech is the lowest floor there is — no typing, no spelling, any of the three languages, answers read back.
Serves best
Low-literacy and elder citizens; hands-busy moments; anyone more comfortable speaking than spelling.
Costs
Speech recognition for Sinhala and Tamil must be genuinely good before this leads; noisy environments defeat it.
Evidence
Voice is the single highest-leverage accessibility feature for mixed-literacy populations.
SLDS build
Voice input, spoken-answer surface CONTRIBUTE.
Risks
Shipping poor recognition in two of three languages is worse than not shipping voice at all.
OPT 3Do-it-with-me
Design logic
Collapse the distance between asking and doing — the assistant assembles the task; the citizen approves it.
Serves best
Repeat tasks (renewals, payments) where the flow is known and the data already exists.
Costs
An acting AI needs guardrails, an audit trail, and flawless confirm gates; errors are expensive and public.
Evidence
Action-taking assistants earn their place only after the informational layer has earned trust.
SLDS build
Confirm-gate card, in-chat task card CONTRIBUTE.
Risks
A single wrong submission in a citizen's name outweighs a thousand good answers — this is a later phase, not launch.
Comparison & recommendation
Dimension
Opt 1 · Chat guide
Opt 2 · Voice-first
Opt 3 · Do-it-with-me
Safety of scope
Highest — informational
Highest
Needs guardrails
Low-literacy reach
Typed only
Best — speech
Typed only
Task completion power
Points the way
Points the way
Does the task
Launch readiness
Ready
Depends on si/ta speech quality
Later phase
Verdict
The chat guide is the direction the design takes — the right scope while trust in a government AI is still being earned.
Voice joins it as an input mode rather than a separate surface (the upgrade below), because speech is the accessibility floor this population needs. Do-it-with-me waits: action-taking belongs to a later phase, behind confirm gates and an audit trail, once the informational layer has proven itself.
V3 · AS DESIGNEDFinal design — Assistant
ASSISTANT · V3
9:41▸▸▮
←AI-GIC Assistant
Hi, I'm the Sewa assistant (AI-GIC). Ask me about any government service, and I'll point you in the right direction.
How do I renew my Revenue Licence?
You can renew it under Services → Vehicle & Transport. Your Revenue Licence is also stored as a credential in your Wallet once issued.
Try asking
What documents do I need for a passport?
Track my application
Ask a question…
›
V4 · PROPOSED UPGRADESame chat, five changes
ASSISTANT · V4
9:41▸▸▮
←AI-GIC AssistantEN · සිං · த 2
Ask me about any government service — I'll point you the right way.
Renew it under Services → Vehicle & Transport. Open Revenue Licence renewal →4
From the Revenue Licence service page · answers can be wrong — check the linked page.
Try asking
Track my application →
Talk to a person · 19193
Ask or speak…
🎙1
1Voice input beside the keyboard — speak in any of the three languages; the accessibility floor for a national assistant.
2Language switch inside the chat — the conversation follows the citizen, not the other way around.
3A human handoff that's always visible — the 1919 Government Information Centre, one tap away.
4Answers deep-link into flows — "open Revenue Licence renewal" beats telling the citizen where to walk.
5A source-and-limits line under answers — cited service pages and honest fallibility keep trust calibrated.
1GovPay: the reference finds the amount — a citizen never asserts what they owe the state; the bill is fetched and shown to confirm.
2GovPay: the same closing ceremony as applications — confirm step, method choice, processing states, receipt to Wallet.
3App lock: unlocking returns to the interrupted screen — a lock is a pause, not a restart.
4App lock: forgot-PIN recovers by OTP re-verification — with the same attempt-limit rigor as sign-in.
5Notifications: an SMS-language choice — the message arrives in the citizen's script, and free channels say so. Drawn below.
V3 · AS DESIGNEDNotification preferences
NOTIF · V3
9:41▸▸▮
←Notification preferences
Channels
SMS notifications
Push notifications
Email notifications
What to notify me about
Application status updates
Payment confirmations
Tips & announcements
V4 · PROPOSED UPGRADESame toggles, three changes
NOTIF · V4
9:41▸▸▮
←Notification preferences
Channels
SMS · free 2
Push · free
1
🌐SMS languageසිංහල ▾
What to notify me about
Application updates
Status changes & requests for documents 3
Payment confirmations
Receipts & reminders
1An SMS-language row — the message arrives in the citizen's script, chosen once, changeable here.
2Free channels say so — nobody declines an update fearing a charge.
3Categories explain themselves — one plain line under each, so a toggle is never a guess.
States
Success · Question answered
The assistant answers, cites the service page, and offers the deep link — one tap from answer to action.
Assistant · Out of scope
That's beyond me — 1919 can help, or browse Services.
Honest limits, human route, never a shrug.
Lock · Wrong PIN
✗ 2 tries left — or unlock with biometrics.
Limits mirror sign-in; recovery by OTP.
GovPay · Reference not found
No bill found for TF-2026-0098 — check the number.
Typo-tolerant lookup; never a free-typed amount.
How these surfaces connect
AssistantReachable from Home's quick action and the floating button — and from any empty or error state that offers help.
LockAppears on resume after inactivity when enabled; unlocking returns exactly where the citizen left off.
Consent managerProfile → Consent; the first-run gate's choices live here, revocable with named consequences.
GovPayHome's quick action for bills and fines without an application — sharing the payment ceremony from section 07.
Part B
The resolved journey — the consent lifecycle
Consent is not a screen but a relationship: granted once, reviewable always, revocable with honesty, renewed when the terms change.
▶
First run
→
1
Grant
the gate · §02
→
2
Review
anytime
→
3
Revoke
if chosen
→
4
Re-consent
policy change
→
◼
Trust kept
2 · REVIEW
9:41▸▸▮
←Consent & data sharingv2.1
Vehicle & licence records
Dept. of Motor Traffic · Granted 12 Jan
Location (nearest office)
Off — turned off 03 Mar
Data-sharing history
14 events · latest today 09:12
›
2Review — the manager
◆ Prerequisite
Consent granted at first run (section 02's gate — optionals off until chosen). The manager shows every category with its grant date, and the ledger behind it.
Entry
Profile → Consent & data sharing
Exit
A toggle changed · the history ledger · nothing at all
✓ Success — the citizen can answer "what does the state know?"
Every category, its recipient, its date, and every actual share one tap deeper — the relationship is inspectable at will.
Revoke → consequences named before confirmingIdentity → locked, explained, never silently forced
4 · RE-CONSENT
9:41▸▸▮
Policy updatedv2.1 → v2.2
The data policy changed on 01 Aug. One thing is different:
Vehicle records — new recipient
Now also shared with provincial councils for road-tax checks
Everything else is unchanged. Your other choices stay as they are.
Review & continue
Keep vehicle records off instead
4Re-consent — only what changedConditional
◆ Prerequisite
The policy version changed. Triggered at next sign-in, before anything else; shows the diff, never the whole document again.
Entry
Sign-in after a version change
Exit
Updated choices recorded, dated, in the ledger
✓ Success — informed in one screen
The citizen sees exactly what changed and decides on that alone; declining the change is a first-class path, not a trap.
Decline → the affected category turns off, said plainlyEvery re-consent logged with its version
The lifecycle's honest shapes
GrantFirst run, optionals off — section 02's gate; choices recorded with date and version.
RevokeConsequences first — what stops working is named before the toggle moves; presentation keeps working offline.
Policy changeA diff, not a wall — re-consent covers only the change; silence never counts as agreement.
07
Apply & Track
Find a government service, apply with only the details SLUDI can't supply, pay, and leave with a tracked reference — or route to an office when that suits the citizen better.
◆ Prerequisites (journey)
A citizen has chosen a service. Signed in to submit — a guest can read the detail, then signs in at "Start" and returns to it.
