Most frontend work is forgiving: a wrong render is a refresh away. These surfaces are different. A duplicated withdrawal is money gone; a session that expires mid-transfer is a user who does not know if they paid; a KYC flow that loses a photo is a customer who gives up. The user is anxious, the action is irreversible, and the regulator is watching, and the design has to hold all three at once.
Nine parts, each a surface: why these are different, authentication from sessions to passkeys and the UX of being locked out, KYC journeys that must be resumable, deposits and withdrawals with idempotency and reconciliation, wallets with display versus authorising balances, trading UIs with confirmations and degraded states, portfolios and statements that must be correct under reload, the catalogue of edge cases every money screen must survive, and the client half of the ledger the Core Banking module built.
consequenceWhat makes money, identity and trust surfaces different: irreversibility, regulation, and the user's state of mind.
authenticationSessions, tokens, refresh, MFA, device trust, passkeys, and the UX of recovery and lockout.
KYCDocument capture, liveness, review states, rejection with a path back, resumability across days.
money movementDeposits and withdrawals: pending states, idempotent submission, optimistic updates with reconciliation, receipts.
balancesDisplay versus authorising balances, holds, currency exponents, integer money, real-time updates that do not lie.
trading and portfolioOrder entry and confirmation, price fidelity, degraded modes; statements and exports that are correct under reload.
the catalogueOffline, timeout, partial success, duplicate submit, stale data, session expiry mid-flow: every case with its design.
the ledgerHow double-entry, idempotency keys, holds and event sourcing from the Core Banking module appear on screen.
Paired with the Core Banking moduleThe Core Banking Architecture module built the ledger: double-entry, idempotency, holds, event sourcing, reconciliation. This course is the other end of the same guarantees: what the user sees, taps and trusts. Part 8 maps them directly.