Model interface layers
Model interface layers
This guide describes the interface-layers and Code development work through 0.66.9. It is not a claim of availability in an installed or hosted edition.
Code, Data, App, and Chat are four ways to work with the same Grid model. A continuous frame surrounds every layer and global screen. Choose Chat, App, Data, or Code from the middle of its left rail. The selected layer has a visible label and highlight. Switching layers keeps the model and folder partition; it does not copy the model or create a second set of calculations.
The top bar and left rail form one continuous material around a rounded, inset workbench. Data's menus and ribbon sit inside that same boundary with the grid; there is no second decorative grid behind the work surface. A slim marker beside the selected layer reinforces its label and highlight. Light and dark appearances use the active theme, and reduced transparency keeps the surrounding frame solid.
At phone widths, the model title occupies the first row of the frame. Back and Forward, Undo and Redo, and the companion control remain together below it. The workbench keeps the same inset boundary as the window narrows.
| Layer | Use it to |
|---|---|
| Code | Write model source, build and preview surfaces, configure connections and packages, and inspect execution. |
| Data | Work in the existing spreadsheet and Ops workspace, with its grid, ribbon, inspectors, and specialized views. |
| App | Use a model's existing app, document, notebook, chart, or other surface. |
| Chat | Ask the Grid agent to explain the model or propose changes, with room for a full conversation. |
The rail runs from Chat at the top through App and Data to Code at the bottom. It organizes ways of working with the model. The frame stays still during a switch; only its content makes a brief arrival transition. On narrow or short windows, a labeled Choose layer button opens an anchored picker. Arrow keys move through its choices, Enter opens one, and Escape closes the picker.
With a mouse or pen, press a layer and drag through the rail to preview its purpose before choosing. Moving past the small drag threshold opens a schematic preview that follows the pointer between button centers. Releasing over a new layer requests one switch. Releasing over the current layer keeps your place; releasing outside the choices, pressing Escape, losing pointer capture, or changing the window cancels the gesture. Previewing preserves the editor's focus and selection, and temporarily withholds typing and Undo/Redo.
For keyboard exploration, focus a rail layer and press Alt+Down Arrow. Use Up/Down or Home/End to preview, Enter to accept, and Escape to cancel. Tab closes the preview and continues normal focus traversal. Normal clicks and keyboard selection remain available, including the compact picker. Hover only gives a quiet description. Previews do not start another workspace, run a model, or capture the live Browser surface. Reduced motion removes their spatial movement.
The Grid mark at the top of the rail opens Home (Models). Help, shown as a question-circle, Appearance, and Account and access sit at the bottom. When a model is open, Home and the other global screens provide a separate Return to model icon below the Grid mark; its label names the open model. Data keeps its local menus, command ribbon, formula bar, grid, and status tools inside the shared frame. Home and Help replace its duplicate Models and Docs ribbon commands.
Data retains its established ribbon: Model, View, Format, Formula, Insights, Data, and Search keep their existing groups and layout. Open definition is an additional action in Formula; Attach to Chat and Reveal in App are available in Insights. Hide ribbon and Show ribbon retain their existing whole-ribbon behavior. The address and formula bar stay directly above the grid. The ribbon scrolls horizontally when needed; focus it and use the arrow keys, Home, or End to reveal remaining commands.
The top bar names the current model or global screen. Back and Forward revisit layers and global screens within the current model and folder partition. For example, open Data, switch to Code, then visit Help: Back returns to Code, and Forward returns to Help. Opening another model or partition starts a fresh location history. Code's working-tab history and App's view navigation remain inside their respective layers.
When a window resize replaces the layer rail with its compact picker, an open navigation popup closes and keyboard focus moves to the visible control.
Undo and Redo occupy a separate group in the top bar. Their curved arrows stay in place and dim when unavailable; available actions identify their editing context in the tooltip. The buttons use the focused editor or surface's existing history: Data edits, Code source, App Builder changes, document edits, and supported grid-view actions. Chat's composer can expose its native text history when the browser reports that it is available; Undo does not retract sent messages. Unsupported editors keep their local keyboard behavior and leave the shared buttons disabled. Home, Help, System, and Network have no editing history.
For example, change a cell in Data, visit Help, and return to Data: Undo still restores the cell's previous value, and Redo reapplies the edit. Focus a Code source editor and Undo applies to that editor's draft instead. Moving focus into the top bar preserves the last supported editing context. Existing editor, model-admission, and accepted-deployment history reset rules still apply.
Supported authored App views also keep acknowledged Undo and Redo steps when you leave App and return to the unchanged view. This history belongs to the same model, partition and View definition; changing its source or configuration starts fresh. An uncertain action, or one that depends on the previous viewer's local state, remains unavailable with an explanation. Undo cannot skip it to reach an older edit. This continuity is session-local and does not apply to check previews, packaged views or views without their full model source. It does not add an Apply to Live operation for private scenarios.
Advanced, below Code, opens System (formerly Monitoring) for app health and diagnostics, or Network for peers, connections, and activity. It also contains the personal starting-layer preference. For example, from Code, open Advanced and choose System to inspect app health, then use Back or Return to model to resume work. Visiting these global screens does not change the model's starting-layer preference.
In Network, Machines keeps small networks in one list. Above 20 machines,
use Find machines to search all peers by name, transport address, or status,
then Previous, Next, or the page selector to browse matches. For example, search
for degraded to find matching peers even when they were on a later page. Refresh
keeps the current page when available and moves to the last valid page if peers
disappear. Counts and speed-test route choices still cover the full network;
browser Find sees the currently displayed machine page.
Choose Open beside in the frame. In Data, Open Chat beside opens a second pane for the existing conversation. In Code, Open App beside opens the model's remembered or configured App view alongside the source workspace. Both pane headings show Live: they share the same model and folder partition. Opening either companion does not make a private copy, duplicate the model, or send a question.
Click inside a pane or its heading to focus it. The shared frame identifies the focused pane, and Undo/Redo follow that pane's supported editor. Focusing Chat does not leave Data's model history active as a fallback. Ctrl+F6 switches between the panes. While a pair is open, choosing either of its layers in the rail focuses the existing pane. Data + Chat retains its pair when visiting another layer and returning to Data. Leaving Code + App for another layer closes that composition through the existing leave guards.
Code + App retains Code's working editor while App changes pages. App page navigation and Close App consult App's unfinished-work guards; leaving the model or opening a global screen consults all mounted surfaces. App's Find and return-to-Code shortcuts belong to its focused, visible pane. Its view history restores App's scroll position without scrolling Code. An exact Reveal in App handoff opens the accepted App destination in the companion and waits until that pane is visible and focused before highlighting its element.
Drag the divider to resize the panes. Its keyboard controls are Left/Right Arrow to adjust the split, Home/End for its limits, and double-click to balance the panes. In a narrow workspace, the two pane names become tabs. Use the tab buttons or Left/Right Arrow, Home, and End to select one. The hidden pane's DOM is inert, and shared editing commands follow the selected pane. Resizing the window retains that selection.
Account, AI setup, Keep in model, and notifications remain available above either pane. Keeping a Chat answer offers the model's existing document, notebook, and deck destinations and live references from either presentation.
Close Chat in the frame or Close Chat pane in its heading returns the space to Data without deleting the conversation or draft. Open Chat beside reopens it with the retained divider position in the current model session. Changing model, account, or partition starts a new pane layout. To open Chat as the full layer, close the companion and choose Chat from the rail.
Close App returns the space to Code after App's leave guard accepts. Reopen it with Open App beside; selecting Code within the pair simply returns focus to its existing editor. A named private scenario can also occupy the companion pane beside Live; its separate lifecycle and editing context are described below.
On Grid Desktop, Open Browser beside opens a reference pane beside any model layer. Enter an address to open a page; an empty pane makes no page request. Its heading says Reference, so it cannot be mistaken for another Live model or a private scenario. Page navigation stays in the Browser's own Back, Forward, and Reload controls. The frame's history continues to navigate the model, and its Undo/Redo never falls back to Data while Browser is focused. While the Browser reference has focus, the model-layer rail has no selected layer. Choose a layer by click or keyboard preview to return to its existing model pane. Changing pane focus cancels an unfinished layer preview.
The reference page does not write a Browser surface's data slot or publish snapshots into formulas. An authored Browser surface keeps its existing surface variable and capture controls. If the same authored Browser is shown by two model panes, one presents its native page at a time; Show here brings that session into the other pane. An independently opened reference page can remain beside it. Native pages follow their pane's visible bounds, and inactive tabs release native visibility and background capture work independently.
Changing the primary layer keeps the reference page beside it. Closing and reopening Browser retains its address draft and uses the existing native session while that bounded session remains resident. An evicted session offers an explicit fresh reopen. This is current-session retention, not saved browsing state across application restarts. Opening another companion uses the same second pane; replacing App still consults App's unfinished-work guard.
A model owns calculations, inputs, and views. A surface is a view of that model: an app, document, notebook, dashboard, table, or specialist view. A layer determines how you work with them. For example, Code authors a dashboard, App presents it, Data exposes its underlying values, and Chat helps explain or change the same model. Documents and notebooks keep their existing editing and execution capabilities; layers do not replace them with a second page system.
Follow an object between layers
Ordinary layer switching returns to that layer's working position. It does not replace your selection with a guessed counterpart. To follow an object, use an explicit command:
- Select an authored cell or named value in Data and choose Open definition. Code opens the matching current source definition, retaining its worksheet or namespace. A visual row number in Data's named-value columns is never treated as a cell address.
- In Code, place the cursor within an authored cell or named-value definition and choose Show in Data. Grid reveals that exact target. Global names keep their identity independently of the worksheet last visited in Data.
- Choose Attach to Chat from Data's selected-object tools or Code's current authored definition. Chat opens with an unsent symbol context chip. Your existing question and attached images remain. This action does not send a request, explain the value, or apply a model change. Remove the chip to leave the value out of the question. The chip can exist before you type anything. Cell chips use familiar A1 labels while retaining the exact worksheet address.
- Choose Reveal in App from Data's Insights tools or Code's current authored definition to find a direct binding in an already loaded declarative View. If several elements or pages bind that value, choose a destination. Grid opens its page and highlights the exact visible element. A hidden or missing element is reported without clicking its control. Inspection does not load values, run actions, change inputs, or ask the assistant.
