You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Converge canonical DataOps surfaces on one operator design system
Status: in progress — Wave A #218–#221 are accepted and committed locally/unpushed; #222 is held at immutable checkpoint 65fb9a8392ed76cc55e74a9b783e352914169411 with final verification and Designer/Tester/PM reviews pending; nothing is shipped
Tags: enhancement, portal, frontend, testing, design, P1
Depends on: #180 is complete on baseline 78e9122; #161 is accepted/integrated locally but unpushed; accepted #164 (3e835a19017da18f2177d81fb7e084764970dee3) and #158 (8839fcfb39a3553a673d395a7b3746e2c92218cd) remain on held branches pending reviewed integration; #222 final gates and #166-safe release sequencing remain open
Blocks: serialized Wave A children #218–#222, dependency-coupled Wave B slices, and final integrated design-system acceptance
Next owner: #222 Software Engineer after the documented quiescence prerequisite, then fresh Designer → independent Tester → PM review on immutable checkpoint 65fb9a8392ed76cc55e74a9b783e352914169411; Orchestrator release integration only after acceptance, preserving the reviewed containing sequence and #166 gates
Implementation baseline: clean local 78e9122 contains accepted #180 and #161. Serialized Wave A then records accepted local commits #2180c89588df809b2e84af02e796d1910a25eea0165 → #2199d204d208820e3d842a3d3fc83493c230bcadaa5 → #220d334020ca5a582d31a81b371988169cab4e7f6b2 → #2218c3b110c8aa138d95385a89fe3328749bdf47250, followed by #222 immutable checkpoint 65fb9a8392ed76cc55e74a9b783e352914169411. All are local/unpushed and unshipped; #158/#164 remain accepted held branches. Release integration must preserve reviewed containing order and cannot claim shipped before push plus source CI/On-Call evidence.
Product outcome
DataOps feels like one internal operations system, not a collection of imported products. Every canonical surface helps an operator answer:
What needs attention now?
What is the next safe action?
What process, relationship, evidence, or history is relevant?
What already happened?
What can automation prepare for review?
This is now a convergence epic over the existing canonical TypeScript-backed frontend. It is not authorization to build a second shell, replay prototype branches, replace the router, introduce a framework, invent browser-only behavior, or redesign all surfaces in one change.
Reconciled current state
The original epic assumed most surface work was still greenfield and globally blocked on #156 → #159 → #158 → #161. That is stale:
Clean local baseline 78e9122 has one top-level frontend, one canonical route contract, the Today/Home direction, account and selected-owner composition, and modular shell, runtime, Home, work detail, operations, task, finance, planning, knowledge, and admin surfaces.
Existing prototypes and subsequent module/coverage commits are current-source inputs, not automatically accepted Converge canonical DataOps surfaces on one operator design system #162 deliverables. Each slice must map this issue's criteria to production modules and behavior tests before proposing code.
Historical prototype branches are not implementation baselines. The reviewed local containing sequence is 78e9122 → #2180c89588 → #2199d204d2 → #220d334020 → #2218c3b110 → #222 checkpoint 65fb9a8. The #222 checkpoint is not accepted; final verification and reviews remain. No commit in this sequence is pushed or shipped.
Design grammar
One shell and route contract. Keep one DataOps identity, desktop sidebar, mobile shell/drawer, shared authenticated session, and canonical hash routes. No domain creates another shell, entry point, router, or navigation model.
One dominant operator question. Lead with the queue, decision, or selected object. Avoid equal-weight dashboard collections and hide document controls outside Process Docs.
One primary action per decision region. Secondary actions stay quiet. Destructive or provider-adjacent actions are separated, precisely named, confirmed, and never implied to have occurred before authoritative success.
Consistent detail ownership. Desktop may use intentional list/detail. Mobile uses one pane and canonical history/return behavior. Entity details order identity, relationship, evidence, activity, then state-valid action.
Human labels first. Resolve safe display names and Card/Task/process/artifact labels. Use semantic Europe/Berlin dates. Do not expose routine raw IDs, provider codes, storage paths, metadata, emails, or reason codes.
Progressive density and shared primitives. Queue rows carry only decision fields. Details own history/evidence/diagnostics. Reuse tokens, headers, queue rows, status strips, tabs, sheets/dialogs, forms, responsive cards, skeletons, toasts, and honest-state components.
One honest-state language. Loading, empty, unavailable, partial failure, validation, conflict, forbidden, not found, retrying, success, and destructive confirmation are explicit. A failed source is unavailable, never zero; successful sources remain usable.
