# UX SPEC — DESIGN ROUND 3
**Kidunaverse · the one dialogue · renders Experience Spec v4 §1–§4 · July 7, 2026**
Pairs with: `Key Screens R3.dc.html` · `MOTION-ADDENDUM.md` · `OPEN-QUESTIONS.md` · the standing R2 set (`INTEGRATION.md`, `MOTION-SPEC.md`, `REALM-EXPRESSION.md`, `MAKING-SURFACE.md`), which remain in force except where noted in §7.

---

## 0. The sentence

**The app is one dialogue with your ally, spoken or typed, standing on the living ground — and everything else is a card that gets bigger for a minute.** No menus, no tabs, no navigation. Voice is not a mode: it is the same thread at a different sample rate. Fuller UIs open *over* the dialogue, do one job, and put you back on the exact sentence you left. Training is a world you enter only through a portal your ally offers. Money never lives here at all — it lives on the web, and the dialogue hands you across and receives you back.

## 1. Anatomy of the dialogue

Top to bottom, the only permanent things (unchanged from R2 §1: no chrome that is always true):

1. **The header is the relationship.** Ally name · grounding line (`grounded in Kinship Duna`) · meter whisper. Pull down past it: the Contract.
2. **The Thread** — one scroll, one memory, all doors (app, voice, Telegram) landing in it. The Account renders inline at attention; claims cite; corrections print; artifacts seal.
3. **Contextual actions** — the ally always offers what fits, as three grades of object:
   - **chips** — one-tap sayables (`show the treasury` · `set my token` · `hold it`). A chip is a shortcut for a sentence; anything a chip does, saying so does.
   - **buttons** — a chip with consequence stated, sky, at most one primary per beat.
   - **cards** — objects with a front (consequence) and a back (context); Docket rules from R2 §4 stand. Some cards are **doors**: treasury, a Forum proposal, a grant panel, a portal, a payment handoff. A door card carries a hairline `opens over the dialogue` footer.
4. **The composer** — text field + mic. One object. The mic does not open a new screen (see §2).
5. **The deck edge** — only while cards exist (R2, unchanged).

## 2. Voice — the same conversation, seriously

**Design rule: voice never takes the screen.** There is no orb, no full-screen visualizer, no "voice mode" UI. The composer *becomes* the voice band; the Thread stays where it is, scrolling as ever. What changes is the bottom 90px and the ground (which warms ~3% while a session is open — presence as weather, per the R2 motion grammar).

Four states, all in `Key Screens R3.dc.html` §2–§4:

- **Listening — folded.** The composer field becomes a live waveform strip (camel, quiet), and your in-flight words render **there, in the band** — small, italic, peripheral — not in the Thread. Nothing enters the Thread until the utterance closes: at that moment the settled words land as one normal member bubble, with the standard claim-settle. Watch anyone talk to a screen that echoes their words as they say them and they start speaking *to the transcript* — self-correcting, slowing down. Folding it keeps voice a conversation with your ally, not a dictation you're proofreading. The Thread stays the record; the band stays the conversation. There is no separate "voice note" object — the settled bubble already is the message.
- **Ally speaking.** The ally's reply streams as text *while it is spoken* — the same bubble a typed reply would use, with a small breathing ember beside the ally's name (the only "she is speaking" indicator). Reading and hearing are the same artifact; scroll back mid-speech and nothing breaks.
- **Barge-in.** Start talking over her: her stream halts mid-sentence within ~120ms, the unspoken remainder collapses to a dim `—` (never deleted from her memory, never shown as error), and your forming bubble takes the floor. Interrupting your ally is a normal act and costs nothing — the UI must make it feel like conversation, not like cancelling a download.
- **Switching mid-thought.** Tap the text field during a voice session: the keyboard rises, the voice band stays warm above it (`still listening` dot), and **your half-spoken sentence is already in the composer** as editable text — finish it by typing. The reverse also holds: press the mic mid-typed-sentence and speak the rest. One thread, one memory, one sentence across two channels.

Ends of sessions leave nothing: no "call ended" card, no duration stat. The transcript already lives in the Thread; the session was never a place.

