Files
aetherbound-guild/docs/03_PAGES_AND_UX.md
T

126 KiB

Aetherbound Guild - 50 Pages And UX

Development order, all player-facing pages, states, navigation, touch, controller, localization and accessibility.

Owner Review / Owner 审核

按玩家真实进入游戏的顺序开发并审核 50 个页面:启动、首次设置、标题首页、新游戏、市场、队伍、风险、战斗、结算和下一轮。每一步都必须能从启动页真实走到当前完成位置。

本文件是当前六份审核文档之一。历史拆分文件仅保留在 Git 历史中;文内规则、表格和 ID 仍是完整开发依据。

P0 Consolidation Role

This document is the player-facing page and interaction authority inside the consolidated project contract. Every page must name its purpose, focal order, primary action, state matrix, input/back path, localization behavior and accessibility contract. Product rules come from 01_GAME_DESIGN.md and 02_GAMEPLAY_AND_BALANCE.md; visual materials and asset standards come from 04_ART_ANIMATION_AUDIO.md.

UI-0A Component, Page And State Contract

Status: OWNER REVIEW REQUIRED / CODE FROZEN Companion visual contract: 04_ART_ANIMATION_AUDIO.md section UI-0A.

UI-0A.1 Page Contract

Every page specification must answer these questions before implementation:

Field Required answer
Purpose What player decision or understanding does this page own?
First read World/actor/object, current resource or next action; name all three in order
Primary action One legal action, with cost/target/consequence in the label or adjacent rail
Supporting information Only facts needed to make that decision; detail opens through Inspect
Back path Exact caller and whether draft/selection/receipt is preserved
States Loading, empty, available, selected, disabled, error, pending, success/receipt
Input Touch target, mouse, keyboard/controller focus and Back behavior
Responsive 760x360, 844x390, 1280x720, English/Chinese and 130% text
Evidence focused behavior, normal render and Owner visual review before next page

The page must remain a world scene first. A page may use one open frame or a small number of attached rails, but it may not become a nested card wall.

UI-0A.2 Canonical Page Templates

Template Primary visual Secondary visual Primary action
FIELD_ENTRY painted threshold/world concise status rail continue/new game/settings
MUSTER complete Recruit figures in one scene selected count and comparison rail select/inspect/compare
GUILD_DESK Company people and physical destination props next pressure and resources open Contract/Market/Roster
RECRUIT_REVIEW one complete Recruit and tool sourced facts, cost and before/after Company recruit/inspect/cancel
MARKET_LEDGER selected object/Recruit plus physical requisition compact repeatable offers inspect/review/purchase
PARTY_LINE four actors on one horizontal cord relation and threat rail reorder/save
BATTLE_FIELD complete line, enemy relation and corridor objective/playback/event rail observe/pause/speed/inspect
RESULT_RECOVERY causal result and affected Recruit retained state and next destination acknowledge/recover/continue

UI-0A.3 Button And Control Contract

Every action uses one of these semantic variants:

Variant Use Visual rule
PRIMARY next irreversible or progress-making action parchment/ivory field, one icon, explicit verb and cost/outcome
SECONDARY reversible inspect or alternate destination quiet open rail, lower contrast, distinct icon
BACK return to caller arrow/return object, never disguised as a primary action
INSPECT open reversible facts lens/eye/board mark plus text
SELECT choose an offer, Recruit or option selection ring/marker and selected text state
CONFIRM commit a reviewed receipt closed contour/seal, target and consequence adjacent
DESTRUCTIVE dismissal/delete/withdraw split edge and full consequence; neutral until review
DISABLED impossible or locked action intact silhouette, cross-pin and exact reason; no silent tap
PENDING receipt in flight fixed dimensions, named operation and input lock

All controls provide a minimum 48x48 logical target, visible keyboard/controller focus, pressed feedback, tooltip/Inspect for unfamiliar symbols and stable dimensions. A disabled control remains readable and explains the owning precondition. No button may be a rounded text rectangle when an authored object, portrait or familiar icon better communicates the action.

UI-0A.4 Text Contract

Text is engine-rendered and localized by semantic message ID.

Role Baseline Rule
Screen title 28-34px one page identity, no paragraph in the title slot
Section title 18-22px identifies the current decision region
Action label 16-18px explicit verb; include price/target when relevant
Body/consequence 14-18px explains one current fact and its implication
Caption 12-14px metadata only; never the sole state explanation
Value/delta 16-20px current value plus signed or before/after change

Letter spacing is 0; line height is stable; numeric values use tabular numerals. At 130% text, critical text wraps instead of ellipsizing. English and Simplified Chinese preserve the same action order and hierarchy.

UI-0A.5 Modal, Notice And Receipt Contract

State Must show Must not do
Loading named operation, blocked scope, progress if known leave active controls apparently clickable
Empty what is empty, why, legal next action show decorative art without a route forward
Error plain cause, retained state, Retry or safe return expose raw exception or silently reset
Notice one changed fact and optional Inspect stack duplicate transient messages
Confirmation target, before, after, cost, risk, retention and destination say only Are you sure?
Receipt stable operation, committed result and duplicate behavior celebrate before authority confirms

Modal focus starts on Cancel for destructive actions, traps keyboard/controller focus, supports Back/Esc, and restores the previous focus owner on close. A notice never covers the primary action, Back, playback controls or key values.

UI-0A.6 State Matrix

Every reusable component and page records these states:

loading -> available -> focused/hovered -> pressed
-> selected/compared -> pending -> committed/receipt
available -> disabled(reason)
available -> error(retained state, retry/safe return)

State meaning is carried by shape, icon, text and motion as well as color. The result must remain understandable with mute, reduced motion, reduced flashes, low power and color-vision differences.

UI-0A.7 Input And Responsive Contract

  • Touch/mouse activation uses the visible control bounds, not child text bounds.
  • Keyboard/controller focus enters the heading, then the primary content, then the footer; it never strands focus in decorative world elements.
  • Back pops one page/modal layer before requesting exit.
  • Safe-area insets are applied to every viewport change; no critical control touches an edge or home-indicator region.
  • Fixed boards, rows, portraits and buttons have stable minimum dimensions so text, focus and disabled states do not resize the layout.

UI-0A.8 DEV-1/2/3 Review Order

The first implementation slice is intentionally narrow:

UI-1A Boot
-> UI-1B First-launch setup
-> UI-1C Title
-> UI-1D Settings/Credits
-> UI-2A Muster choice
-> UI-2B Inspect/Compare/Review
-> UI-2C Company handoff
-> UI-3A Guild
-> UI-3B Contract Board
-> UI-3C Market/Recruit Review

Each slice stops for Owner visual review before the next slice is activated.

VA-1A Guild Anchor Scene Contract

The Guild anchor is a scene composition, not a generic VBox/HBox page shell. Its visual and interaction layers are:

Layer Content Interaction owner
World sky, ruins, route gate, ground and foreground cloth none
Company two or more complete Recruit figures, shadows, identity tags Recruit inspect target
Props Contract Board, Route Map, Guild Banner, Seal/Note Contract/Market destination controls
HUD compact Company/Contract/resource rail and bottom command rail engine-rendered values and controls
Text title, member identity, next action, disabled reason localization/message IDs
HitAreas stable Back, Contract, Roster, Settings and disabled Market bounds EntryShell navigation

The target first frame is 844x390 at 130% Chinese text. The minimum and maximum frames are 760x360 and 1280x720. The scene must preserve the Company focal read and the Contract prop when copy wraps or a destination is disabled. The current right-side utility panel and full-page frame are not part of this contract.