- Return from Chat to the exact Data value or Code definition using the return control. Sent message context keeps that same origin. A bare global name is not reinterpreted as a name in the default worksheet.
- Switch layers normally to resume another working position; use the explicit commands again when you want to follow the object instead.
Open definition is unavailable when the selected object has no exact indexed definition. Show in Data is unavailable for range definitions, generated values, and surface payloads whose Data placement is not known. Named targets must exist in Data's visible named-value layout. Grid does not infer a correspondence from matching values or from text inside embedded content. App's existing binding actions use known symbols; this does not add a mapping for every App element. Reveal in App requires synchronized source and current resident View metadata. It excludes generated or local-row bindings, dependency-only matches, dynamic page parameters, custom code, imported components, and packaged apps without a reverse reveal contract. Finding no target leaves the current layer in place. Private scenarios keep Chat execution unavailable and do not attach their private values to the Live assistant.
Live and private scenarios
The Live context in the top bar identifies the connected model. The layer rail changes how you work with that context. Creating a private scenario changes the context itself: it captures the confirmed Live source and current input state in a separate, temporary calculation session. A named Scenario label stays visible while you work there. A second view of Live is still Live; it does not create this isolation.
Open Live, name the experiment, and choose Create private scenario. The admitted copy opens beside Live under the same frame. Pane headings and narrow-window tabs identify Live and Scenario · your name separately. This workspace supports portable workbooks with local inputs and supported declarative Grid Views. It provides private source editing, input and value inspection, supported View interaction, and a manually advanced clock. Use Run scenario source to apply an edited source draft to the copy. The normal Grid compiler and calculation path still determine formula results. Recompilation preserves matching declared-input overrides and private time but restarts rule state and private files. It never reloads new values from Live into the experiment.
For example, start a pricing experiment from a workbook with a Price input and a Total calculation. Change Price in the scenario, then compare Total with its starting value while Live remains visible alongside it. Select the Live pane or Return to Live to focus ordinary work without ending the experiment. Comparison is against the copy's captured starting values, not a continuously synchronized view of Live. At creation identifies the captured Live revision and stays fixed while Live continues to change independently. Unsent source and input drafts remain in the workspace when you change layers or focus Live. Each input keeps its own draft when you select another value. Data remembers its scroll position and editing focus. In scenario Code, Show in Data follows the authored definition under the cursor, independently of the value previously selected in Data.
The layer rail, Back/Forward, and Undo/Redo belong to the focused context. Changing the private layer leaves Live's layer in place. Private history never falls back to Live's editing history. Selecting private Chat shows why the Live assistant is unavailable there; it does not attach private values or send a request. Native document Open and Save belong to Live, and private source runs only through Run scenario source. An already started native Open may still open its folder after focus changes, but its late result is not adopted by the newly focused private workspace.
An open Live dialog keeps its focus and unfinished edits while a scenario is being prepared. When the copy is ready, finish or close the dialog and select the scenario explicitly. Closing the dialog does not switch contexts for you. Live model dialogs and notification actions stay unavailable under private focus. Account settings, notification text, and dismissal remain available; model-access settings belong to Live. A save already accepted in Live may still finish after focus changes.
Timed notifications pause while you hover over them or focus their buttons. Their remaining time resumes when you move away, so an Undo or other action does not vanish while you are reaching for it. Dismiss remains available at any time; persistent notifications stay until dismissed.
From Home, Help or another global screen, choosing a layer in the rail opens that layer in Live and hides the retained private pane. The named scenario remains available with its drafts. When Live has focus and the private pane is hidden, the top-bar Live control shows the scenario's name beside a hollow diamond. Open that control and choose the scenario to resume it. Return to model instead restores the previous workspace, including its private focus when a scenario was open.
Choose Refresh scenario, or explicitly reopen a hidden scenario, to read its current private state. Ordinary pane focus and narrow-tab changes do not refresh it. Refresh does not replace a staged input or silently advance the revision that edit was based on. If the scenario changed since a draft began, the inspector shows the current value and pauses that draft's Apply action. Choose Keep my draft to retain your edit against the reviewed state, then apply it separately, or choose Use current value to discard the draft. Neither choice writes an input by itself. There is no Apply to Live operation in this increment.
Use Show to narrow the comparison to changed values, inputs, or results. Find a value searches the whole comparison, including values outside the visible rows. In large comparisons, Arrow keys move focus between values; Home and End reach the first and last available value. Explicit returns from Code reveal the matching value. The summary counts changed declared inputs separately from other model values; it does not infer which input caused a result to change. At creation and Scenario now retain type labels, and Change reports compatible numeric differences or a change of type, status, or definition. New and removed definitions remain visible; removed values cannot be selected for editing. Numeric differences require ready finite numbers with the same type tag, so different currencies or text and numbers are not subtracted from one another.
Data's existing saved input scenarios are a different tool: they store input presets in the model's Files, and Restore scenario inputs changes that model's inputs. The top-bar private scenario is a separate temporary session; its name and lifetime do not make it a saved input preset.
The workspace retains one named private copy at a time and shows at most two panes. Closing its pane in the frame hides the copy and keeps its drafts; choose the named Open … beside Live action or its entry in the context menu to reopen it. Opening Chat, App, or Browser in the companion slot also retains the hidden scenario. Reopening reuses that session rather than making another copy. Discard scenario… inside the private workspace asks you to confirm Discard scenario; that action ends the session and discards its drafts. Changing model, folder partition, or account also asks before discarding the private copy and is unavailable until a pending private operation finishes.
Copies are not saved models, durable branches, or recovery files. An idle session expires after 15 minutes. Hiding a pane or focusing Live does not keep it alive through background polling. Create a new copy if the session expires. Keep valuable source changes separately before ending an experiment.
Scenario admission rejects unsupported models with an explanation. It does not silently execute their unsupported features against Live. External model references, connectors, jobs, external actions, native resources, Browser surfaces, JavaScript, and imported View components are unavailable. Private scenarios do not execute AI Chat requests. Initial limits include 1 MiB of source, 4,096 authored values, and 32 supported declarative Views; bounded saved values are required. A failed source compilation preserves the prior accepted scenario. If a mutation cannot be confirmed, the copy stops accepting further operations and asks you to create a new scenario.
This is a bounded private-workbook feature. Durable scenario storage, arbitrary application duplication, comparison against a freshly captured Live revision, and deliberate application of changes to Live remain separate work.
Appearance and desktop behavior
All four layers share the existing application theme. Appearance at the bottom of the rail offers the same Grids, Classic, Excel, Notion, Cursor / VS Code, Terminal, and High Contrast themes as Data, with Light, Dark, and Auto modes. Auto follows the system. Your choice persists across layer switches. Browsers retain it for the same site; desktop keeps it in the app profile across restarts. Document controls and menus inherit that choice; the writing page uses a light paper palette. A failed preference save is reported; the selected appearance remains usable for the current session. The shared frame and Data's local tools use the same selection.
The appearance control also works from the keyboard. Focus it and press Enter to open its panel, then choose a color mode or use the Theme selector. Escape returns focus to Appearance. Tab moves through the panel's controls, then closes it when continuing into the surrounding controls.
Controls, paper, borders, focus indicators, and editor syntax use the shared theme settings. High Contrast uses opaque panels and clear outlines. Reduced motion removes the content arrival transition, and reduced transparency makes the outer frame and floating App panels opaque. The frame's normal transition lasts 140 ms and fades content without moving its bounds. Reading pages, source, and the Data grid remain solid surfaces. On narrow screens, document tools remain accessible through their scrolling toolbar and menus.
On desktop, the frame's top bar spans the window and reserves space for macOS traffic lights or Windows/Linux window controls. The rail begins below it, so Home stays clear of the native controls. Empty top-bar space supports window dragging; buttons and open panels remain clickable. Inner layer toolbars do not reserve a second native titlebar. macOS fullscreen removes the traffic-light gutter. These changes use the existing Tauri window customization and keep one appearance choice across the layers.
Frame menus and Account temporarily hide an open native Browser surface so its child window cannot cover those controls. Closing them restores the existing browser session and its measured bounds; hidden browser polling is paused. Printing and PDF export omit the frame.
Code
Code has seven work areas. Model is the source workspace. Surfaces opens view editors and their bindings. Connections relates runtime declarations to the available connector catalog and configuration tools. Dependencies connects model imports with workspace packages. Projects opens local artifact source and development checks. Registry supports discovery and publication. Debug opens the dependency and execution graph. Each area has its own working tab and history; source drafts survive visits between them. These tools use the same model and runtime as Data.
Large Model source files keep the complete outline and exact source links. Opening Code now avoids reparsing each indexed statement; definitions inside embedded payloads remain excluded. Dense initial opening can still take longer than the local response target.
In Connections, In this model lists connector declarations reported by the runtime. All connectors includes the runtime catalog, even when a connector is not used by the model. Filter by name, source ID, or operation. Select a connector to inspect its declared targets, transport, packaged availability, and configuration requirements. Requirement rows show names and configured status, not secret values or raw declaration configuration.
For example, choose All connectors, filter for local.midi, and select
Local MIDI Events. Check health captures its current runtime health without
starting a MIDI session. Packaged availability, reachability, and readiness are
separate facts: an ok response without a readiness result does not claim Ready.
Health is requested explicitly; overview selection does not mount device
controls or poll every connector. Model or partition changes invalidate pending
reads and health results. Refresh overview rereads the catalog and declarations.
Their failures remain visible separately, so a failed declaration read does not
appear as zero model usage.
Open target source appears when a runtime declaration has a matching authored target in accepted source. Cell and range coordinate aliases are matched within their sheet. The link opens Whole model at that definition; editing a draft hides these links until its source is accepted. Declarations are compiled connector bindings, not a complete inventory of every API or database reference in formulas. Configure connections opens the existing API service, database, model-secret, and connector operation controls. Returning to the overview refreshes its reads. API Try it results belong to the selected model and installed operation. Request fields stay read-only while a call runs; editing them afterward clears the previous result. Leaving configuration retires the client wait, but does not undo an operation already received by its provider. Connections retains the selected connector, filter, scope, and overview/configuration choice while moving between Code areas in the current model session. Returning refreshes inventory; health results are not retained or requested automatically. Back returns directly from a declaration to this context. Data retains its existing connector panel and layout.
