Repository navigation
Fulcrum v4.0.0
Release notes
IMPORTANT NOTE:
- macos dmg release asset removed since I forgot to notarise it (I didn't know that step was necessary after developer signing; the latest version has been notarised).
What's new
One idea defines this release, carried through eight adversarial repairs:
the score now prices authority by scale. Machiavelli holds both positions
and the model encodes their union: The Prince (concentrated authority
governs the small state well) and the Discourses (the durable large state
is an institutionalised republic), hinged on the Dunbar horizon and
grounded in the light-cone axiom rather than preference. The claim was
then attacked adversarially, every finding repaired and every repair
pinned by a conformance test, so the scale dependency is structural and
checkable rather than an asserted preference. Alongside the model: two new
signals, glossary entries for the new vocabulary, a calibration harness
for lived-experience organisations and an updated preregistration.
- The prince band. Five new coefficients in
SimulationParameters
(dunbar_headcount150,prince_band_upper200,prince_attenuation0.3,
prince_amplification0.25,prince_survivor_ceiling1.6). Up to 150
people the three authority charges (capacity cut, escalation share,
influence divisor) cost 0.3 of their flat price; the price rises linearly
to parity across 150 to 200, then grows with the log of the population and
caps at 1.6. The cap is survivorship made structural: rare princes persist
at scale, so concentration is graded, never prohibited. - Frames are priced at their own population. Rolled unit nodes and leaf
frames now carry real headcounts, so a Dunbar-sized pocket deep inside a
conglomerate may stay princely in its own frame while the frames above it
demand a republic. - Contest is never forgiven. The attenuation applies only to clean
concentration; a standing claim keeps its full flat price below the
horizon and above the band it deepens in proportion to the scaled
escalation price, so a contested team's capacity sits strictly below a
merely escalating team's at every scale. This closes the adversarial
finding that the first cut let contest and clean escalation converge to
the same capacity price at scale. - A full republic is scale-invariant. A structure with local authority
everywhere and no claims scores identically at every population; the
band leaves the well-designed archetype column untouched (the routed
dependent demand below moves it separately, since even a well-designed
organisation carries supplier hubs). - Resolution neighbourhoods. Two adversarial findings closed in one
mechanism. Each escalating team resolves at the nearest enclosing unit
whose subtree holds a clean authority: its concentration charges are
priced at that unit's population, so a team whose lead sits across the
desk is never priced at conglomerate scale (an org of 100 empowered
50-person pockets now reads the same headline at any unit count), and
escalation_load_share(0.25) of its workload lands on that unit's
authorities' queues, so a founder absorbing thirty teams' escalations
saturates and prices itself as latency. The shed load is deliberately
not attenuated by the band: the band forgives friction, never bandwidth. - Fragmentation is priced (unowned interfaces). The fourth adversarial
finding closed: a dependency between two clean sovereigns that share no
enclosing domain has no institutional roof under which its conflicts can
be arbitrated, so each such edge pushes its endpoints toward the
cannot-decide-cleanly share, weighted byunowned_interface_weight(0.5)
and scaled by the prince factor. Two roofless founders stay near-free;
a roofless network of 200 sovereign teams at 20,000 people falls from
98.8 to 70.4, while the same network under a declared common roof keeps
its score: the roof is a modelling claim that a shared owner exists.
Machiavelli's republic is institutionalised: a senate, not merely
distributed sovereignty. - Dependency concentration prices itself (routed dependent demand).
The escalation machinery priced authority concentration while a fully
empowered dependency hub rode free: a five-person team that thirty-four
teams wait on read as healthy (the matrixed-enterprise sample exposed
the gap once its Developer experience section was delegated: the hub
fan cost about one point against the same teams in disjoint pairs).
