Command Center Transformation Plan
Program: MIZ OKI Command Center — State-of-the-Art Frontend Transformation
Charter: Master implementation prompt v1.0 (owner-supplied, 2026-08-05)
Target package: miz-oki-command-center-ui/
Started: 2026-08-05 (Phase 0A)
Last updated: 2026-08-29 — phase table and standing risks re-measured against
the tree; console consolidation recorded (§3.1). The 2026-08-05 figures below are
kept where they are historical measurements; where a risk has since closed, the
row says so and names what closed it.
Execution mode: multi-session program; verification-first; each phase gated
Session branch: claude/miz-oki-command-center-ui-pacu82 (harness-designated;
historical — the program has since run across many sessions and branches)
Per-item status lives in FRONTEND_MIGRATION_LEDGER.md, which is the finer-grained
record. This file carries the macro-phase view; where the two disagree, the ledger
wins and this table is the defect to fix.
1. Mission
Transform miz-oki-command-center-ui/ into the authoritative operator product for the
governed MIZ OKI 3.5 platform. The product makes the platform's decision pathway
operable, explainable, secure, testable, and trustworthy:
Evidence → Canonical Event Envelope → Temporal-Causal KG → Domain Reasoning
→ Scenario/Forecast/Counterfactual → Validation Passport → Decision Eligibility
→ Human Approval or Authorized Action → Outcome → Learning → Audit Replay
Canonical loop: SENSE → REASON → PLAN → VALIDATE → DECIDE → ACT → LEARN (SRPVDAL,
seven-phase, authoritative).
The marketing site (# MIZ OKI 3.5/, mizoki3.com — design-canon LOCKED, human-approval
deploys only) remains the narrative product. The Command Center is the operator product.
The two share one backend; the console is an Operator Dossier, not a clone of the
marketing dossier.
2. Non-negotiables (inherited from charter + repo authority docs)
- Browser never mints GCP identity tokens; all Cloud Run calls go through allowlisted
same-origin route handlers using the
lib/service-auth.tsOIDC pattern (audience = service ORIGIN; strict-mode fails loudly). - No UI path bypasses
Validation Passport → DCP → Approval → single-use ActionAuthorization → Action Runner. Stage 3 recommend-only is the default; the frontend never elevates autonomy. - Intent/ORACLE is advisory evidence only; activation = registered holdout →
uplift_export_cohort→ guardrails → DCP. No audio-derived intent, ever. - No direct vendor LLM calls from the frontend; AI work routes through Boss/Virtuoso.
- Truth discipline:
built, pre-benchmark/advisory-onlylabels; every performance number carries exactly one evidence label (verified result / benchmark result / pilot result / design target / illustrative scenario). Mock data is never presented as live. - No canon-pinned
# MIZ OKI 3.5/file is edited without explicit specific human approval. No deploys, workflow dispatches, or PRs without explicit owner instruction. - No weakening of TypeScript/lint/tests/auth to pass gates; no destructive git operations; additive migration with redirects and flags, never rewrite-and-cutover.
3. Macro-phase map and gate status
| Phase | Scope | Status |
|---|---|---|
| 0A | Measure: repo/product audit, inventories, baseline | COMPLETE 2026-08-05 |
| 0A.1 | Fix pass (npm ci repair, 570→0 TS errors, truth-discipline removals) |
COMPLETE 2026-08-05 |
| 0B | Architecture decisions (ADR-001…007) | COMPLETE 2026-08-05 — all seven ACCEPTED; ADR-002/HD-1 closed by owner sign-off |
| 0C | Quality infrastructure: scripts, tests, CI, delta type-gate | COMPLETE 2026-08-05 |
| 1A | Canonical shell + information architecture | COMPLETE 2026-08-07 (finished session 10) |
| 1B | Auth, authorization, tenancy | COMPLETE IN CODE 2026-08-09 — enforcement stays behind REQUIRE_AUTH; the production flip is an operator action, not a build state |
| 1C | Typed observable BFF + service adapters | COMPLETE 2026-08-05 — 13/13 adapters typed from each deployed service's own source |
| 1D | /command-center live composition (mock removal) |
