RDRemoteDesk ITProduct wireframes V1.1 · PRD V2.0 §17 + revision brief 2026-08-01 · Mac only · Volt design system · LIVE = implemented in the Phase 1 console skeleton (2026-08-08)
Wireframe specification · for the engineering team · revision V1.1
RemoteDesk IT — Product Wireframes V1.1
One coherent product, two surfaces: RemoteDesk IT Console for administrators and RemoteDesk Agent for employees. The Mac is managed through Apple MDM and enriched by the Agent. The prototype must demonstrate that RemoteDesk can manage the device, support the employee, understand eligible work context, and operate the full employee-device lifecycle — without collapsing those permissions into employee surveillance. (PRD §17.19) V1.1 is a revision, not a redesign: the two-surface architecture, Mac-only scope, MDM/Agent dual channel, canonical Device Detail, privacy boundary and all eight state matrices are unchanged. What changed is the perceived center of gravity — Enterprise IT + Device Operations first, Work Intelligence optional.
What changed in V1.1 — the product hierarchy this document now encodes
Hierarchy · navigation, dashboards, copy and visual weight all follow it
1 · DEVICE — is my Mac ready?
2 · SECURITY — is it protected and compliant?
3 · SUPPORT — one click to IT help
4 · LIFECYCLE — Day-1 ready → recovery
5 · WORK Optional— workspace-configurable
First impression target: “The company IT app that keeps my Mac ready, secure and supported.” Work Intelligence appears after that impression is formed — and disappears entirely when the workspace turns it off.
Revision map · R01–R09 → where it landed
R01 Agent nav IT-first, WORK group vanishes when off → all Part B frames, A-00 R02 Agent Home default screen → A-00 · new R03 My Device answers four questions → A-03 R04 Work Intelligence workspace-configurable → C-11 R05 Menu bar: support-first, Timer conditional → A-01 R06 Overview second layer: Employee & Device Operations → C-01 R06b Day-1 Readiness as product concept → C-12 · new R07/07b Lifecycle workflows + Recovery Detail → C-10, C-13 · new R08 Engineering language out of product UI → C-03 drawer + legend below R09 Console “Work” → “Work Records” → C-09
Final naming (PRD §17.1) — use these names everywhere
Layer
Final name
Meaning
Product
RemoteDesk IT
Customer-facing product and website module.
Admin web app
RemoteDesk IT Console
Cloud management console.
Mac client
RemoteDesk Agent
Software installed on employee Macs.
Remote screen viewing
Not offered
Removed by design (ADR-0002, 2026-08-08) — incompatible with the privacy posture.
MDM layer
Apple Device Management
Underlying management capability, not a separate product brand.
Naming decision: do not call the client Remote Desktop Agent. Do not call the overall product Remote Desktop. Those names imply a narrow remote-control product. Revision 2026-08-08 (ADR-0002/0005): real-time screen viewing, remote terminal and file transfer are all removed — remote support is a read-only diagnostic bundle only. The product cannot see an employee’s screen, control the device, or read files.
V1 scope: Mac only (PRD §17.3)
Build now
macOS enrollment / Apple MDM · Mac inventory and health · FileVault, firewall, OS compliance · configuration profiles, Wi-Fi, VPN, certificates · software inventory/deployment · read-only diagnostics (no screen / terminal / files — by design) · My Day, Timeline, Timer, Work Summary, Timesheet · procure, assign, recover, wipe, reassign
Defer
Windows, Linux · iOS, Android · cross-platform policy abstraction · proprietary EDR · autonomous AI IT operator · conversational AI IT · mobile work tracking · full warehouse automation
Two-channel Mac model (PRD §17.5) — every screen annotates which channel feeds it
A third chip, CLOUD, marks data computed or stored server-side (RemoteDesk Cloud: Organization, Employee, Device, Policy, Command, Compliance, WorkSession, TimeEntry, RemoteSession, LifecycleEvent — §17.4). The Console never reads NanoMDM storage directly.
How to read these wireframes
Annotation chips — engineering language lives outside the frames (R08)
MDMAGENTCLOUD — data sources feeding the screen (§17.16). New in V1.1: these chips appear only in each screen’s annotation rows and footers — their sanctioned home in this wireframe doc — never inside the product UI itself.
In-frame product UI uses friendly labels instead: Management · ManagedRemoteDesk · ConnectedSecurity · Compliant. Admins who need channel internals open the Technical details drawer (C-03). Wireframe · Demo data — every frame; numbers are small illustrative counts, not targets STATE → Part C — chips on screens use the eight state matrices in the state reference sheet
Each screen ends with an engineering annotation block: permissions, state transitions, confirmations, errors, audit.
State chip color language (semantic colors, never volt)
Volt is the brand accent: primary CTAs, active nav, highlights. It never encodes status, and volt text on light surfaces always uses volt-700 #6E8A00. Dashed frames marked Alternate state show required non-happy-path variants (Part E).
Product principles carried through every screen
Managed does not mean monitored. Admin work screens show approved and submitted outputs only — never raw activity. Quiet, not invisible. The employee can always see, in one glance, what is being captured and who can see what. Employee screens must not look like monitoring software (§17.16). Demo people use role + city (e.g. “Software Engineer · Tokyo”); Alex Rivera appears only because §17.9 names him canonically. Serials are masked SN ····.
V1.1 acceptance criteria — sign-off table for the design team
#
All ten must be YES before V1.1 is done
Proven by
Sign-off
1
Seeing the Agent for the first time, it reads as an IT / device product first
A-00 · A-01 default state · A-03
☐
2
With Work Intelligence off, the product still stands complete
A-00 IT-only variant · C-11 preset A · A-01
☐
3
The Timer is no longer the default visual center
A-01 — Timer is a conditional appendage only
☐
4
An employee can tell at a glance whether the Mac is secure and healthy
A-00 status dots · A-03 · A-01
☐
5
An employee can request IT support in one click
A-00 IT Support block · A-01 · A-04
☐
6
An admin can see who is Day-1 Not Ready
C-12 · C-01 operations layer
☐
7
An admin can complete a full device recovery
C-13 · C-10 offboarding strip · D-6
☐
8
An MDM admin still cannot automatically see raw work activity
Remote screen viewing is not offered — remote support is diagnostics-first (ADR-0002)
C-03 action bar · C-07 · naming table above
☐
DeliverableDevelopers implement from this document plus Part C (badge vocabulary) and Part D (flows). Where this document, PRD V2.0 §17 and the revision brief disagree, the brief wins on emphasis/IA and §17 wins on scope.
PriorityP0 screens: C-01…C-07, C-12 and all of Part B. P1 screens: C-08…C-11, C-13. Priority order of the product: device operations → remote support → lifecycle → work intelligence (§17.10). High-fi demo focus: Day-1 Readiness (C-12) and Device Recovery (C-13).
