Frontend UI Gap Analysis — Final Report

Date: July 23, 2026 Scope: All frontend/UI surfaces in MIZOKICloudRun vs. the full backend product surface Method: Full-repo static audit — route/page inventory, navigation config analysis, API-route tracing, backend endpoint/MCP-tool inventory, config/env review. All counts below were verified against the tree at audit time. Verdict in one line: The product has a ~854-tool / ~94-API-group backend and a frontend that faithfully covers roughly a quarter of it, with the rest either mocked, orphaned, duplicated, or absent — the gap is less about missing pages and more about consolidation, live data, and a missing decision-governance console.


Part 1 — What the frontend IS today

There are four real UI surfaces plus several orphan fragments.

1.1 Command Center UI (miz-oki-command-center-ui/) — the primary product UI

Metric Value
Package version / stack 6.9.0, Next.js 15.5.21, React 19, TanStack Query, Supabase SSR + Firebase (dual), OTel
Page routes (app/**/page.tsx) 152
API route handlers (app/api/**/route.ts) 206
Components 252 .tsx files
API routes mentioning mock / Math.random / fallback 89 of 206 (~43%)
Canonical nav entries (config/navigation.ts) ~91 hrefs (101 path: entries)
Automated tests effectively zero (no *.test.* suite)
Build config eslint.ignoreDuringBuilds: true AND typescript.ignoreBuildErrors: true (next.config.mjs)
Auth middleware.ts: REQUIRE_AUTH defaults off → protectedRoutes = []; dual Supabase + Firebase stacks, Firebase keys are dummies in cloudbuild.yaml

Route classification (152 pages):

Class Count Meaning
Live (real backend data via /api/* proxies or hooks) ~59 Agent IDE, Boss chat (/boss, /chat), MCP tools, MOA/MOE, KG live/memory/external, Google GAQL channel hub, operations/services proxies, streaming, health dashboards, lift measurement, connectors
Mock/demo (hardcoded or Math.random) ~21 /command-center tree, /customer-journey, /neural-brain, /kg/federation, /dashboard/srdal, /a2a-monitor, /agentic
Thin stubs / wrappers ~34 ≤40-line pages; some are live-thin (Google channel leafs mount a shared MetricsView), many are placeholders
Static/marketing UI ~21 1,304-line marketing landing at /, /vision, /intelligence, /creative-studio
Archived/dead 8 boss-archived-v3/-v4/-v5, boss-standalone-archived, boss-versions-archived-react/*, docs-boss-agent-system-archived, test-boss-archived

Navigation reality:

Data path: Browser → same-origin /api/* proxies → Cloud Run (Boss ADK boss-agent-adk, Cell 3 KG, per-cell CELL*_URLs, services). Notable mock fallbacks:

Component debt: ~20+ parallel Boss chat implementations. Live: BossAgentV2 (/boss), BOSSChat (/chat), BossChatPanel (Agent IDE), BossAgentFooter. Dead (no app import): BossAgentAutonomous, BossAgentEnhanced, BossAgentSystem, BOSSChatAdvanced, BOSSChatEnhanced, EnhancedBossChat, EnhancedBossChatCompact, PersistentBossChat, BossAgentSRDAL, BossQuickstartView, BossRedirect, BossAgentDashboard.

1.2 Marketing site (# MIZ OKI 3.5/ → mizoki-website / mizoki3.com)

The strongest, most coherent frontend in the repo:

1.3 Browser/IDE extensions (active secondary UIs)

These two consume Boss /health, /api/v1/chat, /api/v1/mcp/*, /api/v1/cells/status — i.e., they already implement the "operator shell" pattern the web UI half-implements.