## 3. The card → fuller UI → return loop

The one interaction contract every fuller UI signs:

1. **Born from the dialogue.** A door card (or a chip, or asking) opens it. Nothing opens from chrome, because there is no chrome.
2. **Opens over, never instead.** The sheet rises; the Thread dims to 0.85 and scales to 0.97 beneath (the Vigil/deck grammar from R2). The Thread is visibly still there the whole time.
3. **The return seam.** The sheet's top edge quotes, small and dim, **the sentence you left** — the last thread message before the sheet rose. It is both orientation and door: tap it (or swipe down) to return.
4. **The return is shown, not assumed.** On dismiss the sheet recedes, and the message you left is marked with a camel hairline that fades over one breath (2s). Anything you *did* inside lands as a new line under it (a receipt line, a set token, a granted level) — the fuller UI's whole output is a sentence in the thread.
5. **No residue.** No back stack, no "recently viewed," no state on reopen (the Vigil rule, now universal).

Fuller UIs in this round: **Treasury** (§4), **Forum** (§5), **Grant panel** (§6), **Record & wisdom** (screens §8), **Portal → Training** (§8 below — the one takeover-class exception), **Payment handoff** (§9 — the one that leaves the app).

## 4. Treasury — prose first, numbers second, motion when it matters

"Show me the treasury" produces **both**: the ally states the position in one sentence in the thread (that alone answers most asks), and a door card. The full view, opened:

- **The sentence leads.** `You hold $412 across three places; nothing is waiting on you.` Goudy for the figure, Avenir for the sentence.
- **Three shelves, not a table:** bank (Sphere virtual account), wallet (crypto), tokens ($KIDUNA, $FAN…) — each shelf one balance in Goudy + one line of what changed lately, cited.
- **Sending is watched, not formed.** "Send Matt 40 $FAN" is said (or chipped). The Flame moment: a single gold token leaves your wallet line, arcs, and settles into Matt's line (MOTION-ADDENDUM §3). The number decrements only when the token lands. No form, no confirm dialog — sums past the Contract threshold arrive as a card instead.
- **Read-only toward money rails.** Anything requiring payment authorization becomes a handoff card (§9). The treasury view can *show* everything and *move* nothing that needs authorizing.

## 5. Forums — a proposal, its discussion, your one token

Forum view (opened from a claim, a card, or asking):

- **The proposal is prose:** title (Goudy), what passing does, what failing does, the Drafter's treasury math — consequence before mechanics.
- **Discussion is weighted listening made visible** (R2 grammar): members' words with their standing shown typographically; your own prior statement quoted back gold (`what I understand your position to be`).
- **Your token is a physical object, singular.** One pass/fail token per member per proposal, identical for everyone, costing nothing — the UI must make equality legible at a glance: every member's cast token renders the same size, no stake column, no weight numbers anywhere. You set yours by sliding it to PASS or FAIL and **press-and-hold** (a vote is a signature; R2 §4 gravity). Until the close it can be re-set; the Elector settles at the deadline.
- **Deciding is never fundraising.** No balance, no cost, no "boost" — money vocabulary is structurally absent from this surface.

## 6. Access as a glance and a gesture

**The grant panel** (opens when you connect with someone, or from asking "what does Stacy hold?"):

- **One glance:** the person at top; below, a vertical **ladder of four rungs** — public · private · secret · personal — with the person's marker sitting on the rung they hold over you. The **personal rung is drawn sealed** (closed hairline ring, no landing slot): structurally ungrantable, visibly so, no explanation needed.
- **One gesture:** drag the marker to a rung. The consequence rewrites live in one sentence beneath (`Stacy sees what anyone can see, plus what you've marked private — nothing secret, nothing personal.`). Committing a *widening* is press-and-hold (extending trust is a signature); narrowing commits on release (taking back is always cheap — trust must be easier to retract than to extend).
- **Tools are sentences, not scopes:** under the ladder, per-domain grants written as prose with a small marker each — `may see open calendar slots and book them` · `nothing financial`. Each is one flick to revoke.
- **"Actually, that's secret now" is one sentence to your ally** — screen §10 shows it: the member says it in the thread, the ally quotes the new binding back (`Your sleep work is secret now — that binds every face I wear, everywhere, from this moment`), and one record line seals it. No panel needed for the common case; the panel is the glance, the sentence is the law.

