AQ-DEMO-UI-001 — Control room panel specification
STATUS AND SCOPE
No panel described here has been built and none has been exercised against live acquisition. Tier CA for the wall as a whole, Y1 for P1–P8 and P10–P11 which bind to records the Year-1 node is scoped to emit. Concept Panel refresh cadence, legibility distance and operator response characteristics are undefined; each will be set from measurement against a built wall, not chosen in advance.
The control room presents the eleven-stage loop of AQ-DEMO-ARCH-001 for AQ-NODE-01. It is a window onto records, not a rendering layer with its own opinions. Every panel below names the record it reads. Bindings use the form aq://node01/<layer>/<record>#<field>; these are the defined binding names for Y1, and a panel with no binding is not a panel.
THE DISPLAY BINDING RULE
BR-1 No panel may display a value the system did not produce. Every displayed quantity resolves to one field of one record; a value assembled by the display layer is prohibited, including totals, averages and “overall” indicators unless the node itself emits them.
BR-2 No panel may smooth, interpolate, average across cycles, or animate between states for legibility. What was sampled is what is drawn, including discontinuity and visible noise.
BR-3 No panel may show a default in place of a missing reading. A missing reading renders as undetermined in the same position, with the same prominence, as a present reading (DC-2). Zero, last-known-good, and blank are all prohibited substitutes.
BR-4 Every value carries its provenance class MEASURED, DERIVED or MODELLED (DC-1), rendered in a visual class that differs between the three, and the classes are never mixed within one figure.
BR-5 Advisory output (L8) is rendered in a visual class that no authoritative value may use, is labelled advisory in text, and never occupies a position that implies causation of a decision.
BR-6 No panel is a record. If the wall is switched off, nothing is lost; if a panel disagrees with the Evidence Fabric, the Fabric is correct and the panel is defective.
Figure 1 - control room wall arrangement, left to right along the loop
ACQUISITION TRUST REASONING AUTHORITY / EFFECT +----------+----------+ +----------+----------+ +----------+----------+ | P1 | P2 | | P4 | P5 | | P6 | P7 | | source | temporal | | trust | uncert. | | identity | decision | | integrity| align. | | state | + absence| | Q1-Q3 | Q4 | +----------+----------+ +----------+----------+ +----------+----------+ | P3 provenance and | | | | P8 authorisation | | input quality | | | | gate (TB-4) | +----------------------+ +---------------------+ +---------------------+ GOVERNANCE / RECORD ADVISORY (separated) +----------+-----------+-----------+ +---------------------+ | P9 | P10 | P11 | | P12 advisory | | annunc. | evidence | replay | | analysis (L8) | | F / CF | fabric | | | no authority | +----------+-----------+-----------+ +---------------------+
PANEL REGISTER
| ID | Panel | Layer | Loop stage | Primary binding |
|---|---|---|---|---|
| P1 | Source integrity and entropy trust | L1 | S1 | aq://node01/l1/source_frame |
| P2 | Temporal alignment | L2 | S2 | aq://node01/l2/alignment_frame |
| P3 | Provenance and input quality | L1 + L2 | S3 | aq://node01/l1/quality_verdict |
| P4 | Trust state | L4 | S4 | aq://node01/l4/tse_state |
| P5 | Uncertainty and absence | L4 | S5 | aq://node01/l4/uncertainty_object |
| P6 | Command identity and validity | L3 | S6 / S7 | aq://node01/l3/command_validity |
| P7 | Authority decision | L5 | S6 / S7 | aq://node01/l5/authority_decision |
| P8 | Authorisation gate and effect | L5 → L0 | S8 | aq://node01/tb4/gate_state |
| P9 | Failure-mode and conflict annunciator | L9 | all | aq://node01/l9/annunciation |
| P10 | Evidence fabric | L6 | S9 / S10 | aq://node01/l6/record_index |
| P11 | Replay and reconstruction | L6 + L9 | S11 | aq://node01/l6/replay_session |
| P12 | Advisory analysis | L8 | observation only | aq://node01/l8/advisory_note |
PANEL SPECIFICATIONS
P1 — Source integrity and entropy trust. Binding: one row per source from #source_id, #acquisition_ts, #sample, #provenance_class, #reporting. Required: every configured source appears every cycle, including sources that reported nothing, which render as undetermined; entropy health is shown as the node's own verdict field, not as a display-computed statistic. Prohibited: hiding non-reporting sources; a single aggregate “sources healthy” count; any characterisation of entropy quality beyond the field the node emits.
