Age brackets designed
0–12 · 13–17 · 18+
Core flows mapped
Group Plan + Invite/Share
Surfaces covered
Owner app · Member app · Admin web
Approach
No research phase - flow reasoning in-tool







Owner
Runs the plan
Adds members, uploads consent documents, sets what each member can see or do, and watches requests move from draft → pending → active.
Member / Dependent
Lives inside the plan
Access changes automatically as they age - from a fully owner-managed profile at 6, to a self-logging-in teen at 15, to a fully independent account at 18.
Viewer / Caregiver
Sees only what's shared
An outside person - a grandparent, a co-parent, a nurse — invited in and given a hand-picked slice of health information, revocable at any time.
4.User Flows
01
Add Member
Owner enters a name, email and date of birth from the Group Plan screen.
02
Age is detected
The DOB silently routes the member into one of three consent paths.
03
Add as Dependent
Owner confirms the relationship and chooses to link the member as a dependent profile.
04
Submit for Review
Signed and documented, the profile is sent to the admin team for verification.
Age 0–12
ID proof + legal custody questions + guardian signature required. Profile stays in Pending until an admin verifies the documents. Rejections come with a reason and allow resubmission.
Age 13–17
Lighter acknowledgment, no custody questions. An email becomes mandatory the moment they turn 13, so they can start logging into their own account.
Age 18
Added as an independent member from day one - they get their own login and full control the moment they accept.
Edge case I designed for:
members age out. Turning 13 triggers an optional email prompt; turning 18 auto-converts a dependent into an independent account, with a "Happy Birthday" screen that hands them full ownership of their own profile - no owner action required.
Group dashboard onboarding
First-run welcome screen leading into the owner's home dashboard.


Group Plan overview
Seats used, plan renewal date, and every member's status in one place.


Per-member permission controls
Owner toggles exactly what each member can access - login, records, wearables, sensitive-data visibility - module by module.


01
Add Profile
Member chooses to invite a viewer or request to become a medical proxy for someone else.
02
Invite Viewer
Name, email, relationship, and an explicit trust confirmation before anything is sent.
03
Accept or Decline
The invitee sees the request under "Linked Profiles" and chooses to accept.
04
Share Access
The member then hand-picks exactly which records, reminders and documents the viewer can see.
The detail I cared about most:
sharing isn't all-or-nothing. Every category - reminders, medications, appointments, questionnaires, wearables, legal documents - opens into its own item-level picker. Before anything is confirmed, a warning screen calls out if the selection includes mental health, HIV/STI, genetic or child-confidentiality data, so nothing sensitive gets shared by accident.
Later refinement pass:
I revisited this flow to make the shared records feel real rather than abstract - swapping empty placeholder boxes for actual document thumbnail previews, and replacing initials with real profile photos across every screen, so the flow reads as a finished product rather than a wireframe.
Share Access with Viewer
Category-level sharing that drills into item-level selection for full control.


Select Records
Drilling into "Records" - each report is its own checkbox, with document previews and status tags like Lab Report or Extraction failed.


Manage Shared Items
Everything currently shared, grouped by category and date, editable at any time.


A reusable permissions model
Edge cases designed up front
















