Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion content/docs/build/agents.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -47,7 +47,7 @@ export const tier1Support = defineAgent({
});
```

Or in the UI: **Agents → New Agent**.
Or in the UI: **Studio → Agents → New Agent**.

Or — and this is the point — say to the AI Builder:

Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/data/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,7 +18,7 @@ is generating and can edit it directly when you want to.
| Path | Looks like |
|---|---|
| **AI Builder** (primary) | *"Create a `support_ticket` object with subject, description, priority, status, assignee."* |
| **Click-build** | **Objects → New Object** → forms |
| **Click-build** | **Studio → Objects → New Object** → forms |
| **TypeScript (`*.object.ts`)** | The TS shown below — typically inside a forked [template](/docs/build/templates) |

All three produce the same schema. The schema is canonical; everything
Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/packages.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -51,7 +51,7 @@ pnpm dev

### From the UI

**Packages → New Package** — name, id, version, namespace.
**Studio → Packages → New Package** — name, id, version, namespace.

## Active package

Expand Down
21 changes: 18 additions & 3 deletions content/docs/configure/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,24 @@ You manage people and their permissions day to day; the applications,
objects, and permission sets themselves ship with the platform and the
app packages you install.

> **Permissions are designed in Studio, assigned in Setup.** Most
> administration never leaves Setup — you enter Studio only to author
> permission sets or to run the explain engine.
## Setup and Studio

**Permissions are designed in Studio, assigned in Setup.** That
sentence is the canonical statement of a split that runs through the
whole product, not a rule about permissions alone: Setup *operates* a
running deployment, Studio *authors* the metadata that deployment runs.
Both live inside the same UI at `/_console/`; neither is a surface of
its own.

| | Setup | Studio |
|---|---|---|
| Answers | Who is here, and what may they do? | What does this app consist of? |
| Where | `/_console/apps/setup` | `/_console/studio` |
| Gated by | `setup.access` | `studio.access` |
| For | System administrators | Implementers and developers |

Most administration never leaves Setup — you enter Studio only to
author permission sets or to run the explain engine.

## The Setup app

Expand Down
6 changes: 3 additions & 3 deletions content/docs/configure/permissions/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -161,9 +161,9 @@ applies uniformly across REST, ObjectQL, and the UI.
- The **explain engine** (`explain(principal, object, operation)`)
reports the verdict of every layer in order — required permissions,
object CRUD, field security, OWD baseline, sharing, row-level
security — with per-layer attribution. It surfaces as the
"Why can this user access?" panel. Explaining another user requires
the `manage_users` capability.
security — with per-layer attribution. Studio's **Access** pillar
surfaces it as the "Why can this user access?" panel. Explaining
another user requires the `manage_users` capability.
- `/_console/` shows the effective permissions of any user as they're
evaluated.
- Audit log (`sys_audit_log`) records permission-sensitive changes —
Expand Down
13 changes: 13 additions & 0 deletions content/docs/resources/glossary.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,19 @@ query time, compiled into row-level filters. A rule stored **without**
criteria shares nothing — it is not a match-all. See
[Record Access](/docs/configure/permissions/record-access#both-switches-fail-closed).

### Studio

The built-in metadata-authoring surface, at `/studio` inside the UI
served at `/_console/`, gated by the `studio.access` permission.
Where the metadata itself is *designed* — packages, objects, apps,
flows and permission sets — one package at a time, across four pillars:
Data, Automations, Interfaces, Access. Peer of **Setup**, not part of
it: Setup operates a running deployment (its people, their grants, its
configuration), Studio authors what that deployment runs — hence
**permissions are designed in Studio, assigned in Setup**. Unlike
Setup it is not an app under `/apps/`; the UI serves it as its own
route subtree. See [Administration](/docs/configure#setup-and-studio).

### Surface

One of the HTTP entry points a running ObjectOS exposes: `/` (REST API)
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion content/docs/build/agents.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -47,7 +47,7 @@ export const tier1Support = defineAgent({
});
```

Or in the UI: **Agents → New Agent**.
Or in the UI: **Studio → Agents → New Agent**.

