Skip to contentWolf-Rayet

Decision records

ADR-0021 The component set reopens to Carbon's published roster

Accepted2026-09-01Phase 4, reopened

#Context

Seven components are built, and each carries the full battery: a generated component tier complete in every theme it is chromatic in and every density it is spatial in, the level rule, APCA floors, the field-day no-hairline check, a recorded field-night hue count, a monotonic size and weight ladder, motion grants with the reduced-motion collapse, Storybook specimens, tone records, content-lint against real shipped copy, registration in the nesting lint, and at least one fixture scene with a committed receipt. 191 component tier tokens, 768 contrast checks, one distinct hue in field-night for every one of them.

The docs site ships that evidence: 105 routes live at r136.dev, every receipt published including the six scenes declared to fail, the decision register generated from these files, the enforcement table, and the ninety-second demo running the real engine server-side. Phase 6's remaining gap is the pairing matrix, not the components.

What seven components cannot do is test the claim §3 makes about itself. §3 says the authority question "has exactly one answer per component and no ambiguous cases." Seven components — four Emitters and three Arbiters, no Scope, no View, no Substrate — is not a test of that. It is a demonstration on the easy half of the model. Carbon's roster is the test: forty-odd components spanning overlays, shells, tables, forms and content surfaces, assembled by a team that was not thinking about this system's premise, is the nearest thing available to an adversarial sample.

There is a second force, and it is about how the work is read rather than about whether it is right. A reviewer's first question of a design system is coverage. A receipt cannot answer that question, because the reviewer has to already believe the system is a system before the receipt means anything. Seven components with excellent receipts reads as a prototype with excellent receipts.

§11 says the opposite of what this record decides, in terms, and it was right when it was written: there was nothing built, and breadth without the mechanism would have produced sixty pieces of scenery. The mechanism now exists and is machine-checked. The constraint that protected it has become the constraint holding it at prototype scale.

The roster below was read from Carbon's own sitemap on 2026-09-01 — 44 /components/<slug>/ entries, one of which is that section's index page rather than a component, leaving 43 published components.

#Decision

The component set expands from seven to Carbon's full published roster. Every component on it is designed in field-night first per §4, carries the same battery the existing seven carry with no reduced variant of it, and declares its layer by answering §3's authority question — *what authority does this have over attention?* — against its own behaviour, never by analogy to Carbon's grouping of it. A Carbon component whose premise this system has no position on is dropped by name with its reason rather than carried as a name that will not be built. The four components this system already ships that Carbon does not publish stay on the roster, because removing built work to match someone else's index would be the same error as inheriting their taxonomy. The roster is 45 components: 41 carried from Carbon's 43, plus those four, of which 7 are built.

#Rejected options

Hold at seven. What §11 currently says, and the option with the strongest internal logic: every component carries a complete battery, the receipts are the portfolio, nothing on the shelf is unproven, and the cost of the next component is fully known. It lost because a seven-component library is not read as a design system regardless of the quality of its receipts. Coverage is the question a reviewer asks first and a receipt is an answer to a question they have not asked yet. It lost a second time on §3's own terms: the claim that the authority question has one answer per component and no ambiguous cases is untested against a sample that contains no Scope, no View, and no component anybody else designed.

A middle roster — twenty components, or "the ones a product actually needs", or §11's own twelve. It had the best cost profile of the three and a real principle behind it: build what a supervisor tool needs and stop. It lost because any line short of the full set is arbitrary and has to be defended per component. Every omission becomes a question — why no tree view, why no date picker — with no principled answer available, only a budget one, and the defence costs more attention over time than the build costs once. The full set is the only line that defends itself without argument.

Adopt Carbon's grouping as the layer assignment. Free, immediate, and Carbon's groupings are considered rather than accidental. It lost because Carbon groups by form and this system groups by authority over attention, and those are different questions with different answers. §3 derives its tiers from its own premise specifically to avoid inheriting a taxonomy whose boundaries were drawn for something else — assigning tile a layer because Carbon files it under one heading would reintroduce the exact failure §3 names: tiers borrowed from a domain where the boundaries are real, applied where they are not.

Build the roster without the battery — specimens first, receipts later. The roster count arrives in a fraction of the time, and the gallery would look complete. It lost because the battery is the system. §11's own word for a component without a receipt is scenery, and shipping forty-five pieces of scenery is precisely the failure the seven were built to disprove. A component that cannot pass the battery is not shipped late; it is not shipped.

#Consequences

This contradicts §11 and amends it. §11 says "Depth on twelve components beats shallowness on sixty." That sentence is amended by this record rather than quietly ignored: depth is a per-component property and breadth is a property of the set, and this system now claims both. The amended reading is that depth on forty-five beats depth on seven, and that a component which cannot carry the battery does not join the set at any roster size. The old sentence stands as the reason the seven were built first, which is why the mechanism exists to scale.