Public-safe evidence. Tests, fixtures, screenshots, comments, and logs use synthetic records only. No operational corpus, private link/contact, sponsor or finance fact, production identifier, credential-adjacent note, or generated operational artifact enters this public repository or issue.
Dependency partition
Dependency
What it gates
What it does not gate
#180 complete: accepted increments e684162 and b045739 on clean baseline 78e9122
Wave A implementation is now eligible; the baseline supplies common focus, refresh, recurring semantics, browser diagnostics, and behavior assertions
If a slice discovers a missing API, persisted field, permission rule, or lifecycle contract, stop and amend/file a separate backend issue. #162 does not authorize compatibility shims, dual behavior, migration machinery, imports, restores, or browser-only simulated success.
Staged implementation slices
This epic is a tracker and final acceptance gate. Do not implement it as one mega-change. Child issues are raw intake first, then separately PM-groomed and lifecycle-gated.
Clean local 78e9122 records the reviewed containing integration as the common baseline.
Wave A implementation remained held until this gate completed.
Wave A — accepted through #221; #222 final verification pending
Children #218–#222 are filed and PM-groomed. #218–#221 completed their required reviews and are committed locally/unpushed in serialized order as 0c89588 → 9d204d2 → d334020 → 8c3b110. #222 is held at immutable checkpoint 65fb9a8; its final verification and fresh Designer, independent Tester, and PM reviews remain pending. These slices do not wait for #158, #161, or #164, provided their PM scope explicitly excludes Home, account/team scope, global navigation, accepted #180 behavior, and missing backend contracts.
#218 — Shared visual primitives inventory and bounded convergence — accepted; committed locally/unpushed as 0c89588df809b2e84af02e796d1910a25eea0165. Audit current tokens and existing primitives; consolidate only proven duplication needed by Wave A surfaces. No shell IA, account, Home, routing, or broad CSS rewrite.
#220 — Process Docs and search — accepted; committed locally/unpushed as d334020ca5a582d31a81b371988169cab4e7f6b2. Converge library/reader/editor/create, local drafts, Task return context, grouped result presentation, and partial-source honesty. Operational knowledge remains in the private knowledge repository.
#221 — Bookkeeping and Sponsors — accepted; committed locally/unpushed as 8c3b110c8aa138d95385a89fe3328749bdf47250. Converge Ledger/Evidence/Monthly package and Sponsor Overview/Finance/Communications/History presentation using existing authenticated contracts. No live payment, provider send, migration, import, or data-model expansion.
Wave A remains serialized in one reviewed containing chain. #218–#221 are accepted and locally committed but unpushed/unshipped. #222 is the current immutable checkpoint, not an accepted candidate; after its final verification and fresh reviews, the Orchestrator must preserve the containing order through coordinated #166-safe integration, push, and On-Call verification.
Admin, Users, Settings, and system feedback — after reviewed integration of accepted Show signed-in identity and authorized teammates’ Task/Card work #164 commit. Converge identity, appearance, version, sign-out, role-aware user management, small health/action hub, notifications, dialogs, and toasts without exposing the administrative /api/users projection as a general teammate directory.
#161 is accepted and integrated locally, so slice 6 is dependency-eligible on that reviewed local baseline but remains subject to Wave A serialization and publication gates. Slices 7–8 remain blocked until accepted #164 is reviewed and integrated; slice 9 remains blocked until accepted #158 is reviewed and integrated.
Wave C — integrated acceptance
Cross-surface accessibility, responsive, route, and source/SAM audit. Start only after accepted slices 1–9 are integrated. Repair only integrated design-system regressions; do not hide child-slice failures in a final mega-patch.
Per-slice acceptance contract
Every child issue must:
Post a criterion-to-current-production-source/test inventory before implementation, classifying each item as already compliant, concrete gap, dependency-owned, or out of scope.
Preserve the one canonical frontend, route/deep-link/history/close-return contract, shared login/logout, and source/SAM asset identity.
Implement only concrete gaps in current modular files. Do not replay old prototype commits or restore monolithic frontend code.
Preserve exact selected entity, relationship context, entered retryable values, authoritative server state, and useful focus through loading, validation, conflict, non-404 failure, stale/not-found, close, Back, and Forward.
At 1440x900 provide one dominant column or intentional master/detail; at 390x844 provide intentional cards/agenda/one-pane detail, 44px touch targets, and no overflow, clipping, overlap, or unreachable action.
Provide correct landmarks/headings/list or table semantics, names/descriptions, live/busy/error state, visible focus, keyboard operation, focus trap/restoration, reduced motion, light/dark tokens, and zero critical/serious WCAG A/AA findings on changed states.