Or — and this is the point — say to the AI Builder:

Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/data/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,7 +18,7 @@ is generating and can edit it directly when you want to.
| Path | Looks like |
|---|---|
| **AI Builder** (primary) | *"Create a `support_ticket` object with subject, description, priority, status, assignee."* |
| **Click-build** | **Objects → New Object** → forms |
| **Click-build** | **Studio → Objects → New Object** → forms |
| **TypeScript (`*.object.ts`)** | The TS shown below — typically inside a forked [template](/docs/build/templates) |

All three produce the same schema. The schema is canonical; everything
Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/packages.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -51,7 +51,7 @@ pnpm dev

### From the UI

**Packages → New Package** — name, id, version, namespace.
**Studio → Packages → New Package** — name, id, version, namespace.

## Active package

Expand Down
21 changes: 18 additions & 3 deletions content/docs/configure/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,24 @@ You manage people and their permissions day to day; the applications,
objects, and permission sets themselves ship with the platform and the
app packages you install.

> **Permissions are designed in Studio, assigned in Setup.** Most
> administration never leaves Setup — you enter Studio only to author
> permission sets or to run the explain engine.
## Setup and Studio

**Permissions are designed in Studio, assigned in Setup.** That
sentence is the canonical statement of a split that runs through the
whole product, not a rule about permissions alone: Setup *operates* a
running deployment, Studio *authors* the metadata that deployment runs.
Both live inside the same UI at `/_console/`; neither is a surface of
its own.

| | Setup | Studio |
|---|---|---|
| Answers | Who is here, and what may they do? | What does this app consist of? |
| Where | `/_console/apps/setup` | `/_console/studio` |
| Gated by | `setup.access` | `studio.access` |
| For | System administrators | Implementers and developers |

Most administration never leaves Setup — you enter Studio only to
author permission sets or to run the explain engine.

## The Setup app

Expand Down
6 changes: 3 additions & 3 deletions content/docs/configure/permissions/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -161,9 +161,9 @@ applies uniformly across REST, ObjectQL, and the UI.
- The **explain engine** (`explain(principal, object, operation)`)
reports the verdict of every layer in order — required permissions,
object CRUD, field security, OWD baseline, sharing, row-level
security — with per-layer attribution. It surfaces as the
"Why can this user access?" panel. Explaining another user requires
the `manage_users` capability.
security — with per-layer attribution. Studio's **Access** pillar
surfaces it as the "Why can this user access?" panel. Explaining
another user requires the `manage_users` capability.
- `/_console/` shows the effective permissions of any user as they're
evaluated.
- Audit log (`sys_audit_log`) records permission-sensitive changes —
Expand Down
13 changes: 13 additions & 0 deletions content/docs/resources/glossary.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,19 @@ query time, compiled into row-level filters. A rule stored **without**
criteria shares nothing — it is not a match-all. See
[Record Access](/docs/configure/permissions/record-access#both-switches-fail-closed).

### Studio

The built-in metadata-authoring surface, at `/studio` inside the UI
served at `/_console/`, gated by the `studio.access` permission.
Where the metadata itself is *designed* — packages, objects, apps,
flows and permission sets — one package at a time, across four pillars:
Data, Automations, Interfaces, Access. Peer of **Setup**, not part of
it: Setup operates a running deployment (its people, their grants, its
configuration), Studio authors what that deployment runs — hence
**permissions are designed in Studio, assigned in Setup**. Unlike
Setup it is not an app under `/apps/`; the UI serves it as its own
route subtree. See [Administration](/docs/configure#setup-and-studio).

