One information architecture viewed through three lenses. The lens sets summarisation depth; entitlements set scope. Five business areas and three cross-cutting capabilities sit on a shared object model and a provenance layer.
Read top to bottom. Each layer may use only the layers beneath it. Governance services are shared, so certification, materiality, clocks and the AI boundary behave the same on every page.
One ID lineage from signal to closure. Each object adds an accountable human element. Materiality governs whether an object reaches Core Group and Owner.
Attached to every Case and Incident: Action · Decision · Escalation · Evidence · Communication · Scenario · AI explanation · Audit entry. 13 incident states: see 09.
The navigation is identical in every lens (predictable). Each nav item resolves to the lens-appropriate route. Every lens × nav cell resolves to a landing route; there are no dead navigation items (v0.2, CX-06).
Global header (S-01): lens selector · permitted business/entity selector · reporting period · last refresh · search / Ask Control Tower · notifications · help · user profile. Route totals: Owner 8 · Core Group 10 · Entity 10 · Shared 13 (S-09 to S-13 pending D-20) = 41.
One breadcrumb component everywhere. A level the user is not entitled to is not rendered at all; it is never shown as a disabled crumb (D-12).
The full anatomy (1–10) applies to templates A–C. D–F adapt it as stated. No route may invent its own layout.