What §11 still governs, unchanged. The ninety-second demo is still the test every build decision is measured against, and the failing check is still the portfolio. What changes is the reading of "if a piece of work does not make that ninety seconds sharper, it waits": a roster that proves the layer model, the ladder and the two-tier demand ration hold across forty-five components makes the demo's claim larger rather than diluting it, because the claim being demonstrated is about the system and not about the component on screen. A component added without a scene, a receipt or a tone record makes the demo weaker and is refused on §11's own authority.

§14's Phase 4 is reopened. Its exit criterion is restated by this record as the build sequence below, in place of the five named components. The gate ordering in §14 is otherwise untouched.

The enforcement surface does not grow with the roster. The generated pairing matrix is keyed on layers, levels, themes, densities, motion classes and easings — never on component names — so it stands at 194 cells across 10 dimensions today and stays there at forty-five components. No new check kind is added by this decision. What grows is the fixture set: every attention-carrying component earns at least one scene, and a component whose illegal case is a compile failure rather than a render says so in its own record, as the meter, the input field and the table row already do.

A third layer acquires its first components. Everything built today is an Emitter or an Arbiter — no Scope, no View, no Substrate. The roster is 21 Emitters, 15 Arbiters and 9 Scopes. A Scope holds no allocation, it distributes one, so those nine declare a stacking context and a density and no level, and they are the first test of the Scope contract outside a fixture. View and Substrate still acquire nothing: a View is a route and a Substrate is the ground, and neither is a component anyone imports.

Cost, stated plainly. Thirty-eight components × the battery. This is the largest single commitment in the project, and it is made against a mechanism that is already green rather than against a hope that one can be built.

#Build sequence

Ordered per §14 Phase 4 — attention-carrying first, then form and navigation — with surfaces last because a Scope's contract is exercised by the components it hosts. Layer is this system's answer to §3's authority question; the Carbon slug is provenance only. A Scope and a View allocate rather than hold, so neither declares a level.

#Not carried, with the reason

The first row is an exclusion rather than a drop: it was never a component, so it is not part of the 43.