Use normal local TypeScript backend behavior and synthetic public-safe records. Core success behavior cannot rely on request interception, source-string assertions, fixed sleeps, history-length arithmetic, serial fallout, broad 404 swallowing, exact incidental copy/whitespace, byte pins, or screenshot pixel goldens.
Prove source and packaged SAM frontend parity for changed routes/assets.
Capture and inspect only the child issue's exact desktop/mobile ready and critical state screenshots under .tmp; do not commit or publicly attach them.
Receive Designer review where visual hierarchy changed, independent Tester PASS, and PM acceptance on a frozen fingerprint before commit.
Given an authenticated synthetic operator/admin fixture and every canonical route/parameter combination
When each route is opened directly, refreshed, reached from the shell, followed through relationships, closed, and revisited through Back/Forward
Then the exact surface/entity/context renders inside one shell, URL and focus remain synchronized, and unsupported/stale input follows honest recovery
Responsive decision hierarchy
Given deterministic ready fixtures at 1440x900 and 390x844
When every surface and its primary detail/overlay is opened
Then the next decision is visually first, mobile reflows rather than squeezing desktop layout, targets meet size requirements, and no content becomes unreachable
Honest failure and mutation state
Given empty, partial outage, full outage, forbidden, validation, version conflict, stale entity, and double-submit fixtures through the real local server
When the page loads or the operator attempts its state-valid action
Then successful data and recoverable input remain, false zero/success never appears, duplicate writes are prevented, and focus moves to useful status/error guidance
Identity and teammate boundary
Given a signed-in actor and selected authorized teammate after #164
When visible work scope changes and a delegated Task action is attempted
Then the actor never changes, safe server projections and filters bound visible work, authorization is enforced server-side, actor attribution is authoritative, and raw ID/email is not exposed
Keyboard and assistive technology
Given desktop/mobile viewports, both themes, and reduced motion
When keyboard-only navigation traverses shell, list/detail, tabs/disclosures, dialogs, destructive confirmations, close, and Back
Then names/roles/states are announced, focus order/ownership/restoration is correct, and scans report no critical/serious findings
Verification contract
Each child records exact commands, exit codes, test counts, behavior titles, and evidence paths appropriate to its bounded diff. The final integrated audit runs, at minimum:
npm run test:frontend:unit
npm run test:frontend:coverage
npm --prefix backend test
npm --prefix backend run typecheck
npm --prefix backend run build
node backend/scripts/verify-frontend-artifact.mjs --source frontend --artifact backend/dist
npm --prefix backend run test:e2e
npm --prefix backend run test:e2e:frontend-parity
make sam-validate
make sam-build
node backend/scripts/verify-frontend-artifact.mjs --source frontend --artifact .aws-sam/build/BackendFunction
make ci
git diff --check
A PM may narrow iteration commands per child, but Tester acceptance must cover the changed behavior and its integration seams. Never execute raw import/export/migration/restore scripts or one-off data-movement tests for this epic.
Final screenshots are untracked, public-safe, native-size evidence under .tmp/screenshots/issue-162-final, with source/SAM desktop 1440x900 and mobile 390x844 pairs for every changed canonical surface plus notifications, Settings, mobile navigation, and critical empty/error/dialog states. The final child defines the exact finite filenames from the then-integrated surface inventory; the directory has no stale extras. Screenshots support behavior evidence and never replace it.
Converge canonical DataOps surfaces on one operator design system
Status: in progress — Wave A #218–#221 are accepted and committed locally/unpushed; #222 is held at immutable checkpoint
65fb9a8392ed76cc55e74a9b783e352914169411with final verification and Designer/Tester/PM reviews pending; nothing is shippedTags: enhancement, portal, frontend, testing, design, P1
Depends on: #180 is complete on baseline
78e9122; #161 is accepted/integrated locally but unpushed; accepted #164 (3e835a19017da18f2177d81fb7e084764970dee3) and #158 (8839fcfb39a3553a673d395a7b3746e2c92218cd) remain on held branches pending reviewed integration; #222 final gates and #166-safe release sequencing remain openBlocks: serialized Wave A children #218–#222, dependency-coupled Wave B slices, and final integrated design-system acceptance
Next owner: #222 Software Engineer after the documented quiescence prerequisite, then fresh Designer → independent Tester → PM review on immutable checkpoint
65fb9a8392ed76cc55e74a9b783e352914169411; Orchestrator release integration only after acceptance, preserving the reviewed containing sequence and #166 gatesImplementation baseline: clean local
78e9122contains accepted #180 and #161. Serialized Wave A then records accepted local commits #2180c89588df809b2e84af02e796d1910a25eea0165→ #2199d204d208820e3d842a3d3fc83493c230bcadaa5→ #220d334020ca5a582d31a81b371988169cab4e7f6b2→ #2218c3b110c8aa138d95385a89fe3328749bdf47250, followed by #222 immutable checkpoint65fb9a8392ed76cc55e74a9b783e352914169411. All are local/unpushed and unshipped; #158/#164 remain accepted held branches. Release integration must preserve reviewed containing order and cannot claim shipped before push plus source CI/On-Call evidence.Product outcome
DataOps feels like one internal operations system, not a collection of imported products. Every canonical surface helps an operator answer:
This is now a convergence epic over the existing canonical TypeScript-backed frontend. It is not authorization to build a second shell, replay prototype branches, replace the router, introduce a framework, invent browser-only behavior, or redesign all surfaces in one change.
