Nexus UI review — 24 September 2026
This review covers all 35 page routes in nexus-ui/src/app: 33 operator
surfaces, sign-in, and the /trading redirect. It combines a source inventory
with local browser checks. Changes described as implemented refer to the local
workspace; this document does not assert that they have been deployed.
This audit and its screenshots precede the portfolio-only navigation refocus. See the portfolio console guide for the current page inventory and removed workflows.
Design direction
Nexus is an operator console. The interface should make the next action, the source of each number, and the difference between missing data and an empty result immediately understandable.
The shared design now uses a slate background, distinct raised surfaces, restrained violet accents, clearer muted text, larger page titles, consistent section borders, rounded cards, and more legible table headers. Dense data stays in horizontally scrollable tables. Page actions wrap on narrow screens. Light mode has white cards on a softly tinted canvas; reduced-motion preferences apply to animations and transitions.
The desktop sidebar stays within the viewport and scrolls independently. Page
search filters both section and page names. Trading goals and task goals have
distinct labels. Squads ceremony is discoverable, and the footer links to the
operator documentation. Mobile navigation, modals, and drawers use Radix Dialog
for focus containment, Escape handling, accessible titles, and scroll locking.
The shell has a skip-to-content link and active navigation has aria-current.
Shared form fields associate labels and hints with direct input, select, and
textarea controls.
Visual examples
These local screenshots use synthetic review fixtures, not production balances or activity.


Information integrity fixes
- Failed reads have a visible retry state across the main lists, settings, learning tables, oracle views, and trading catalogs. They no longer take the same branch as “no records”.
- The dashboard no longer shows a permanent “Live” badge or endless skeletons after an error. Its workspace cards link to approvals, treasury, cycle health, and agent management. Usage failures remain visible.
- Selected page headers show the source and last successful response receipt time. This is not the upstream observation time and is explicitly described as such in the timestamp tooltip.
- Missing execution status is “unknown”, not “dry-run”. The compact header retains execution status on narrow screens. The on-chain estimate requires all of its request sources to succeed and is labeled separately from consolidated treasury NAV.
- The hard-coded half-hour countdown was removed. Actual cadence belongs on Cycles, using persisted output and schedule data.
- Lending supply is shown as raw token base units. The old six-decimal conversion incorrectly labeled every asset's supply as dollar TVL. Human units and dollar valuation need explicit mint decimals and valuation prices.
- Telegram is labeled as a command reference, not a queried registration list. Static integration cards no longer imply a monitored connection status.
- Analysis copy no longer describes the decision officer as a daily job; Scope explains monitored markets without implying execution trades all of them.
Page-by-page coverage
All operator pages inherit the shell, page-header, theme, card, and applicable shared-table improvements. This table distinguishes additional changes from remaining review findings. Follow-ups are proposals, not implemented features.
| Route | Reviewed surface / implemented change | Remaining information or interaction gap |
|---|---|---|
/ | Fleet KPIs, request state, usage, workspace links | A combined incident inbox and time-window selection would make triage faster. |
/agents | Agent table, editor, search, retry, receipt time | Cross-links from an agent to recent runs and explicit ownership would improve diagnosis. |
/skills | Skill list/editor and proposed skills, retry, receipt time | A version comparison and list of consuming agents would make edits easier to assess. |
/memory | Scope/status filters, review actions, drawer, retry | Entry provenance, expiry, and memory-use evidence deserve a consistent summary. |
/boards | Project cards and editor, retry, receipt time | Surface sync health and last successful sync per project. |
/board | Board selection, creation, drag-and-drop, error state | Provide a keyboard alternative to dragging; distinguish filtered counts from project totals. |
/goals | Task dependency graph, clarification, retry; renamed Task goals | Highlight blocked dependency, owner, and age together; offer a text equivalent to the graph. |
/schedules | Schedules, worker/queue sections, retry, receipt time | Standardize timezone display and expose misfire policy and scheduler heartbeat. |
/runs | Episode history, traces and knowledge, retry, receipt time | Make loaded-list limits and links to related jobs consistent. |
/approvals | Pending queue, retry, named approve/reject controls, receipt time | Show the full action diff, resource target, expiry, and durable decision history. |
/hosts | Host topology/cards, retry, receipt time | Separate configured/enabled state from measured heartbeat and running version. |
/mobs | Mob/host list, independent failure states, receipt time | Running state is derived from host assignment; an actual heartbeat is still needed. |
/mobs/[id] | Roster, versions, loadouts and learning detail; retry states | Some secondary sections still need consistent source timestamps and partial-failure treatment. |
/registry | Artifact tabs, searchable lists, body readers, retry | Add explicit version comparison, promotion audit, and rollback eligibility. |
/jobs | History, status filter, execution detail, retry, receipt time | Row selection needs a keyboard affordance; add correlation links to schedules/runs. |
/learning | Overview, seven tabs, per-tab retry, refresh includes all tabs | Counts are based on loaded lists (up to 500), not authoritative platform totals. Add coverage and attribution-window metadata. |