Carbon slugReason
overviewNot a component. Carbon's own index page for the section, present in the sitemap because it is a page
ai-labelEncodes provenance, not intensity. §2 closes the channel list at three — light, language, motion — and nothing in the ladder answers what level "this was generated" holds. Carrying it would mean opening a fourth channel to hold one component
menu-buttonsA documentation grouping rather than a part: Carbon's page covers a button that opens a menu and a split variant of it. Both halves are on the roster in their own right, as button and menu, and this system builds them separately
listADR-0057. Not an Arbiter and not a component. §3 gives the Arbiter one power — resolving competing requests among its children — and Carbon defines the unordered list as items *"of equal importance without a specific order"*, a set with the ranking declared absent. The ordered list's marker is an ordinal, and the ordinal that ranks belongs to queue-item. What remains is a marker, an indent and prose: a rule, a divider and content, which §3 files under Substrate — the layer this record's own Consequences say acquires nothing
contained-listADR-0057. data-table with one column. The list title is a caption, the rows are rows, an interactive element in a row is an Emitter in a cell, and the on-page/disclosed variant axis is a stacking context — which ADR-0013 makes a property a Scope declares and never a per-component effect. What separates it from a data table in Carbon's own words is the number of header columns and the size of the space
structured-listADR-0057. data-table and table-row, identical in layer, levels, interactivity and governed copy. Column headers are the table's columns; cells, alignment, gridlines and the dividing rule are TABLE_ROW_CHROME; read-only against selectable is resting against selected; condensed height is density, which the Scope declares and the row inherits. What separates it from a data table in Carbon's own words is the amount of content and the depth of the nesting
content-switcherADR-0060. tabs at a lower rung. Carbon's own page separates the two on *"a lower hierarchy"*, and ADR-0027 settled what hierarchy is here — emphasis is the level, which the ladder already carries. The rest of the separation is what the panels are *about*, which no check in this system can read. And its documented pairing — a switcher inside a tab panel — is an Arbiter inside an Arbiter, which §5 forbids and TABS_ACCEPTS refuses at the call site
breadcrumbADR-0061. The pattern navigation-item was built for. That contract already says the containing nav is *"plain markup a composer supplies"*, and section D carries the decision as an absence — there is no navigation row. A trail is navigation entries with the last one variant="current", at the quieter rung Carbon's own *"always treated as secondary"* asks for (ADR-0027: emphasis is the level). What remains is a separator character, which shell-header and page-header both refused in favour of a drawn rule rather than spend the shipped font subset on a rule's job (ADR-0035)
file-uploaderADR-0067. Every part of it is built. The heading and description are a Region's name and count; the button or drop zone is a Button (ADR-0050's split); an uploaded file is InlineLoading, whose variants are pending, complete and failed and whose one governed part is *"which operation this reports"*; the remove control is a Button. And the layer question has no answer: three files uploading and one fails, and nothing resolves anything — the failed one reports its own failure and several may fail at once. Carbon's own placement guidance, *"use a tertiary button ... so it does not conflict with the primary action"*, is the problem button-group was built to solve, stated in prose
toggletipADR-0076. A popover and a Button. ADR-0026 left these rows an instruction — *"modal, popover and toggletip are Scopes because they host, not because they occlude ... each answers the hosting question"* — and the two answer it with the same word: both host arbitrary content anchored to something else, accepts unnarrowed for both, agreeing on all eight dimensions. What Carbon separates them on is the trigger, and this system has put the control outside the component four times (ADR-0050, ADR-0062, ADR-0066); toggletip names that trigger while popover names the place, and §3 names Scopes for places. Section E gave the two rows one sentence between them, shared with modal — the shape ADR-0057 removed three rows for
tree-viewADR-0068. A component whose normal state is illegal. A tree exists to keep most of itself closed, and ADR-0040 refuses a demand inside a panel removed from the frame — so the only legal place for a demand on a screen with a tree is outside the tree, always. The three remedies all fail on records already made: never collapsing defeats the component, lifting to every ancestor draws one alarm once per level (ADR-0055), and lifting to the root alone leaves the hidden node still declaring level 4, which ADR-0040's own remedy refuses to let anyone re-declare lower. Not §5's nesting rule: the engine names no Arbiter and emission rolls up to the nearest Scope regardless of depth
toggleADR-0081. checkbox. Identical on all eight, D4 included — a toggle's label is *"the proposition being agreed to or declined"* exactly. What Carbon separates them on is the drawing, a track and a knob against a box and a tick, which is mark and geometry and is excluded by name; and *immediacy*, that the state applies without a submit, which is a rule about when a composition commits rather than an authority over attention. Extract it and a checkbox remains, already carrying the set rule this row would need — *"several of the set may be picked"*
dropdownADR-0081. select — now input-field's choice control (ADR-0091). Identical on all eight. Carbon ships both because one is the native control and one is a custom listbox, which is an implementation and not a claim; select already carries *"exactly one of the set may be chosen"* and the chevron that says a set opens beneath. Multi-select is not the exception it looks like — its rule is checkbox's, so it is a set of checkboxes in a surface, and the surface is popover
searchADR-0081. An input-field whose value filters something, and the filtering is the set's business. Identical on all eight. What it appears to add is the claim that the set on screen is the filtered one, and ADR-0055 already put that claim in empty-state, whose filtered variant carries *"what is not here"* and *"why it is not"*. The magnifier is a mark; the clear control is a Button beside it, on ADR-0050's split
selectADR-0091. input-field with control="choice". Built as a component of its own and then found alike with input-field on all eight dimensions; the one thing it carried that input-field did not — ADR-0028's set rule and the chevron that carries it — is a declaration about how a choice is drawn, and it moved into input-field's contract under the control. The first built component to leave the set
sliderADR-0081. A Meter and a NumberInput — ADR-0076's shape arriving at a control. Identical to number-input on all eight; what separates them is the gesture, drag against type, which is not one of the eight and is not a claim about attention. What it appears to add is showing the value against its range, which is meter's whole subject, one bucket away and separated by the dimension that matters: meter reports and does not accept input. Reporting and acting have been put on opposite sides of a component boundary four times
date-pickerADR-0081. An InputField, a Button and a Popover — or, read the other way, a select whose options are computed. Identical to input-field on all eight. Its calendar is a set in which exactly one may be chosen, which is radio-button's set rule, laid out as a grid; layout lives in scene stylesheets (ADR-0073), so the grid is a stylesheet. Its surface is where the difference was supposed to live, and ADR-0077 put that surface in popover
formADR-0081. A Region holding controls with a Button beside it. Extract its rules and all four are already placed: shared density is §5's density coherence, every Scope's; the submit is a Button on ADR-0050's split; an invalid field's correction is input-field's own hint role; and *a validation pass must not produce one demand per field* is section C's own ceiling rule, enforced on every control by the ladder stopping at 3. What remains is a bounded place holding things and holding no allocation, which is region. Its one candidate D4, *how many are still required*, is region's count over the same set — and pagination was kept on the opposite property, that its subject is a set the reader cannot see
menuADR-0082. A Popover holding a ButtonGroup. It is a Scope that hosts arbitrary content anchored to a control, which is ADR-0026's hosting question, and ADR-0080 built the component that answers it — identical to popover on all eight: scope, [1], non-interactive because its items are the things a reader acts on and it is not one of them, no vouching, no acknowledgement, no persistence, *what this is about* for governed copy, and disclosure, because a closed menu is absent from the frame exactly as a closed popover is. ADR-0076's argument arriving a second time, and that record's sentence fits unaltered: both host content anchored to something else, and what a system separates them on is the trigger, which this one puts in a Button beside the component. What is left over is the set rule, and ADR-0054 built the Arbiter for it in a sentence written about alarms — *"an alarm's controls arrive as a set, of which exactly one may be the local focus"*
overflow-menuADR-0082. A Button and a Popover, and section D's own prose had already said the first half — *"the trigger and is an Emitter; the surface it opens is a menu"* — so refusing menu refused the rest. As a trigger it is identical to button on all eight, governed copy included: *the action itself, named as an imperative* carries "Show three more actions" without strain. The fifth time this system has put the control outside the thing it controls (ADR-0050, ADR-0062, ADR-0066, ADR-0076). Its one apparent remainder — that there are more actions than fit — is a count of things not on screen, which is pagination's subject, and a count spoken by a control is that control's label