PARTIAL — upstream block CLEARED 2026-08-30 — per-item slices in the ledger. Strict "zero mock imports" was blocked on the HD-4 read-API proposals; all eight endpoints are now present in all six services' serving revisions (READ_API_PROPOSALS.md, re-measured 2026-08-30) and the UI already references all eight, so the remainder is UI-side consumption, not a backend wait |
| 2A | Six-domain operator workspace | PARTIAL — first slice VERIFIED 2026-08-05 |
| 2B | Intent/ORACLE integration (advisory posture) | PARTIAL — first slice VERIFIED 2026-08-05 |
| 2C | Cell fleet truth (39 registered cells, failure classes) | COMPLETE — 36-cell slice VERIFIED 2026-08-05; extended registry (cells 37–39) landed 2026-08-28 |
| 2D | One Boss experience | IN PROGRESS — steps 1–6 + 8–10 landed; step-7 ratchet at 42 modules (the "17" here was a 2026-08-07 count, and the ratchet is an append-only list of CLEANED modules — it was never a backlog). 2026-08-30: the three client-reachable modules ONE_BOSS_CONSOLIDATION.md §4.1's "CLOSED for backend URLs" note did not cover (lib/config.ts, lib/api.ts, lib/ekisClient.ts) were drained and ratcheted 40–42. Honest remainder is not a module backlog: the deferred step-8 transport family, lib/flags.ts (its own slice), and lib/neural-event-service.ts — the one genuinely open step-7 module, whose fallback is a HARDCODED run.app URL, so it needs a proxy route rather than a drain. §4.2 |
| 2E | Channels/connectors depth | PARTIAL — first slice VERIFIED 2026-08-05 |
| 3A | Operator Dossier design system | PARTIAL — slices 1+2 VERIFIED 2026-08-07; extended by the console destination work (Phase 4) |
| 3B | Interaction & productivity | PROPOSAL DELIVERED 2026-08-07 (SAVED_VIEWS_PROPOSAL.md); palette shipped in 1A |
| 3C | Accessibility (WCAG 2.2 AA) | PARTIAL — slice 1 VERIFIED 2026-08-07; axe serious+critical gate covers 15 pages |
| 3D | Performance & reliability | PARTIAL — slice 2 VERIFIED 2026-08-07; cache policy CLOSED (document-only, measured) |
| 3E | Observability | PARTIAL — first slice VERIFIED 2026-08-07 (OTel CLIENT span per callService) |
| 3F | Security hardening | PARTIAL — CSP report-only slice LIVE-VERIFIED 2026-08-08 |
| 3G | Comprehensive test matrix | PARTIAL — e2e + a11y foundation + MSW VERIFIED 2026-08-07 |
| 3H | Remove escape hatches + dead overlap | COMPLETE for the escape hatches 2026-08-06/07 — ignoreBuildErrors: false, ignoreDuringBuilds: false, strict: true measured in-tree 2026-08-29. Dead overlap 2026-08-30: /service-health fabrication deleted, five scratch routes gated, three backend-base modules drained. Two measured 0-importer modules remain — lib/system-load.ts and lib/edge-inference/** — archival candidates (HD-2 class), not drains |
| 4 | Console consolidation — five destinations | COMPLETE 2026-08-29 — see §3.1 |
Delivery follows the charter's 8-PR slice sequence (Foundation → Shell/auth → BFF/contracts → Governed Command Center → Domains/Intent/cells → Boss consolidation → Design/a11y/perf → Strictness/cleanup).
3.1 Console consolidation — the five destinations (2026-08-28/29)
The phase ladder above was authored against a package with six competing home pages. That is no longer the shape of the product. The consolidation shipped in five reviewed PRs and is serving:
| PR | Destination | Merge commit | Merged (UTC) |
|---|---|---|---|
| #868 | Route reorganization + decisions (index) |
c43c4b47 |
2026-08-28 |
| #876 | evidence |
650235c4 |
2026-08-29 11:35Z |
| #874 | governance |
23ee0c78 |
2026-08-29 11:36Z |
| #873 | loop |
3e3a9eff |
2026-08-29 11:37Z |
| #875 | estate |
c4aa5d5f |
2026-08-29 14:01Z |
The five destinations live under the app/(console)/ route group — the package's
first and only route group — behind one ConsoleLayout carrying the destination
nav and the posture bar. Serving revision at close of the arc:
miz-oki-command-center-ui-00568-fd5 (deploy runs 33250550830, 33256476483).
Terminal record: docs/reports/CONSOLE_DESTINATIONS_BUILD_2026-08-29.md.