Design systemTokens embedded here are a condensed copy of assets/css/tokens.css (Volt v1.0): ink #10131C/#1B1E26/#232733 · volt #CDFF05 (text-on-light #6E8A00) · paper #F6F6F3 · slate scale · semantic success/warning/danger · Archivo + IBM Plex Mono · radii 2/4/8px.
C-01 · IT Console · IT overview · P0 · revised in V1.1 (R06)
Two layers: is the fleet healthy — and are the people ready?
Key outcome (§17.8): understand fleet health and exceptions — plus, new in V1.1, the Employee & Device Operations layer: new hires approaching Day-1, shipments, recoveries and inventory. This second layer is the start of the divergence from pure MDM: Jamf watches devices, RemoteDesk operates the employee-device relationship. Every tile deep-links into the matching filtered screen.
DataMDMAGENTCLOUDStatesDevice · Compliance · MDM → Part C
console.remotedesk.io/overviewWireframe · Demo data
Overview
Demo Company · 12 Macs · last aggregation 2 min ago
Managed Macs
12
of 13 invited
Online now
9
Agent heartbeat < 5 min
Non-compliant
2
View exceptions →
Enrolling
1
1 failed · retry →
Support sessions
1
active now · view →
Exceptions · needs actionsorted by severity
MacBook Pro 16 · SN ···· Data Analyst · Singapore
Non-compliant
FileVault off
MacBook Pro 14 · SN ···· Alex Rivera · Software Engineer · Tokyo
Needs attention
OS update overdue
MacBook Air 13 · SN ···· Backend Engineer · Manila
1 in transit · on schedule 1 return overdue · 4 days
Inventoryby city
Tokyo4
Singapore2
Hong Kong1
DataTiles are CLOUD aggregations: “Managed” from MDM enrollment state, “Online” from Agent heartbeat (< 5 min), compliance from CLOUD rule evaluation over MDM inventory. Operations layer aggregates People records, LifecycleEvents and shipping fields (CLOUD).
PermissionsAny IT Console role sees this screen. Work data never appears here — the Work Records area (C-09) has its own role check (§17.11).
StateTile taps navigate to C-02 pre-filtered (e.g. Non-compliant → compliance=Non-compliant). Exception rows deep-link to C-03/C-04. New hires → C-12; Recovery → C-13; Shipping/Inventory → the matching Lifecycle sub-pages.
LoadingTiles render as gray skeleton blocks until the first aggregation returns; exceptions list shows 3 skeleton rows (see Part E). The operations layer keeps its own skeleton — fleet health never blocks on people data.
C-02 · IT Console · All devices · P0
Every Mac, both channels, one table
Key outcome (§17.8): find every Mac and its employee, MDM, Agent and compliance state. MDM and Agent are independent channels and get independent columns — never merge them into a single “status”. Chips use the Part C vocabulary.
DataMDMAGENTCLOUDStatesDevice · MDM · Agent · Compliance → Part C
console.remotedesk.io/devicesWireframe · Demo data
All Macs
12 devices · exceptions sorted first
MDM All ▾Agent All ▾Compliance All ▾Group All ▾
Device
Employee
MDM
Agent
Compliance
Last seen
MacBook Pro 14 SN ····
Alex Rivera Software Engineer · Tokyo
Healthy
Online
Needs attention
2 min ago
›
MacBook Pro 16 SN ····
Data Analyst · Singapore
Healthy
Online
Non-compliant
5 min ago
›
MacBook Air 13 SN ····
Backend Engineer · Manila
Failed
Not installed
Unknown
—
›
MacBook Air 13 SN ····
Frontend Engineer · Hanoi
Pending
Not installed
Unknown
—
›
MacBook Air 13 SN ····
Product Designer · Osaka
Healthy
Offline
Compliant
3 d ago
›
MacBook Pro 14 SN ····Recovery
Unassigned · offboarding
Enrolled
Offline
Unknown
6 d ago
›
Showing 6 of 12 · phase: table paginates at 50
Alternate state · EmptyPart E
MAC
No Macs yet
Send your first enrollment invitation to bring a Mac under management.
Alternate state · Loading / console offlinePart E
Connection lost. Showing data cached at 14:02. States may be stale — retry.
DataMDM column from Apple MDM check-ins; Agent column from Agent heartbeats; compliance computed in CLOUD. “Last seen” = most recent of the two channels; hover reveals per-channel timestamps.
StateChips come straight from Part C matrices. A device-level chip (e.g. Recovery) renders next to the serial. Default sort: exceptions first, then last-seen desc.
ErrorsIf the fleet query fails, keep the table skeleton and show the cached-data banner (alternate state above); never render an empty table as if the fleet were empty.
The canonical device page: one Mac, both channels, six tabs
Key outcome (§17.8): operate one Mac across Security, Software, Support, Work, Lifecycle and History. This header block is the canonical layout every tab reuses. The action bar hosts one support action — Collect diagnostics (read-only). Screen viewing, terminal and file transfer are deliberately not offered (ADR-0002/0005).
DataMDMAGENTCLOUDStatesDevice · MDM · Agent · Compliance → Part C
console.remotedesk.io/devices/mbp14-····Wireframe · Demo data
Mini-frame · Technical details drawer (admin-only) · R08collapsed by default
Channel internals live here — behind one click, for admins who need them — so the product UI stays free of engineering vocabulary.
MDM channelEnrolled · Healthylast check-in 14 min
AGENT channelOnlinev0.9 · heartbeat 2 min
CLOUD policyBaseline security v3 · evaluated 12 min ago
EnrollmentUDID ···· · profile v3 · APNs ok
CanonicalHeader (identity + 3 friendly status chips + action bar + tabs) is fixed across tabs C-03/C-04 and the Work/Lifecycle/History tabs. The 3 chips map to MDM (Management · Managed), Agent heartbeat (RemoteDesk · Connected), CLOUD policy (Security · Compliant) — channel names surface only in the Technical details drawer (R08).
PermissionsAction-bar buttons disabled when Agent is Offline (tooltip explains which channel is missing). Sensitive actions require admin re-auth + employee consent → C-07 flow.
StateWork tab shows only policy-allowed work records (rules in C-09); it renders a permission-denied explainer when the admin lacks the work role (Part E).
AuditEvery command, profile push, support session and lifecycle event on this device appears in History with actor + timestamp; history is read-only.
Key outcome (§17.8): see FileVault, firewall, OS and policy exceptions for one Mac. Compliance is a computed verdict — always show which rule produced it and the one-click remediation, with confirmation and audit.
DataMDMCLOUDStatesCompliance → Part C
console.remotedesk.io/devices/mbp14-····/securityWireframe · Demo data
rule: install updates within 14 days · 9 of 14 elapsed
Rules come from Policies (C-11). “Send update command” asks for confirmation, then issues an MDM command and writes an audit event.
