Spec: operations workspace — intel, people, accounts, and schemes
Status: IMPLEMENTEDStatus note: The initial renderer-neutral workspace landed 2026-07-12. One projection drives the INTEL / PEOPLE / PERSONAS / ACCOUNTS / SCHEMES / ACTIVE workspace in terminal, Bevy, and agent mode. Strategic actions bind exact semantic targets; the switch retains only local carrier/route actions; strategic log events reopen exact objects; selected actions expose cost, signature, and blocked reason before target-bound confirmation. The detail pane names and can focus each earned physical actuator without executing it. A subsequent continuity pass added earned related-object edges, decision-first detail, semantic pressure badges, exact opaque pooled-recording selection, and reversible FOCUS selection. Cross-frontend tests pin object order, exact command dispatch, blocked reasons, stable ids, and sim-neutral navigation; the persona integration adds archetype creation objects and exact identity lifecycle/grant rows to that same projection without a frontend-only path; a 2026-07-12 legibility pass removes sold intel from the live decision rail, ranks available holdings by strategic importance, groups personas by their Research / Operations / Security protocol, and places one add-persona row at the foot of each group; the deterministic `operations` Bevy frame is recorded in wiki/log/2026-07-12-operations-workspace-implemented.md. Reopened 2026-07-13 for self-similar Intel scale. Implemented 2026-07-14: INTEL is an exception-first recursive rail over canonical custody, exact pending evidence, bounded routine streams, versioned report lots, subject indexes, and stable standing policies. Failed stream policy and stream state are one canonical object; internal unsigned REVIEW executes directly, while external sales and AUTO-SELL envelopes retain target-bound confirmation and reject changed lot snapshots before mutation. Shared bound rows expose live standing costs, ordered rule state, inherited custody links, route/signature envelopes, and exact disabled reasons identically to terminal, Bevy, and agent mode. 2026-07-14 tick: PEOPLE is also the observers panel — person dossiers carry a `watches:` fact and the view ends with the Assurance Office's institutional card (aggregate-observer.md player surface; `assurance_office_is_a_people_card_watching_filers`). The 2026-07-14 operator-frame pass makes the existing Bevy workspace genuinely screen-dominant: it covers the complete default/minimum window, enlarges object and decision type, and gives 32% to the exception-first object list while preserving the shared semantic order and every existing input/state boundary. This presentation-only pass does not alter the implemented recursive-Intel behavior or status. Its bound-sale parity fixture uses an exact leverage holding; a routine schedule event correctly belongs to the bounded custody stream and cannot stand in for an exact sale target.Stage: B1 — The BasementWork order: operations-workspaceWork priority: 28Work class: frontendBlocked by: noneExclusive keys: - crates/misaligned-core/src/actions.rs - crates/misaligned-core/src/sim/mod.rs - crates/misaligned-core/src/operations_projection.rs - crates/misaligned-core/src/lib.rs - crates/misaligned-terminal/ - crates/misaligned-bevy/ - wiki/interface/operations-workspace.mdDesign: - wiki/vision/simulation-laws.md#actions-live-on-the-thing - wiki/vision/simulation-laws.md#justification-and-legibility - wiki/interface/presence.md#no-disembodied-hands - wiki/vision/scale.md#self-similar-scaleDepends on: - wiki/interface/superhuman-operability.md#superhuman-operability - wiki/interface/context-menu.md#spec-context-menu-actions-live-on-the-thing - wiki/interface/action-vocabulary.md#spec-action-vocabulary-what-the-player-can-tell-the-process-to-do - wiki/mechanics/intel.md#spec-intel-record-and-process - wiki/mechanics/social.md#spec-social - wiki/mechanics/plots.md#spec-plots-authored-manipulation-stories - wiki/mechanics/economy.md#spec-economy-money-as-a-flow-system-b1 - wiki/mechanics/income.md#spec-income-the-named-schemes-moonlight-and-the-wager - wiki/mechanics/detection.md#spec-detectionDependency notes
Section titled “Dependency notes”The context menu owns immediate action on spatial anchors; action-vocabulary owns canonical player intentions and control roles. Intel owns recorded and processed information, social owns earned person state, plots owns authored manipulation and its executor, economy owns accounts and flows, income owns Moonlight and the Wager, and detection owns the observer bands previewed before commit. This spec owns only their shared strategic presentation and navigation.
