# Process

> The workspace where a procedure model is defined once, realized on units and run as recorded, evaluated tests: the Workspace column, a model's four groups, the command bar, the permission ladder and the two locks.

**Process** is the rail page where a test or a manufacturing step is built and then run. You define a **model** once (what it measures, what a run stamps, what moves a station on its own, what it produces, where it prints), realize it on **units** (the physical stations, each wired to sources of its own), compose **procedures** from the model's libraries, and start them on a unit. Every run records into its own self-contained file, so a recorded run outlives any later change to the configuration that produced it. The same vocabulary covers a quality test and a production step: anything timed that applies setpoints, records channels and judges the result.

The page header reads "Process: Define procedure models, concretize them on units and run recorded, evaluated tests." It opens for any identity that holds one of the four Process permissions (Look at models, Run procedures, Edit recipes & evaluations, Manage process) or View histories.

## In this area {#in-this-area}

| Page or group | What it covers |
| --- | --- |
| [Models and folders](process-models) | The Models root, a model's own page, Copy model, Delete model, and the folders you file models, reports and labels into. |
| [Units](process-units) | The units table on the model's page, adding and removing a unit, the unit picked across the Definition screens, the unit under Operate, Start all and Stop all. |
| [Definition](process-definition) | Channels, Metadata, Automation, Productivity and Printers: the structure of the process, changed only when the process itself changes. |
| [Visualization](process-visualization) | Dashboards and Panels: how the model shows itself, defined once and drawn for every unit. |
| [Setup](process-setup) | Occurrences, Aliases, Datalogs, Recipes, Evaluations, Actions and Procedures: what changes when the product on the bench changes. |
| [Operate](process-operate) | One node per unit, holding the panels and dashboards a run is staged, started and watched through. |
| [Templates](process-templates) | The two station-wide libraries, Reports and Labels, shared by every model. |
| [Histories](histories) | The recorded-run browser, a root of this same tree. |

## The page {#the-page}

Process is a master-detail page: the **Workspace** column on the left, and on the right the detail panel of whatever the column has selected, under a command bar that carries the verbs of that selection. Panels autosave: a switch applies when it is flipped, a field when you leave it, and a refused write puts the field back and says why in the action feed at the bottom of the window.

The page answers at two addresses. `/process` opens on the first root your role can see. `/histories` is a deep link onto the Histories root, so a bookmark to the runs still lands on them. An address carrying `?focus=<id>&screen=channels`, `automation`, `action`, `view` or `screen` opens the workspace on that surface: the [Validation](validation) page writes the first two (the Channels or Automation screen of the model, with the faulty unit's row already picked), and the [View](home) page writes the last two. An id your role cannot see, or a screen name the page does not draw, opens the page the ordinary way.

When a role holds no root at all, the panel reads: "No branch of this workspace is open to this operator: models and templates are configured at the Manage level, and recorded runs need their own permission. Procedures are started from a unit's Operate screen or a dashboard."

## The Workspace column {#the-workspace-column}

One tree with three roots:

| Root | What it holds |
| --- | --- |
| **Models** | Every model of the station, listed by name, each with its four groups. Models can be filed into folders of your own; a folder is navigation only and never enters an address. |
| **Templates** | The two station-wide libraries: **Reports** (PDF layouts) and **Labels** (printer command files). Both take folders the same way. |
| **Histories** | The recorded-run browser. It is a leaf: selecting it opens the run list in the detail panel. |

Every row is born closed; you open the branch you came for, and what you open stays open across saves. A group that lists rows carries a count mark, `(3)`, or the word `Empty` when it holds nothing, so a fresh station can tell "nothing here" from "not loaded yet". The five rows of Definition and the three grouping rows (Definition, Visualization, Setup) carry no mark: they edit in the panel, or only group other rows. Operate counts its units. Roots, models and folders are drawn bold.