DataPosture facts (FileVault, firewall, OS version) from MDM inventory; verdicts computed in CLOUD against the assigned policy. No Agent data is needed on this tab.
StateCompliance states: Compliant / Needs attention / Non-compliant / Unknown. A device Offline > 7 days degrades to Unknown rather than keeping a stale verdict.
ConfirmRemediation buttons open a confirm dialog naming the exact MDM command and the target device; destructive commands (lock/wipe) additionally require typed confirmation (C-10).
ErrorsA failed command surfaces inline on the rule row (Failed chip + error code + retry) and in History — never silently.
C-05 · IT Console · Enrollment · P0
Invitation to managed, with every stalled step visible
Key outcome (§17.8): get a new Mac from invitation to managed state. Enrollment crosses three systems — invitation (CLOUD), MDM profile (MDM), Agent install (AGENT) — so the pipeline shows each device’s exact position, including Failed.
DataCLOUDMDMAGENTStatesMDM · Agent → Part C
console.remotedesk.io/devices/enrollmentWireframe · Demo data
Before joining, the employee sees the org’s device-management and work-capture policies (A-02).
StatePer-device MDM states (Part C): Not enrolled → Pending → Enrolled → Healthy, with Failed as a branch that keeps the invitation valid. Agent install is a separate track (Not installed → Installing → Online).
DataInvitation lifecycle is CLOUD; profile install events come from the MDM protocol; Agent install status arrives with the first heartbeat.
ErrorsFailed rows keep the raw MDM error code and a retry that re-issues the profile. Two consecutive failures escalate to an exception on C-01.
AuditInvitation sent/opened, enrollment, profile install and Agent install each write an audit event (§17.13 acceptance).
C-06 · IT Console · Security & compliance · P0
Fleet posture and the exceptions that break it
Key outcome (§17.8): see FileVault, firewall, OS and policy exceptions across the fleet. Fractions, not gauges: posture reads “11 of 12”, and every exception carries its reason and remediation.
DataMDMCLOUDStatesCompliance → Part C
console.remotedesk.io/securityWireframe · Demo data
Security & compliance
Baseline security policy v3 · applies to all Macs · evaluated hourly
DataPosture facts from MDM inventory; rule evaluation and exception list computed in CLOUD. Devices in Unknown (offline > 7 d) are listed separately, not counted as compliant.
PermissionsRemediation requires the device-admin role; viewing posture is available to all Console roles. This area never links into Work data.
StateFixing the rule flips the device Needs attention/Non-compliant → Compliant on next evaluation; the exception row animates out and History records the transition.
Confirm / auditEvery remediation shows the exact command before sending and lands in the audit log with actor, device, command, result.
C-07 · IT Console · Remote support (diagnostics) · P0
Diagnostics — a read-only health snapshot, with consent
Key outcome (§17.8): when an employee reports a problem, IT collects a read-only diagnostic bundle — the one and only remote-support capability (ADR-0005). No screen viewing, no remote terminal, no file access: RemoteDesk cannot control the device or read its files. The bundle lifecycle (Idle → Requested → Collecting → Collected / Failed) is visible throughout, and §17.16 requires consent + audit on collection.
DataAGENTCLOUDStatesRemote support → Part C
console.remotedesk.io/support/diagnosticsWireframe · Demo data
Diagnostics
Bundle lifecycle:
Idle→Requested→Collecting→Collected/Failed
Support requests
Frontend Engineer · HanoiRequested
“External display not detected after OS update.” · 5 min ago
Every field is a query from the employee-visible diagnostic set (A-08). Collection is written to the audit log (C-11).
Alternate state · Failed collectionFailed
Collecting→Failed
Bundle could not be collected. The employee declined, or the device stayed offline past the request window. Nothing was collected; the attempt is still audited.
ScopeDiagnostics is read-only: no screen viewing (ADR-0002), no remote terminal, no file transfer (ADR-0005). The bundle is a fixed set of health queries — device state, not files, not activity.
PermissionsConsent is separate from MDM admin rights (§17.11): collection needs the employee’s acceptance, and the exact query set is visible to them in the Agent’s Privacy Center (A-08).
StateIdle → Requested (IT initiates) → Collecting (Agent runs the query set on next check-in) → Collected / Failed. Each transition is timestamped and audited.
AuditEvery collection writes an audit entry with who requested it and when (C-11); the recent-diagnostics list is the queryable record (§5.4).
C-08 · IT Console · Software · P1
Inventory in, required apps out
Key outcome (§17.8): inventory and install/update/remove company apps. Marking an app required starts the deploy flow (D-4); each device reports its own install state back through the two channels.
DataMDMAGENTCLOUDStatesInstall states (per device)
console.remotedesk.io/softwareWireframe · Demo data
Software
Required apps · deployed via MDM managed apps · versions reported by Agent
Required appsInventory
App
Required for
Installed
State
RemoteDesk Agentv0.9
All Macs
11/12
Update required · 1
Slack
All Macs
12/12
Installed
—
Figma
Design group
2/3
Installing · 1
—
Endpoint AV
All Macs
10/12
Failed · 1Pending · 1
Inventory snapshotby app · fleet-wide
App
Versions seen
Macs
Outdated
Chrome
2 versions
12
3
Zoom
1 version
9
0
Per-device install states
Not installedPendingInstallingInstalledUpdate availableFailed
Clicking a count opens the per-device list with the raw MDM/install error for Failed rows.
DataDeploy/update/remove commands travel over MDM (managed software §17.5); fine-grained installed-version telemetry comes from the Agent heartbeat; the required-app policy object lives in CLOUD.
StateMarking required → target devices go Pending → Installing → Installed; failure keeps the error and retries are explicit, never silent loops.
ConfirmRemoving an app from devices requires confirmation listing affected Macs; removal is audited.
FlowSee D-4: mark required → deploy → device reports version (also visible to the employee in A-03 My Device).
C-09 · IT Console · Work Records · Timesheets · P1 · renamed in V1.1 (R09)
Work Records: outputs, not activity
Key outcome (§17.8): review approved and submitted work records only — never raw activity. This area is intentionally boring: what employees chose to submit, and the approvals queue. Nothing here knows which apps anyone used. Renamed from “Work” to “Work Records” in V1.1 because the name must say what admins actually receive: approved and submitted outputs — records, not a window into work.
DataCLOUDStatesTime entry → Part C
Managed does not mean monitored
The Console has no raw activity, timelines, app or website data, no screenshots, and no productivity scoring of any kind (§5.14). Employees review and submit in the Agent (A-06/A-07); admins see submitted records only. Visibility is governed by the workspace work role — being an MDM administrator grants nothing here (§17.11).
console.remotedesk.io/work-records/timesheetsWireframe · Demo data
Data Analyst · Singapore · Internal · Reporting · 12.5h
Narrative: “Weekly reporting pipeline maintenance and Q3 dashboard prep.”