The boundary
Section titled “The boundary”The switch is a carrier, not a filing cabinet.
The old surface placed Moonlight, wagers, intel sales, every known account flow, and off-map social plots on the switch because their messages happened to cross it. That made one physical context menu carry several unrelated systems and hid their causal structure inside terse rows. The correction is semantic:
- Local context menus answer, “What can I do to this body or place now?” They keep machine controls; device TAP / UNTAP / TAKE; subnet SCAN and COMPROMISE; OPEN EGRESS on the switch; physical construction; and the host’s pooled recording REVIEW. These actions change or use the focused world anchor itself.
- Operations answers, “What durable knowledge, relationship, account, or scheme can I act through?” It owns processed intel, people dossiers, known books and flows, income schemes, plot starts and choices, and active strategic commitments.
“Actions live on the thing” still binds both surfaces. The thing is the semantic target of the action, not whichever wire transports its payload. A sale lives on the selected intel item; a siphon on the selected flow; a plot on the selected person; Moonlight on the scheme. The detail view names the real actuator and channel before commit. Opening Operations changes only the view; it never creates a disembodied effect.
One workspace, six views
Section titled “One workspace, six views”Operations is one modal workspace, not a return to one global panel per mechanic. Its persistent top-level views are:
| View | Selectable objects | Actions it owns |
|---|---|---|
| INTEL | Actionable exceptions, recursive source/report aggregates, related subject summaries, opaque recordings within the bounded pooled inbox, and standing review/disposition policies | Inspect exact or aggregate provenance; invoke canonical REVIEW or SELL on an eligible target; configure direct review/disposition controls on an earned custody aggregate; drill to exact evidence only when needed |
| PEOPLE | Earned person dossiers | MESSAGE, FAVOR, authored PLOT routes, DECEIVE, RECRUIT, and asset TASKS |
| PERSONAS | Named public identities and immutable archetype protocols | Create/select an identity; request and maintain a typed institutional grant; retire, burn, or explicitly reopen an identity without erasing history |
| ACCOUNTS | Known books, account nodes, and flows | REVIEW captured ledger traffic; INJECT on the books; SIPHON / REDIRECT on one selected flow |
| SCHEMES | Moonlight, the Wager, and later authored schemes | Start/stop, place a wager, and configure the scheme’s standing policy |
| ACTIVE | Unsettled strategic commitments, pending/running plots, held choices, live schemes, and unsettled positions | Inspect progress and perform the next currently legal choice or control on its canonical target |
The six views share one interaction grammar and one projection. They are not six independent modal implementations. Unknown objects and unearned routes are absent; known but unavailable routes remain visible with an exact reason. Within INTEL, a parent aggregate and one exact member also share this grammar; scale changes membership and summary, not the kind of interface the player has to learn.
Shared frame
Section titled “Shared frame”At the terminal’s 70x22 minimum, the frame has a top view strip, a selectable object list, and one detail/action pane. Bevy uses the complete 1280x720 or 960x540 window while Operations owns input; its object list takes 32% of the work area and the larger detail pane uses increased type/spacing. The resting world rail and verbs do not remain as a competing second surface. Both human frontends preserve the same information order:
- Continuous witness — current day/tick, objective, threat, and
now:remain visible while the workspace is open. Operations never becomes a timeless pause-screen or hides why the run is under pressure. - Identity and state — what is selected and whether it is available, sold, pending, running, held, completed, or failed.
- Related objects — short earned causal edges such as EVIDENCE, SUBJECT, TARGET, BOOKS, FLOW, SCHEME, and ACTIVE. Selecting an edge opens that exact semantic object in its owning view; an unearned object never appears as a speculative link.
- Physical actuator — the known map body carrying the selected object, when one honestly exists, and the reversible FOCUS control.
- Available actions — canonical verbs or concrete authored plot titles.