## 7. Training — entered only through a portal

- **The portal card** is a door card with weather in it: a thin live strip of the world's ground breathing along its top edge. Front: what you'd do, with whom, how long (`Enter Foundry Row? You'd negotiate a squad rate with Harl's crew — about twenty minutes, with Teo and Mika.`). Back: why the ally chose it for you now. **Entering is a tap.** The signature gesture means one thing everywhere else — an act with consequence — and entering a training has none by design; holding to enter would either dilute the gesture or teach newcomers that it costs something, and newcomers meet trainings first. Press-and-hold stays reserved for real signatures, votes, authorizations, and — inside training — **practice signatures**, where holding the gesture is itself the exercise.
- **Regimen progress is conversational, never a level list.** Finishing prints in the thread (`You held the rate. That's the third negotiation you've closed`), and *new portals opening* arrive as new portal cards with the reason attached. You never see a menu of worlds; the ally curates, and says why.
- **The entry transition** inverts drift: instead of the ground warming under the thread, **the thread recedes INTO the ground** and the world rises around it as an isometric diorama (MOTION-ADDENDUM §4). Duration ~1400ms, and the crossing itself *is* the deliberation window — a second tap mid-crossing aborts it and rolls it back, and you never left. There is no separate hold to release; the tap that opened the portal is the only gesture involved.
- **In the world:** members are present **as their allies** — named marks with their member's name beneath. Your own ally may wear a **role**: shown as `MERIDIAN — quartermaster · worn by Aurelia, your ally`, role name in Goudy, the underlying identity never hidden (one system wearing personas is a thing members *learn here*, so the seam is always visible). **Actors** (NPCs) carry a visible purpose chip and a drawn routine path — you can see what they're for and where they cycle.
- **The first tell is narrative, before it is material: the practice economy has a name and a giver.** A first-time member has never seen filled gold, so hollow gold alone doesn't yet mean anything to them. An actor hands the practice currency over *in the fiction*, by name, before the wallet ever renders — Meridian, in role: `Harl's crew pays in foundry scrip.` The name and the provenance do the first-contact work; the render is the confirmation, not the only signal.
- **The tell that nothing here is real money — without words: gold is never filled in training.** System-wide, filled gold = signature/value moments. Inside any training, every value-bearing object renders **hollow**: sim tokens are dashed-stroke open circles, sim treasury figures sit in dashed-hairline chips, the sim Forum's cast tokens are outline rings, and a practice signature stamps a hollow seal. Real-money surfaces can never render hollow gold; training surfaces can never fill it. One rule, learnable in one glance, enforced at the render layer. (Secondary tell: the training ground breathes on a fast ~20s cycle — a world that is slightly *too* alive.)
- **Real channels are real, and say so.** An exercise that sends an actual Telegram message renders the outbound message **solid** (filled sky send button, real recipient, `this leaves the training — Dana really receives it`), sitting inside the hollow-gold world. The contrast IS the lesson: the boundary is money, not realism.
- **Exit** reverses the entry; the world sinks, the thread rises, and what happened prints as normal thread lines with training provenance (`in Foundry Row`).

## 8. The record & wisdom — asked, never browsed

"What did you tell me about Dana in June?" is answered in prose, cited, in the thread. The fuller view (from the answer's card) is **the answer, expanded**, never a search results page: the ally's sentence stays pinned at top, the artifacts that support it stack beneath — renderings, corrections (always printed, never hidden), seals, wisdom items — each with its access-level mark (`secret` / `private` / `personal` in IBM Plex small caps). Refinements are chips in the ally's voice (`only corrections` · `earlier`), because search is conversation; there is no query field.

"Asked, never browsed" is the principle, not an absolute limit on how broad the question can be. "Show me everything we've decided about Dunathon" is still a question put to the ally — wider in scope, but answered the same way, as prose with the record expanded beneath it. The line that matters isn't how much ground the answer covers; it's whether the member is asking or going somewhere to look. If usage ever shows members reaching for something that behaves like a browser, the fix is a better answer, not a better browser.