2026-08-17 Continuous-Growth Page Override

The current player order is Title -> New Game -> Initial Expedition Company -> Guild -> Contract. SYS-005 is the one-time Initial Company page, not a per-Contract run setup. It owns four stable provisional Recruit offers, exact two-of-four selection, inspect/compare, review/revise, atomic persistent-roster creation and a truthful Guild handoff. Contract and difficulty selection move to the later Guild flow and are outside DEV-2.

Across every page below, the Expedition Company and its recruited members, levels, XP, Professions, Traits, equipment and history persist across Contract runs. Zero HP is a current-battle knockout; the same Recruit is battle-ready again for the next stage. Product UI must say Knocked Out / 击倒 rather than permanent death. The exact next-stage HP amount remains a later balance decision.

Rows that still describe death review, Replacement Credit, Company collapse, roster archiving, ordinary New Run after every Contract or cleared-Recruit loss are FROZEN_LEGACY_FG4 page evidence pending their named later conversion. They do not override this section and are not authorized for new DEV-2 UI. DEV-2 implements only SYS-005 and the bounded post-commit Guild handoff; all later Guild, Market, battle, result and recovery pages remain frozen.

Aetherbound Guild Page Development Plan

Status: READY_FOR_OWNER_REVIEW Total canonical pages: 50 Orientation: landscape Visual authority: 04_ART_ANIMATION_AUDIO.md Detailed state authority: 03_PAGES_AND_UX.md

Where Development Starts / 从哪里开始

正式开发从 SYS-001 Boot and verification 开始,随后依次完成首次设置、 标题首页和基础设置。战斗页不再作为第一个孤立页面;它必须通过新游戏、 招募、自动排阵和风险确认的真实流程到达。

每个开发步骤都必须满足:使用真实 Godot 场景和运行代码、从启动页可达、 返回路径可用、没有看似可点但无反应的按钮,并在聚焦验证后提交和推送。

Development Waves

Wave A - 启动、首次设置与标题首页

先完成玩家打开游戏后实际看到的入口。页面必须采用日式 2D 手绘游戏构图, 不能继续使用卡片式 App 首页。

ID Page Required result
SYS-001 Boot and verification Illustrated loading state; failures remain game-branded and recoverable.
SYS-002 First-launch setup Language, safe area and accessibility with a live painted preview.
SYS-003 Title Immediate world/Company identity, Continue/New Game/Settings hierarchy.
SET-001 Settings index Clear categories and exact return to Title, Guild or Pause.
SET-002 Display and text Safe area, brightness, contrast and 100/115/130% preview.
SET-003 Motion, flashes and power Reduced motion/flashes, shake, hit pause, particles and low power.
SET-004 Audio and captions Music/ambience/SFX, mute, dynamic range, captions and event labels.
SET-005 Controls Touch, keyboard/mouse, controller, hold timing and vibration.
SET-006 Language and locale English/Simplified Chinese preview without changing run state.
SYS-008 Credits, licenses and data Authorship, licenses, privacy and offline behavior in a readable book view.

Wave B - 新游戏、公会与第一次招募

完成从标题页创建新游戏,到拥有第一支可用队伍的连续流程。

ID Page Required result
SYS-005 Initial Company Four equal stable generated offers, choose exactly two once, review, then create the persistent Expedition Company.
HUB-001 Guild desk World-first preparation hub showing pressure, Company and next action.
SHP-001 Market Recruit/item offers, affordability and current Company comparison.
SHP-002 Recruit review Profession, Trait benefit/cost, equipment, level and recruit consequence.

Wave C - 自动排阵、风险、战斗与结算

这一阶段完成首次 15-20 分钟核心体验,并成为第一份完整可玩 H5 验收版本。

ID Page Required result
PTY-001 Party line Choose members; system orders the line and previews reach/protection.
PTY-002 Readiness review Final automatic formation, warnings and reversible preparation summary.
RSK-001 Risk board Compare visible threat, uncertainty, reward and recovery exposure.
RSK-002 Risk commitment Confirm exact Party and known consequence before battle.
BAT-001 Battle opening Painted scene, formation, objective and first disclosed threat before motion.
BAT-002 Live battle Approved Japanese 2D composition with real melee, ranged, magic, healing, guard, damage and defeat events.
BAT-003 Actor/event inspect Pauseable causal inspection without covering the battle.
BAT-004 Pause and speed Compact overlay for resume, speed, log, settings and retreat entry.
OUT-001 Result and diagnosis Victory/loss, first decisive interaction and truthful downstream effect.
OUT-002 Knockout review Knocked-out Recruit identity, battle effect and next-stage return.
OUT-003 Reward choice Compare mechanically different rewards inside the same world style.
OUT-004 Stage recovery Result consequences and next-stage readiness with no same-battle return.

Wave D - 队伍经营与连续游玩

ID Page Required result
HUB-002 Forecast Upcoming pressure and information confidence integrated into the Guild world.
SHP-003 Item offer review One-item-slot comparison, eligibility, exact behavior and cost.
REC-001 Roster Scan persistent Company members, reserve state, readiness and history.
REC-002 Recruit detail Individual Profession, Trait, level/XP, item, position and survival history.
REC-003 Dismissal review Explicit permanent consequence, separate from run abandonment.
EQP-001 Equipment workbench Equip one item per Recruit with visible before/after behavior.
EQP-002 Item comparison Compare current/candidate item and affected battle rules.
ART-001 Artifact ledger Run-wide rules, interactions and acquisition, never a Recruit slot.
PRO-001 Company progression Persistent level, promotion, capacity and Contract choices.

Wave E - 存档、失败与恢复

ID Page Required result
SYS-004 Run ledger Save slots, run phase, play time, difficulty and health.
SYS-006 Resume review Exact safe phase and unresolved transaction before simulation resumes.
SYS-007 Save recovery Compare valid lineage, migration, conflict and known lost interval.
BAT-005 Retreat review Exact retreat losses, retained state and next destination.
BAT-006 Battle resume review Frozen timeline, pending events and legal playback state.
OUT-005 Contract result Failure/clear, retained Company growth, discoveries and next legal choice.
OUT-006 Contract withdrawal Voluntary expedition closure that never dismisses a Recruit.
SET-008 Save and data Save health, backups, export, conflict and diagnostics.
SET-009 Reset and deletion Separate destructive scopes with explicit review and recovery policy.

Wave F - 长期成长、结局与通关后玩法

ID Page Required result
PRO-002 Guild Charter Eight Region seals and breadth unlocks without permanent flat combat power.
PRO-003 Records and compendium Professions, Traits, equipment, Artifacts, enemies, Bosses and histories.
PST-001 First Chronicle decision Choose finite ending or open Oath Season after the sixteenth Boss.
PST-002 Oath Season hub Review compatible laws for the persistent Company's next Contract.
PST-003 Oath Season result Explain laws that mattered, Records/Renown and the next attempt.
SET-007 Gameplay information Forecast detail, reminders, log density and default speed.

Page Completion Definition

A page is complete only when all of these are true:

  1. normal, empty, loading, disabled, error and interruption states exist;
  2. its primary action, cost, consequence and return destination are truthful;
  3. Chinese/English, 130% text and all target landscape sizes fit;
  4. touch targets are at least 48 logical pixels and controller focus is valid;
  5. imported art matches the Japanese 2D direction at actual play size;
  6. state-changing motion and audio follow committed game events; and
  7. the page is reached through real navigation in a playable build.

Static HTML or an AI concept image can approve composition, but cannot mark a page implemented.

Aetherbound Guild: Screen And State Map

Authority: complete player-facing landscape navigation, page purposes, interaction states, onboarding, return paths, and endgame presentation.

Product source: 01_GAME_DESIGN.md and the three companion product system contracts.