Entry
Services list · Home search & featured · Assistant deep-link
Exit / expected outcome
A submitted, paid, trackable application · certificate delivered to Wallet
Part A
Approaches & rationale
The structural options considered for this journey. Service detail, the application form, and payment each carry a genuine design decision, explored below; review, confirmation and tracking follow a single settled pattern, noted at the end.
Service detail — three ways to earn the "Start" tap
The decision: inform the citizen, verify their readiness, or route them to the right channel.
V1The brief
A linear dossier — what you get, who can apply, what you'll need, how it works — then Start.
V1
9:41▸▸▮
←Birth Certificate
Birth & IdentityLKR 2003–5 days
A certified digital copy (PDF), issued by your district registrar.
Who can apply
✓ Yourself · ✓ Parent, for a child · ✓ Representative, with a letter
First-time applicants who read; anyone burned before by arriving under-prepared.
Costs
Heaviest reading load; repeat users scroll past known content.
Evidence
GOV.UK service start pages use this order and cut mid-form abandonment.
SLDS build
List Item, Button real; CONTRIBUTE a "service start page" template.
Risks
Grows ~40% taller in Sinhala/Tamil; the office row must not become a footnote.
V2Check before you start
Design logic
Error prevention as the interface — three taps verify readiness and pre-fill the form.
Serves best
Low-literacy users (tapping beats reading); the department (fewer rejected applications).
Costs
Friction for veterans (needs a skip); a question bank to author per service.
Evidence
GOV.UK "check before you start"; pre-checks cut rejection-driven support volume.
SLDS build
Segmented via TabBar, Button real; CONTRIBUTE readiness-check card.
Risks
Cap at 3–4 checks; every "No" must end in an action, never a dead end.
V3Two ways to get this
Design logic
Honest channel parity — the state's job is the outcome, so it routes rather than traps.
Serves best
Connectivity-poor citizens; elders who trust counters; urgent same-day cases.
Costs
Splits attention before the online path is sold; office data must stay fresh.
Evidence
GDS assisted-digital doctrine — never strand the offline user.
SLDS build
Accordion, Service Card real; CONTRIBUTE office card with live hours.
Risks
Stale office hours burn trust — no feed, no promise; can cannibalise online adoption.
Comparison & recommendation
Dimension
V1 · Brief
V2 · Readiness
V3 · Channels
Confidence at Start
High — informed
Highest — verified
High — self-selected
Rejection prevention
Passive
Active — before the form
Passive
Reading load
Heaviest
Lightest
Medium
Offline / assisted inclusion
One row
One row
A designed channel
Ops dependency
Static content
Question bank
Office-hours feed
Verdict
The dossier is the direction the design takes — read, understand, then one unmistakable Apply. It scales to 200+ services from a single template.
Fee and processing time sit above the fold in chips — the design's strongest trust habit, kept everywhere. The readiness interview survives as a conditional add-on for document-heavy services, and the channel study's office alternative joins the dossier as a permanent row in the upgrade below.
V3 · AS DESIGNEDFinal design — Service detail
DETAIL · V3
9:41▸▸▮
←Birth Certificate
Birth & IdentityLKR 2003–5 days
Apply online through the Dept. of the Registrar General. Your identity is pre-verified using your SLUDI Digital ID.
MINISTRYRegistrar General
PROCESSING3–5 days
FEELKR 200
TRACK ONLINEYes
Requirements
✓ Original NIC or valid passport ✓ Completed application form ✓ Two recent passport photographs ✓ Proof of current address ✓ Payment of applicable fees
Apply now
V4 · PROPOSED UPGRADESame dossier, four changes
DETAIL · V4
9:41▸▸▮
←Birth Certificate
Birth & IdentityLKR 2003–5 days
Who can apply 2
✓ Yourself (16+) · ✓ Parent, for a child · ✓ Representative, with a letter
What you'll need — this service 1
☐ Your NIC number ☐ Birth date & place (hospital or district) ☐ For a child: parent's NIC or marriage cert.
Prefer an office? DS Colombo 03 · open till 4:30 → 3
Guests sign in at Apply and return here. 4
Apply now
1Requirements become service-specific — one generic list for every service sends citizens to counters under-prepared; rejections start here.
2Eligibility up front — who can apply is the first question a family asks, answered before any effort is spent.
3The office alternative is a designed row — nearest branch and hours; the offline citizen is routed, not stranded.
4Guests are gated at Apply with return-to-intent — no walking the whole form before hitting a wall.
Application form — three containers for the same fields
The decision: what happens when life interrupts, and how much guidance each field earns.
V1Two clear pages
Who you are (SLUDI, read-only) then what you need. Two mental chapters, autosave always on.
V1 · 1/2
9:41▸▸▮
←Personal detailsSaved ✓
🔒 From your SLUDI ID — something wrong?
Nimal Kumara Perera🔒
200XXXXXXXXV🔒
Add your address
District ▾
DS div. ▾
No. 24, Galle Road
Continue — service details
V2One thing at a time
Every question its own screen, its own "why we ask", instant validation. The most guided container.
V2 · Q4/9
9:41▸▸▮
←Birth Certificate4/9 · Saved ✓
Which district do you live in?
Your certificate is issued by your district's registrar — that's why we ask.
⌕ Colombo▾
ColomboGampahaKalutara
Continue
V3Sections you tick off
The form as a place, not a corridor — four sections, any order, each showing its state. Built for interruption.
V3 · HUB
9:41▸▸▮
←Birth CertificateSaved ✓
Your application — 4 sections
✓About youfrom SLUDI
✓Your addressedit
Service details›
Documents›
Stop anytime — everything keeps. Resume from Home.
Review & submit
Rationale
V1Two clear pages
Design logic
Two mental chapters — identity (read-only from SLUDI) and intent. Fewest screens that still separate the two.
Serves best
The mainstream mid-literacy majority on adequate connections.
Costs
Long pages risk mid-page abandonment; needs an error summary plus inline marks.
Evidence
USWDS multipage guidance — group by topic, not length.
SLDS build
Input, Dropdown, ProgressBar real; CONTRIBUTE provenance field + autosave chip.
One extra layer (hub ↔ section); real completeness & per-section state engineering.
Evidence
GOV.UK task-list pattern — reserved for long, interruptible, multi-document services.
SLDS build
CONTRIBUTE task-list hub + File Upload with camera capture & pause/resume.
Risks
Section granularity 3–5; the submit lock needs a "what's left" message.
Comparison & recommendation
Dimension
V1 · Two pages
V2 · One thing
V3 · Task hub
First-timer completion
Good
Best
Good, once the hub clicks
Error-rate exposure
Page-level
Lowest — local validation
Low — short sections
Interruption resilience
Autosave, mid-page return
Resume screen
Structural — the hub is resume
Perceived length
Shortest
Longest
Honest chunks
Low-end device cost
Fewest transitions
Most transitions
Medium
Verdict
The two-page wizard with SLUDI pre-fill is the direction the design takes — and its provenance banner ("auto-filled from your SLUDI Digital ID") is the single best form idea in the app.
Two mental chapters — who you are, what you need — fit the mid-size majority of services. The one-question study survives as the treatment for the two riskiest fields (NIC entry, document photos); the task hub remains the container for document-heavy services past ~12 fields. The upgrade below hardens the wizard for patchy networks and imperfect data.
