Phase 1
Repos
Source: c81 phase1-pages — Repos (PRO-33); c12 repos grammar (owner routing, sensitive-file cluster) + inventory-companies-v1 repo directory + inventory-agent-expand-v2 Repos panel, re-derived from the phase1 world
fixture state
7 repos from observed cwd, 6 active this week — 1 had a credential file read by an agent.
qpoint/infra — ~/.aws/credentials, Marcus Chen's Codex CLI, redacted · 2 secrets touched (Files)
6
people working with AI in them
of 18 people known to Okta
10
installs
of 28 installs · with a repo from cwd
Repos
identity derived from the session working directory · ranked credential reads first, then sensitive touches, then sessions this weekOwner | People | Installs | Sessions · 7d | Tokens · 7d | Sensitive files | Last session | |
|---|---|---|---|---|---|---|---|
⑂qpoint/infra ~/code/infra | Engineering→ | 1 | 1 | 0 | 0 | 1 credential, redacted | 12d ago on record, not this week |
⑂qpoint/qplane ~/code/qplane | Engineering→ | 3 | 4 | 5 | 7.5M | 1 secret | 2d ago |
⑂qpoint/qtap-installer-win ~/code/qtap-installer-win | KRKamal Reddy→ | 1 | 3 | 4 | 5.7M | 1 secret | 4h ago |
⑂qpoint/qplane-ui ~/code/qplane-ui | Engineering→ | 2 | 2 | 4 | 6.4M | 0 | 3h ago |
⑂qpoint/qtap ~/code/qtap · ~/src/qtap | Engineering→ | 3 | 4 | 4 | 8.7M | 0 | 3h ago |
⑂qpoint/qtap-tools ~/code/qtap-tools | JFJonah Fitz→ | 1 | 1 | 3 | 2.5M | 0 | 8h ago |
⑂qpoint/qbench ~/code/qbench | MCMarcus Chen→ | 1 | 2 | 2 | 4.2M | 0 | 7h ago |
7 repos from observed cwd; 6 people of 18 and 10 installs of 28 have a repo on record. Sessions and tokens are the 7-day sample on record; older scenario sessions print as "on record". Dollars are estimates (tokens × blended model rate). Owner is a routing assignment (team, or a person for single-owner tools), not a sensor observation.
Composition notes
- Question: where is AI working in our code — which repos have agents in them, who is working there, and did any of that work touch a sensitive file? Repo identity is derived from the session working directory (c59 T2); the page says so on the surface and claims nothing the cwd cannot tell it — no commits, no PRs, no "what this repo is about".
- Verdict line from reposVerdict(world) (a sharper twin of verdicts.repos, listed as a fold-in): repos from cwd, how many had sessions this week (6 of 7 — qpoint/infra's only session is 12 days old, so the brief's "7 with sessions this week" would be false), people and installs, and the credential read. Two grains of "sensitive" are kept apart: a flagged read (a policy-redacted file_access or a credential-category file — red, the same tone the verdict and band give it) vs a secret touched in the course of work (a receipt — counted, content-colored, pointed at Files). The clear state is calm because the receipt's home is the Files page.
- Framing band = the brief's four claims: repos (reset button), people working with AI in them (of 18 — denominator printed), installs (of 28), credential reads (the one attention device, a filter button, names the repo). People and installs are plain blocks — nobody filters repos by "has people".
- Table is the raw UxTableList family so ?id= can pre-open a row (inventory.vue pattern). Rows from repoRollup(world), pre-ranked flagged reads → sensitive touches → sessions this week; search rides the Repo header (name, cwd, owner, people). Owner is a team chip or a person chip (c12 owner routing). A cwd with no remote would render as a workspace — the cwd as its name, "workspace · no remote", no owner, no warning color; none exists in this world, and none was fabricated (an unreferenced workspace would be a row with zero installs, which the sensor could never produce).
- Expand = four UxTableListExpandSection cards on a bare row: header (identity caveat, owner, first/last seen, headline stats, the honest "view details →" stub — Surface pages are listing + expand in Phase 1), people & installs (person chips → User detail; agent chips → Agent detail, sub = detected-only / stale where true), sessions on record (→ Session detail; the row prints each session's own one-line summary — a session fact, not a repo narrative), and the sensitive-file cluster (file chips → Files, category, sensitivity, read/write/edit, the sessions that touched it, policy column). No prompt-topic mining anywhere: nothing aggregates session lines into "this repo is mostly X".
- Derivation: every number traces to repoRollup / reposBand / sensitiveTouchesForSessions; the band cross-foots with the visible rows under the sensitive filter; 7d and on-record are never mixed on one row; dollars are labelled estimates. The layer has no github icon (agent-expand-v2's known gap) — the repo glyph is mono ⑂.
- Open: workspaces have no carrier in the world (Stage 5 could add one repo with no remote and put it in one instance's repoIds); whether ordinary secrets should echo Files' attention tone here; defaultBranch is stored but unearned at T1 (cwd cannot know it) and stays off the surface.