Pages
Teams & Users — Strip Horizons

Source: qdash /teams — c67 expansion round, 2026-08-15

The lever strip is settled; this round widens the aperture: what additional data exists (or could cheaply exist), and what windows of insight it opens — including the less-defensible territory, explored honestly. Every window carries a tier, a named danger, and a persona. One line gets drawn on purpose. All schema claims verified against qcontrol source (db.rs · normalize.rs · web.rs) this session.

buildable today named confounds / modest capture speculative, worth wanting fantasy (today)dangers: Goodhart · privacy · counterfactual · composite · fabrication
Corrections

The schema knows more than the page

Five discoveries from reading the ingest and schema code — each one re-tiers windows we had filed as unbuildable.

file_access is live

Path, category (e.g. secret_file), severity, opens, first/last seen — normalize.rs projects sensitive file.opens into it. File-level sensitivity classification exists; only repo-level is missing.

unlocks: sensitive-touch surface ✓ · secret dwell context

quota posture is captured

agent_instances.quota_5h/quota_7d/quota_status from provider rate-limit metadata, with an explicit overage_rejected promotion. A capacity gauge nobody is reading.

unlocks: quota headroom / seat rightsizing ◐

campaigns is a real table

metric · direction (at_most/at_least) · target · window · baseline · baseline_at. The budget object runway needs already exists, snapshotted baseline included.

unlocks: spend runway ✓ (was ◐)

attestations + control packs

Per-pack requirement rows with pending|attested, owner, reviewed_at. The maturity checklist has literal backend receipts waiting for a surface.

unlocks: maturity-as-checklist ✓ (was concept)

session shape is rich

message/tool-call counts, durations, tool_kind (builtin|mcp|skill), reasoning tokens, cache read/write, runs.exit_code, egress TLS flags — and proc:<pid> entity ids marking observed-but-uninstrumented AI processes.

unlocks: practice profiles ◐ · shadow-process delta ✓ · friction tax ✓ · blowout ledger ✓

Catalog

Twenty-one windows

WindowThe insight, spokenTierDangerForLives
Friction tax"Support-Ops was denied 41 tool calls — 38 by one un-allowlisted MCP server"inverse Goodhart — pair with dividendenablement · platformfocus card · controls (ship with dividend)
Policy dividend"policy enforced 38 actions this week — enforced, never "prevented""counterfactual phrasingCISO · execcontrols · verdict line
Sensitive-touch surface"core-banking agents opened 6 secret-class files — five were the same repo .env"privacy (paths at floor only)CISOfocus card · controls
Shadow-process delta"3 AI processes visible on instrumented machines are running outside instrumentation"small-N noiseCISO · platformCoverage receipt · hygiene block
Secret dwell"the same AWS key has appeared in prompts for 11 days — it lives in a dotfile"counterfactual temptationCISO/identity · focus card
Blowout ledger"one ci-pool session cost $212 — 5% of the month in 40 minutes"session-splitting GoodhartFinOpsCost Center · Spend receipt
Unattended autonomy"6 sessions ran unattended overnight with approval=never; 2 reached hosts first seen that night"privacy unless agent-framedCISOAuto lens · verdict line
Spend runway"Research breaches its ceiling ~Aug 24 at the current 7d rate"label the projection, alwaysFinOpsverdict line on breach · Cost Center
Maturity checklist"7 of 9 controls attested · coverage 91% · SLA held — receipts, not a number"composite temptation (someone WILL average it)exec · CISOoverview card, not /teams
New-joiner ramp"chen reached the team band on day 8"mild Goodhart · new-hire scrutinyenablement · eng mgrfocus card
Bus-factor"one person carries 71% of the team's tokens — say the ratio, never a Gini index"composite-in-disguiseeng mgrfocus-card sub-line
Harness currency"4 machines run claude-code ≥3 versions behind fleet-max"staleness of the comparatorCISO · platformhygiene block
Quota headroom"Research's 5h bucket hit 94% by 2pm three days running — work is waiting on a quota"fabrication-by-sampling (print the reporting denominator)FinOps · platformfocus card · Cost Center
Behavioral drift"r.vance's codex ran 4× its baseline at 03:00, to a host first seen tonight"privacy · false-positive fatigueCISOalert + focus card (held for daily aggregates)
Practice profiles"ML-Infra runs marathons (few, long, cache-heavy); Support-Ops runs Q&A (many, short)"privacy — team-level onlyenablementfocus card interior
Posture regression"d.reyes's codex ran approval=never for the first time; her previous 61 runs were sandboxed"privacy framing — config fact, not accusationCISOfocus card · /identity
Offboarding risk"an identity deactivated in the IdP ran 3 sessions yesterday"▲→✓none structural — gated on one read-only IdP call, not SCIMCISOverdict line · /identity
SCIM-day unlocks"manager rollups, department views, joiner/leaver flows"scope creep into HR analyticseng mgrprojected mocks
Outcome coupling"what does a token buy — spend joined to shipped work"Goodhart · correlation-as-productivityexecseparate page, never the strip (first rung: spend-per-repo)
Peer benchmarking"your retention is p38 of orgs your size"fabrication — synthetic percentiles are the vendor fantasyexecnowhere without disclosed N
Prompt-topic mining"what your people ask AI to do, classified"▲/✗privacy, maximal — THE DRAWN LINEenablement · execnowhere yet — see the line below
honorable mentions folded into their parents: plaintext egress (tls_enabled=0 → an egress receipt row) · egress novelty (→ drift's destination component) · zombie installs & harness sprawl (→ the hygiene block) · toil rate (exit codes vary by harness — held)
The line