PermissionsThis whole area requires the workspace work role (approver/manager per policy). MDM/device admins without it see a permission-denied explainer, not the data (§17.11, Part E).
StateTime-entry machine (Part C): Draft → Needs Review → Approved → Submitted → Exported, plus Conflict. Draft never leaves the employee’s Mac view; the legend row marks it employee-side.
ConflictOverlap detection flags Conflict and returns the week to the employee to resolve in A-07; admins cannot edit employee entries, only approve or return with a note.
Anti-goalNo leaderboards, no scores, no per-minute views, no “active time” meters — by design, not omission (§5.14, §17.16).
C-10 · IT Console · Lifecycle · P1 · deepened in V1.1 (R07)
Employee + Device Lifecycle Operations — the board, plus the two workflows
Key outcome (§17.8): track procure → ship → assign → recover → wipe → reassign. The 9-state board is unchanged from V1 (§17.14). New in V1.1: Lifecycle is framed as Employee + Device Lifecycle Operations — two workflow strips run the board: Onboarding (12 steps, ends at DAY-1 READY → C-12) and Offboarding (12 steps, ends at Reassign / Retire → C-13). Board scrolls horizontally inside the frame.
DataCLOUDMDMStatesLifecycle → Part C
console.remotedesk.io/lifecycleWireframe · Demo data
Lifecycle
Every transition is recorded as a LifecycleEvent (§17.4)
Procured
MacBook Air 13 SN ···· Procured
In transit
MacBook Pro 14 SN ···· → Frontend Engineer · Hanoi In transit
Assigned
MacBook Air 13 SN ···· Product Manager · Tokyo Assigned
Active
9 managed Macs collapsed → C-02
Recovery
MacBook Pro 14 SN ···· offboarding · checklist ↓ Recovery
Received
empty
Wiped
empty
Available
MacBook Air 13 SN ···· inventory · Tokyo office Available
StateLifecycle states (Part C): Procured / In transit / Assigned / Active / Recovery / Received / Wiped / Available / Retired. Only legal transitions are offered on each card (e.g. Received → Wiped, never Received → Active directly).
ConfirmWipe is the highest-risk action in the product: typed device-serial confirmation, second-role approval if policy demands, and an immutable audit entry. Lock requires standard confirmation.
DataBoard and events are CLOUD; lock/wipe execute over MDM. Shipping fields are manual/partner-fed in V1 (no warehouse automation — §17.3 defer).
FlowOffboarding flow D-6 walks Recovery → Received → Wiped → Available; per-device recovery has its own full screen in V1.1 (C-13). Onboarding’s readiness gate is C-12. Approved work/timesheet records are preserved per retention policy (§6.2).
C-11 · IT Console · Policies & audit · P1 · revised in V1.1 (R04)
Two policies that must never look like one — and the Work Intelligence switch
Key outcome (§17.8): separate device/security policy from work/privacy policy. §17.16 requires the split to be visually distinct — device policy is ink and management-flavored, work policy is volt-tinted and Agent-flavored, with separate editors and separate audit trails. New in V1.1 (R04): Work Intelligence is a workspace configuration, not a product constant — the panel below enables it, picks the work mode, and selects features; turning it off removes the entire WORK area from every employee’s Agent.
DataCLOUDMDMAGENTStatesPolicy versions · audit
console.remotedesk.io/policiesWireframe · Demo data
Policies
Separate objects · separate editors · separate audit trails (§17.16)
Device & security policy
Baseline security v3 · applies to all Macs
Apple Device Management
FileVault required · recovery key escrowed
Firewall on · stealth mode
OS updates within 14 days
Screen lock after 5 min
Wi-Fi / VPN / certificate profiles
v3 · edited Aug 6 · audit ✓
Work & privacy policy
Work capture v2 · shown to employees before it takes effect
RemoteDesk Agent
Capture: app/window/domain/file metadata only
Screenshots: off (separate permission if ever enabled)
Exclusions: employee-managed, always allowed
Private Mode: always available, immediate
Admin visibility: submitted records only
v2 · edited Jul 30 · audit ✓ · announced in Agent ✓
Work Intelligence · workspace configurationnew in V1.1 · R04
Enable Work Intelligence
◉ Automatic — no timer needed; activity becomes reviewable sessions○ Timer — explicit start/stop with client/project/matter○ Hybrid — timer as intent, context fills the gaps
☑ My Day☑ Timeline☑ Work summary☑ Missing-time suggestions☐ Timer☐ Timesheet & approvals
App & window metadata
Browser domain (never full URL)
File names · paths redacted
ScreenshotsOff
Private ModeAlways available
Private Mode has no toggle — it cannot be configured away by any workspace.
Turning Enable off removes the WORK group from every employee’s Agent nav and menu bar — the group disappears entirely; nothing renders disabled (R01). Changes are versioned and announced in the Agent before they apply.
Preset A · IT-onlyWork Intelligence off
Pure device management, security and support.
Agent nav Home · My Device · Support Privacy · Settings no WORK group — absent, not grayed
Preset B · Remote teamAutomatic mode
Work records for distributed employees — no billable time.
Agent nav Home · My Device · Support WORK My Day · Timeline Privacy · Settings
Preset C · Professional servicesHybrid + Timer
Billable work: timer, timesheets and approvals on top of B.
Agent nav Home · My Device · Support WORK My Day · Timeline · Timesheet Privacy · Settings
Quiet, not invisible
Work-policy changes are versioned, announced in the RemoteDesk Agent before they apply, and always readable by every employee in the Privacy Center (A-08). Device policy and work policy are edited by different roles and never merge into one document.
Audit logfilter by actor · action · target · immutable
Time
Actor
Action
Target
Aug 7 14:21
IT admin · Tokyo
Diagnostic bundle collected · consent ✓
MacBook Pro 14 · SN ····
Aug 7 13:48
IT admin · Tokyo
Policy edited · Baseline security v2 → v3
Device & security policy
Aug 6 17:10
Approver · Singapore
Timesheet approved · W32
Product Designer · Osaka
Aug 5 09:30
IT admin · Tokyo
Wipe command issued · typed confirmation ✓
MacBook Pro 14 · SN ···· (recovery)
PermissionsDevice policy: device-admin role. Work/privacy policy: workspace-owner role. Neither role implies the other; the UI enforces and displays the split (§17.11).
StatePolicies are versioned; a work-policy version is Pending-announce until the Agent has surfaced it to employees, then Active. Device-policy versions push profiles on activation.
AuditThe audit log is append-only and captures policy edits, sensitive commands, support sessions, approvals and lifecycle events with actor + timestamp (§5.3, §17.13).
ConfirmPublishing either policy shows a diff against the current version before confirm.
Workspace configThe Work Intelligence panel is part of the Work & privacy policy object (workspace-owner role). Enable/mode/features drive which WORK screens exist in the Agent (A-00/A-05/A-06/A-07) and whether Work Records (C-09) appears in the Console. Data-capture toggles map to the §5.5 capture list; screenshots stay a separate permission that this panel alone cannot grant.
