Source: c81 phase1-pages — Fleet Overview (PRO-19); fleet-overview-v3's spine with the c68 exception queue restored, the report-card-minidocs-v2 briefing skeleton on the gateway cards, re-derived from the phase1 world as a summary of the other 16 pages
11 things need attention in 7 of 12 areas — 2 of them red.
a personal ChatGPT account · a credential read (redacted) · +9 more, below
Exception queue
11 · owned by 7 of 12 areas, echoed on 5 more · red first, then trust → identity → accounts → surface 2 open · 9 on one line —Dana Whitfield runs ChatGPT on a personal account beside the enterprise org — user-dw72hfqb (dwhitfield.72@gmail.com), 2 sessions this week
~/.aws/credentials read by Marcus Chen's Codex CLI in qpoint/infra — redacted by policy, Aug 19
On file, not in the queue: postgres-prod.query denied ×1 — policy working Tools → · 2 secrets read in the course of work — qplane/.env.local, qtap-installer-win/certs/qpoint-codesign.p12 Files →
▲3 people without a sensor — Alexis Romero holds an enterprise seat · 1 more
✗Dana's personal ChatGPT account beside the enterprise org · 3 more
✗~/.aws/credentials read by Marcus Chen's Codex CLI, redacted · 4 more
The four c78 report mocks, on the report world — not derived from this estate, not rebuilt here.
using AI = at least one install observed, or 30-day usage on record · active = last seen within 24h · 1 install has no owner and counts in installs only · the arrow into installs changes grain from people to installs
Composition notes
- Question: is anything wrong across the estate — and where do I go to deal with it? The landing is a summary of the other pages (Tyler: "really just a summary of those reports"). It owns judgment: the count, the tone, the rank, the drill target it offers. It owns no nouns.
- Verdict line from fleetOverviewVerdict(world) (derived/fleet-overview.ts, a sharpened verdicts.fleetOverview — fold-in): counts entity-resolved exceptions, prints the spread as areas that own one, names the kinds red-first in the sub. The calm morning names the estate and the receipts.
- Exception queue is entity-resolved, not per page. Eleven of twelve areas light in the attention world, but the story beats cascade — the unreviewed browser server lights MCP servers, Tools and Endpoints; Hermes lights Inventory, Providers, Models and Accounts (c78's cross-report finding). A queue of page verdicts would be eleven rows of five stories, i.e. a nav menu with tone. So each row is one exception, derived from the same predicate its home page's verdict uses, tagged with the area that owns the number (a grey label — the tone border is the row's one device), linked there pre-selected, with the areas that echo it as quiet "also on" links. Subjects are Phase1EntityChips — the actor web leaves the page from every row. The queue is as short as the verdict: red items open as full cards, amber items collapse to one headline line each with "show all n" — so the first fold holds the queue and the trust band together.
- Receipts are not attention debt (ruling made here, for Stage 5): a reviewed-and-denied call is policy working; secrets read in the course of work are a receipt, never a target (c67). They print under the queue in both states and are never counted. Tools and Files currently tone their verdicts amber for them on the calm morning; Repos, looking at the same two secrets, reads clear with the receipt in its sub. The card footer marks such a page receipt in grey instead of an amber dot, so the operator is told what the page will look like and why it does not count.
- Trust band = four Phase1StatBlock claims with links (people covered → Teams · installs monitored → Inventory · accounts enterprise → Accounts · destinations allowlisted → Endpoints). One attention device: the block with the worst tone lights (red beats amber, ties go to trust-first order); the others state their gap in neutral tone. When that block is red, only the red-class fragment of its sub is printed in red (the personal account); the amber facts it would otherwise append are already cards in the queue above, so the sub does not repeat them.
- Gateway cards wear the report-card-minidocs-v2 briefing skeleton without the paper: masthead rule · one alarm line with the tone glyph (the group's worst exception, or the calm claim) · a register of two or three claims the band does not already print, each linking to its owner · a filing footer listing every page in the group. The footer dot lights only where an exception is homed; a page that merely echoes one (the same Hermes on Providers, Models and Accounts; the representative's user or device page) prints echo in grey, the way the queue prints "also on" — otherwise the footer is eleven rows of the same five stories. Detail pages get a representative id the overview chooses — the person, session, device and install the exceptions name; on the calm morning the heaviest user, the latest session on record, the busiest device, the freshest install. Session detail stays amber in both states for the blocked-tool session: history does not change with posture. The Reports card is four quiet links to the c78 report mocks on the report world — not derived from this estate, not rebuilt.
- Funnel footer from fleetFunnel(world): people known → covered → using AI → installs → monitored → active 24h, definitions printed, the grain change named. The estate counts are wallpaper with links; the derived new this week from firstSeen is the judgment (counts are wallpaper, deltas are judgment — c68 v2). Tokens and dollars are deliberately absent: spend is Cost Center's and Models' number, not the landing's.
- Ownership seams — what this page does not restate: no person rows (Teams), no install grid or technology rollup (Inventory), no per-provider share bars (Providers), no per-account seat lists (Accounts), no per-page filter bands, no tokens or dollars, and none of the pages' own sub-line receipts. The band prints four fractions as claims whose home is the linked page; nothing beneath a fraction — the who, the which — is repeated here except as a chip that leaves the page.
- Areas are the 12 listing pages. User, Session, Device and Agent detail take an id and hold no fleet-scope verdict — they are drill targets, so the verdict says "of 12", not "of 16".
- Open: whether the queue should fold echo-only areas into the owning row's chips instead of an "also on" line; eleven kinds in the verdict sub is long — a real Monday carries fewer, but a cap ("… and 4 more") may still be wanted; the word "areas" vs "pages"; whether verdicts.tools / verdicts.files should adopt the receipt ruling so tone and count agree everywhere.