In Dependencies, In this model lists authored USE declarations with
source links, including incomplete declarations while editing. The list excludes
embedded payloads and describes direct declarations, not transitive dependencies
or compiler-resolved availability. Draft imports are labeled. For example,
USE "shared/finance.gs" AS finance appears as finance and opens its exact
line in Whole model. A source change invalidates an outstanding source jump.
On desktop, Choose workspace reads the selected local package catalog without activating it. Workspace packages shows activation state, recovery needs, and a filterable list of installed packages. Select a package to see exports, actions, and declared capabilities. Copy import copies the same declaration used by Package Center; Inspect runtime fit requests its existing verified artifact/export explanation. Neither action installs a package or edits the model. A matching package reference is labeled In selected catalog; that label does not imply runtime activation. Other imports are labeled Not in selected catalog only when a catalog has actually been read. Inspect package beside a matching import reveals its installed package and moves keyboard focus to the details. If several slots contain the same package reference, it shows the matching choices with slot labels instead of choosing one.
Package Center hides the previous workspace's catalog while reading a selection. If reading fails, Retry catalog retries that directory. Acquisition stays disabled until its catalog is available; late catalog, update-check, and runtime handoff responses cannot replace a newer workspace selection. Starting an install or lifecycle action immediately locks workspace changes and repeat submissions while its native job ID is pending. Status failures retry without repeating the action. Cancellation stays visible as Cancelling… while cancellation is pending; transaction commit phases finish without cancellation.
Manage packages opens the existing Package Center installation, activation, configuration, upgrade, and recovery workflows. Its selected workspace is shared with Code, and the catalog refreshes when it closes. From a dependency report, Review package activation also carries the exact requested import and filters the catalog. The review distinguishes an exact catalog match from a different version and provides Return to Code dependencies. Returning from package or runtime settings marks retained resolver results stale and disables their actions; Check model dependencies requests a fresh result explicitly. Pending results from the earlier environment cannot replace the new check. Refresh catalog also rereads explicitly. Re-selecting the current workspace also retries its catalog; cancelling the folder picker preserves any catalog error. Catalog and inspection failures remain retryable. Leaving Dependencies releases its view; late responses cannot populate a different workspace or package. Browser sessions retain authored import navigation and explain that local package operations require desktop. Package inspection does not poll or automatically check remote registries. Package selection and its filter survive Code-area navigation in the current model session. Selection is bound to the chosen workspace, so an identical slot in another workspace is not automatically selected. Catalogs are reread on return; inspection reports and clipboard results are not retained. Reload or a model/account/partition change starts a new tool context.
The Working tabs strip spans those areas. Opening a model section, surface file, or tool keeps it available in the strip; Back in Code and Forward in Code revisit recent resources. For example, follow a JSX model binding to its definition, then go Back to continue the surface draft. The model and surface editors restore their retained cursor, scroll, and Undo state. Both editor groups also retain deliberate source jumps: model definitions, search results, problems, recorded-execution locations, and committed editor navigation. Surface files record Go to Line and preview element or diagnostic jumps into JSX. Each visit remembers its editor group; Back can reopen a closed split at its source location without moving the cursor in the other group. For example, choose Forecast in the outline, follow another definition, then use Back to return to Forecast. Go to Line participates in the same history.
Code source editors derive their syntax colors from the shared theme with stronger contrast for faint comments, strings, numbers, line numbers, and bracket pairs. Model source and JSX/TOML/JSON authoring use the same palette. Theme changes retain the editor session; returning to Data restores its existing appearance. Large model source keeps the same scoped files and complete navigation while the workspace prepares those files with one framing scan. Dense opening is still a measured response exception; source editing and diagnostics remain available as before.
Narrow source panes keep value inspection, Problems, recorded execution, and Go to Line available as compact controls. Problems shows its total count; its accessible label and tooltip retain the error/warning breakdown. Larger editor groups display full labels independently of a narrower split beside them.
Code checks the current model draft after a short typing pause, without applying
it. Syntax errors and provably undefined named references appear as underlines
and clickable Problems, with spelling suggestions when there is one close
match. For example, Forecast = Pipline * Conversion points at Pipline when
the declared input is Pipeline. Forward declarations and intentionally empty
cell addresses are allowed. Results belong to the exact source revision and
are removed as soon as it changes. For an unambiguous spelling correction,
place the cursor on the underline and use Quick Fix (Cmd+. / Ctrl+.).
The preview shows the old and replacement text; Apply fix makes one undoable
edit. Changes to the draft or binding inventory invalidate the preview. The
same action works on misspelled literal JSX model bindings. Ambiguous names
remain diagnostics for manual correction.
Code also checks reads inside sequential LET bindings and LAMBDA bodies,
including supported lookup and higher-order calls. Local names become visible
after their initializer and stay inside their scope. Malformed binding lists
and non-name binding targets receive located errors. A named-function argument
count or type error does not hide independent missing-name errors elsewhere in
the draft. Compiler type failures retain their existing severity: strict-mode
errors remain errors and loose-coercion warnings remain warnings. Syntax failures
still limit further analysis; unsupported or dynamic scopes are not guessed.
Autocomplete prefers the innermost supported local scope. Renaming across local
bindings remains conservative until capture can be proven safe.
JSX source also checks literal model bindings, such as
model.useValue("Forecats"), against the compiler's declaration inventory and
known resident symbols. Missing bindings have underlines and a clickable list
below the editor. This covers reads, writes, aliases of Grid's API methods,
and literal members of useValues arrays. A locally shadowed model or hook
is not treated as Grid's API. Dynamic binding expressions, external references,
and scopes whose declarations cannot be established remain runtime checks;
the editor explicitly reports limited or unavailable checking rather than
claiming the source is clean. These checks neither apply drafts nor change
formula evaluation.
Use Control+Minus / Control+Shift+Minus on macOS, or Alt+Left / Alt+Right on other platforms, for Back / Forward anywhere in Code. Mac Option+Arrow retains normal word movement. Typing and ordinary cursor movement do not add visits. Back and Forward preserve the forward branch; taking another source jump starts a new one.
Source locations follow an unchanged line after surrounding lines are inserted or removed. Repeated text is disambiguated by adjacent lines. An edited, ambiguous, or removed target is reported instead of guessed. Anchors with more than 4,096 characters across their three lines fall back to resource navigation. Surface locations are checked against the current shared draft when one exists. A pending jump is checked again against the mounted editor before moving its cursor. History never applies a draft or changes the model.
Closing a tab closes its view; it does not discard source edits or a surface draft. Reopening the resource restores that editor session. Draft surface files show a dot, and Apply or Revert clears it. Left/Right arrows and Home/End move between focused tabs; Delete closes a focused tab, and middle-click also closes one. At least one working tab stays open. Tabs and the last 80 navigation visits survive work-area and layer changes for the active model/partition. Changing models, partitions, or reloading starts a new session. A removed or renamed resource cannot be opened through an obsolete tab; use the explorer to choose its current destination.
Split editor opens the current model section or surface file in a second editor group. Select an open resource in that group’s header, or focus the group and choose a working tab. Both groups share source text, surface drafts, and Undo; each keeps its own cursor and scroll position. Applying or reverting a surface draft updates both groups. Closing the second group retains its editor sessions and split width for the current model/partition.
Drag the divider to resize. With the divider focused, Left/Right adjusts the width; on narrow windows the groups stack and Up/Down adjusts their height. Home/End selects the minimum/maximum share; double-click restores equal space. Explorers initially collapse when splitting, and can be reopened from either pane. Narrow panes use an overlay explorer and stack the surface editor above its preview. Opening a surface binding focuses its definition in the first model editor while the second surface editor remains available.
The source workspace uses the locally bundled Monaco editor in both browser and desktop-hosted sessions. It includes Grid syntax highlighting, the existing function completion and signature help, folding, multiple cursors, Find/Replace, Go to Line, and editor commands. The editor and its workers do not require a public CDN. Source changes follow the existing live update and Save operations, including their conflict checks. Reference suggestions in Code use accepted model names and explicitly qualified cell references, independently of Data's selected sheet. Bare named bindings retain their compiler spelling. Compiler-backed suggestions also include declarations in the current unsaved draft, local namespace names, and function parameters. They share the draft check and discard results after an edit. These suggestions are available at compiler-recognized named reads; comments, strings, incomplete syntax, opaque binders, and unsupported qualifiers retain the existing catalog suggestions without claiming complete scope analysis. This is contextual completion, not AI predictive text.
The explorer separates Model logic from each worksheet or surface namespace. Choose Review, for example, to work with its document configuration and data without scrolling past dashboard source. These are editable sections of one model, not independent files or duplicate calculations. Qualified names stay visible. Whole model shows the complete authored source. Source views retain their own cursor, scroll, and Undo history within the current model session. View whole model carries the current scoped line and column into the complete source. Back returns to the scoped position; Forward restores the whole-model position. The same contextual transition is available when an edit crosses a section boundary and the editor offers Open Whole model. A surface section also offers Open surface builder. For source with nested control flow or ambiguous lexical boundaries, the editor uses Whole model so a body cannot become detached from its declaration. A replacement spanning separated source regions requires Whole model; the editor keeps the existing text and offers that route rather than moving hidden source.
Grid's embedded languages stay readable in source. Generated JSON data uses
<json> blocks with normal indentation, and TOML receives a two-space margin
when that preserves its parsed value. Whitespace-sensitive payloads retain
their contents. Legacy string-encoded surface data remains supported. The
language style guide
shows the preferred authored form.
The Model outline lists recognized source assignments. Filter by name and select an entry to move to its source. This is a navigation aid using Grid's existing statement index; it is not a complete semantic symbol table or a refactoring engine. Large outlines display a bounded set of matches and can be filtered further.
Search model searches the complete authored source, including comments, embedded content, and sections outside the current editor. Use Command/Ctrl+Shift+F to open it. Results identify their source section; selecting a match opens that section and selects the matching text. A match spanning section boundaries, or source with unusual line endings that cannot be mapped safely, opens Whole model. Match case narrows literal text search; this does not interpret regular expressions or change source. Large result sets are capped at 200 and identified as partial. The query and case setting survive layer switches within this model session. Search uses the current draft and does not require compiler navigation support.
