Command Center Transformation Plan

Program: MIZ OKI Command Center — State-of-the-Art Frontend Transformation Charter: Master implementation prompt v1.0 (owner-supplied, 2026-08-05) Target package: miz-oki-command-center-ui/ Started: 2026-08-05 (Phase 0A) Last updated: 2026-08-29 — phase table and standing risks re-measured against the tree; console consolidation recorded (§3.1). The 2026-08-05 figures below are kept where they are historical measurements; where a risk has since closed, the row says so and names what closed it. Execution mode: multi-session program; verification-first; each phase gated Session branch: claude/miz-oki-command-center-ui-pacu82 (harness-designated; historical — the program has since run across many sessions and branches)

Per-item status lives in FRONTEND_MIGRATION_LEDGER.md, which is the finer-grained record. This file carries the macro-phase view; where the two disagree, the ledger wins and this table is the defect to fix.


1. Mission

Transform miz-oki-command-center-ui/ into the authoritative operator product for the governed MIZ OKI 3.5 platform. The product makes the platform's decision pathway operable, explainable, secure, testable, and trustworthy:

Evidence → Canonical Event Envelope → Temporal-Causal KG → Domain Reasoning
→ Scenario/Forecast/Counterfactual → Validation Passport → Decision Eligibility
→ Human Approval or Authorized Action → Outcome → Learning → Audit Replay

Canonical loop: SENSE → REASON → PLAN → VALIDATE → DECIDE → ACT → LEARN (SRPVDAL, seven-phase, authoritative).

The marketing site (# MIZ OKI 3.5/, mizoki3.com — design-canon LOCKED, human-approval deploys only) remains the narrative product. The Command Center is the operator product. The two share one backend; the console is an Operator Dossier, not a clone of the marketing dossier.

2. Non-negotiables (inherited from charter + repo authority docs)

3. Macro-phase map and gate status

Phase Scope Status
0A Measure: repo/product audit, inventories, baseline COMPLETE 2026-08-05
0A.1 Fix pass (npm ci repair, 570→0 TS errors, truth-discipline removals) COMPLETE 2026-08-05
0B Architecture decisions (ADR-001…007) COMPLETE 2026-08-05 — all seven ACCEPTED; ADR-002/HD-1 closed by owner sign-off
0C Quality infrastructure: scripts, tests, CI, delta type-gate COMPLETE 2026-08-05
1A Canonical shell + information architecture COMPLETE 2026-08-07 (finished session 10)
1B Auth, authorization, tenancy COMPLETE IN CODE 2026-08-09 — enforcement stays behind REQUIRE_AUTH; the production flip is an operator action, not a build state
1C Typed observable BFF + service adapters COMPLETE 2026-08-05 — 13/13 adapters typed from each deployed service's own source
1D /command-center live composition (mock removal) PARTIAL — upstream block CLEARED 2026-08-30 — per-item slices in the ledger. Strict "zero mock imports" was blocked on the HD-4 read-API proposals; all eight endpoints are now present in all six services' serving revisions (READ_API_PROPOSALS.md, re-measured 2026-08-30) and the UI already references all eight, so the remainder is UI-side consumption, not a backend wait
2A Six-domain operator workspace PARTIAL — first slice VERIFIED 2026-08-05
2B Intent/ORACLE integration (advisory posture) PARTIAL — first slice VERIFIED 2026-08-05
2C Cell fleet truth (39 registered cells, failure classes) COMPLETE — 36-cell slice VERIFIED 2026-08-05; extended registry (cells 37–39) landed 2026-08-28
2D One Boss experience IN PROGRESS — steps 1–6 + 8–10 landed; step-7 ratchet at 42 modules (the "17" here was a 2026-08-07 count, and the ratchet is an append-only list of CLEANED modules — it was never a backlog). 2026-08-30: the three client-reachable modules ONE_BOSS_CONSOLIDATION.md §4.1's "CLOSED for backend URLs" note did not cover (lib/config.ts, lib/api.ts, lib/ekisClient.ts) were drained and ratcheted 40–42. Honest remainder is not a module backlog: the deferred step-8 transport family, lib/flags.ts (its own slice), and lib/neural-event-service.ts — the one genuinely open step-7 module, whose fallback is a HARDCODED run.app URL, so it needs a proxy route rather than a drain. §4.2
2E Channels/connectors depth PARTIAL — first slice VERIFIED 2026-08-05
3A Operator Dossier design system PARTIAL — slices 1+2 VERIFIED 2026-08-07; extended by the console destination work (Phase 4)
3B Interaction & productivity PROPOSAL DELIVERED 2026-08-07 (SAVED_VIEWS_PROPOSAL.md); palette shipped in 1A
3C Accessibility (WCAG 2.2 AA) PARTIAL — slice 1 VERIFIED 2026-08-07; axe serious+critical gate covers 15 pages
3D Performance & reliability PARTIAL — slice 2 VERIFIED 2026-08-07; cache policy CLOSED (document-only, measured)
3E Observability PARTIAL — first slice VERIFIED 2026-08-07 (OTel CLIENT span per callService)
3F Security hardening PARTIAL — CSP report-only slice LIVE-VERIFIED 2026-08-08
3G Comprehensive test matrix PARTIAL — e2e + a11y foundation + MSW VERIFIED 2026-08-07
3H Remove escape hatches + dead overlap COMPLETE for the escape hatches 2026-08-06/07 — ignoreBuildErrors: false, ignoreDuringBuilds: false, strict: true measured in-tree 2026-08-29. Dead overlap 2026-08-30: /service-health fabrication deleted, five scratch routes gated, three backend-base modules drained. Two measured 0-importer modules remain — lib/system-load.ts and lib/edge-inference/** — archival candidates (HD-2 class), not drains
4 Console consolidation — five destinations COMPLETE 2026-08-29 — see §3.1

