Frontend Route, Mock, Navigation, Auth, State & Design Inventory

Measured: 2026-08-05 (Phase 0A; six parallel read-only inventory passes over miz-oki-command-center-ui/ at branch claude/miz-oki-command-center-ui-pacu82) All figures are measured results. UNKNOWN marks what could not be determined from the repo. Re-measured 2026-08-29 — see §0 before reading the body.


0. Status re-measurement (2026-08-29)

The body of this document is a dated 2026-08-05 measurement and is kept as written — it is the Phase 0A baseline the whole program is diffed against. This section carries the re-measurement. Where the two differ, this section is current.

0.1 Census delta

Item 2026-08-05 2026-08-29
User-facing routes (app/**/page.tsx) 155 173
API route handlers 211 278 (of which 46 under app/api/bff/**)
Layouts 6 7 (adds app/(console)/layout.tsx + app/(console)/estate/layout.tsx; app/channels/google and app/marketing unchanged)
Route groups 0 1 — app/(console), holding the five destinations
loading / not-found / error / global-error 0 4 — all four now exist at the app root
Routes named *-archived* still routable 8 0
Test/scratch routes routable in prod 5 0 — all five still present, all five gated behind ENABLE_DEV_ROUTES 2026-08-30 (404 in production; reachable in a non-prod deploy)
Components 260 284
Test files 0 152 (2026-08-30: +/service-health retirement, +the dev-route gate, +the [kernel]/insights gate)

0.2 The consolidation this inventory predates

The package now has five destinations under app/(console)/ — decisions (index), evidence, loop, governance, estate — shipped 2026-08-28/29 in PRs

868, #873, #874, #875, #876. Six competing roots (/, /dashboard,

/dashboard/modern, /command-center, /operate, /mizoki) now answer 307 → /decisions via next.config.mjs redirects(), kept in step with lib/console/destinations.ts RETIRED_ROOTS by a contract test. See COMMAND_CENTER_TRANSFORMATION_PLAN.md §3.1 for the destination map and the legacy → successor route table.

Consequence for §1.1 below: the /command-center row's "MOCK — zero fetch on all 10 pages" is stale. Those pages were rebuilt against the BFF in Phase 1D (useGovernanceReads, useGovernanceLookups, useFleet), and the tree itself is now the legacy surface behind the five destinations. Likewise /audit no longer exists as a route (it is /governance/audit), and /kg/federation and /customer-journey have had their fabricated Math.random() data deleted — the only surviving matches are comments recording the removal.

0.3 Findings carried forward — all CLOSED or VERIFIED 2026-08-30

(Retitled 2026-09-01: every row below closed on 2026-08-30 with its evidence inline; the "still open" heading outlived the findings by a day.)

0.4 Escape hatches and auth (§ cross-reference)

The build-gate and test findings this inventory fed into (ignoreBuildErrors, ignoreDuringBuilds, strict: false, zero tests) are all closed — see COMMAND_CENTER_TRANSFORMATION_PLAN.md §5 rows 2–3 for the measured literals. Auth is closed in code (Phase 1B) but enforcement is still gated on the operator setting REQUIRE_AUTH=true against real Supabase credentials (middleware.ts:102).

1. Route census

Item Count
User-facing routes (app/**/page.tsx) 155
API route handlers (app/api/**/route.ts + app/auth/callback/route.ts) 211
Layouts 6 (root + command-center + channels/google + marketing + agent-ide + error boundary)
Route groups / parallel / intercepting routes 0
loading.tsx / not-found.tsx / global-error.tsx 0 (no route-level Suspense fallbacks anywhere)
Orphan non-route page variants (dead) 2 (app/kernel/[kernel]/page-simple.tsx, app/login/page-fixed.tsx)
Routes named *-archived* still routable 8
Test/scratch routes routable in prod 5 (/test-orchestration, /test-moa-integration, /causal-test, /kg-brain-test, /agent-ux)

Structural hazard: app/[kernel]/page.tsx is a ROOT-LEVEL dynamic segment — any unmatched single-segment path (/foo, /agent_ide, /boss-orchestrator) is absorbed by it instead of 404ing, masking every broken nav link.

