Tour leader app
The tour leader (group leader / mutawwif) who travels with a departure opens the ERP on their phone and sees only the groups they lead: who is on the trip, which room they are in, what happens today, and a way to record who is here. Nothing about money.
Routes: /field, /field/groups/:id, /field/groups/:id/check-in, gated on field.view
and field.checkin. Own shell, no sidebar.
The same screens exist in the native app (the tour leader's stack), which adds two things the web field app does not have: Live — where the travellers who switched location sharing on are — and the departure's Programme with notices. A leader may use either; check-ins recorded on one are seen on the other.
Rules: 14 · Field operations (FLD-001 … FLD-006).
1. Who is a tour leader
Anyone the office appoints on a departure: an employee, a business partner's login or a
traveller's (FLD-007). The appointment gives
the login the TOUR_LEADER role and nothing else; the role holds field.view and
field.checkin only, so a leader cannot open any staff page, and a leader reads no User
row but their own. A partner who leads stays a partner; a traveller who leads stays a
traveller (their own booking and the trip screens are unchanged, and Groups I lead
appears in the native app). An employee keeps their own bundle.
A staff or invited leader signs in on the staff page (/auth) with their username or email
and lands on /field; a partner or traveller signs in where they always do.
A leader sees a group when the operations desk appoints them on it: Groups → the group →
Overview → Tour Leader (groups.edit) — search a name, phone, email or agency, appoint;
Dismiss takes them off and removes the role when they lead no other group. One group has
one tour leader; one leader can have several groups. The list shows departures from two
weeks before return onward. The person is told in their inbox each time.
2. What a leader sees
My groups — each departure with its dates, the head-count, and the last check-in (and who was missing at it).
One group — four tabs:
- People — every active traveller: name, category, passport number, booking number, the room they are in today, whether they are the group's leader, any traveller state from an incident (hospitalised, missing). A phone button dials the traveller, or the booking's contact when the traveller has no phone of their own. A traveller whose booking declined location sharing is marked.
- Rooms — each hotel with its dates, and who is in which room.
- Plan — the itinerary the office entered: flights, transfers, the programme's activities (INV-008), hotels, with today highlighted.
- Log — the check-ins recorded so far, newest first, and any waiting on this phone to be sent.
- SOS — the operations desk (call, WhatsApp) and, for every traveller, the emergency contact recorded on their booking (INC-005), with a call button. Bookings without one are flagged so the desk can add it.
Prices, payments, other groups and the rest of the ERP are not there.
3. Recording a check-in
Record a check-in on the group page. Choose what it is (daily headcount, airport arrival, flight boarded, hotel check-in, bus boarding, ziyarat departure or return, hotel check-out, return flight, other) and where. Everyone starts as present; tap a name to mark them missing. Attach my location takes the phone's own position at that moment (the leader may skip it). Save.
Check-ins are optional (FLD-002): nobody chases a leader for one. Every one recorded is kept and shown to the office.
Missing travellers are named on the group's Overview tab (Groups page) and in the traveller's Customer 360 "where they are today" panel. A work-inbox item for a missing traveller is not built; the desk reads the group card.
4. Without signal
The last group list and the last manifest opened stay on the phone, so the app opens without a connection. A check-in saved without signal goes into the phone's outbox with the time it was saved, the header shows how many are waiting, and they are sent as soon as the connection is back (or when the leader taps the badge). A check-in that was sent but whose answer never came back is sent again and stored once (FLD-004).
Install the app from the browser's Add to Home screen for the full-screen version, or install the Android app, which opens the same site.
5. Consent (FLD-005) and live location (FLD-006)
The location on a check-in is the leader's phone's, at that moment; a check-in never
reads a pilgrim's phone. At booking, the staff wizard and the partner portal ask whether the
travellers agree that the leader's location may be kept with their check-ins; the booking
page shows the answer and lets staff with bookings.edit change it. Presence is counted
either way — that is duty of care — but without consent no location is attached to the
traveller, and Customer 360 says so.
Separately, since 2026-09-25 a traveller may switch on live sharing of their own position
in the native app (FLD-006). Only the
traveller's own login can switch it on, only for their own booking, and it is stored only
while the booking is travelling (two days before departure to the day after return): one row
per person, overwritten, deleted the moment they switch off. The leader sees those travellers
on the Live tab of the native app (fld_group_locations) — on a map (OpenStreetMap in a
WebView; there is no Google Maps key) with the leader's own phone as a blue pin and a position
older than ten minutes in grey, and as a list with distance, bearing, battery and
Open in Maps for directions; staff with groups.view see the same on the group's screen
in the app. The positions go only into that map on the leader's phone. Details and the
OpenStreetMap terms: Native app → The map. The web field
app does not show them. The privacy page (§10) explains both to customers.
6. Not built
- Reporting an incident from the app; the leader calls the desk (the SOS tab), the desk records it.
- Live positions and the programme on the web field app; they are in the native app only.
- A push or work-inbox alert for a missing traveller.
- Health and insurance details on the manifest (HLT-002, HLT-003).
- "Remember this device": the leader signs in like any staff member, with the authenticator step if they have one.