/portfolio | Exchange balances, positions, orders; clarified relationship to Treasury | Standardize per-source valuation time and reconciliation to consolidated NAV. |
/treasury | NAV, exposure, benchmarks, earning, P&L, flows; shared design | Preserve existing coverage/dispute semantics; add a single freshness summary across component sources. |
/trading | Redirect verified | Continues to land on Harvest. |
/trading/goals | Mandate, caps, sleeve targets, ladders; renamed Trading goals; mandate error state | Distinguish decision acceptance time from observation and expiry; explain missing budget/headroom fields consistently. |
/trading/harvest | Plane status, arming, prices, ladders, lending; unknown/error states | Some health/reconciliation cards still conflate loading, missing configuration, and service failure. |
/trading/analysis | Thesis, order plan, briefs, dream, decisions; error/loading states and cadence copy | Structured parse failures and schema versions need explicit diagnostic metadata. |
/trading/lending | Ranked markets, supply/APY/utilization, retry, rescan failures, receipt time | API needs mint decimals, price and valuation time before USD TVL can be shown. Explain score version and available withdrawal liquidity. |
/trading/liquidity | Positions, pool and vault catalogs, retry, receipt time | Keep pool APR distinct from realized position return. Standardize catalog/vault refresh errors and observation windows. |
/trading/oracle | Feature table, sort/history, retry, receipt time | Add sortable coverage/missing-feature counts and consistent observation-age semantics. |
/trading/oracle-health | Family coverage and age, retry, receipt time | Freshest observation alone can hide stale members; report oldest age and missing symbols. |
/trading/inspector | Per-symbol feature provenance and failure state | Symbol selection is hard-coded; derive available symbols from the managed scope. |
/trading/cycles | Persisted flow health and alerts; shared visual treatment | Show scheduler timezone and next scheduled execution from an authoritative source. |
/trading/scope | Managed markets and coverage, retry, receipt time, corrected copy | Summarize the impact of a scope change on coverage and consumers before applying it. |
/trading/ceremony | Spending-limit ceremony; now reachable in navigation | Preflight needs a clearly persistent network, signer, amount, expiry and transaction-summary presentation. Hardware signing was not exercised. |
/logs | Filters, live toggle and detail, retry, receipt time | Show retention, stream/reconnect state, and correlation navigation. |
/integrations | Taiga configuration failure state; honest static-card labels | Need live health, last sync, failure reason and ownership for each adapter. |
/telegram | Clearly labeled command reference | Actual registered commands, bot identity, allowed chats and last delivery are not queried here. |
/settings | LLM/memory/cycle settings; errors no longer leave permanent skeletons | Add revision, last editor/time, dirty-state navigation protection and effective-vs-requested values. |
/sign-in | New brand/typography hierarchy and access guidance | Keep identity-provider errors actionable; live OIDC flow was not exercised. |
Prioritized follow-up
P1 — information needed for trustworthy operations
- Unified freshness contract. Each relevant API response should expose observation time, source, completeness, error/degraded reason, and expected cadence. Receipt time cannot prove upstream freshness.
- Authoritative valuation contract. Lending must expose decimals and valuation price/time. The header's on-chain estimate still needs explicit unknown-asset coverage and should eventually share the treasury's canonical accounting model.
- Integration and execution health. Return measured heartbeats, actual running version, sync/delivery status, and role-scoped capabilities. Static configuration must not be used as proof that a service is healthy.
- Decision/action audit context. Approvals, promotions, settings and ceremonies need the target, before/after values, requester, reviewer, timestamps, and durable outcome in a consistent presentation.
P2 — faster navigation and complete reporting
- Server-side totals and pagination for truncated learning/run lists; consistent time-range, timezone and filter persistence across analytical pages.
- Keyboard-operable data-row actions and Kanban moves; text alternatives for graphs, chart descriptions, and accessible names for remaining custom controls.
- A dashboard incident summary linked to affected hosts, schedules, jobs and decisions; consistent links between related records.
- Separate loading, empty, stale, partial and failed states in remaining bespoke trading and secondary detail panels.
Validation boundaries
Validation uses local development with a synthetic local session and intercepted API responses. No production credentials, mutations, deployment, trading actions, or hardware signing are required. Failed-service checks exercise rendering and navigation; they do not validate production data correctness or every populated chart and detail drawer. Shared changes must retain Treasury's existing accounting tests and the proxy/session boundary.
Verification results
- UI production build and TypeScript checking passed. The build retains the existing Next.js middleware-convention deprecation warning.
- All 174 existing tests passed, including accounting and proxy-header checks.
- All 35 route entries were opened in Chromium at 1440 × 1000 and 390 × 844
with unavailable upstreams. No page exceptions or document-level horizontal
overflow were observed;
/tradingredirected to Harvest. - Synthetic populated dashboard and agent data were checked in dark and light themes. Search with no matches, failed refresh followed by retry recovery, mobile table containment, drawer focus containment/restoration, field labeling, mobile navigation search and Escape/focus return passed.
- Documentation builds successfully. Existing broken-anchor warnings remain in older roadmap, security and audit links; no new review-page link errors were reported.
These are targeted rendering and interaction checks, not full accessibility certification or end-to-end verification of every production workflow.