Use Navigate for compiler-backed Go to definition (F12), Find references (Shift+F12), and Rename symbol (F2). Definition and reference locations come from the compiler’s parsed source, including direct model bindings and local function calls. Reference headings use the authored filename; internal account and model ownership keys stay out of the displayed path. Reference results identify incomplete coverage when a construct cannot yet be traced. The outline remains a separate, lightweight way to move through a draft.
Rename applies a complete set of source edits as one Undo step and then uses the existing live source update and Save flow. The compiler checks the new name, collisions, and binding relationships before returning edits. The editor rejects results if the source changed while the request was running. Rename currently supports a conservative subset of ordinary calculated named bindings, including worksheet-qualified names. It preserves the namespace and changes only the name and its compiler-proven references. A rename that would capture another binding is refused. It is unavailable for cells, functions, persistent input/state bindings, imported or dynamic bindings, and source whose references cannot be established completely. It does not migrate references from other models or external consumers. The runtime also withholds rename when the model has stored input overrides or Notebook-owned formulas. A name appearing in opaque text is withheld because that text may encode a surface binding. These restrictions protect existing state and bindings until their migration is supported; navigation remains available. The runtime checks current state when preparing edits, and the existing source-save conflict rules still govern their later publication.
Compiler actions analyze the complete authored model while you work in a
surface section. Definitions and references that fit in that section stay there;
a complete result spanning other sections opens Whole model at the originating
symbol and repeats the requested action. Rename stays in the section only when
the compiler provides a complete edit set within it. External and explicit
Default qualifiers still require additional binding information. Surface slots
such as type, config, data, and source cannot be renamed. Models containing
executable surface source, nonempty surface configuration/data, or other opaque
payloads may encode bindings that a source-only edit cannot migrate; rename is
withheld there. No source is changed when a restriction is reported.
Located problems and recorded execution reveal their matching section or the
complete source.
A failed navigation action offers Try again at its original source position. Changing the source, model, partition, or section invalidates that retry. Rename shows progress and keeps a compiler rejection visible; a later successful action clears the previous message.
After explicit compiler navigation, hovering a known named binding can show its current
model value. These tooltips use the compiler's cached binding identity and require
the analyzed source to match the accepted model. Pending, stale, and unknown
values are withheld. Worksheet cell values are also withheld until their cached
snapshots can prove which source revision produced them. Hover does not analyze source or request values, and it does
not inherit the last selected Data sheet. Function documentation in Code appears
for calls such as PRICE(...); a binding named Price does not inherit those
function descriptions. Data retains its existing tooltip behavior.
These actions require a runtime that supports source intelligence. An older runtime reports that the feature is unavailable; ordinary editing continues. Analysis runs when requested, with one result cached for the current editor version and a 1 MiB source limit. Leaving Code or changing source cancels pending requests. The retained-authority lifecycle profile currently refuses this service until its dedicated read contract is implemented.
Problems shows parser errors, structured compiler warnings/errors, and source-update failures. Select a located problem to reveal it in the editor. Markers use the source that produced the diagnostic; admitted compiler spans are withheld while the draft differs or the accepted source is unknown. Messages without locations remain visible without inventing a source target. Long lists scroll continuously. With a problem action focused, Arrow Up/Down move between available actions and Home/End jump to the first/last actionable problem. Tab visits each problem and its fix-review actions without skipping entries as you scroll. Long explanations wrap to the pane width. Browser Find searches the visible portion of a long list; editor markers still represent every current diagnostic.
Inspect value opens live model investigation directly from Grid source. Use an inspection button beside a definition, the editor's Inspect definition value context command, or Inspect value in the status bar while the cursor is inside a definition. This works without creating a custom surface or writing JSX. The selected value remains available in the Value details tab across source-section and work-area visits within the current model session.
For example, in a model containing Pipeline = 240000, Conversion = 0.75, and
Forecast = Pipeline * Conversion, inspect Forecast, choose Why this value?,
and follow Conversion back to its authored definition. The inspector shows the
live value, type, status, accepted expression, and available runtime errors.
Provenance is explicitly requested and bounded to four levels and 48 nodes.
Load value or Refresh value requests only the selected scalar; ranges
retain their bounded visible-page loading. Source edits do not disguise accepted
values as draft results. Unaccepted source is labeled, and stale provenance
requires an explicit refresh. Escape closes inspection and returns to the editor.
Choose Inspect value beside a dependency to investigate it in the same panel. The trail and back arrow return to an earlier value; Go to definition opens the currently inspected value's source. For example, follow Forecast → Conversion, inspect the assumption, then return to Forecast. Returning reuses captured evidence only when its source, model revision, and live snapshot still match. Otherwise, refresh explicitly. Only the selected value has a live subscription; following a dependency neither loads its missing value nor requests provenance automatically. The trail retains at most 12 steps, keeps its original value, and labels omitted middle steps. Closing inspection or changing models ends the investigation.
Model inspection preserves explicit sheet coordinates and distinguishes global names from Default-qualified names. A runtime resolution failure remains visible; missing values and unsupported host results are not synthesized by the editor. Provenance links locate definitions in the current authored source, including across source sections. If a definition no longer exists, Code reports that instead of jumping to a different symbol.
Open Recorded execution to inspect available execution traces alongside source. Set breakpoints with the gutter or F9; F5 moves to the next recorded breakpoint, F10 advances one operation, and F11 advances one calculation stratum. This does not pause the live runtime. Values are the current resident values after the run, not historical snapshots. Default-sheet cell assignments and ranges can bind to trace operations. Named definitions and sheet-qualified scalar cells bind when the accepted runtime provides their exact cell IDs; missing or ambiguous mappings remain pending. Other-sheet ranges still require supported runtime mappings. Deleted or ambiguous breakpoint targets are withheld rather than attached to an unrelated line. Code only admits a trace for its matching model, folder partition, and accepted source. Changing source or the runtime symbol inventory withholds old frames until their mapping is refreshed. You can browse other source files while paused without being pulled back to the current frame.
The outline and details panel can be resized with a pointer or their focused separator's arrow keys. Their state and breakpoint choices survive layer and tool switches for the active model. Editor cursor, scroll, and Undo history also survive layer changes. Opening another model or partition releases this session; these preferences and breakpoints are not durable across reloads.
| Shortcut | Action |
|---|---|
| Command/Ctrl + S | Save the model |
| Command/Ctrl + F | Find in source |
| Command/Ctrl + Shift + F | Search the complete model |
| Ctrl + G | Go to line |
| F1 | Editor commands |
| F12 | Go to definition |
| Shift + F12 | Find references |
| F2 | Rename a supported source symbol |
| Command/Ctrl + B | Show or hide the source outline |
| Command/Ctrl + Shift + O | Focus outline search |
| Command + Shift + M (macOS), Ctrl + Shift + M (Windows/Linux) | Show or hide Problems |
| Control + Shift + M (macOS), Ctrl + M (Windows/Linux) | Toggle whether Tab leaves the editor or inserts indentation |
Connections, extensions, and surface tools retain their existing edition and permission checks. There is no additional evaluator, simulated terminal, or second set of model calculations in Code.
Surface builder
The Surfaces explorer lists the model's views and their files. Choose the
visual editor or edit config.toml, a supported source.tsx, or the surface's
data payload. Apply sends the file through the model's existing write path;
Revert restores the current model value. Unapplied drafts survive file,
surface, work-area, and layer switches within the active model/partition.
They are temporary: changing models or reloading ends this authoring session.
Each file retains its cursor, scroll position, and Undo history during that
session. Hiding Preview remains your choice as you move between files.
If a slot changes while you have a draft, choose the model value or explicitly
keep your draft before applying it. These choices wait for any pending write to
finish, and Apply stays disabled while its submitted value is awaiting the model.
The adjacent preview offers Working draft and Applied model. Working draft renders your local configuration, JSX, and data edits immediately through the same surface renderer used in App. This does not apply those edits to the model. Applied model lets you compare the accepted surface without discarding your draft. Fit, tablet, and phone viewport options support layout inspection; the preview and editor inherit Grid's shared theme.
JSX previews allow local controls such as tabs and disclosure buttons while model writes remain disabled. Enable interactions explicitly allows actions against the live model; it is unavailable while previewing an unapplied draft or inspecting an element. Changing surfaces or leaving the builder revokes the preview's action callbacks. Native surface previews remain inert until interactions are enabled. Open in App uses the applied surface with its normal controls.
For JSX surfaces, Inspect element reveals a rendered HTML element's source
line without triggering its action. Enter or Space inspects a focused preview
control. Grid's ui.* primitives link to their authored JSX call, including their
empty states. Source links below the preview controls also offer enclosing
function/class definitions from the JSX editor's TypeScript worker. These are
source definitions, not a reconstructed runtime component tree. The renderer
supplies line-only positions; ambiguous definitions on the same line are omitted,
and shared primitive aliases use their canonical component name. Editing the
source hides the old selection's links. Elements inside other compiled libraries
may lead to the nearest mapped HTML ancestor. JSX errors remain visible beside a
dimmed, inert snapshot of the
last successful preview. Recovery does not execute the old component again;
canvas pixels, media playback, and other imperative state are not retained by
this DOM snapshot. Local form values and successful DOM updates are retained.
Further incomplete edits keep the same passive image while errors change;
Updating preview · last successful render identifies a pending replacement.
Repairing the source restores the live preview.
Syntax errors with a validated parser position offer Go to line…, which opens
source.tsx at that position even if another surface file is selected. Runtime
exceptions in module execution, component rendering, and preview controls use
the exact compilation's source map when their stack identifies that preview.
Unhandled promise rejections with the same identity are reported too. These
errors also offer Go to line…; unknown stack formats and locations that only
identify generated helpers offer Open source. No coordinates are inferred
from an error's message. Errors belong to the exact source that produced them;
an applied-source diagnostic cannot navigate into a different working draft.
Delayed render callbacks and error events from retired drafts are ignored.
Runtime source links also work in the macOS desktop WebKit preview, including
click-handler errors and asynchronous failures with an identifiable preview stack.