43 published components, 19 dropped, 24 carried, filed as 25 rows. ADR-0057 split this sentence from the dated account that used to be welded to it, and splitting it exposed the reason two of this record's figures had never agreed. One Carbon page is deliberately carried as two rows, with its own record: notification is alert and toast (ADR-0042, a condition against an event). text-input was carried as input-field and text-area (ADR-0052, which found the slug rather than the split) until ADR-0091 folded the second row back into the first. So *24 components carried* and *25 rows derived from Carbon* are both true and neither is the other, which is why the original sentence could say 41 while the summing sentence said 43 and nothing in the repository could see the gap.

The identity is now derived on every run and it is the load-bearing half: 18 dropped + 25 distinct slugs carried = 43, Carbon's published count. A row leaving the table without a reason entering the one above breaks it.

*As of 2026-09-01, when this record was written:* 41 carried, plus 4 this system ships that Carbon does not publish — 45 on the roster, 7 built, 38 to build. Those four figures are history and are read by nothing.

#A: attention-carrying Emitters

ComponentCarbon slugLayerLegal levelsState
status-indicator—Emitter1 to 4built
alertnotificationEmitter2 to 4built
toastnotificationEmitter2 to 3built
meterprogress-barEmitter1 to 3built
tagtagEmitter1 to 3built
inline-loadinginline-loadingEmitter1 to 3built
loadingloadingEmitter1 to 3built
tooltiptooltipEmitter1 to 2built
paginationpaginationEmitter1 to 2built

toast shares notification's slug with alert, and the split is ADR-0042's. Carbon documents the inline and the toast form on one page; this system files them as two components because they answer §2 differently, which is the same reason menu-buttons was refused as a row and its two halves entered separately. An alert *is* a condition and may reach Demanded; a toast *reports* an event, and §2 rations level 4 on a demand being live — liveness belongs to a condition, so the ceiling is Directed. Two components with different ceilings do not become one row because one vendor's documentation groups them.

tooltip stops at 2: a label attached to a control describes it and does not direct anyone to it. inline-loading and loading stop at 3 for the meter's reason — a pending state reports and does not demand.

#B: attention-carrying Arbiters

An Arbiter's ceiling is level 3 throughout. A container that could reach the region maximum would compete with the things it exists to rank, which is the rule the queue item established and every Arbiter since has inherited.

ComponentCarbon slugLayerLegal levelsState
queue-item—Arbiter1 to 3built
table-row—Arbiter1 to 3built
accordionaccordionArbiter1 to 3built
tabstabsArbiter1 to 3built
progress-indicatorprogress-indicatorArbiter1 to 3built

Each ranks one member of a set above its siblings — a selected tab, an expanded panel, a current page, a current step, a failed upload — which is §3's Arbiter answer and not an inference from Carbon's grouping.

A second row has left this section since, and for the same kind of reason (ADR-0066). pagination was filed here as an Arbiter and is an Emitter: §3's Arbiter resolves competing requests among its children, and a pagination bar has none — its controls are Buttons beside it, which core's nesting table makes structural rather than stylistic, since emitter: never means an Emitter accepts nothing. It is in section A, at a ceiling of Marked argued in its own record. Two of this section's layer assignments have now been wrong, which is what section B's justifying sentence not stretching was a symptom of.

This sentence used to end with a second one about tile, and that row has left the section (ADR-0058). The extra sentence was the tell: the shared argument did not stretch to it, so a reason was written for that row alone — *"tile is an Arbiter for the same reason §3's own example list names a card"* — and Carbon's tile page says on the same screen that Carbon does not have a card pattern and that tiles *"have no pre-set styles and are purposely flexible."* Carbon's tile is four functions on one page and three of them are components this system already ships. The fourth is a bounded area on a route that owns a budget, which is a Scope, and it is in section E as region. ADR-0021's own Rejected options named this row while refusing to inherit Carbon's grouping; section B then inherited it in one sentence.