dependent_demand_weight(0.15) now routes that fraction of the
frame's workload from each dependent onto its upstream's queue,
authority notwithstanding, grounded in Little's law and LatencyLab's
serial-queue placement result. The imbalance floor keeps a light
fan-out free, so the cost begins where the queue does; the coefficient
is held at or belowescalation_load_share(enforced in code) since
waiting on a supplier may never cost more than resolving through an
authority. The 34-fan hub now prices 5.6 points below its distributed
twin, every calibration case stays in its band and the knife-edge
greedy great on the enterprise archetype (+9.09 against the 9.0
threshold) honestly becomes a strong good. - Frames carry their roof. A focused frame previously dropped its
enclosing domains, so every edge between two sovereign teams inside a
drilled section read as roofless fragmentation (a fully roofed section
showed "Unowned interfaces: 34") while the whole-org score priced the
identical edges as roofed: the same fact, two prices. Every focused
frame (a leaf section, an aggregate unit, a mixed unit's direct-teams
row) now keeps its subtree's domain rows with the root cut loose from
the world outside, so in-frame pricing agrees with the whole
organisation; section scores rise wherever a roof genuinely stands and
the whole-org score is untouched. The top-level frame stays roofless
deliberately: nothing above the top level is modelled. - The matrixed enterprise drills sanely. The calibration sample's
oversized sub-units (a lead plus thirty-four flat teams) now split
into led groups of a handful of teams each, so every leaf has a sane
span and the case reads as the drillable hierarchy it claims to be.
The matrix claims the group leads exactly as it claims the unit and
sub-unit leads (line leadership is dual-reported all the way down),
so the documented-collapse shape survives the restructure and the
case scores 16.3 inside its 0..30 band. - Influence is priced proportionally. The third adversarial finding
closed: the influence divisor reads the per-team mean rather than the
absolute load, so one no-authority advisory hub with ten dependents
costs a 5,000-person organisation 3.4 points instead of half its score.
A knock-on stated honestly: the approval-layer blunder softens on the
large archetypes (enterprise -2.59 vs best repair +3.15 with dependent
demand priced), so the site now says a blunder erases most of the best
repair rather than outweighs it. - Archetypes carry a Company roof. All ten example organisations now
declare the common domain their real counterparts have, which is what
keeps the well-designed column's sovereign interfaces owned. - Claims are priced proportionally. The claim divisor reads the
per-team mean like the influence divisor, so a standing claim costs the
share of the organisation it contests rather than a flat tithe: one
claim on a 5,000-person org costs about a point, not nine. - Shed load follows the wiring. A resolving authority receives the
escalations it actually has dependencies with, so a disconnected puppet
authority absorbs nothing and cannot launder a saturated founder's
queue; wiring the puppet in costs coupling on both ends. Escalators with
no edge to any resolving authority fall back to an equal split. - A roof needs an officer. A shared domain owns its sovereigns'
interfaces only when its subtree holds a clean authority beyond the two
endpoints, so two sovereigns alone under a nominal roof stay unowned. - A claim is strictly additive. Contested no-authority teams still
shed their escalations (a claim disputes who clears the queue, it never
drains it), structural sovereignty keeps an unowned edge unowned when a
claim lands on it and the matrix-overlay actor is now an unmodelled
claimant beside the delivery graph rather than a team, so imposing an
overlay can never dilute the per-team means or relieve a loaded centre. - Two new signals. Centre escalation load (the escalated decisions per
turn landing on the most loaded authority) and unowned interfaces, each
with its own definition and tooltip, so the new pricing is observable in
the app rather than silent. - Glossary grows the new vocabulary. The prince band and the Dunbar
horizon, resolution neighbourhoods with escalation load and unowned
interfaces, in the same plain register as the rest. - Calibration harness.
python calibrate.pyscores the organisations
inexamples/calibration/against expected bands drawn from known
outcomes, with a template for adding lived-experience cases; three
synthetic seed cases mark the healthy, saturated and matrixed shapes.
Each case is a real drillable hierarchy whose leaf teams hold three to
eight people with varied sizes: the startup's eighteen squads group
under three tribes and the enterprise is generated deterministically
(generate_matrixed_enterprise.py, seeded) as eight divisions, 45
domains and about 1,100 small teams with the matrix claiming every
line lead, so drilling into any case shows real structure at every
level. Calibration cases are permanently ineligible for the
preregistered blind validation, stated in both documents. - Organisation menu. The organisation entry points (new random,
model my organisation, edit my org and the examples submenu) move from
File into their own Organisation menu, leaving File to presentation,
import, export and exit. - The quick-org wizard is retired. The two-pane editor starts at any
tier with a seeded draft and named leads, and random generation covers
the fast first position, so the wizard had become a third entry point
to the same choices. An organisation the editor builds now records the
origin "modelled"; files saved under the wizard's old origin still
load, arriving as modelled organisations (the migration happens at the
JSON boundary, so the model carries no dead vocabulary). - Icon header buttons. Model my organisation, Edit my org and Show
the guide become icon-only buttons drawn in the app palette (org tree,
pencil with blue stripe and red tip, climbing arrow), their old text
living on as tooltips; the New random organisation button leaves the
header for its Organisation menu entry. The icons are generated
deterministically bygenerate_button_icons.pyintoassets/buttons
and ship in every build. - Help content auto-scrolls. About, both licences, the decision
glossary and Book background read themselves down slowly, hold at the
bottom, rewind and repeat, in the ClearBudget Help About manner; any
manual scroll suspends the cycle and it resumes from wherever the
reader stopped. The board's available-moves list joins the cycle when
it overflows, behaving exactly as the help dialogs do; keyboard focus
entering the list suspends the cycle the same way a manual scroll
does, so it never fights the reader. The whole family reads down at
one standard pace, halved from the first cut so dense content stays
readable, and every surface holds still for five seconds on opening
before its first descent, so the reader orients before anything moves.