Reconciled current state
The original epic assumed most surface work was still greenfield and globally blocked on #156 → #159 → #158 → #161. That is stale:
78e9122has one top-level frontend, one canonical route contract, the Today/Home direction, account and selected-owner composition, and modular shell, runtime, Home, work detail, operations, task, finance, planning, knowledge, and admin surfaces.e684162andb045739, both present on clean local baseline78e9122.0c89588→9d204d2→d334020→8c3b110. Converge Newsletter, Calendar, and Mailing Export presentation #222 is the current immutable checkpoint65fb9a8; final verification and fresh Designer, independent Tester, and PM reviews remain pending. Every Wave A commit is unpushed and unshipped.78e9122, but that integration is unpushed and not shipped. Converge canonical DataOps surfaces on one operator design system #162 preserves its accepted result.3e835a19017da18f2177d81fb7e084764970dee3on a held branch, but is not integrated or pushed; slices 7–8 remain gated until reviewed integration.8839fcfb39a3553a673d395a7b3746e2c92218cdon a held branch, but is not integrated or pushed; slice 9 remains gated until reviewed integration.Historical prototype branches are not implementation baselines. The reviewed local containing sequence is
78e9122→ #2180c89588→ #2199d204d2→ #220d334020→ #2218c3b110→ #222 checkpoint65fb9a8. The #222 checkpoint is not accepted; final verification and reviews remain. No commit in this sequence is pushed or shipped.Design grammar
Dependency partition
e684162andb045739on clean baseline78e912278e9122, unpushed3e835a19017da18f2177d81fb7e084764970dee3, integration pending8839fcfb39a3553a673d395a7b3746e2c92218cd, integration pendingIf a slice discovers a missing API, persisted field, permission rule, or lifecycle contract, stop and amend/file a separate backend issue. #162 does not authorize compatibility shims, dual behavior, migration machinery, imports, restores, or browser-only simulated success.
Staged implementation slices
This epic is a tracker and final acceptance gate. Do not implement it as one mega-change. Child issues are raw intake first, then separately PM-groomed and lifecycle-gated.
Stage 0 — complete
e684162andb045739.78e9122records the reviewed containing integration as the common baseline.Wave A — accepted through #221; #222 final verification pending
Children #218–#222 are filed and PM-groomed. #218–#221 completed their required reviews and are committed locally/unpushed in serialized order as
0c89588→9d204d2→d334020→8c3b110. #222 is held at immutable checkpoint65fb9a8; its final verification and fresh Designer, independent Tester, and PM reviews remain pending. These slices do not wait for #158, #161, or #164, provided their PM scope explicitly excludes Home, account/team scope, global navigation, accepted #180 behavior, and missing backend contracts.0c89588df809b2e84af02e796d1910a25eea0165. Audit current tokens and existing primitives; consolidate only proven duplication needed by Wave A surfaces. No shell IA, account, Home, routing, or broad CSS rewrite.9d204d208820e3d842a3d3fc83493c230bcadaa5. Converge list/editor, clean/dirty/saving/validation/conflict states, mobile disclosure, pause/resume, and safe delete/409 guidance while preserving canonical Template/Card/Task contracts and Restore behavior-based browser coverage and fix canonical UI accessibility races #180 recurring semantics.d334020ca5a582d31a81b371988169cab4e7f6b2. Converge library/reader/editor/create, local drafts, Task return context, grouped result presentation, and partial-source honesty. Operational knowledge remains in the private knowledge repository.8c3b110c8aa138d95385a89fe3328749bdf47250. Converge Ledger/Evidence/Monthly package and Sponsor Overview/Finance/Communications/History presentation using existing authenticated contracts. No live payment, provider send, migration, import, or data-model expansion.65fb9a8392ed76cc55e74a9b783e352914169411; final verification and fresh Designer/Tester/PM reviews pending. Converge chronological planning, desktop calendar/mobile agenda, overlay/unavailable states, and explicit Wait/Retry/Fix authorization/Download language while preserving accepted Automate private Mailchimp account exports and attach them to recurring work #108/Reconcile and close one Europe/Berlin business date #134 behavior.Wave A remains serialized in one reviewed containing chain. #218–#221 are accepted and locally committed but unpushed/unshipped. #222 is the current immutable checkpoint, not an accepted candidate; after its final verification and fresh reviews, the Orchestrator must preserve the containing order through coordinated #166-safe integration, push, and On-Call verification.