The JSX editor supplies syntax diagnostics, the injected React/model API, and completion snippets for Grid's UI components. Quoted model bindings offer names from the current symbol snapshots. These suggestions are advisory; they are not compiler proof of a binding or permission to write it. The existing custom-UI trust policy still applies: this preview is not a security sandbox. Try the surface studio example to edit a revenue view, inspect its source, and compare a draft with the model.
Select a model binding to inspect its live value, type, resolution status, reported dimension, and authored expression. Why this value? requests runtime provenance on demand, bounded to four levels and 48 nodes. The trace labels truncation and captures a point in time; if the live value or model revision changes, Refresh provenance replaces the stale trace. There is no polling. Dependency names and Go to definition open their authored source sections. Inspect value follows a dependency within the panel, with the same bounded investigation trail and freshness checks as model definition inspection. The arrow beside each scalar binding remains a direct source shortcut. Escape closes the inspector and restores a useful editing focus. The selected binding survives work-area changes within the model session; returning requires an explicit new provenance request. These source destinations are lexical locations, distinct from compiler-backed definition/refactoring actions. Data files show readable JSON from the current acknowledged model value; a document edit can update that live value while its authored initial value remains unchanged in model source.
Range bindings remain single authored resources in the explorer. Selecting one opens a live table, paged by 12 rows and eight columns. Load visible cells fetches missing values for that page. Select a cell to inspect its value, type, source, and runtime provenance; Back to range restores the page and focused cell. Arrow keys navigate cells, Home/End move within a row, and Escape closes the inspector. Range paging and cell selection last while this inspector is mounted; reopening the work area starts at the range's first page. Cross-sheet ranges are not supported by this inspector. These are read-only investigations; loading or inspecting cells does not apply the surface draft.
Opening the builder does not write the model. An unchanged visual configuration leaves its authored TOML, YAML, or JSON untouched. Config and JSX file edits replace only the target literal, preserving its declaration, surrounding comments, and other source. Intentional comment-only Code edits still apply. A visual control that regenerates a changed payload may replace comments inside that payload; this is not a general comment-preserving TOML editor.
Document editing
Documents use the same editor in App, Data, and the surface builder. Hover over or focus a block to reveal its grip. Drag that grip to a visible insertion line, or click it for block actions. Right-click opens the block menu unless text is selected or a link is targeted; those retain their native clipboard/link menu. Move, duplicate, delete, insert text, and text/heading conversion are available there; Undo restores structural edits. Inside a list, actions target the selected item and preserve its children and checkbox state. Move and drag reorder siblings within the same container. The menu names the current target and offers an explicit Whole task list, Whole numbered list, or other container action when you want to operate on that larger block. Text in callouts, toggles, and quotes has its own block controls. Tables and live embeds retain their structure.
Keyboard users can open block actions with Shift+F10 or the context-menu key, and move a block with Alt+Shift+Up/Down. On touch screens, the block menu provides movement without dragging.
The formatting toolbar follows your text selection and offers text styles, bold,
italic, links, Undo, and Redo. More formatting includes underline,
strikethrough, inline code, highlighting, alignment, and clearing text formatting.
Command/Ctrl+K edits links. List controls indent and outdent the selected item
with its nested content; converting selected text into a list preserves that text.
Insert opens blocks and live values at the cursor; / remains available in
the page. Selecting a table exposes row/column operations and cell merge/split
controls. Selecting an image offers URL and description editing, width adjustment with its natural aspect ratio, reset, or removal.
Selecting an existing link exposes its destination and edit/remove actions.
Link and image dialogs keep their original target. If the document changes while
a dialog is open, cancel and reopen it before applying changes. Removing editing
permission closes the dialog.
The main tools and table controls remain visible while scrolling a long page.
Undo separates explicit formatting, link/image insertion, and paste from
surrounding typing. Converting selected list items keeps their nested content
and the numbering of the remaining list. Pasting a table into existing table
cells fills those cells through the editor's table-paste behavior.
Pasted or dropped images retain their insertion location while files load;
ordinary rich-text paste continues through the editor's existing rules. Markdown
paste preserves nested lists, numbering, task state, links, and tables. Ambiguous
tables retain their source text instead of dropping excess cells.
Pending imports show progress and can be canceled. An import can finish after
you leave the layer, through the same document save lane. A replaced document
cancels stale insertion locations and explains how to retry. Editing the selected
replacement text also cancels its pending image import, protecting the newer text.
Images remain
embedded and limited to 4 MiB each, with up to eight pending in a document.
Import Word adds a .docx file to the end of an editable rich document.
For example, open your report, choose Import Word, and select a Word memo;
its content becomes editable alongside the report's existing text and live
values. Undo removes the import in one step. Imports use the same guarded save
and recovery flow as other edits. Read-only and bound markdown views do not
offer Word import.
Word import retains supported named styles, local text formatting, paragraph spacing and alignment, heading levels 1–6, numbered and nested lists, explicit page breaks, links, and PNG/JPEG/GIF/WebP images with their dimensions. Tables retain unequal widths, merged cells, and consecutive repeating header rows. Empty documents adopt Letter/A4 paper, orientation, individual margins, simple headers and footers, and page numbers. Appending keeps the destination page setup and renames conflicting styles so existing paragraphs do not change. Review Import notes, which identify affected paragraphs, tables, styles, and page setup. Internal links retain text but lose their destinations. External images are not fetched. Unsupported images and images larger than 4 MiB are omitted with a note.
Conversion happens on your device. The file limit is 20 MiB, with at most
2,000 archive parts and 64 MiB of expanded content. Each XML part is limited
to 16 MiB, with bounded nesting and no document type or entity declarations.
Imports stop after 30 seconds and can be canceled. Leaving the document cancels
an unfinished Word import. If the document changes while conversion is running,
choose the file again to import into the current version. Older .doc files
must first be saved as .docx in Word.
Styles defines Body, Title, Subtitle, Heading 1–6, Caption, and Quote for this document, plus imported named styles. Choose Roboto, Times New Roman, Courier New, Arial, Calibri, Cambria, Aptos, Georgia, or Verdana, size, color, line spacing, paragraph spacing, indentation, alignment, and keep-with-next. Update named style changes paragraphs using that style; local paragraph and text formatting takes precedence. Apply style to selection applies the chosen style without changing its definition. Formatting and page settings travel in the document's saved content and existing recovery drafts, and support Undo. Browser spelling assistance is enabled where the device provides it.
Find (Command/Ctrl+F while writing) searches literal text, including text split across formatting. Replace one occurrence or all matches in one Undo step. Search does not cross paragraphs or live values. Queries are limited to 200 characters and results to 1,000; narrow the query before replacing a larger result. Outline navigates Heading 1–6 and shows word and character counts for authored text. Zoom is a local viewing preference and does not alter output.
Page setup saves Letter/A4 paper, portrait/landscape orientation, individual 36–108 pt margins, single-line header/footer text (80 characters each), and page numbers. Insert explicit page breaks at the cursor. The editor remains a continuous writing view; Publish → Preview PDF shows the generated pages. The preview's Save preview PDF saves those exact bytes.
Publish saves an editable Word file or PDF with current writing, styles, lists, tables, images, and page settings. Page setup controls whether to include the surface title; imported documents omit it initially to avoid duplicate titles on repeated exports. Desktop uses a native Save dialog; browser versions download the file. Canceling leaves the document unchanged and failures are reported. Files are limited to 64 MiB. Exports include unsaved edits. The selected operation freezes the resident displayed values before loading output libraries; later edits and model updates do not change that copy. Pending, stale, missing, or failed live values prevent export and explain which reference needs attention. Exported values are static text/tables and do not recalculate. Resolve incoming document conflicts and pending image imports before publishing.
Word uses fonts installed by its recipient, which can change its pagination. PDF uses bundled Roboto and standard Times/Courier fonts; other families use Roboto with an export note. Review the preview, especially for special characters. Authored table widths are retained and proportionally reduced to fit the page; unspecified widths share remaining space. Merged cells and repeating headers are retained. Collapsible sections expand and callouts become quotations, with export notes. Embedded GIF/WebP images become static PNGs; external images are refused without fetching them. Export supports at most 128 embedded images, each at most 32 megapixels, and scales images to fit the page. A damaged image fails clearly. Output conversion runs in a disposable local worker, stops after 60 seconds, and can be canceled; closing Publish cancels an unfinished operation. Opening an ordinary document does not start import or export workers or load their conversion libraries.
Round trips preserve the supported vocabulary, without promising identical Word pagination. Custom numbering patterns become standard labels, section layouts use one final page setup, and floating images become inline blocks. Footnotes receive reference placeholders and notes; their bodies are not imported. Dynamic fields retain displayed text, except supported page numbers. Footnote authoring and section-specific layout remain outside these writing tools.
Review adds comments to selected written text. Choose a reviewer name, enter an observation, and choose Post comment. Replies, dates, and resolution are saved through the normal document save and recovery flow. Show comment text returns to its anchor. If that text is removed, the discussion remains available and says Original text removed. Resolved threads can be shown and reopened. Reader mode exposes discussion without editing controls. Reviewer names are user-chosen attribution labels, not verified identities; review actions do not send messages or start a collaboration service.
Track text changes records typing, deletion, and replacement within one paragraph or heading, including paragraphs in tables and lists. Insertions are underlined and deletions struck through. Adjacent typing is grouped into one suggestion. Accept change keeps proposed text; Reject change restores original wording. Bulk accept/reject and individual decisions support Undo. Tracking starts off when reopening; pending suggestions remain visible. Turn it off and resolve pending changes before formatting or structural editing. Block moves, paragraph splits/joins, formatting, embedded objects, and replacements across paragraphs are not tracked. Unsupported edits are refused with an explanation. Another reviewer's pending text and suggested deletions are protected until accepted or rejected.
Word exchange retains supported text revisions, anchored comments, replies, authors, dates, and resolved status. Repeated imports receive new review IDs. Some readers hide comments whose original text was removed. Formatting revisions, move history, and structural revisions are not supported; import notes identify simplifications. Nested or non-text inline revisions are refused. PDF includes suggested insertions and omits suggested deletions and comments, with an export note; this never accepts changes in the editable document. Ejection refuses review-bearing documents rather than discarding discussion.
