[{"data":1,"prerenderedAt":1294},["ShallowReactive",2],{"$foENura0bGw8bk_sZKhvTnpy16kw1rGJrJEQHSh2uklM":3},{"newThing":4,"project":5,"cycle":8,"sections":22,"threads":1139,"otherDocs":1140,"images":1142,"archiveItems":1245,"links":1254},null,{"id":6,"label":7,"liveBase":4},"design","Design",{"id":9,"num":10,"dir":11,"name":12,"title":12,"focus":13,"status":14,"statusNote":4,"created":15,"completed":4,"mode":4,"recordless":16,"thumbnail":17,"imageCount":18,"artifactCount":19,"lastActivity":20,"hasPickup":16,"hasInitialPrompt":21},"c65",65,"c65.control-center-v2","control-center-v2","Shift the control center from infinitely-configurable controls to a compliance-driven system of pre-defined Policies — research the framework↔policy connection, then mock the policy catalog and per-policy config pages","active","2026-08-12",false,"\u002Fcycles\u002Fdesign\u002Fc65-compliance-frameworks.png",27,4,"2026-09-11",true,[23,96,130,281,1100],{"key":24,"title":25,"empty":16,"ast":26},"why","Why",{"type":27,"children":28},"root",[29,77],{"type":30,"tag":31,"props":32,"children":33},"element","p",{},[34,37,43,45,51,53,60,62,67,69,75],{"type":35,"value":36},"text","c64 consolidated qdash around the flexible control model and shipped the V5 expand-card authoring flow — and in doing so made the cost of that flexibility visible: every control is a hand-built rule (signal + clauses + decisions + actions + packs), which is more complexity and manual configuration than the product wants to put in front of an operator. c65 deliberately reverses the emphasis: the infinite configurability moves ",{"type":30,"tag":38,"props":39,"children":40},"em",{},[41],{"type":35,"value":42},"behind",{"type":35,"value":44}," a curated set of ",{"type":30,"tag":46,"props":47,"children":48},"strong",{},[49],{"type":35,"value":50},"pre-defined Policies",{"type":35,"value":52}," — narrow in scope, activated\u002Fdeactivated with a toggle, each with focused context-specific configuration (e.g. the egress allow-list policy gets a page for managing the list). The ",{"type":30,"tag":54,"props":55,"children":57},"code",{"className":56},[],[58],{"type":35,"value":59},"\u002Fpolicy",{"type":35,"value":61}," page had already started down this path; we veer back toward it, minus its enforcement-mode\u002Fviolation-handling cascade (that becomes a global function, out of scope here). ",{"type":30,"tag":46,"props":63,"children":64},{},[65],{"type":35,"value":66},"Compliance frameworks are the driver:",{"type":35,"value":68}," frameworks are toggled globally (as on ",{"type":30,"tag":54,"props":70,"children":72},{"className":71},[],[73],{"type":35,"value":74},"\u002Fcompliance",{"type":35,"value":76}," today) and determine global health and security posture; policies exist to satisfy them.",{"type":30,"tag":31,"props":78,"children":79},{},[80,82,87,89,94],{"type":35,"value":81},"Vocabulary decision (2026-08-12): the pre-defined units are ",{"type":30,"tag":46,"props":83,"children":84},{},[85],{"type":35,"value":86},"Policies",{"type":35,"value":88},", a distinct concept sitting above the flexible ",{"type":30,"tag":46,"props":90,"children":91},{},[92],{"type":35,"value":93},"Controls",{"type":35,"value":95}," engine — reintroducing the word c64's IA pass retired, now with a real distinction to carry (policy = curated, narrow, toggleable unit; control = underlying executable rule).",{"key":97,"title":98,"empty":16,"ast":99},"objective","Objective",{"type":27,"children":100},[101],{"type":30,"tag":31,"props":102,"children":103},{},[104,106,112,114,120,122,128],{"type":35,"value":105},"Four deliverables: (1) ",{"type":30,"tag":54,"props":107,"children":109},{"className":108},[],[110],{"type":35,"value":111},"research-frameworks.md",{"type":35,"value":113}," — in-depth analysis of the 12-framework union catalog (rules.rs PACKS ∪ frontend catalog): what each framework demands that is runtime-addressable, provable\u002Fattestation\u002Fout-of-scope split, and the policy mappings it implies; (2) ",{"type":30,"tag":54,"props":115,"children":117},{"className":116},[],[118],{"type":35,"value":119},"policy-definitions.md",{"type":35,"value":121}," — the canonical policy roster with stable P-ids: purpose, underlying control rule, config shape + fields, framework mappings, provenance; (3) ",{"type":30,"tag":54,"props":123,"children":125},{"className":124},[],[126],{"type":35,"value":127},"\u002Fpages\u002Fpolicy-catalog",{"type":35,"value":129}," — the main mock: global framework toggles + posture rollup over a categorized policy table with toggles and framework-gap emphasis; (4) first-pass config pages — one page per policy, built almost entirely from ~5 shared config-shape template components (list editor, threshold, level select, detector list, toggle + exceptions), egress allow-list as the deep exemplar. Explicitly NOT solving enforcement modes, violation handling\u002Falerting, or qdash implementation.",{"key":131,"title":132,"empty":16,"ast":133},"scope","Scope",{"type":27,"children":134},[135],{"type":30,"tag":136,"props":137,"children":138},"ul",{},[139,151,170,181,276],{"type":30,"tag":140,"props":141,"children":142},"li",{},[143,149],{"type":30,"tag":54,"props":144,"children":146},{"className":145},[],[147],{"type":35,"value":148},"cycles\u002Fc65.control-center-v2\u002F",{"type":35,"value":150}," — research-frameworks.md, policy-definitions.md",{"type":30,"tag":140,"props":152,"children":153},{},[154,160,162,168],{"type":30,"tag":54,"props":155,"children":157},{"className":156},[],[158],{"type":35,"value":159},"app\u002Fpages\u002Fpages\u002Fpolicy-catalog.vue",{"type":35,"value":161}," + ",{"type":30,"tag":54,"props":163,"children":165},{"className":164},[],[166],{"type":35,"value":167},"app\u002Fpages\u002Fpages\u002Fpolicy-config-*.vue",{"type":35,"value":169}," + page-registry