C-12 · IT Console · Lifecycle · Day-1 Readiness · P0 · new in V1.1 (R06b)
Is this employee ready to start work Monday?
The per-employee readiness list: every new hire in the next 7 days, with the full chain — employment, Mac, shipping, enrollment, Agent, policy, software, VPN — collapsed into one answer per person. This screen carries P0 visual weight in V1.1: it is the first thing the high-fi demo shows, because it is the question a pure MDM cannot answer.
DataCLOUDMDMAGENTStatesLifecycle · MDM · Agent · Compliance → Part C
The strategic line
Jamf asks “Is this Mac compliant?” — RemoteDesk asks “Is this employee ready to start work Monday?” Compliance is one input; readiness is the product.
console.remotedesk.io/lifecycle/day-1-readinessWireframe · Demo data
Day-1 Readiness
3 new hires in the next 7 days · 2 ready · 1 at risk
Window 7 days ▾
Alex Rivera· Software Engineer · Tokyo · starts Mon Aug 11
Employment ✓Mac assigned · MacBook Pro 14 · SN ····Shipping · deliveredEnrolled ✓Agent connected ✓Security policy ✓Required software 5/5VPN ✓
DAY-1 READY ✓
Sarah Lee· Product Designer · Singapore · starts Mon Aug 11
Employment ✓Mac assigned · MacBook Air 13 · SN ····Shipping · in transitEnrollment · pending deliveryAgent · pendingSecurity policy · pendingRequired software · pendingVPN · pending
Expected delivery: Monday 2:00 PM — after her start time. Options: expedite shipping, or prepare a loaner from Singapore inventory (2 available).
AT RISK
QA Engineer · Osaka· starts Wed Aug 13· all 8 checks passing
DAY-1 READY ✓
DataReadiness is a CLOUD aggregation per employee: employment (People record), assignment + shipping (LifecycleEvents), enrollment (MDM), Agent heartbeat (AGENT), policy + software + VPN (CLOUD evaluation). Each check links to the screen that fixes it (C-05, C-08, C-13, C-03).
StateAn employee is DAY-1 READY only when all checks pass before their start date; any pending check within 72 h of start flips the card to AT RISK with the blocking reason and the recovery options. States come from the Part C matrices — readiness adds no new chip vocabulary.
PriorityP0 in V1.1. C-01’s “New hires” tile deep-links here; this screen and C-13 are the two the high-fi demo must nail — 30 seconds to show a customer this is not another MDM.
EmptyNo upcoming hires: calm empty state with “Create a new hire” (People → New Hires), never a bare table.
C-13 · IT Console · Lifecycle · Device Recovery Detail · P1 · new in V1.1 (R07b)
One recovery, walked to the end
The full recovery timeline for one offboarding device: access revoked → locked → return label → pickup → in transit → received → inspect → secure wipe → inventory. Every step is timestamped and audited; the current step always names the next action. The post-receipt inspection and the wipe’s terminal choice (reassign or retire) are shown as mini-frames below.
DataCLOUDMDMStatesLifecycle · Device → Part C
console.remotedesk.io/lifecycle/recovery/mbp14-····Wireframe · Demo data
Lifecycle / Recovery / MacBook Pro 14 · SN ····
MacBook Pro 14SN ····
Previously: Backend Engineer · Manila · employment ended Aug 3
RecoveryIn transit
Recovery timelineall steps audited
✓Access revoked · corporate accounts + certificates Aug 4 09:12 · audit ✓ ✓Device locked · management lock command Aug 4 09:15 · audit ✓ ✓Return label created · SF Express · sent to employee Aug 4 10:02 ✓Pickup completedAug 5 16:40 ●In transit — current stepexpected Tokyo office Fri Aug 8 ○ Received · confirm at intake ○ Inspect & record condition mini-frame ↓ ○ Secure wipe (typed confirmation required)audited ○ Return to inventory → reassign, or retire
Shipping · SF ExpressIn transit
TrackingSF ···· ···· 8841
FromManila
ToTokyo office
ExpectedFri Aug 8 · before 18:00
Device condition
Pending
Recorded at inspection, after receipt.
Next action
Confirm receipt when the package arrives — that unlocks inspection.
Opens the typed-confirmation dialog: type the device serial to confirm. Second-role approval if policy requires. Immutable audit entry.
Variant · after wipe — terminal choiceWiped
Wipe verified Aug 9 11:20 · audit ✓. The device leaves Recovery by exactly one of two doors:
Inventory → Available (reassignable, D-1). Retire → terminal state with disposal note. Approved work/timesheet records and audit history survive the wipe per retention policy (§6.2.8).
StateThe timeline is the Lifecycle machine walked linearly: Recovery → Received → Wiped → Available / Retired. Steps can only complete in order; skipping is impossible in the UI, not just discouraged.
ConfirmSecure wipe keeps the V1 rule: typed device-serial confirmation, optional second-role approval, immutable audit. Lock and revoke were confirmed at offboarding start (C-10).
DataTimeline and shipping are CLOUD (partner-fed tracking, manual in V1 — no warehouse automation, §17.3); lock and wipe execute over MDM. Serial and tracking numbers render masked in demo data.
OverdueA return not received by the expected date + 3 days flips the recovery to overdue: C-01’s Recovery card counts it, and this screen shows an escalation banner (contact employee · re-issue label · report lost → lock stays on).
A-00 · RemoteDesk Agent · Home · P0 · new in V1.1 (R02) · the default screen
The first screen answers: is my work Mac ready?
Home is what opens when the employee opens RemoteDesk — and it is an IT screen, not a work screen. Hierarchy on the page: Device → Attention → Support → Work. Three status dots give the one-glance answer; the WORK section sits last, carries an Optional tag, and disappears entirely when the workspace runs IT-only (C-11 preset A).
DataMDMAGENTCLOUDStatesMDM · Agent · Compliance → Part C
RemoteDesk — HomeWireframe · Demo data
Good afternoon, David.
Your Mac is ready for work.
ProtectedManaged by Demo CompanyRemoteDesk connected
Device statusMy Device →
FileVault encryptionOn
FirewallOn
macOS15.6 available
Required software4 of 5 installed
Needs your attention · 1
macOS 15.6 update
Company policy asks for updates within 14 days — 5 days left. Installing takes about 30 minutes.
IT support
Something not working? IT can collect a read-only diagnostic snapshot — you approve first, and IT never sees your screen or files.
last diagnostic Aug 6 · you accepted · read-only
Work OptionalMy Day →
Today’s work 6.2h · 2 need review
Only what you submit is ever shared.
Variant · IT-only workspace (C-11 preset A)Work Intelligence off
RemoteDesk
HomeMy DeviceSupportPrivacySettings
The WORK group is completely absent — no grayed items, no teaser. Home drops the Work card; the grid becomes Device / Attention / Support. The product is complete without it.