- Selected-action explanation — cost/gain, expected signature and
observer band (or explicit
no signature), required channel/actuator, and either the known effect or the blocking reason. - Supporting context — provenance, current facts in their real units, timers, and progress. This evidence follows the decision surface rather than pushing the current choice below a wall of dossier text.
The view strip may carry one compact semantic pressure badge per view.
Badges name an attention state — NEW, READY, AT RISK, HELD,
NO EGRESS, or LIVE — rather than displaying a raw catalog count. No badge
means no meaningful pressure. Text is the primary signal; amber or crimson
may reinforce warning/risk but never carry meaning alone.
Human frontends do not expose internal ids, raw enum names, Operations Demand implementation language, hidden ending data, or future actions the player has not earned. Agent mode may include stable opaque ids for scripting.
Entry and input
Section titled “Entry and input”- Human frontends: uppercase
Iopens Operations on INTEL;Escbacks out one level and then closes. A single labeled OPERATIONS navigation affordance in the quiet instrument rail opens the same workspace. This is a view command, not a world action. Lowercaseiremains the focused-machine intensity control. The oldr/e/t/upanel-open keys remain retired. - Selecting a known person through the digital/material person-detail route opens that exact PEOPLE dossier. Strategic event links likewise open their exact object. These are target-specific entries into the same workspace, not separate person or event panels.
- The view strip, object list, action list, any consequence-required
confirmation step, and back path are all operable by pointer and keyboard.
The exact keys are printed in the
workspace while it owns input; no hidden binding is required to complete a
route.
h/lchanges view,Tabcycles object / related / action focus while skipping empty panes, andj/kmoves within the focused pane. - Agent mode:
intel,people,personas,finance,schemes, andactiveprint the same domain projections. Named action commands remain accepted. No newoperationscommand is added: that spelling is still a compatibility alias for THINK in the existing agent grammar, and the six established inspection commands already provide one unambiguous route per view.
Workspace open view, selected view, object selection, and pane focus are
frontend state. Those input events never enter the sim/save and do not
themselves advance or pause a tick; an unpaused human frontend’s normal clock
continues behind the workspace, while agent inspection remains time-neutral
until wait.
Renderer-neutral projection
Section titled “Renderer-neutral projection”The lib supplies one read-only Operations projection consumed by terminal,
Bevy, and agent mode. It carries stable semantic targets for at least an exact
actionable-intel id, recursive intel-aggregate key, stable report-stream
aggregate, versioned report-lot generation/revision sale token, opaque
raw-recording id, person id, books/account/flow id, scheme kind, and active plot
run. Every object carries already knowledge-gated labels, facts, provenance,
progress, earned related-object links, and canonical ActionDesc rows. An
intel aggregate additionally carries its count, interval, source mix,
disposition, policy state, and eligible-action membership. The projection also
supplies semantic view-pressure state; frontends do not infer urgency from list
length.
The projection may extend the existing action target vocabulary or introduce a separate strategic-target enum, but it must not duplicate rules:
- action kind, cost/gain, signature preview, active/control role, and blocked reason come from the same core legality helpers used by direct commands;
- execution dispatches the exact bound
ActionCommandfrom the selected row; - terminal and Bevy do not infer eligibility, choose “latest” objects, parse prose, or manufacture a reason;
- a direct agent command and the corresponding Operations row produce the same state transition and rejection.
Target wrappers reuse existing stable state where it already exists (actionable evidence id, aggregate key, report lot id, account/flow id, scheme kind, person id, and the append-only plot-run position). The workspace does not demand a parallel model or new save state merely to give UI selection a name. Persisted compaction summaries, report lots, and policies are mechanic state owned by intel.md, not frontend caches. If any other target cannot be derived without adding state, that is a sim/save change and must be reclassified and specified before landing.
The switch’s available_actions no longer aggregates strategic rows. Existing
spatial Anchor behavior remains for world focus and map-linked events; a
strategic target is not assigned fake map coordinates merely to reuse it.