Stage: design-only. This document specifies intended presentation; it does not claim implemented behavior, device validation, or human comprehension.

1. Experience Contract

Aetherbound Guild is operated through a repeatable decision path:

review pressure -> inspect offers -> recruit or dismiss when eligible -> equip -> reorder the party line -> choose risk -> observe automatic battle -> diagnose -> resolve knockouts and rewards -> adapt

Every player-facing screen answers six questions in its first viewport:

  1. Where am I in the run?
  2. What changed since I arrived?
  3. What decision is available now?
  4. What does that decision cost or expose?
  5. Can it be reversed?
  6. Where will Back return me?

The interface presents one primary action per decision region. Inspection is always reversible. Purchases, dismissal, risk commitment, retreat, reward selection, recovery expenditure, and destructive data actions show a review before they change authoritative state.

2. Integration Bindings

Presentation uses named bindings for values and rules owned by the product or content workstreams. A binding is displayed only after its source resolves; the UI must not substitute a guessed number, price, formula, or probability.

Binding Presentation use Owning authority Unresolved design state
BIND:RUN_PHASE current loop step and legal destinations core systems named phase plus Rules pending integration in design fixtures
BIND:DIFFICULTY_RULES run setup options, consequences, and postgame compatibility difficulty/core systems Begin remains disabled until resolved
BIND:PROVISIONAL_RECRUIT_OFFERS one stable four-offer set, generated Recruit fields, selected stable IDs, and Initial Company receipt recruitment/save SYS-005 cannot create a Company until exactly four unique complete offers resolve
BIND:RUN_RESOURCES balances, deltas, affordability economy label and non-numeric placeholder
BIND:SHOP_OFFERS available recruit and item offers shop/content structurally complete sample rows with no authoritative values
BIND:SHOP_REFRESH refresh cost, limit, result policy economy/shop disabled action with binding name
BIND:RECRUIT_TRANSACTION price, capacity effect, receipt recruitment/economy review skeleton with no commit
BIND:DISMISSAL_ELIGIBILITY total owned Recruits across deployed and reserve, operation restrictions, and disabled reason recruitment/core systems dismissal remains disabled until eligibility is verified
BIND:DISMISSAL_OUTCOME retained, returned, or lost value recruitment/economy consequence field marked unresolved
BIND:RECRUIT_SCHEMA name, profession, trait, attributes, one equipped item or null, individual level/XP, history content/core systems field labels remain; missing fields show Pending
BIND:EQUIPMENT_RULES one universal slot, forms, eligibility, conflicts, replacement result equipment/content incompatible reason requires source data
BIND:ARTIFACT_RULES active shared modifiers, acquisition, conflicts, and lifecycle artifacts/core systems ledger remains read-only until resolved
BIND:PARTY_CAPACITY current simultaneous deployment and growth progression/simulation count area displays binding, never a guessed cap
BIND:PARTY_ORDER_EFFECTS exposure, reach, protection, movement, replacement battle/core systems preview lists only sourced effects
BIND:RISK_OPTIONS risk choices, entry costs, known outcomes run/economy choice remains unavailable until resolved
BIND:BATTLE_SNAPSHOT actors, time, events, health, status, targets deterministic battle battle mock state is labeled non-authoritative
BIND:BATTLE_SPEEDS available playback speeds and restrictions battle/accessibility control renders from supplied options
BIND:RETREAT_OUTCOME timing, losses, retained state failure/economy review cannot commit while unresolved
BIND:CASUALTY_OUTCOME knockout, next-stage return and unchanged ownership/equipment failure/recruitment consequence list waits for receipt
BIND:RESULT_CAUSALITY first collapse and downstream effects battle validator Cause unavailable is an error, not an empty success
BIND:REWARD_OPTIONS choices, eligibility, claim receipt reward/content no generic fallback reward
BIND:RECOVERY_OPTIONS legal recovery paths, costs, consequences recovery/economy disabled path explains missing rule source
BIND:RUN_FAILURE Contract-ending condition and retained Company growth failure/save summary waits for authoritative transaction
BIND:RUN_ABANDONMENT explicit voluntary Contract-withdrawal consequence, receipt, and Guild destination failure/save action remains disabled until resolved
BIND:PROGRESSION unlocks, prerequisites, receipts progression/content unknown future nodes stay undisclosed
BIND:POSTGAME postgame rules, eligibility, modifiers difficulty/postgame entry remains locked with sourced requirement
BIND:SAVE_STATE slot health, resume point, migration, conflict save safe recovery path only

Binding failure is a presentation error with a safe exit. It never silently turns into zero cost, no consequence, a default target, or a successful claim.

3. Navigation And Shells

3.1 Global Navigation

Boot
|- First-launch setup
`- Title
   |- Continue -> Resume review -> last safe state
   |- New Game -> Initial Company -> Guild
   |- Run ledger -> Open Guild/Contract / Save recovery
   |- Records
   |- Postgame (when eligible)
   `- Settings / Credits / Licenses

Guild desk
|- Contract board -> Contract setup (DEV-3+)
|- Forecast
|- Shop -> Offer detail -> Recruit review / Item review
|- Roster -> Recruit detail -> Dismissal review
|- Equipment -> Item comparison
|- Party line -> Readiness review
|- Active artifacts / Progression / Records
|- Contract withdrawal review
`- Risk board -> Risk review -> Battle opening

Battle
|- Live automatic battle -> Inspect
|- Pause and speed -> Settings / Retreat review
|- Background or suspend -> Resume review
`- Result diagnosis
   |- Knockout resolution (when required)
   |- Reward choice (when earned)
   |- Recovery (when required)
   |- Contract withdrawal review (explicit player choice)
   |- Contract result summary (when ended)
   `- Guild desk / next risk choice

Postgame
|- Final boss settlement -> First Chronicle decision
|- Oath Season rules review -> Next Contract
|- Challenges and records
`- Oath Season result -> Oath Season hub / Final Ledger / persistent Guild

3.2 Shell Responsibilities

Shell Persistent information Primary surface Persistent exits
Title active language, accessibility shortcut, save health illustrated guild threshold and current Company/Contract summary Settings, run ledger, credits
Guild run phase, sourced resources, save state current preparation decision Shop, roster, equipment, party line, risk board
Battle objective, playback state, greatest current danger actors and event projections Inspect, pause; retreat only through review
Result outcome, earliest causal event, unresolved transactions causal timeline and affected recruits next required resolution only
Records filter, discovery state, selected entry readable catalog or history previous safe screen
Settings changed values and current category live preview or setting rows Apply/Discard and exact caller

Back closes only the top overlay. From a base screen it returns to the named parent in the inventory below. Back never commits, claims, purchases, equips, reorders, dismisses, retreats, or starts a battle.

3.3 Overlay Order

Only the top layer owns input:

base screen -> inspect drawer -> selection surface -> transaction review -> confirmation

A confirmation may not open another confirmation. A system interruption closes no layer until the operation result is known. When focus returns, it returns to the invoking control or the nearest still-valid sibling.

4. Input Profiles

Each inventory row names one profile. Mouse and keyboard use the controller focus order plus pointer shortcuts; no workflow depends on hover.