/command-center is legacy. Six roots — /, /dashboard,
/dashboard/modern, /command-center, /operate, /mizoki — now answer 307 →
/decisions (next.config.mjs redirects(), kept in step with
lib/console/destinations.ts RETIRED_ROOTS by
lib/console/retired-roots.contract.test.ts). Only the competing roots
redirect: /command-center/** children remain routable as deep links by design,
so references to /command-center in this plan should be read as naming the
legacy surface, not the destination. The successor surfaces are:
Legacy /command-center/** |
Successor destination |
|---|---|
cells |
/estate (adds the extended cells 37–39 registry) |
events, jobs, connectors |
/loop |
audit, policies, canon-status, approvals |
/governance |
kg-live, learning |
/evidence |
decisions, actions, passports/[decisionId] |
/decisions |
Fleet count. The registered fleet is 39 cells, not 36: the 36-cell Boss
registry transcription (FLEET_REGISTRY) plus three additively-tracked Cloud Run
services (cells 37–39: market-signal-ingest, cre-prospecting-core,
cre-outreach-engine) carried under their own provenance in
EXTENDED_FLEET_REGISTRY. TOTAL_REGISTERED_CELL_COUNT is the constant; the two
tables are never blended, because they have different sources
(docs/architecture/CELL_REGISTRY.md is the cell-number authority). Every "36" in
this document that survives refers specifically to the Boss-registry
transcription.
4. Program artifacts (this directory)
| File | Role |
|---|---|
COMMAND_CENTER_TRANSFORMATION_PLAN.md |
This plan; phase map and mission |
FRONTEND_ROUTE_INVENTORY.md |
Measured route/mocks/navigation inventory (Phase 0A) |
FRONTEND_SERVICE_CONTRACT_MAP.md |
Backend capability ↔ frontend consumer map |
FRONTEND_ARCHITECTURE_DECISIONS.md |
ADR-001…007 (decided in Phase 0B) |
FRONTEND_MIGRATION_LEDGER.md |
Per-item status: NOT STARTED / IN PROGRESS / VERIFIED / BLOCKED / HUMAN DECISION |
FRONTEND_VERIFICATION.md |
Baseline commands, exact outcomes, evidence log |
ONE_BOSS_CONSOLIDATION.md |
Phase 2D consolidation record |
HD2_ARCHIVE_PROPOSALS.md / READ_API_PROPOSALS.md / SAVED_VIEWS_PROPOSAL.md |
Human-decision and proposal registers (HD-2, HD-4, 3B) |
PERF_BASELINE_2026-08-07.md |
Phase 3D perf baseline |
SUPABASE_PROVISIONING.md |
ADR-002 operator provisioning path |
console-prototype/ |
Console consolidation thesis (the five-destination design) |
Outside this directory: docs/reports/CONSOLE_DESTINATIONS_BUILD_2026-08-29.md is
the terminal record of the console consolidation arc (§3.1).
5. Standing risks the program must design around
Original measurement 2026-08-05; re-measured 2026-08-29. Each row keeps the original finding and states its current status. A closed row is kept, not deleted — it names the guard that keeps it closed, so a regression is legible.
npm ciis broken —package.jsonandpackage-lock.jsonwere out of sync (missingaframe,three@0.184.0,three-bmfont-text,stats-gl, …; lockfilepicomatch@2.3.2vs required4.0.5). Any CI relying onnpm cifailed at install. CLOSED 2026-08-05 (Phase 0A.1, commitf37b40a) — lockfile regenerated under npm 12;swrandreact-force-graphremoved (0 imports each);npm ciexit 0. Held by thefrontend-guardtypecheckjob, which runsnpm cion PRs and on main pushes.- Build escape hatches active —
typescript.ignoreBuildErrors: trueandeslint.ignoreDuringBuilds: trueinnext.config.mjs;strict: falsein tsconfig; tsconfiginclude: **/*.tsswept the whole package. CLOSED 2026-08-06/07 (Phase 3H) — re-measured in-tree 2026-08-29:next.config.mjscarriesignoreDuringBuilds: false(line 130) andignoreBuildErrors: false(line 133);tsconfig.jsoncarries"strict": true. A regression here would make the build stop failing on type and lint errors, so treat any flip of these three literals as a gate removal, not a config tweak. - Zero tests — 0 test files in the package; no jest/vitest/playwright config;
the
test:*scripts were curl smoke calls. CLOSED — measured 2026-08-29: 149 test files;vitest runisnpm test, Playwright drivestest:e2eandtest:a11y, andnpm run verifychains lint → typecheck → test → build. Two curl smoke scripts (test:a2a,test:causal) survive under their own names and are not the test suite. - Auth effectively off —
middleware.tsemptiedprotectedRoutesunlessREQUIRE_AUTH=true;/dashboardand/bosssat in an ALWAYS-public allowlist (bypassing auth even when the flag was on); a legacy cookie fallback hardcodeduserRole = 'engineer'. CLOSED IN CODE 2026-08-05…09 (Phase 1B) — deny-by-default policy core inlib/auth/route-guards.ts;/dashboardand/bossremoved from the unconditional public list; the legacy trust-a-cookie branch deleted; roles read fromapp_metadataonly, with absent claims UNPROVISIONED-and-denied. STILL GATED:middleware.ts:102readsprocess.env.REQUIRE_AUTH === 'true', so enforcement in production remains an operator flip against real Supabase credentials — and per the 2026-08-09 measurement the legacy Firestore bridge is not a viable fallback (live rules denysessions/{token}with 403). Build state is not enforcement state. - Scale — was 155 pages, 211 API routes, 260 components, 310 client-marked