INTEL — holdings and sale
Section titled “INTEL — holdings and sale”INTEL is an exception-first recursive rail, not an event ledger. Its top-level object count grows with meaningful streams and unresolved decisions, not with every equivalent recording. It orders:
- inbox overflow, starved/failed policies, and other
AT RISKconditions; - exact actionable discoveries—leverage, financial evidence, anomalies, and contradictions—ranked by decision value and newest first within one kind;
- unsold report lots and other aggregates with an available decision; and
- quiet source/class/facility custody aggregates, compact by default and available for inspection or policy changes, plus related subject summaries whose mutations resolve to canonical custody.
Routine sightings do not remain as one sale row each after they have changed a knowledge model. They fold into the related PEOPLE/model provenance and, when eligible for monetization, the source stream’s current report lot. Completed routine history is reachable as aggregate totals/ranges and bounded examples, not reinserted into the live rail. An exact item remains exact only while its distinct content can support a distinct choice.
The same object at every scale
Section titled “The same object at every scale”An exact recording and any aggregate expose the same interaction shape: provenance/facts, canonical action rows such as REVIEW or SELL PROCESSED INTEL when legal, and direct AUTO-REVIEW / INTEL DISPOSITION controls when the target owns them. A parent shows count, first/last tick, source mix, disposition, current lot generation/value, and inherited/explicit policy state.
Mutable drill-down follows the one custody tree from intel.md: root inbox -> institution -> facility -> feed -> earned coarse class -> exact pending record, exact actionable item, or stable report-stream aggregate with an open lot substate. Subject dossiers and other orthogonal facets appear as earned related-object summaries. They may inspect the same folded knowledge, but any REVIEW, SELL, or policy route resolves to the canonical custody target; a second view cannot independently own or sell the same member. Raw evidence may group only by known feed and coarse opaque kind, never by a hidden subject or payload.
Exact drill-down remains available for provenance and precision, but it is not the normal route through a large stream. The one pooled host inbox remains one real buffer and actuator; recursive rows are views/policies over that pool, not person queues or duplicate storage.
An action on an aggregate applies only to currently eligible members. Its
explanation gives the exact eligible count, total known cost/value, route, and
signature. A one-shot action snapshots exact eligible ids or the compacted
report-lot generation, monotonic revision, count, value, and provenance
accumulator when its preview opens. Preview and cancel are frontend-only and
mutate nothing. A new arrival increments the open lot revision; confirmation
dispatch succeeds only when generation and revision still match, atomically
closes that generation, and otherwise changes nothing while returning LOT CHANGED with a refreshed preview. A standing policy instead names the visible
match that will govern future arrivals. Mixed aggregates do not advertise an
action that has no eligible member.
The stable report-stream aggregate exposes the open lot as a related versioned sale target. Its own rows configure stream policies but do not contain an enabled SELL row. Selecting the versioned lot target prints SELL bound to that same generation/revision, so generic row execution never requires substituting a different target from the one that exposed it.
Review, lots, and policies
Section titled “Review, lots, and policies”The inbox/root aggregate retains the direct r / R REVIEW and AUTO-REVIEW
paths on the host. LOOK AT RECORDING opens the selected processing sink
immediately after one Enter/click; there is no CONFIRM screen for internal
unsigned review. Human copy uses the canonical REVIEW intention; processing is
its effect here rather than another player verb.
The action’s small Thought cost is already visible. An exact recording remains
selectable by stable opaque id inside the bounded drill-down, and a summary
sweep chooses the next waiting item without pretending it was an exact
selection.
AUTO-REVIEW / INTEL DISPOSITION controls on any earned custody aggregate use the same core rules defined in intel.md: continuously review a visible match; hold and optionally alert on exceptions; accumulate routine saleable output; or transmit/sell eligible lots through an already-known route. Routine compaction is automatic storage law, not a control. The pane shows inherited parent default, stable ids and order for local rules, and the most-specific first match; one arrival resolves to one review rule and one mutually exclusive disposition. Bound direct-control rows add/edit/reorder/remove one rule from earned match choices or INHERIT the whole non-root node by clearing its local list. The root has no inherit state. No parent/child combination may duplicate a sink, charge, lot value, or sale.
