Viaggianow Product Tour

Viaggianow · AI Marketing Manager · Product tour, 27 August 2026

A marketing department that asks permission.

Sixteen specialist AI agents plan, write and measure the marketing for a travel agency — and not one of them can spend a euro, publish a post or answer a customer until a person says yes.

Live at viaggianow.site · 9 languages · 14 markets · MVP deployed AI model key pending
Screens
35
routes, role-gated
API endpoints
120
every one RBAC-checked
AI agents
16
9 wired, 7 awaiting scope
Automated tests
1,300+
domain, integration, UI, E2E
Languages
9
incl. Arabic, right-to-left
Data entities
39
38 migrations

What it is for

A travel agency running campaigns across Italy, Egypt, Germany and the Gulf needs a marketing team it cannot afford: someone to plan campaigns, write posts in nine languages, buy ads, chase leads, watch reviews, and explain last week's numbers.

Viaggianow is that team, as software. The manager states an objective; specialist agents produce structured, sourced work; and every action with consequences — money, publishing, messaging a customer — stops at an approval queue until a human decides.

The product is not the content generation. Anything can generate content. The product is the gate, the audit trail, and the refusal to state a price or an availability the system has not actually looked up.

Instead of
An agency retainer
Fixed monthly cost, slow turnaround, no audit of what was decided or why.
Instead of
A generic AI writer
No approval gate, no spend ceiling, no record, and happy to invent a price.
Instead of
Six separate SaaS tools
Ads, email, social, CRM and reviews each with their own login and their own truth.
Viaggianow
One desk
One queue to approve, one trail to answer for, one place the numbers agree.

The mechanism everything else is built around

Nothing with consequences happens without a person

This is a real sequence, so it is numbered. Each step is enforced in the API, not in the interface — a caller with a valid token and the wrong approval still gets a 403.

01 Agent produces

A specialist returns structured output — a campaign plan, ad copy, a reply draft — with its sources attached.

02 Request is raised

Anything that spends, publishes, sends or answers publicly becomes an approval request, bundled by intent.

03 The gate

ApprovalGateMiddleware refuses the action at the API. Unknown state fails closed: a campaign with no budget row is refused, not treated as zero.

04 Human decides

Approve, or request revision with a reason. The Chief Agent regenerates against that reason.

05 Trail is written

Who, what, when, which agent, which automation rule. Append-only, and it outlives everything else.

The exception is explicit, bounded and auditable

An Owner may switch on an automation rule to skip the queue for a narrow case — activating a campaign under a budget cap, say. Those rules carry a hard ceiling in a stated currency (an exchange rate inside a safety limit makes the limit soft, and a stale one makes it wrong), cannot be activated without a ceiling if they commit spend, cannot have that ceiling raised while live, and every bypass they perform is written to the same trail with the rule’s own id attached.

The morning view

Executive dashboard & daily plan

Opens on what needs a decision today, not on a wall of charts. Every KPI tile carries its own provenance badge, and a tile only reads LIVE when every metric behind it is live — blended ROAS stays MOCK when it divides live revenue by mock spend.

That rule exists because a dashboard which rounds “partly real” up to “real” is worse than one that says nothing at all.

viaggianow.site/dashboard
Good morning, Owner Generate AI plan
Impressions128,400mock
Clicks4,870mock
Revenue€38,210mock
Blended ROAS3.1×mock
Today’s plan
6 items waiting for your approval action needed
Reputation: 1 review escalated as urgent urgent
Summer Egypt campaign ends in 3 days ending

Every figure is labelled mock because no analytics provider is connected yet. The badge comes from whichever adapter answered, not from a hand-typed string.

Approval Center

The queue the whole product exists to feed. Items arrive bundled by intent — a campaign plan and the six ads it implies are one decision, not seven.

Requesting a revision is a first-class action carrying a written reason, because “no” without a reason produces the same output again.

Decided items stay visible behind a toggle. Hiding them would make the screen disagree with the audit trail that still names them.

viaggianow.site/approvals
Approval Center Show decided
ItemTypeRaised by
Estate in Costiera 2026
Go live · €4,000 cap
campaign Chief Agent Approve
3 posts · Sharm el-Sheikh
IT, DE, AR
content Copywriting Approve
Reply to 1★ review
safety complaint · escalated
urgent Reputation Review
Newsletter · September
2,140 consented contacts
email Email Agent Revise

Journey #1 of the vision document, covered end to end by Playwright against the real stack.

Ask the AI Manager

The Chief Agent answers in the manager’s own words — “why did bookings drop this week?” — by calling the Analytics Agent and reporting what it found.

The answer separates measured data from hypothesis and labels which is which, cites the campaigns and channels it used, and offers the next action as a button that still goes through the approval queue.