### Surface

One of the HTTP entry points a running ObjectOS exposes: `/` (REST API)
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion content/docs/build/agents.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -47,7 +47,7 @@ export const tier1Support = defineAgent({
});
```

Or in the UI: **Agents → New Agent**.
Or in the UI: **Studio → Agents → New Agent**.

Or — and this is the point — say to the AI Builder:

Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/data/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,7 +18,7 @@ is generating and can edit it directly when you want to.
| Path | Looks like |
|---|---|
| **AI Builder** (primary) | *"Create a `support_ticket` object with subject, description, priority, status, assignee."* |
| **Click-build** | **Objects → New Object** → forms |
| **Click-build** | **Studio → Objects → New Object** → forms |
| **TypeScript (`*.object.ts`)** | The TS shown below — typically inside a forked [template](/docs/build/templates) |

All three produce the same schema. The schema is canonical; everything
Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/packages.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -51,7 +51,7 @@ pnpm dev

### From the UI

**Packages → New Package** — name, id, version, namespace.
**Studio → Packages → New Package** — name, id, version, namespace.

## Active package

Expand Down
21 changes: 18 additions & 3 deletions content/docs/configure/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,24 @@ You manage people and their permissions day to day; the applications,
objects, and permission sets themselves ship with the platform and the
app packages you install.

> **Permissions are designed in Studio, assigned in Setup.** Most
> administration never leaves Setup — you enter Studio only to author
> permission sets or to run the explain engine.
## Setup and Studio

**Permissions are designed in Studio, assigned in Setup.** That
sentence is the canonical statement of a split that runs through the
whole product, not a rule about permissions alone: Setup *operates* a
running deployment, Studio *authors* the metadata that deployment runs.
Both live inside the same UI at `/_console/`; neither is a surface of
its own.

| | Setup | Studio |
|---|---|---|
| Answers | Who is here, and what may they do? | What does this app consist of? |
| Where | `/_console/apps/setup` | `/_console/studio` |
| Gated by | `setup.access` | `studio.access` |
| For | System administrators | Implementers and developers |

Most administration never leaves Setup — you enter Studio only to
author permission sets or to run the explain engine.

## The Setup app

Expand Down
6 changes: 3 additions & 3 deletions content/docs/configure/permissions/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -161,9 +161,9 @@ applies uniformly across REST, ObjectQL, and the UI.
- The **explain engine** (`explain(principal, object, operation)`)
reports the verdict of every layer in order — required permissions,
object CRUD, field security, OWD baseline, sharing, row-level
security — with per-layer attribution. It surfaces as the
"Why can this user access?" panel. Explaining another user requires
the `manage_users` capability.
security — with per-layer attribution. Studio's **Access** pillar
surfaces it as the "Why can this user access?" panel. Explaining
another user requires the `manage_users` capability.
- `/_console/` shows the effective permissions of any user as they're
evaluated.
- Audit log (`sys_audit_log`) records permission-sensitive changes —
Expand Down
13 changes: 13 additions & 0 deletions content/docs/resources/glossary.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,19 @@ query time, compiled into row-level filters. A rule stored **without**
criteria shares nothing — it is not a match-all. See
[Record Access](/docs/configure/permissions/record-access#both-switches-fail-closed).

### Studio

The built-in metadata-authoring surface, at `/studio` inside the UI
served at `/_console/`, gated by the `studio.access` permission.
Where the metadata itself is *designed* — packages, objects, apps,
flows and permission sets — one package at a time, across four pillars:
Data, Automations, Interfaces, Access. Peer of **Setup**, not part of
it: Setup operates a running deployment (its people, their grants, its
configuration), Studio authors what that deployment runs — hence
**permissions are designed in Studio, assigned in Setup**. Unlike
Setup it is not an app under `/apps/`; the UI serves it as its own
route subtree. See [Administration](/docs/configure#setup-and-studio).

### Surface

One of the HTTP entry points a running ObjectOS exposes: `/` (REST API)
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion content/docs/build/agents.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -47,7 +47,7 @@ export const tier1Support = defineAgent({
});
```

Or in the UI: **Agents → New Agent**.
Or in the UI: **Studio → Agents → New Agent**.