#C: form

ComponentCarbon slugLayerLegal levelsState
input-fieldtext-inputEmitter1 to 3built
buttonbuttonEmitter1 to 3built
checkboxcheckboxEmitter1 to 3built
radioradio-buttonEmitter1 to 3built
number-inputnumber-inputEmitter1 to 3built

ADR-0091 removed two built rows from this table, text-area and select, and they are the first built components to leave the set. Both were alike with input-field on all eight of §12's dimensions, read out of the tier and the contracts; what separated them was the native element each rendered, which is how a field is drawn. They are now input-field's multiline and choice controls, and select's set rule moved into that contract with its chevron. select is in the exclusion table under its Carbon slug; text-area was never a Carbon slug of its own, so it leaves with no row to file. The paragraph below is the history of text-area's arrival, kept as written.

text-area was added to this table after the fact, and the gap is worth naming rather than quietly filling. This roster was taken from Carbon's published component list, and Carbon ships text-area as a component distinct from text-input. It was missed on the first pass — the only slug in section C that was. It is entered here at the same layer and the same ceiling as input-field for the identical reason, so nothing about the section's argument moves; what moves is that the table now covers the roster it claims to cover. A roster that silently omits a member is worse than one that argues for excluding it, because the omission reads as a decision nobody made.

Two counts in this record are snapshots and one is live, and the difference matters when they disagree. The Decision above says "the roster is 45 components … of which 7 are built", and both halves were true the day it was written. Neither is maintained: the roster is 47 rows with text-area entered and toast split out of notification by ADR-0042, and the State columns — which *are* maintained, one edit per component as it lands — read 21 built on disk today. The Decision's numbers are left as written rather than corrected in place, because a decision records what was decided and rewriting its arithmetic to match a later tree would erase the fact that the roster grew. The State columns are the register; the Decision is the record.

Every control stops at 3, on the input field's precedent and for its reason: an ordinary interaction routinely produces several at once — a validation pass invalidating four fields, a toolbar holding six buttons — and a component whose normal state could reach the region maximum would make the one-demand rule fail on the most ordinary thing a form does. The demand belongs to the message about the failure, not to the control that failed. ADR-0081 audited this section as a group and refused every row that was not built. Six of the thirteen went to the exclusion table, and what the audit found first was about the section rather than about any row in it: run the six tier axes over the built set and twelve of these thirteen rows fall into one bucket — interactive Emitters stopping at Directed — so the machine-checkable half of the identity test is constant across this whole section and every separation in it is D4 or D5. That is the opposite of every audit before it, each of which turned on a layer or a ladder. The sentence that used to end this paragraph said date-picker and dropdown *"each open a surface; that surface is an overlay Scope"*, and both halves are gone: ADR-0077 refused overlay for a popover from the measurement, and both rows are refused here.

#D: navigation and shell

ComponentCarbon slugLayerLegal levelsState
navigation-item—Arbiter1 to 3built
linklinkEmitter2 only — ADR-0085built
shell-headerUI-shell-headerScope1 only — ADR-0046built
shell-left-panelUI-shell-left-panelScope1 only — ADR-0046built
shell-right-panelUI-shell-right-panelScope1 only — ADR-0046built

The none — allocates column has now been contradicted by every Scope built, and ADR-0046 names why rather than leaving a fourth reader to rediscover it. modal declares levels 3 and 4, data-table declares 1, and shell-header declares 1 and nothing else. A Scope allocates a budget *and* holds chrome of its own — a ground, a perimeter, a title — and that chrome sits somewhere on the ladder. The column describes what a Scope distributes, which is nothing, not what it is. shell-header's row is corrected in place to say what it declares, because a roster whose level column disagrees with every row it describes is worse than one that admits the column meant something narrower.

ADR-0082 audited this section and section G together, refused four of their five unbuilt rows and kept one. The sentence that stood here read *"overflow-menu is the trigger and is an Emitter; the surface it opens is a menu, and the split is the layer model doing its job on a component Carbon documents as one thing"* — and it was already half a refusal. The surface is a popover (ADR-0077, built by ADR-0080), so menu is a Popover holding a ButtonGroup and identical to popover on all eight; the trigger is a Button, which is the fifth time this system has put the control outside the thing it controls. link is the row that stood, and it stood on two separations rather than one: from button on D4, because a part obliged to name a destination is not a part obliged to name an action, and from navigation-item on D1, because §3's question gives two answers — a navigation entry ranks one of several siblings as current and accepts an Emitter, and a link cannot be current. Built (ADR-0085), and both of the questions this paragraph left open are answered. The perimeter was ADR-0084's: it is the first interactive component in the system that draws no ground, so ADR-0045's turned corner had nothing to turn, and that rule generalised from a corner to the perimeter with a third carrier — the rule under a component's own text. The ladder was the scene's: the row read 1 to 3, the ceiling argued down to Marked from §2's *language* column, and fixture 66 measured the two remaining rungs 1.5% apart and refused to move when the rule was thickened. Its pixels are glyphs plus a hairline and the tier's ladder lives in mark and geometry, so there was never a second rung to draw. It declares one rung, Marked — bounded above by the language column and below by its own affordance, since a link at minimal deviation is an actable thing the reader cannot find — and it is the first single-rung Emitter in the system.

#F: the r136-native set (ADR-0048)

5 components with no Carbon equivalent, and the reason there is none is that Carbon is built for applications rather than for supervision. An application's screen is true when it renders; a supervision screen is true only while something keeps telling it so. These five are what that difference costs.