An agent may only state figures a tool call returned. Anything else is marked a draft or an estimate and is blocked from every publishing path.

viaggianow.site/chat
Chief Marketing Agentgpt-off ยท key pending
Why did bookings decrease this week?
measured Bookings fell 18% week-on-week (142 → 116). The drop is concentrated in Paid Search · Germany, where spend was paused on Tuesday after the budget cap was reached. hypothesis The Egypt campaign’s creative has been live 34 days; click-through has declined each week since day 21, which is consistent with fatigue but I have not tested it.
Raise budget +€500 — needs approval Refresh creative
Sources: Campaign #418, Channel Paid Search, Metric rows 12–18 Aug · mock provider

Structure, sourcing and the approval button are shipped and tested. The language itself needs an Anthropic__ApiKey — see “what is honestly not done” below.

Doing the work

Six working areas, each a real screen against a real database.

Campaigns & the builder wizard

Destination, audience, markets, channels, budget — then Generate strategy. Paid Ads, Copywriting and Creative return one structured plan that lands in the queue as a single bundled request.

A campaign moves through a real state machine: Draft → Pending → Approved → Active → Completed. Stopping is never behind an approval — you can always halt spending immediately; only starting it needs a yes.

Spend is derived from metric rows rather than typed in, so the budget bar cannot quietly disagree with the numbers underneath it.

viaggianow.site/campaigns
Campaigns+ New campaign
Name ↓MarketObjectiveStatusBudget
Estate in Costiera 2026ItalyBookingsactive1,840 / 4,000
Sharm Winter SunGermanyAwarenesspending0 / 2,500
عروض البحر الأحمرEgyptLeadsactive920 / 1,500
Winterreise nach ÄgyptenAustriaBookingsdraft
Sorted by name · every column header sorts, and paging keeps the sort

Sorting reaches all seven list screens and carries a unique tiebreaker, so paging a tied column never repeats or drops a row.

Leads, scored and explained

A board by pipeline stage, with a score band on each card. The score is an additive rule over five factors, not a calibrated probability — so the detail page shows the whole sentence that produced it, never a bare 0–100.

Companies can be created inline from the lead form: the need appears halfway through typing, and navigating away to satisfy it would discard the half-entered form. Typing a name that already exists selects the existing row instead of creating a twin.

viaggianow.site/leads
Leads+ New lead
New · 4
Giulia Rossi Siwa Desert Expeditions score 82
Karim Adel Website form score 41
Contacted · 2
Lena Fischer Meta lead form unscored
Qualified · 1
Marco Bianchi €6,200 opportunity score 91
“Unscored” is a real state — the engine declines to guess below its evidence floor.

Consent status is a first-class field on every contact, and opt-out is enforced in the send layer rather than in the interface.

Nine languages, localised rather than translated

English, Italian, German, Spanish, French, Portuguese, Russian, Chinese and Arabic. Arabic flips the entire interface to right-to-left — navigation, icons, tables and the sidebar transform — because a translated string in a left-to-right shell is not a localised product.

Content is generated per market, not translated from an English original. A German winter-sun ad and an Egyptian one are different arguments, not the same sentence twice.

viaggianow.site/dashboard · ar
صباح الخير إنشاء خطة
المشاهدات128,400
النقرات4,870
الإيرادات€38,210
خطة اليوم 6 عناصر تنتظر موافقتك

The same components, mirrored. Layout uses logical properties throughout, so direction is a data change rather than a second stylesheet.

Every screen in the product

Thirty-five routes, each behind a role check enforced at the API. This is the complete list — nothing here is planned or partial unless it says so.

Executive dashboard

/dashboard

KPI tiles with per-metric provenance, daily plan, alert feed.

Getting started

/getting-started

In-app onboarding that states known gaps rather than hiding them.

Approval Center

/approvals

The queue. Approve, or request revision with a reason.

AI Chat

/chat

Chief Agent, conversation history, sourced answers, inline actions.

Campaigns

/campaigns

List, detail, state machine, derived spend against budget.

Campaign builder

/campaigns/new

Wizard that emits one bundled strategy request.

Advertising

/advertising

Ads by campaign and channel, with platform publish state.

Ad editor

/advertising/:id/edit

Headline, body, creative, daily budget, approval state.

Creative concepts

/creatives

Concepts kept as words about a picture, not fabricated images.

Content calendar

/content/calendar

Scheduled posts by channel and market, colour-coded.

Content editor

/content/:id/edit

Per-market, per-language items with A/B variant groups.

Leads board

/leads

Pipeline stages, score bands, inline company creation.

Lead detail

/leads/:id

Opportunities, activities, the full scoring explanation.

Do Not Contact

/suppressions

The suppression register, searchable and demonstrable.