1.4 Orphan/legacy fragments (confusion sources)


Part 2 — What the product IS (the surface the frontend must cover)

Backend inventory (verified in code, not just docs):

Layer Scale
Boss Agent (miz-oki-adk-agents/boss/boss_agent_core.py v6.49.1 + ~246 sibling modules) ~861 unique HTTP paths across ~94 /api/v1/* groups; ~854 named MCP tools in source
Six-domain packages (src/shared/mizoki_{core,counsel,estate,risk,finance,media,cre}) Decision Control Plane (DEL 0–100, threshold 80), Validation Passports (12/13/14 checks), RiskGate APPROVE/HOLD/VETO, OperatorGates, FORBIDDEN_AUTONOMY, audit replay
Cells (src/cells/) 32+ cells + google_ads_gaql (SRPVDAL sensing cell, /srpvdal/run-mcc, per-account GAQL audit) + identity_attribution
Services (services/) 25+ deployables: virtuoso-models-service, gemini-kg-pipeline, kg-multi-tenant-service, gate-eval-service, replay-sim-ope, ekis, graph_writer, predictions_api, lift-engine, path-metrics APIs, budget-reallocation-service, websocket-gateway, coding-moa, …
Governance (mizoki-remediation/) Ten horizontal services: canonical-ingestion, decision-control-plane, validation-orchestrator, policy-engine, approval-routing, action-runner, audit-replay, model-registry, data-manager-connector, media-incrementality
Model governance (src/shared/virtuoso_models/) Locked role registry (DATA_CAUSAL=gemini-3.6-flash, CODING_ARCH=claude-fable-5, CREATIVE_MM=gpt-5.6-sol, DEVOPS_OPS=grok-4.5, GLOBAL_FALLBACK=claude-opus-4-8), JourneyEvent ingestion with idempotency gate

Largest MCP tool families (each is a candidate UI surface): fl_* (46, federated learning/privacy), connector_* (33), email_* (30, MPP/list hygiene), research_* (19), amo* (~45, marketing optimization), gdp_* (15, Gemini data pipeline), roi_* (15), kg_* (15), journey_* (14), legal_* (13, MoLE), gndi_* (13), cf_* (13, counterfactuals), clds_* (12, closed-loop decisions), aadf_* (12), structured_task_* (11), sixdomain_* (10), srpvdal_* (10), plus cre_*, sfmc_*, relu_*, vbb, uplift/pacing/creative-fatigue, attribution, guardrails, policy engine, rollback, multi-tenant, Cloud Run gate, Vertex AI lifecycle (18 HTTP routes), capsules/closed-code, compliance (EU political ads, consent, GA4 EU).