Or — and this is the point — say to the AI Builder:

Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/data/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,7 +18,7 @@ is generating and can edit it directly when you want to.
| Path | Looks like |
|---|---|
| **AI Builder** (primary) | *"Create a `support_ticket` object with subject, description, priority, status, assignee."* |
| **Click-build** | **Objects → New Object** → forms |
| **Click-build** | **Studio → Objects → New Object** → forms |
| **TypeScript (`*.object.ts`)** | The TS shown below — typically inside a forked [template](/docs/build/templates) |

All three produce the same schema. The schema is canonical; everything
Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/packages.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -51,7 +51,7 @@ pnpm dev

### From the UI

**Packages → New Package** — name, id, version, namespace.
**Studio → Packages → New Package** — name, id, version, namespace.

## Active package

Expand Down
21 changes: 18 additions & 3 deletions content/docs/configure/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,24 @@ You manage people and their permissions day to day; the applications,
objects, and permission sets themselves ship with the platform and the
app packages you install.

> **Permissions are designed in Studio, assigned in Setup.** Most
> administration never leaves Setup — you enter Studio only to author
> permission sets or to run the explain engine.
## Setup and Studio

**Permissions are designed in Studio, assigned in Setup.** That
sentence is the canonical statement of a split that runs through the
whole product, not a rule about permissions alone: Setup *operates* a
running deployment, Studio *authors* the metadata that deployment runs.
Both live inside the same UI at `/_console/`; neither is a surface of
its own.

| | Setup | Studio |
|---|---|---|
| Answers | Who is here, and what may they do? | What does this app consist of? |
| Where | `/_console/apps/setup` | `/_console/studio` |
| Gated by | `setup.access` | `studio.access` |
| For | System administrators | Implementers and developers |

Most administration never leaves Setup — you enter Studio only to
author permission sets or to run the explain engine.

## The Setup app

Expand Down
6 changes: 3 additions & 3 deletions content/docs/configure/permissions/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -161,9 +161,9 @@ applies uniformly across REST, ObjectQL, and the UI.
- The **explain engine** (`explain(principal, object, operation)`)
reports the verdict of every layer in order — required permissions,
object CRUD, field security, OWD baseline, sharing, row-level
security — with per-layer attribution. It surfaces as the
"Why can this user access?" panel. Explaining another user requires
the `manage_users` capability.
security — with per-layer attribution. Studio's **Access** pillar
surfaces it as the "Why can this user access?" panel. Explaining
another user requires the `manage_users` capability.
- `/_console/` shows the effective permissions of any user as they're
evaluated.
- Audit log (`sys_audit_log`) records permission-sensitive changes —
Expand Down
13 changes: 13 additions & 0 deletions content/docs/resources/glossary.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,19 @@ query time, compiled into row-level filters. A rule stored **without**
criteria shares nothing — it is not a match-all. See
[Record Access](/docs/configure/permissions/record-access#both-switches-fail-closed).

### Studio

The built-in metadata-authoring surface, at `/studio` inside the UI
served at `/_console/`, gated by the `studio.access` permission.
Where the metadata itself is *designed* — packages, objects, apps,
flows and permission sets — one package at a time, across four pillars:
Data, Automations, Interfaces, Access. Peer of **Setup**, not part of
it: Setup operates a running deployment (its people, their grants, its
configuration), Studio authors what that deployment runs — hence
**permissions are designed in Studio, assigned in Setup**. Unlike
Setup it is not an app under `/apps/`; the UI serves it as its own
route subtree. See [Administration](/docs/configure#setup-and-studio).