entries",{"type":30,"tag":140,"props":171,"children":172},{},[173,179],{"type":30,"tag":54,"props":174,"children":176},{"className":175},[],[177],{"type":35,"value":178},"app\u002Fcomponents\u002Fpolicy\u002F",{"type":35,"value":180}," — site-local config shell + shape components (layer extraction is a later cycle)",{"type":30,"tag":140,"props":182,"children":183},{},[184,186,192,194,200,202,208,209,215,216,222,223,229,230,236,238,244,245,251,253,259,261,267,268,274],{"type":35,"value":185},"Read-only inputs: qcontrol ",{"type":30,"tag":54,"props":187,"children":189},{"className":188},[],[190],{"type":35,"value":191},"crates\u002Fqdash\u002Fui",{"type":35,"value":193}," (",{"type":30,"tag":54,"props":195,"children":197},{"className":196},[],[198],{"type":35,"value":199},"policy.vue",{"type":35,"value":201},", ",{"type":30,"tag":54,"props":203,"children":205},{"className":204},[],[206],{"type":35,"value":207},"compliance.vue",{"type":35,"value":201},{"type":30,"tag":54,"props":210,"children":212},{"className":211},[],[213],{"type":35,"value":214},"framework.vue",{"type":35,"value":201},{"type":30,"tag":54,"props":217,"children":219},{"className":218},[],[220],{"type":35,"value":221},"controls.vue",{"type":35,"value":201},{"type":30,"tag":54,"props":224,"children":226},{"className":225},[],[227],{"type":35,"value":228},"GovernSheet.vue",{"type":35,"value":201},{"type":30,"tag":54,"props":231,"children":233},{"className":232},[],[234],{"type":35,"value":235},"utils\u002Fframeworks.ts",{"type":35,"value":237},"), ",{"type":30,"tag":54,"props":239,"children":241},{"className":240},[],[242],{"type":35,"value":243},"crates\u002Fqdash\u002Fsrc\u002Frules.rs",{"type":35,"value":161},{"type":30,"tag":54,"props":246,"children":248},{"className":247},[],[249],{"type":35,"value":250},"db.rs",{"type":35,"value":252}," seeds, ",{"type":30,"tag":54,"props":254,"children":256},{"className":255},[],[257],{"type":35,"value":258},"docs\u002Fplan\u002Fqdash-information-architecture.md",{"type":35,"value":260}," §7.5; bob-wire ",{"type":30,"tag":54,"props":262,"children":264},{"className":263},[],[265],{"type":35,"value":266},"c17-governance.ts",{"type":35,"value":161},{"type":30,"tag":54,"props":269,"children":271},{"className":270},[],[272],{"type":35,"value":273},"c17-frameworks.ts",{"type":35,"value":275},"; design c54\u002Fc56\u002Fc64 cycles",{"type":30,"tag":140,"props":277,"children":278},{},[279],{"type":35,"value":280},"Out: qdash code changes, enforcement\u002Fviolation-handling design, layer changes beyond necessity",{"key":282,"title":283,"empty":16,"ast":284},"key-changes","Key Changes",{"type":27,"children":285},[286],{"type":30,"tag":136,"props":287,"children":288},{},[289,319,357,401,422,504,572,582,652,708,747,778,810,860,947,1000],{"type":30,"tag":140,"props":290,"children":291},{},[292,297,299,303,305,310,312,317],{"type":30,"tag":46,"props":293,"children":294},{},[295],{"type":35,"value":296},"Kick-off + decisions (2026-08-12):",{"type":35,"value":298}," vocabulary = ",{"type":30,"tag":46,"props":300,"children":301},{},[302],{"type":35,"value":86},{"type":35,"value":304}," above Controls; framework catalog = ",{"type":30,"tag":46,"props":306,"children":307},{},[308],{"type":35,"value":309},"union of 12",{"type":35,"value":311}," (rules.rs PACKS ∪ frontend catalog — adds HIPAA\u002FGDPR and NIST CSF\u002FISO 27001 to one list); config pages = ",{"type":30,"tag":46,"props":313,"children":314},{},[315],{"type":35,"value":316},"one page per policy leaning on ~5 shared shape templates",{"type":35,"value":318},"; custom-control engine kept as a de-emphasized escape hatch.",{"type":30,"tag":140,"props":320,"children":321},{},[322,332,334,340,342,348,350,355],{"type":30,"tag":46,"props":323,"children":324},{},[325,330],{"type":30,"tag":54,"props":326,"children":328},{"className":327},[],[329],{"type":35,"value":111},{"type":35,"value":331}," (2026-08-12):",{"type":35,"value":333}," per-framework runtime-addressability analysis for all 12 (provable\u002Fattestation\u002Fout-of-scope per IA doc §7.5, ",{"type":30,"tag":54,"props":335,"children":337},{"className":336},[],[338],{"type":35,"value":339},"ok\u002Fpartial\u002Fout",{"type":35,"value":341}," fits following the OWASP LLM01–10 exemplar), a reverse view ranking policies by compliance weight (P8 Credential Protection carries 9 frameworks; P10\u002FP1\u002FP2\u002FP9 next), findings R1–R6 (framework-list drift, hipaa\u002Fgdpr missing from ",{"type":30,"tag":54,"props":343,"children":345},{"className":344},[],[346],{"type":35,"value":347},"valid_pack()",{"type":35,"value":349},", casing drift, crosswalk too coarse, only OWASP LLM has a requirements mapping, framework ",{"type":30,"tag":38,"props":351,"children":352},{},[353],{"type":35,"value":354},"kind",{"type":35,"value":356}," should shape the UI).",{"type":30,"tag":140,"props":358,"children":359},{},[360,369,371,376,378,383,385,391,393,399],{"type":30,"tag":46,"props":361,"children":362},{},[363,368],{"type":30,"tag":54,"props":364,"children":366},{"className":365},[],[367],{"type":35,"value":119},{"type":35,"value":331},{"type":35,"value":370}," the