Part 3 — Coverage matrix: what the frontend covers vs. fails to cover

Legend: ✅ real coverage · 🟡 partial/mock/thin · ❌ none

# Product capability (backend) Frontend today Status
1 Boss chat + streaming (/api/v1/chat[/stream]) /boss, /chat, Agent IDE panel, footer chat, both extensions — but orphaned from nav and 4+ parallel implementations 🟡
2 MCP tool catalog + invoke (~854 tools) /boss/mcp-tools (sidebar-only), extensions' browsers, marketing-site admin runner 🟡
3 Cells health/status (32+ cells) /cell-monitoring (thin), /system/health-dashboard, extension trees; per-cell stream proxies heavily mocked 🟡
4 SRPVDAL pipeline state + autopilot /dashboard/srpvdal (live Firestore but silently degrades to Math.random), orphaned from nav 🟡
5 MOA/MOE orchestration, arbitration, credibility voting /boss/moa-moe (sidebar-only); no arbitration/credibility UI at all 🟡
6 Google Ads GAQL cell (SRPVDAL runs, MCC, per-account audit) /channels/google + 9 leafs via shared MetricsView — the best-wired channel desk ✅
7 KG Brain / Cell 3 (GraphRAG, reason/traverse/explain, 63 endpoints) /kg/live, /kg/memory, /kg/external, /kg-registry live; /kg/chat, /kg/federation mock; no neuro-symbolic explain/provenance viewer 🟡
8 Journey intelligence (stalls, leaks, hazards, NBA, risk scoring) /journey/stalls, /journey/profiling, /journey-intelligence (hybrid mock) 🟡
9 Connector capability discovery + gateway + integration health /connectors, /connectors/[id], integrations health tile ✅
10 Decision gateway (score/allocate/NBA + SSE) /operations/gateway proxy exists; no scoring/allocation console 🟡
11 Policy Engine (5 starter policies, transitions, rollback) ❌ no policy list/history/rollback UI ❌
12 Six-domain Decision Control Plane (DEL, passports, RiskGate, OperatorGates, audit replay) Only the marketing site's mock /console; nothing in Command Center ❌
13 Governance ten-service loop (approval routing, action runner, audit replay, model registry) ❌ nothing ❌
14 HITL approvals (/api/v1/actions/*, realloc_approve, marketing approval workflow) /operations/actions proxy only; no approval inbox 🟡
15 Uplift stack (pacing, cohort export, Qini/AUUC, meta-learners) /lift-measurement (+ recommendations) live; no pacing/cohort-export/Qini console 🟡
16 Attribution + identity (cross-platform, enhanced conversions, CAPI, AEM) /meta-deduplication (orphan), no attribution sync/drift UI 🟡
17 Value-based bidding, creative fatigue, budget reallocation (ReLU) /relu page (orphan); no VBB rules / fatigue rotation / realloc approval UI 🟡
18 Vertex AI ML lifecycle (18 routes: train/deploy/monitor/registry) ❌ nothing ❌
19 Legal / Counsel MoLE (13 tools), Estate, Risk, CRE, Finance, Media domain desks Only marketing-site demos; extensions carry legal/CRE mini-flows; Command Center has none ❌
20 Federated learning + privacy (46 tools: RDP budget, Byzantine agg, drift) ❌ nothing ❌
21 Email intelligence (30 tools: MPP, engagement, hygiene) /operations/email-intelligence + /email-agent (orphan) — partial 🟡
22 Multi-tenant SLO/quota/cost (/api/v1/mt/*, kg-multi-tenant-service) ❌ no tenant dashboard ❌
23 Cloud Run ROI/SLO gate + gate-eval-service + replay-sim-ope (causal promotion gates) ❌ nothing ❌
24 Virtuoso model registry health (role pins, failover, journey ingestion) ❌ nothing (and site mirror is stale) ❌
25 Autonomous research (research_*, priority, institutional, adversarial) ❌ nothing ❌
26 Closed-code execution (capsules, adapters, Logic-as-Policy, bounded autonomy) ❌ nothing ❌
27 AADF (agent taxonomy, trust calibration, oversight violations, maturity) ❌ nothing (some /agents pages are mock) ❌
28 Simulation frameworks (V1/V3: swarms, auctions, governance sim) /simulation page exists (static/thin) 🟡
29 Compliance (EU political ads, consent defaults, GA4 EU, API sunset firewall) ❌ nothing ❌
30 Streaming/voice/media agent /media-agent, /streaming live; SSE topics partially synthetic 🟡
31 Agent IDE + coding MOA /agent-ide — one of the strongest live surfaces ✅
32 Marketing demos / investor storytelling Marketing site — complete and tested ✅

Score: ~4 capabilities fully covered, ~15 partially (often mock-degraded or nav-orphaned), ~13 with zero frontend. The zero-coverage set clusters exactly around the platform's differentiators: decision governance (DCP/passports/gates/replay), model governance, ML lifecycle, multi-tenancy, and the domain desks.


Part 4 — What the frontend SHOULD BE

Given the backend and the product's own stated posture ("Production Candidate / Controlled Pilot", Stage-3 recommend-only, "No evidence, no action"), the right frontend is not 152 pages. It is one consolidated operator application with five hubs, plus the marketing site, plus the extensions:

  1. Operate hub (operator shell) — Boss chat (one implementation), MCP catalog + governed invoke, cells/services health, SRPVDAL loop state, live SSE feed. (exists, fragmented)
  2. Decide hub (governance console) — the missing centerpiece: proposal queue → DEL gauge → Validation Passport check matrix (12/13/14) → RiskGate verdicts (APPROVE/HOLD/VETO) → OperatorGate resolve → ActionAuthorization + rollback token → audit replay timeline. Backed by sixdomain_* tools + mizoki-remediation services + policy engine + approval routing. The marketing site's mock /console is the design spec; it needs to become real, in the product UI.
  3. Grow hub (channel & marketing desks) — Google GAQL (done), Meta/attribution/dedup, SFMC email, VBB + pacing + creative fatigue + budget reallocation approvals, uplift/lift measurement, journey stalls/NBA. (half exists)
  4. Know hub (KG & intelligence) — KG explorer, GraphRAG chat (real), decision provenance/explain, journey/identity graph, path metrics. (partially exists)
  5. Platform hub (admin/ops) — Virtuoso registry health + role pins + failover status, multi-tenant SLO/quota/cost dashboards, Cloud Run gate/canary promotions, Vertex ML lifecycle, API-sunset firewall, compliance (consent/political ads), integration health. (almost entirely missing)