Profile Touch Controller Focus and cancel rule
NAV tap destination; horizontal swipe is optional directional focus; shoulder buttons change top-level destination focus enters heading then primary content; Cancel returns to parent
LIST tap row; drag scroll; long press opens the same inspect action vertical focus; left/right changes defined filter or comparison target virtualization preserves logical focus by stable item ID
SELECT tap option then explicit action focus option, South selects, South on primary commits review selection is not commitment; Cancel clears selection first
ORDER tap Recruit then destination; drag is optional; left moves toward protected rear and right toward exposed front select Recruit, move focus left/rear or right/front, confirm destination; bumpers shift one logical position undo is available until readiness commitment; position 0 remains the rightmost exposed front
BATTLE tap actor/event to inspect; dedicated pause and speed controls bumpers cycle actors/events; face buttons open inspect and pause focus never enters moving world elements; closing inspect resumes prior playback state
MODAL tap explicit action; destructive hold duration is setting-aware focus starts on Cancel; destructive action requires second explicit input or hold Cancel spends nothing and returns focus to invoker
SETTINGS native toggle, segmented control, slider, menu, remap row predictable row navigation; left/right adjusts; South activates uncommitted changes prompt Apply/Discard on exit

Input-device change during selection, ordering, remapping, or confirmation freezes the transaction and shows the equivalent controls for the new device. No resource is spent and no selection is lost.

5. Complete Screen Inventory

The tables are normative. Empty / loading, Error / confirmation, and Interruption / return are required for every listed screen, including pages that are not expected to be empty during ordinary play.

5.1 Boot, Title, And Runs

ID / screen / input Purpose Primary action and consequence Empty / loading Error / confirmation Interruption / return
SYS-001 Boot and verification / NAV Verify rules, content, settings, and BIND:SAVE_STATE before exposing a run. None; proceed only after all required sources are valid. Empty install shows required local content status. Loading names the current verification step and progress. Recoverable source failure offers Retry; unsafe mismatch offers diagnostics and Exit. No confirmation. Suspend resumes verification from a safe checkpoint. Return exits to platform only before Title is legal.
SYS-002 First-launch setup / SETTINGS Establish language, safe area, 100/115/130% text, contrast, reduced motion/flashes, captions, and input prompts. Apply settings; writes preferences only. Missing locale falls back to sourced English text and names the missing pack. Loading renders the preview inline with text status. Invalid safe area or unavailable output is explained. Apply review lists changed accessibility settings. Device change refreshes prompts without reset. No Back until one usable preset has been applied; later visits return to caller.
SYS-003 Title / NAV Identify the game, current safe resume state, save health, and legal entry paths. Continue opens SYS-006; New Game opens SYS-005 only when no persistent Company exists. No Company promotes New Game. A saved draft resumes the same four offers; an existing Company disables New Game with a truthful reason. Loading keeps Settings usable. Save warning links to SYS-007; offline optional service warning does not block local play. No confirmation. Suspend returns to the same selection. Back invokes platform exit review; child pages return here.
SYS-004 Run ledger / LIST Inspect run slots, last safe state, play time, difficulty, and health. Open selected run; opens resume or recovery review. No runs explains New Run. Loading uses per-slot skeletons with slot names retained. Corrupt, incompatible, conflict, and migration states name their safe next action. Delete and overwrite require SYS-005 or SET-009 review. Refresh or cloud interruption keeps the last verified local list. Back returns to Title.
SYS-005 Initial Company / SELECT Inspect and compare four stable provisional generated Recruit offers and choose exactly two at no Coin cost before the Guild exists. With exactly two selected, Review Company opens the creation review; Create Company commits those two stable Recruit IDs once, discards only the two provisional unchosen offers and opens the bounded Guild handoff. Empty or non-four offer output is invalid, not a legal empty choice. Loading shows four fixed positions, the named operation and no selectable identity until its stable ID and required fields resolve. Duplicate IDs, missing Profession/Trait cost, stale offer-set revision, existing-Company conflict or creation failure blocks commit with retained safe setup. Review names both selected Recruits, both unchosen offers, no-Coin cost and Revise Recruits; zero, one, three or four selected cannot open review. Touch and controller can inspect, compare, toggle, revise, cancel and create without drag. Suspend preserves the verified offer-set ID and selected stable IDs without creating a Company; resume revalidates the same set. Back before commit returns to Title; interruption after receipt resumes at the Guild handoff.
SYS-006 Resume review / SELECT Explain current phase, last committed transaction, unresolved consequence, and resume destination. Resume; enters the exact safe state from BIND:SAVE_STATE. No active run offers Run Ledger. Loading shows the saved destination name. Invalid snapshot routes to Save Recovery. Resuming battle requires explicit review of playback state. Suspend changes nothing. Back returns to Title or Run Ledger, whichever invoked it.
SYS-007 Save recovery / SELECT Compare valid save lineage, migration, conflict, and known lost interval. Load selected valid state; changes active lineage and records a receipt. No valid recovery offers diagnostics and safe deletion path. Loading validates and names each candidate. Failed recovery cannot overwrite the last valid source. Selection review lists timestamp, ruleset, lost interval, and reversibility. Suspend retains candidates but makes no choice. Back returns to Run Ledger.
SYS-008 Credits, licenses, and data notice / LIST Present authorship, licenses, privacy, local/offline behavior, and external-link policy. Open section; no run consequence. No search result offers Clear Search. Loading long text retains the current local section. Missing license is a blocking production defect with diagnostics. External links require destination confirmation. Suspend preserves scroll position. Back returns to the invoking Title or Settings screen.
5.1.1 SYS-005 Staged-State Contract

SYS-005 is one player-facing page with staged states. Stage changes preserve the page ID, safe-area layout, offer-set ID, selected stable IDs, and focus history; they do not create hidden pages or increment the 50-page inventory.

Stage First-viewport surface Primary action Required boundary and return
A Four-offer choice four equally weighted stable offer markers; generated name, base Profession job, Trait benefit/cost, five attributes, starting item state, No Coin cost; selected count 0/2..2/2 Review Company, enabled only at 2/2 Inspect changes no selection; Compare accepts any two offer IDs; selecting a third is rejected until one current selection is cleared; Back returns to Title
B Creation review the two selected Recruits together, two explicitly unchosen offer IDs, no-Coin transaction and persistent-Guild consequence Create Company Revise Recruits returns to stage A with the same four offers and two selections; Cancel changes nothing
C Pending creation stable two-Recruit summary, named creation operation and progress none while pending duplicate Create input returns the original pending state; failure returns to stage B with no Company and no changed offer set
D Receipt and handoff created-Company receipt, selected two as the owned Expedition Company and the next truthful Guild boundary Enter Guild the two unchosen provisional offers are not retained; Contract and Market actions clearly state that DEV-3 has not implemented them

Every offer exposes BIND:RECRUIT_SCHEMA through one common comparison order: generated name, base Profession job and target/reach responsibility, Trait benefit, Trait cost, rolled attribute distribution, default Profession equipment, and stable offer ID. Rarity, portrait prominence, offer position, animation, or a tutorial highlight cannot imply a recommended opening pair.

Required invalid and interruption states:

  • zero, one, two, three, or more than four returned offer rows are an invalid source result; the page shows expected 4, received count, Retry Same Set, and Return to Title, with Create Company unavailable;
  • duplicate stable IDs, unresolved Profession, unresolved Trait benefit/cost, or incompatible content revision marks the affected offer and blocks all selection commitment;
  • before any stable IDs resolve, loading reserves four positions but exposes no generated identity; after an ID resolves, sort/filter/animation cannot move it to another position;
  • suspending stages A or B stores no Company-creation receipt. Resume restores the same verified offer-set ID, selections, comparison pair, and focus. If that set cannot be verified, a recoverable error replaces the choice; the UI never silently rolls four new offers; and
  • LOC:PROVISIONAL_SELECTED_COUNT, LOC:PROVISIONAL_NO_COIN_COST, LOC:PROVISIONAL_UNCHOSEN_NOT_RETAINED, LOC:REVISE_PROVISIONAL_RECRUITS, and every Profession/Trait comparison require English (en) and Simplified Chinese (zh_CN) fixtures at 100/115/130% without obscuring selection, Inspect, Compare, Back, or Create Company.