While a dialog sits above the board only the dialog's own surfaces
read: anything beneath freezes in place (its position and remaining
hold untouched) and resumes the moment the dialog closes, so two
moving surfaces never compete for the eye. - The top-level frame offers no moves. Every move is made by an
authority above its target and nothing sits above the top level with
the authority to make one, so the frame where root units are the
actors now offers an empty palette; its score, signals and priced
dependencies remain and the focus note explains the absence. The
hierarchy guide plans no top-frame row for the same reason: repairs
live in the frames beneath, where a roof exists to make them. - Play this level never lands on a single box. A lone top-level
unit (one Company wrapping everything) made the toggle show one huge
tile with nothing to play. The toggle now drills through lone tiers
to the first level that shows more than one actor, descending a chain
of lone wrappers as far as it needs. The map follows: when the landing
is the wrapper whose contents the complete picture already draws, the
picture simply stays; any deeper landing opens the drill map at that
section. - The guide's progress bar reports the whole build and fills once. On
a large organisation the bar froze mid-way: sections plan in seconds,
then the composition guard (pricing every leaf line against the whole
org) and the whole-org growth step ran for minutes with no reporting.
Progress units now cover every long phase: one per section, one per
line the guard prices and one per chunk of candidates a growth step
valuates. The whole total is declared up front from reserves that
bound the open-ended phases, so the reported fraction never decreases:
the bar no longer refills from full each time a phase extended the
work, a phase that overruns its reserve holds just short of full and
only the finishing snap reports complete. On the shipped 6,000-person
case the longest silent gap falls from about a minute to under a
second and the bar climbs monotonically to a single close. - The guide builds on every core. The guide's two long phases are
independent piecework: the composition guard prices each leaf line on
its own and a growth step valuates independent candidates. On a large
organisation those now run on a pool of worker processes (threads
cannot help: the interpreter lock serialises pure-Python compute),
with every task pricing exactly what the serial loop prices and the
results reassembled in submission order, so the guide is bit-identical
with and without the pool. Small organisations stay serial, a broken
pool degrades to serial pricing mid-build and one core is left to the
interface so it keeps painting. On the shipped 6,000-person case the
fixed guide falls from about a minute to nine seconds and the grown
build from about six minutes to forty-two, on a twenty-four core
machine. - Both planning bars can be cancelled. The guide's progress dialogs
(planning every level, planning growth) now carry a Cancel button, so
a machine without the cores for the worker pool is never trapped in a
long serial build. Escape presses it too; a cancel-less busy dialog
now swallows Escape instead of closing over a still-running worker.
Cancellation is cooperative and prompt on every path: the build
checks at every planner step, valuation chunk and progress tick, the
pool waits for results in short slices so a request lands even while
its worker processes are still spawning and the pool is released
without waiting for stragglers (workers finish their current chunk in
the background and exit). Serial or pooled, warm or cold, the bar
closes within about half a second of the click.