Cross-cutting requirements the current UI fails: single navigation source of truth; auth on by default; no silent mock fallbacks (degrade loudly, never fabricate metrics); one Boss chat component; CI that fails on type/lint errors; smoke tests.


Part 5 — Bridging the gap (detailed plan)

Ordered by dependency, not calendar time. Each item lists concrete files/actions.

Workstream A — Stop the bleeding (hygiene, low risk, high leverage)

  1. Delete/quarantine dead routes: remove the 8 archived route trees (app/boss-archived-v3|v4|v5, app/boss-standalone-archived, app/boss-versions-archived-react, app/docs-boss-agent-system-archived, app/test-boss-archived) and the ~12 dead Boss chat components listed in §1.1. Move anything historically interesting to archive/ (already exists).
  2. Unify navigation: make config/navigation.ts the single source; delete or refactor components/NavigationSidebar.tsx + MainLayout usage; fix broken targets (/services/boss-enhanced, /visualize/test-kernel); add nav entries for live orphans — /boss or /chat (pick one, redirect the other), /dashboard/srpvdal, /agent-launcher, /agentmanager, /media-agent, /boss/mcp-tools, /boss/moa-moe, /boss/realtime, /lift-measurement, /journey/stalls, /relu, /email-agent, /meta-deduplication.
  3. Re-enable build gates: flip ignoreDuringBuilds/ignoreBuildErrors to false in next.config.mjs, fix what breaks. Add a minimal CI job (typecheck + lint + next build).
  4. Kill silent mock fallbacks: in app/api/srpvdal/metrics/route.ts, app/api/boss/chat/route.ts, app/api/registry/*, SSE topic routes, kernel metrics — replace fabricated data with an explicit degraded payload ({ degraded: true, reason }) and render a visible "backend unavailable" state. Gate any remaining demo data behind NEXT_PUBLIC_ENABLE_MOCK_DATA (already false in env.production.yaml) and honor it everywhere.
  5. Repo-level orphans: delete /workspace/index.html, /workspace/app/metrics (or fold into the command center), decide apps/web's fate (archive unless it is the intended v2 shell); fix or remove marketing-site /11/* routes and root login.html.

Workstream B — One operator shell (consolidation)

  1. Single Boss chat: standardize on the Agent IDE BossChatPanel engine (streaming + voice + thinking toggle), wrap it as the /chat page and the footer widget; delete BossAgentV2 vs BOSSChat duplication.
  2. Auth: pick one stack (Supabase SSR is already wired in middleware.ts), remove the Firebase-auth path from login (useTenantAuth/TenantLogin) or make it the one choice; set REQUIRE_AUTH=true in cloudbuild.yaml for the deployed service with real keys via Secret Manager (mirror the marketing site's --set-secrets pattern); protect at minimum: all write/invoke actions, approvals, MCP invoke.
  3. Cells & services health: replace mocked stream proxies with the real /api/v1/cells/status + service /health fan-out (the VS Code extension already proves this pattern); one health dashboard, retire /system-health vs /system/health-dashboard duplication.
  4. MCP catalog: promote /boss/mcp-tools into a first-class governed console — namespace/tag filtering (registry v2 supports it), schema-driven invoke forms, invocation history — reusing connector_v2_* / capability-discovery endpoints.