### Surface

One of the HTTP entry points a running ObjectOS exposes: `/` (REST API)
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion content/docs/build/agents.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -47,7 +47,7 @@ export const tier1Support = defineAgent({
});
```

Or in the UI: **Agents → New Agent**.
Or in the UI: **Studio → Agents → New Agent**.

Or — and this is the point — say to the AI Builder:

Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/data/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,7 +18,7 @@ is generating and can edit it directly when you want to.
| Path | Looks like |
|---|---|
| **AI Builder** (primary) | *"Create a `support_ticket` object with subject, description, priority, status, assignee."* |
| **Click-build** | **Objects → New Object** → forms |
| **Click-build** | **Studio → Objects → New Object** → forms |
| **TypeScript (`*.object.ts`)** | The TS shown below — typically inside a forked [template](/docs/build/templates) |

All three produce the same schema. The schema is canonical; everything
Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/packages.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -51,7 +51,7 @@ pnpm dev

### From the UI

**Packages → New Package** — name, id, version, namespace.
**Studio → Packages → New Package** — name, id, version, namespace.

## Active package

Expand Down
21 changes: 18 additions & 3 deletions content/docs/configure/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,24 @@ You manage people and their permissions day to day; the applications,
objects, and permission sets themselves ship with the platform and the
app packages you install.

> **Permissions are designed in Studio, assigned in Setup.** Most
> administration never leaves Setup — you enter Studio only to author
> permission sets or to run the explain engine.
## Setup and Studio

**Permissions are designed in Studio, assigned in Setup.** That
sentence is the canonical statement of a split that runs through the
whole product, not a rule about permissions alone: Setup *operates* a
running deployment, Studio *authors* the metadata that deployment runs.
Both live inside the same UI at `/_console/`; neither is a surface of
its own.

| | Setup | Studio |
|---|---|---|
| Answers | Who is here, and what may they do? | What does this app consist of? |
| Where | `/_console/apps/setup` | `/_console/studio` |
| Gated by | `setup.access` | `studio.access` |
| For | System administrators | Implementers and developers |

Most administration never leaves Setup — you enter Studio only to
author permission sets or to run the explain engine.

## The Setup app

Expand Down
6 changes: 3 additions & 3 deletions content/docs/configure/permissions/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -161,9 +161,9 @@ applies uniformly across REST, ObjectQL, and the UI.
- The **explain engine** (`explain(principal, object, operation)`)
reports the verdict of every layer in order — required permissions,
object CRUD, field security, OWD baseline, sharing, row-level
security — with per-layer attribution. It surfaces as the
"Why can this user access?" panel. Explaining another user requires
the `manage_users` capability.
security — with per-layer attribution. Studio's **Access** pillar
surfaces it as the "Why can this user access?" panel. Explaining
another user requires the `manage_users` capability.
- `/_console/` shows the effective permissions of any user as they're
evaluated.
- Audit log (`sys_audit_log`) records permission-sensitive changes —
Expand Down
13 changes: 13 additions & 0 deletions content/docs/resources/glossary.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,19 @@ query time, compiled into row-level filters. A rule stored **without**
criteria shares nothing — it is not a match-all. See
[Record Access](/docs/configure/permissions/record-access#both-switches-fail-closed).

### Studio

The built-in metadata-authoring surface, at `/studio` inside the UI
served at `/_console/`, gated by the `studio.access` permission.
Where the metadata itself is *designed* — packages, objects, apps,
flows and permission sets — one package at a time, across four pillars:
Data, Automations, Interfaces, Access. Peer of **Setup**, not part of
it: Setup operates a running deployment (its people, their grants, its
configuration), Studio authors what that deployment runs — hence
**permissions are designed in Studio, assigned in Setup**. Unlike
Setup it is not an app under `/apps/`; the UI serves it as its own
route subtree. See [Administration](/docs/configure#setup-and-studio).

### Surface

One of the HTTP entry points a running ObjectOS exposes: `/` (REST API)
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion content/docs/build/agents.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -47,7 +47,7 @@ export const tier1Support = defineAgent({
});
```

Or in the UI: **Agents → New Agent**.
Or in the UI: **Studio → Agents → New Agent**.

