DocslothDoc programs
checking session

Doc programs

Doc programs displays real server state with a next action, not placeholder statistics.

Served by the core studio

Software records (sources, programs, runs, releases, components, environments, media, verification and exports) live in the core engine and are edited in its studio. When a connected engine answers through this workspace, the panels above render its own records as returned; without a connection the shell states that and shows nothing rather than an invented row. The surface contract below names each action and the setup it needs.

Surface contract

Primary object: doc programs: audiences, objectives and the coverage policy that governs what the engine may publish.

Actions

  • Create objectiveThe guided setup records the program objective through POST /v1/software/{id}/programs; generation stays locked until a program exists. No cost is implied by creating one.
  • Edit policyCore studioCoverage policy is stored with the program in the core studio, revision-bound so a concurrent edit is refused rather than overwritten. The hosted shell holds no program row.
  • PreviewCore studioPreview renders the program’s pages from engine facts; this hosted build has no facts to preview and never fabricates a page.
Required states and how this surface reaches them
loading
the session probe and each list show Loading… until the control plane answers.
ready
the server’s own records render as returned; the primary object is named before its details.
empty
no doc program exists until the guided setup creates one (POST /v1/software/{id}/programs); the direct action is the guided setup.
error
the control plane’s status and detail are shown; no placeholder row replaces them.
offline
no control plane is reachable; nothing is rendered rather than invented.
permission_denied
a 401 returns to sign-in with this path; a 403 states that the role cannot read this surface.
not_configured
a 503 names the missing provider or secret; setup is shown, never fake results.
budget_paused
a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
requires_approval
mutations the server reserves for an explicit human owner/admin are refused with its own detail and never auto-approved here.

Scope: workspace membership. Engine records are read and written through the core engine’s own routes (proxied by the control plane); the hosted shell binds only to named contracts, shows a record only when the server returned it, and never calculates permissions in the browser.