The full flow, screen by screen

Every screen below is a capture from the running proof of concept, in the order a reviewer meets them. Nothing here is a mockup.

1. Sign in

Identity first: the product name, one line, and sign-in. No catalogue and no data render before identity is resolved.

The signed-out screen: the product name, one line on what it is, and sign-in.
Signed out.
The same signed-out screen at 390px.

2. Admit

The model catalogue is the default route: admission counts, the held-and-rejected control, the five-axis filter console and the scan table.

The model catalogue as the default route after sign-in: admission counts, the held-and-rejected control, the five-axis filter console and the scan table.
The front door.
The same catalogue at 390px.

A row is the scan; the record opens in a modal with digests, the licence pin, provenance and review.

One admitted record opened in the modal with its digests, licence pin, provenance and review.
One record, in full.
The same record at 390px.

3. Hold and reject

Held and rejected candidates sit behind their own control, each with the gate's verbatim reason.

The held and rejected candidates behind their own control, each with the gate's verbatim reason.
The exceptions, with reasons.
The same held and rejected candidates at 390px.

4. Compare

Retained runs, newest first; two are picked for the comparison. A run in flight reports its state while the harness works, and the report carries cost per completed task.

Retained Compare runs, newest first, with the base and compared selectors.
Retained runs.
The same retained runs at 390px.
A Compare run in flight, reporting its running state.
A run in flight.
The same running state at 390px.
A Compare report with cost per completed task.
The report.
The same report at 390px.

Base against compared, per model, with the delta. The hosted leg is labelled provenance by host attestation, not verified.

Base against compared, per model: metric rows for both runs with the delta, per-task blocks and a task-by-task table.
Base against compared.
The same comparison at 390px.

A governed hosted call through the hook, reported against its decision row.

A governed hosted call through the enforcement hook with its audit trail.
The hosted call, governed.
The same hosted call at 390px.

5. Ledger

A refusal shows its reason to the person who made it, and the same reason sits in the ledger with the policy revision that decided it.

One policy denial with its verbatim reason from the ledger.
The refusal, with its reason.
The same denial row at 390px.
Every denial in the ledger with its reason.
Every denial.
The same denials at 390px.
The audit query over the hash-chained ledger rows.
The ledger, queried.
The same audit query at 390px.

6. Entitlement

Keys are issued through the gateway admin API; the secret shows once and is never stored. Revocation lands in the same list, and budgets total the committed tokens beneath it.

A virtual key issued, with its one-time secret shown once.
Issued, shown once.
The same issued key at 390px.
The same key list with the key revoked.
Revoked, in the list.
The same revoked key at 390px.
Budgets and consumption totalled from the ledger rows.
Budgets, totalled.
The same budgets at 390px.

7. Data flow

The generated data-flow document: classes, flows, egress, listeners and the controls awaiting a human.

The data-flow documentation with its tables and attestations.
The document.
The same document at 390px.

Walking this flow against your own estate? Heliast runs this inside your environment, on your policy.

Book a discovery session