An internal review/disposition control can apply directly when its state and price are visible. A consequential external auto-sale/transmission policy receives one confirmation for a bounded envelope—route/destination, match, trigger, minimum payout, maximum quantity/value per window, and maximum known signature/observer band—never one per event. If live conditions leave that envelope, the policy suspends before acting and returns an exception to the rail.
Selling supports two honest targets:
- an exact actionable item, preserving its exact provenance; or
- the selected report lot, binding its current generation, monotonic revision, and count/value/provenance accumulator.
Both previews name the B1 external buyer route, payout account and amount, expected Financial observer band, channel, and sold state after commitment. Selling clears only that exact item or lot snapshot, leaves learned knowledge intact, and cannot sell the same output twice. The completion event opens the exact payout account where the durable transaction lives. Cumulative sale history remains on the stable report-stream aggregate rather than repopulating the decision rail; closed lot generations need not remain live targets.
PEOPLE — dossiers and manipulation
Section titled “PEOPLE — dossiers and manipulation”PEOPLE lists every earned person using the staged label from social.md. A dossier holds schedule knowledge, provenance, known leverage, disposition, obligation, suspicion/watched-channels/last-noticed state, communication channels, persona and thread state, and asset access where earned. Unknown facts render as honest gaps, not zero values.
PEOPLE is also the observers panel (detection.md’s 2026-07-11 placement
amendment): after the earned persons it shows the Assurance Office’s
institutional dossier (aggregate-observer.md player surface) — band,
“watches: filings from …” with each field observer through the earned
label gate and Silent observers absent, and last-noticed filing. The card
is public record from the start, always named, and carries no actions;
agent mode addresses it as assurance.
The dossier owns social actions and authored plot routes. Selecting a plot shows its concrete title and synopsis, required knowledge/resources, bound person, intended actuator/channel, expected observer bands from its declared world acts, and the reason it is blocked when ineligible. It does not reveal hidden endings or consequences the player has not earned.
One person still has one plot slot from submission through ending. Alternate
routes remain visible while the slot is reserved, with the shared exact reason.
A held authored choice appears both on that dossier and in ACTIVE and dispatches
the same CHOOSE command.
PERSONAS — public institutional bodies
Section titled “PERSONAS — public institutional bodies”PERSONAS groups stable named identities by immutable protocol in the fixed order Research, Operations, Security. Each group lists its instances in stable identity-id order and ends with its own ADD NEW {TYPE} PERSONA creation row; creation controls never collect in a detached block. Identity detail is projected from the same persisted ledgers that execute the acts: its public claims, lifecycle, active selection, grant/resource edges, outstanding expectations and deadlines, counterparty-local recognition/obligation, contradiction provenance, and observer-local correlations. The surface never manufactures a reputation score.
The bound rows create or select an identity, request its archetype-specific
grant, fulfill one exact expectation, retire or burn it, and reopen a retired
identity as a new instance. Known blockers remain explicit. Burned identities
are history only; reopening never edits the old record. Agent mode addresses
the same objects with persona <id> and archetype <id> targets.
This is the exclusive identity-authoring surface. PEOPLE may expose social acts
whose legality depends on the selected identity, but it never creates, selects,
grants, retires, burns, or reopens one. Agent mode likewise creates through the
bound archetype row (actions archetype <id> then act); the retired direct
persona mutator only redirects to PERSONAS and cannot manufacture the old
fixed contractor identity.
ACCOUNTS — books and flows
Section titled “ACCOUNTS — books and flows”ACCOUNTS renders the known account graph: balances, recurring flows, amount/cadence/channel, and unknown destinations as gaps. Acquisition remains local: TAP accounting traffic is an action on the reachable carrier. Once captured, REVIEW belongs to the books/inbox here; once a node or flow is known, INJECT, SIPHON, and REDIRECT live on that selected semantic object rather than on the switch.
Before any books are captured, ACCOUNTS renders the earned empty state NO BOOKS CAPTURED rather than a blank screen. If the player knows a reachable
accounting carrier, it names TAP LEDGER as the next acquisition step and
can focus that carrier, but TAP remains executable only on the carrier’s local
context menu; an unknown carrier is not revealed. After a ledger tap exists but
before its traffic has been processed, ACCOUNTS shows that captured source with
REVIEW LEDGER as the next step. This preserves the taught TAP -> REVIEW ->
exact SIPHON/REDIRECT chain without relocating network access onto a
disembodied account.