V3 · AS DESIGNEDFinal design — Application form
FORM · V3
9:41▸▸▮
←Personal details
Step 1 of 3 — Personal details
✓ Details auto-filled from your SLUDI Digital ID
Nimal Kumara Perera🔒
200XXXXXXXXV🔒
15 March 1990🔒
Home address
No. 24, Galle Road, Colombo 03
District
☏+94 77 XXX XXXX
Next — Service details
V4 · PROPOSED UPGRADESame wizard, five changes
FORM · V4
9:41▸▸▮
←Personal detailsSaved ✓ 4
✓ From your SLUDI Digital ID — something wrong?2
Nimal Kumara Perera🔒
200XXXXXXXXV🔒
Address — pick, don't type 1
Colombo ▾
Thimbirig… ▾
House no. & street
Documents — photos are fine 3
📷Take a photo of your NICor file
Next — Service details
Errors listed at the top + marked inline 5
1District / DS-division pickers replace freeform address — structured entry matches how departments file and route applications.
2A "something wrong?" path on SLUDI data — pre-filled data can be wrong; a citizen with a wrong birth date must never be stuck.
3Camera-first uploads with visible states — photographing documents is how citizens actually work; uploading, failed and too-large all show themselves.
4Autosave, said on-screen — on patchy networks, losing a half-done form is the worst failure this app can produce.
5Error summary + inline marks — page-level validation never hides below the keyboard.
Payment — three ways to close
The decision: how much ceremony money deserves, and whose wallet reality it respects.
V1Three ceremonies
Separate acts — check, choose method, watch it process, receive. Money gets full attention.
V1 · PAY
9:41▸▸▮
←Pay LKR 200.00
Birth Certificate
LKR 200.00
ref BC-2026-99201
How would you like to pay?
◉GovPay — from your bank
○Debit / credit card
○Internet banking
Pay LKR 200.00
Recorded even if the app closes
V2One last look
Answers, declaration, method and pay on one canvas — a deliberate hold-to-pay with biometric confirm.
V2
9:41▸▸▮
←Confirm & pay
Birth Certificate · 1 copy
LKR 200.00
✓I confirm this is true & complete.
◈GovPay · Commercial ••42change
◉ Hold to pay LKR 200
Fingerprint or PIN · no accidental payments
V3The commitment fork
Submit and pay are different promises — pay now, or submit now and pay within 3 days.
V3 · FORK
9:41▸▸▮
←Check & submit
Birth Certificate
LKR 200.00 · all complete ✓
✓I confirm this is true & complete.
Two ways to finish
Submit & pay now
Pay LKR 200 & submit
Submit now, pay within 3 days
Submit — pay by Mon 20 Jul
Rationale
V1Three ceremonies
Design logic
Separate acts create separate certainties — my answers are right, I chose how to pay, it went through.
Serves best
First-time payers; anyone for whom the fee is not a rounding error; phone support.
Costs
The slowest path — four surfaces for one outcome.
Evidence
GOV.UK check-your-answers is a standalone page; gateway separation is the norm.
SLDS build
Summary List, Button real; CONTRIBUTE the processing-screen pattern.
Risks
Drop-off between acts on slow devices — prefetch the payment screen.
V2One last look
Design logic
Commitment happens once — show everything at that once; one deliberate hold with biometric step-up.
A long canvas compresses gravity; editing detours through sheets.
Evidence
Checkout research — each removed step recovers completion; hold-to-confirm prevents accidents.
SLDS build
CONTRIBUTE hold-to-pay button + inline payment state machine.
Risks
Never ship the hold without step-up auth; declaration must reset after any edit.
V3The commitment fork
Design logic
Form work and fee money run out at different times — submitting free, paying flexible (3 days, 3 channels).
Serves best
Cash-flow-constrained households; counter-payment norms; the department (complete apps).
Costs
A real state machine — awaiting-payment, lapsed, revived, counter-reconciliation.
Evidence
Pay-by-reference is Sri Lankan muscle memory; court fines & university apps submit-then-pay.
SLDS build
CONTRIBUTE "awaiting payment" as a 9th status + deadline nudge.
Risks
Deadline must be forgiving — revivable in one tap; never let "pay later" read as "maybe free".
Comparison & recommendation
Dimension
V1 · Acts
V2 · Canvas
V3 · Fork
Certainty at the pay moment
Highest
High
High
Speed for repeat payers
Slowest
Fastest — one hold
Fast when paying now
Wallet-reality inclusion
Pay now or leave
Pay now or leave
3-day window, 3 channels
Accidental-payment defence
Separate screen + tap
Hold + biometric
Inherits V1/V2 surface
State-machine load
Lowest
Medium
Highest
Verdict
The amount-first sheet with three familiar methods is the direction the design takes — its fee breakdown and method clarity are exactly right for a first government payment.
What the design needs is not a different shape but a complete middle: the upgrade below adds the processing, failed and pending states with a receipt on every paid outcome. The hold-to-pay study remains the surface for repeat, form-free payments; the commitment fork joins as a conditional path where fees are heavy.
V3 · AS DESIGNEDFinal design — Payment
PAYMENT · V3
9:41▸▸▮
←Payment
Total to payLKR 200.00Birth Certificate applicationService fee LKR 200.00 · Processing Free
Select payment method
🛡
GovPay
JustPay / LankaQR
◉
▭
Debit / Credit card
Visa, Mastercard
○
⌂
Internet banking
14 supported banks
○
Pay LKR 200.00
V4 · PROPOSED UPGRADESame sheet, the middle completed
PAYMENT · V4
9:41▸▸▮
←Paymentref BC-2026-99201
Total to payLKR 200.00Service LKR 200 · Processing free
🛡
GovPay
JustPay / LankaQR
◉
◌ Talking to your bank… recorded even if the app closes. 1
✗ Didn't go through — you were NOT charged. Retry · other method 2
Bank confirmed — syncing. Don't pay again; we'll SMS the receipt. 3
▤Official receipt → Wallet · also by SMS4
Fee ≥ LKR 1,000? Submit now, pay within 3 days — here, at a counter, or by reference. 5
Pay LKR 200.00
1A real processing state — "recorded even if the app closes" removes the deepest payment fear; success is never an instant jump.
2Failure with dignity — an explicit not-charged assurance, retry and change-method paths; the application is never lost.
3Pending reconciliation handled — when the bank says paid and Sewa is still syncing, the citizen is told plainly not to pay twice.
4A receipt on every paid outcome — auto-filed to Wallet and sent by SMS; the state's proof of its own word.
5Pay-later fork for heavy fees — submit now, pay within 3 days by any channel; a LKR 10,000 application never dies on an empty wallet.
The other screens in this journey — a single settled pattern each
These screens follow a single settled pattern. The reason is noted for each.
Review & declareA check-your-answers list with per-row edit and a declaration gate. The pattern is settled; its one variable — whether editing resets the declaration — is a rule (it does), not an option.
ConfirmationThe outcome screen: reference, ready-by date, receipt filed to Wallet, and a Track button carrying that reference. One sound pattern; it is the journey's expected outcome, drawn in Part B.
Track / My applicationsA status timeline against the service SLA, with an action-needed state. The structure is settled; it reuses the 8-state status tokens already built. The list screen is drawn below.
My applications — settled structure
The tabbed list every application lands in: one sound pattern, shown as designed with its proposed refinements.
V3 · AS DESIGNEDFinal design — My applications
MY APPS · V3
9:41▸▸▮
My Applications
All
In Review
Approved
▤
Birth Certificate
BC-2026-78432 · 15 Jan
Approved
▭
NIC Renewal
NIC-2026-12345 · 20 Jan
In Review
🚗
Driving License
DL-2026-98765 · 22 Jan
Pending
▦
Vehicle Registration
VR-2026-54321 · 10 Jan
Rejected
V4 · PROPOSED UPGRADESame list, four changes
MY APPS · V4
9:41▸▸▮
My Applications
1All · 4Needs action · 1In review · 1Done · 2
3▦
Vehicle Registration — rejected
Document not legible · re-apply with a clearer scan
Re-apply
4▭
NIC Renewal
Day 6 of 14 · expected 28 Jul
In Review
▤
Birth Certificate
Certificate in Wallet
Approved
1Needs-action and rejected get filters with counts — the applications that need the citizen stop hiding behind "All".
