Organism, and it contains another
Frame
The record that leaves the building. 5 instances across 5 screens: a client summary, an exported log entry, something that will be read by somebody who was not in the room and does not have the console.
It is marked as a record on all four sides, and the marking is a frame rather than a banner for one measured reason: a banner scrolls away, and somebody arriving by permalink and reading the middle must still know what they are reading. The top edge of that marking is rail, which is sticky; the bottom is rail foot, which is not; the two vertical sides are this component and nothing else.
--width-frame had no consumer in the register. The token was in tokens.css from step 3 and the component that reads it was one of the thirteen the step 2 census missed, because that census counted controls and a frame has none. docs/inventory.md section 13.
2px, and it is the fourth line width with no token. The focus ring, the alert toast, the current navigation item and this. Whether that is a fourth line token or four component decisions is the open row on the geometry page, and step 9 answers it with the count in front of it.
Anatomy
A scaled scene, not a diagram. A frame is a boundary, and a block drawing of a boundary is the boundary. At 1440 the frame below is at its real --width-frame of 820px with the real 2px on all four sides; below 852 it takes the width it is given, which is also what it does in the product. The box it stands in scrolls at 440px so the sticky marking can be produced rather than asserted: scroll it and the top edge stays.
dark, shipped
AS IT STOOD 2026-08-22T04:14:05ZA record of what was known then. This is not the live case.Open the log
C-4417 · Larkfield LogisticsDecided 2026-08-22T04:41:12Z
What was decided, and by whom
Escalated, not ruled. Handed to S. Varga, SOC lead, by R. Idrissi. Clerk’s verdict, real, contain identity, stands unruled.
The evidence as it stood, 9 signals
identityA refresh token was presented from ASN 41xxx, first time for this tenantEntra sign in
mailAn inbox rule was created 90 seconds later, forwarding to an external addressExchange audit
6 sources queried over 24h as it stood: Entra ID, Exchange audit, EDR, proxy, threat intel, tenant baseline.
820px at 1440, and the ground behind it is the stand’s, not the product’s
light, the pair
AS IT STOOD 2026-08-22T04:14:05ZA record of what was known then. This is not the live case.Open the log
C-4417 · Larkfield LogisticsDecided 2026-08-22T04:41:12Z
What was decided, and by whom
Escalated, not ruled. Handed to S. Varga, SOC lead, by R. Idrissi. Clerk’s verdict, real, contain identity, stands unruled.
The evidence as it stood, 9 signals
identityA refresh token was presented from ASN 41xxx, first time for this tenantEntra sign in
mailAn inbox rule was created 90 seconds later, forwarding to an external addressExchange audit
6 sources queried over 24h as it stood: Entra ID, Exchange audit, EDR, proxy, threat intel, tenant baseline.
820px at 1440, and the ground behind it is the stand’s, not the product’s
.framethe whole record. width:min(--width-frame,100%), centred by margin:--space-5 auto, on --bg-page so the record keeps the reading ground even when the surface behind it does not
- the border2px solid
--line-record, and it is the only four sided marking in the product. --line-record is the 3:1 line role, which is what makes the boundary itself perceivable rather than decorative
railthe top edge, sticky at top:0. Inverted, uppercase mono, and it carries the way out
rail-footthe bottom edge, static and quiet. Zero zones, which is why it is a component of its own rather than a variant of the rail
- between thema doc or a block. The frame does not care which, and it sets no padding of its own: the thing inside owns its margins
Variants
There are none. Two of the three axes below are prohibitions with reasons rather than gaps waiting to be filled.
| Axis | Value | Uses | The rule |
| marking | no values | – | Prohibited, and it is the decision the component exists to carry. A record is marked on four sides or it is not marked. A single strip at the top is a banner, and a banner scrolls away |
| width | no values | – | One measure, --width-frame at 820px, on all five. A record that is wider at one width and narrower at another is a different artefact each time it is opened |
| content | no values | – | A doc or a block between the rails. That is a count of what is inside rather than a form of this, which is the same reason Z45 has no variants either |
When to use it
Around anything that will be read outside the console: an entry as it stood, a client summary, an export. If the reader has the console in front of them and can see the top bar, they already know where they are, and the frame is spent.
Where she meets it. Not often, and mostly not her at all. This is the one component in the system whose primary reader is not the analyst: it is the auditor, the client, or the SOC lead reading a permalink months later from a mail. That is why the marking has to survive being scrolled into the middle of, and why the frame is what says this is a record rather than a sentence saying so.
Rule and anti-rule
Do
AS IT STOOD 2026-08-22T04:14:05Z
The record, on all four sides.
Marked top, bottom and both sides. Land in the middle of it by permalink and the two vertical edges are still on the screen.
Do not
This is a record as it stood. It is not the live case.
The record, announced once and then unmarked.
Never a banner instead. banner is the component for something said once to somebody who is already on the screen and will scroll past it. A record has to keep saying what it is, so the marking is the frame.
The two rails in the pair above are written as divs rather than the p the product uses. That is the stand’s own stylesheet reaching into a product component: .k-vs p is written for the caption under each example and it is one step more specific than .rail, so a rail rendered as a paragraph inside this block came back at 1.97 in dark and 2.85 in light. Found by checks/contrast.mjs, and the markup to copy is the block at the foot of this page.
States
It has none, and it is not interactive. The rails inside it carry what they have, and the way out is a link that belongs to the rail.
dark, shipped
AS IT STOOD 2026-08-22T04:14:05ZA record of what was known then.Open the log
Rest, and the only live state on this component is the way out in the rail above.
light, the pair
AS IT STOOD 2026-08-22T04:14:05ZA record of what was known then.Open the log
Rest, and the only live state on this component is the way out in the rail above.
Put the pointer and the keyboard on the way out in the rail: that is the whole of what moves inside a frame, in whichever theme you are reading.
What it reads, and where it stands
| Role | Surface | Where on the component | Dark | Light |
--line-record | line 3:1 | the border, 2px on all four sides | | |
--bg-page | fill | the ground inside the border, so the record keeps the reading ground | | |
--bg-invert | fill | the top edge, and it is rail’s rather than this component’s | | |
Copy this
<article class="frame">
<p class="rail">AS IT STOOD <b>2026-08-22T04:14:05Z</b>…</p>
<div class="doc">…</div>
<p class="rail-foot">Nothing below this line can be edited.</p>
</article>
Where it stands