RelayCTX / Concept · console · v4.0 App concept →
Experience 4.0 · operator surface

The console is the same shell

This page and the app concept are dressed by one stylesheet — v40.css, no console fork. That is the entire proposal: an operator learns one rail, one list, one card, one confirm, and has learned both surfaces. What separates them is density and scope, never grammar. The console's sections are deliberately left alone — its information architecture was never the problem. Its shell was.

Stylesheets 1, shared with the app Sections unchanged Shared list shell 1 of 20 → 20 of 20 Display type arrives
Generation
Width
console.relayctx.com — Orgs 1180 × desktop
Orgs Search operators, orgs, Codes… ⌘K

Preview-as-role is a lens, and a lens never grants

The console already ships a role switcher. 4.0 names what it is and states its limit in the surface, because an operator tool is exactly where a filter can be mistaken for a permission. Previewing a role changes what you see. It never changes what you may do, and it never changes who the audit log records. Same law as the app's hats and lenses, applied to the operator plane.

what changes

The projection

Nav rows, columns, and rows you would see as that role. Useful for answering "why can't my admin see the Loop screen" without an account swap.

what never changes

Authorization

Every action still evaluates server-side against your real capabilities. A previewed role cannot perform what your own role cannot — and cannot stop you performing what it can.

what it must say

Your real identity

While a preview is active the rail states it plainly and the audit entry names you, not the role you were wearing. A lens that could be mistaken for an identity is a security defect.

Say the blast radius before the switch, not after

The plan-features screen already does this well, and it is the best confirm pattern in the estate: it states how many live orgs change immediately, how many stay pinned to a contract snapshot, and it refetches those counts right before the dialog rather than trusting page load. 4.0 promotes it from one screen's good behaviour to the console's confirm grammar — every operator action that reaches beyond one row states its reach in the same shape. Try it: switch to v4.0 above and toggle a plan feature in the table.

And where the count cannot be trusted, say that instead. If the refetch fails, the dialog falls back to the last known number and labels it as stale rather than blocking the operator or quietly showing a figure that might be wrong. An operator surface that hides its own uncertainty is worse than one that admits it.

What 4.0 changes here — and what it deliberately does not

Areav3.5 shippedv4.0
ShellFixed 220px sidebar, its own geometryThe universal rail — same component, same collapse, same stripe as the app
TablesShared table adopted on 1 of ~20 screensAll 20 — sticky head, density, column picker, honest count
DensityA property of whichever screen you are onA setting — comfortable or compact, operator's choice, remembered
CountsSilent caps; a page-1 list looks completeHonest — what is drawn, what exists, per viewer
Display typeCormorant never loads; the console has no editorial momentOne per screen — the same single display moment the system is built around
PhoneDense tables do not reflowTables become cards — the app's own rule, not a console exception
PreferencesColumn and density prefs in local storage, per browserServer-side — an operator's setup follows them to the next machine
SectionsSeven sections, 36 screensUnchanged — membership is not the problem and re-grouping would cost recall for nothing
The console is where the shared shell earns its keep twice. Everything on this page is framework material, not Relay trivia — a second product built on the same foundation inherits this operator surface by changing names, not structure. That is the argument for fixing it here rather than after.
Concept — not a build instruction. Direction doc: relay-board/docs/product/experience-4-0.md App concept → Console v3.5 → All concepts →