DefaultHome is the window’s default screen (R02). The three dots map to CLOUD compliance verdict (Protected), MDM enrollment (Managed by {Company} — links to A-03), and Agent connection (RemoteDesk connected). Any dot degrading flips the headline (“Your Mac needs one thing before it’s ready”) and promotes the fix into Needs your attention.
HierarchySection order is fixed: Device → Attention → Support → Work. The Work card renders last, dashed, tagged Optional — and only when Work Intelligence is enabled for the workspace (C-11). It shows totals and review counts only; no timer is rendered on Home.
AttentionAttention items are actionable requirements only (update due, software failed, permission missing) with the policy reason and a scheduling choice — never alarms. Empty attention section collapses to a single “Nothing needs your attention” line.
Support“Get help” opens A-04 pre-focused on the request form — acceptance criterion 5: one click from Home.
A-01 · RemoteDesk Agent · Menu bar · P0 · rebuilt in V1.1 (R05)
Support-first by default — the Timer is conditional content, not identity
Redesigned per R05. The default menu bar answers “is my Mac okay, and where is help?” — device health and support lead. The WORK block appends only when the workspace enables Work Intelligence, and the Timer block only in timer/hybrid mode. No timer digits sit in the menu bar by default: the Timer is conditional content, not the product’s identity.
DataMDMAGENTStatesMDM · Compliance · Work capture → Part CWireframe · Demo data
◐🔋📶RDThu 14:31
1 · Default state — always present
RDRemoteDesk
Demo Company
ProtectedYour Mac is protected and managed.
SecurityCompliant
Get IT support›
My DeviceOpen RemoteDesk ↗
2 · Attention state — when something is due
RDRemoteDesk
1 item
macOS 15.6 update
due in 5 days · ~30 min
Get IT support›
My DeviceOpen RemoteDesk ↗
Menu-bar icon gains a small warning dot. Same calm register — a reminder, not an alarm.
3 · Conditional appendages — only if enabled
Work · appended when Work Intelligence is on
Today’s work
Platform project · 6.2h · 2 to review
›
Private Mode — pause capture
Timer · appended only in timer / hybrid mode
0:42:10
Client A · Platform
These blocks append below the default rows — they never replace them. Timer digits appear in the menu bar only while a timer runs in timer/hybrid workspaces.
IdentityDefault popover = device health + support (R05): Protected headline, Security row, Get IT support. Work rows and the Timer are appendages gated by C-11 workspace config — in an IT-only workspace states 1 and 2 are the entire menu bar experience.
StateThe icon reflects the highest-priority state: normal, attention dot, support-session glyph while a session is active, private/paused glyph when capture is paused, offline glyph when local-only. Work-capture states (Part C) surface only when Work Intelligence is on.
Private ModeLives in the WORK appendage (there is nothing to pause in an IT-only workspace). Toggling pauses work-context capture immediately; the block renders as Private in A-06. Scheduled privacy periods live in A-08.
Support“Get IT support” opens A-04; during an active session the dropdown pins a session row with an End control. No admin capability surfaces here; “Demo Company” links to A-03 for what management means.
A-02 · RemoteDesk Agent · Onboarding · P0
Device management and work capture — explained separately, then enroll
Prototype content (§17.6): explain device management and work capture separately; permissions; company policy; enrollment. The two halves of the product get two distinct cards so consent is informed, not bundled.
DataCLOUDMDMAGENTStatesMDM · Agent → Part C
Welcome to RemoteDeskWireframe · Demo data
1 · Device management2 · Work capture3 · Permissions4 · Company policy5 · Enroll
RD
Two things, explained separately.
Your company manages this Mac. You manage your work record. They are not the same permission.
Device management · for ITApple Device Management
Sets up Wi-Fi, VPN and security settings Keeps FileVault, firewall and OS updates on Installs required work apps Can lock or erase this Mac if it’s lost or when you leave
Work capture · for youRemoteDesk Agent
Builds your day from app/window metadata You review, edit and classify before anything is formal Private Mode and exclusions, always available Your company sees only what you submit
macOS permissions requested next
Accessibility · required for activity metadataNotifications · reminders & supportLogin items · start at loginScreen Recording · never requested — remote screen viewing does not exist in this product
OrderTransparency before permission prompts (§5.11): steps 1–2 explain, step 3 requests, step 4 shows the org’s device + work policies (§5.12), step 5 enrolls (MDM profile, then Agent registration).
Permission deniedIf Accessibility is declined, the Agent still enrolls the device and runs device features; work capture stays off with a persistent, calm fix-it banner (Part E).
StateEnrollment progress mirrors C-05: this device moves Pending → Enrolling → Managed; failures show the same error code the admin sees.
Copy ruleNever bundle the two consents into one “Accept all”. Each card links to its own detail sheet.
A-03 · RemoteDesk Agent · My Device · P0 · was A-06 in V1 · moved forward (R03)
Four questions, answered without asking IT
Prototype content (§17.6): model, OS, management status, Agent status, security, updates, required software — restructured in V1.1 around the four questions an employee actually has: Is my Mac managed? Is it secure? Is anything required of me? What can my company manage? Same underlying states as C-03 — management is visible, so it never feels covert.
DataMDMAGENTStatesMDM · Agent · Compliance → Part C
RemoteDesk — My DeviceWireframe · Demo data
MAC
MacBook Pro 14 · Apple Silicon
macOS 15.5 · SN ····
1 · Is my Mac managed?
ManagementManaged by Demo Company
RemoteDeskConnectedv0.9 · synced 1 min ago
2 · Is it secure?
FileVault encryptionOn
FirewallOn
Security checkUpdate needed
3 · Is anything required of me?
macOS update15.6 available
SlackInstalled
FigmaInstalling
Endpoint AVFailed
4 · What can my company manage?
Security settings, Wi-Fi, VPN and certificates
Required work apps · install and update
Lock or erase this Mac if it’s lost or when you leave Not your files, messages, browsing or personal accounts
TransparencyStates here must equal what C-03 shows for this device — one source of truth rendered on both surfaces, in the same friendly labels (R08; no channel jargon on the employee side either).
Trust-critical“View Device Management Policy” is the trust-critical element of this screen: question 4 is answered by the actual readable policy (the A-02 step-4 document), not a marketing summary. It must always be one click away, never behind support, and always current with the policy version in C-11.
UpdatesOS updates initiated here are user-scheduled (“tonight”); if policy enforces a deadline, the deadline is shown, not sprung.
ErrorsA failed required-app install shows the same error the admin sees in C-08, with Retry and “Ask IT” (opens A-04 pre-filled).
A-04 · RemoteDesk Agent · Support · P0 · was A-07 in V1 · moved forward
Help that announces itself
Prototype content (§17.6): request support, connection status, active remote-session state, diagnostics. During a session, a banner stays pinned with the session state and an End control the employee can always reach (§17.11).
