Govern
The rules a leg runs under, the decisions only a human makes, and the money — with the reason a gate is copied and not clicked.
Policies (Advanced)
About the pictures on this page. They are rendered from the built console over a demonstration data set, not from a live fleet — a screenshot of somebody's real record would publish their work. What the pictures are evidence of is the layout, the chips and the acts; every number in them is sample data.
Three tabs, one screen.
Egress rules
Every leg runs behind an egress policy: which hosts it may dial, on which ports, with what verdict — and seven ceilings: bytes, requests, headers, line length, idle time, total time, handshake.
The left list is the library of rule-sets — floor · in force · draft · admitted · invalid, with tags. The editor shows the rules, the ceilings, a Validate line (the engine's own loader and compile: rules, allows, conflicts, dead rules, and hosts measured against fact records), and the acts Copy as new · Merge… · Save · Delete, and Admit, which opens the signing step.
Merge shows the sources side by side and makes you choose at every conflict — the engine
never resolves a conflict for you.

The floor is not a document. It is always in force, and a run that needs a policy and has none is refused before it spawns. See Egress control.
Permission classes
What a leg's toolchain may do on the machine: the class, its image, the tools allowed, the
environment it sees. Same library and editor layout, same states, same acts.

Connections
Who holds a seat: people, never workloads — their sign-ins and sessions, refusals in the last
24 hours, and the queue of subjects waiting to be admitted to a seat. Admission is an act in the
signed register, and the panel shows the queue and links to it. See
Identity.

Gates
A gate is a decision only a human makes: a review round is ready, or a leg stopped at stop-1
for a permission or at stop-2 for a decision.
The table lists open gates — filters open · decided today · all — with the stream, gate, kind,
when it opened, cost so far, and your act: Accept · Conditions · Reject for a review,
Grant · Refuse for a permission. The columns are fixed, so the same act is always under the
same act.

Below it, the gate card for the selected gate: its facts — rehearsal green, findings, worktree clean, who opened it — each finding with its remedy chip, and then the line that matters:
Your line — copied, never fired here.
The exact saphan gate … command, with Copy, then Executed — check once you have run it.
The act becomes a row of the record when the command runs in your terminal, signed by your
seat — which is the whole reason the console does not run it. See
Gates for what a gate decides.
Ledger · Costs
Money, live. Tiles for today, for each live role and for the fleet. Daily cost for the last 14 days by role and by fleet, side by side or stacked, with today highlighted. Caps and envelopes — each role's spend against its cap, and the envelopes of the streams.
An envelope is derived from the estimate at stop-1; an override is an owner's act; and new
work in a stream is a new envelope. The bottom line of the sidebar is the same number.

Everything here is booked before it is spent. See Operations.
Development
Streams and trains, the legs running now, the defects the fleet files about itself, the twelve report plates, the prompt library and the generated chapters.
The fleet
The machines themselves: the overlay network, every seat and its measured headroom, the fleet's own events, and what it remembers.