5.2 Guild, Shop, And Recruits

ID / screen / input Purpose Primary action and consequence Empty / loading Error / confirmation Interruption / return
HUB-001 Guild desk / NAV Show current pressure, preparation readiness, latest outcome, resources, and all preparation destinations. Open Risk Board when ready; navigation itself changes nothing. First run uses a compact opening decision prompt. Loading each status region leaves destinations usable. Missing mandatory binding blocks only its dependent destination and names the owner. No confirmation. Suspend records no new transaction. Child pages return here with the changed field highlighted.
HUB-002 Forecast / LIST Explain upcoming known threats, opportunities, deadline, and information confidence. Track pressure; changes the Guild desk summary only. No optional forecast still shows the mandatory next pressure. Loading preserves last verified forecast with timestamp. Stale or incomplete forecast labels uncertainty instead of inventing certainty. Tracking needs no confirmation. Suspend preserves filters. Back returns to Guild desk.
SHP-001 Shop / LIST Compare BIND:SHOP_OFFERS, affordability, roster/equipment fit, and refresh consequence. Inspect offer; purchase is never performed from the list row. Sold out explains next sourced restock. No matching filter offers Clear Filters. Loading keeps balances visible and rows inert. Stale, duplicate, or unavailable offers refresh before review. Refresh and any paid action require exact cost confirmation. Suspend cancels no verified purchase and polls receipts on resume. Back returns to Guild desk.
SHP-002 Recruit review / SELECT Evaluate generated name, profession, trait benefit/cost, rolled attributes, one starting item, individual level/XP, survival history, price, and party impact. Recruit; commits BIND:RECRUIT_TRANSACTION after review. Missing roster comparison states which binding is pending. Loading shows stable recruit identity, never a substitute recruit. Offer expired, insufficient value, invalid capacity, or duplicate receipt keeps the prior state. Confirmation states exact Recruit, level, starting item, cost, capacity effect, and undo policy. Suspend after commit checks receipt before retry. Cancel returns to Shop on the same stable offer ID.
SHP-003 Item offer review / SELECT Explain item behavior, eligible recruits, owned conflicts, price, and likely party effect. Buy; adds the item according to sourced inventory rules. No eligible recruit is informative, not an error. Loading retains item identity and offer price timestamp. Expired, unaffordable, full-policy, or duplicate claim states preserve balance. Confirmation lists cost, destination, and conflict. Suspend reconciles the transaction receipt. Cancel returns to Shop on the offer.
REC-001 Roster / LIST Scan all persistent Recruits, deployed status, Profession, Trait, readiness, equipment issue and battle history. Inspect Recruit; changes nothing. Zero owned Recruits is invalid outside pre-Company setup or explicit deletion recovery; it never results from battle. No filter match offers Clear Filters. Loading uses stable roster order. Binding failure preserves last verified summary and blocks dependent edits. No confirmation. Suspend preserves selection and filters. Back returns to Guild desk or the required recovery screen.
REC-002 Recruit detail / NAV Read one Recruit's sourced identity, mechanical history, current role, equipment, position, and legal actions. Open Equip or Party Line; navigation changes nothing. Dismiss is a separate destructive action. Missing optional history states No recorded battles. Loading keeps name, stable ID, and the last verified BIND:DISMISSAL_ELIGIBILITY. Deleted/stale Recruit returns to Roster with explanation. When total live Recruits across deployed and reserve equals one, Dismiss remains visible but disabled with One member must remain; its explanation directs the player to the separate Run Abandonment Review. Suspend preserves the selected tab. Back returns to Roster and its prior scroll position.
REC-003 Dismissal review / MODAL State exactly what leaves the run, what is retained, affected party/equipment references, verified eligibility, and BIND:DISMISSAL_OUTCOME. Dismiss Recruit; permanently applies the sourced transaction only after eligibility is revalidated. If dismissal is already illegal, the review does not open; Recruit Detail shows the disabled reason and abandonment route. Loading must verify current total live Recruits before the destructive action enables. Confirmation uses generated name, stable ID, outcome, and an explicit destructive gesture. If a stale confirmation is submitted after the total live count falls to one, reject and close the review with no Recruit mutation and no rebate; Recruit Detail shows One member must remain and the separate abandonment action. Suspend before commit cancels nothing; after commit verifies receipt. Cancel returns to Recruit Detail.

5.3 Equipment And Party Preparation

ID / screen / input Purpose Primary action and consequence Empty / loading Error / confirmation Interruption / return
EQP-001 Equipment workbench / LIST Equip a selected Recruit while showing individual level/XP, its one universal slot, eligible inventory and sourced behavior changes. Equip selected item; atomically returns the prior item or null and changes the one slot only after comparison review. No owned items points to Shop. No eligible item explains Profession/form requirements. Loading retains the current slot. Incompatible, already used, stale inventory, or ruleset error blocks commit with reason. Confirmation states the returned prior item, one-slot result, conflicts, and before/after behavior. Suspend before receipt keeps the old item; resume reconciles receipt. Back returns to Recruit Detail or Party Line caller.
EQP-002 Item comparison / SELECT Compare the one current item and candidate in the vocabulary used by party preview, battle, and results. Apply candidate; returns to workbench with changed effects and returned prior item highlighted. Empty candidate keeps current item and offers Choose Item. Empty current slot is explicit. Loading never clears current values. Unknown derived effect is labeled unresolved and blocks Apply when consequence-critical. Confirmation lists the exact old/new item IDs and affected saved plan references. Suspend keeps comparison but performs no equip. Back returns to Equipment with selection intact.
ART-001 Active artifact ledger / LIST Inspect run-wide artifact rules, acquisition source, interactions, conflicts, and lifecycle without treating them as recruit equipment. Inspect artifact; changes nothing unless BIND:ARTIFACT_RULES supplies a separate legal action. No active artifacts explains their sourced acquisition route. Loading retains verified active rules. Missing or conflicting artifact references identify stable IDs and block dependent commitment. Any lifecycle-changing action requires a separate sourced confirmation. Suspend preserves selection. Back returns to Guild desk or the Reward caller.
PTY-001 Party line / ORDER Select simultaneous Recruits on one visual line from protected rear at left to exposed front at right, with position 0 at the front and larger numbers extending leftward; preview sourced targeting, protection, reach, healing, movement, and replacement changes. Save order; changes the prepared party snapshot but does not start battle. Zero live Recruits is a casualty/Company-collapse settlement state and routes to sourced recovery or run close; ordinary dismissal never creates it. No eligible deployable Recruit explains the recovery or roster reason. Loading preserves last committed order and rear-left/front-right endpoints. Invalid count, duplicate Recruit, incompatible state, or stale capacity identifies the exact numbered position. Confirmation is required only when removing a currently prepared Recruit has a sourced consequence. Suspend stores only the last committed order; uncommitted moves are offered to Restore or Discard. Back returns to Guild desk.
PTY-002 Readiness review / SELECT Summarize the frozen rear-left/front-right order, position numbers, protection contributors toward the right/front, equipment issues, known pressure coverage, Reserve state, and BIND:PARTY_CAPACITY. Accept preparation; records a reviewable battle-plan snapshot. Empty party blocks acceptance and points to Add Recruits. Loading verifies all stable IDs without reversing visual order. Invalid or outdated effect opens the owning edit screen. Confirmation states warnings that are allowed but does not overstate outcome prediction. Suspend preserves the last accepted snapshot. Back returns to Party Line.
RSK-001 Risk board / SELECT Compare sourced risk options by known pressure, uncertainty, entry cost, reward class, recovery exposure, and current party coverage. Review selected risk; selection alone changes nothing. No legal option explains whether preparation, progression, or recovery is required. Loading retains accepted party summary. Unresolved or stale option cannot be committed. No confirmation until RSK-002. Suspend preserves selection only locally. Back returns to Guild desk.
RSK-002 Risk commitment / MODAL Present the chosen option, known threats, uncertainty, cost, reward class, retreat implication, and frozen party snapshot. Begin battle; commits the sourced risk transaction and opens Battle Opening. Missing party snapshot or option returns to the owning screen. Loading verifies all dependencies. Stale resources, changed recruit state, or invalid rule reopens the changed source. Confirmation is the page's purpose and names irreversible effects. Suspend before receipt changes nothing; after receipt resumes at Battle Opening. Cancel returns to Risk Board.