2The status taxonomy widens — needs-action joins approved/in-review/pending/rejected, matching the tracker.
3Rejected rows carry the reason and the way back — re-apply in place, never a dead verdict.
4Rows show the day-count against the promise — "day 6 of 14" turns waiting into information.
Part B
The resolved journey
The recommended path, from opening a service to a tracked application.
▶
Start
→
1
Service detail
always
→
2
Form
if SLUDI gaps
→
3
Review
always
→
4
Payment
if fee > 0
→
5
Confirm
always
→
6
Track
after submit
→
◼
Done
1 · DETAIL
9:41▸▸▮
←Birth Certificate
LKR 2003–5 days
Certified PDF from your district registrar.
What you'll need — this service
☐ Your NIC · ☐ birth date & place ☐ For a child: parent's NIC or marriage cert.
Prefer an office? DS Colombo 03 →
Start application
1Service detail
◆ Prerequisite
A citizen has opened a service. Guests read freely and are gated at "Start" with return-to-intent.
Entry
Services list · Home · Assistant
Exit
Form — or straight to Review if SLUDI is complete
✓ Success — after "Start"
The form opens on Step 1 with SLUDI details pre-filled and the readiness answers carried in — momentum, not a blank form.
Recommended: the dossier with a readiness gate for document services.
2 · FORM
9:41▸▸▮
←Personal detailsSaved ✓
🔒 From SLUDI — something wrong?
Nimal K. Perera🔒
Add your address
District ▾
No. 24, Galle Road
Continue
2Application formConditional
◆ Prerequisite
SLUDI is missing fields this service requires. The form collects only what SLUDI can't supply. If SLUDI already holds everything, it shortens or is skipped to Review.
Entry
"Start" (authenticated, consent given)
Exit
Review, once required fields & documents are captured
✓ Success — after "Continue"
Each step confirms Saved ✓ and advances the bar; the final Continue hands off to Review. Work is never lost.
Offline → saved, uploads queueUpload too large → auto-shrinkResume → "welcome back, step 5 of 9"
Recommended container: sized to the form; NIC & document photos always single-focus.
3 · REVIEW
9:41▸▸▮
←Check your answers
Service
Birth Certificate · 1 copy
Address
No. 24 Galle Rd · Colombo
Fee
LKR 200.00
✓I confirm this is true & complete.
Continue to payment
3Review & declare
◆ Prerequisite
All required fields & documents captured (from the form, or straight from SLUDI when it was skipped). The declaration must be ticked — the gate.
Entry
Final "Continue" from the form · or a SLUDI-complete jump
Exit
Payment (fee > 0) · or Confirmation (free)
✓ Success — after "Continue"
Payment opens with the reference already reserved — the citizen sees their application is logged before paying a rupee.
Edit → jumps to field, declaration resetsFree service → payment skippedOffline → declaration blocked, saved
4 · PAY
9:41▸▸▮
←Pay LKR 200.00
LKR 200.00
ref BC-2026-99201
How would you like to pay?
◉GovPay — from your bank
○Card · banking
Pay LKR 200.00
Recorded even if the app closes
4PaymentConditional
◆ Prerequisite
The service carries a fee (> LKR 0). Free services skip this step. For fees ≥ LKR 1,000 a "submit now, pay within 3 days" fork is offered.
Entry
"Continue to payment" (declaration signed)
Exit
Confirmation · or pending/failed, application safe
✓ Success — after "Pay"
A real processing state ("recorded even if the app closes") resolves to Confirmation — never an instant jump.
Tracker (this reference) · receipt + certificate to Wallet
✓ The outcome the citizen leaves with
A reference, a promised date, a filed receipt, and a Track button — concrete and legible, not a vague "thank you".
Pay-later → "Awaiting payment · 3 days left"Receipt also by SMS
6 · TRACK
9:41▸▸▮
←Application status
Birth Certificate
BC-2026-99201 · Day 2 of 5
Progress
✓Submitted & paid
●Under review
Ready to download
6Track / My applications
◆ Prerequisite
An application exists. Reachable from Confirmation, from Home's in-progress strip, and from the Profile applications list.
Entry
"Track" · Home strip · Profile → My applications
Exit
Download certificate to Wallet when approved
✓ Success — the citizen stays informed
A timeline against the service SLA (Day 2 of 5), with SMS at each step and a download when approved.
Action needed → dept. requests a documentRejected → reason + re-applyApproved → download PDF
Recommended: status timeline on the SLDS 8-state tokens, with an action-needed state.
The same journey, three honest shapes
SLUDI complete · free serviceDetail → Review → Confirmation. Two steps skipped — a citizen whose data SLUDI holds, applying for a free certificate, is done in three taps.
SLUDI gaps · fee > 0The full journey above — the Birth Certificate case: detail → form → review → payment → confirmation → track.
SLUDI gaps · fee ≥ 1,000…Review → Payment fork (pay now / pay within 3 days) → Confirmation. High-fee services never lose a submission to an empty wallet.
08
Proposed Additions
Screens the app doesn't have yet — each one already promised elsewhere in this book: the bell that needs an inbox, the payment that files a receipt, the credential that opens a detail, the citizen who loses a SIM. Proposed as additions, never as redesigns.
◆ Prerequisites
These are new surfaces — no counterpart exists in the current wireframe. Each is drawn to the same standards and tagged as a proposal.
The pattern kit first — every other addition reuses it
08.1
Offline & error pattern kit
One shared language for the moments the network fails, data is missing, or the app needs something. The genuine decision: how the app announces being offline.
Announcing offline — three ways
The decision: one global voice, many local voices, or a quiet signal.
OPT 1Persistent banner
One global strip under the header, everywhere, until signal returns — with what still works stated plainly.
OPT 1
9:41✕ offline
SEWA
⚠ Offline — saved content shown. Your Wallet still works fully.
Good morning, Nimal
What can we help you with today?
⌕Search needs a connection
Quick actions
✎Apply
▭My Wallet ✓
◈GovPay
OPT 2Per-surface notes
No global chrome — each surface states its own capability where the citizen is looking: the catalogue says "saved", the wallet says "works".
OPT 2
9:41✕ offline
←Servicessaved copy
⌕Search offline — browse below
▤ Birth & Identity
▤
Birth Certificate
fees as of 20 Jul — may have changed
Applying needs a connection — reading doesn't.
OPT 3Status pill
A small floating pill that says "offline"; tap it for detail. Minimal chrome, maximal subtlety.
OPT 3
9:41✕
SEWA◌ Offline
Good morning, Nimal
⌕Search services…
Quick actions
✎Apply
▭My Wallet
◈GovPay
Everything looks normal until a tap fails.
Rationale
OPT 1Persistent banner
Design logic
One unmissable truth, told once, everywhere — with the positive half stated: what still works.
Serves best
Low-literacy and first-time users; anyone who would otherwise blame themselves for a dead button.
Costs
Permanent chrome on every screen while offline; can numb if it overstays.
Evidence
Persistent connectivity banners out-perform toasts for comprehension on low-end devices.
Must never block content — inform, dim, and let reading continue.
OPT 2Per-surface notes
Design logic
Truth where the eye already is — each surface declares its own offline behaviour, dated where data can stale.
Serves best
Surfaces whose offline behaviour genuinely differs — the wallet works, applying doesn't, the catalogue is a dated copy.
Costs
No single moment of realisation; every surface needs its own copy, tripled across languages.
Evidence
Capability labels beat global flags for setting expectations per task.
SLDS build
Chip/Inset Text real; capability chip CONTRIBUTE.
Risks
Alone, it makes the citizen discover offline surface by surface.