canonical roster — ",{"type":30,"tag":46,"props":372,"children":373},{},[374],{"type":35,"value":375},"17 policies (P1–P17)",{"type":35,"value":377}," in 5 categories (adds Cost & Consumption to \u002Fpolicy's 4), each with purpose, executable underlying rule (rules.rs vocabulary), config shape + fields, defaults (seeded-backed → on), severity, remediation, 12-framework matrix, provenance. Config-shape taxonomy: list editor (P5\u002FP6\u002FP10\u002FP14), threshold (P15\u002FP16\u002FP17), level select (P7\u002FP11), detector list (P8\u002FP9\u002FP12\u002FP13), toggle + exceptions (P1–P4). ",{"type":30,"tag":46,"props":379,"children":380},{},[381],{"type":35,"value":382},"Exceptions replace enforcement modes",{"type":35,"value":384}," — scoped, reasoned, expiring carve-outs instead of the Audit\u002FEnforce cascade. Capability gaps fed back to qcontrol: G1 no negated set operator (allow-lists need the egress ",{"type":30,"tag":54,"props":386,"children":388},{"className":387},[],[389],{"type":35,"value":390},"allowlisted",{"type":35,"value":392}," derived-flag pattern), G2 no injection\u002FPII detector families on ",{"type":30,"tag":54,"props":394,"children":396},{"className":395},[],[397],{"type":35,"value":398},"content",{"type":35,"value":400},", G3 hipaa\u002Fgdpr unrecognized packs. Not carried forward: targets\u002Fcampaigns, the \u002Fpolicy cascade, per-framework control toggles.",{"type":30,"tag":140,"props":402,"children":403},{},[404,413,415,420],{"type":30,"tag":46,"props":405,"children":406},{},[407,412],{"type":30,"tag":54,"props":408,"children":410},{"className":409},[],[411],{"type":35,"value":127},{"type":35,"value":331},{"type":35,"value":414}," the main mock (",{"type":30,"tag":54,"props":416,"children":418},{"className":417},[],[419],{"type":35,"value":159},{"type":35,"value":421},", registered) — 12-framework toggle grid (kind icon, live completeness bar, per-framework \"N gaps — enable\" bulk close), 4-tile posture rollup (posture % = active ÷ required across active frameworks), categorized policy table in the \u002Fpolicy toggle idiom with Enforcement\u002FAlerting columns replaced by compliance chips (active-framework requirements, red when the policy is off = gap), mono underlying-rule line per row, Configure→ links to the config pages, quiet custom-controls footer. One shared reactive model — framework toggles, policy toggles, gaps, and posture all recompute live.",{"type":30,"tag":140,"props":423,"children":424},{},[425,430,432,438,440,446,448,454,456,462,464,470,472,478,480,486,488,494,496,502],{"type":30,"tag":46,"props":426,"children":427},{},[428],{"type":35,"value":429},"Config shell + 5 shape components (2026-08-12):",{"type":35,"value":431}," ",{"type":30,"tag":54,"props":433,"children":435},{"className":434},[],[436],{"type":35,"value":437},"app\u002Fcomponents\u002Fpolicy-config\u002F",{"type":35,"value":439}," (site-local; layer extraction deferred) — ",{"type":30,"tag":54,"props":441,"children":443},{"className":442},[],[444],{"type":35,"value":445},"Shell",{"type":35,"value":447}," (back-link, name + activation toggle, meta strip with SecuritySeverity + satisfies chips, ",{"type":30,"tag":54,"props":449,"children":451},{"className":450},[],[452],{"type":35,"value":453},"\u003Cdetails>",{"type":35,"value":455}," underlying-control disclosure, body dims when inactive, remediation footer), ",{"type":30,"tag":54,"props":457,"children":459},{"className":458},[],[460],{"type":35,"value":461},"Exceptions",{"type":35,"value":463}," (shared section on every policy — scope\u002Fvalue\u002Freason\u002Fexpiry with add\u002Fremove), ",{"type":30,"tag":54,"props":465,"children":467},{"className":466},[],[468],{"type":35,"value":469},"ListEditor",{"type":35,"value":471}," (mutates the passed reactive array so page-level flows can push into it), ",{"type":30,"tag":54,"props":473,"children":475},{"className":474},[],[476],{"type":35,"value":477},"Threshold",{"type":35,"value":479}," (ceiling\u002Ffloor via ",{"type":30,"tag":54,"props":481,"children":483},{"className":482},[],[484],{"type":35,"value":485},"dir",{"type":35,"value":487},", observed-value breach state), ",{"type":30,"tag":54,"props":489,"children":491},{"className":490},[],[492],{"type":35,"value":493},"LevelSelect",{"type":35,"value":495}," (ordered floor, below-floor blast-radius preview), ",{"type":30,"tag":54,"props":497,"children":499},{"className":498},[],[500],{"type":35,"value":501},"DetectorList",{"type":35,"value":503}," (families, per-detector toggle + severity + 24h hits, enable-all).",{"type":30,"tag":140,"props":505,"children":506},{},[507,512,513,519,521,530,532,538,540,546,548,554,556,562,564,570],{"type":30,"tag":46,"props":508,"children":509},{},[510],{"type":35,"value":511},"17 config pages (2026-08-12):",{"type":35,"value":431},{"type":30,"tag":54,"props":514,"children":516},{"className":515},[],[517],{"type":35,"value":518},"policy-config-\u003Cslug>.vue",{"type":35,"value":520}," for P1–P17, all registered — thin shell+shape instantiations from the P-id specs. Deep exemplar = ",{"type":30,"tag":46,"props":522,"children":523},{},[524],{"type":30,"tag":54,"props":525,"children":527},{"className":526},[],[528],{"type":35,"value":529},"policy-config-egress-allowlist",{"type":35,"value":531}," (the prompt's named case): pending non-allowlisted destinations (83-match c64 snapshot framing) with a live approve→list