DataAGENTCLOUDStatesRemote support → Part C
RemoteDesk — SupportWireframe · Demo data
IT support session active — an IT admin is running a terminal session (never your screen).
Started 14:02 · 12:41 elapsed · session is audited
Active
Get IT support
Something isn’t working ▾
Requested IT has been notified · you’ll get a consent prompt before anyone connects
Share diagnostics
Send system info and Agent logs to IT to speed things up. You’ll see the exact contents before sending.
Recent sessions on this Mac
Aug 7 14:02 · Diagnostic bundle · you accepted · collected Aug 6 16:04 · Diagnostic bundle · you accepted · collected Aug 2 11:30 · request expired · nothing collected
ConsentThe consent prompt names the admin and states exactly what will be collected (the read-only diagnostic set, shown in full). Decline ends the request as Failed on the Console side — nothing is collected, attempt still audited.
StateSession states mirror C-07 exactly; the banner persists across all Agent screens and the menu bar while Active. Ending from either side transitions to Ended for both.
PermissionsSupport sessions never request macOS Screen Recording — screen viewing does not exist in this product (ADR-0002); support permissions stay separate from work capture (§17.11).
DiagnosticsDiagnostics sharing is explicit-action with a content preview; nothing is pulled silently.
A-05 · RemoteDesk Agent · My Day · P0 · was A-03 in V1 · WORK group · Optional
My work, my numbers, my call
Prototype content (§17.6): current work, work time, sessions, missing/unclassified suggestions, daily summary, End My Day. In V1.1 this is no longer the default screen — Home (A-00) is; My Day heads the optional WORK group and exists only when the workspace enables Work Intelligence (C-11). It remains a personal work journal — deliberately nothing here resembles a monitoring dashboard (§17.16).
DataAGENTStatesWork capture · Time entry → Part C
RemoteDesk — My DayWireframe · Demo data
My Day · Thursday, August 7
You decide what becomes formal. Suggestions never auto-add.
Platform project · 0:42:10
Work time
6.2h
recorded so far
Meetings
1.0h
2 sessions
Breaks
0.8h
incl. lunch
To review
2
1 unclassified · 1 missing →
Today’s sessions
Project sessionsInternalUnclassifiedPrivate · not captured
Suggestions · you confirm, nothing auto-adds
10:12–10:30 · 18 min before your first timer looks like Platform project
same document · same repo
13:44–14:31 · 47 min unclassified session
assign a project or mark break/private
Daily summary · draftDraft
Drafted from your confirmed sessions. You edit and approve — it is never sent anywhere on its own.
Anti-goalNo productivity scores, no percent-active gauges, no comparisons to teammates — the tiles are plain durations under the employee’s own control (§5.14, §17.16).
State“To review” counts exceptions only (§5.10). End My Day opens Daily Review: resolve missing time, classify sessions, approve the summary; unresolved items persist as Needs Review.
DataEverything on this screen is Agent-local plus CLOUD sync of confirmed items; raw events never leave the review pipeline (§5.5 ActivityEvent → WorkSession → summary → optional TimeEntry).
ConfirmSuggestion “Add” creates a session pending the employee’s classification — formal time entries only ever come from explicit action (§5.5 “never silently add”).
A-06 · RemoteDesk Agent · Timeline · P0 · was A-04 in V1 · WORK group · Optional
Understood sessions, with full edit control
Prototype content (§17.6): Simple/Detailed modes; edit, split, merge, classify, private, break. Simple shows understood work sessions; Detailed may expose app/file evidence — to the employee only, per privacy policy (§5.5).
DataAGENTStatesWork capture → Part C
RemoteDesk — TimelineWireframe · Demo data
Thursday, August 7
SimpleDetailed41 events → 6 sessions
09:00 10:00 11:00 12:00 13:00 14:00
Platform project — feature work09:00–10:12
3 activity blocks merged · selected
10:12–10:30 · not recorded — see suggestion in My Day
Internal — code review10:30–11:24
Lunch break12:05–12:48
Platform project — docs12:52–13:40
Unclassified · 47 minAssign ▾
Private14:35–14:52 · nothing captured
Selected session
Platform project — feature work
09:00 – 10:12 · 1.2h
Platform project ▾
All edits are undoable. Detailed mode shows this session’s evidence (apps · files) to you only.
Alternate state · Offline-localOffline-local
You’re offline. Activity is being stored only on this Mac and will sync when you reconnect. Nothing is lost; nothing is sent.
Banner sits above the timeline; the menu-bar icon shows the offline glyph. Queue status in A-09.
LayersAlways distinguish raw evidence → inferred WorkSession → formal TimeEntry (§5.8). Simple mode hides evidence; Detailed reveals it to the employee only.
StateBlock styles are the work-capture vocabulary (Part C): Tracking (solid), Idle/break (paper), Private/Excluded (dashed — no content exists), Unclassified (warning), Offline-local (banner).
InteractionEdit/split/merge/classify/private/break all act on the inferred layer; “Create time entry” is the only bridge into the formal layer (A-07).
PrivacyMarking private retroactively deletes captured content for that span, not just hides it; confirm dialog states exactly that.
A-07 · RemoteDesk Agent · Timesheet · P0 · was A-05 in V1 · WORK group · Optional
The formal record the employee submits
Prototype content (§17.6): weekly entries, project/matter, narrative, hours, status, conflict, export. This is the only layer that ever reaches the Console (C-09), and only when submitted.
DataAGENTCLOUDStatesTime entry → Part C
RemoteDesk — TimesheetWireframe · Demo data
Week 32 · Aug 4 – Aug 8DailyWeekly
Day
Project · matter
Narrative
Hours
Status
Mon 4
Client A · Platform
Implemented enrollment flow error handling and…
7.5
Submitted
Tue 5
Client A · Platform
Device table state chips; review feedback…
8.0
Approved
Wed 6
Internal · Hiring
Interview panel + debrief notes…
2.0
Needs Review
Wed 6
Client A · Platform
Overlaps 13:00–13:30 with the entry above — adjust one of them.
6.5
Conflict
Thu 7
Client A · Platform
Draft — from today’s sessions…
6.2
Draft
Week total 30.2h · 1 conflict blocks submission
StateMachine (§5.9): Draft → Needs Review → Approved → Submitted → Exported; Conflict is a blocking flag raised by overlap detection and must be resolved before submit.
VisibilityOnly Submitted (and later) states sync to C-09. Draft and Needs Review are employee-side; the admin cannot see or edit them.
ExportCSV, Excel, PDF, copy-as-text (§5.9); optional payroll/billing hand-off is a CLOUD integration, out of the Agent’s UI scope beyond the submit action.
BulkMulti-select supports bulk classify/approve/submit; destructive bulk actions confirm with a count.