OPT 3Status pill
Design logic
Quiet chrome for the connectivity-literate — a pill in the corner, detail on demand.
Serves best
Power users who toggle networks all day and just need the flag.
Costs
Too subtle for exactly the citizens most likely to misread a failure as their own fault.
Evidence
Ambient indicators test poorly with low-digital-literacy cohorts.
SLDS build
Badge real.
Risks
"Everything looks normal until a tap fails" is the definition of a trust failure here.
Comparison & recommendation
Dimension
Opt 1 · Banner
Opt 2 · Per-surface
Opt 3 · Pill
Comprehension, low literacy
Highest
High, local
Low
Per-surface honesty
Generic
Exact
None
Chrome cost
One strip
Distributed
Minimal
Translation load
One string set
Many strings
One word
Verdict
The banner announces; the surfaces specify. One global strip states the situation and the headline capability, and surfaces whose behaviour differs add their own dated note.
The pill is declined: subtlety is a cost, not a virtue, for this population. This combination is the pattern the whole book already draws in its offline states — formalised here as the kit below.
PROPOSED DESIGN · NEWThe kit — six patterns, one language
1 · Offline banner (global)
⚠ Offline — saved content shown. Your Wallet still works fully.
Under the header, everywhere, until signal returns. Tap → "what works offline" sheet. Never blocks reading.
2 · Fetch failed + retry
Couldn't reach the Dept. of Motor Traffic.
RetryOffice / 1919
Name the department. Always a next step — retry plus a human or offline route.
3 · Partial result
✓ Revenue Licence · ✓ Emission ✕ Insurance — not found at NDX
Retry insurance only
Keep what arrived; retry item-level; say which registry answered.
4 · Empty state
▢
No applications yet. Most people start with NIC renewal →
Empty is the default, not an error: one line + one useful action.
5 · Permission primer
To photograph documents, Sewa needs the camera — only while you're using it.
AllowChoose a file
Primer before the OS prompt; an alternative always offered.
6 · Saved chip (autosave)
Saved ✓
On every form header: work is kept on the phone, said out loud. Offline, it reads "Saved on phone — syncs later."
7 · Planned maintenance
GovPay is under maintenance tonight 2–4 AM. Applications save as drafts meanwhile.
Announced ahead, scoped to the affected service, with what still works stated.
8 · Update required
This version can no longer connect safely — update to continue.
UpdateWhat changed
Wallet presentation keeps working offline even here.
1Plain words, named departments, dated data — "Couldn't reach the Dept. of Motor Traffic", never "Error 504"; a saved catalogue shows its date.
2Always a next step — every failure offers retry plus a human or offline route (1919, an office); no dead ends anywhere in the app.
3State never relies on colour — fills, outlines, icons and words carry it, in any script.
4Where each pattern lives — banner: app-wide · retry & partial: sync, payments, tracking · empty: lists and trackers · primer: camera, notifications · saved chip: every form · maintenance & update: app-wide gates.
08.2
Notifications inbox
The bell's destination. Application updates, payment confirmations, expiry reminders and policy changes land here — mirrored by SMS according to the citizen's preferences. The genuine decision: is an inbox a news feed, a case file, or a to-do list?
Three shapes for an inbox
The decision: how updates organise — by time, by matter, or by what they ask of the citizen.
OPT 1Flat feed
Reverse-chronological, unread marked, nothing clever — the shape every citizen already knows from every other app.
OPT 1
9:41▸▸▮
←NotificationsMark all read
●
Payment confirmed — LKR 200
Birth Certificate · receipt in Wallet · 09:12
●
Your application is under review
NIC Renewal · day 6 of 14 · 08:40
○
Emission certificate expires in 28 days
WP CAB-4521 · yesterday
○
Application approved
Birth Certificate · 30 Jan
OPT 2Grouped by matter
Updates cluster under the thing they concern — the citizen asks "what happened with my NIC?", not "what happened at 08:40?".
OPT 2
9:41▸▸▮
←Notifications
NIC Renewal3 updates
Under review · day 6 of 14 · 08:40
Payment confirmed · 20 Jan
Vehicle — WP CAB-45211 update
Emission cert expires in 28 days
Birth Certificate2 updates
Approved · certificate in Wallet · 30 Jan
OPT 3Actionable rows
Every notification carries its next step — the inbox reads as a to-do list, and a tap finishes the errand.
OPT 3
9:41▸▸▮
←Notifications
Clearer NIC photo requested
NIC Renewal · today
Fix
Emission cert — 28 days left
WP CAB-4521
Renew
Certificate ready
Birth Certificate
Download
Payment confirmed — LKR 200
receipt in Wallet
View
Rationale
OPT 1Flat feed
Design logic
Chronology is the simplest mental model there is — newest first, unread marked, no structure to learn.
Serves best
Everyone on day one; light users with a handful of updates a month.
Costs
A busy matter scatters across the feed; the one update that needs action drowns among confirmations.
Evidence
The default shape of every inbox the citizen already uses — zero learning cost.
SLDS build
List Item real; unread marker without colour (dot + weight).
Risks
Becomes noise without hygiene — confirmations must age out gracefully.
OPT 2Grouped by matter
Design logic
Citizens think in matters, not timestamps — the inbox as a case file, one cluster per application or vehicle.
Serves best
Multi-application households; anyone returning after a week away.
Costs
Two-level navigation; single-update matters wear heavy chrome; grouping logic must never mis-file.
Evidence
Threading beats flat feeds once volume grows — and feels bureaucratic before it does.
SLDS build
Accordion, List Item real; matter-group header CONTRIBUTE.
Risks
A mis-grouped update is worse than an ungrouped one — trust in the filing itself is at stake.
OPT 3Actionable rows
Design logic
A notification that requires something should carry its next step — the inbox becomes the shortest path to done.
Serves best
Renewals, fixes and downloads — the recurring majority of what government tells a citizen.
Costs
Buttons on every row add density; acting from a summary risks acting on stale context.
Evidence
Actionable notifications measurably lift completion — provided the action routes into the real flow.
SLDS build
List Item, Button real; actionable row CONTRIBUTE.
Risks
Nothing paid or irreversible may ever complete from a row — actions deep-link into the proper ceremony.
Comparison & recommendation
Dimension
Opt 1 · Flat
Opt 2 · Grouped
Opt 3 · Actionable
Learning cost
None
Two levels
Low
Finding a matter's story
Scattered
One cluster
Scattered
Time to action
Tap → navigate
Tap → tap → navigate
One tap, deep-linked
Low volume (year one)
Right-sized
Heavy chrome
Right-sized
High volume (year three)
Noisy
Scales best
Noisy
Verdict
A flat feed that pins what needs action — Opt 1's simplicity as the base, Opt 3's deep-linked actions on the rows that have a next step.
Year-one volume is low; chronology plus a capped "Needs action" cluster at the top covers both the news and the to-do without teaching anyone a filing system. Actions route into the proper flows — nothing paid or irreversible ever completes from a row. Matter-grouping (Opt 2) is the growth path if volume proves it, mirroring Home's attention-stack graduation.
PROPOSED DESIGN · NEWNotifications inbox
INBOX · NEW
9:41▸▸▮
←NotificationsMark all read
Needs action · 2 1
Clearer NIC photo requested
NIC Renewal · today 08:40
Fix 2
Emission cert — 28 days left
WP CAB-4521 · yesterday
Renew
Earlier
●3
Payment confirmed — LKR 200
Birth Certificate · receipt in Wallet · 09:12 4
View
○
Application approved
Birth Certificate · 30 Jan
Download
○
Consent policy updated to v2.1
Review your choices · 01 Jul
Review
Also sent by SMS · Notification preferences5
1"Needs action" pins to the top, capped at three — the to-do rises above the news; overflow rolls into the feed.
