# Eve Phase 8 interaction design brief · September 2026

**Decision:** adopted under Eve SOTA gap-closure initiative ledger. This brief
governs Tasks 8.3–8.9.

This is a preregistered design constraint for later implementation, not a UI
redesign. It consumes the Task 8.1 shipped-interface baseline, covers both admin
web and customer mobile, and keeps Phase 8/G9 open.

## Visual thesis

Eve is a quiet, evidence-bearing layer inside the existing product: a compact
right drawer over the dark admin operations shell and a focused sheet over the
warm mobile experience. The current workspace remains visually dominant;
hierarchy comes from type, spacing, rules, and state contrast rather than a
field of interchangeable containers.

| Surface         | Primary workspace                                                                                                                                     | Eve placement                                                                                                                                            | Palette and density                                                                                                                                     |
| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| admin-web       | Keep the routed AdminShell content region, workspace heading, compact rows or tables, filters, and fixed action rails as the primary operating plane. | Open Eve as the existing bounded right-side drawer; contextual entry must not replace, shrink into cards, or visually compete with the active workspace. | Retain the dark operational palette, compact scan-first density, semantic blue active state, amber fallback state, and visible audit or evidence bands. |
| customer-mobile | Keep the current routed customer experience primary and preserve a single readable content or transcript lane at narrow widths.                       | Use the existing mobile assistant sheet and composer lane; new controls stay adjacent to the turn or state they govern instead of forming a dashboard.   | Use the established Lilith dusk and cream tokens with domain accents only for semantic identity, not ornamental section boxing.                         |

Default container pattern: `semantic-rows-tables-and-open-sections`. Card use is
limited to discrete repeated items or framed tools.

**Prohibited patterns**

- generic-card-grid
- nested-card-stack
- dashboard-for-a-single-task
- ornamental-gradient-container

## Content plan

Each Eve surface explains the operator or member context first, then the
connected capability state, the current turn and evidence, the next safe action,
and recovery. Copy is short, concrete, and truthful about what is connected now.

| Order | Content          | Purpose                                                                                                                  |
| ----: | ---------------- | ------------------------------------------------------------------------------------------------------------------------ |
|     1 | context          | Name the active workspace, artifact or sanitized selection, why Eve opened, and the governing privacy or tool scope.     |
|     2 | capability-state | Show connected, fallback, unavailable, buffered, or streaming state before offering a control.                           |
|     3 | turn-evidence    | Keep the transcript, activity, citations, tool trace, and evidence status in the main reading sequence.                  |
|     4 | safe-action      | Place stop, retry, resume, inspect, confirm, decline, or compensate beside the turn or consequence each action controls. |
|     5 | recovery         | Explain what happened, what did not happen, retained transcript state, and the next available recovery action.           |

**Copy rules**

- Use verb-first labels that name the immediate action.
- State the affected object, scope, and consequence before confirmation.
- Describe unsupported features as unavailable and name the actual fallback.
- Never label a local preview as active routing or buffered delivery as
  streaming.
- Avoid promotional, anthropomorphic, congratulatory, and filler copy in
  operational flows.

**State vocabulary**

- `connected`: Active
- `degraded`: Fallback
- `unsupported`: Unavailable
- `idle`: Inactive
- `pending`: Working
- `cancelled`: Stopped
- `failed`: Could not complete

## Interaction thesis

Eve enters from the object or action already in view, preserves the surrounding
workspace, and exposes control beside the state it affects. Every transition
remains understandable without animation, color, hover, or hidden context.

- **Invocation:** Attach contextual entry to the existing semantic row or action
  and carry only sanitized context into the drawer or sheet; stale, unknown, or
  blocked entry refuses in place.
- **Steering:** Keep long-turn controls adjacent to the active turn and show
  scope, activity, evidence, and side-effect state before a consequential
  action.
- **Confirmation:** Use one bounded confirmation region with explicit object,
  scope, consequence, confirm, and decline actions; generative intents render
  only inside that deterministic lane.
- **Recovery:** Retain transcript continuity, distinguish cancelled from failed
  or disconnected, prevent duplicate submission, and offer the smallest safe
  retry, resume, edit, or compensation path.
- **Focus and input:** Move focus into the opened surface deliberately, preserve
  keyboard and touch order, announce state changes, and restore focus to the
  exact invoking control on close.

### Motion policy

The default is **static**. Motion is admitted only when it communicates a
meaningful state or affordance.

**Allowed uses**

- drawer-or-sheet-open-close-orientation
- progress-or-streaming-state-change
- confirmation-or-error-state-change

**Prohibited uses**

- decorative-loop
- ambient-floating-element
- staggered-card-reveal
- motion-only-status

Reduced motion: Remove nonessential transform and timing while retaining the
same order, labels, status, focus behavior, and completion feedback.