A cancelled fixed build simply closes; a cancelled growth build
releases the grow toggle, which asks again on the next flip. No
partial guide is ever shown. - Playing a guide move replans off-thread. Playing a move from the
guide used to rebuild the fixed guide synchronously, freezing the
interface for the build's full length on a large organisation. The
rebuild now runs off-thread behind its own cancellable bar
(Replanning every level) and the fresh guide lands in the open
dialog when it completes. Cancelling closes the guide instead: the
move itself is already played and the board already updated. - The installer asks before touching a running app. Installing,
upgrading, repairing or uninstalling while the app was running used
to leave a quiet note in the installer's status line. The installer
now raises a proper ask: close the app, then Retry, with Cancel
abandoning the action and a premature retry answered with a
still-running notice. The registered uninstaller in the Apps list
asks the same way. - The grown guide plans on demand. Opening the guide used to build
both variants up front, and on a large organisation growth planning is
most of the wait. The guide now opens on the fixed plan alone and the
grown variant builds only when the grow toggle first asks, behind its
own progress dialog; playing a move from the guide rebuilds the fixed
plan and drops the stale grown one, which rebuilds lazily if asked
again. On the shipped 6,000-person case the guide opens in about a
quarter of the old time, and nobody pays for growth they never look
at. The dialogs' shared open-at-most-of-the-window sizing rule also
moved into one helper (dialog_sizing) instead of three copies. - The app opens maximised. The board's side panel was truncating move
labels at the default half-screen width, so the window now launches
maximised; un-maximising restores the old sized, centred geometry. - Windows names the process Fulcrum. Task Manager and Explorer show
an executable's FileDescription, which carried the tagline
(Organisational Simulation Tool), so the process list named the app by
its subtitle. The build now stamps the app name there (and Fulcrum
Setup on the installer); the new name shows once the app is rebuilt
and reinstalled. - Quit requests are honoured while a dialog is open. Qt discards a
close request aimed at a modally blocked window before the app can see
it, so a programmatic close (a graceful taskkill, an automation tool)
arriving while a dialog was up used to vanish without effect. A native
guard now catches that request, dismisses the open dialogs and runs
the ordinary close flow, autosave included. Closing from the taskbar
while a dialog is up follows the Windows convention instead: the
dialog is brought forward to be answered first, exactly as native
apps behave. - The complete picture is the board. The board's map area now opens
as the complete overview (every domain and team at once) and clicking
any domain drills straight into that section on the navigable map, at
any depth; climbing out of the top returns to the picture. The old
separate overview dialog is gone: it had become a duplicate of views
the board now simply has. Two shape rules keep the picture honest: a
lone wrapper tier (one Company holding everything) is skipped and its
contents drawn directly, with the drill map's climb matching so the
identical tier is never shown twice; and several root companies draw
inside one synthetic dashed "Shell" tier, presentation only, so a
multi-company group reads as a group without asserting a modelled roof
the score would price. A real governing tier (a Board above companies,
or one within a company) is modelled as a unit with a custom label,
which nests anywhere. Enter on the focused picture hands keyboard
users to the drill map, where the full node cursor lives. The picture
keeps its human-readable scale, opens anchored at the topmost entity
(it used to fit before the pane had its real size, cutting off the top
and bottom) and a picture taller than the pane reads itself down at
the app's standard auto-scroll pace, suspending the moment the wheel,
a drag, a click or keyboard focus touches it. - The app icon opens the move record. The centre tray button (the
glowing Fulcrum mark, on the same plate in both themes) now opens the
live sibling of the exportable presentation: every move to date as a
list (earlier runs marked and dimmed, exactly as the record persists
across app restarts through the autosave), and for the selected move
the complete picture of the organisation it acted on, with a toggle
between the position before the move and the position after it and
the structural-health climb stated beside them. File Export and
Import already carry the whole record with the organisation, so a
shared JSON resumes with its history intact. - The guide shows real progress. Planning every level used to sit on
a bar stuck at full; the planner already counted its sections, so the
busy dialog now starts empty and fills genuinely across both passes
(fixed then grown), while the generating dialog keeps its indeterminate
animation. - The electric-glow app icon. The icon set is regenerated with the
approved treatment baked intogenerate_icons.py: the master's
near-black backdrop keyed to real transparency, the colours lifted and
a soft halo composited beneath, so the mark reads on any surface. The
window, taskbar, About dialog, header overview button, Windows
installer, macOS disk image and Flatpak all carry it. - Light and dark themes. The whole stylesheet now builds from a
palette (the shipped look stays the dark palette) with a light
alternative: amber stays the meaning colour in both, deepened to read
as ink on light surfaces. The organisation map follows the theme too:
the painters resolve a per-theme map palette, so the canvas, node