Review data is limited to 300 comment threads, 1,000 replies, 2,000 pending changes, 4,000 characters per message, and 1 MiB of metadata. Resolve changes or split a larger review into separate documents when these limits are reached.
Live values can be changed in place with their pencil control or F2; live ranges offer Change range. Type an exact reference, or use the arrow keys to choose a suggestion. An unselected suggestion does not replace what you typed. Ranges must belong to one worksheet and contain at most 400 cells. Pending, out-of-date, missing, and failed values retain distinct status labels. Inserting and configuring a reference is one Undo action; changing an existing reference is separate from adjacent typing. Opening or cancelling a new reference leaves the document and its Undo/Redo history untouched. If the document changes while the picker is open, cancel and choose the insertion point again.
Returning to an unchanged document restores its text selection and scroll position without moving focus into the page. These positions belong to the model, partition, and surface and are retained for up to 32 recent documents in the current application session, within a bounded source budget. A changed document invalidates its old position.
Document edits show saving and failure feedback. Leaving a layer flushes pending edits; model and partition navigation starts a flush before changing the active model. Writes to each document stay ordered across layer changes and check the accepted model revision before replacing its saved content. Another author's unseen change cannot be overwritten by a stale editor. A confirmed document save remains successful if refreshing an embedded live value fails.
Editable documents keep a local recovery copy when saves are pending, failing, or paused for a conflict. Reopening offers the unsaved version for review before writing it to the model. Multiple drafts remain separate choices; unsupported drafts can be downloaded without passing through the editor. Download copy saves the rich document JSON, including its embedded images and model references. It is a recovery artifact, not a standalone rendered document or a snapshot of the referenced model values.
Recovery belongs to the local profile, server, account, model, partition, and surface. Browsers use local browser storage; desktop uses its application profile's recovery journal so a changing internal server address does not strand unsaved documents after restart. Web and remote servers remain separate. Public unclaimed instances share their profile's recovery space. Read-only views do not read or consume author drafts. Storage denial or capacity failures show a warning with a download action. Recovery has a shared limit of 32 drafts and 16 Mi UTF-16 characters; it refuses additional storage rather than evicting unsaved work. A browser crash before its pending storage transaction completes, an unfinished image read, cleared browser data, or a changed browser server address can prevent recovery. This does not provide offline model execution, synchronized history, or a cross-device backup.
Incoming changes wait while the document or its editing controls have focus. If you have unsaved edits, saving pauses and offers Use latest or Keep my edits, with a downloadable copy available before either choice. That unresolved choice survives a layer visit and can be recovered after reload. Adopting the latest version starts a new Undo history; later typing has normal Undo. Revision checks and explicit version choices do not merge simultaneous text edits.
Malformed, unsupported, or unavailable saved data cannot become an editable blank page. Live values continue to update after initial hydration. Document values use readable number grouping and declared currency codes; an unspecified currency does not invent a currency symbol. Eject to code explains and refuses content the current renderer cannot faithfully preserve, leaving the document untouched.
Data
Data places the existing workbench tools inside the continuous frame. Choosing another layer does not deliberately replace its selected Ops view, active workbook tab, or pane preferences. Returning to Data restores that working context. Actions that explicitly navigate to a model value, create a surface, or open a model can still select the corresponding destination through their existing paths.
The frame's layer navigation is separate from Data's views. Model Flow, Inputs / Outputs, Replay, and the other specialized workbench views continue to belong to Data.
Data's clipboard commands belong to its visible, focused grid. Home, Help, advanced screens, specialist workspaces, and embedded surfaces keep their own clipboard behavior. Pasting Grid content into an ordinary text field stays in that field. Paste Special and dropped text files retain the destination chosen when you started the action, even if you select another cell while the clipboard or file is being read.
A pending paste is cancelled if you leave its Data context before reading or parsing finishes. For example, start a large paste, switch to Code while it is being prepared, then return: the earlier paste does not resume into your new selection. Focusing a private scenario or another pane also cancels preparation. A save already started remains attached to its original model and partition; its completion cannot repaint a different model. A cut from another account, model, or partition is treated as copied content when pasted, so it cannot clear cells in the previous workspace. Rich Grid paste that changes only formatting now has a Data Undo/Redo entry. That entry remains available when you leave and return to the same model; a failed formatting save removes the entry.
Grid context menus remain open when a separate source editor scrolls. Scrolling the grid or page, or resizing the window, dismisses the menu.
App
App presents the model's existing views with controls for Views and Context. A packaged model UI keeps its existing bridge to Grid. A workbook surface keeps its existing renderer, bindings, and operations. The App layer does not manufacture a new dashboard from the source.
In App → Views, Customize, or Code → Surfaces → App settings, configure the model's navigation labels, order, groups, descriptions, opening view, and canvas width. Reading suits a page, Wide gives a notebook room, and Full lets an application use its canvas; Auto chooses by surface type. These settings live with model metadata and preserve the underlying namespace used by links and formulas. New views appear automatically by default. Customize can instead require deliberate inclusion, and individual surfaces can be hidden from navigation. Hidden surfaces remain addressable by links and available in Data and Code. A configured opening surface must remain visible. Renaming or deleting a surface updates its navigation entry. Settings drafts survive layer visits; observed changes from elsewhere require reviewing the saved settings before another save.
An existing App Home remains the preferred view when automatic opening selects App. When App is explicitly chosen without a configured home, Grid can use the currently selected surface, then the first available surface. A model without views offers a route to the surface builder.
Switching between layers retains the App surface and page route. Moving among App views uses browser history while preserving Data's selected workbook tab. The model's published UI and its App Home configuration remain separate from your personal starting-layer preference.
Context → Edit source opens the current surface's authored configuration in Code. Open surface builder opens its visual editor and files. Clicking a live value in a workbook surface opens its current value and status, an explicit Explain this value action, Show in Data, and Go to definition for that value. The Data action selects the cell or named value, including names on another worksheet, after Data has mounted. Unqualified App references address the Default worksheet regardless of the previously active Data tab. Returning to App restores the originating view and its selected-value context. These source hops offer Return to in Code.
Custom views can select a value in the same Context panel. Component JSX uses
model.setContext?.({ symbol: "Forecast", title: "Revenue outlook" });
packaged apps use await grid.setContext(...) through their existing connector.
Pass null to clear the selection. This contribution contains a model symbol,
an optional title, and an optional description. Grid reads the actual value and
provides the explanation and navigation actions. Contributions cannot supply
claimed values, executable actions, or replacement host UI. Packaged apps need
model.read. The selection belongs to the current model, view, and route;
callbacks from a departed view cannot replace it.
The left Views panel retracts after navigation and includes search for longer lists. Its filter survives a layer visit. Arrow keys move through matches; Escape clears a search before closing the panel. Escape also dismisses an open panel from the canvas when the view itself has not handled the key. The right Context panel retains its open/closed and expanded state per view and internal page (up to 80 in the active model and partition). Returning restores it without moving focus. It expands for more room, with routes to inspect the model in Data or edit the current view in Code. Stale or unresolved values are identified rather than presented as current. Layout tiles keep live value selection in App; Arrange layout exposes their existing editing tools. Design app and Edit chart similarly open the existing built-in editors, with Done arranging returning to use. Notebook starts in its reading presentation; Edit notebook exposes narrative, block and execution controls without switching layers. Documents retain their editing controls.
The Context panel identifies Selected object or About this view. Charts and Visuals offer explicit inspection and their own editing commands; Go to definition opens their configuration, while native content objects open their data. Complex models use the whole-source editor at the matching definition. Model and archive details sit in a collapsed Model details disclosure.
App's Context distinguishes the live model from its saved archive. When source is current but the archive is older, it shows Live and Archive: Update available. Use Save model in App’s header to update the archive. It drains pending native surface content and chart configuration edits, waits for acknowledged writes, and uses the same archive checkpoint as Data. Conflicting or failed surface edits stop the checkpoint and identify the affected view; correct them in that view before retrying. While saving, duplicate requests are disabled; the existing save notification confirms completion. App settings still require their own Save App settings action. An unapplied source draft still shows Unsaved source changes; save failures and updates in progress retain their own status. This is separate from a document's confirmation that its edits were saved to the live model.
The bottom question bar opens compact assistance within App. Expand it to continue the same conversation in Chat or review a proposed source change. Its unfinished question and panel state survive a layer round trip. Requests capture the originating view, route, and selected value, independently of the last Data selection. Chat's context references open those model destinations; Return to restores the originating App route and selection. Opening saved history does not replace the App location you just came from; individual message references still open their own captured locations. Chat opened without an App origin can return to the latest message's App reference. In smaller windows, Context and assistance share vertical space and scroll independently; the answer does not cover the context actions.
Compact assistance shows the current exchange and its predecessor, including your questions. A pending follow-up keeps the preceding answer available. Open full conversation continues in Chat. Both presentations render answer headings, emphasis, lists, tables, links, and code as readable prose. Generated HTML remains literal text, and generated images are links opened deliberately.
Customize, create, and navigate
Customize shares its draft with Code. Rename destinations directly in the compact navigation list, drag their handles to reorder (or use the up/down buttons), and toggle their visibility. Select a destination to edit its group, description, and opening-view status. Visual width choices show reading, wide, full-width, and automatic presentation without exposing every destination’s settings at once. Preview uses the draft without saving. Return to Customize to save or cancel; content edits remain real edits to their surfaces. Add or create a view offers starting points: Overview creates an App Builder screen, Brief creates a rich Document, and Exploration creates a Notebook. Choose existing model values and inputs; only model inputs are eligible for controls. Add an introduction and edit the labels used in the new surface. Overview also offers number, USD currency, percent, and text formats. Preview starting view renders the native surface using currently loaded snapshots, with controls and links inactive. Return to choices without losing selections, or choose Create view to persist it. Title, bindings, formats, ranges, choices, preview, and outstanding creation remain intact while visiting another layer. Cancel discards the starter; successful creation starts a fresh form next time. This unfinished form is session-local, scoped to the current owner, model and partition. Overview previews follow the current App theme rather than print colors. The preview does not resolve additional model values or write inputs. Overview controls accept decimal assumptions; the App Builder can impose a specific step when needed. Brief and Exploration also accept bounded live ranges. More view types uses the existing surface creator. Creating a surface is immediate and is not undone by cancelling navigation settings. The title becomes its App navigation label. A published custom App Home retains its existing opening precedence.