Explored, named, declined: prompt-topic mining

The most tempting window on the board: classify what people actually ask their agents to do (debugging vs boilerplate vs docs vs analysis) and profile team practice. Technically it's a small step — the DLP pipeline already reads message content. Socially it's a cliff: DLP reads content to protect the author; topic mining reads it to characterize them. The chilling effect — people self-censoring what they ask AI because the dashboard is watching — would suppress exactly the adoption qdash exists to make safe. Per-person, it's surveillance (✗). Team-level with k≥5 suppression and a published taxonomy, it's merely corrosive (▲).

The defensible cousin ships instead: practice profiles at repo grain — capture the git remote basename beside the cwd the agent already reads. "40% of ML-Infra's tokens go to the training repo" is a project fact, not a person profile — and it's the first honest rung of outcome coupling (spend per repo) with near-zero privacy cost.

Finding

Growth is depth, not width

Count where the 21 windows live: two touch the strip (a Coverage receipt, an Auto/verdict surfacing), nine land in the focus card, three in the verdict line, and the rest belong to other pages entirely (Cost Center, /identity, /controls). The strip is full at six lenses — and that's the finding: the lens debate is over, and the catalog's value pours into the descent. The portal grammar predicted this: a mark opens what it depicts, so every new window is something a click reveals, not a seventh tab. Coverage finally gets its honest floor (the hygiene block below); the focus card becomes the page's real estate frontier.
Graduates

Four to the roadmap, with faces

1 · Policy dividend + friction tax — one build

Same table (tool_calls decision/decision_source + egress_decisions), two lenses. Either alone is propaganda; the pair is receipts. ✓ today, zero capture work.

Support-Ops · governance, both sidesthis week
38 actions enforced by policy — never say "prevented"41 denials paid — 38 from one un-allowlisted MCP server ·
2 · Spend runway vs campaign

The campaigns table already holds target/window/baseline — no surface consumes it. A labeled linear projection, threshold printed: an argued estimate, not a fabricated series.

Research breaches its $1k ceiling ~Aug 24 at the current 7d rate
$900 spent · day 15 of 31projected at current 7d rate — an estimate, labeledcampaign ceiling $1k (at_most · 30d window)ceiling
solid = spent · dashed = projection (labeled) · amber tick = the campaign target the backend already snapshots
3 · Fleet hygiene — Coverage's descent floor

The Coverage lens finally gets what the portal law owes it: click the gap, land on the named machines and processes. All ✓ from existing inventory tables.

3 AI processes visible but uninstrumentedtwo aider · one unknown Electron (proc: entities)
4 machines on claude-code ≥3 versions behind fleet-maxabsolute comparator needs the version feed
2 zombie installs — present 60d, never rununinstall or onboard, either closes the row
4 · New-joiner ramp

Sessions/day since first_seen against the team's steady band. The positive-direction window — the counterweight that makes the CISO windows socially survivable. ✓ today.

chen — day 12 · inside the team band since day 8
Frontend's steady-state band: 2–5 sessions/dayday 1 — 0 sessionsday 2 — 1 sessionsday 3 — 1 sessionsday 4 — 2 sessionsday 5 — 1 sessionsday 6 — 3 sessionsday 7 — 2 sessionsday 8 — 4 sessionsday 9 — 3 sessionsday 10 — 5 sessionsday 11 — 4 sessionsday 12 — 4 sessions
grey = ramping · green = inside the band · the enablement question is "how many days to green," per team
Held, deliberately: behavioral drift — the highest-value window on the board ("r.vance's codex ran 4× its baseline at 03:00") — waits for the daily-aggregates capture. Shipping it against the 200-row sessions cap would break "the descent stops at real data" the moment someone clicks the anomaly. Next round, with its floor.
Capture

Six cheap captures, disproportionate unlocks

1
Daily per-identity aggregates — identity × day × tokens/cost/sessions/active-hours — one rollup table written by the existing ingest loopunlocks: drift baselines · ramp curves · retention trends · per-team sparklines without N fetches or the sessions cap. The highest-leverage row-per-day in the product.
2
Posture-change events — emit when a run's danger-relevant config differs from the identity's previous rununlocks: posture regression, cleanly · feeds drift
3
Repo identity from cwd — read git remote.origin.url basename (or hash) beside the cwd the agent already readsunlocks: practice profiles at project grain · spend-per-repo — the defensible first rung of outcome coupling, near-zero privacy cost
4
Read-only IdP pull (pre-SCIM) — one directory-list call: users + active flag; no write plumbingunlocks: OFFBOARDING RISK — the killer window, un-gated from SCIM-day
5
Latest-version feed — a small adapter→latest-version JSON qcontrol ships and refreshesunlocks: harness currency goes absolute ("14 behind upstream") instead of fleet-relative
6
Session outcome reason — formalize completed/interrupted/error alongside runs.exit_codeunlocks: toil rate, honest across harnesses
The reorder worth flagging at checkpoint: item 4 means offboarding risk — the SCIM-day "killer window" — is actually gated on one read-only directory call, not on SCIM. It moves years closer for the price of an API token.

Qpoint Brand Style Guide