1.1 Classification of key routes (Phase 1 targets)

Route(s) Purpose Data source Phase-0 classification
/command-center + 9 children §19 governed-loop surface MOCK — zero fetch on all 10 pages; imports the 12 fabricated arrays from lib/command-center/data.ts KEEP → rebuild live (Phase 1D)
/channels/google + 9 children GAQL Intelligence Cell LIVE via /api/gaql/[...path] authedFetch proxy KEEP (pattern exemplar)
/intent Intent read-only viewer LIVE via allowlisted intent proxy KEEP
/boss* (22 routes) Boss chat/orchestration Mixed live; 8 archived-but-routable; 3 redirects CONSOLIDATE (Phase 2D)
/dashboard, /dashboard/modern, /dashboard/srpvdal, /dashboard/srpvdal-live, /dashboard/srdal(307) Operator dashboards ×5 HYBRID (env-gated mock defaults; srpvdal-live has explicit isMock flag) CONSOLIDATE
/kg* (10) + /command-center/kg-live + /neural-brain + /causal-* KG viewers ×13 Mixed; /kg/federation fully fabricated (8 Math.random sites, 0 fetch) CONSOLIDATE
/service-health was "Real-time service monitoring" ~~MOCK — PRODUCTION RISK: 521 lines, zero network calls, 20 hardcoded services w/ uptime %, relative timestamps, fake critical alert~~ CLOSED 2026-08-30 — fabrication deleted; route now renders a retirement notice + pointers RETIRED (not rebuilt): /system/health-dashboard is the live equivalent; /estate/services + /estate are the BFF successors behind the engineering role floor
/audit Audit & reports MOCK — hardcoded audit events (the one surface that must never be synthetic) KEEP → rebuild live (Phase 1D)
/analytics Analytics dashboard MOCK-seeded + statically bundles d3+recharts+tfjs+framer CONSOLIDATE + code-split
/customer-journey Journey feed MOCK — invents synthetic named individuals on a 5s interval REDESIGN or REMOVE (HD-2)
/decisions/[id]/evidence Decision evidence BROKEN — fetches /api/boss/srpvdal/trace, a route that does not exist (live 404) FIX in Phase 1D
/kernel/[kernel] + /[kernel] + /[kernel]/insights + /kernel Kernel views ×4 MOCK via lib/api-service.ts (setTimeout + hardcoded KPIs) CONSOLIDATE
/blog* + /blogs* (4) Blog duplicated verbatim (two identical content modules) STATIC CONSOLIDATE → redirect
/login Tenant login LIVE against client-side Firestore auth (see §5) KEEP → rebuild on ADR-002
Remaining ops/marketing/agent routes various Mixed; per-route table in agent transcript classify during Phase 1A consolidation

1.2 Duplication clusters (route consolidation backlog)

2. API route posture

3. Mock/fallback inventory (highest-risk)

Math.random occurrences: app 324 · components 64 · lib 48 · hooks 29. The one correctly-gated mock boundary (NEXT_PUBLIC_ENABLE_MOCK_DATA, false in every deploy manifest) covers only 3 files of ~40 fabrication sites.

PRODUCTION RISK (fabricated data on nav-reachable routes, no user-visible disclaimer):

Source Fabricates
lib/command-center/data.ts (12 arrays → 10 pages) Event volumes ("18,742 ↑24%"), decisions w/ ROAS+confidence, executed actions ("reengagement nudge → 1,204 contacts"), audit rows with fake sha256 digests, an approval attributed to gc@acme.com. Scaffold banner exists but is desktop-only (hidden lg:block) — mobile/tablet see mock data with NO disclaimer
~~app/service-health/page.tsx~~ CLOSED 2026-08-30 ~~Entire health dashboard incl. fake critical alert~~ — deleted; the route now renders a retirement notice and pointers, with source-literal guards in app/service-health/page.test.tsx
app/api/cells/stream/route.ts SSE metrics with comments laundering randoms as "real Cell 29/30 performance"
app/api/kernel/{metrics,activities,graph} Random spend/ROAS; fake "auto-applied bid adjustments" activity feed (asserts actions were TAKEN); fake KG
app/api/v1/{moe/activate-cells, moa/coordinate-stages, kg/route-task} Random cell loads/latency/success feeding /cell-monitoring
app/kg/federation/page.tsx Live-looking counters, 0 fetch
app/customer-journey/page.tsx Synthetic named customers invented every 5s
app/audit/page.tsx Hardcoded audit events
app/boss-nav/page.tsx "15,234 nodes / 45,678 edges / 25 cells / 85% autonomy"
app/agents/config/page.tsx Simulated fleet weights/efficacy/health
lib/api-service.ts Hardcoded per-channel KPIs behind setTimeout
app/api/events/route.ts 20%-random backend "health" signal consumed globally
lib/neural-event-service.ts Fabricates heatmap on ANY http error, unmarked
app/api/srpvdal/metrics empty-collection branch Silently mocks in prod, no UI signal
components/{AdvancedAnalyticsDashboard, CausalAnalysisDashboard, KGCompositionDashboard, creative/ABResultsPanel, kg/KGMetricsDisplay, agent-ide/*} Mock analytics/mediation/A-B/skills data on live routes