Document’s Insert menu offers Open view links while hosted in App. App Builder’s Link inspector offers the same destination picker and a button appearance. The searchable picker targets a surface or a named App Builder page in the current model. It loads page metadata only for the selected view. Deleted pages show an explicit recovery route to that view’s home instead of silently opening a different page. Packaged custom apps keep their existing navigation bridge. Existing document and notebook formats remain authoritative; no separate page format is introduced.
Back in App and Forward in App retain up to 80 surface/page visits in the current model session, including the selected value and supported scroll state. A surface choosing its initial page replaces that visit, so Back leaves the first slide instead of becoming stuck there. Copy link to this view includes the selected model value when there is one. Desktop links contain the current local server address; they do not publish the model or grant access, and that address can change after a desktop restart. Find in model searches visible destination labels and accepted model names. Open it from Views or with Command/Control+Shift+K; inspect a found value or go to its definition. It does not resolve every model value to build the search list.
Try the forecast example: Overview, Assumptions, Live forecast, Report, and Presentation share the same Growth, Forecast, and Contribution values.
Refined App authoring
App puts the model’s task first. View actions contains Design view, Edit layout, Edit slides, and Edit notebook; an active editor keeps Done visible. Deck opens for browsing and presenting, with arrangement available on request. Keeping a Chat answer in a deck opens its authoring mode for insertion. Content-owned views keep their introduction beside their title; the navigation description is available in About this view instead of appearing again above the page. Inspecting an object replaces that overview with the object’s own identity and commands. The compact conversation entry groups its question scope with the composer, retaining unfinished questions when you move between views.
New Overview starters size the results row to its content and distinguish the first destination from supporting links. Brief and Exploration starters include continuation links to the destinations chosen during creation. These are ordinary editable surface content, not workflow state or inferred completion.
App uses one view frame. Content-owned headings stay in their surface; Layout can use the host heading. Primary commands stay near the content and secondary commands appear in View actions. Charts and Visuals open as presentations; Edit chart or Edit visualization opens their existing editor, and Done returns to viewing. Visual export review remains in the same menu. Leaving a chart flushes its pending specification edit instead of dropping the final keystroke. Design view and Edit layout enter arrangement; Done returns to use. Document writing, notebook execution, and Deck presentation keep their native tools.
Customize App also authors Next steps for each destination: a label, optional description, surface/page destination, order, and one optional primary step. Preview uses the same settings draft as Code; Save persists it and Cancel discards it. Cancel does not undo ordinary content edits. Existing models have no Next steps until their author adds them. Hidden views remain linkable; a missing destination produces an explicit recovery message. Renaming a surface updates its Next step targets. Removing it preserves references as unavailable rather than silently changing their destination.
App Builder numeric/text controls and notebook numeric/text inputs retain local
text while typing. Enter or blur submits; Escape restores the last accepted
value. Labels, help text, unit labels, bounds, required text, and authored number
formats make assumptions understandable. A percent field displays 6 beside
% for a stored ratio of 0.06; typing 7.5 submits 0.075. Bounds and step
messages use those displayed units. Currency controls accept correctly grouped
numbers, keep incomplete text while typing, and restore the accepted value on
Escape. USD formatting is explicitly selected. Numeric edits preserve existing
currency and unit tags. When the host supplies its input catalog, controls bound
to other values identify them as read only. Older embedding hosts retain their
existing setter contract. Pending writes and
failures appear by the field, and failed text remains editable. Built-in App
actions wait for accepted writes before following success routes. Hosts without
acknowledged writes retain their legacy setter behavior and do not claim Saved.
There is no staged-form transaction or implicit reset of model defaults.
Selecting a native object updates an open context panel without opening it or moving keyboard focus. Inspect opens its context. Documents, notebooks, App Builder components, charts, layout tiles, and Deck slides contribute their own supported commands. Inspect bound value opens the existing value context, including Explain, Show in Data, and Go to definition. Technical model details remain collapsed. Selection identity is scoped to the model, partition, view, and page; packaged applications retain their existing capability bridge.
Notebook blocks support drag reordering, the existing move buttons, and Alt+Shift+Up/Down. Insertions and deletions restore focus to the working block. Undo/Redo covers notebook content changes; text fields retain native text Undo. Document and App Builder operations continue using their own histories. App Builder, Layout, and Notebook reuse the existing ordered document draft writer for navigation flush and retained failed edits. These surface drafts remain session-local; this does not add cross-device synchronization. A conflict preserves the local draft and offers a downloadable copy before explicitly loading the saved version. Viewing a notebook does not normalize or save its content as an editing side effect.
The canonical examples/canonical/app-layer-forecast.grid connects Overview,
Assumptions, ForecastView, Report, and ForecastDeck. In Customize, arrange them
in that order after Overview, name ForecastView Live forecast and ForecastDeck
Presentation, make Overview the opening view, and choose Reading width for
Overview and Wide for Live forecast. Add Set assumptions to Overview,
Review forecast to Assumptions, Prepare report to Live forecast, and
Present to Report. Follow the live Growth input through the forecast,
inspect a value in Data or Code, return to the original App position, and use
Chat's existing Keep in model to append an explanation to Report.
Chat
Chat expands the same agent conversation used by Data's agent rail. Moving between the rail and Chat retains the current conversation and unfinished prompt during the session. The compact App composer edits that same draft, including line breaks, rather than keeping a separate question. Opening Chat from App carries the current view and selected value even before a question is sent; returning restores the view and preserves edits to the question. Drafts containing images open in Chat for review before sending. Conversation storage opens when you first use the composer or open the conversation. Asking from App enters this conversation with the current model context. Requests use the existing provider, generation, explanation, cancellation, and proposal-application paths.
Proposed source changes remain reviewable and use the existing source-change checks before application. The layer selector grants no additional model access or agent capabilities.
Completed assistant answers offer Keep in model in both App assistance and Chat. Edit the excerpt and use Preview formatting to read its structure, then append it to an existing rich Document or Notebook, or create a Document. Explicitly selected references become live embeds; explanation text stays as written. Existing editors own persistence and revision conflicts. Document insertion is one Undo step; Notebook offers Undo inserted answer. Custom-source and read-only destinations do not accept native insertion. Continue in destination lets you inspect a pending save; the answer is only reported saved after the destination acknowledges it. The saved receipt names the destination and offers Return to conversation, preserving the originating App view/page or expanded Chat. Failed saves retain the edited excerpt for revisiting choices; review the destination’s save notice before reinserting. Saving prose never executes it as Grid code. Opening a destination first accepts its saved revision before inserting and saving the answer. The dialog keeps keyboard focus while the destination opens. Try the explanation-to-report walkthrough with the forecasting example.
The composer shows its model, originating view and selected value. An unsent question saves that context alongside its text and attached images in the existing conversation store, including explicit removal of the selected value. App restores it when the composer mounts, without requiring focus. Moving to another view keeps the question’s original scope; Use this view or Use current selection changes it explicitly. Remove the value chip to ask without that selection. Expanded Chat restores the same draft and Return to route after reopening. Old saved conversations without draft context remain readable.
Chat starts with model-focused suggestions. Enter sends and Shift+Enter adds a line; text composition does not accidentally send. You can draft the next message while a request is running. Proposed changes offer a concise action with an expandable source review; existing validation and stale-source checks still apply. Actual replies require a configured, available agent provider.
Long drafts expand within a bounded composer. Reading earlier replies keeps your place when a request completes; Latest message returns to the end. Failed or interrupted requests and individual replies can be retried without losing your next draft. AI setup opens provider configuration.
Conversations opens history for this server, account, model, and folder partition. New conversation preserves the previous conversation. Select a saved conversation to resume its messages and unfinished draft, including attached images that fit the local storage limits. The window remembers that selection for reload when session storage is available; otherwise it opens the most recently saved conversation. Refresh list finds entries created in another window without replacing your current work. Delete requires an explicit confirmation; Export current downloads conversation JSON. History is device-local: browsers use IndexedDB for that site, and desktop uses its application profile across changes to the internal server address. It is not synchronized to other devices. Clearing browser data or removing the profile removes its history. Public unclaimed instances share their local profile's history; authenticated owners remain separate.
Switching models or accounts cancels the active client request and clears it from view. Returning restores saved messages in the matching scope. A reply that was still pending when its conversation closed reopens as interrupted; retry is explicit and uses the current model. This does not resume a provider request or assert that remote execution was stopped. Runtime audit records remain separate from local conversation history.
Each request includes at most eight recent user/assistant messages in a quoted transcript of at most 8,000 characters. Long replies and prior proposed source are shortened. The current model takes precedence; an earlier proposal is identified as applied or unapplied. This gives follow-up questions context without sending an unbounded conversation. Restored proposals retain their source baseline and the existing stale-source/application checks. Source review compares the proposal with its captured original model. Applied records that the change reached the editor; it is not a claim that every later calculation or archive save succeeded. App and Chat keep model-update failures visible with details, Retry Save, and a route to Code. Source changes can be confirmed directly from these layers without first opening a Data worksheet.
For a proposal that updates two assumptions far apart in a large model, source review shows both exact edits, their surrounding context, and the unchanged gap. Repeated blank lines retain their original alignment. Reviewing or applying the proposal preserves a draft reply in the composer.
Long conversations open at their latest messages. When reopening more than 40 messages, Chat and the side rail initially show the latest 20. Select the previous messages control to reveal 20 more at a time. Revealed messages stay open: expanding a source review, selecting text, switching layers, or receiving a reply does not discard them. Latest message returns to the end without collapsing earlier groups. Choosing another saved conversation resets the visible range. The saved transcript and export still include every message; reveal older groups before using browser text search on their contents.