Wave B — dependency-coupled
#161 is accepted and integrated locally, so slice 6 is dependency-eligible on that reviewed local baseline but remains subject to Wave A serialization and publication gates. Slices 7–8 remain blocked until accepted #164 is reviewed and integrated; slice 9 remains blocked until accepted #158 is reviewed and integrated.
Wave C — integrated acceptance
Per-slice acceptance contract
Every child issue must:
Integrated acceptance scenarios
One shell across direct routes
Given an authenticated synthetic operator/admin fixture and every canonical route/parameter combination
When each route is opened directly, refreshed, reached from the shell, followed through relationships, closed, and revisited through Back/Forward
Then the exact surface/entity/context renders inside one shell, URL and focus remain synchronized, and unsupported/stale input follows honest recovery
Responsive decision hierarchy
Given deterministic ready fixtures at 1440x900 and 390x844
When every surface and its primary detail/overlay is opened
Then the next decision is visually first, mobile reflows rather than squeezing desktop layout, targets meet size requirements, and no content becomes unreachable
Honest failure and mutation state
Given empty, partial outage, full outage, forbidden, validation, version conflict, stale entity, and double-submit fixtures through the real local server
When the page loads or the operator attempts its state-valid action
Then successful data and recoverable input remain, false zero/success never appears, duplicate writes are prevented, and focus moves to useful status/error guidance
Identity and teammate boundary
Given a signed-in actor and selected authorized teammate after #164
When visible work scope changes and a delegated Task action is attempted
Then the actor never changes, safe server projections and filters bound visible work, authorization is enforced server-side, actor attribution is authoritative, and raw ID/email is not exposed
Keyboard and assistive technology
Given desktop/mobile viewports, both themes, and reduced motion
When keyboard-only navigation traverses shell, list/detail, tabs/disclosures, dialogs, destructive confirmations, close, and Back
Then names/roles/states are announced, focus order/ownership/restoration is correct, and scans report no critical/serious findings
Verification contract
Each child records exact commands, exit codes, test counts, behavior titles, and evidence paths appropriate to its bounded diff. The final integrated audit runs, at minimum:
npm run test:frontend:unit npm run test:frontend:coverage npm --prefix backend test npm --prefix backend run typecheck npm --prefix backend run build node backend/scripts/verify-frontend-artifact.mjs --source frontend --artifact backend/dist npm --prefix backend run test:e2e npm --prefix backend run test:e2e:frontend-parity make sam-validate make sam-build node backend/scripts/verify-frontend-artifact.mjs --source frontend --artifact .aws-sam/build/BackendFunction make ci git diff --checkA PM may narrow iteration commands per child, but Tester acceptance must cover the changed behavior and its integration seams. Never execute raw import/export/migration/restore scripts or one-off data-movement tests for this epic.
Final screenshots are untracked, public-safe, native-size evidence under .tmp/screenshots/issue-162-final, with source/SAM desktop 1440x900 and mobile 390x844 pairs for every changed canonical surface plus notifications, Settings, mobile navigation, and critical empty/error/dialog states. The final child defines the exact finite filenames from the then-integrated surface inventory; the directory has no stale extras. Screenshots support behavior evidence and never replace it.
Lifecycle gates
e684162andb045739, with containing baseline78e9122recorded3e835a19017da18f2177d81fb7e084764970dee3; reviewed integration still required before slices 7–88839fcfb39a3553a673d395a7b3746e2c92218cd; reviewed integration still required before slice 90c89588df809b2e84af02e796d1910a25eea0165; unpushed and not shipped9d204d208820e3d842a3d3fc83493c230bcadaa5; unpushed and not shippedd334020ca5a582d31a81b371988169cab4e7f6b2; unpushed and not shipped8c3b110c8aa138d95385a89fe3328749bdf47250; unpushed and not shipped65fb9a8392ed76cc55e74a9b783e352914169411; final verification and fresh Designer, independent Tester, and PM reviews remainOut of scope