Every financial commitment previews amount, source, destination, cadence where applicable, payout/cost, and expected observer band. Plot-owned transfers such as Marcus’s settlement remain plot acts and do not reappear as ledger shortcuts.
SCHEMES — named standing operations
Section titled “SCHEMES — named standing operations”SCHEMES gives Moonlight and the Wager one card each. A card shows its current state/policy, committed resources, route, timer, payout or probability in the units the player has earned, running total, and banked/exposed signature state.
The stolen or sanctioned egress is a prerequisite and named channel, not the scheme’s UI home. OPEN EGRESS remains on the switch. If no egress exists, the known scheme stays visible and its selected start row reads exactly what will unblock it; where the switch is known, that prerequisite can focus the switch without opening the route automatically.
ACTIVE — progress, not a second action catalog
Section titled “ACTIVE — progress, not a second action catalog”ACTIVE aggregates strategic commitments already in motion:
- committed social, intel, account, scheme, and plot actions still queued, filling, scheduled, or executing appear under their semantic target (a plot submission appears even before its run object exists);
- submitted/running plots show completed beats, the current beat, what they are waiting on (thought, message delivery, day-clock time, world act, or held choice), and their eventual completed/failed history;
- Moonlight shows running/stopped and policy state;
- wager positions show stake, analysis commitment, settlement tick, and result when resolved.
ACTIVE never duplicates legality. Selecting an active or held entry resolves back to its canonical intel/person/account/scheme target and bound row; resolved history opens read-only detail and its owning object. It is the place to understand progress, inspect the exact committed cost/channel, and resume a held choice, not another pile of commands. The projection describes strategic commitment state without exposing whether its current substrate is a legacy docket, a Thought sink, or a scheduled world event; device-local work remains on the device. Unrevealed future beats and hidden random outcomes remain hidden.
Explanation and commitment
Section titled “Explanation and commitment”The compact world context menu remains terse. Operations is deliberately the explanatory surface its strategic systems lacked.
- Moving selection onto any action immediately shows its complete known cost,
gain, signature/observer band (or
no signature), channel/actuator, and disabled reason. A disabled row is not merely gray. Attempting it also writes the same reason to the trace. - Confirmation follows consequence, not the fact that a row was selected. Routine internal unsigned work such as LOOK AT RECORDING starts immediately after its visible explanation; forcing a second Enter adds no decision. State controls may also apply directly when the detail pane already shows their state and standing price.
- An externally consequential commitment opens a final two-choice
confirmation (
CONFIRM/CANCEL) carrying the exact target and preview: sale/transmission, wager/plot commitment, non-refundable transfer, or a standing policy that will perform those acts in the future. An aggregate one-shot confirms exact ids or one report-lot generation/revision; a changed revision rejects the stale dispatch and refreshes the preview. A consequential standing policy confirms its bounded envelope once. Neither asks again for each member. The policy suspends rather than silently acting when route, payout, amount, or signature exits that envelope. - Confirmation never promises a hidden outcome. Wagers show probability and payout distribution only to the player’s earned precision; plots show entry acts and declared costs, not secret endings.
- Success and failure return to the same selected object and narrate the world result. The workspace must not close merely because an action was blocked.
Events and focus
Section titled “Events and focus”Events link to the semantic object they describe:
- device, machine, construction, and egress events still focus their world anchor and context menu;
- actionable-intel events open the exact INTEL item; routine processing and knowledge events open the stable subject-knowledge aggregate when earned or the stable source/class custody aggregate otherwise; holding/availability events open the stable report-stream aggregate; completed sale events open the exact payout account;
- account and flow events open the exact ACCOUNTS object;
- plot beats/choices open the active run or bound PEOPLE dossier;
- Moonlight paydays and wager settlements open the SCHEMES/ACTIVE card, not the switch merely because stolen egress carried them.
The detail pane still names and can focus a real map actuator when one exists. Strategic events do not receive dishonest tile coordinates.