5.4 Automatic Battle

ID / screen / input Purpose Primary action and consequence Empty / loading Error / confirmation Interruption / return
BAT-001 Battle opening / BATTLE Establish objective, the visible No combat respawn / no Reserve auto-entry rule, player order from protected rear at left to position 0 exposed front at right, enemy-facing direction, first known threat, playback speed, and inspection affordance. Start observation; releases the deterministic timeline. Missing actor data blocks start and names the binding. Loading shows verified actor silhouettes, position markers, and progress. Snapshot mismatch returns safely to Risk Commitment or Resume Review. Start needs explicit input only on first onboarding or resumed state. Suspend preserves an unopened snapshot. Back is disabled after risk commitment; Pause offers legal exits.
BAT-002 Live battle / BATTLE Make automatic resolution readable: current objective, permanent encounter casualty rule, urgent cause, actor state, target relation, event sequence, pause, speed, inspect, and retreat access. Inspect the highlighted cause; battle decisions are diagnostic controls only. No current event shows Waiting for next event, not a blank field. Loading occurs only during safe resume and the timeline does not advance. Invalid event data pauses and offers Retry Snapshot or Safe Exit. Speed change needs no confirmation; retreat is separated. Backgrounding or device loss freezes according to save rules and routes to BAT-006. Closing inspect restores the prior legal playback state.
BAT-003 Actor and event inspect / BATTLE Explain selected actor, action, target, status source, order interaction, equipment contribution, and causal neighbors. Pin event or close; changes no battle result. No related event states why. Loading pauses inspect data at the selected event ID. Hidden information states the discovery rule; missing required cause pauses with diagnostics. No confirmation. Suspend routes to Resume Review with the selected event remembered. Back closes inspect to Live Battle.
BAT-004 Pause and speed / BATTLE Freeze observation where rules allow, expose playback options, settings, event log, controls, and retreat entry. Resume; restores the selected legal speed. No speed alternatives shows one sourced speed. Loading settings does not resume time. Disallowed speed explains the rule. Applying settings may require its own Apply/Discard review. App suspend remains paused. Back resumes only when the player explicitly chooses Resume; Settings returns here.
BAT-005 Retreat review / MODAL State BIND:RETREAT_OUTCOME, timing, interruption rule, affected recruits, losses, retained state, and next destination. Begin retreat; commits only after the full consequence is sourced. Unavailable retreat shows exact condition and Close. Loading keeps battle paused. Stale outcome refreshes before confirmation; duplicate input returns the original receipt. Confirmation uses explicit Begin retreat. Suspend before commit returns to Pause; after commit resumes the retreat resolution snapshot. Cancel returns to Pause.
BAT-006 Battle resume review / SELECT Explain saved time, playback state, pending events, latest committed receipt, and whether retreat resolution is active. Resume from verified snapshot; never resumes in motion without review. No resumable battle routes to the last safe Result or Guild state. Loading validates the snapshot. Invalid snapshot uses save recovery and never starts a partial simulation. Resume confirmation states current speed and pause behavior. Repeated suspend leaves the battle frozen. Back returns to Title without discarding the snapshot.

5.5 Result, Knockout, Reward, And Recovery

ID / screen / input Purpose Primary action and consequence Empty / loading Error / confirmation Interruption / return
OUT-001 Battle result and diagnosis / LIST Show outcome, first meaningful divergence, decisive interaction, downstream costs, survivor state, and available next resolution. Continue to the earliest unresolved consequence. No preventable cause states No actionable divergence and still shows decisive events. Loading preserves outcome receipt. Missing causal data is an explicit diagnostic error; transaction remains paused. No confirmation. Suspend preserves the result receipt and scroll position. Back does not bypass unresolved consequences.
OUT-002 Knockout review / SELECT Name each knocked-out Recruit, stable identity, Profession, Trait, level, battle history, unchanged equipment ownership, current-battle gap and next-stage return. Acknowledge the committed battle consequence; advances to Reward, Recovery or Contract Result. No knockouts skips this screen. Loading renders known identities before consequence details. Incomplete outcome receipt blocks acknowledgement and offers Retry. Confirmation acknowledges an already committed result; it does not imply deletion or same-battle return. Suspend preserves unresolved acknowledgement. Back returns to Result diagnosis but cannot alter battle outcome.
OUT-003 Reward choice / SELECT Compare BIND:REWARD_OPTIONS by changed decision, eligible target, conflicts, and run impact. Claim selected reward; commits one sourced receipt. No earned reward explains the result and offers Continue. Loading preserves result context. Expired, ineligible, duplicate, or storage-policy state returns a deterministic next action. Confirmation names reward, target, conflicts, and skip outcome. Suspend checks receipt before retry. Cancel returns to Result only if reward choice is not mandatory.
OUT-004 Stage recovery / SELECT Explain next-stage readiness, any sourced recovery choice and the unchanged persistent roster. Commit an optional sourced recovery choice; otherwise Continue returns the same Recruit IDs to the next planning state. No optional recovery shows Continue. Loading retains knockout and resource facts. Unaffordable, stale or illegal optional paths remain inspectable with reason. Confirmation lists the full transaction and next destination. Suspend before receipt spends nothing; after receipt resumes at its destination. Back returns to Result or Knockout Review.
OUT-005 Contract result / LIST Explain BIND:RUN_FAILURE or clear, retained Company growth, knockouts, discoveries, decisions unlocked and exact next choices. Finish Contract; closes Contract-local state, applies the verified progression receipt and returns the persistent Company to the Guild. No progression gain is stated plainly. Loading waits for all receipts before enabling Finish. Duplicate or failed progression application preserves the Contract as unresolved. Finish confirmation is needed only if viewing unresolved optional pages would be lost. Suspend preserves the unresolved summary. Back remains within summary tabs; Finish returns to Guild or Progression.
OUT-006 Contract withdrawal review / MODAL Keep explicit voluntary Contract closure separate from Recruit dismissal and state every consequence from BIND:RUN_ABANDONMENT. Withdraw; closes Contract-local state through one sourced receipt without selecting or dismissing a Recruit. If withdrawal is not legal from the current state, show the reason and safe return. Loading verifies closure consequences before enabling the action. Confirmation names the Contract, cleared Contract-local state, retained Company/resources/history, Guild destination and irreversibility; default focus is Cancel. A stale or duplicate operation returns a readable rejection or original receipt without partial closure. Suspend before commit changes nothing; after commit verifies the closure receipt. Cancel returns to Guild desk or Result, whichever invoked it.

