Decision: adopted under Eve SOTA gap-closure initiative ledger. This brief governs Tasks 8.3–8.9.
This is a preregistered design constraint for later implementation, not a UI redesign. It consumes the Task 8.1 shipped-interface baseline, covers both admin web and customer mobile, and keeps Phase 8/G9 open.
Visual thesis#
Eve is a quiet, evidence-bearing layer inside the existing product: a compact right drawer over the dark admin operations shell and a focused sheet over the warm mobile experience. The current workspace remains visually dominant; hierarchy comes from type, spacing, rules, and state contrast rather than a field of interchangeable containers.
| Surface | Primary workspace | Eve placement | Palette and density |
|---|---|---|---|
| admin-web | Keep the routed AdminShell content region, workspace heading, compact rows or tables, filters, and fixed action rails as the primary operating plane. | Open Eve as the existing bounded right-side drawer; contextual entry must not replace, shrink into cards, or visually compete with the active workspace. | Retain the dark operational palette, compact scan-first density, semantic blue active state, amber fallback state, and visible audit or evidence bands. |
| customer-mobile | Keep the current routed customer experience primary and preserve a single readable content or transcript lane at narrow widths. | Use the existing mobile assistant sheet and composer lane; new controls stay adjacent to the turn or state they govern instead of forming a dashboard. | Use the established Lilith dusk and cream tokens with domain accents only for semantic identity, not ornamental section boxing. |
Default container pattern: semantic-rows-tables-and-open-sections. Card use is
limited to discrete repeated items or framed tools.
Prohibited patterns
- generic-card-grid
- nested-card-stack
- dashboard-for-a-single-task
- ornamental-gradient-container
Content plan#
Each Eve surface explains the operator or member context first, then the connected capability state, the current turn and evidence, the next safe action, and recovery. Copy is short, concrete, and truthful about what is connected now.
| Order | Content | Purpose |
|---|---|---|
| 1 | context | Name the active workspace, artifact or sanitized selection, why Eve opened, and the governing privacy or tool scope. |
| 2 | capability-state | Show connected, fallback, unavailable, buffered, or streaming state before offering a control. |
| 3 | turn-evidence | Keep the transcript, activity, citations, tool trace, and evidence status in the main reading sequence. |
| 4 | safe-action | Place stop, retry, resume, inspect, confirm, decline, or compensate beside the turn or consequence each action controls. |
| 5 | recovery | Explain what happened, what did not happen, retained transcript state, and the next available recovery action. |
Copy rules
- Use verb-first labels that name the immediate action.
- State the affected object, scope, and consequence before confirmation.
- Describe unsupported features as unavailable and name the actual fallback.
- Never label a local preview as active routing or buffered delivery as streaming.
- Avoid promotional, anthropomorphic, congratulatory, and filler copy in operational flows.
State vocabulary
connected: Activedegraded: Fallbackunsupported: Unavailableidle: Inactivepending: Workingcancelled: Stoppedfailed: Could not complete
Interaction thesis#
Eve enters from the object or action already in view, preserves the surrounding workspace, and exposes control beside the state it affects. Every transition remains understandable without animation, color, hover, or hidden context.
- Invocation: Attach contextual entry to the existing semantic row or action and carry only sanitized context into the drawer or sheet; stale, unknown, or blocked entry refuses in place.
- Steering: Keep long-turn controls adjacent to the active turn and show scope, activity, evidence, and side-effect state before a consequential action.
- Confirmation: Use one bounded confirmation region with explicit object, scope, consequence, confirm, and decline actions; generative intents render only inside that deterministic lane.
- Recovery: Retain transcript continuity, distinguish cancelled from failed or disconnected, prevent duplicate submission, and offer the smallest safe retry, resume, edit, or compensation path.
- Focus and input: Move focus into the opened surface deliberately, preserve keyboard and touch order, announce state changes, and restore focus to the exact invoking control on close.
Motion policy#
The default is static. Motion is admitted only when it communicates a meaningful state or affordance.
Allowed uses
- drawer-or-sheet-open-close-orientation
- progress-or-streaming-state-change
- confirmation-or-error-state-change
Prohibited uses
- decorative-loop
- ambient-floating-element
- staggered-card-reveal
- motion-only-status
Reduced motion: Remove nonessential transform and timing while retaining the same order, labels, status, focus behavior, and completion feedback.