flow, scoped entries (global\u002Fhost\u002Fagent per EgressDecisionModal). Toggle-shaped pages carry a live status band (shadow installs, static-key runs, root runs, never-ask runs). Verified: all 18 routes 200 on the running dev server, SSR content present, no stale classes. Two vocabulary fixes along the way: ",{"type":30,"tag":54,"props":533,"children":535},{"className":534},[],[536],{"type":35,"value":537},"error-surface",{"type":35,"value":539},"\u002F",{"type":30,"tag":54,"props":541,"children":543},{"className":542},[],[544],{"type":35,"value":545},"warning-surface",{"type":35,"value":547}," don't exist in the layer tokens (swapped for ",{"type":30,"tag":54,"props":549,"children":551},{"className":550},[],[552],{"type":35,"value":553},"error\u002F10",{"type":35,"value":555},"-style tints) and there is no ",{"type":30,"tag":54,"props":557,"children":559},{"className":558},[],[560],{"type":35,"value":561},"arrow-left",{"type":35,"value":563}," icon (back-link uses the precedent's ",{"type":30,"tag":54,"props":565,"children":567},{"className":566},[],[568],{"type":35,"value":569},"‹",{"type":35,"value":571}," character).",{"type":30,"tag":140,"props":573,"children":574},{},[575,580],{"type":30,"tag":46,"props":576,"children":577},{},[578],{"type":35,"value":579},"Catalog iteration (2026-08-12):",{"type":35,"value":581}," \"Show inactive (N)\" toggle on the framework strip header — hides non-activated framework cards, live count, defaults to showing all. Later same-day passes: description into its own column (4-col table), shrink-to-fit Policy\u002FConfig columns (width:1% + nowrap), align-middle rows, bare-dash empty state replaced with \"N mapped frameworks — none active\" text, Compliance column header renamed by Mark.",{"type":30,"tag":140,"props":583,"children":584},{},[585,595,597,603,605,610,612,618,620,626,628,634,636,642,644,650],{"type":30,"tag":46,"props":586,"children":587},{},[588,594],{"type":30,"tag":54,"props":589,"children":591},{"className":590},[],[592],{"type":35,"value":593},"\u002Fpages\u002Fcompliance-frameworks",{"type":35,"value":331},{"type":35,"value":596}," visual-semantics iteration page (",{"type":30,"tag":54,"props":598,"children":600},{"className":599},[],[601],{"type":35,"value":602},"compliance-frameworks.vue",{"type":35,"value":604},", registered) — the policy-catalog framework grid duplicated as baseline with the kind label dropped and ComplianceFrameworkIcon replaced by the new ",{"type":30,"tag":46,"props":606,"children":607},{},[608],{"type":35,"value":609},"compliance-shield",{"type":35,"value":611}," art (via ",{"type":30,"tag":54,"props":613,"children":615},{"className":614},[],[616],{"type":35,"value":617},"\u003Cimg>",{"type":35,"value":619},", own brand purples). Inactive state got its own grey-variant svg (",{"type":30,"tag":54,"props":621,"children":623},{"className":622},[],[624],{"type":35,"value":625},"compliance-shield-grey.svg",{"type":35,"value":627},", light half #d4d4d4 — a filter can't split the two halves). Iteration same-day: V2 \"surface semantics\" set added (shared state with V1) — active = white card + grape-400 border, inactive = dashed stroke-strong border on ",{"type":30,"tag":54,"props":629,"children":631},{"className":630},[],[632],{"type":35,"value":633},"surface-sunken-subtle",{"type":35,"value":635}," (one step lighter than the page's ",{"type":30,"tag":54,"props":637,"children":639},{"className":638},[],[640],{"type":35,"value":641},"surface-sunken",{"type":35,"value":643},"); gaps tag → \"Enable Required Policies\" outline button; progress bar de-semanticized (grey-400 fill via inline style — arbitrary Tailwind classes aren't generated on this page — grape-500 only at 100%); toggle micro→tiny with ",{"type":30,"tag":54,"props":645,"children":647},{"className":646},[],[648],{"type":35,"value":649},"-mr-3",{"type":35,"value":651}," flush-right fix (UxToggle keeps its label wrapper's pl-2 + root gap-1 even with an empty label slot — layer nit worth fixing upstream).",{"type":30,"tag":140,"props":653,"children":654},{},[655,660,661,667,669,675,677,683,685,691,693,699,701,706],{"type":30,"tag":46,"props":656,"children":657},{},[658],{"type":35,"value":659},"Layer fix — UxToggle empty-label gap (2026-08-12):",{"type":35,"value":431},{"type":30,"tag":54,"props":662,"children":664},{"className":663},[],[665],{"type":35,"value":666},"q-nuxt-layer\u002Fcomponents\u002Fux\u002FToggle.vue",{"type":35,"value":668}," — the label wrapper div rendered unconditionally, so a label-less toggle carried a 12px phantom on the right (wrapper ",{"type":30,"tag":54,"props":670,"children":672},{"className":671},[],[673],{"type":35,"value":674},"pl-2",{"type":35,"value":676}," + root ",{"type":30,"tag":54,"props":678,"children":680},{"className":679},[],[681],{"type":35,"value":682},"gap-1",{"type":35,"value":684}," as an empty flex item). Root cause of the V2-card alignment issue; the root's ",{"type":30,"tag":54,"props":686,"children":688},{"className":687},[],[689],{"type":35,"value":690},"inline-flex",{"type":35,"value":692}," is load-bearing (track\u002Flabel row, items-center, gap, reverse mode) and must stay. Fix: ",{"type":30,"tag":54,"props":694,"children":696},{"className":695},[],[697],{"type":35,"value":698},"v-if=\"$slots.label\"",{"type":35,"value":700}," on the wrapper. The ",{"type":30,"tag":54,"props":702,"children":704},{"className":703},[],[705],{"type":35,"value":649},{"type":35,"value":707}," page