UI kit

Circle admins — the operator's patterns

The recurring components behind every console screen: the role matrix, queue states, the audit row, the safeguarding gate, and the view-as-member session.

1 · The role matrix — what each admin can touch

Capabilitysuper_adminadminmoderatoranalyst
{{ m.cap }} {{ m.v1 }} {{ m.v2 }} {{ m.v3 }} {{ m.v4 }}

Mirrored client-side (useCanWrite) so controls hide rather than fail — the backend matrix is the authority. An admin's own row never offers role or revoke actions.

2 · Queue states — a queue with work must look different from a settled one

Moderation queue2 flags waiting on a decision 2 ApplicantsQueue is clear
Stat that failed to load A dash, never a fabricated zero

3 · The audit row — every mutation leaves one

Aug 14, 4:12pm Announcement sent to 4 members Platform Admin announcements ip · UA recorded

Cross-tenant peer rows (Kindness Cup) are stripped to the acting circle's name — no actor, email, ip, or device crosses the boundary.

4 · The safeguarding gate — asymmetric on purpose

Circle super_admin sees
Safeguarded circle

Lowering protection requires a platform admin. Raising it is always allowed.

View as member — read-only session
AR Viewing as Alex Rivera · read-only · ends on reload

Platform admins only · reason required · both ends audited under the member's circle. Writes are refused server-side, not by the viewer's manners.

5 · The archived-circle banner — one statement for the whole app

This circle is archived. It is read-only — nothing new can be posted or changed, and it is closed to new members. Everything already here stays. Ask a platform admin to reopen it.

role="status", not "alert" — a standing condition, not an error. Platform admins see a different wording, because for them the controls still work.