How the pages work
The two page templates, the inline panels that save as you edit, the command bar and its two kinds of refusal, right-click menus, the engineering lock, the stopped runtime, confirmations, and where every result lands.
The pages of Ganter Lab share a small set of conventions, so that once you have configured one thing you know how to configure the next: two page templates, panels that save as you edit, one way of placing a command and two ways of refusing it, a right-click menu that repeats the bar, and one place where results land. This page states them once; the pages of each area only say what is particular to them.
Two page templates
Master-detail pages
Connector, Logic, Process and Users are master-detail pages, and View is laid out the same way by hand. Under the page masthead (title, one-line description, a hairline) the screen splits into a column on the left and a detail card on the right.
| Part | What it is | What you can do |
|---|---|---|
| The column's masthead | The column's name (Communication, Address space, Workspace, Station access, Visualization) and a chevron | The chevron folds the column into a narrow rail that wears the name sideways; pressing the rail brings the column back. |
| Search or filter | The page's own, above the tree: Connector has a search box ("Search drivers, lines, devices, tags") and the state chips All, OK, Issues, Off; Logic has "Filter…" | Rows that do not match are hidden; captions that name a group of roots ("Defined here", "From other pages") go with their rows. |
| The tree | The page's nodes, with an expand chevron on every row that has children and a highlight on the selected one | A click selects and opens the node's panel on the right. Up and Down move the selection, Right expands, Left collapses, Enter selects. A double-click activates in the pickers that use one. A row being renamed becomes its own name field: Enter or leaving the field commits, Esc cancels. |
| The footer | The column's commands, in the same corner on every page: a + (tooltip "New…"), an optional reorder cluster, and Expand all / Collapse all | + opens a menu anchored to the button that names what can be created and where it lands. Expand all and Collapse all are greyed while no row opens. The whole footer is dropped when the identity may use none of its commands. |
| The splitter | A hairline between the column and the card | Drag it between 260 and 600 pixels, or reach it with Tab and move it from the keyboard: an arrow nudges it 16 pixels, Page Up and Page Down move it 96, and Home and End take it to the two ends. The width stays where you left it while the page is open. |
| The detail card | A pinned head with the selected node's header (a monochrome icon, the title, optional pills, a one-line sub, sometimes a right-aligned action) and under it the command bar; the body scrolls beneath | Nothing selected leaves the head unfilled and a placeholder in the body. Some screens hand the body over to surfaces of their own (the definition screens of a Process model), with their own columns and their own draggable divider. |
Scrolling pages
Settings, Account, Agent and Validation are one scrolling column. Under the masthead, a left index headed "On this page" lists every section under its eyebrow group (GENERAL, OPC UA SERVER, DATA and so on); a click scrolls the section into view, the active entry follows your scrolling, and a link can open a section directly (/settings#sec-updates). Each section carries its title and, for the first of a group, the group eyebrow. Validation takes the whole width, because its rows are sentences. Events is the one tabbed page: Alarms, Occurrences, Interlocks and Console, each with an address of its own (/events?view=…).
Inline panels with autosave
There is no OK, Save or Apply button on a panel: the selected thing is edited in place and every change is saved as you make it. A value the panel cannot accept is refused where you typed it, in a note under the field, and never saved.
| Control | Saves | Notes |
|---|---|---|
| Switch | When flipped | A greyed switch keeps its state and says in its tooltip why it cannot change. |
| Checkbox | When ticked | |
| Text field | Per keystroke | Name, address and connection fields are the exception: they commit when you leave the field or press Enter, and Enter commits once. A name field shows, under itself, what the commit carries with it (the references it rewrites) before you commit. |
| Number field | When you leave the field | A value that is not a number, or lies outside the field's range, is refused with a note ("'abc' is not a number.", "Enter a number between 1 and 65535.") and the box returns to the value in force. A value spelled another way ("007", "7.0") is accepted and rewritten canonically. |
| Combo box | On selection | An editable combo box commits what it holds whether or not the list offered it (a Logic address, for instance). |
| Grid cell | When the cell is edited | Ticking rows first applies the edit to every ticked row (the Tags grid). |
| Code editor | Per the editor's own commit | Expressions, scripts and conditions; see Expressions. |
Two more things a field carries:
- Under a field, a legend that never changes explains what the field decides, and a separate effect line (its own indent, its own mark) states what the current value produces. A legend you can trust as an explanation is one that does not rewrite itself when you choose.
- Where an option changes what the app draws (a gauge preset, a chart shape, a criterion window, a chart tool) the picker shows a mark of the result beside the option's name, derived from the same code that draws the real thing. Where the drawing cannot tell two options apart at that size, neither gets one.
The outcome of a save lands in the status bar's action feed, not on the panel (see Where results land).
The command bar
A verb belongs to what it acts on, and where it lives is read off its target, never off how dangerous it is. Three targets, three homes:
| Target | Home | Order |
|---|---|---|
| The node the column has selected | The bar under the card's pinned head | The leading cluster (left) creates, copies, edits, forks and starts. The trailing cluster (right) ends: Delete, Remove, in danger ink, so the danger group reads as a warning. A bar with nothing to end does not leave the corner empty: it takes the verbs whose target is the window, Expand and Full screen, so how much room the open surface gets is found in the same corner on every stage. |
| The whole table a card holds | The card's own head, above the rows it touches | What grows the list first, what re-reads it, and last, in danger ink, what ends the row the page has selected. The ending verb names what it acts on and says why it is refused rather than vanishing when nothing is picked. |
| One row and nothing else | The row's trailing action cluster: glyph buttons, danger ink for the one that ends | Pressing one never changes the selection. A card ends its own rows either in its head or on its rows, never both ways for the same table. |
A boxed area of a split screen is a card. The shared panel header keeps its icon, title, sub and pills and never carries a verb; an action inside an inline notice is the notice's reply, not a header verb.