hack removed; labeled toggles verified unaffected. Rides along with ComplianceTag in the next layer release.",{"type":30,"tag":140,"props":709,"children":710},{},[711,721,723,729,731,737,739,745],{"type":30,"tag":46,"props":712,"children":713},{},[714,720],{"type":30,"tag":54,"props":715,"children":717},{"className":716},[],[718],{"type":35,"value":719},"\u002Fpages\u002Fpolicy-catalog-v2",{"type":35,"value":331},{"type":35,"value":722}," expand-row variation (",{"type":30,"tag":54,"props":724,"children":726},{"className":725},[],[727],{"type":35,"value":728},"policy-catalog-v2.vue",{"type":35,"value":730},", registered, non-destructive) — Config column dropped to a 3-column table; each policy row is a ",{"type":30,"tag":54,"props":732,"children":734},{"className":733},[],[735],{"type":35,"value":736},"UxTableListExpandRow",{"type":35,"value":738}," whose card carries the underlying rule (mono, sunken box + custom-control escape hatch), the FULL framework mapping as small ComplianceTags (inactive frameworks dimmed at 40%, error state only when an active framework is unmet), severity + P-id + maturity + remediation, and the \"Open config page →\" link. Activation toggle wrapped in ",{"type":30,"tag":54,"props":740,"children":742},{"className":741},[],[743],{"type":35,"value":744},"@click.stop",{"type":35,"value":746}," so it doesn't fight the row expand. Framework strip\u002Fposture rollup identical to v1.",{"type":30,"tag":140,"props":748,"children":749},{},[750,760,762,768,770,776],{"type":30,"tag":46,"props":751,"children":752},{},[753,759],{"type":30,"tag":54,"props":754,"children":756},{"className":755},[],[757],{"type":35,"value":758},"\u002Fpages\u002Fpolicy-catalog-v3",{"type":35,"value":331},{"type":35,"value":761}," inline-config variation (",{"type":30,"tag":54,"props":763,"children":765},{"className":764},[],[766],{"type":35,"value":767},"policy-catalog-v3.vue",{"type":35,"value":769},", registered) — direct duplicate of v2 with the expand row hosting the policy's ACTUAL config controls: shape components (",{"type":30,"tag":54,"props":771,"children":773},{"className":772},[],[774],{"type":35,"value":775},"\u003Ccomponent :is>",{"type":35,"value":777}," over a shape→component map — explicit imports, since resolveComponent can't see auto-imports) + the shared Exceptions section, fed by the same config snapshots the policy-config-* pages carry (CONFIGS\u002FEXCEPTIONS keyed by P-id). Identity strip (rule · severity · P-id · maturity · escape hatch) above the config; config dims at 50% when the policy is off (the config-shell idiom). Poses the open question: do the standalone config pages survive, or is the catalog the config surface?",{"type":30,"tag":140,"props":779,"children":780},{},[781,786,788,801,803,808],{"type":30,"tag":46,"props":782,"children":783},{},[784],{"type":35,"value":785},"Gap-cluster + pill polish (2026-08-12):",{"type":35,"value":787}," exclaim circle sized up to h-5 with an italic muted \"Required\" label after it (gap rows only); Beta pill iterated warning-amber → grey → light blue → ",{"type":30,"tag":46,"props":789,"children":790},{},[791,793,799],{"type":35,"value":792},"grey body with a ",{"type":30,"tag":54,"props":794,"children":796},{"className":795},[],[797],{"type":35,"value":798},"#318bc4",{"type":35,"value":800},"\u002F60% blue border",{"type":35,"value":802}," (Roadmap = full grey) — blue applied via style binding since one-off arbitrary color classes don't generate on pages; ",{"type":30,"tag":54,"props":804,"children":806},{"className":805},[],[807],{"type":35,"value":798},{"type":35,"value":809}," is a token candidate if a layer blue ramp ever lands.",{"type":30,"tag":140,"props":811,"children":812},{},[813,818,820,826,828,834,836,842,844,850,852,858],{"type":30,"tag":46,"props":814,"children":815},{},[816],{"type":35,"value":817},"ComplianceTag gap variant (2026-08-12):",{"type":35,"value":819}," third state on the tag — ",{"type":30,"tag":54,"props":821,"children":823},{"className":822},[],[824],{"type":35,"value":825},"gap",{"type":35,"value":827},": muted grey pill + grey shield for required-but-off, with ONE page-side exclaim circle (UxIcon ",{"type":30,"tag":54,"props":829,"children":831},{"className":830},[],[832],{"type":35,"value":833},"exclaim",{"type":35,"value":835}," in a red-tinted rounded-full span) placed inline after the tag cluster rather than marking every tag. All three catalog pages swapped from ",{"type":30,"tag":54,"props":837,"children":839},{"className":838},[],[840],{"type":35,"value":841},":error",{"type":35,"value":843}," to ",{"type":30,"tag":54,"props":845,"children":847},{"className":846},[],[848],{"type":35,"value":849},":gap",{"type":35,"value":851}," + cluster exclaim; the red ",{"type":30,"tag":54,"props":853,"children":855},{"className":854},[],[856],{"type":35,"value":857},"error",{"type":35,"value":859}," variant remains for loud failure contexts. Demo + registry docs updated.",{"type":30,"tag":140,"props":861,"children":862},{},[863,868,870,876,878,884,885,891,893,898,900,906,908,914,916,922,924,930,932,938,939,945],{"type":30,"tag":46,"props":864,"children":865},{},[866],{"type":35,"value":867},"ComplianceToggleCard extraction + component docs (2026-08-12):",{"type":35,"value":869}," the settled framework card extracted to the layer as ",{"type":30,"tag":54,"props":871,"children":873},{"className":872},[],[874],{"type":35,"value":875},"compliance\u002FToggleCard.vue",{"type":35,"value":877}," (props