Delivery follows the charter's 8-PR slice sequence (Foundation → Shell/auth → BFF/contracts → Governed Command Center → Domains/Intent/cells → Boss consolidation → Design/a11y/perf → Strictness/cleanup).

3.1 Console consolidation — the five destinations (2026-08-28/29)

The phase ladder above was authored against a package with six competing home pages. That is no longer the shape of the product. The consolidation shipped in five reviewed PRs and is serving:

PR Destination Merge commit Merged (UTC)
#868 Route reorganization + decisions (index) c43c4b47 2026-08-28
#876 evidence 650235c4 2026-08-29 11:35Z
#874 governance 23ee0c78 2026-08-29 11:36Z
#873 loop 3e3a9eff 2026-08-29 11:37Z
#875 estate c4aa5d5f 2026-08-29 14:01Z

The five destinations live under the app/(console)/ route group — the package's first and only route group — behind one ConsoleLayout carrying the destination nav and the posture bar. Serving revision at close of the arc: miz-oki-command-center-ui-00568-fd5 (deploy runs 33250550830, 33256476483). Terminal record: docs/reports/CONSOLE_DESTINATIONS_BUILD_2026-08-29.md.

/command-center is legacy. Six roots — /, /dashboard, /dashboard/modern, /command-center, /operate, /mizoki — now answer 307 → /decisions (next.config.mjs redirects(), kept in step with lib/console/destinations.ts RETIRED_ROOTS by lib/console/retired-roots.contract.test.ts). Only the competing roots redirect: /command-center/** children remain routable as deep links by design, so references to /command-center in this plan should be read as naming the legacy surface, not the destination. The successor surfaces are:

Legacy /command-center/** Successor destination
cells /estate (adds the extended cells 37–39 registry)
events, jobs, connectors /loop
audit, policies, canon-status, approvals /governance
kg-live, learning /evidence
decisions, actions, passports/[decisionId] /decisions

Fleet count. The registered fleet is 39 cells, not 36: the 36-cell Boss registry transcription (FLEET_REGISTRY) plus three additively-tracked Cloud Run services (cells 37–39: market-signal-ingest, cre-prospecting-core, cre-outreach-engine) carried under their own provenance in EXTENDED_FLEET_REGISTRY. TOTAL_REGISTERED_CELL_COUNT is the constant; the two tables are never blended, because they have different sources (docs/architecture/CELL_REGISTRY.md is the cell-number authority). Every "36" in this document that survives refers specifically to the Boss-registry transcription.

4. Program artifacts (this directory)

File Role
COMMAND_CENTER_TRANSFORMATION_PLAN.md This plan; phase map and mission
FRONTEND_ROUTE_INVENTORY.md Measured route/mocks/navigation inventory (Phase 0A)
FRONTEND_SERVICE_CONTRACT_MAP.md Backend capability ↔ frontend consumer map
FRONTEND_ARCHITECTURE_DECISIONS.md ADR-001…007 (decided in Phase 0B)
FRONTEND_MIGRATION_LEDGER.md Per-item status: NOT STARTED / IN PROGRESS / VERIFIED / BLOCKED / HUMAN DECISION
FRONTEND_VERIFICATION.md Baseline commands, exact outcomes, evidence log
ONE_BOSS_CONSOLIDATION.md Phase 2D consolidation record
HD2_ARCHIVE_PROPOSALS.md / READ_API_PROPOSALS.md / SAVED_VIEWS_PROPOSAL.md Human-decision and proposal registers (HD-2, HD-4, 3B)
PERF_BASELINE_2026-08-07.md Phase 3D perf baseline
SUPABASE_PROVISIONING.md ADR-002 operator provisioning path
console-prototype/ Console consolidation thesis (the five-destination design)

Outside this directory: docs/reports/CONSOLE_DESTINATIONS_BUILD_2026-08-29.md is the terminal record of the console consolidation arc (§3.1).