The footer carries **New…**, **Expand all** and **Collapse all**. New… is drawn only for Manage process, and is greyed with the reason as its tooltip while the station is locked. It opens one menu: **New model**, **New report**, **New label**, and a **New folder** submenu whose three entries (**Models**, **Reports**, **Labels**) open an empty folder at that root with its name field already open for typing. Each entry creates at the root of its category; creating inside a folder is a gesture on the folder (its bar, or its right-click menu).

## A model's four groups {#a-models-four-groups}

Selecting a model opens its own page: its identity, the units table and tiles over its groups (see [Models and folders](process-models)). Under it stand four groups, ordered by how often each changes:

| Group | Rows | What the group page says |
| --- | --- | --- |
| **Definition** | Channels, Metadata, Automation, Productivity, Printers | "The structure of this process: the stations it runs on, what it measures, what a run stamps, what moves a station on its own, what it produces and where it prints. It changes when the process changes." |
| **Visualization** | Dashboards (n), Panels (n) | "How this process shows itself: the operator dashboards defined on it, and the surfaces its units are operated through. One definition of each serves every unit of the model." |
| **Setup** | Occurrences, Aliases, Datalogs, Recipes, Evaluations, Actions, Procedures | "What changes when the product on the bench changes: what is watched, the names the channels are read under, what is recorded, the setpoints a run applies, what it is judged by and the procedures that put all of those together." |
| **Operate** | One node per unit, each holding one node per panel and one per dashboard of the model | "The stations this model runs on. Open one to stage a procedure, start it and watch a recorded, evaluated run." |

The three grouping pages are walls of tiles that jump to a row: a tile standing for a list shows its count, and Automation, Productivity and Printers show their name. Operate lists its units with their live status. None of the four carries a command bar of its own.

## The ladder of permissions {#the-ladder-of-permissions}

Process access is four local-user permissions, granted per role on the [Users](users) page, each including the ones below it (see [Permissions](users-permissions)):

| Level | What it admits | What the tree shows |
| --- | --- | --- |
| **Look at models** | Read every model, unit, definition, setup surface and template without running or changing anything. | Models and Templates whole; every panel held read-only and no verb drawn. |
| **Run procedures** | Stage and start procedures on a unit's surfaces; Hold, Resume, Stop and Abort; comments; the single commands; Start all and Stop all; Rearm. | The same as Look. |
| **Edit recipes & evaluations** | Everything under Setup: create, edit and remove occurrences, alias sets, datalogs, recipes, evaluations, actions and procedures. | Each model reduced to its Setup branch, in the folders it was filed in; Templates dropped. |
| **Manage process** | Everything: models, units, the five Definition screens, Visualization, folders, the Reports and Labels libraries, and every rename. | Everything. |

Two more bits reach this page. **View histories** admits the Histories root (and, for an identity holding nothing else, the page itself). **Edit dashboards** is what the Edit dashboard verb on a model's dashboard asks for.

The page tells two refusals apart the way every command bar of the app does. What the role will never permit is not drawn at all. What is refused right now stays drawn and greyed, with the reason as its tooltip. A menu row a role cannot use reads "Managing this workspace requires the “Manage process” permission."; a rename attempted without the bit answers "Renaming Process address identities needs the Manage process permission."

## The command bar {#the-command-bar}

The bar stands wherever the selection has a verb: what grows, copies, edits or starts it on the left, what ends it on the right in the danger ink. It is dropped where the selection has neither.