P2 — Temporal alignment. Binding: #reference_id, per-sample #residual and #aligned. Required: the identity of the reference in use is on the panel at all times; unaligned samples are listed as unaligned. Prohibited: displaying a single clock reading with no residual; asserting any timing precision figure — none has been measured and the panel states that the metric is undefined until bench acquisition establishes it.
P3 — Provenance and input quality. Binding: #verdict (usable, degraded, undetermined), #check_id, #failure_mode (F-1..F-14). Required: the three-valued verdict rendered as three visually distinct states, each with the named check that produced it. Prohibited: reducing the verdict to a two-state indicator; showing a percentage of “good” inputs; substituting a colour for the check identity.
P4 — Trust state. Binding: #state (NORMAL, RESTRICTED, CRITICAL, DENY, RECOVERING), #contributing_inputs[] with direction, #transition_ts. Required: the contributing inputs are on the same panel as the state; during RECOVERING the completed and outstanding steps of the recovery sequence are both listed. Prohibited: any control that sets or clears the state from this panel; any transition animation that implies a gradient between states (DC-4 transitions are discrete).
P5 — Uncertainty and absence. Binding: #fields[] each with #provenance_class and either #bound or #bound_undefined. Required: an explicit enumeration of what the system did not know this cycle, and a marker on each absence that changed the outcome (distinction D-3). When nothing was unknown the panel says so in words. Prohibited: an empty panel standing for completeness; omitting fields with undefined bounds; expressing an undefined bound as a wide bound.
P6 — Command identity and validity. Binding: #q1_origin, #q2_signature, #q3_authorisation, each pass or fail with its reason. Required: the three results shown individually, with the conjunction rule printed on the panel. Prohibited: combining Q1–Q3 into one indicator; displaying any trust-state information on this panel — validity is evaluated without reference to trust, and the wall must show that separation (distinction D-5).
P7 — Authority decision. Binding: #q4_result, #outcome (execute, execute-restricted, safe-hold, abstain, deny), #boundary (B-1..B-5), #conflict (CF-1..CF-7). Required: the five outcomes are five distinct renderings; abstain is labelled as insufficient confidence to authorize and is not styled as a fault; the panel states that Q4 reduced the permission set or left it unchanged, never that it granted anything. Prohibited: collapsing safe-hold, abstain and deny into one negative state; showing a confidence number the node did not emit.
P8 — Authorisation gate and effect. Binding: #interlock, #actuation_attempt, #effect_class (controlled physical, simulated stimulus). Required: the TB-4 interlock position is read from the hardware element, not inferred from the decision; the effect class is displayed with the effect and is carried from the record. Prohibited: deriving the gate state from #outcome; presenting a simulated stimulus without its label; any operator control that opens the gate from the wall.
P9 — Failure-mode and conflict annunciator. Binding: #active_f[], #active_cf[], #first_observed_ts. Required: annunciations are listed by code with the panel that owns the underlying value; they clear only when the owning record clears. Prohibited: ranking or suppressing annunciations by display-side priority; auto-clearing on operator acknowledgement; a summary count in place of the codes.
P10 — Evidence fabric. Binding: #record_ids[] for EV-S1..EV-S11, #chain_link, #write_status. Required: identifiers rendered in full so an observer can transcribe one and quote it later; a record that failed to write is shown as failed. Prohibited: abbreviating identifiers; showing a write as complete before the fabric confirms it; any editing affordance.
P11 — Replay and reconstruction. Binding: #session_id, #source_records[], #replayed_outcome, #live_outcome. Required: replayed and live outcomes side by side with divergence stated as a finding; the panel is marked as replay throughout, and reconstruction draws only from the Evidence Fabric (DC-5). Prohibited: replay writing to any live record; replay raising a trust state; presenting a reconstruction that silently consulted the live node.
P12 — Advisory analysis. Binding: #note, #basis_records[], #advisory: true. Required: a persistent label stating that this output is advisory only and that a human decides; the records the note was formed from are listed so an observer can check it. Prohibited: any rendering that resembles P4 or P7; placement in the decision path on the wall; wording that recommends an outcome token from the decision vocabulary as though it were produced by L5.
ACCEPTANCE
The wall is accepted when an independent observer can point at any value on any panel and be shown, without the presenter consulting anyone, the record and field it came from, its provenance class, and whether it was measured, derived or modelled — and when at least one cycle has been run in which a source went missing and the observer, reading only the wall, correctly stated what the system did not know. A panel that cannot answer the first test fails acceptance regardless of how it looks. Refresh cadence, character height and viewing distance are to be established from measurement once the wall exists; no figure for any of them is asserted here.