2Actions deep-link into the real flow — Fix opens the form's document step; Renew opens the renewal; nothing paid or irreversible completes from a row.
3Unread reads without colour — a filled dot and weight, legible in any script and any palette.
4Every row names its matter and time — "which application?" is never a question.
5The SMS mirror is acknowledged — and preferences are one tap away, honouring the citizen's channel choices.
STATESThe inbox when there's nothing — or no signal
Empty · All caught up
✓
You're all caught up — nothing needs you.
Calm, not congratulatory. The kit's empty-state pattern.
Notifications off
Updates about your applications will only appear here — SMS and push are off.
Turn on in preferences
States the consequence, offers the switch, never nags.
Offline
⚠ Offline — showing notifications from 08:12.
Reading works; actions that need signal queue and say so. The kit's banner + dated-data rules.
Success · After an action
Tapping Fix lands in the form's document step with the request quoted; done, the row resolves to "Photo re-submitted ✓".
08.3
Payment receipt
The proof of the state's word — promised on every paid outcome. A light decision: where does the receipt live, and what does it look like when a citizen needs to show it?
Three homes for a receipt
The decision: a formal document, an in-flow card, or a Wallet row.
OPT 1Document view
A formal receipt page — reads like the paper it replaces, with everything an auditor, employer or embassy would ask for.
OPT 1
9:41▸▸▮
←ReceiptShare
GOVPAY · OFFICIAL RECEIPT
GP-2026-40218 · 21 Jul 2026, 09:12
Paid byN. K. Perera · 200XXX•••••V
ForBirth Certificate · BC-2026-99201
ToDept. of the Registrar General
MethodGovPay · Commercial ••42
Total paidLKR 200.00 ✓
Download PDF
OPT 2In-flow card
A compact confirmation card at the end of payment — enough to trust, with the document a tap deeper.
OPT 2
9:41▸▸▮
✓
Paid LKR 200.00
▤
Receipt GP-2026-40218
filed to Wallet · sent by SMS
View
ShareDownload
OPT 3Wallet row
No dedicated surface — the receipt is a document row in the Wallet that opens the PDF. Minimal, but hides the proof.
OPT 3
9:41▸▸▮
Wallet
Documents
▤
Birth Certificate
BC-2026-78432
PDF
▤
Receipt — Birth Certificate
GP-2026-40218 · LKR 200
PDF
▤
Receipt — Traffic fine
GP-2026-40103 · LKR 2,500
PDF
Rationale
OPT 1Document view
Design logic
A receipt is shown to third parties — it should read as a document, not an app state.
Serves best
Audits, employers, embassies, disputes — the moments a receipt exists for.
Costs
A dedicated surface to maintain.
Evidence
Paper-receipt conventions carry instant legitimacy across literacy levels.
SLDS build
Document card CONTRIBUTE.
Risks
Must stay legible printed in grayscale — which this book guarantees by construction.
OPT 2In-flow card
Design logic
Right after paying, the citizen needs confidence, not paperwork — a card with the essentials and a route to the document.
Serves best
The success moment itself; section 07's confirmation already plays this role.
Costs
Not sufficient alone — the document must exist behind it.
Evidence
Confirmation-then-document is the settled pattern of banking apps.
SLDS build
Panel, Card real.
Risks
None — as the front door, not the archive.
OPT 3Wallet row
Design logic
Receipts are documents; documents live in the Wallet. Filing is the feature.
Serves best
Finding last March's receipt in one place, offline.
Costs
Alone, it buries the proof at the moment of payment.
Evidence
The Wallet is already the app's document home — consistency costs nothing.
SLDS build
List Item real.
Risks
None — as the archive, not the front door.
Comparison & recommendation
Dimension
Opt 1 · Document
Opt 2 · Card
Opt 3 · Wallet row
Third-party credibility
Highest
Low
Via the PDF
Moment-of-payment fit
Heavy
Right-sized
Hidden
Findable months later
Needs a home
No
One place, offline
Verdict
Not a competition — a chain. The confirmation card fronts it, the document view is it, the Wallet files it.
Section 07's success screen already shows the card; this screen is the document behind it, auto-filed to Wallet → Documents and reachable from success, the inbox, and history. One receipt, three doors.
PROPOSED DESIGN · NEWThe receipt document
RECEIPT · NEW
9:41▸▸▮
←ReceiptShare
GOVPAY · OFFICIAL RECEIPT
GP-2026-40218 · 21 Jul 2026, 09:12
PAID ✓
Paid byN. K. Perera · 200XXX•••••V 4
ForBirth Certificate · BC-2026-99201
ToDept. of the Registrar General
MethodGovPay · Commercial ••42
Service feeLKR 200.00
ProcessingFree
Total paidLKR 200.00
Verify this receipt — scan, or enter GP-2026-40218 at govpay.gov.lk 3
Download PDFShare
Filed in Wallet → Documents · sent by SMS 1
1Auto-filed and mirrored — every paid outcome lands here, in Wallet → Documents, and by SMS; nothing to remember to save.
2Reachable from three doors — the success screen, the notification, and payment history; one document behind all of them.
3Independently verifiable — a code and QR any third party can check against GovPay; the receipt stands without the phone that made it.
4The NIC is masked on the document — proof of payment shouldn't leak identity to whoever gets handed the paper.
STATESThe receipt under stress
Offline
Once filed, the receipt opens and shares with no signal — a Wallet document like any other.
Third-party check
GP-2026-40218 · PAID · LKR 200.00 · 21 Jul 2026
What the verification page shows — status and amount, nothing personal.
Payment reversed
⚠ Superseded — this payment was reversed on 22 Jul.
The receipt never disappears; it gains a state. Verification says the same.
08.4
Credential detail
The Wallet's tap-through — what a credential is, where it came from, and what can be done with it, with the QR an explicit choice rather than a surprise. The decision: how much surface the detail deserves.
Three surfaces for a credential
The decision: a sheet over the wallet, a page of its own, or an expansion in place.
OPT 1Bottom sheet
Slides over the Wallet — glance, act, dismiss. The wallet stays visible behind; the thumb never travels far.
OPT 1
9:41▸▸▮
Wallet
▦Revenue Licence
🚗Driving LicenceValid ✓
HolderN. K. Perera
NumberB1234567 · classes B, B1
Valid until09 May 2031
IssuerDept. of Motor Traffic · NDX
▦ Show QR
All details & history →
OPT 2Full page
A dedicated screen with everything — fields, provenance, presentation history, management. Complete, but a journey for a glance.
The wallet card opens in place — no navigation at all, but a long wallet gets longer and management doesn't fit.
OPT 3
9:41▸▸▮
Wallet
▦Revenue Licence›
🚗Driving Licence▴
B1234567 · B, B1 · until May 2031 Dept. of Motor Traffic · synced today
▦ QRMore
🛡Motor Insurance›
Rationale
OPT 1Bottom sheet
Design logic
The common case is a glance and one action — a sheet keeps the wallet in view and the thumb in place.
Serves best
Pre-stop checks ("is it valid?"), quick QR, quick renew.
Costs
Not enough room for history and management without scrolling the sheet.
Evidence
The mobile-native pattern for peek-and-act; SLDS names the Bottom Sheet its primary mobile overlay.
SLDS build
Bottom Sheet spec; credential summary CONTRIBUTE.
Risks
Sheets must be dismissible by swipe and back alike.
OPT 2Full page
Design logic
A credential is a legal object — a page gives provenance, history and management their own room.
Serves best
Disputes ("here's my log"), re-syncs, removals, understanding what this thing is.
Costs
A full navigation for what is usually a two-second glance.
Evidence
Detail pages are where audit trails live in every document system.
SLDS build
List Item, Badge real; presentation-history list CONTRIBUTE.