| Selected node | Leading verbs | Ending verb | Needs |
| --- | --- | --- | --- |
| Models root | **Model** | | Manage process |
| A folder (under Models, Reports or Labels) | **Model** / **Report** / **Label** (created inside the folder), **Folder** (a subfolder), **Rename folder** | **Remove folder** | Manage process |
| A model | **Copy model** | **Delete model** | Manage process |
| Reports | **Report** | | Manage process |
| A report | **Print sample** (see [Templates](process-templates)) | **Delete report** | Manage process |
| Labels | **Label** | | Manage process |
| A label | | **Delete label template** | Manage process |
| Dashboards | **Dashboard** | | Manage process |
| A dashboard | **Edit dashboard**, **Show on View** (a switch) | **Remove dashboard** | Manage process; Edit dashboards for the editor |
| Panels | **Panel** | | Manage process |
| A panel | **Show on View** (a switch) | **Remove panel** | Manage process |
| Occurrences, Aliases, Datalogs, Recipes, Evaluations, Actions, Procedures | **Occurrence**, **Alias set**, **Datalog**, **Recipe**, **Evaluation**, **Action**, **Procedure** | | Edit recipes & evaluations |
| One occurrence, alias set, datalog, recipe, evaluation or procedure | | **Remove occurrence** … **Remove procedure** | Edit recipes & evaluations |
| An action | **Command** | **Remove action** | Edit recipes & evaluations |
| Operate | **Start all**, **Stop all** | | Run procedures |
| A dashboard being edited | **Done editing** (on the editor's own strip) | | |

Every create verb makes its row under a placeholder name ("New model", "Report 2", "Procedure 3", "Channel 4"). Model, Report, Label and Dashboard also select what they made, so naming it is the first thing you do; the other create verbs add the row to its group, where you open it. Every ending verb confirms first, in the one dialog every configuration deletion uses ("Delete 'X'? … This cannot be undone."); No, Esc or a click outside refuses. Remove folder is the exception that deletes nothing: its confirmation counts the rows that move back to the root.

No bar stands on the three grouping pages, on the five Definition rows (their verbs sit in the area heads of the screen itself), on the Templates and Histories roots, on a unit under Operate, or on the model page's units table (its verbs sit in that card's head).

Every verb of this bar is greyed, with the reason as its tooltip, while the station is locked (below). A verb the role does not hold is not drawn.

## Right-click {#right-click}

Right-clicking a row selects it and opens the same verbs as a menu. It adds the gestures that belong to a row rather than to the bar: **Add unit** on a model (the unit lands in the table on the model's page), **Move to** on a model, a report or a label (a new folder, a new subfolder when the row already sits in a first-level folder, the category root, or any folder that exists), **Add channel** on Channels, **Add field** on Metadata, and **Add command** on an action. The menu does not open while the station is locked, nor on a row the role may not change.

## The engineering lock {#the-engineering-lock}

While any unit of any model is occupied by a run operation (preparing, recording, held, saving, finalizing), the whole station's configuration is read-only. A banner at the top of the page reads "Engineering locked: A Unit operation is active. Configuration stays read-only until every Unit finishes; run controls and other operator actions remain available." Every Process panel is held inert, every bar verb greys with "Configuration is locked while a Unit is running.", and an open dashboard editor closes. Connector, Logic and the dashboards are locked by the same boundary. The unit surfaces under Operate, their run commands, the View page and Histories stay available throughout.

## The stopped runtime {#the-stopped-runtime}

While the station runtime is stopped, every Process mutation (configuration, staging, lifecycle commands, comments, run deletion) refuses as "Runtime stopped"; Start all and Stop all grey out with it. Reading, Histories, exports and reports stay available.

## Agents {#agents}

The loopback [Agent access](agent) endpoint reaches the same models and runs: the read tools `process_models`, `process_runs`, `process_run` and `unit_status` are part of the read group, and the operate tools (`process_start`, `process_stop`, `process_hold`, `process_resume`, `process_abort`, `process_snapshot`, `process_evaluate`, `process_recipe_apply`, `process_comment`, `process_report`, `process_run_delete`) sit behind their own opt-in on the Agent page. Their writes journal as Agent. While the runtime is stopped, only the read tools and `process_report` answer.

## What this page does not do {#what-this-page-does-not-do}

- It starts no run from the tree: a procedure is staged and started on a unit's panel under Operate, on a dashboard, through a bound command point, or by a PLC through Automation.
- It does not reorder models, folders or the rows of a group: models, procedures and libraries are listed by name, actions in their own order, units in the order they were added.
- It does not rename from the tree: a model, unit, channel or metadata field is renamed in its own panel, through the safe rename that rewrites references.
- Nothing is undone: every deletion confirms first, and a recorded run is never touched by a deletion in this workspace.