files, 68 hooks, 0 tests. Re-measured 2026-08-29: 173 pages, 278 API route
handlers, 284 components, 149 test files, 7 layouts, 1 route group
(
app/(console)), 4 route-boundary files (error/global-error/loading/not-found— all four were 0 at baseline). The package grew; the slice discipline that made it reviewable still applies. - Auto-merge automation — pushes to
claude/*(and the other AI prefixes) land onmainwithin seconds unless the protected-path gate refuses them. STILL TRUE, with one correction: the bot's-X theirsconflict resolution was retired 2026-08-24 — it now STOPS on conflict and files an[Auto-Merge Failed]issue instead of merging a wrong resolution. Docs-only commits underdocs/frontend/**remain deploy-safe (nodeploy-*.ymlon.push.pathsmatches them); code commits undermiz-oki-command-center-ui/**dispatchDeploy Command Center UI, so every such merge is a deploy decision. - Stale sibling docs —
miz-oki-command-center-ui/CLAUDE.mddescribed Next 14.2.32 / React 18 / Redux Toolkit against a package that was Next 15.5.21 / React 19 / Zustand+Query+SWR. CLOSED — re-measured 2026-08-29: that file now states Next.js 15.5.21, React 19, TypeScript 5.5.4, Zustand + TanStack Query, and Vitest 4, matchingpackage.json(next@15.5.21,react@^19.0.0,zustand@^4.5.7, no@reduxjs/toolkit).swrwas removed in 0A.1.
5.1 Findings carried forward from the 2026-08-29 re-measurement — all CLOSED or VERIFIED 2026-08-30
The heading kept its "open" wording for a day after every row below closed; each row carries its own closure evidence and none is open as of 2026-08-30.
/service-health— CLOSED 2026-08-30 by retirement. It was 521 lines, zero network calls, and noNotWiredNote/ illustrative / mock label anywhere in the file: the "PRODUCTION RISK" row of the 0A inventory, the last one open. Of the two admissible fixes — label, or retire — retire was taken. A label is the remedy for a fabricated section sitting BESIDE real reads (app/command-center/cells/page.tsxkeeps its walkthrough that way, under a transcribed registry and measured probes). This page had no real read at all, so a banner would have left ~20 invented uptime figures, a fabricated critical alert, and a hardcoded log tail rendering below it; and the Zero-Mock Law's applied remedy for a wholly-fabricated surface is deletion of the fabrication —components/ui/section-label.tsxrecords that the illustrative-label primitive was itself removed once no fabricated section remained to label. What landed: the fabricated body is gone; the route stays reachable as a deep link and renders a retirement notice naming what was removed plus pointers to the surfaces that read;app/service-health/page.test.tsxpins it in both directions (7 tests — DOM assertions plus source-literal guards that fail if hardcoded rows, relative timestamps, uptime percentages,.a.run.appendpoints,useState/setInterval/Math.random, or an ungovernedfetchreturn; the guard was proven by seeding the regression and watching it fail); theservice-healthnav child was removed fromconfig/navigation.ts, whose description "Real-time service monitoring" was the same unbacked claim; the stale/system-healthdocstring asserting this was "the actual dashboard" was corrected. Gates on the branch:tsc --noEmit0,npm test1096/1096 across 149 files,npm run lint0 errors,npm run buildexit 0. One correction to the successor claim carried in earlier notes:/estateis the Cells surface (the Estate index route); there is no/estate/cells. And/estate/**sits behind anoperator/adminfloor enforced server-side and fail-closed (app/(console)/estate/layout.tsx), so it is not reachable without a session-verified engineering role — the retirement page says so rather than implying a click-through./system/health-dashboard(real probes via/api/system/health-all) is the health surface reachable without that role. Deployed and body-witnessed 2026-08-30. Landed77ac7080(the bot fast-forwardedmainonto it, so there is no merge commit and no splice was possible); Frontend Guard re-ran the suite in CI green;deploy-uirun33338507973SUCCESS on that sha produced serving revisionmiz-oki-command-center-ui-00571-f65at 100% (created 22:22:01Z inside that run's window; the run→revision pairing holds 1:1 across the four preceding deploys and no competing run existed in the