fills, edges and the authority encoding (green decides locally, amber
escalates, violet is contested) all repaint on switch with their depths
re-weighted to read on either surface. A sun/moon toggle sits left of the header's right-hand
links, showing the theme a press switches to; the choice persists in
per-user settings and the generated header icons swap to dark-stroke
variants in light mode. - Scores and move values show three decimals. At whole-organisation
altitude a real improvement can be worth hundredths of a point, which
one decimal rendered as nothing at all. Every rendered score and move
value (the board's headline and move list, the preview dialog, the
guide's badges and climbs and the exported HTML report) now carries
three decimal places from one shared constant, so a small honest gain
is visible instead of reading as +0.0. - Scoring is an order of magnitude faster at scale. The scale pricing
used to rescan the whole organisation once per escalating team; a
one-pass population table now prices every resolution neighbourhood in
a single walk, taking the six-thousand-person example from 60ms to
under 3ms per score with identical results (the golden archetype
numbers and every calibration band are unchanged). Planning the whole
guide for that organisation drops from minutes to seconds. - Growth planning is never refused, and says what it did. A large
organisation used to report "too large to plan growth live", wrongly
implying growth planning was off entirely when every frame still
planned its own growth. Past the live-planning size the whole-org
growth line is now planned rather than refused: over the organisation's
most coupled teams (growth pays where the edges live) and with fewer
greedy steps, with the line's detail stating that scope plainly. When
no shortlisted move clears the planner's bar the row is simply absent,
like any other gainless line. - The record names the move you played, not its expansion. Playing a
move on a rolled unit (delegating a whole division from the top level)
used to record the translated act against every real team, so the
"Last move played" note became a wall of dozens of team names. The
label is now captured in the frame it was played in, as the same text
the player clicked ("Delegate authority to Platform division"), while
the stored move still carries the real teams so history replays
exactly. As a backstop, any genuinely wide name now stops at three
teams and counts the rest ("A + B + C and 28 more teams"). - The numbers now account for themselves in-app. A golden kin of the
app icon (the same mark retinted and glowed by the icon generator)
sits beside it at the tray's centre and opens "What grounds the
numbers": every coefficient in the model with what it does, the
mechanism source in the books, whether its magnitude is evidence,
experience or judgement and how fragile the conclusions are to it
(the sensitivity sweep and calibration bands, stated plainly). Every
value on the page is read live from the parameter objects and a test
fails the build if a coefficient exists without an account, so the
page can never drift from the model. The centred pair also grew: both
marks now sit larger on a tighter plate, so the icons read at full
presence. The page wears the same identity banner as the move record
(its golden mark beside the accent title), from one shared builder. - The guide shows where growth has any effect. With the grow toggle
on it was invisible which levels growth actually changed; the toggle
now wears a dedicated growth blue when on and every tree row whose
line growth changes wears the same colour (the whole-org growth row
included), so cause and effect share one colour and an untouched row
visibly stays plain. The blue is theme-aware (deepened to read as ink
in light mode) and deliberately neither the amber meaning colour nor
a ring colour. - The planning dialog paints before the work starts. The guide's
progress dialog could sit as a blank white rectangle for seconds while
the planner's tight loops held the interpreter; the window now paints
before the worker thread starts, so the bar is visible from the first
moment. - The editor opens large organisations instantly. The dependency and
claim tables used to hold a live combo box in every cell, each filled
with every node, which priced the six-thousand-person example at
millions of combo inserts and hung the interface for minutes. The
tables now hold plain rows and a pick combo exists only while a cell
is being edited, so the same organisation opens in a fraction of a
second with the round trip byte-identical. - No uninvited focus rings. When the toolkit hands focus back after
a menu or dialog closes, it used to land on a header button and light
its keyboard ring though nothing was selected. The navigator now
bounces any focus the user did not cause (popup close, window
reactivation) to the neutral start, so a ring appears only where Tab,
Shift+Tab, a shortcut or a real click put it. - Examples in the app. Organisation | Open example organisation lists the
calibration cases by label with their outcome note as the tooltip; a
chosen example loads onto the board as an imported organisation, ready
to inspect, play and rework in the editor, with the usual confirmation
when opening one would discard played moves. The examples ship in the
Windows, macOS and Flatpak builds and the menu simply stays disabled if
the directory is absent. - New published archetype numbers. Typical: startup 83.4, scale-up
44.9, enterprise 18.8, very large 15.1, conglomerate 12.0 (the influence
normalisation lifts the large typical archetypes; the startup dips as
its escalator's shed load follows the wiring onto one authority; routed
dependent demand then prices every archetype's supplier hubs).