Or — and this is the point — say to the AI Builder:

Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/data/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,7 +18,7 @@ is generating and can edit it directly when you want to.
| Path | Looks like |
|---|---|
| **AI Builder** (primary) | *"Create a `support_ticket` object with subject, description, priority, status, assignee."* |
| **Click-build** | **Objects → New Object** → forms |
| **Click-build** | **Studio → Objects → New Object** → forms |
| **TypeScript (`*.object.ts`)** | The TS shown below — typically inside a forked [template](/docs/build/templates) |

All three produce the same schema. The schema is canonical; everything
Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/packages.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -51,7 +51,7 @@ pnpm dev

### From the UI

**Packages → New Package** — name, id, version, namespace.
**Studio → Packages → New Package** — name, id, version, namespace.

## Active package

Expand Down
21 changes: 18 additions & 3 deletions content/docs/configure/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,24 @@ You manage people and their permissions day to day; the applications,
objects, and permission sets themselves ship with the platform and the
app packages you install.

> **Permissions are designed in Studio, assigned in Setup.** Most
> administration never leaves Setup — you enter Studio only to author
> permission sets or to run the explain engine.
## Setup and Studio

**Permissions are designed in Studio, assigned in Setup.** That
sentence is the canonical statement of a split that runs through the
whole product, not a rule about permissions alone: Setup *operates* a
running deployment, Studio *authors* the metadata that deployment runs.
Both live inside the same UI at `/_console/`; neither is a surface of
its own.

| | Setup | Studio |
|---|---|---|
| Answers | Who is here, and what may they do? | What does this app consist of? |
| Where | `/_console/apps/setup` | `/_console/studio` |
| Gated by | `setup.access` | `studio.access` |
| For | System administrators | Implementers and developers |

Most administration never leaves Setup — you enter Studio only to
author permission sets or to run the explain engine.

## The Setup app

Expand Down
6 changes: 3 additions & 3 deletions content/docs/configure/permissions/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -161,9 +161,9 @@ applies uniformly across REST, ObjectQL, and the UI.
- The **explain engine** (`explain(principal, object, operation)`)
reports the verdict of every layer in order — required permissions,
object CRUD, field security, OWD baseline, sharing, row-level
security — with per-layer attribution. It surfaces as the
"Why can this user access?" panel. Explaining another user requires
the `manage_users` capability.
security — with per-layer attribution. Studio's **Access** pillar
surfaces it as the "Why can this user access?" panel. Explaining
another user requires the `manage_users` capability.
- `/_console/` shows the effective permissions of any user as they're
evaluated.
- Audit log (`sys_audit_log`) records permission-sensitive changes —
Expand Down
13 changes: 13 additions & 0 deletions content/docs/resources/glossary.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,19 @@ query time, compiled into row-level filters. A rule stored **without**
criteria shares nothing — it is not a match-all. See
[Record Access](/docs/configure/permissions/record-access#both-switches-fail-closed).

### Studio

The built-in metadata-authoring surface, at `/studio` inside the UI
served at `/_console/`, gated by the `studio.access` permission.
Where the metadata itself is *designed* — packages, objects, apps,
flows and permission sets — one package at a time, across four pillars:
Data, Automations, Interfaces, Access. Peer of **Setup**, not part of
it: Setup operates a running deployment (its people, their grants, its
configuration), Studio authors what that deployment runs — hence
**permissions are designed in Studio, assigned in Setup**. Unlike
Setup it is not an app under `/apps/`; the UI serves it as its own
route subtree. See [Administration](/docs/configure#setup-and-studio).