name\u002Factive\u002Fpercent\u002Fsatisfied\u002Frequired\u002Fgaps\u002FgapTitle, emits toggle + enable-gaps; shield art from layer assets, grey bar fill inline to dodge consumer-scan issues); both grids (",{"type":30,"tag":54,"props":879,"children":881},{"className":880},[],[882],{"type":35,"value":883},"policy-catalog",{"type":35,"value":201},{"type":30,"tag":54,"props":886,"children":888},{"className":887},[],[889],{"type":35,"value":890},"compliance-frameworks",{"type":35,"value":892}," V2) now consume it — V1 stays inline as the baseline artifact. ComplianceTag gained ",{"type":30,"tag":54,"props":894,"children":896},{"className":895},[],[897],{"type":35,"value":857},{"type":35,"value":899}," (red two-tone shield ",{"type":30,"tag":54,"props":901,"children":903},{"className":902},[],[904],{"type":35,"value":905},"compliance-shield-error.svg",{"type":35,"value":907}," + error border\u002Ftext) and ",{"type":30,"tag":54,"props":909,"children":911},{"className":910},[],[912],{"type":35,"value":913},"size",{"type":35,"value":915}," ('small' | 'medium', UxToggle convention); small got a py bump; catalog table gap chips → ",{"type":30,"tag":54,"props":917,"children":919},{"className":918},[],[920],{"type":35,"value":921},"\u003CComplianceTag size=\"small\" error>",{"type":35,"value":923},". Both components documented: new ",{"type":30,"tag":54,"props":925,"children":927},{"className":926},[],[928],{"type":35,"value":929},"compliance",{"type":35,"value":931}," group in component-registry (also fixes ComplianceFrameworkIcon's dangling group id), registry entries with coverage, interactive demos (",{"type":30,"tag":54,"props":933,"children":935},{"className":934},[],[936],{"type":35,"value":937},"_demos\u002FComplianceTag.vue",{"type":35,"value":201},{"type":30,"tag":54,"props":940,"children":942},{"className":941},[],[943],{"type":35,"value":944},"_demos\u002FComplianceToggleCard.vue",{"type":35,"value":946},"), and a Compliance section on the \u002Fcomponents visual index.",{"type":30,"tag":140,"props":948,"children":949},{},[950,955,956,962,964,970,972,978,980,986,988,993,995],{"type":30,"tag":46,"props":951,"children":952},{},[953],{"type":35,"value":954},"Layer component — ComplianceTag (2026-08-12):",{"type":35,"value":431},{"type":30,"tag":54,"props":957,"children":959},{"className":958},[],[960],{"type":35,"value":961},"q-nuxt-layer\u002Fcomponents\u002Fcompliance\u002FTag.vue",{"type":35,"value":963}," — small reusable compliance tag: shield mark + framework name in a grape-50 pill (grape-400 border, grape-600 bold label), optional ",{"type":30,"tag":54,"props":965,"children":967},{"className":966},[],[968],{"type":35,"value":969},"removable",{"type":35,"value":971}," ✕ emitting ",{"type":30,"tag":54,"props":973,"children":975},{"className":974},[],[976],{"type":35,"value":977},"@remove",{"type":35,"value":979},", label via default slot. Shield asset resolved from the layer's own assets at build (",{"type":30,"tag":54,"props":981,"children":983},{"className":982},[],[984],{"type":35,"value":985},"?url",{"type":35,"value":987}," import, AgentPawn pattern). Demo strip added to ",{"type":30,"tag":54,"props":989,"children":991},{"className":990},[],[992],{"type":35,"value":593},{"type":35,"value":994}," (static, removable, and live-wired tags that deactivate frameworks on remove). Confirmed the design dev server runs NUXT_LOCAL_LAYER (picked the component up without a release). ",{"type":30,"tag":46,"props":996,"children":997},{},[998],{"type":35,"value":999},"Not yet in a layer release — run \u002Frelease-layer (→ v0.9.8) before tarball consumers can use it; component not yet added to the design-site component docs.",{"type":30,"tag":140,"props":1001,"children":1002},{},[1003,1008,1009,1015,1017,1023,1025,1031,1033,1038,1040,1045,1046,1052,1054,1059,1061,1067,1068,1074,1076,1082,1084,1090,1092,1098],{"type":30,"tag":46,"props":1004,"children":1005},{},[1006],{"type":35,"value":1007},"qcontrol application (2026-08-12):",{"type":35,"value":431},{"type":30,"tag":54,"props":1010,"children":1012},{"className":1011},[],[1013],{"type":35,"value":1014},"qcontrol-application.md",{"type":35,"value":1016}," written (reuse model, hybrid persistence map, backend backlog B1–B8, supersession map). The six policy-config components extracted to the layer as controlled components (emit contracts: add\u002Fremove\u002Fchange\u002Ftoggle\u002Ftoggle-all\u002Ffloor; arbitrary classes → inline styles; Shell gained the white bg-surface content box + backTo\u002FbackLabel props + ComplianceTag satisfies chips) — design locals deleted, all 17 config pages + v3 rewired to the new contracts (v3 imports via ",{"type":30,"tag":54,"props":1018,"children":1020},{"className":1019},[],[1021],{"type":35,"value":1022},"#components",{"type":35,"value":1024},"), registry ",{"type":30,"tag":54,"props":1026,"children":1028},{"className":1027},[],[1029],{"type":35,"value":1030},"policy-config",{"type":35,"value":1032}," group + 6 entries + 6 demos added. ",{"type":30,"tag":46,"props":1034,"children":1035},{},[1036],{"type":35,"value":1037},"Layer v0.9.8 released",{"type":35,"value":1039}," (commit 4708cf2, tag-driven CI publish, all 5 consumer lockfiles re-resolved — qcontrol's git#main ref included). ",{"type":30,"tag":46,"props":1041,"children":1042},{},[1043],{"type":35,"value":1044},"qdash c13 