**This sentence used to say "six" and used to say "no Carbon *or Lightning* equivalent", and both halves were wrong. Six became five when ADR-0050 removed acknowledge, and the number was not moved with it. The Lightning half was never checked at all until ADR-0052 read Salesforce's own component directory: activity-timeline and feeds are timeline and live-feed, so two of what were then five had a Lightning equivalent and always did. One of the two did not survive being asked why (ADR-0073):** live-feed stays, because Lightning's feed is a record of what happened in an application and this system's is a Scope whose own claim is that it is still being told things; timeline was removed, because *a record of what happened* is what this system's was too, and a record of what happened inside a bounded named set is region.

ComponentCarbon slugLayerLegal levelsState
staleness— noneEmitter2 to 4 — no Ambient formbuilt
live-feed— noneScope1 only — ADR-0046, ADR-0075built
sla-countdown— noneEmitter1 to 3 — ADR-0069built
trend— noneEmitter1 to 3 — ADR-0104built
bezel— noneScope1 only — ADR-0046, ADR-0135built

staleness is the one ADR-0048 is written for and the one the other five depend on. Built, and building it moved one figure in this row: its legal levels are 2 to 4, not 1 to 4. A staleness report with nothing to report does not exist — a source answering normally is reported by its readings, which is what readings are for — so it has no Ambient form, which is alert's rule reached from the opposite direction. It reports a *source* rather than a reading — "no contact with the seal press for 4m" — which is why it may reach Demanded while every reading it invalidates withdraws to Ambient. One true demand replaces twelve false green marks.

live-feed is a Scope and persistent, so ADR-0046 governs it by citation exactly as it governs the shell: it remains rendered across a change of route, so it declares level 1 and may not demand. What signals is what it holds.

timeline was removed from this section by ADR-0073, and the paragraph that stood here is why. It said the two *"differ from each other in direction and not in authority — a feed is open at the recent end and a timeline is closed at both — which is the same shape of difference shell-right-panel had from shell-left-panel."* Direction is subject matter, which is the axis ADR-0060 rejected, and the precedent is about places: a left edge and a right edge are two locations an operator learns, while open-at-one-end and closed-at-both is one location with two contents. On the seven dimensions a timeline is region — a name, a count, one rung, no vouching — its order is markup in the manner ADR-0061 gave breadcrumb, and it does not outlive its route, which is the half of ADR-0052's defence that was false.

What keeps live-feed is not the place, since a place alone is what shell-right-panel already is. It is that its own claim is that it is live: if the source stops, a quiet period and a dead connection render identically inside it, which is ADR-0048's thesis said about a container. It would be the first Scope in the system to declare vouches.

Built (ADR-0075), and the build answered both questions ADR-0073 left for it and found a third. A Scope's retraction has one half rather than two — the descent is a no-op because a Scope holds no ration and its floor is where it already stands — and the withdrawal does not reach the subtree, because each arrival was true when it arrived and stays true; a container that retracted them would withdraw facts nothing has put in doubt. The third is ADR-0053's table gaining a row: a feed persists, so its subtree may not hold the View's demand, and it is the first component that is not a shell to inherit that. It also costs nothing to withdraw — ADR-0013 already requires a raised context to draw a perimeter, so the largest surface in the system that can retract does it with a change of border-style.

acknowledge was removed from this section by ADR-0050, and the removal is the finding. Everything this row used to say was a *rule* — the ceiling, the descent, the refusal to let acknowledgement clear a condition. Extract the rule into a record and what is left is a control with a label, identical to button in layer, levels, interactivity and governed copy. Building it would have added a component differing from the twelfth in its name, which is the scenery §11 warns against, and would have put a rule about a state transition inside a widget where no check could reach it. The control that performs an acknowledgement is a Button; what was missing was never the button.

sla-countdown is the only component in the system whose level rises with no input changing. Everything else declares a level about a state; a countdown declares one about elapsed time, and it escalates on its own. That makes it the first component that can breach the View's demand cap *without anyone rendering anything* — two countdowns approaching breach both want Demanded — so it needs an arbitration rule of its own and cannot simply be built from the indicator's shape.

Built, and the arbitration rule it asked for turned out not to be needed (ADR-0069). The row said 1 to 4 and the ceiling is 3. A countdown reports time *remaining*, which is a prediction, and §2's Demanded rung is the View's ration for what is happening; a breach that has occurred is a condition, and conditions are alert's. Two countdowns cannot breach a cap neither of them can reach. What the paragraph above got right is that it cannot be built from the indicator's shape — its level is computed from the fraction of budget spent rather than passed, which no other component in the set does, and it takes that fraction as data rather than reading a clock because REPRODUCIBILITY_TOLERANCE is 0 and the engine renders every scene twice demanding exact equality.

trend was added by ADR-0104: a meter over time. Carbon keeps charts in a separate library and publishes no sparkline among its components, so the row has no Carbon slug. It is the meter on every dimension the tier reads except the one it adds, a series, and a supervision screen needs that dimension: a reading that has just crossed its limit and one that has been climbing toward it for twenty minutes are different situations, and one number cannot tell them apart.