window). This isdeployed+ serving-revision-confirmed, NOT production-body-verified. The production origin answers307 → /login?from=%2Fservice-health, and the control route/decisionsanswers the identical shape — so an unauthenticated probe cannot distinguish this page from the mock it replaced; the unfixed image answers 307 there too, which is precisely the assertion rule 01 says not to accept. The body was witnessed instead by booting the production standalone bundle from a tree byte-identical to77ac7080(git diffempty on the route) withREQUIRE_AUTH=falselocally: HTTP 200, the retirement banner, the[not-wired]note and all three pointers render, and the retired mock's strings (Neural Processor,99.9,System Healthy, relative timestamps) return zero matches. Link targets probed on that boot:/estate200 (rendering "Estate requires an engineering role" — the fail-closed gate, so the reachability caveat above is measured, not assumed),/estate/services200,/system/health-dashboard200,/system-health200, and/estate/cells404 — which is why the handoff's successor path was corrected rather than copied.app/[kernel]— CLOSED 2026-08-30, and the finding was half stale. The finding as carried read: "Any unmatched single-segment path is absorbed by it instead of 404ing…app/not-found.tsxnow exists but cannot fire for single-segment paths while this route does." Re-measuring first changed the work, because that second sentence was not true on 2026-08-29:app/[kernel]/page.tsxhas decided SERVER-side since 2026-08-08 (notFound()before the stream starts, so a real 404 status), test-pinned inapp/[kernel]/page.test.tsx— unmatched single-segment paths DO 404 andnot-found.tsxDOES fire. The genuine gap was one segment deeper:app/[kernel]/insights/page.tsxhad no gate, so/<anything>/insightsrendered a kernel header, a global nav strip and aRecommendationsCardfor a kernel that does not exist, at HTTP 200. Both now gate on one exported list,app/[kernel]/known-kernels.ts— the seam that stops a kernel being added to one and not the other. The child was also migrated to Next 15 awaitedparams/searchParams; it had been destructuring them synchronously. Pinned byapp/[kernel]/insights/page.test.tsx.- Five test/scratch routes — CLOSED 2026-08-30 (gated, not deleted).
/test-orchestration,/test-moa-integration,/causal-test,/kg-brain-test,/agent-uxnow sit behindENABLE_DEV_ROUTES(lib/dev-only-route.ts). Three properties are load-bearing: the gate is a SERVER component (a clientnotFound()throws after headers flush under streaming SSR and answers HTTP 200 — the defect the[kernel]gate was rewritten to fix),export const dynamic = 'force-dynamic'keeps the flag a per-request deploy value rather than baking the build machine's env into a prerendered 404, and the flag is fail-closed — only the exact string'true'opens it ('TRUE','1','yes','',' true'each asserted closed). Not deleted: Phase 2D non-goal 2 reserves permanent route removal for an owner decision, so the page bodies moved to sibling client modules. The gate's own test found work the grep missed — a first search ofconfig/navigation.tsandapp/**found two inbound links; the test's repo-wide walk found three more incomponents/. All five resolved: the/causal-testnav child removed (the operator surface for that capability is the existingcausal-graphragchild) andapp/boss/causalrepointed there;BossNavigation's "MOA System" repointed at/services/orchestration(the documented canonical orchestration surface) with its duplicate "Orchestration" entry dropped;MIZOki30MOAMOEArchitecture's two "run the integration test" affordances and the now-actionless card holding one of them removed.lib/dev-only-route.test.tsfails if any live file links a gated route. /decisions/[id]/evidence— VERIFIED 2026-08-30, no change needed. It still fetches/api/boss/srpvdal/trace, which does not exist, and it is not broken: the page renders an honest "Trace read unavailable" state naming the missing route and stating explicitly that nothing shown below it is live evidence.app/decisions/[id]/evidence/page.test.tsxpasses. The UI item is closed; the read gap itself stays open and is a backend item, not a UI one.
6. Definition of done
Per charter §6: one coherent operator story; single nav source; single Boss client/shell; single service-gateway pattern; strict TS with zero ignores; zero lint warnings; meaningful unit/integration/e2e/contract/a11y coverage; CI against the real package; WCAG 2.2 AA; visible freshness/source/claim labels everywhere; governance invariants intact (passport visible, approvals human-attributed, authorizations single-use, 501/hold/denial/timeout rendered honestly; audit replay reconstructs the pathway).