Stella Ops Console UI

The operator console for the Stella Ops release control plane: dashboards and workflows for scans, policies, VEX evidence, runtime posture, and administration.

Status: Implemented Source: src/Web/StellaOps.Web/ Owner: UI Guild

The Console is the Angular front end that presents real-time status and operator workflows across the platform. It integrates with Authority for scope-enforced, DPoP-protected calls and ships with deterministic, offline-capable builds.

Related: see ../web/for triage-specific UX documentation (Smart-Diff, Triage Canvas, Risk Dashboard).

Recent milestones

Recent UI delivery has focused on consolidating canonical navigation shells and retiring inline component mocks in favour of live backend bindings. Highlights:

Per-feature verification dossiers live under ../../features/checked/web/; UI design proposals and restoration notes live in the subdirectories listed under Related resources. Detailed sprint history is tracked in docs/implplan/SPRINT_*.md.

Responsibilities

Key components

Integrations & dependencies

Operational notes

Reference & operations

UX dossiers & shell proposals

Backlog references

Roadmap by epic

EpicUI workstreamStatus
Epic 2 – Policy Engine & EditorDeterministic policy authoring, simulation, and explain UXIn progress
Epic 4 – Policy StudioRegistry workspace, approvals, and promotion workflowsPlanned
Epic 5 – SBOM Graph ExplorerGraph navigation, overlays, and diff viewsPlanned
Epic 6 – Vulnerability ExplorerTriage dashboards, findings ledger, audit exportsIn progress
Epic 8 – Advisory AIAdvisory summaries and remediation hints with strict provenance/citationsPlanned
Epic 9 – Orchestrator DashboardSource/job monitoring with throttling and replay controlsPlanned
Epic 11 – Notifications StudioNotifications workspace with rule/channel previews and audit trailsPlanned

Standing objectives across all epics: maintain deterministic behaviour and offline parity across releases; keep documentation, telemetry, and runbooks aligned with the latest sprint outcomes; and verify Authority scopes before enabling uploads (see the access-control guidance carried in the Vulnerability Explorer sprint history).