A-08 · RemoteDesk Agent · Privacy Center · P0
The contract, readable any time
Prototype content (§17.6): what is captured / not captured, exclusions, Private Mode, visibility rules. This screen is the standing answer to “what does my company see?” — current org policy included, in plain words.
DataAGENTCLOUDStatesWork capture → Part C
Principles rendered on this screen
Managed does not mean monitored — device management rights (A-03) grant no work-content visibility. Quiet, not invisible — capture state is always visible (menu bar), and this page always reflects the current policy version.
RemoteDesk — Privacy CenterWireframe · Demo data
Captured · metadata only
Application name and window title Browser domain (never the full URL) File name, with path redaction Time and foreground / idle state Current Timer / project context
Never captured
No keystroke or password capture No email/chat message-body capture No clipboard capture No camera or microphone capture for Work Intelligence Screenshots off by default and not required for the core product No remote screen viewing — support cannot see your screen. The capability does not exist in this product (ADR-0002).
Exclusions
Personal browser profileExcluded
Banking sitesExcluded
~/Personal folderExcluded
Private Mode
Pause capture now
Scheduled privacy daily 18:30 – 09:00
Takes effect immediately. Private time shows as a dashed block — content is never captured.
Who can see what
IT admin · device & security state only Approver · timesheets you submit No one · your raw timeline, private time, excluded activity
Org policy: Work capture v2 · view full policy →
Your data. View, export or delete your personal work data (deletion honors org/legal retention where it applies — the screen says which).
SourceCaptured / never-captured lists are the §17.11 and §5.5 defaults verbatim; if the org enables anything beyond defaults (it cannot enable screenshots without a separate permission), this page shows it before it applies.
StateExclusion and Private states are Part C work-capture states; the menu bar reflects them instantly.
Data controlsView/export/delete per §5.11; delete requests that hit retention rules explain the rule instead of failing silently.
A-09 · RemoteDesk Agent · Settings · P0
Reliability, in one compact page
Prototype content (§17.6): sync, launch at login, shortcuts, offline queue, updates, diagnostics. Nothing clever — the settings a distributed employee actually needs when the network is bad.
DataAGENTStatesAgent → Part C
RemoteDesk — SettingsWireframe · Demo data
Connection
StatusSynced · 1 min ago
Offline queue0 pending · 0 failed
Behavior
Launch at login
Shortcut · Start/stop timer⌥⌘T
Shortcut · Private Mode⌥⌘P
Agent updatesAutomatic · v0.9
Data & diagnostics
Local data retentionPer company policy · 90 days
Diagnostics
OfflineQueue shows pending/failed counts (§5.13); failures list per-item errors and retry. Offline-local capture state is announced in A-06 and the menu bar, not buried here.
Repair“Repair agent” reinstalls Agent components without touching MDM enrollment; it warns what it will and won’t change.
PolicyRetention is read-only when set by org policy, with a link to the policy text in A-08.
Part C · State reference sheet · design-system extension (§17.17)
The badge vocabulary — all eight state matrices from §17.14
These chips are the design-system extension developers implement once and reuse everywhere: MDM/Agent/compliance badges, support-session states, work-session blocks and lifecycle states. Colors are the semantic set — volt never encodes status.
Color languagehealthy / positivetransitional / attentionfailed / violationnot yet / inactiveformal / submitteddormant / terminalprivate / excluded — content does not exist
Deviceoverall device record · shown beside the serial · C-02, C-03, C-10
Time entrythe formal layer · §5.9 state machine · A-07, C-09
Draft→Needs Review→Approved→Submitted→Exported+Conflict·Draft & Needs Review are employee-side; the Console sees Submitted onward (plus entries routed for approval)
Lifecycledevice asset journey · board columns in C-10 · readiness checks in C-12 · recovery timeline in C-13
ImplementationOne chip component, seven visual variants (ok / warn / bad / mute / ink / out / private-dashed). State names are the API strings; do not rename in the UI.
RuleMDM, Agent and Compliance are three independent chips on any device row — a device can be MDM-Healthy and Agent-Offline at once (C-02 shows this on purpose).
Volt disciplineVolt marks selection, primary CTAs and brand accents (active tab underline, selected card outline). If a chip is volt, it’s a bug.
Part D · End-to-end flows (§17.15) · seventh flow added in V1.1
Seven flows the prototype must walk without dead ends
Each node names the screen that hosts it. These are the click-through paths for the Figma/coded prototype — and the demo script: new hire → Day-1 ready → daily work → support → offboarding/recovery (§17.17). Screen references use the V1.1 numbering (Part B was renumbered; each renumbered screen carries a “was A-0x” note).
Reassign / retireback to D-1 or end of lifeC-13 → C-05
D-7 · Day-1 readiness
new in V1.1 · R06b · the demo’s opening flow
Employee createdstart date setConsole · People · New Hires
→
Device sourcedinventory or procureC-10 · C-12
→
Shiptracked to the employeeC-12
→
Enrollmanagement profile installsC-05 → A-02
→
Agentconnects · first heartbeatA-02 · C-12
→
Policydevice + work appliedC-11
→
Softwarerequired apps installC-08
→
DAY-1 READY ✓all checks pass before startC-12
PrototypeEach flow must be walkable in the prototype without dead ends; error branches (Failed enrollment, Failed session, Conflict) route to the alternate states in Part E.
RetentionD-6 preserves required audit and approved work/timesheet records per retention policy even after wipe (§6.2.8).
Part E · Required prototype states (§17.16)
Non-happy paths the prototype must demonstrate
§17.16: design empty, loading, offline, permission-denied, failed-command, non-compliant and recovery states. This index says where each one is demonstrated in this document; three screens carry full alternate-state mini-frames.
Required state
Demonstrated on
Notes
Empty
C-02 mini-frame · C-10 empty columns
Empty ≠ error: always an explanation plus the next action (send invitation).
Loading
C-02 mini-frame · C-01 annotation
Skeleton blocks, never spinners over stale numbers.
Recovery devices are unassigned but still audited; wipe path is D-6. C-13 adds the overdue-return escalation.
Alternate state · Permission-denied (Console, Work area)example
LOCK
Work records need the work role
Device administration doesn’t include work visibility. Ask a workspace owner to grant the approver role if reviewing timesheets is part of your job.
Alternate state · Permission-denied (Agent, Accessibility off)capture off
Work capture is off. macOS Accessibility permission was declined, so nothing is being recorded. Device management still works. Open System Settings →
Calm banner in A-05/A-06; menu-bar icon shows the paused glyph. Never a blocking modal.
MandateThe three full alternate-state mini-frames live on C-02 (empty + loading/cached), C-07 (failed session) and A-06 (offline-local banner); this page adds the two permission-denied patterns.
ToneError and empty states use the same calm register as the rest of the Agent — especially on employee screens, where alarm styling would read as monitoring pressure (§17.16).