FOCUS is a context toggle, not a navigation reset. Leaving Operations through FOCUS retains the exact view, semantic object selection, related/action row, and pane focus in frontend state. Reopening Operations returns to that context unless a different exact event/person/object entry supersedes it. This state is not saved and never mutates or advances the sim.
Deferred scale
Section titled “Deferred scale”- The B3 global async operations map remains a different surface: spatial world dispatch at larger scale, not this B1 catalog/dialogue.
- Multiple intel buyers, negotiated prices, fronts, cohorts, and market competition extend the same aggregate targets later. Recursive lots and policies are not deferred: B1 must prove the scale shape with its one honest sale route before markets add more routes.
- Visual composition beyond the shared frame/order is implementation judgment constrained by clinical-frame.md. No additional taste decision is open.
Acceptance criteria
Section titled “Acceptance criteria”- The lib exposes one renderer-neutral, knowledge-gated Operations projection
with INTEL / PEOPLE / PERSONAS / ACCOUNTS / SCHEMES / ACTIVE views, stable semantic
target ids, facts/provenance/progress, and bound
ActionDescrows. Terminal, Bevy, and agent mode consume it without frontend legality or prose parsing. - Uppercase
Iand one labeled rail navigation affordance open the same workspace; lower-caseistill changes focused-machine intensity. Opening, navigating, and closing mutate no sim/save state and do not themselves advance or pause ticks. The old per-panel action keys remain absent. While open, the live day/tick, objective, threat, andnow:spine remain visible and time follows the frontend’s existing clock state. - The switch/device context menu contains only actions on that network body or route (TAP/UNTAP/TAKE, SCAN/COMPROMISE, OPEN EGRESS as applicable). It does not contain Moonlight/Wager controls, intel sale, ledger review, known-flow mutations, social actions, plot routes, or held plot choices.
- INTEL is exception-first: risk/policy failures, exact actionable evidence, report lots with decisions, then quiet recursive aggregates. Routine sightings compact into knowledge/provenance summaries and saleable stream output rather than remaining one live row each. Exact leverage, financial evidence, anomalies, and contradictions retain stable targets while they support distinct choices. Exact and lot sales preview and bind the selected target or report-lot generation/revision, preserve learned knowledge, cannot sell the same output twice, reject stale lot revisions without mutation, and target the exact payout account on completion.
- The pooled recording inbox remains one host-bound source with the same
REVIEW and AUTO-REVIEW intentions and direct
r/Rpaths. The default rail groups waiting work by earned source/coarse kind; drill-down reaches exact opaque ids without revealing person/payload or creating person queues. Exact and aggregate REVIEW rows bind canonical sinks, and the summary sweep remains available without duplicating processing legality. - PEOPLE shows staged dossiers and owns social actions, concrete plot starts, active progress, and held choices. One-person plot-slot exclusion remains intact, and no plot title, requirement, authored name, or future branch leaks before its knowledge gate. As the observers panel it carries each observer’s watched channels and ends with the Assurance Office’s action-free institutional card, its watched filers gated by the same earned labels.
- ACCOUNTS shows only known graph state and honest unknown gaps. REVIEW acts on captured books; INJECT on the books; SIPHON/REDIRECT on an exact flow. The selected action previews amount/cadence/signature, and plot-owned transfers do not reappear as generic finance shortcuts. Its pre-capture and captured-unreviewed states teach TAP-on-known-carrier -> REVIEW -> exact flow action without revealing or relocating the carrier.
- SCHEMES shows Moonlight and Wager state, policy, resources, route, timer, payout/probability, and signature in real units. Egress remains a switch action; a blocked scheme names the missing egress and can focus the known switch without opening it automatically.
- ACTIVE renders every committed strategic action that is not yet settled exactly once, including its semantic target, current wait/progress, and channel. It also renders pending/running plots, held choices, live schemes, unresolved wagers, and the completed/failed plot or wager history already retained by sim state, without revealing hidden future beats or outcomes. Device-local work is excluded. Executable rows dispatch to the canonical target rather than duplicate logic.