Well-designed: 98.7, 88.9, 75.9, 66.8, 64.9 (the startup holds no hub
worth pricing; the rest pay their hubs honestly). The site (model.html,
why.html, tool.html) is updated in the same change. - Conformance suite.
tests/domain/test_authority_scale.pypins the
band claims C1 to C10 (autocrat scores well small and badly large,
monotone penalty, roofed-republic invariance, widening republic
preference, saturation, edge continuity, contest never forgiven,
delegation reads larger at scale, the pocket principality) and
tests/domain/test_resolution_conformance.pypins the repair claims C11
to C17 (escalation loads the centre, escalation priced at its resolution
distance, fragmentation priced under no roof, influence priced
proportionally, claims priced proportionally, shed load follows the
wiring, a roof needs an officer), so the scale dependency is checkable,
not asserted. - Sensitivity extended. The prince floats join both sweeps (the integer
band edges stay outside as structural counts); all five qualitative
conclusions survive every axis perturbation and 100% of the 1,000 joint
draws under the new model. - The picture rings what a click opens. Hovering any section on the
complete picture rings it in green (the same open cue the drill map
has always given), so the drill target reads before the click; the
display-only maps in the move record show no cue a click could not
honour there. - The picture's units carry their subtree's state. A domain box on
the complete picture used to draw a flat amber border whatever lay
inside it, which left the move record's before and after positions
looking identical when a move acted below the drawn level. Domain
borders now roll their subtree up exactly as the drill map's unit
nodes do (violet when any member is contested, otherwise blending
amber toward green with the share of teams deciding locally) and
every unit box carries a rollup line of the numbers themselves
("23/161 decide · 41 contested"), so a delegation deep inside a
division that stays contested throughout still visibly changes the
box. The move record also rings the nodes the selected move acted on
in both positions (a summarised team rings its nearest drawn
ancestor) and states the move's concrete delta in a line of its own,
located by the unit it happened in ("now deciding locally: 31 teams
in Messaging"; claims, dependencies, delay and incentive skew read
the same way), computed from the two positions, so every move kind
shows what it changed even where no map encoding can. Each line
keeps to one frame: the caption carries the shown position's own
structural health (so stepping visibly changes the number) and the
change line carries the move's climb and located delta. - The record walks its positions sequentially. Instead of a worded
before/after toggle, emoji arrow buttons (with hover text) step a
position cursor over the whole timeline, from the original
organisation to the position after the latest move, where the dialog
opens; the list carries the whole timeline too, "0. The original
position" first (muted, as the earlier runs are) then each move, and
clicking any row jumps straight to that position.
An arrow at its end of the timeline disables (wearing the standard
red ring) and the dialog carries the full keyboard model: it opens
focused on the move list, Up and Down walk the moves there, Tab and
Right step the ring forward (list, arrows, Close, wrapping), Shift+Tab
and Left step back, dead arrows are skipped, Enter and Space activate
the focused control and Escape closes. The dialog wears an identity
banner (the glowing mark that opened it beside an accent title, in
the header tray's manner) and joins the self-reading family: a long
move list or a picture taller than its pane reads itself down at the
standard pace, yielding to any manual input. - Both maps zoom. Corner + and - chips act on whichever map is
showing and the + and - keys do the same on the focused map. The
complete picture steps within its wheel-zoom bounds; each drill level
opens at its own fit and zooms over it in quarter steps up to four
times, with the fit as the floor the minus returns to, so a wide
level's small type is one press from readable. Zooming the picture
also counts as reading by hand, suspending its self-reading cycle. - Contested reads violet, not red. The contested encoding across
both maps, the move previews and the SVG export moves from red to a
theme-weighted violet: a sea of red read as an error state when it is
a structural signal, and red beside the green hover ring collapses
for red-green colour-blind players where violet stays distinct. - The installer catches up with the app. Every button is dark grey
with a light blue caption, so the green hover and focus ring (the only
hover reaction) reads against every fill; the amber stays on the
headings as branding. Launch is neutral, exactly like the app's main
window: nothing wears a ring until the mouse hovers or the first Tab
enters the ring. Enter activates the focused control exactly as
Space does, checkboxes are
visible in both states (muted outline unchecked, amber filled
checked), the native inner focus rectangle no longer doubles the ring
and the installer notice and both licence texts read themselves down
at the app's standard auto-scroll pace, opening with nothing ringed. - The icon fills its tile. The generated icon set is trimmed to the
artwork's ink (a mass-based crop, so the faint orbit trails no longer
hold wide margins open) and re-squared with a thin breathing margin,
so the mark reads at full presence in the taskbar, the title bar and
the installer instead of floating small in transparent padding. - Preregistration updated. PREREGISTRATION.md now names this release
as the earliest depositable model, describes the scale-dependent
mechanics and conformance suites in the frozen-model section and
permanently excludes calibration cases from the blind validation set.