Reputation

/reputation

Reviews, deterministic triage, escalation, draft replies.

Performance

/performance

Campaign ROAS, anomalies, budget advice, each able to say “I don’t know”.

Reports

/reports

Daily snapshots, comparisons, CSV/PDF export, scheduled delivery.

Agents

/agents

The roster, per-agent cost, task history, reachability.

Prompt templates

/agents/:id/prompts

Versioned prompts in the database, never hardcoded.

Brand guidelines

/brand-guidelines

Brand memory the agents retrieve from before writing.

Integrations

/integrations

Nine providers, credential vault, connection probe, sync.

Automation

/automation

Rules with hard ceilings and their bypass history.

Markets

/markets

Countries and languages the agency actually sells to.

Users

/users

Invite, assign roles, deactivate — enforced at three points.

Security

/security

Two-factor enrolment, recovery codes, session policy.

Audit log

/audit-log

Append-only trail of every AI action and human decision.

The sixteen agents

All sixteen are built, registered and contract-conformant — a shared test suite enforces the same shape on every one. Nine are reachable from a real trigger today. The other seven are a product decision, not a missing feature.

Reachable — a real user action creates work for these

ChiefwiredOrchestrates the rest; answers in chat.
CopywritingwiredAd and post copy, per market.
Content StrategywiredCalendar and themes.
Social MediawiredChannel-shaped posts.
Paid AdvertisingwiredBudget split and targeting.
CreativewiredConcepts as briefs, not images.
EmailwiredNewsletters and sequences.
AnalyticswiredReads numbers, refuses to invent them.
ReputationwiredTriage, escalation, reply drafts.

Built and waiting for a trigger the business has not chosen yet

SEOawaiting scope
Lead Generationawaiting scope
WhatsAppawaiting scope
Competitor Intelawaiting scope
Conversion Rateawaiting scope
Video & Reelsawaiting scope
Influencerawaiting scope

Why those seven are deliberately not switched on

Wiring them would take an afternoon and would be the wrong call. The vision names all sixteen but specifies a trigger for none of them, and they appear in none of the user journeys. Connecting them to entry points nobody asked for would be a product built by whoever was nearest the keyboard. A test pins the current state, so each agent must either be reachable or carry a written note saying what it is waiting for — the gap cannot widen quietly.

The question for the business is which of the seven it actually wants, and what should set each one going. That is a conversation, and it is a short one.

What it is built on

Backend .NET 10 Clean Architecture across Domain, Application, Infrastructure and API. CQRS over a message bus with a Postgres outbox, so a command and its side effects commit together.
Frontend Angular 22 Zoneless, signal-based, standalone components. Tailwind 4 on the product’s own token layer, with a 44px touch minimum keyed to pointer type rather than screen width.
Data Postgres + pgvector 39 entities, 38 reversible migrations, soft delete, and vector search backing the brand memory the agents retrieve from.
Security 17 policies JWT with a 15-minute access token, refresh in an HttpOnly cookie, optional two-factor, rate-limited sign-in, and a strict Content-Security-Policy that blocks inline script outright.
Operations Live on a VPS Docker Compose behind Caddy with automatic TLS and six-month HSTS. Verified backups run six-hourly and are pulled off the box automatically.
Observability Traces & metrics Self-hosted OpenTelemetry collector into Tempo and Prometheus, with Grafana over both and an alert when the API returns server errors.
IntegrationStateWhat that means
Meta Marketinglive adapter, offReads spend and performance. Read-only by construction — it has no way to create or fund anything.
Google Analytics 4 + Search Consolelive adapter, offSwitches on with one setting. Needs a service account granted Viewer on the property.
Google Adslive adapter, offCreates campaigns paused, under a daily ceiling, behind the approval gate.
SendGrid emaillive adapter, offConsent and suppression are enforced above the adapter, so no adapter can bypass them.
WhatsApp, CRM, payments, socialmockMock adapters with the same contract, so swapping one in changes configuration, not code.
Booking engineblockedThe revenue source of truth. Needs the vendor named before an adapter can exist.

Nothing is claimed live without a tested credential. With no configuration every provider reports Mock, and a test asserts exactly that, so real traffic cannot appear unnoticed.

What is honestly not done

Stated plainly, because a demo that hides this is a demo that breaks in the room.