Workstream C — The Decision Governance console (the biggest missing piece)

New route group app/decide/ backed by existing backends (no new backend required for v1):

  1. Proposal queue: sixdomain_submit_proposal results + /api/v1/actions/pending + mizoki-remediation approval-routing /pending — one inbox with filters (domain, DEL, gate state).
  2. Decision detail: DEL score vs threshold-80 gauge; ReasoningPath weights; EvidenceBundle links; Validation Passport matrix (12/13/14 checks, hard vs soft, PASS/PASS_WITH_CONSTRAINTS/FAIL) — render DecisionProof.render_markdown()'s twelve-slot grammar as the canonical layout.
  3. Gate actions: RiskGate verdict display (APPROVE/HOLD/VETO + undeclared-exposure holds); OperatorGate resolve form (sixdomain_resolve_gate) with alternative-proposal support (the ACT-991 flow already demoed on the marketing site); FORBIDDEN_AUTONOMY scopes rendered as hard-blocked.
  4. Audit replay: timeline view over sixdomain_replay / audit-replay service, with hash-chain verification status.
  5. Policy Engine panel: list/create policies, transition history, one-click rollback (policy_* HTTP group /api/v1/policy-engine/* already exists — 11 endpoints, zero UI today).
  6. Reuse the mock /console's visual language (it is already investor-approved) but drive it from live APIs. This also fixes the credibility problem of demoing a governance product with a scripted terminal.

Workstream D — Platform hub (admin/ops surfaces with zero coverage)

  1. Virtuoso model governance page: role→model pins (from virtuoso-models-service /registry, /models, /health), served_by primary vs global_fallback rates, forbidden-legacy scan results, credential status (Anthropic/OpenAI/xAI), JourneyEvent ingest stats (inserted/duplicate/updated), schema hash. Also re-sync the marketing site's stale mizoki_runtime/virtuoso.py mirror (flagged in WIRING.md §10).
  2. Multi-tenant dashboard: /api/v1/mt/dashboard, quotas, costs, SLO health, alerts (kg-multi-tenant-service is fully built; UI is zero).
  3. Deploy gates: Cloud Run ROI/SLO gate + gate-eval-service + replay-sim-ope causal gate — a promotions board (evaluate → promote/hold/rollback with the causal-evidence check surfaced).
  4. Vertex ML lifecycle: models/endpoints/monitoring drift/batch jobs off the 18 existing /api/v1/vertex-ai/* routes.
  5. Compliance panel: API-sunset firewall alerts (mcp_check_api_versions), consent defaults by region, EU political-ads declarations.

Workstream E — Domain desks (product depth)

Port the marketing site's six demo desks into real Command Center desks, in this order of backend readiness:

  1. Risk desk — sixdomain_risk_register/risk_overview, exposure graph, limit headroom, stress results (backend complete in mizoki_risk).
  2. Counsel desk — legal_* (13 tools): MoLE query with IRAC output, conflict check, authority corpus browser, compliance playbooks; must render the UPL disclaimer + flagged_for_review state (use the legal-disclaimer skill contract).
  3. Media/Capital desks — budget reallocation approvals (realloc_*/ABR with ReLU-gate scores), uplift pacing, creative fatigue rotation queue.
  4. Estate/CRE desks — ownership graph, reconciliation runs, underwriting handoff drift (the Chrome extension's CRE flows are the interaction spec).
  5. Journey/Email consolidation: merge /journey*, /email-agent, /operations/email-intelligence into one Grow-hub journey desk with stall/NBA/hygiene actions.

Workstream F — Quality floor

  1. Tests: Playwright smoke suite (login → each hub renders → chat round-trip → MCP list loads); route-handler unit tests for the top 20 API proxies asserting no fabricated data on failure; contract test that every config/navigation.ts href resolves to a page (would have caught the current broken links).
  2. Telemetry: the OTel wiring exists (instrumentation.ts, lib/telemetry.ts) — add per-hub spans and a real error boundary reporting path.
  3. Docs: one ARCHITECTURE.md refresh describing the five-hub IA and the single nav source; deprecate the many stale BOSS_*/A2A_* docs in the UI folder.

Sequencing & risk notes


Appendix A — Key files cited

Appendix B — Counts summary

Surface Pages/Routes Live Mock Stub/Static Dead
Command Center UI 152 pages / 206 API routes ~59 ~21 ~55 8 (+~12 dead components)
Marketing site ~35 pages + 6 demo desks ~30 1 (console) ~4 thin 3 (login.html, /11, root index)
Backend to cover ~861 HTTP paths, ~94 groups, ~854 MCP tools — — — —
← All docsView source on GitHub →