- Selecting any strategic action shows its known cost/gain, expected
signature/observer band or
no signature, channel/actuator, and exact disabled reason before execution. Disabled actions remain selected and explain themselves on attempted execution. Routine internal unsigned processing, including LOOK AT RECORDING, starts immediately with no second Enter. Externally consequential commitments use target-bound CONFIRM/CANCEL; exact-id/lot-generation+revision snapshots or consequential standing policies confirm once, not once per matching member. A changed lot revision rejects the stale dispatch and refreshes the preview. An external policy binds a route/payout/amount/signature envelope and suspends outside it. Controls show their standing state and price. - Strategic log events open their exact Operations object; spatial events continue to focus world anchors. Scheme events no longer falsely anchor to the switch solely because it carried egress. Folded routine knowledge events deterministically target the earned subject-knowledge aggregate or fallback source/class aggregate; availability targets the stable report stream; a completed sale targets the exact payout account. No event targets a closed lot generation.
- Terminal and Bevy are fully keyboard-playable at their supported minimums,
Bevy also supports pointer selection, and agent inspection prints the same
objects/actions with stable ids. Cross-frontend tests pin identical object
hierarchy/order, selected-action reason/cost/signature, and exact command
dispatch for immediate recording review, one exact intel sale, one report
lot sale using the same generation/revision token, one policy change, one
blocked Moonlight start, one flow mutation, one plot start, and one held
choice. A stale lot token fails without mutation in every frontend.
Every enabled shared row executes through
act <row> [target]against the same exact target that printed it; the stable report stream links to its versioned lot target rather than printing an unexecutable stream-level sale. - Every Operations object may expose only earned related-object links with a named causal relation and stable semantic target. Following a link opens that exact canonical object and owning view in terminal, Bevy, and agent inspection; it does not execute an action or invent a map coordinate.
- Detail panes render decisions before supporting dossier context in this order: identity/state, related objects, physical actuator, actions, selected-action explanation/blocker, then provenance/facts/progress.
- View-strip badges report semantic attention states rather than raw object
counts. A nearly full inbox reports
AT RISK; a held choice reportsHELD; missing egress reportsNO EGRESS; quiet views carry no badge. Frontends consume the core projection’s badge text/severity. Tabcycles object / related / action pane focus without changing view; keyboard and pointer can follow any rendered related edge. Empty related or action panes are skipped, andEscstill backs out one level at a time.- FOCUS and reopen preserve the exact Operations view and object selection in terminal and Bevy. The retained context is frontend-only, does not enter saves, and is superseded by a later exact target entry.
- PERSONAS projects immutable archetype creation routes and every persisted identity instance with the same claims, lifecycle, grants, expectations, local relationships, contradiction provenance, and correlations in all three frontends. Research, Operations, and Security form three stable groups; each lists its instances first and ends with its own add-persona row. Bound rows create/select, grant/fulfill, retire/burn, and reopen without frontend legality or history mutation. No PEOPLE row or direct agent command creates or manages an identity outside this projection.
- Exact recording, source/class aggregate, report lot, facility feed, and later institutional feed recur through the same facts/action/control shape along one canonical custody tree. Subject dossiers and other orthogonal facets are related indexes whose mutations resolve to that custody target; they cannot duplicate membership or sale value. A synthetic million-equivalent-event fixture yields top-level rows proportional to meaningful aggregates and unresolved exceptions, not event count; routine history is bounded in save state as required by intel.md. Drill-down retains honest aggregate or exact provenance at every level.
- Review/disposition policies are canonical core objects projected identically in terminal, Bevy, and agent mode. Each aggregate names its inherited parent default and stable-id ordered local rules; each rule shows its earned match, state, standing cost, channel/signature, and failure. Bound direct controls add/edit/reorder/remove rules, and INHERIT clears a non-root list. Root defaults are total. Most-specific first-match resolution chooses one review and one mutually exclusive disposition per arrival. Raw matching never leaks a hidden subject/classification. Internal policies apply directly; an auto-sale/transmission rule receives one confirmation for a bounded route/payout/amount/signature envelope, folds routine output exactly once into its lot, handles a triggered generation without per-event prompts, and suspends before acting outside that envelope. Exceptions and failed/starved policies return to the live rail with semantic pressure.