Contract-freeze · UX approval

FuzeFront — Design Frames

Every feature awaiting UX approval. Each entry is a navigable HTML frame set built in the fuse-seam design system — the visual contract that implementation and Playwright verification are measured against. This directory is generated from the folders present in design/frames/; it is never hand-maintained.

account-security

Account Security hub — approval frames

Contract-freeze UX artifacts for the account-security hub: the navigational spine linking password, two-factor, devices & sessions, API tokens, and connected accounts. Approving these frames approves the AccountSecurityHub visual + interaction model and its component/package plan before UI implementation. frontend-test-engineer drives Playwright against these via the data-frame / data-* hooks.

approved (1/1 flows) 2 frames stamp 4ac159cdb36a
api-tokens

Service tokens (M2M) — approval frames

Contract-freeze UX artifacts for the vendor-neutral machine-to-machine service-token surface (create-scoped → reveal-once secret → list → revoke) backed by FuzeFront's Security API. Approving a flow approves its visual + interaction model AND the component/package build inventory before UI implementation. frontend-test-engineer drives Playwright against these via the data-frame / data-* hooks. The reveal-once screen (03) is the most important in the flow.

pending (0/1 flows) 5 frames stamp 90a5c56f35ce
app-scopes-user-menu

App scopes, consolidated user menu & notifications — approval frames

Contract-freeze UX artifacts for four shell changes and one new backing service: per-app install scope levels (personal / organization / both) with an install-for-me vs install-for-everyone choice; the organization switcher and language switcher moving out of the top bar into the avatar menu; a multi-account switcher bounded at MAX_PARALLEL_ACCOUNTS=5 with a per-account storage-namespace isolation contract; and the notification bell backed by a real notification-service inbox. Approving these frames approves the interaction model AND the build inventory (flows / components / services) before implementation.

pending 5 frames stamp b238e064a626
auth-experience

Auth experience — approval frames

Contract-freeze UX artifacts for FuzeFront's complete, professional sign-up & sign-in: inline email-availability, password strength + confirm-match against the real 12+ policy, Cloudflare Turnstile, the email-verification state machine, and the honest no-enumeration password reset. Approving these frames approves the flows, components, packages and contract deltas in `build`. frontend-test-engineer drives Playwright against the data-frame / data-* hooks. Per-flow approval — one approved flow unblocks that flow's implementation.

approved (4/4 flows) 7 frames stamp c047375d3b72
authz-admin

Access administration — approval frames

Contract-freeze UX artifacts for the vendor-neutral tenant/org access-administration surface (members, roles, invite/add, change-role, remove) backed by FuzeFront's Security API. Approving a flow approves its visual + interaction model AND the component/package build inventory before UI implementation. frontend-test-engineer drives Playwright against these via the data-frame / data-* hooks.

pending (0/1 flows) 5 frames stamp 95b85336bf68
billing-invoices

Billing Invoice History — approval frames

Contract-freeze UX artifacts for the vendor-neutral, DB-backed invoice history capability. Approving these frames approves the InvoiceHistoryPanel visual + interaction model before UI implementation. frontend-test-engineer drives Playwright against these via the data-frame / data-* attributes.

approved 2 frames stamp 3e25e99bc31a
devices-sessions

Sessions & devices — approval frames

Contract-freeze UX artifacts for active-session/device management: list every signed-in device (browser, OS, location, last-seen, this-device flagged), sign out a single session (including the caller's own current session), and sign out everywhere else. Revocation is enforced server-side. Approving a flow approves its component/package plan before UI implementation. frontend-test-engineer drives Playwright against these via the data-frame / data-* hooks. No provider name appears in any consumer surface.

pending (0/3 flows) 3 frames stamp 990a3071fea4
federated-apps

Federated App Platform — approval frames

Contract-freeze UX artifacts for the federated-app platform. Approving these frames approves the App Manifest model before UI implementation. frontend-test-engineer drives Playwright against these via the data-frame / data-* attributes.

pending 4 frames stamp 644fa5fa6e87
locked-app-mode

Locked App Mode — approval frames

Contract-freeze UX artifacts for locked app mode (white-label own-domain web + per-product native app). Approving these frames approves the mode:locked + branding + native manifest model before UI implementation. frontend-test-engineer drives Playwright against these via the data-frame / data-* attributes (frontend/tests/locked-app-mode-frames.spec.ts).

pending 4 frames stamp 57046a2faef2
mfa-management

MFA management — approval frames

Contract-freeze UX artifacts for two-factor authentication management: enrol an authenticator (TOTP) or phone (text message), one-time recovery codes, remove a method, and the step-up challenge shown mid sign-in. Approving a flow approves its component/package plan before UI implementation. frontend-test-engineer drives Playwright against these via the data-frame / data-* hooks. No provider name appears in any consumer surface.

pending (0/5 flows) 6 frames stamp d67fea98b2de
password-reset

Password reset & change — approval frames

Contract-freeze UX artifacts for three password flows: unauthenticated self-service reset, signed-in change-password, and set-first-password for a social-only account. The 'check your email' screen renders the deliberate no-enumeration 202 honestly. Approving each flow approves its slice of the component/package plan. frontend-test-engineer drives Playwright against these via the data-frame / data-* hooks.

pending (0/3 flows) 6 frames stamp 366a56f70ef7
portal-admin-consoles

portal-admin-consoles

Contract-freeze UX artifacts for the two multi-tenant admin surfaces: a master-admin console to run the portal fleet (list/create/suspend/resume + domain status) and a portal-admin console for a tenant to run its own users, app catalog, and billing (Stripe Connect). Approving a flow approves its visual + interaction model AND its component/package/contract build inventory before UI implementation. frontend-test-engineer drives Playwright against these via the data-frame / data-* hooks. UI-only (FF-EPIC-14) consuming FF-EPIC-09/11/12/15.

pending (0/3 flows) 9 frames stamp 57c22c8ce439
white-label-portal

White-label tenant portal — shell & login (approval frames)

Contract-freeze UX artifacts for the FuzeFront white-label tenant portal: one shell (topbar + side panel + app grid) and one login, reskinned to the active portal's name/logo/accent from GET /api/v1/portal/context, applied entirely through design-system token overrides (no raw hex). Covers loading (no-flash), error, and the fail-closed cases (suspended portal, unknown-host root fallback, cross-portal login rejection) plus light/dark theming. Approving these frames approves the flows, components, DS primitive, and package in `build`. frontend-test-engineer drives Playwright against the data-frame / data-* hooks. Per-flow approval — approving portal-shell unblocks that flow independently of portal-login.

approved (2/2 flows) 6 frames stamp 61c774adba75