UI kit
The recurring components behind every console screen: the role matrix, queue states, the audit row, the safeguarding gate, and the view-as-member session.
1 · The role matrix — what each admin can touch
2 · Queue states — a queue with work must look different from a settled one
3 · The audit row — every mutation leaves one
Cross-tenant peer rows (Kindness Cup) are stripped to the acting circle's name — no actor, email, ip, or device crosses the boundary.
4 · The safeguarding gate — asymmetric on purpose
Lowering protection requires a platform admin. Raising it is always allowed.
Platform admins only · reason required · both ends audited under the member's circle. Writes are refused server-side, not by the viewer's manners.
5 · The archived-circle banner — one statement for the whole app
role="status", not "alert" — a standing condition, not an error. Platform admins see a different wording, because for them the controls still work.