bezel was added by ADR-0135: the strip beside an instrument's physical keys. Carbon has no instrument bezel, so the row has no Carbon slug. On every axis the tier reads it is the shell panels, a persistent Scope at one rung, and ADR-0073 is what keeps it: a Scope is a place, and this is the first place in the set that neither the component nor the composer defines. The hardware does. Its one rule is that the keys are a list in hardware order and an idle key is an empty slot, because a missing one would move every label after it onto the wrong key.

presence reports which other operators hold this view. Ceiling 2: another human looking at the same alarm is worth marking and is never itself the emergency. It is the one component here that is about the humans rather than the machines, and it is what makes "human-in-the-loop" a property of the system rather than a phrase in its description.

Audited before building, and the audit found the paragraph above was defending the row on the wrong ground (ADR-0071). "About the humans rather than the machines" is a claim about subject matter, and the tier reads no subject matter — it is the axis ADR-0060 rejected when it collapsed content-switcher. Put against pagination rather than against tag, this row is identical on all five dimensions the test then had: Emitter, [1, 2], non-interactive, one governed part whose role is *what is being counted*, no disclosure. What keeps it is vouches, an axis the test never named and the tier has read since ADR-0048: a total is a result the product computed, and who is holding a view is only ever a condition a source keeps confirming. The row stands, it declares vouches: true, and it is the first component here kept by an axis the test did not contain.

Built (ADR-0072), and the build moved nothing the audit decided and one thing it did not. Its three states are three, not two: alone and accompanied are the variants, and the third is vouched: false, which is not a variant and is the axis the row was kept on. The scene found the defect — a withdrawn report first rendered its last known count with the retraction carried by the perimeter alone, which is the component contradicting itself in one element, since the unvouched mark is a single token precisely so a withdrawn claim cannot encode what it would have said. The quantity now withdraws with the mark. And the engine found the second: the first wording of that retraction cost twenty characters and made the withdrawn report out-emit the same component's Marked rung, which is §2's ladder inverted by wordiness.

The roster is 37 components: 25 rows derived from Carbon's published set, 4 this system shipped before it reopened, 5 r136-native and 3 carried from Lightning, which is 37.

presence was the fifth r136-native row and is gone from the table under ADR-0121. It is not a component any more: the capability ships as Avatar's presence prop, and the package exports the name as a type rather than as something that renders. The paragraph below it stands as the reasoning that put it here, which is still what happened.

That sentence used to say "47 from Carbon's published set", and it was wrong in the way a total is wrong when it absorbs a term. Four of those 47 — status-indicator, queue-item, table-row and navigation-item — are components this system shipped before the roster reopened, and this record's own Decision section names them as such in the same paragraph that states the total. tools/check-roster.js derives all five figures from the table below on every run, so the sentence can no longer drift from the rows it counts (ADR-0052).

#G: carried from Lightning (ADR-0052)

Three components Salesforce's Lightning Design System publishes and Carbon does not, carried after a row-by-row reconciliation of all 91 of its component directories. The other 86 are covered by rows above or dropped by name with a reason; ADR-0052 holds the full table. This section said five until ADR-0082 audited it, and the two it removed are recorded below rather than in the exclusion table above, which is Carbon's drop list — a Lightning row entering it would break the identity that joins it to Carbon's published count. That is where ADR-0050 recorded acknowledge and ADR-0073 recorded timeline, for the same reason.

ComponentLightning slugLayerLegal levelsState
button-groupbutton-groupsArbiter1 to 3built
empty-stateillustrationEmitter1 to 2built
page-headerpage-headersScopenone — allocatesbuilt

avatar was removed by ADR-0082, and the removal is the second time a row here was defended on a dimension the tier excludes. The paragraph that stood said this system *"calls itself human-in-the-loop and has nothing that draws a human"* and that presence *"has no mark to draw them with"*. Both sentences ask for a shape, and mark is excluded from the identity test by name — *how the component is drawn, downstream of a level and a variant*. It is the same shape ADR-0071 caught for presence itself, where *about the humans rather than the machines* turned out to be subject matter the tier does not read. A human figure is also refused a place in ADR-0028's shared vocabulary on that record's own test: a shared entry is a statement about attention, and *this is a person* is not one. So it is a private shape belonging to whichever component draws it, which is presence — exactly as the chevron belongs to accordion, select, data-table and number-input. presence draws no polygon today and may acquire one as its own.

button-group is built (ADR-0054), and it is the first component whose whole job is ranking a set of *controls*, and that is why it is not scenery. Building it found the sharper reason: four Arbiters existed and not one of them assigned a level to anything — they resolve by position, which is a real resolution and not a grant — so the layer's defining capability had no user until this one. Four Arbiters are built and every one of them ranks rows of data. ADR-0050 supplies the case: the control that performs an acknowledgement is a Button, and an alarm's controls arrive as a set — acknowledge, escalate, silence — of which exactly one may be the local focus. That is an allocation, and a Button cannot make it, because §3 says an Emitter holds an allocation and cannot grant one.