Risks
Remove must confirm and explain the re-add path.
OPT 3Expanding card
Design logic
Zero navigation — the card is the detail. Honest for small wallets.
Serves best
Wallets with two or three credentials, rarely managed.
Costs
Long wallets get longer; history and management still need somewhere else to live.
Evidence
Accordion detail works until content outgrows the row — which credentials do.
SLDS build
Accordion real.
Risks
Half a detail in the card plus half elsewhere is the worst of both.
Comparison & recommendation
Dimension
Opt 1 · Sheet
Opt 2 · Page
Opt 3 · Expanding
Glance-and-act speed
Fastest
Slowest
Fast
Room for history & management
Scrolls
Complete
Doesn't fit
Context kept
Wallet visible
Lost
Inline
Scales with wallet size
Yes
Yes
No
Verdict
Sheet first, page behind — the sheet answers the glance, "All details & history" opens the full page for provenance and management.
This is the same shape the rest of the app uses: the quick surface for the common case, the complete surface one honest tap deeper. The expanding card is declined — credentials outgrow rows. The wallet's v4 rule holds: the QR is always an explicit button, never a surprise.
PROPOSED DESIGN · NEWThe credential sheet
CREDENTIAL · NEW
9:41▸▸▮
Wallet
▦Revenue Licence
🚗Driving LicenceValid ✓ 2
HolderN. K. Perera
NumberB1234567 · classes B, B1
Valid until09 May 2031
IssuerDept. of Motor Traffic · synced today 3
▦ Show QR 1
History 4All details →
1The QR is an explicit button — presenting is a choice; the wallet's tap-to-QR surprise is retired.
2The status badge carries the expiry state — Valid, expiring-soon with a Renew primary, or expired with the QR disabled and the reason shown.
3Provenance on the glance surface — issuer and last-synced tell the citizen this is alive, not a screenshot.
4History and management one tap deeper — the full page holds the presentation log, re-sync and a confirmed remove with its re-add path.
STATESThe sheet under stress
Expiring soon
28 daysRenew becomes the primary; QR stays available.
Renew now
Expired
Expired 14 Aug — presenting is disabled until renewed.
The QR button is replaced by the renewal path; never a dead code.
Sync stale
Last synced 34 days ago — refresh from Motor Traffic?
Stale provenance invites a re-sync; offline presentation still works.
Remove
Remove from this phone? You can re-add it anytime by re-syncing.
Confirmed, reversible, explained.
08.5
Account recovery
The day the phone is stolen, the SIM changes, or the number moves on — and the OTP that guards everything can no longer arrive. A full journey, because losing access to government must never mean losing government. The decision: who does the recovering.
Three ways back in
The decision: the citizen recovers alone, a human recovers with them, or the app tries first and hands over when it must.
OPT 1Self-serve
The citizen re-proves identity on the new device — NIC plus SLUDI biometric — and confirms a new number. No queue, no call.
OPT 1
9:41▸▸▮
←Recover your account
Prove it's you — without the old number
Step 1 · Your NIC
▤200XXXXXXXXV or 902345678V
Step 2 · SLUDI biometric
🛡 Fingerprint or face — checked against your SLUDI record, not this phone.
Verify with SLUDI
OPT 2Assisted
Recovery is a human matter — call 1919 or visit an office with the NIC; staff verify and reset. Slow, but nobody is left behind.
OPT 2
9:41▸▸▮
←Recover your account
Let's do this together
☏
Call 1919
Free · Sinhala, Tamil, English · verify by questions + NIC
⌂
Visit any DS office
Bring your NIC · reset on the spot
Your account stays locked until recovery completes.
OPT 3Hybrid
Self-serve first — SLUDI biometric where it can carry the proof — with the assisted door always on screen for everyone it can't.
OPT 3
9:41▸▸▮
←Can't sign in?
🛡
Recover with SLUDI
NIC + fingerprint or face · about 3 minutes
›
☏
Get help — 1919 or an office
If biometrics aren't possible for you
›
Either way: old sessions end, and we notify your old number and email that recovery happened.
Rationale
OPT 1Self-serve
Design logic
The identity anchor is national, not the SIM — SLUDI's biometric can vouch for a citizen on any device.
Serves best
The common case: new phone or new number, same person, working biometrics.
Costs
Excludes citizens whose biometrics fail or who never enrolled; a fraud target if step-up is weak.
Evidence
Aadhaar-style biometric recovery works precisely because identity outlives the device.
SLDS build
Recovery flow CONTRIBUTE.
Risks
Biometric failure needs a dignified exit, not a dead end.
OPT 2Assisted
Design logic
Account loss is stressful and rare — a human can weigh evidence no form can.
Serves best
Citizens without biometrics, disputed identities, fraud victims.
Costs
Queues and hours for everyone, including the 90% the app could have served in minutes.
Evidence
Every national system keeps a human recovery channel — as the floor, not the path.
SLDS build
List Item real; office locator ties to the help hub.
Risks
If this is the only path, recovery becomes a day's leave from work.
OPT 3Hybrid
Design logic
Serve the common case in minutes; keep the human door on the same screen for everyone else. Notify the old channels either way.
Serves best
Everyone — by routing, not by compromise.
Costs
Two paths to build and audit; risk rules to define (what forces the assisted path).
Evidence
Tiered recovery is the settled pattern where stakes and populations vary this widely.
SLDS build
Recovery flow + risk step-up CONTRIBUTE.
Risks
The self-serve door must never quietly swallow the cases that needed a human.
Comparison & recommendation
Dimension
Opt 1 · Self-serve
Opt 2 · Assisted
Opt 3 · Hybrid
Time to recover (common case)
Minutes
Hours–days
Minutes
Nobody excluded
Biometrics required
Fully inclusive
Fully inclusive
Fraud resistance
Biometric + step-up
Human judgement
Risk-routed
Operational load
Lowest
Highest
Low — humans get the hard cases
Verdict
Hybrid — SLUDI-backed self-serve as the fast lane, the human door always on the same screen, and risk rules that force step-up when too much changes at once.
A new number on a known device flows through in minutes; a new number AND a new device demands the biometric plus a waiting period or the assisted path. Recovery always ends old sessions and notifies the old channels — the rightful owner must always find out.
PROPOSED DESIGN · NEWThe recovery journey
▶
Can't sign in
→
1
Choose a path
always
→
2
Prove identity
NIC + SLUDI
→
3
New number
if changed
→
4
Security review
always
→
◼
Signed in
2 · Prove identity
▤NIC — old or new format
🛡 SLUDI biometric — checked against the national record, not this phone.
Fails twice → the assisted door, pre-filled with what's already verified.
3 · Confirm the new number
☏+94 7X XXX XXXX
OTP to the new number proves possession; the old number is notified that it's being replaced.
4 · Security review
✓ All old sessions ended ✓ Old number & email notified ✓ New device bound · PIN reset
Wallet credentials re-sync; nothing was lost with the phone.
The honest shapes of losing access
New phone · same numberLightest: sign in by OTP on the new device, biometric confirms, wallet re-syncs. Minutes.
Same phone · new numberSteps 2–3: biometric proves the person, OTP proves the new SIM. The old number is notified.
New phone · new numberEverything changed: biometric + a 24-hour hold with notifications to old channels — or the assisted path, immediately.
No biometrics possibleAssisted from the start: 1919 or any DS office with the NIC — the same outcome, a human carrying the judgement.
08.6
Data-sharing history
The ledger behind the consent manager's promise that "every share is logged" — a settled structure: one chronological ledger, filterable, in plain language. No exploration needed; the design decision was made when consent was.
