The console's pages
What each page of a World's console (apps/console) owns, and the reference it follows. A control lives on the
page that owns its job; a page with nothing of its own to show says so in one line, never as empty panels.
The model the console shows is the model: a World is Neon for every SaaS (branches, checkpoints, time travel), and git for its changes (a log, changesets, a remote). A World opened is a repository opened, so its window follows the desktop git apps (GitHub Desktop, SourceTree, GitKraken), and each page the desktop app that does its job best.
Two places to stand
- The list of Worlds is where a person stands online: a host's or a platform's Worlds, grouped by org, filtered, each opened in place (GitHub Desktop's repository list). A host's admin makes a World there (New World) and rotates or removes one from its row; the list asks for a token where nothing opens by itself (Sign in: one window, one field, one act, as GitHub Desktop asks).
- A World's window is where a person works in one World: on this machine (
volter world view), on a host, and a snapshot of one (read only, with the way back to live). It is the same window in each; what differs is the World menu (online it switches between the Worlds this page opens and leads back to the list) and who the Account says is here.
The window
| Part | Owns | Follows |
|---|---|---|
| Toolbar | one short row: the World menu (Connect an app; Settings) and the branch picker at its left; where this is in its middle (the World, the branch served here, the origin and what waits for it, the World's clock); Pull, Push with its count and Settings at its right | TablePlus's and Proxyman's toolbar; GitHub Desktop's Current Repository and Current Branch |
| Branch picker | a filter and New branch; this World's branches with the one served here ticked; the branches made of it (live, or as of an instant), each opening when this page holds its key; Manage branches… | GitHub Desktop's Current Branch dropdown |
| Sidebar | the places: Screens (how many, and whose); Changes and Events; each vendor's records; the remote and what waits for it | SourceTree's sidebar |
The places
| Page | Owns | Follows |
|---|---|---|
| Board | the World's board: each thing a pack lays out (a Worker's site, a repository's page) as a live frame where it is seen, marked with its changes not yet cut (the mark opens the comparison: the frame before them, from a read-only copy of the World as it was, beside it now, and each change in words); sections are regions with a name (each pack's group to begin with), moved with what sits in them, resized, renamed by a double-click, drawn with ⇧S and removed with Delete, a frame being in the section that holds it; a click selects, a double-click uses a frame's live page and Esc leaves; scrolling pans and pinching zooms; boards as pages down its left (Everything opens by default with changed pages marked, Changes filters them, and a board named in the URL takes precedence; other boards include frames or whole groups) with their layers; all of it kept by the World for everyone; one opened alone fills the window | Figma's canvas, sections, layers and pages; a changed file's mark |
| Changes | two tabs. Changes: the records changed and not in a changeset, flat or under their vendor (Path, Tree), the selected record's fields before and after, and the cut box at the foot (whom it is recorded as, the summary, Cut). History: the changesets, newest first, each with its owner and when; the selected one's message and what it changed, its records beside the selected record's diff, and Review, a window with where it went, its checks, its approvals and Verify, Approve and Deploy | GitHub Desktop's Changes and History; SourceTree's file status; GitKraken's Path and Tree |
| Events | every write on this branch, newest first, by vendor and operation: when, the vendor, what, the record, who, its receipt; the selected one under the list, the request it came from beside what it wrote, and its trace | Proxyman |
| A trace | one traced action across the vendors: when it started, how long it took, each write on its timeline, the selected one opened under its row | Jaeger's trace view |
| A vendor's records | what the vendor stores by type, the type's records as rows, the selected record's fields; its events and its screens a click away | TablePlus |
The windows over it
| Window | Owns | Follows |
|---|---|---|
| Settings | Account (who is here, their access, and the way out where there is one); Changesets (whom a cut is recorded as, what a cut takes, what makes one ready to deploy, where each vendor deploys); Remote (the origin); Access (the keys, each with the person it is for); Real services (a vendor's root, its deploy policy, reading from it); Vault (credentials sealed for real vendors, and the links); Checks; Clock; Appearance | GitHub Desktop's Settings and Repository Settings; Keychain Access for the Vault |
| Branches | every branch as one table (branch, parent, as of, made, goes away), each branch's page and its acts; New branch; a look at an earlier moment | Neon's Branches page |
A sealed credential lives beside the World (.volter/credentials/); a branch the World serves is made with its config,
scenarios and checks, never its tokens, keys or sessions. So the Vault is the World's.
Rules the pages keep
-
A control has one home, the page that owns its job. Push and Pull are the toolbar's; a changeset's Verify, Approve and Deploy are its Review; Sign out is Account's.
-
Who acted is said where it is recorded (architecture, "Who acted is recorded"): a write's caller, a key's person, a changeset's owner, who cut it and who pushed it. A service (a key made for no one, the World's token) is named as itself, never as a person.
-
Push and deploy are different facts and read differently: a pushed changeset says where it was pushed; only a
deployedreceipt on its entries, or a remote'sconfirmed, says a change reached a vendor. -
A page never tells a person to run a command or call an HTTP path; a door's refusal reads as what to do on the page. The one place commands belong is Connect an app, in the World menu, which says how to point an app at this World, as GitHub's Code button gives the clone command.
-
The console holds no vendor's paths: it frames a vendor's screens at the address the pack lists. A board entry loads fresh iframe documents lazily at the listed addresses, so offscreen pages wait to ask for page passes. Reloads remount the iframe without changing the URL. A frame refetches when its page's covered-write position moves, falling back to its change count and first-change time when no position is available; cutting a changeset alone leaves a frame with a position loaded, and unchanged frames keep their documents. A frame in use defers its pending reload until the person leaves it.
-
Vendor marks use Simple Icons, then Google's favicon for a concrete hostname from the twin's workspace manifest or vendor page URLs, then the initial when no host is available or the image fails. The same mark renders in vendor tiles, layers and frame names. Pages marked
oursnever supply a vendor's site icon. The Worlds list shows the initial for a vendor with no bundled logo. -
For a vendor with no bundled logo, the person's browser asks Google for that vendor's site icon, sending the vendor's hostname. Google also receives their IP address and any Google cookies their browser sends. It sends no World name, no World token and no referrer.
First use and twin identity
Empty Changes points the person to Records, Board and the existing Connect an app control before asking for a changeset. Commands stay in Connect an app. A vendor’s Records pane exposes a read-only Twin and execution section using the served status projection: the package/version captured at boot, the configured source, real-root connection and deploy policy, and recorded data origin. Older hosts show missing identity explicitly. A catalog lookup names the booted release, with no claim that a privately installed package has admission. A root connection does not imply every local call is a real execution; deployments follow that root’s policy and receipts. Data without recorded provenance is unknown, not presumed synthetic.