A competing window cannot overwrite or delete a newer saved revision. A conflict offers Save a copy, Export conversation, or an explicit choice to replace the window's unsaved work with the saved version. Storage failures remain visible. If history cannot be read, Use a temporary conversation allows work to continue with a clear unsaved status. Export it or retry saving before closing. Draft writes are coalesced over 400 ms and flushed on focus loss and conversation changes; a crash before a storage transaction completes can lose the latest work. History refuses additional storage instead of evicting conversations: up to 100 conversations, 2 Mi UTF-16 characters each, and 16 Mi across the local store. Images have a separate allowance: up to 4 MiB per image, 128 distinct images and 32 MiB per conversation, and 128 MiB across the local store. Reusing an image does not consume another copy of its storage. Deleting a saved conversation removes images no other saved conversation uses. Export includes the images in a portable conversation file. A save failure keeps active work available for export and shows an unsaved status. Remove saved images or conversations to make room. Existing saved conversations remain readable. Editions without the agent show an unavailable state and a route back to Data.
Changing accounts also clears the active model, retained Code/App drafts, and the visible conversation; saved conversation history remains isolated by its recorded owner. Saved startup source and the last-open model are restored only for their recorded server/account. Older unowned startup caches remain available to unclaimed public desktop sessions; private sessions require a known owner before restoring cached source.
Desktop conversations, document recovery, and appearance/starting-layer choices survive local address changes. The last-open workspace and unsaved model-source cache still use browser storage and can reset when desktop starts at a new local address. Reopen the model and its document to review a retained document draft.
Your starting layer and links
Advanced → Open this model in is personal to this model and folder partition on this device. Desktop keeps it across restarts; browsers keep it for the same site. Saving failures are reported and leave the previous starting layer intact. It does not change the model for another person. Changing the setting affects the next normal model open, rather than switching the current layer immediately. Auto removes this personal preference and uses the model's existing App Home behavior, otherwise Data.
An explicit link takes precedence over the personal default:
gridLayer=code,sheet,app, orchatchooses that layer. Data keeps the existingsheetlink identifier so saved links continue to work.- Existing
gridMode=devlinks open Data. - Existing
gridMode=app,surface, andappPathlinks keep their App meaning. A valid explicitgridLayertakes priority over that legacy mode. modelandpartitioncontinue to identify the model target. Surface and page-route parameters are retained while another layer is selected.
For example, a link containing
?model=<model-id>&partition=0&gridLayer=chat opens Chat for that model. An App
view link can add gridMode=app&surface=Dashboard; a supported App page route
uses appPath. Browser Back and Forward restore layer and App-route choices.
Try the same model through several layers
The existing Revenue Dashboard example contains named calculations and a Dashboard surface. It requires no new language syntax for layers:
- Open the example and inspect
Forecastin Data. - Choose Code to read its revenue inputs and calculation.
- In Code → Surfaces → App settings, label Dashboard Revenue outlook, put it in Plan, choose Wide, and save. Choose App to see the same live tiles under the authored navigation label.
- Select Forecast and ask for an explanation. Expand the answer into Chat; its context reference returns to Revenue outlook and Forecast.
- Write an unfinished follow-up in Chat, open Conversations, and start a new conversation. Reopen the earlier entry to restore the draft; reloading also restores the saved conversation. Sending needs a configured provider.
The model's calculations remain shared throughout. This walkthrough is an authoring example, not a claim that packaged-product or provider-backed QA has been completed for the preview.
Live presentations
Deck follows these same four layers. App offers Presentation · Deck as a starting view, direct slide authoring, and Present. Code retains the native editor and configuration/data files. Data inspects slide bindings, and Chat can keep proposed slides in a new or existing deck. Stable slide routes retain context across layer changes. See Deck presentations for saving, audience isolation, and export behavior.
Quiet controls, readable content
App keeps document writing tools in one compact strip. Document opens Find, Outline, Styles, Page setup, Word import, publication, zoom, and view commands such as Duplicate view and Edit in Code. Selection offers Inspect beside these tools; ready rich documents do not get a second host action strip. Same-model links show their destination labels and an Open view action. Save failures and conflicts remain visible beside the content. Data retains its existing document toolbars. Import uses the same native document command and guarded save behavior.
In App documents, accepted live references read as underlined values within the sentence. Their names remain available to assistive technology and on hover; reference editing appears on hover or keyboard focus (and stays visible on touch interfaces). Missing, stale, pending, and failed references keep their explicit states. The underlying document and its export formatting are unchanged.
Deck keeps Present prominent in one App action row. View actions groups capture settings, speaker notes inclusion, exports, and Edit slides. Its live/frozen setting is preserved. The whole slide fits the browsing area, with a numbered slide outline and Previous/Next controls. Narrow windows keep navigation beside the slide and expose the outline in a drawer. Slide visits participate in App Back/Forward; an unavailable slide identifies its route and offers explicit recovery. Opening a deck does not select its technical data slot for Chat. App's view and document menus share theme tokens, keyboard Escape behavior, and outside-click dismissal. Arrangement remains a separate command, with Undo/Redo near the slide and structural commands under Slide actions.
Live presenter assumptions use the shared input controls: percentages accept percentage points, Enter or blur commits, acknowledgements show Saved, and failed text remains available for correction. Escape in a numeric or text field restores the accepted value; Escape outside those fields ends the presentation. Frozen presentations and non-input values remain read only. These controls subscribe only to the active presentation's declared references.
The forecasting example is a
complete illustrative planning case: Overview, assumptions, a live comparison
chart, a written planning position, and a presentation. Currency values carry
explicit Grid currency tags; percentages use ordinary FORMAT metadata.
Documents and notebooks receive the host’s existing display metadata with their
selected live values, without resolving or copying the full model catalog. The
numbers remain live; the explanation is authored prose.
It is explicitly an illustrative case, not a claim of observed business results.
Layout uses the same App title, view menu, live-value formatting, and explicit Inspect behavior. New layouts begin with an empty state and Edit layout. Add value and Add note create ordinary blocks in the existing data slot; drag, keyboard movement, resize, and Undo arrange them. Done waits for acknowledged saving and returns to reading with focus on the selected block. Reading stacks blocks on narrow windows, while arrangement retains the grid with scrolling. These content edits are separate from Customize App’s navigation settings.
Native Code history
On macOS, Edit → Undo/Redo, Command+Z and Command+Shift+Z act on the focused Code source editor's retained history, including after switching files or source projects. This applies to model source, surface source/configuration and local extension projects. A read-only Code editor consumes the command without changing source. Other text controls and native browser children keep macOS editing behavior; a Find field does not undo the source model. Windows and Linux retain their existing native menu implementation.
See Author projects and Registry content in Code for local project tabs, CLI development commands, model imports, workspace activation, publisher enrollment and publication, and catalog installation/inspection.
Shared command and tooltip details
Workspace buttons acknowledge hover, keyboard focus, and press immediately; leaving a control uses a short color transition. Reduced-motion preferences remove that transition. These rules cover shared buttons and ribbon controls; model-authored App content keeps its own presentation.
The application menu is one Tab stop. Left/Right moves between menu names; Down opens the first available command and Up opens the last. Inside a menu, Up/Down skips unavailable commands, Home/End reaches the ends, and typing a command's first letters finds it. Escape returns to the menu name. Tab closes the menu and continues through the workspace. Command availability updates keep your current keyboard position whenever that command remains available.
Menus stay within the window and scroll when needed. They escape the ribbon's clipping boundary and temporarily cover an embedded native Browser through the shared overlay mechanism. Tooltips flip at window edges, cancel on Escape, scroll or resize even during their hover delay, and stay quiet after a pointer click. Keyboard focus shows the hint immediately. Focus a shared formatting control to read its label and shortcut; press Escape to dismiss the hint while keeping the control focused.
Command and model search focus their search field as soon as they open. Up/Down moves the highlight; Page Up/Page Down moves ten results at a time. Enter runs the highlighted result, and clicking a row runs that exact result. Editing the query starts at the first current match. A source refresh retains the highlighted item while it remains available. Escape closes search and returns to its invoker; a command that opens another dialog transfers focus to that dialog. Input-method composition keeps its normal confirmation keys.
Search exposes the field, result list and active option together to assistive technology. Long lists scroll inside the overlay, retain the active result when the window shrinks, and report when only the first 60 commands or 80 models are shown. The panel opens in place with a brief opacity transition; reduced-motion preferences remove that transition. Closed search does not index items or keep search listeners active. These interaction refinements preserve existing model and command behavior; they do not promise a universal command-completion time.
Context menus fit the window edges and keep the focused command when availability changes. Up/Down, Home/End and typing a command's first letters move within the menu; disabled commands are skipped. Scrolling its own list keeps the menu open. Escape restores its invoker, while Tab continues to the next control. A command that opens an editor keeps that focus. Grid selection recovery yields to a new pointer or keyboard gesture, so a delayed focus update cannot undo that gesture.
In the App builder's Outline, click selects one component; Command/Control-click toggles separate components. Shift-click or Shift+Up/Down extends or shrinks a range from its anchor. Command/Control+Shift adds that range to the existing set. For example, select Heading, Shift-click Button, then Shift-click Text to shrink the selection back to Heading and Text. The final endpoint owns the inspector.
The outline is one Tab stop. Up/Down, Home/End and typeahead navigate; holding Command/Control moves focus without changing selection. Space toggles the focused component. Left/Right collapses, expands or moves between parent and child; collapsing a branch preserves its selection. Command/Control+A selects visible rows. Escape clears the selection before another Escape leaves the outline's local scope. Outline ranges share the canvas selection and bulk inspector actions; the canvas retains its existing spatial selection and drag behavior.
Large outlines keep a compact scrolling viewport and render rows as they become visible. Home/End, parent/child navigation and range selection still reach the entire expanded tree, including rows currently outside the viewport. Keyboard destinations remain visible inside a narrow Elements drawer. Browser Find sees the rendered portion of the outline; the authored canvas and Preview retain all components. Opening an App uses its initial document once, while recovered drafts and later model changes keep their existing conflict and adoption checks.
Home search leaves the model list in place when opening and closing the picker. Updated summaries and active-model changes still refresh the library normally. Model thumbnails keep their stable shape and input/output colors in both list and card layouts.
Large Home libraries render the visible rows or cards as you scroll. A rename draft, pending save, or delete confirmation remains attached to its model even when you scroll it out of view. Tab and Shift+Tab continue through adjacent models, including those not yet rendered; changing the layout keeps your place. For example, start renaming a model, scroll through the library, then return: the same draft is still there. The library toolbar wraps on narrow windows so Search, layout controls, and New stay reachable.