Source: qdash / (Fleet Overview) — design-pass concepts, 2026-08-03
The Overview answers "are we exposed?" but not the other two beats of the CISO Monday-morning read — "what changed since Friday" and "what needs my decision" — and the activity timeline the north star names was never built. Eight concepts, fully rendered against the Meridian world (34 monitored agents · 14 users · 39 installs · 87% coverage · $4.2k/90d). Ideas 1–5 complete the console read; ideas 6–8 make it an overview — people, things, and meaning, not only metrics. It is Monday; the weekend brought sofia's secrets.yaml finding (Fri), felix's egress destination (Sun), and a Windsurf install on chen-mba (Sun).
The headline answer
The scorecard answers the one question if you read six rows. One synthesized sentence answers it in genuinely ten seconds, and a delta digest makes "since Friday" a first-class object. Everything below is computable from data the page already fetches.
Mostly on target — 5 of 7 dimensions green. The weekend brought 1 new high-severity finding and 1 new shadow install; 3 decisions are waiting.
Needs your decision
The product's core loop is making a decision, yet the Overview never shows the pending queue. Three cards, named verbs (the owning control's decisions, not generic status). The buttons deep-link into the one canonical decision surface — the finding modal — so this is a queue, not a second surface.
The scorecard grows a Δ column
The keystone keeps its shape; a "Δ since Fri" column lands between current and status. Note the Coverage row — on target yet slipping — a state the current page cannot express. Also folded in: honest cells for the two incoherences (no-target rows render neutral, never a house default; no-history trends render "—", never a borrowed series).
| Dimension | What good looks like | Where we are | Δ since Fri | Status | Trend (90d) | Action |
|---|---|---|---|---|---|---|
| Security posture | avg score ≥ 80 | 84 avg | +3 recovering | on target | ▲ 84 | open Security Posture → |
| High-severity findings | 0 high-severity | 2 high | +1 felix's egress · Sun | gap | ▲ 2 | work Findings → |
| Unexpected egress | 0 unapproved destinations | 1 destination | +1 metrics.coderelay.io | gap | ▲ 1 | decide in Findings → |
| Monitoring coverage | ≥ 80% installs monitored | 87% (34/39) | −2pts new shadow install | on target | ▾ 87% | onboard in Inventory → |
| Spend | ≤ $1.5k / 30d | $1.34k 30d | +$132 | on target | ▲ $1.34k | review Campaigns → |
| Token throughput | no target — set one | — | — | no target | — | set a target → |
| Compliance evidence | 0 findings unmapped | 3 unmapped | ±0 | gap | — | review evidence gaps → |
The activity timeline
The north star's per-tab spec: "the scorecard… below: activity timeline and the exceptions strip." The timeline never got built. It gives the page its narrative — why did the trend move? — and it's reconstructed entirely from timestamps already stored (finding first_seen, decisions, install discoveries, agent first_seen).
Adoption & growth
The page is entirely risk-and-cost framed, but "an overview of all agent usage in the company" also means the growth question: is it spreading, who's new, on what tools? Summarize + deep-link to Teams/Inventory — never re-list their tables.
The crew — people first
"14 users" is a count; this is the fleet as a crew. Every person, grouped by team, with their agents as pawns carrying live state. Who's running what right now, who's new, who's the outlier, who's gone quiet — readable at a glance, before any number.
What the fleet is doing
Meaning, not telemetry: the running agents described as work. The verb lines are derivable from data qdash already has (cwd/repo, tool-call mix, last command); deeper task inference from prompt content is staged capability and says so.
The fleet portrait
The whole system in one picture: people → harnesses → where the traffic goes. Ribbon width is observed volume; amber dashed is the traffic we can't see (shadow installs, local models); the red ribbon is Sunday's undecided destination. The interactive version of this picture is qmap's territory — this is the standing glance.
The composed page
Two ways the pieces could stack. A is the console read (the funnel: verdict → decide → measure → explain). B leads with the living fleet — people and the portrait — and lets the scorecard follow. The likely answer is A's spine with B's crew + portrait as the middle band.