### Surface

One of the HTTP entry points a running ObjectOS exposes: `/` (REST API)
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion content/docs/build/agents.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -47,7 +47,7 @@ export const tier1Support = defineAgent({
});
```

Or in the UI: **Agents → New Agent**.
Or in the UI: **Studio → Agents → New Agent**.

Or — and this is the point — say to the AI Builder:

Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/data/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,7 +18,7 @@ is generating and can edit it directly when you want to.
| Path | Looks like |
|---|---|
| **AI Builder** (primary) | *"Create a `support_ticket` object with subject, description, priority, status, assignee."* |
| **Click-build** | **Objects → New Object** → forms |
| **Click-build** | **Studio → Objects → New Object** → forms |
| **TypeScript (`*.object.ts`)** | The TS shown below — typically inside a forked [template](/docs/build/templates) |

All three produce the same schema. The schema is canonical; everything
Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/packages.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -51,7 +51,7 @@ pnpm dev

### From the UI

**Packages → New Package** — name, id, version, namespace.
**Studio → Packages → New Package** — name, id, version, namespace.

## Active package

Expand Down
21 changes: 18 additions & 3 deletions content/docs/configure/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,24 @@ You manage people and their permissions day to day; the applications,
objects, and permission sets themselves ship with the platform and the
app packages you install.

> **Permissions are designed in Studio, assigned in Setup.** Most
> administration never leaves Setup — you enter Studio only to author
> permission sets or to run the explain engine.
## Setup and Studio

**Permissions are designed in Studio, assigned in Setup.** That
sentence is the canonical statement of a split that runs through the
whole product, not a rule about permissions alone: Setup *operates* a
running deployment, Studio *authors* the metadata that deployment runs.
Both live inside the same UI at `/_console/`; neither is a surface of
its own.

| | Setup | Studio |
|---|---|---|
| Answers | Who is here, and what may they do? | What does this app consist of? |
| Where | `/_console/apps/setup` | `/_console/studio` |
| Gated by | `setup.access` | `studio.access` |
| For | System administrators | Implementers and developers |

Most administration never leaves Setup — you enter Studio only to
author permission sets or to run the explain engine.

## The Setup app

Expand Down
6 changes: 3 additions & 3 deletions content/docs/configure/permissions/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -161,9 +161,9 @@ applies uniformly across REST, ObjectQL, and the UI.
- The **explain engine** (`explain(principal, object, operation)`)
reports the verdict of every layer in order — required permissions,
object CRUD, field security, OWD baseline, sharing, row-level
security — with per-layer attribution. It surfaces as the
"Why can this user access?" panel. Explaining another user requires
the `manage_users` capability.
security — with per-layer attribution. Studio's **Access** pillar
surfaces it as the "Why can this user access?" panel. Explaining
another user requires the `manage_users` capability.
- `/_console/` shows the effective permissions of any user as they're
evaluated.
- Audit log (`sys_audit_log`) records permission-sensitive changes —
Expand Down
13 changes: 13 additions & 0 deletions content/docs/resources/glossary.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,19 @@ query time, compiled into row-level filters. A rule stored **without**
criteria shares nothing — it is not a match-all. See
[Record Access](/docs/configure/permissions/record-access#both-switches-fail-closed).

### Studio

The built-in metadata-authoring surface, at `/studio` inside the UI
served at `/_console/`, gated by the `studio.access` permission.
Where the metadata itself is *designed* — packages, objects, apps,
flows and permission sets — one package at a time, across four pillars:
Data, Automations, Interfaces, Access. Peer of **Setup**, not part of
it: Setup operates a running deployment (its people, their grants, its
configuration), Studio authors what that deployment runs — hence
**permissions are designed in Studio, assigned in Setup**. Unlike
Setup it is not an app under `/apps/`; the UI serves it as its own
route subtree. See [Administration](/docs/configure#setup-and-studio).

### Surface

One of the HTTP entry points a running ObjectOS exposes: `/` (REST API)
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion content/docs/build/agents.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -47,7 +47,7 @@ export const tier1Support = defineAgent({
});
```

Or in the UI: **Agents → New Agent**.
Or in the UI: **Studio → Agents → New Agent**.