One control on a bar is not a verb: a state switch for a decision whose target is the open surface itself and that has no card or field common to every surface answering it ("Show on View" on a dashboard of a Process model). It is the app's own labelled switch, so the state is read off the control rather than off a verb that looks pressed; its tooltip says what the state in force means. A verb that is a mode (Edit, Done editing; a chart tool) shows as pressed while it is on.
Two kinds of refusal
Every bar, menu and switch tells two refusals apart the same way:
| Refusal | How it shows | Why |
|---|---|---|
| The signed-in role will never be permitted to run it | The command is not drawn at all | No press earns the permission, and a row of greyed verbs the role can never reach only takes space and suggests the product is broken. A viewing role reads a bar the size of what it may do. |
| The command is refused right now | The command stays drawn and greyed; the tooltip says what is missing: nothing selected, the station locked while a unit runs, a run in progress, "Runtime stopped" | That changes, and you have to know the command exists and what brings it back. |
The verb that ends something is no exception when the reason is a situation: it stays in place, greyed, still naming what it ends. Menus say the same reason on hover, the state switch puts the reason ahead of the sentence that says what the state means, and the footer's + and its Expand all / Collapse all are greyed the same way.
Right-click mirrors the toolbar
A right-click on a tree row selects that row first and then opens a menu at the cursor with the same verbs, in the same danger ink and under the same refusals as the bar, so the menu always acts on the row under the cursor. A row that opens a list of destinations (Move to a folder, the drivers a device can be added under) opens it beside itself, one level deep, on hover or on a press; pressing a leaf runs it and closes the menu. A click outside, a resize, or the row scrolling away closes the menu without running anything. The column's + opens the same kind of menu against the button, for a press made from the keyboard as much as from the mouse.
The engineering lock
Configuration and live runs share the station. While at least one unit is running a procedure, the configuration is read-only: the page shows the banner Engineering locked, "A Unit operation is active. Configuration stays read-only until every Unit finishes; run controls and other operator actions remain available.", and the detail card, its pinned header included, goes inert. The bar's verbs each keep saying their own availability, because several stay open under the lock: what runs, holds, resumes, stops or aborts a run, acknowledges an alarm or writes a value keeps working. Editing resumes on its own when the last unit finishes. See Runs.
The stopped runtime
An unlicensed station whose free-mode window has run out stops the runtime: every page except Account gives way to one paused notice, and every command that would change the station, including the ones a run would leave open, is refused with "Runtime stopped". The band, the paused page and the restart are described under The window; the windows themselves under Free mode and the license.
Confirmations and dialogs
Editing never opens a window; a dialog is for what is transient or destructive.
| Dialog | When | How it behaves |
|---|---|---|
| Confirmation | Before a deletion or a restore: "Delete 'name'? What disappears. This cannot be undone." | Two buttons, the refusing one focused: Enter, Esc, and a click outside all answer No; confirming takes a deliberate Tab or click. Nothing destructive proceeds without an explicit Yes. |
| Message | The primary administrator's one-time recovery key, when that PIN is set or changed. That is the station's only use for this window: the key is on screen once and nowhere else, so it has to be held there until it is written down. | One OK. The window takes the focus as it opens, so what it says is announced; Esc or a click outside dismisses it, and Tab stays inside. Never an outcome: a command that ran says so in the action feed. |
| Transient editor | The sign-in dialog, the crash-consent dialog, a client being added to the OPC UA server | Esc or a click outside cancels; Enter commits when the dialog has a default action; Tab stays inside the dialog. |
Inline notices, on the page rather than over it, are banners: a title, a body and sometimes one action, with a thin rule in the tone of their severity (info, caution, critical, success). A banner spends the full colour field only for a condition whose consequence is already running, such as a live external stop; everything else is an observation of status.
Where results land
Whatever you just did reports its outcome in the status bar's action feed and nowhere else: a save, a delete, a rename, an import, a print, a rescan, a sign-in. Both outcomes are reported, and a failure stays until you dismiss it. The one exception is a command fired from inside a dashboard component, which answers under that component. Notifications (snackbars) are for what interrupts, never for the answer to a press. See The action feed.
Theme and colour
Colour is reserved for meaning. A state dot is grey when neutral, green when healthy, amber when degraded or starting, red when faulted or offline, and the accent colour when noteworthy without being degraded (a medium-priority alarm, for instance). Danger ink marks what ends something; a caution note marks what is refused or held. The light and dark appearance is chosen with the theme keys in the title bar or under Settings, Appearance, and it is the station's: every screen, the remote ones included, renders the station's preference.
What no page does
- No page opens a modal editor for a device, a tag, a variable, a model, a user or a role; each is edited in its panel.
- No page shows a "Saved" flash, a status line or a toast of its own.
- No page greys a verb the role can never run, and no page hides a verb that is merely refused right now.
- No page freezes control by control while the runtime is stopped; the shell replaces the page as a whole.
- No verb sits on a panel header, and no page reorders the clusters of its bar.