console organization Information architecture Relay Context Inc. · org admin
org governance · SPEC.collections · RCTX-1177

Information architecture

The org's libraries and shelves — the structure every member and agent mounts. Governance only: nothing on this screen reads, counts, or reaches into anyone's content. Every figure below is structural; member views are computed per viewer, elsewhere, under their own grants.

Libraries

One lens per library, never mixed. Overrides are deny-only — they restrict or pin, never widen.

LibraryLensShelvesOverridesAuthoring
Relay — IA
os_4f2a91c8b7d3
catalog 4 defaultrequired mountfork disabled Admins + Librarians group
Relay — Code
os_9b17e04d22aa
workspace 2 hideableforkable Admins

Shelves — Relay IA (catalog)

A shelf is populated by its rule and augmented by curators. Rule edits are audited with the predicate before and after — a rule edit changes what every member sees, with no visible diff of its own.

ShelfRuleStateOverrides on ruleBoot pin
Runbookscontent_type:runbook valid1 addition · 1 exclusionpinned · #1
Decisionscontent_type:decision validpinned · #2
Clients › Acmetag:client AND entity:Acme valid1 addition
Ops (legacy)tag:ops-2025 needs attention — tag no longer exists

Delegation

Capabilities, not ranks. A group can never be granted more than its grantor holds. The constants read container/slot while the screen says library/shelf — deliberate: every one of these writes a permanent rbac_audit row, and an audit trail must not change vocabulary partway through its own history.

HolderCapabilities
Org adminscontainer.manageslot.authorslot.curate
Librarians group · 3slot.authorslot.curate
Support group · 5slot.curate
All memberscontainer.view

Audit — IA changes

Every rule edit carries the predicate before → after. Additions and exclusions name their curator.

Dana Whitfield edited the Runbooks ruletoday 14:02
tag:deploycontent_type:runbook
Erik Christensen excluded R7KQ2M from Runbooks28 Jul
superseded revision — still reachable by search
Dana Whitfield added sess_9kf2 to Runbooks2 Aug
manual addition · origin=user · pin by reference
Erik Christensen pinned Decisions into the agent boot manifest25 Jul
boot order #2 · re-projection debounced

What this screen can never do: read into a personal library, write into one, or widen content reach. Governance and content are separate axes (SPEC.rbac-model.md §0); shelf contents are computed per viewer through the one projection engine, and every count a member sees is post-filter — this console shows structure only. Rule edits and overrides land in rbac_audit; membership changes land on relay_timeline. Capabilities here fail closed while RBAC enforcement is dark (legacy_allow=False — RCTX-1102).