Non-negotiable review guardrails#
| Guardrail | Rule | Review question |
|---|---|---|
| restrained-app-hierarchy | Preserve the existing shell navigation, page heading, workspace density, and task order; Eve is secondary until explicitly opened. | Can a person still identify the primary workspace and primary task before noticing assistant chrome? |
| utility-copy | Every label and sentence must explain state, scope, consequence, evidence, fallback, or recovery in concrete language an operator or member can act on. | Can ornamental or promotional copy be removed without losing required meaning? |
| minimal-chrome | Reuse the drawer, sheet, transcript, context band, composer, rows, tables, rails, and confirmation lane before adding a new container. | Does each new border, badge, panel, or control have a distinct semantic job? |
| clear-primary-workspace | Contextual assistance must preserve the active record or queue as the dominant plane and return focus to its invoking control. | Does opening, using, and closing Eve preserve spatial and task continuity? |
| meaningful-motion | Motion may orient opening or communicate progress, confirmation, or failure; it cannot carry meaning alone and must collapse under reduced motion. | Does the flow remain complete and equally understandable with reduced motion enabled? |
| no-generic-card-grid | Do not turn workspaces, assistant states, or controls into a generic card grid; cards remain limited to discrete repeated items or framed tools. | Would rows, a table, an open section, or the existing transcript lane express the relationship more directly? |
Downstream task bindings#
| Task | Design admission |
|---|---|
| 8.3 | Add contextual affordances to existing high-value rows and actions, then open the bounded Eve drawer with visible sanitized scope and in-place refusal. |
| 8.4 | Expose the measured mobile transport state and reconnect behavior inside the existing transcript or mode band, not a new transport dashboard. |
| 8.5 | Place stop, resume, retry, scope, activity, evidence, undo, and compensation controls beside the active turn or confirmation consequence. |
| 8.6 | Render an allowlisted generated intent only inside the deterministic confirmation, status, or evidence lane with a plain fallback. |
| 8.7 | Keep captions, recording privacy, playback, interruption, and text fallback within the composer and response lane. |
| 8.8 | Treat focus, live announcements, keyboard order, zoom, target size, reduced motion, captions, and recovery as structural acceptance criteria. |
| 8.9 | Retain browser and mobile journeys for the real contextual, control, degraded, responsive, and highest-value visual states defined here. |
Baseline coverage#
The brief is bound to eve.interface-baseline.v1 digest
d2c739731b67c3e4cd31cbde6f48ecdd34dd9107860cd1d6605467f8445a1ff1 and all 20
canonical admin workspaces:
dashboardinboxreviewpolicytrust-safetylilithegberightsincidentseditorialresearch-integritypersonasmodelsisissupportprivacyanalyticsadmin-toolsmessagingtenant-console
Non-goals and limits#
- Task 8.2 makes no product UI or runtime behavior change.
- This brief does not choose the mobile transport or claim streaming, cancellation, persona routing, voice depth, or assistive-technology interoperability.
- This brief does not replace either client palette, navigation model, typography system, or primary workspace.
- This brief does not close Phase 8 or G9.
Only Task 8.2 closes. Phase 8 is open, G9 is open, and final reclassification remains owned by Task 18.1.
Source evidence#
| Source | Digest scope | SHA-256 | Bytes |
|---|---|---|---|
docs/audits/eve-sota-interface-baseline/2026-09-09.json |
file-bytes | 4856f8ecad72a3cdab97cb9f810268d56d96d08141823016aaa26f5132e47632 |
47366 |
docs/oshun/ia-and-experience-quality.md |
file-bytes | b6b180f21901c1ab87a4d1a203db3add0616e91992379322b68c89a7933427e6 |
2364 |
apps/oshun/admin/src/components/AdminShell.tsx |
file-bytes | b44890b3fbaae07a11bd9ba1ef5bf24ac597499c01143f4f4205acb1899a6594 |
13071 |
apps/oshun/admin/src/components/AdminShell.module.css |
file-bytes | 6931214a485eb2546573e3056865bd1e062780b08e4d0136fe29ea2a6e5f8c9e |
1219 |
apps/oshun/admin/src/components/AdminAssistantPanel.tsx |
file-bytes | 51173ac9c80edde5b17d6a0ab7e6b871dfa89474f62b83e9bc1825074289aabf |
27206 |
apps/oshun/admin/src/components/AdminAssistantPanel.module.css |
file-bytes | 97e217ee4d0af7d0e0bbca994b52c6f02399a8cc850a1330066e94e221c3ad69 |
9087 |
apps/oshun/mobile/src/components/MobileAssistantSheet.tsx |
file-bytes | 3a2b3545603713f7c3f8549b4e5fa3385f16030018a655788ded000475c9f6c2 |
57882 |
apps/oshun/mobile/src/theme/lilithPalette.ts |
file-bytes | 0d909a55e5bc761394fb59f4d876074acbfd8a1069ce39fa30e8dbb808f72e8c |
2564 |
EVE_SOTA_GAP_CLOSURE_TODOS_2026-09-01.md |
task-requirement | 77222bbc7759b71688d31035829f2b41068b7dac435fe7f2044d0d341aa51dd4 |
308 |
Record digest:
d91c81c7c3deb82f4c8720cd70532772689bc2e1c084a57e0e64a0ed87d9c618