EXPLICIT DEMO MODE (acceptable pattern, keep-and-formalize): components/modern/* (env-gated), lib/mock/srpvdal.ts + /dashboard/srpvdal-live (isMock surfaced), /marketing/patent-ui, /agent-ux demos. DEVELOPMENT FALLBACK w/ header marker only: app/api/skills/* (X-Mock-Response: true, no current UI consumer). DEAD: app/api/sse/creative-updates, app/api/viz/[kernel]/timeseries, hooks/useCollaboration.ts.

4. Navigation state

The prompt's "nav may already be consolidated" hypothesis is REFUTED. - config/navigation.ts (last updated 2025-09-25) declares itself the single source but has only 2 consumers — NavigationShell (mounted) and MobileNavigationShell (dead, 0 importers). - 11 active navigation trees, 10 of which do NOT read the config: section layouts (command-center NAV, channels/google TABS, marketing ×2 renders), BossNavigation (22 hardcoded links, 3 dead targets), page-as-nav hubs (/boss-nav, /intelligence, /evaluations), agent-ide SideBar, breadcrumbs' own configs. - 5 dead nav components still in components/ (MobileNavigationShell, MainLayout, NavigationSidebar — stale route table incl. deleted /services/boss-enhanced, NavigationHeader, Sidebar). archive-ui/ does not exist anywhere in the repo. - MOBILE_ROUTES positional indexes are all four mislabeled vs the actual array (moot only because its consumer is dead). - icon: any occurrences: navigation.ts:51-52 (+3 more files); no correctly-typed icon anywhere (no LucideIcon/ComponentType usage).

5. Auth, identity, tenancy (measured conclusions)

6. State & API-client duplication (migration backlog)

7. Design system & accessibility (debt summary)

  1. Four uncoordinated color systems; the unwired lib/design-system.ts even exports a ready tailwindExtend never added to tailwind.config.ts (17 lines, 5 tokens with 4 total usages).
  2. ~576 shadcn-style utility usages emit zero CSS (variables never defined) — Card/ Badge/Alert effectively unstyled; the shared Button's focus-visible:ring-ring ring color doesn't exist (rescued only by a global outline).
  3. Dark mode structurally broken: <html className="dark"> hardcoded, darkMode unset (defaults media) → 467 dark: usages keyed to OS preference.
  4. tailwind.config.ts content omits lib/ and hooks/ → classes authored there are purged in prod.
  5. app/layout.tsx viewport sets maximumScale:1, userScalable:false twice — WCAG 1.4.4 failure (blocks pinch-zoom).
  6. A11y at scale: 85 aria-* vs 1,024 buttons; 75 clickable divs (mostly keyboard- inaccessible); 62% of inputs unlabeled; 0 skip links; 0 next/image; 12 tables with 0 scope=; 1 prefers-reduced-motion query — in a stylesheet imported by nothing; the shared skeleton runs an infinite animation unguarded. The best-annotated components (Sidebar, Header) are dead code.
  7. Bundle: /analytics statically chains recharts + import * as d3 + tfjs + framer; 15 files import * as d3; framer-motion on the critical path of every route via PageTransition + skeleton; BossAgentFooter (A2A client, mic, upload) renders on every non-auth route; only 11 files use next/dynamic (monaco/cytoscape/three done right).
  8. Primitives: 21-file components/ui (shadcn-copied, no components.json, cannot re-sync) + a SECOND full primitive set in components/command-center/primitives.tsx (holds the only Table); no form/checkbox/popover/sheet/command/toast-renderer; 195 raw animate-pulse ad-hoc skeletons; no shared EmptyState; ErrorBoundary used by 3 files.
  9. Layout: global NavigationShell stacks with 4 nested layouts + 18 per-page shells (double header/sidebar on /command-center and /marketing); useResponsive() initializes width 0 → every desktop load flashes mobile chrome (hydration mismatch); desktop sidebar collapse is wired but impossible.
  10. Fonts: 4 strategies (next/font Inter; unloaded design-system JetBrains Mono; unloaded 'Fira Code' in globals.css; homepage render-blocking Google Fonts link).

8. UNKNOWNS carried forward

← All docsView source on GitHub →