## 9. Money handoff — a door, not an eviction

The app never touches payments. When authorization is needed:

1. **The card states everything before you leave:** what, how much, to where, and that the money surface is on the web — `This one signs on the web · you'll be back on this sentence.`
2. **The web surface is another material.** It rises as a **cream sheet** (`--kin-cream-white` ground, espresso type — the print world) over the dimmed thread. Money's home is visibly *a different place* with the same blood: same type families, same gold-for-signature. The thread's return seam stays visible above it the whole time.
3. **The return is a receipt line**, landing under the sentence you left, gold-sealed, cited to the web record — and the camel return-hairline marks the spot. Total round trip feels like reaching over to the desk and back, not like being sent away.
4. **The cream sheet is designed; the web surface behind it isn't yet — that's an R4 commission, not a gap left to discover on launch.** The handoff only reads as reaching across a desk if the web side (join, wallet, limits, authorize) honors the same design system: espresso↔cream inversion, Goudy figures, gold-for-signature, no promotional chrome, no cookie-wall. The authorize page in particular renders **nothing but the act** — what, how much, to whom, one signature. The receipt-line return contract is specified now, as an API between the two surfaces, in MOTION-ADDENDUM §6.

## 10. What changed from R2, and why

| R2 said | R3 says | Why |
|---|---|---|
| Voice existed in principle (composer mic) | Voice fully designed: four states, no voice screen, transcript-as-message, barge-in as a normal act | v4 §1: voice is the same conversation — so it gets the same surface, not a mode |
| Fuller views = the Vigil lens only | The lens grammar generalized to a **universal card → sheet → return loop** with the return seam and return mark | v4 §1: chips/cards open fuller UIs; the R2 lens rules were already correct, so they were promoted, not replaced |
| The Commons demoted to the ground; no walkable world (R2 Disagreement 1) | The world returns **as Training** — entered only by portal, never the app's frame | v4 §3 resolves the R2 disagreement in both directions: the frame stays the Thread, and the world ships with an honest job |
| "Markets," influence framing open | **Forums**; one equal pass/fail token, costless, equality made visible | v4 §5 / Foundation §5 |
| Access levels public/private/secret in wisdom modes | Four levels everywhere + the grant ladder + sealed personal rung + grants-as-sentences | Foundation §2–§3 promoted Connections to first-class; the UI had no surface for them |
| Money in prose, rails unspecified | Prose + Flame in the dialogue; **all authorization on the cream web sheet**; receipt-line return | v4 §4: mobile never touches payments |
| The deck, drift, realm expression, making, idle state | **Unchanged.** All R2 rules stand | Nothing in v4 contradicts them |

Everything else in the R2 set — motion timing tokens, realm dials, the making beats, "emptiness is success" — is inherited verbatim.

## 11. Resolved this round, from Open Questions (July 7)

All six disagreements in `OPEN-QUESTIONS.md` were adopted the same day and are folded into the sections above. Recorded here for traceability — full resolutions live in `OPEN-QUESTIONS.md`.

| # | Disagreement | Resolution | Where it landed |
|---|---|---|---|
| 1 | Live transcript reads as dictation | Fold it: settled turns in the Thread, in-flight words in the voice band | §2 |
| 2 | The record browser shouldn't exist | Kept "asked, never browsed" as a principle, not an absolute — broad asks are still conversation | §8 |
| 3 | Portal hold dilutes the signature gesture | Portals open on a tap; the crossing is the deliberation/abort window; hold reserved for real and practice signatures | §7 |
| 4 | Hollow gold needs a second tell | Named, in-fiction provenance (Foundry Scrip) precedes the material tell | §7 |
| 5 | Does spoken voice drift with realm register? | No — spoken voice constant per ally; register drifts word choice and pacing only | `design-r2/REALM-EXPRESSION.md` §2 |
| 6 | The web money surface is undesigned | Commissioned as an R4 deliverable; receipt-line return contract specified now | §9, `MOTION-ADDENDUM.md` §6 |