Or — and this is the point — say to the AI Builder:

Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/data/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,7 +18,7 @@ is generating and can edit it directly when you want to.
| Path | Looks like |
|---|---|
| **AI Builder** (primary) | *"Create a `support_ticket` object with subject, description, priority, status, assignee."* |
| **Click-build** | **Objects → New Object** → forms |
| **Click-build** | **Studio → Objects → New Object** → forms |
| **TypeScript (`*.object.ts`)** | The TS shown below — typically inside a forked [template](/docs/build/templates) |

All three produce the same schema. The schema is canonical; everything
Expand Down
2 changes: 1 addition & 1 deletion content/docs/build/packages.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -51,7 +51,7 @@ pnpm dev

### From the UI

**Packages → New Package** — name, id, version, namespace.
**Studio → Packages → New Package** — name, id, version, namespace.

## Active package

Expand Down
21 changes: 18 additions & 3 deletions content/docs/configure/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,24 @@ You manage people and their permissions day to day; the applications,
objects, and permission sets themselves ship with the platform and the
app packages you install.

> **Permissions are designed in Studio, assigned in Setup.** Most
> administration never leaves Setup — you enter Studio only to author
> permission sets or to run the explain engine.
## Setup and Studio

**Permissions are designed in Studio, assigned in Setup.** That
sentence is the canonical statement of a split that runs through the
whole product, not a rule about permissions alone: Setup *operates* a
running deployment, Studio *authors* the metadata that deployment runs.
Both live inside the same UI at `/_console/`; neither is a surface of
its own.

| | Setup | Studio |
|---|---|---|
| Answers | Who is here, and what may they do? | What does this app consist of? |
| Where | `/_console/apps/setup` | `/_console/studio` |
| Gated by | `setup.access` | `studio.access` |
| For | System administrators | Implementers and developers |

Most administration never leaves Setup — you enter Studio only to
author permission sets or to run the explain engine.

## The Setup app

Expand Down
6 changes: 3 additions & 3 deletions content/docs/configure/permissions/index.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -161,9 +161,9 @@ applies uniformly across REST, ObjectQL, and the UI.
- The **explain engine** (`explain(principal, object, operation)`)
reports the verdict of every layer in order — required permissions,
object CRUD, field security, OWD baseline, sharing, row-level
security — with per-layer attribution. It surfaces as the
"Why can this user access?" panel. Explaining another user requires
the `manage_users` capability.
security — with per-layer attribution. Studio's **Access** pillar
surfaces it as the "Why can this user access?" panel. Explaining
another user requires the `manage_users` capability.
- `/_console/` shows the effective permissions of any user as they're
evaluated.
- Audit log (`sys_audit_log`) records permission-sensitive changes —
Expand Down
13 changes: 13 additions & 0 deletions content/docs/resources/glossary.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,19 @@ query time, compiled into row-level filters. A rule stored **without**
criteria shares nothing — it is not a match-all. See
[Record Access](/docs/configure/permissions/record-access#both-switches-fail-closed).

### Studio

The built-in metadata-authoring surface, at `/studio` inside the UI
served at `/_console/`, gated by the `studio.access` permission.
Where the metadata itself is *designed* — packages, objects, apps,
flows and permission sets — one package at a time, across four pillars:
Data, Automations, Interfaces, Access. Peer of **Setup**, not part of
it: Setup operates a running deployment (its people, their grants, its
configuration), Studio authors what that deployment runs — hence
**permissions are designed in Studio, assigned in Setup**. Unlike
Setup it is not an app under `/apps/`; the UI serves it as its own
route subtree. See [Administration](/docs/configure#setup-and-studio).

### Surface

One of the HTTP entry points a running ObjectOS exposes: `/` (REST API)
Expand Down