executed:",{"type":35,"value":431},{"type":30,"tag":54,"props":1047,"children":1049},{"className":1048},[],[1050],{"type":35,"value":1051},"\u002Fcontrols",{"type":35,"value":1053}," replaced by the policy catalog (framework strip + 17-policy expand-row table + custom-controls escape section), ",{"type":30,"tag":54,"props":1055,"children":1057},{"className":1056},[],[1058],{"type":35,"value":59},{"type":35,"value":1060}," deleted, one ",{"type":30,"tag":54,"props":1062,"children":1064},{"className":1063},[],[1065],{"type":35,"value":1066},"controls\u002Fdetail.vue",{"type":35,"value":193},{"type":30,"tag":54,"props":1069,"children":1071},{"className":1070},[],[1072],{"type":35,"value":1073},"?policyId=",{"type":35,"value":1075},") serving all policies, hybrid persistence (egress via ",{"type":30,"tag":54,"props":1077,"children":1079},{"className":1078},[],[1080],{"type":35,"value":1081},"\u002Fapi\u002Fegress-decisions",{"type":35,"value":1083},", P15\u002FP17 thresholds via real control rule rewrites with dry-run, rest via ",{"type":30,"tag":54,"props":1085,"children":1087},{"className":1086},[],[1088],{"type":35,"value":1089},"usePolicyState",{"type":35,"value":1091}," localStorage). Verified: 11\u002F11 headless DOM checks, live API round-trips, 137 vitest, dist regenerated. See ",{"type":30,"tag":54,"props":1093,"children":1095},{"className":1094},[],[1096],{"type":35,"value":1097},"qcontrol crates\u002Fqdash\u002Fui\u002Fcycles\u002Fc13.control-policies\u002FCYCLE.md",{"type":35,"value":1099},".",{"key":1101,"title":1102,"empty":16,"ast":1103},"outcome","Outcome",{"type":27,"children":1104},[1105],{"type":30,"tag":31,"props":1106,"children":1107},{},[1108,1110,1115,1117,1122,1124,1129,1131,1137],{"type":35,"value":1109},"The full arc shipped in one cycle: research (12-framework analysis + P1–P17 policy definitions with stable IDs) → design-site mocks (policy-catalog v1\u002Fv2\u002Fv3, 17 config pages, compliance-frameworks iteration surface) → layer components (ComplianceTag, ComplianceToggleCard, the policy-config six, UxToggle fix — released as v0.9.8) → qcontrol application (qdash c13: ",{"type":30,"tag":54,"props":1111,"children":1113},{"className":1112},[],[1114],{"type":35,"value":1051},{"type":35,"value":1116}," IS the policy catalog, ",{"type":30,"tag":54,"props":1118,"children":1120},{"className":1119},[],[1121],{"type":35,"value":59},{"type":35,"value":1123}," retired). Backend follow-ons specified in ",{"type":30,"tag":54,"props":1125,"children":1127},{"className":1126},[],[1128],{"type":35,"value":1014},{"type":35,"value":1130}," (B1–B8). Design-site mocks remain as the iteration surface; qdash work sits uncommitted on ",{"type":30,"tag":54,"props":1132,"children":1134},{"className":1133},[],[1135],{"type":35,"value":1136},"feat\u002Fcontrol-center",{"type":35,"value":1138}," for review.",[],[1141,119,1014,111],"initial-prompt.md",[1143,1148,1152,1156,1160,1163,1167,1171,1175,1179,1183,1187,1191,1195,1199,1203,1207,1211,1215,1219,1223,1226,1229,1233,1236,1239,1242],{"src":1144,"kind":1145,"order":1146,"caption":1147},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-egress-allowlist.png","hero",0,"Policy Config — Egress Allow-List — c65 P10 — list-editor shape, the deep exemplar: pending non-allowlisted destinations with live approve-into-list flow, scope",{"src":1149,"kind":1145,"order":1150,"caption":1151},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-agent-registration.png",1,"Policy Config — Agent Registration — c65 P1 — toggle + exceptions shape, shadow-AI status band, scoped carve-outs with reason + expiry",{"src":1153,"kind":1145,"order":1154,"caption":1155},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-org-backed-identity.png",2,"Policy Config — Org-Backed Identity — c65 P2 — toggle + exceptions shape, static-key run status, service-account exception",{"src":1157,"kind":1145,"order":1158,"caption":1159},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-no-root-execution.png",3,"Policy Config — No Root Execution — c65 P3 — toggle + exceptions shape, live privileged-run status",{"src":1161,"kind":1145,"order":19,"caption":1162},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-require-tool-approval.png","Policy Config — Require Tool Approval — c65 P4 — toggle + exceptions shape, never-ask run status, batch-pipeline exception",{"src":1164,"kind":1145,"order":1165,"caption":1166},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-tool-allowlist.png",5,"Policy Config — Tool Allow-List — c65 P5 — list-editor shape, approved tools with glob patterns and global\u002Fagent scope",{"src":1168,"kind":1145,"order":1169,"caption":1170},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-mcp-allowlist.png",6,"Policy Config — MCP Server Allow-List — c65 P6 — list-editor shape, approved MCP servers (the tool-supply-chain control)",{"src":1172,"kind":1145,"order":1173,"caption":1174},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-sandbox-required.png",7,"Policy Config — Sandbox Required — c65 P7 — level-select shape, sandbox-mode floor with live below-floor blast radius",{"src":1176,"kind":1145,"order":1177,"caption":1178},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-credential-protection.png",8,"Policy Config — Credential Protection — c65 P8 — detector-list shape, sensitive-path categories with severity + 24h opens",{"src":1180,"kind":1145,"order":1181,"caption":1182},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-data-redaction.png",9,"Policy Config — Data Redaction — c65 P9 — detector-list shape, Secrets + PII\u002FPHI families (the HIPAA\u002FGDPR carrier)",{"src":1184,"kind":1145,"order":1185,"caption":1186},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-tls-floor.png",10,"Policy Config — TLS Floor — c65 P11 — level-select shape, TLS version ladder with SP 800-52 minimum and weak-TLS counts",{"src":1188,"kind":1145,"order":1189,"caption":1190},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-prompt-inspection.png",11,"Policy Config — Prompt Inspection — c65 P12 — detector-list shape, injection heuristics (detect & contain, honest-partial)",{"src":1192,"kind":1145,"order":1193,"caption":1194},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-output-validation.png",12,"Policy Config — Output Validation — c65 P13 — detector-list shape, output detectors before downstream tools act",{"src":1196,"kind":1145,"order":1197,"caption":1198},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-provenance-pinning.png",13,"Policy Config — Provenance Pinning — c65 P14 — list-editor shape, pinned model\u002Ftool sources (pin-at-load, honest-partial)",{"src":1200,"kind":1145,"order":1201,"caption":1202},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-spend-ceiling.png",14,"Policy Config — Spend Ceiling — c65 P15 — threshold shape, fleet\u002Fper-run ceilings with observed values and breach state",{"src":1204,"kind":1145,"order":1205,"caption":1206},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-quota-compliance.png",15,"Policy Config — Quota Compliance — c65 P16 — threshold shape, quota warning levels; overage rejections always flag",{"src":1208,"kind":1145,"order":1209,"caption":1210},"\u002Fcycles\u002Fdesign\u002Fc65-policy-config-posture-floor.png",16,"Policy Config — Posture Floor — c65 P17 — threshold shape with floor direction, minimum posture score vs fleet reality",{"src":1212,"kind":1145,"order":1213,"caption":1214},"\u002Fcycles\u002Fdesign\u002Fc65-control-verification.png",34,"POL-701 — Independent verification that agent connections are governed",{"src":1216,"kind":1145,"order":1217,"caption":1218},"\u002Fcycles\u002Fdesign\u002Fc65-policy-catalog-v2.png",42,"c65 iteration — Config column dropped; policy rows expand (UxTableListExpandRow) to the underlying rule, full framework mapping with inactive dimmed, severity\u002Fremediation, and the config-page link",{"src":1220,"kind":1145,"order":1221,"caption":1222},"\u002Fcycles\u002Fdesign\u002Fc65-policy-catalog-v3.png",43,"c65 iteration — direct duplicate of v2 with the config controls inside the expand row: shape components (list editor \u002F threshold \u002F level select \u002F detector list) + Exceptions inline, config dims when the policy is off",{"src":17,"kind":1145,"order":1224,"caption":1225},44,"c65 iteration surface — the policy-catalog framework grid as baseline: kind label dropped, compliance-shield art in place of the kind icon, same live completeness\u002Fgap mechanics",{"src":1227,"kind":1145,"order":1228},"\u002Farchive\u002F2026-q3\u002Fc65-policy-catalog.png",4999,{"src":1230,"kind":1231,"order":1232},"\u002Farchive\u002F2026-q3\u002Fc65-policy-catalog-full.png","full",9000,{"src":1234,"kind":1231,"order":1235},"\u002Fcycles\u002Fdesign\u002Fc65-control-verification-full.png",9034,{"src":1237,"kind":1231,"order":1238},"\u002Fcycles\u002Fdesign\u002Fc65-policy-catalog-v2-full.png",9042,{"src":1240,"kind":1231,"order":1241},"\u002Fcycles\u002Fdesign\u002Fc65-policy-catalog-v3-full.png",9043,{"src":1243,"kind":1231,"order":1244},"\u002Fcycles\u002Fdesign\u002Fc65-compliance-frameworks-full.png",9044,[1246],{"path":1247,"title":1248,"image":1227,"gallery":1249},"archive\u002F2026-q3\u002F2026-08-12-c65-policy-catalog","Policy Catalog",[1250,1252],{"src":1227,"alt":1251},"The policy catalog mock — compliance-driven pre-defined policies with P-ids.",{"src":1230,"alt":1253},"Policy Catalog — full page",[1255,1256,1258,1259,1260,1262,1264,1266,1268,1270,1272,1274,1276,1278,1280,1282,1284,1286,1288,1290,1292],{"route":593,"href":593},{"route":1257,"href":1257},"\u002Fpages\u002Fcontrol-verification",{"route":719,"href":719},{"route":758,"href":758},{"route":1261,"href":1261},"\u002Fpages\u002Fpolicy-config-agent-registration",{"route":1263,"href":1263},"\u002Fpages\u002Fpolicy-config-credential-protection",{"route":1265,"href":1265},"\u002Fpages\u002Fpolicy-config-data-redaction",{"route":1267,"href":1267},"\u002Fpages\u002Fpolicy-config-egress-allowlist",{"route":1269,"href":1269},"\u002Fpages\u002Fpolicy-config-mcp-allowlist",{"route":1271,"href":1271},"\u002Fpages\u002Fpolicy-config-no-root-execution",{"route":1273,"href":1273},"\u002Fpages\u002Fpolicy-config-org-backed-identity",{"route":1275,"href":1275},"\u002Fpages\u002Fpolicy-config-output-validation",{"route":1277,"href":1277},"\u002Fpages\u002Fpolicy-config-posture-floor",{"route":1279,"href":1279},"\u002Fpages\u002Fpolicy-config-prompt-inspection",{"route":1281,"href":1281},"\u002Fpages\u002Fpolicy-config-provenance-pinning",{"route":1283,"href":1283},"\u002Fpages\u002Fpolicy-config-quota-compliance",{"route":1285,"href":1285},"\u002Fpages\u002Fpolicy-config-require-tool-approval",{"route":1287,"href":1287},"\u002Fpages\u002Fpolicy-config-sandbox-required",{"route":1289,"href":1289},"\u002Fpages\u002Fpolicy-config-spend-ceiling",{"route":1291,"href":1291},"\u002Fpages\u002Fpolicy-config-tls-floor",{"route":1293,"href":1293},"\u002Fpages\u002Fpolicy-config-tool-allowlist",1789151081957]