combobox was removed by ADR-0082: it is a select whose option set is computed from what has been typed. The paragraph that stood argued it was *"the case select and search leave between them"*, and ADR-0081 refused search, so half the argument went with it. The other half was *"the set is too large to enumerate and too structured to free-text"* — and too large is a quantity, which is what ADR-0057 removed three roster rows to keep out of the tier. On the eight dimensions it is select: Emitter, [1, 2, 3], interactive, no vouching, no acknowledgement, no persistence, the field pair for governed copy, and disclosure — which select has in fact and under-declares, per ADR-0081's finding. Carbon does not publish it, which was checked rather than assumed (ADR-0052) and is why the row arrived here rather than in section C; provenance is not a separation.

empty-state is built (ADR-0055), and it is ADR-0048's thesis standing in a different place. That record refused a screen that replaces a lie with a blank; a region with nothing in it and no component to say so *is* that blank, and "there is nothing here" and "nothing has arrived" render identically as empty space. Ceiling 2, because an empty region is worth marking and is never itself the alarm — the alarm about an empty region is staleness, which is what the pair is for.

page-header is built, and it is the half of ADR-0046 that was never built. That record split chrome that outlives a route from chrome that belongs to one, and the persistent half now has three Scopes; the route half has none. ADR-0040's own remedy names the gap in passing — *"Lift the demand to something on the screen — a disclosure header carries a summary for exactly this"* — and there is no such header on the roster. Building it corrected the sentence that stood here: it is *not* the first Scope whose ceiling is not 1, because a Scope has no ceiling of its own at all — §3 leaves it no allocation to raise, so it declares Ambient exactly as the shell Scopes do. The difference is in what its subtree may hold, and ADR-0053 is where that distinction lives.

#E: surfaces

ComponentCarbon slugLayerLegal levelsState
data-tabledata-tableScopenone — allocatesbuilt
modalmodalScopenone — allocatesbuilt
popoverpopoverScopenone — allocatesbuilt
regiontileScopenone — allocatesbuilt
codecode-snippetEmitter1 to 2built

region is the general one and every other Scope in the set is a *particular* place — the shell surfaces are at the edges, the page header is at the top, the modal occludes, the data table is a grid. It is §3's own third example, *page region*, and it was the only one of that list's five with no component: 123 of the 144 Scope declarations in the fixture set had none behind them (ADR-0058). data-table is a Scope and table-row is the Arbiter inside it, which is why the row was buildable before the table: the row's contract never depended on the region's. modal is the only Scope that grounds on the scrim composite (ADR-0077). This sentence named popover too, and measure.js refuses that: an overlay predicts a ground of substrate composited with the scrim, a popover draws no scrim, and the check compares the prediction against the pixels. The escape is worse than the refusal — a popover that drew a scrim would dim the screen, which ADR-0014 makes a statement about interactivity, and the only thing then separating it from modal is how much of the view the sheet covers, which is the quantity ADR-0057 removed three rows for. popover is a raised Scope at §5's second depth, rendered inside its anchor's Scope and never portalled (ADR-0026's rule for the tooltip, arriving at a component that hosts). It is the row §5's unoccupied second Scope depth was left open for, and it is built (ADR-0080) — the first component in the system at that depth, after two records removed what stood in the way: ADR-0078 gave the engine containment, so a nested Scope and its parent are no longer both charged for the same pixels, and ADR-0079 re-based the ground prediction to the containing Scope, so it may be anchored where controls actually live. What makes it a component rather than a fourth name for region is D5: on the six tier axes it is region, page-header and data-table exactly, and what none of those does is take itself off the screen. It is the only Scope in the set that discloses. Two things the build found and the record did not predict: a Scope at depth 2 accepts two layers where every Scope before it accepts three — core's Accepts table is keyed on layer and cannot answer a question about depth, so this contract reads ScopeChildren instead — and its subtree's demand rule needs no attribute, because a closed popover is present in the frame and not rendered, which is the node ADR-0040's check has collected since long before this row. That sentence used to name three rows and was the only argument any of them had — which is the shape ADR-0057 removed three list rows for, and ADR-0076 removed toggletip for: put to ADR-0026's own hosting question, a popover and a toggletip answer with the same word, and what Carbon separates them on is the trigger, which this system puts in a Button beside the component. code-snippet stops at 2 and declares its body a content slot: the body is payload the budget does not govern, and the frame and its copy control are chrome that it does. Built (ADR-0070), and it is the first component in the system to declare an exempt content slot — ADR-0009 is the oldest decision here and thirty-three components had never used it. One half of that sentence needed correcting on the way: the copy control is not chrome this component draws, because emitter: never means an Emitter accepts nothing, so the control is a Button beside it exactly as pagination's is.