5.6 Progression, Records, And Postgame

ID / screen / input Purpose Primary action and consequence Empty / loading Error / confirmation Interruption / return
PRO-001 Run progression / LIST Show current level paths, profession changes, capacity growth, prerequisites, and decisions opened within the active run. Inspect or apply a legal sourced choice. No pending choice shows next prerequisite. Loading retains current applied state. Stale prerequisite or invalid choice refreshes before commit. Irreversible branch or reset uses explicit comparison confirmation. Suspend reconciles any receipt. Back returns to Guild desk or Result caller.
PRO-002 Guild Charter / LIST Show current Renown, eight horizontal Region seals, prerequisite tracks, breadth-only packet cards, exact costs, future-run effects, and claimed receipts without resembling a radial power tree. Tap a Region seal, Tap one eligible packet, then review and claim it; the receipt changes future-run catalog, trial, threat-information, or Oath-law breadth and never raw power. First-run state explains how Renown is earned and keeps all eight seals visible. Loading reserves stable claim IDs and disables packet selection until cost, prerequisites, and effect resolve. Unknown content stays undisclosed. Failed prerequisites and insufficient Renown preserve selection with reasons; duplicate claim returns its receipt. Confirmation shows before/after Renown, prerequisites, future-run effect, and No permanent combat power. Suspend retains selected Region, packet and scroll anchor. Back before commit spends nothing; after commit it verifies the receipt and returns to Title, Guild, or Run End caller.
PRO-003 Records and compendium / LIST Browse professions, traits, equipment, artifacts, enemies, bosses, regions, recruit histories, and battle reports without spoilers. Inspect entry; changes no run result. Category empty states discovery route when allowed. No search result offers Clear Search. Loading keeps category context. Missing referenced entry reports stable ID and diagnostics. Inspection requires no confirmation and external links do not exist here. Suspend preserves category, filter, and scroll ID. Back returns to caller.
PST-001 First Chronicle decision / SELECT After the sixteenth boss and verified settlement, compare Complete the First Chronicle with Open the Oath Season; state that both retain the persistent Expedition Company. Tap one choice, review its destination, then confirm: Chronicle shows the finite ending/Final Ledger and returns to the Guild/Title boundary; Oath Season opens postgame rule review for the same Company. Before final eligibility, show the exact remaining boss requirement while ordinary Contract play remains visible. Loading keeps the verified final-boss receipt and disables both commits. Missing settlement, unresolved knockout/reward or stale first-clear state blocks both choices. Confirmation repeats the retained Company, persistent resources/Records/Renown and destination with no Recruit duplication or deletion. Suspend retains the uncommitted choice and final receipt. Back stays in final result. After receipt, resume at Final Ledger/Guild or Oath Season hub; never reopen the settled Contract.
PST-002 Oath Season hub and Contract review / SELECT Compare eligible Oath laws, conflicts, known consequences, difficulty, Guild Charter breadth and the next Contract. Tap laws to assemble a compatible set, review the complete rules, then begin a Contract with the persistent Expedition Company. No eligible law explains its Charter requirement and still offers ordinary Contract play. Loading verifies modifier, profile and Contract IDs before Begin. Conflict, expired ruleset, missing eligibility or active-Contract collision preserves selection with reasons. Confirmation lists every active law, difficulty, persistent-Company promise and irreversible Contract setup choice. Suspend saves the uncommitted form. Cancel returns to Guild/postgame hub. Interruption after receipt opens the committed Contract boundary.
PST-003 Oath Season result / LIST Explain challenge outcome, laws that mattered, Record change, earned Renown, retained Expedition Company and next legal Contract. Finish result; applies verified Record/Renown receipts and returns to the Oath Season hub, Final Ledger or Guild. No Record or Renown change is stated plainly. Loading waits for all receipts and preserves ordinary Contract access. Duplicate or invalid score is separated from local clear status. Finish confirmation appears only while a claim remains unresolved. Suspend preserves the result. Back stays within result tabs; Finish returns the same Company to the Guild.

5.7 Settings And Data

ID / screen / input Purpose Primary action and consequence Empty / loading Error / confirmation Interruption / return
SET-001 Settings index / SETTINGS Navigate Display/Text, Motion/Effects, Audio/Captions, Controls, Language, Gameplay Information, Save/Data, and Reset. Open category; no run consequence. No changed settings shows current preset. Loading categories does not block Back. Invalid stored setting uses documented safe default and identifies it. No confirmation. Suspend preserves selected category. Back returns to exact caller: Title, Guild, or Pause.
SET-002 Display and text / SETTINGS Set safe area, brightness, contrast, color-independent cues, and 100/115/130% UI/text with live preview. Apply display settings. Unavailable display option remains visible with reason. Preview loading shows text sample. Unsupported combination offers nearest supported result without auto-applying. Apply/Discard review appears on exit with changes. Output change freezes preview and retains values. Return to Settings index.
SET-003 Motion, flashes, and power / SETTINGS Set reduced motion, reduced flashes, shake, hit pause, particle density, and low-power behavior with a non-combat sample. Apply effects settings. Unsupported effect control explains platform behavior. Sample loading never flashes. Unsafe or unavailable combination reverts preview only. Apply/Discard on exit. Backgrounding stops sample. Return to Settings index.
SET-004 Audio and captions / SETTINGS Set master/music/ambience/SFX/voice-when-present levels, mute, dynamic range, captions, event labels, and mono-compatible cues. Apply audio settings. Missing output or absent voice category is stated. Test loading is silent with visible status. Output failure keeps captions and visual cues active. Apply/Discard is the exit confirmation. Output change pauses test and retains settings. Return to Settings index.
SET-005 Controls / SETTINGS Inspect and remap touch, keyboard/mouse, and controller actions; set hold timing and vibration. Save mapping. No controller attached still permits mapping inspection. Loading keeps safe Cancel binding. Conflict names both actions and requires resolve; essential actions cannot be left unbound. Save confirmation lists changed mappings. Device loss pauses capture and spends no input. Return to Settings index after Apply/Discard.
SET-006 Language and locale / SETTINGS Select English or Simplified Chinese and preview mechanics, dates, numbers, and wrapping. Apply language; reloads localized text without changing run state. Missing optional locale pack names the fallback. Loading uses current language until complete. Invalid string key shows stable diagnostic ID, not raw code in player copy. Apply confirmation appears when a reload is required. Suspend resumes the reload safely. Return to Settings index in the applied language.
SET-007 Gameplay information / SETTINGS Set forecast detail, tutorial reminders, battle log density, default speed, and other information assists without hiding result-changing rules. Apply information settings. Unavailable option states dependency. Preview loading uses a fixed non-authoritative sample. Disallowed combination explains the rule. Apply/Discard on exit. Suspend stops preview only. Return to Settings index.
SET-008 Save and data / SETTINGS Inspect local save health, optional synchronization, conflicts, backups, export, and diagnostics. Open selected management action; routine inspection changes nothing. Offline state keeps local status and names queued optional work. Loading shows last verified timestamp. Conflict and recovery use SYS-007; export failure retains local data. Replacing a lineage requires full comparison confirmation. Suspend pauses external work and keeps a durable receipt. Return to Settings index.
SET-009 Reset and deletion / MODAL Separate run deletion, profile reset, settings reset, and diagnostics clearing with exact scope and recovery policy. Execute reviewed destructive action. No eligible data disables the action with reason. Loading inventory must finish before review. Write failure preserves data. Confirmation names scope, stable target, retained data, recovery window, and explicit destructive gesture. Suspend before receipt cancels nothing; after receipt verifies outcome. Cancel returns to Settings index.

6. Global State Rules

6.1 Loading And Empty

  • Operations longer than 300 ms show the named operation and whether input is blocked. An apparently tappable control never sits under an unlabeled spinner.
  • Lists retain stable headers, selected IDs, and known balances while rows load.
  • Filter-empty and truly empty are distinct. Filter-empty always offers Clear Filters; truly empty explains the legal way content becomes available.
  • Unknown, undiscovered, unavailable, unaffordable, incompatible, full by a sourced rule, and completed are distinct states with distinct next actions.