5. Standing risks the program must design around

Original measurement 2026-08-05; re-measured 2026-08-29. Each row keeps the original finding and states its current status. A closed row is kept, not deleted — it names the guard that keeps it closed, so a regression is legible.

  1. npm ci is broken — package.json and package-lock.json were out of sync (missing aframe, three@0.184.0, three-bmfont-text, stats-gl, …; lockfile picomatch@2.3.2 vs required 4.0.5). Any CI relying on npm ci failed at install. CLOSED 2026-08-05 (Phase 0A.1, commit f37b40a) — lockfile regenerated under npm 12; swr and react-force-graph removed (0 imports each); npm ci exit 0. Held by the frontend-guard typecheck job, which runs npm ci on PRs and on main pushes.
  2. Build escape hatches active — typescript.ignoreBuildErrors: true and eslint.ignoreDuringBuilds: true in next.config.mjs; strict: false in tsconfig; tsconfig include: **/*.ts swept the whole package. CLOSED 2026-08-06/07 (Phase 3H) — re-measured in-tree 2026-08-29: next.config.mjs carries ignoreDuringBuilds: false (line 130) and ignoreBuildErrors: false (line 133); tsconfig.json carries "strict": true. A regression here would make the build stop failing on type and lint errors, so treat any flip of these three literals as a gate removal, not a config tweak.
  3. Zero tests — 0 test files in the package; no jest/vitest/playwright config; the test:* scripts were curl smoke calls. CLOSED — measured 2026-08-29: 149 test files; vitest run is npm test, Playwright drives test:e2e and test:a11y, and npm run verify chains lint → typecheck → test → build. Two curl smoke scripts (test:a2a, test:causal) survive under their own names and are not the test suite.
  4. Auth effectively off — middleware.ts emptied protectedRoutes unless REQUIRE_AUTH=true; /dashboard and /boss sat in an ALWAYS-public allowlist (bypassing auth even when the flag was on); a legacy cookie fallback hardcoded userRole = 'engineer'. CLOSED IN CODE 2026-08-05…09 (Phase 1B) — deny-by-default policy core in lib/auth/route-guards.ts; /dashboard and /boss removed from the unconditional public list; the legacy trust-a-cookie branch deleted; roles read from app_metadata only, with absent claims UNPROVISIONED-and-denied. STILL GATED: middleware.ts:102 reads process.env.REQUIRE_AUTH === 'true', so enforcement in production remains an operator flip against real Supabase credentials — and per the 2026-08-09 measurement the legacy Firestore bridge is not a viable fallback (live rules deny sessions/{token} with 403). Build state is not enforcement state.
  5. Scale — was 155 pages, 211 API routes, 260 components, 310 client-marked files, 68 hooks, 0 tests. Re-measured 2026-08-29: 173 pages, 278 API route handlers, 284 components, 149 test files, 7 layouts, 1 route group (app/(console)), 4 route-boundary files (error/global-error/loading/ not-found — all four were 0 at baseline). The package grew; the slice discipline that made it reviewable still applies.
  6. Auto-merge automation — pushes to claude/* (and the other AI prefixes) land on main within seconds unless the protected-path gate refuses them. STILL TRUE, with one correction: the bot's -X theirs conflict resolution was retired 2026-08-24 — it now STOPS on conflict and files an [Auto-Merge Failed] issue instead of merging a wrong resolution. Docs-only commits under docs/frontend/** remain deploy-safe (no deploy-*.yml on.push.paths matches them); code commits under miz-oki-command-center-ui/** dispatch Deploy Command Center UI, so every such merge is a deploy decision.
  7. Stale sibling docs — miz-oki-command-center-ui/CLAUDE.md described Next 14.2.32 / React 18 / Redux Toolkit against a package that was Next 15.5.21 / React 19 / Zustand+Query+SWR. CLOSED — re-measured 2026-08-29: that file now states Next.js 15.5.21, React 19, TypeScript 5.5.4, Zustand + TanStack Query, and Vitest 4, matching package.json (next@15.5.21, react@^19.0.0, zustand@^4.5.7, no @reduxjs/toolkit). swr was removed in 0A.1.

5.1 Findings carried forward from the 2026-08-29 re-measurement — all CLOSED or VERIFIED 2026-08-30

The heading kept its "open" wording for a day after every row below closed; each row carries its own closure evidence and none is open as of 2026-08-30.

6. Definition of done

Per charter §6: one coherent operator story; single nav source; single Boss client/shell; single service-gateway pattern; strict TS with zero ignores; zero lint warnings; meaningful unit/integration/e2e/contract/a11y coverage; CI against the real package; WCAG 2.2 AA; visible freshness/source/claim labels everywhere; governance invariants intact (passport visible, approvals human-attributed, authorizations single-use, 501/hold/denial/timeout rendered honestly; audit replay reconstructs the pathway).

← All docsView source on GitHub →