Blocking the headline claim No AI model key The orchestration, dispatch, cost tracking, prompt versioning and refusal rules are all real and tested — against a deterministic stub. No agent has met a live model. One API key changes that with no code change; until then the AI in “AI Marketing Manager” is unproven.
Blocking real numbers No connected analytics Every metric on every screen is mock and labelled mock. The live GA4 adapter exists and has never spoken to a real property. It needs a Google service account with Viewer access.
Blocking attribution No booking engine Revenue attribution is modelled and tested, but the source of truth is a vendor that has not been named. Writing an adapter for an unnamed vendor means inventing its payloads.
Also outstanding Alert delivery The 5xx alert fires and routes correctly; it reaches SMTP and stops at authentication. One credential finishes it.
Also outstanding CI has never run The pipeline is written but GitHub Actions billing is unpaid, so it has never executed a step. Tests run locally instead.
Acceptance criteria 9 of 10 met The one unmet criterion is the AI answer quality, for the reason above. Everything else — auth, RBAC, workflows, approvals, provenance, tests, secrets, docs — is verified.

The horizon

What comes after the MVP

Four stages, in the order they unblock each other. This is a sequence, so it is numbered — stage 2 is worth little until stage 1 lands.

01

Switch on what is already built days, not weeks

Nothing here needs new code. Every item is a credential or a decision, and each one converts work already paid for into working software.

  • An AI model key — turns sixteen tested agents from plumbing into a product, and closes the last acceptance criterion.
  • A Google service account — replaces every mock badge on the dashboard with real traffic, spend and search data.
  • Meta and Google Ads credentials — live ad performance, and create-as-paused publishing behind the gate.
  • A SendGrid key — sends the newsletters and scheduled reports, and finishes the production alert.
  • Name the booking vendor — unblocks revenue attribution, which is what makes ROAS mean anything.
  • Choose which of the seven idle agents you want, and what should trigger each.
02

Make the daily work fast next

The MVP proved the workflows are correct. This stage is about the twentieth time someone does them, not the first.

  • Sorting — shipped, on all seven list screens.
  • Global search — one box that finds a campaign, a lead, a review or an ad without knowing which screen owns it.
  • Bulk actions — approve six items in one decision instead of six; retire a whole campaign’s ads together.
  • Saved views and filters — the manager’s Monday view is not the same as the sales handler’s.
  • Surface or delete the orphaned endpoints — four API routes have no screen; each should get one or go.
  • Alert delivery and a dashboard — finish the notification path and put the five engines on one operational page.
03

Close the loop from spend to booking the real prize

Everything so far tells you what was published and what it cost. This stage tells you what it earned — and lets the system act on that with a ceiling.

  • Revenue attribution end to end — booking engine to campaign to channel, counting explicitly the revenue it cannot explain rather than silently assigning it.
  • Budget reallocation proposals — move money toward what is converting, raised as an approval request with the evidence attached.
  • Creative fatigue detection — flag an ad whose click-through has decayed past its own baseline, and brief a replacement.
  • WhatsApp sequences — the highest-intent channel for this market, gated by consent at the send layer like every other.
  • Competitor monitoring — treated as untrusted text, sanitised before an agent ever reads it.
04

From one agency to many the business question

The architecture already assumes a single tenant carefully enough that multi-tenancy is an addition rather than a rewrite.

  • Multi-tenancy — row-level isolation per agency, with the audit trail and approval gate unchanged.
  • White-label — the token layer already drives every colour and control; branding becomes configuration.
  • Agency-of-agencies — a marketing consultancy running Viaggianow across a portfolio of travel clients.
  • Vertical templates — the domain model is travel-shaped, but the gate, the trail and the agent runtime are not. Hospitality and events are the nearest neighbours.
  • A published API — 120 endpoints already exist behind one authorization model; opening a subset is a policy decision.

Why this is worth continuing

The hard part of an AI product is not generating text. It is being trusted with the consequences — and trust is made of unglamorous things: a gate that fails closed, a ceiling that cannot be raised while live, a badge that admits when a number is fake, an agent that says “I don’t know” rather than guessing.

Those are built, tested and deployed. They are also the parts nobody builds after the fact, because retrofitting an approval gate into a system that has been publishing for six months means auditing everything it already did.

What remains is mostly credentials and product decisions, not engineering. That is an unusually good position to be in.

DefensibleThe trailEvery AI action and human decision, append-only. For a regulated conversation about consent or a disputed spend, this is the answer.
DefensibleThe refusalsFive separate engines can return “insufficient evidence”. Systems that cannot say that produce confident nonsense.
LeverageNine languagesLocalised, not translated, with a real RTL implementation. Most competitors in this segment ship English and a translation layer.
LeverageSwap-in adaptersEvery provider sits behind one contract with a conformance test. Adding a platform is configuration plus an adapter, never a refactor.

The one honest caveat for anyone evaluating this

Judge it on the workflow, the safety model and the engineering — those are demonstrable today at viaggianow.site. Do not yet judge it on the quality of AI output, because no agent has spoken to a real model. That is one key away, and it is the first thing to fix; but until it is fixed, anyone claiming the AI is proven would be overselling it.