## Non-negotiable review guardrails

| Guardrail                | Rule                                                                                                                                                    | Review question                                                                                               |
| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- |
| restrained-app-hierarchy | Preserve the existing shell navigation, page heading, workspace density, and task order; Eve is secondary until explicitly opened.                      | Can a person still identify the primary workspace and primary task before noticing assistant chrome?          |
| utility-copy             | Every label and sentence must explain state, scope, consequence, evidence, fallback, or recovery in concrete language an operator or member can act on. | Can ornamental or promotional copy be removed without losing required meaning?                                |
| minimal-chrome           | Reuse the drawer, sheet, transcript, context band, composer, rows, tables, rails, and confirmation lane before adding a new container.                  | Does each new border, badge, panel, or control have a distinct semantic job?                                  |
| clear-primary-workspace  | Contextual assistance must preserve the active record or queue as the dominant plane and return focus to its invoking control.                          | Does opening, using, and closing Eve preserve spatial and task continuity?                                    |
| meaningful-motion        | Motion may orient opening or communicate progress, confirmation, or failure; it cannot carry meaning alone and must collapse under reduced motion.      | Does the flow remain complete and equally understandable with reduced motion enabled?                         |
| no-generic-card-grid     | Do not turn workspaces, assistant states, or controls into a generic card grid; cards remain limited to discrete repeated items or framed tools.        | Would rows, a table, an open section, or the existing transcript lane express the relationship more directly? |

## Downstream task bindings

| Task | Design admission                                                                                                                                        |
| ---- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 8.3  | Add contextual affordances to existing high-value rows and actions, then open the bounded Eve drawer with visible sanitized scope and in-place refusal. |
| 8.4  | Expose the measured mobile transport state and reconnect behavior inside the existing transcript or mode band, not a new transport dashboard.           |
| 8.5  | Place stop, resume, retry, scope, activity, evidence, undo, and compensation controls beside the active turn or confirmation consequence.               |
| 8.6  | Render an allowlisted generated intent only inside the deterministic confirmation, status, or evidence lane with a plain fallback.                      |
| 8.7  | Keep captions, recording privacy, playback, interruption, and text fallback within the composer and response lane.                                      |
| 8.8  | Treat focus, live announcements, keyboard order, zoom, target size, reduced motion, captions, and recovery as structural acceptance criteria.           |
| 8.9  | Retain browser and mobile journeys for the real contextual, control, degraded, responsive, and highest-value visual states defined here.                |

## Baseline coverage

The brief is bound to `eve.interface-baseline.v1` digest
`d2c739731b67c3e4cd31cbde6f48ecdd34dd9107860cd1d6605467f8445a1ff1` and all 20
canonical admin workspaces:

- `dashboard`
- `inbox`
- `review`
- `policy`
- `trust-safety`
- `lilith`
- `egbe`
- `rights`
- `incidents`
- `editorial`
- `research-integrity`
- `personas`
- `models`
- `isis`
- `support`
- `privacy`
- `analytics`
- `admin-tools`
- `messaging`
- `tenant-console`

## Non-goals and limits

- Task 8.2 makes no product UI or runtime behavior change.
- This brief does not choose the mobile transport or claim streaming,
  cancellation, persona routing, voice depth, or assistive-technology
  interoperability.
- This brief does not replace either client palette, navigation model,
  typography system, or primary workspace.
- This brief does not close Phase 8 or G9.

Only Task 8.2 closes. Phase 8 is open, G9 is open, and final reclassification
remains owned by Task 18.1.

## Source evidence

| Source                                                           | Digest scope     | SHA-256                                                            | Bytes |
| ---------------------------------------------------------------- | ---------------- | ------------------------------------------------------------------ | ----: |
| `docs/audits/eve-sota-interface-baseline/2026-09-09.json`        | file-bytes       | `4856f8ecad72a3cdab97cb9f810268d56d96d08141823016aaa26f5132e47632` | 47366 |
| `docs/oshun/ia-and-experience-quality.md`                        | file-bytes       | `b6b180f21901c1ab87a4d1a203db3add0616e91992379322b68c89a7933427e6` |  2364 |
| `apps/oshun/admin/src/components/AdminShell.tsx`                 | file-bytes       | `b44890b3fbaae07a11bd9ba1ef5bf24ac597499c01143f4f4205acb1899a6594` | 13071 |
| `apps/oshun/admin/src/components/AdminShell.module.css`          | file-bytes       | `6931214a485eb2546573e3056865bd1e062780b08e4d0136fe29ea2a6e5f8c9e` |  1219 |
| `apps/oshun/admin/src/components/AdminAssistantPanel.tsx`        | file-bytes       | `51173ac9c80edde5b17d6a0ab7e6b871dfa89474f62b83e9bc1825074289aabf` | 27206 |
| `apps/oshun/admin/src/components/AdminAssistantPanel.module.css` | file-bytes       | `97e217ee4d0af7d0e0bbca994b52c6f02399a8cc850a1330066e94e221c3ad69` |  9087 |
| `apps/oshun/mobile/src/components/MobileAssistantSheet.tsx`      | file-bytes       | `3a2b3545603713f7c3f8549b4e5fa3385f16030018a655788ded000475c9f6c2` | 57882 |
| `apps/oshun/mobile/src/theme/lilithPalette.ts`                   | file-bytes       | `0d909a55e5bc761394fb59f4d876074acbfd8a1069ce39fa30e8dbb808f72e8c` |  2564 |
| `EVE_SOTA_GAP_CLOSURE_TODOS_2026-09-01.md`                       | task-requirement | `77222bbc7759b71688d31035829f2b41068b7dac435fe7f2044d0d341aa51dd4` |   308 |

Record digest:
`d91c81c7c3deb82f4c8720cd70532772689bc2e1c084a57e0e64a0ed87d9c618`