PROPOSED DESIGN · NEWThe ledger
HISTORY · NEW
9:41▸▸▮
←Data-sharing history
AllMotor TrafficSLUDIGovPay
Licence status → verifying officer
Because you presented your DL · today 21:12
Payment record → GovPay
Because you paid LKR 200 · today 09:12
Vehicle records ← Dept. of Motor Traffic
Because you synced your wallet · 12 Jan
Identity verified → SLUDI
Because you signed in · 12 Jan
Only you see this list · Export · Something looks wrong?
2Each entry names its trigger in plain words — "because you presented your DL", never a system code.
3"Something looks wrong?" is a real path — an entry the citizen doesn't recognise routes to 1919 and the data-protection officer.
4Exportable, and only the citizen's — the ledger leaves with them on request; nobody else browses it.
STATESThe ledger's edges
Empty
Nothing shared yet — entries appear the first time your data moves, starting with sign-in.
Reporting an entry
Don't recognise "Licence status → officer, 21:12"?
One tap opens a report with the entry attached — to 1919 and the PDPA officer.
Offline
⚠ Offline — ledger as of 08:12.
Readable offline; new entries sync with signal.
08.7
Help & support hub
The destination behind every "Get help" in the book — a settled structure with one rule: the human route leads, and it works even when the app barely does.
PROPOSED DESIGN · NEWThe hub
HELP · NEW
9:41▸▸▮
←Help & support
☏
Call 1919
Government Information Centre · free · සිංහල · தமிழ் · English
Call 1
⌂
Nearest office
DS Colombo 03 · 2.1 km · open till 4:30 2
›
💬
Ask the assistant
Instant answers · any language
›
?
Common questions
By journey — applying, paying, wallet, sign-in
›
⚑
Report a problem
Creates a tracked ticket · reply by SMS 3
›
About Sewa · v1.0.3 · Terms · Privacy
11919 leads, as a working call button — the human route is the hub's headline, not its footnote, in all three languages.
2The office locator shows dated hours — from an owned data feed; no feed, no promise.
3Problems become tracked tickets — with a reference and an SMS reply, not a message into the void.
4Every dead "Support" tap in the app now lands here — Home's quick action, Profile's row, the assistant's handoff.
STATESHelp when things are worst
Offline
⚠ Offline — you can still call.
1919 and office addresses are cached; the phone dialler needs no data.
Assistant handoff
When the assistant reaches its limits it lands here — with the conversation's context attached to the ticket, so the citizen never repeats themselves.
Ticket resolved
✓ SUP-2026-0142 resolved — "photo upload fixed".
Closure is told, not assumed — by SMS and in the inbox.
08.8
SLUDI data correction
The flow behind every "Something wrong? Report it": when the state's record of a citizen is wrong, fixing it must be as designed as using it. A tracked correction request, with the citizen's work never held hostage to the error.
▶
Wrong data
→
1
Report the field
from any pre-fill
→
2
Evidence
photo of proof
→
3
Tracked request
SLUDI reviews
→
◼
Corrected
PROPOSED DESIGN · NEWReport the field
CORRECTION · 1
9:41▸▸▮
←Report incorrect data
Which detail is wrong?
Date of birth▾
SLUDI currently has
15 March 1990
What it should be
15 March 1991
Proof — a photo is fine
📷Photograph your birth certificate
Send to SLUDI
1Reachable from every pre-filled field — the "something wrong?" link lands here with the field and current value already selected.
2Evidence is a photo, coached by the kit — the same camera-first upload with legibility help.
3Corrections are SLUDI's to make — Sewa carries the request and the tracking; the identity registry stays the single source of truth.
PROPOSED DESIGN · NEWThe tracked request
CORRECTION · 2
9:41▸▸▮
←Correction requestIn review
Request
Date of birth · SC-2026-0871
Sent 21 Jul · SLUDI reviews in 5–7 days
While this is reviewed
Your applications can continue — this field carries a "correction pending" note the department can see.
Progress
✓ Received · ● Under review · ○ Decision
You'll be told by SMS and in the inbox either way
4Work is never held hostage — applications continue with a visible "correction pending" flag instead of freezing the citizen.
5The outcome closes the loop — accepted: the record updates everywhere at once; declined: the reason and an escalation path (1919, PDPA officer).
08.9
Edit contact details
The destination behind Profile's edit button — the calm, signed-in way to change a mobile number or email, cousin to account recovery but without the crisis.
PROPOSED DESIGN · NEWChange mobile number
CONTACT · NEW
9:41▸▸▮
←Edit contact details
Mobile number — used for sign-in
+94 77 XXX XXXX
current · verified
☏New number · +94 7X XXX XXXX
We'll text a code to the new number, and tell the old one about the change.
1The new number proves itself by OTP — possession verified before anything changes; sign-in moves with it.
2The old number is told — a change notification with a "wasn't you? call 1919" line; hijacks never happen silently.
3Signed-in and calm — no biometric ceremony needed here; the crisis path (no access at all) is account recovery, 08.5.
STATESEdges
Code to the new number
The same six-cell code screen as sign-in — cooldown, lockout and all. One pattern everywhere.
Number already in use
This number is linked to another Sewa account.
Routes to recovery or 1919 — never merges silently.
08.10
Close my Sewa account
The right to leave, honestly designed: what closing removes, what it cannot, and a ceremony that respects the decision without trapping or shaming.
PROPOSED DESIGN · NEWWhat closing means
CLOSE · NEW
9:41▸▸▮
←Close my account
What closing removes
✓ This Sewa account and its sign-in ✓ Credentials stored on this phone ✓ Notification and consent choices
What it cannot remove
Your civil records — birth, licence, vehicle — live with their departments and SLUDI, not in Sewa. Applications already submitted continue with those departments.
Take your data first: export your data-sharing history and receipts.
Export my data first
Close my account
1Honest scope, stated first — the account closes; the state's records don't pretend to vanish. No false promise of erasure.
2Export offered before the door — history and receipts leave with the citizen, per their data rights.
3The ceremony is real — PIN or biometric confirms, a 7-day undo window follows, and reopening later re-verifies through SLUDI as ever.
4No guilt trips — one confirmation, no discount-style retention screens; leaving a government app must be as dignified as joining it.
STATESEdges
Open applications exist
2 applications are still in progress — closing won't cancel them.
Updates continue by SMS to the registered number.
Within the undo window
Signing in within 7 days restores everything as it was — said on the closing screen, honoured on return.
08.11
Mini-app data access
Sewa hosts services that behave like small apps of their own — GovPay, fuel quota, and the departmental mini-apps to come. The first time one opens, it must ask for exactly the data it needs, and the grant must live where all consent lives.
PROPOSED DESIGN · NEWFirst-open access sheet
MINI-APP · NEW
9:41▸▸▮
Fuel Quota
⛽Opening…
⛽
Fuel Quota wants access
Ministry of Energy · first time opening
✓Your vehicle registrations
✓Fuel credential status
Nothing else — not your NIC number, not your applications, not your location.
Allow & open
Not now
Change anytime in Profile → Consent → Mini-apps
1Scoped to exactly what's needed — the sheet lists the data, names the owner ministry, and says what is NOT included.
2Asked at first open, not at install — the request arrives with its context; "Not now" closes the mini-app without penalty.
3Grants live with all other consent — a Mini-apps group in the consent manager, each grant dated, revocable, and visible in the data-sharing ledger.
4Scope changes re-ask — a mini-app that later wants more data triggers the same sheet showing only the difference, like the policy re-consent.
STATESEdges
Declined
The mini-app closes with a plain line — "Fuel Quota needs vehicle access to work" — and the tile stays available for another day.
Revoked later
Access revoked — Fuel Quota will ask again next time it opens.
From the consent manager's Mini-apps group.
In the ledger
"Vehicle registrations → Fuel Quota · because you opened it · 21 Jul" — every mini-app read is an entry like any other.