6.2 Error And Receipt

  • Every commit has an operation ID and resolves to one receipt. Retry never duplicates purchase, recruit, dismissal, equip, reward, progression, recovery, retreat, or run completion.
  • A stale review refreshes all changed values and requires a new explicit confirmation. It never commits the old preview.
  • A binding error states the affected feature and safe next action. Raw stack traces, credentials, paths, and internal tokens are excluded from player copy.
  • Offline optional services cannot block local run play.

6.3 Interruption And Save

  • Backgrounding during battle produces or verifies a deterministic snapshot and returns through BAT-006; time never advances behind an obscured app.
  • Backgrounding during any transaction returns through receipt reconciliation.
  • A low-memory restart returns to Title with the exact resumable state named.
  • Clock rollback, cloud divergence, migration, corruption, duplicate claims, rollback, and bounded offline behavior are presented through SYS-007 or SET-008 using sourced save rules.

6.4 Final-Survivor Dismissal And Abandonment

  • Dismissal eligibility uses the authoritative total of live Recruits across deployed and reserve. It does not use only the current party-line count.
  • When that total equals one, REC-002 keeps Dismiss visible but disabled. The reason says One member must remain and exposes a separate action to open OUT-006; activating the disabled control never opens REC-003.
  • REC-003 revalidates eligibility at commit. If a once-valid review becomes stale because the total is now one, confirmation is rejected and the review closes. No Recruit is removed, no equipment ownership changes, no rebate is granted, and focus returns to the disabled Dismiss state with the reason announced.
  • OUT-006 is a run-close transaction, not a dismissal variant. It has no selected Recruit target and cannot grant a dismissal rebate.
  • A zero-live-Recruit state can result only from committed casualty/Company- collapse settlement or explicit run abandonment. Casualty settlement routes to sourced recovery or closure; abandonment routes directly to OUT-005 and never exposes an empty preparation or Shop state. Ordinary dismissal cannot produce either path.
  • LOC:DISMISS_LAST_LIVE_RECRUIT and LOC:OPEN_RUN_ABANDONMENT_REVIEW require English (en) and Simplified Chinese (zh_CN) fixtures at 100/115/130%. The first preserves one member must remain; the second preserves the distinction between leaving one Recruit and ending the entire run.

7. Onboarding Map

Onboarding uses production screens and can be replayed from Records. It teaches one decision at a time and never completes a build choice for the player.

Moment Base screen Teaching focus Completion evidence Skip/return behavior
Before 0:00 SYS-002 language, text preview, reduced motion/flashes, captions one usable preset applied cannot skip before usable settings; later returns to Title
0:00-1:00 provisional Company SYS-005 stages A-C inspect four stable offers, compare Profession jobs and Trait costs, choose exactly two, then review both together player states one Profession job and one Trait cost and reaches creation review at 2/2 skip hides teaching layers only; it never preselects, recommends, removes, or commits an offer
1:00 run creation SYS-005 stages D-E confirm selected two, unchosen-not-retained consequence, Contract/difficulty, and first-Market handoff one run-creation receipt owns exactly the selected two and opens the first Market Revise Recruits remains legal before commit; interruption resumes the same pending/receipt boundary
1:00-3:00 first Market hires SHP-001/002 inspect the protected affordable base-Profession opportunities and complete two separate hire reviews two hire receipts move opening Company from two owned Recruits to filled Line capacity four; player distinguishes Line capacity from owned Company no offer is auto-selected or labeled correct; skip removes callouts but never buys, refreshes, locks, or spends
3:00-5:00 first order PTY-001 swap protected rear-left and exposed front-right Recruits and read changed targets/protection/reach tap-select/tap-destination or controller move completed; player identifies position 0 at right/front and who protects whom drag is never required and the original order can be restored before commit
5:00-7:00 first risk RSK-001/002 known pressure, uncertainty, cost, and recovery exposure player reviews and commits a legal option no recommended option is auto-selected
7:00-9:00 first battle BAT-001/002/003 observe target choice, pause, inspect one cause player opens a causal explanation speed remains sourced; no combat action prompt
9:00-12:00 first result/adaptation OUT-001/003 and EQP-001/002 locate earliest divergence, choose reward, and compare one behavior-changing equipment/order adaptation player follows one cause chain and identifies a before/after behavior Continue remains available after review; no build change is applied without commit
12:00-16:00 first casualty OUT-002/004 distinguish committed loss, equipment return, and Credit from the next recovery decision player acknowledges receipt and inspects legal recovery training fixture grants no persistent reward or death; no loss is silently undone
16:00-20:00 independent Round production screens buy, order, commit, and diagnose without a pointer one complete independent Round one no-reward reset is available before commitment when supplied by product rules
First final-survivor dismissal attempt REC-002 explain why ordinary dismissal is disabled and where explicit run abandonment lives player dismisses the explanation or opens OUT-006 disabled action changes nothing and does not auto-open confirmation

The SYS-005 -> SHP-001 handoff preserves the two selected stable Recruit IDs, shows opening Company 2 separately from Line capacity 4, and points to the first hire decision without choosing an offer. After each authoritative hire receipt, the same status region updates Company 2 | Line capacity 4 to Company 3 | Line capacity 4, then Company 4 | Line capacity 4; the two-step progress is never faked by a tutorial-only counter or a combined purchase.

After repeated failure, Result may offer a replayable explanation or training surface only if supplied by product rules. It may identify the earliest preventable event, but it does not equip, recruit, reorder, or choose risk.

8. Landscape, Localization, And Accessibility Matrix

Every base screen and required overlay must be captured and reviewed across these axes before a gallery can claim coverage:

Axis Required design states
Landscape phone 1280x720 reference; short-height and wide-cutout fixtures; touch-safe edges
Landscape tablet 1366x1024 and 2048x1536; world expands without stretching controls
Large landscape 1920x1080 and 2560x1440; constrained HUD with lateral world reveal
Language English (en), Simplified Chinese (zh_CN), and a longest-string fixture for every action and consequence
Text/UI scale 100%, 115%, and 130%; no critical value, cost, state, or action truncated
Input touch-only and controller required; keyboard/mouse parity; visible focus at all times
Motion normal and reduced motion; no information conveyed only by travel, parallax, shake, or speed
Flashes normal and reduced flashes; event geometry and text remain sufficient
Audio normal, master mute, captions-only, output loss, and mono-compatible information cues
Power normal and low-power; same decisions, simulation state, event order, and receipts
Vision standard and high contrast; no state depends on hue, opacity, or image detail alone

At 130%, secondary explanation moves to an inspect drawer or full-screen detail. Objective, current state, cost, consequence, primary action, Back, focus, and transaction status stay in the first viewport. Battle inspection becomes a pauseable full-screen linear view when a side drawer would make actors unreadable.

SYS-005 keeps all four stable offer markers, selected count, Inspect/Compare, Back, and the disabled/enabled Review Company state visible at 130%. On a short landscape phone the four markers use a fixed 2 x 2 arrangement and selected detail replaces the secondary region; on tablet/reference they use one fixed four-offer row. Text growth never hides an offer, changes offer order, or makes Create Company appear before the review stage.

The visual Party line is not mirrored by locale: protected rear remains left, exposed front and position 0 remain right, and larger position numbers extend left in both en and zh_CN. Text labels, front/rear icons, protection connectors, and screen-reader order carry the meaning without relying on reading-direction inference.

At every text scale, the final-survivor dismissal reason and separate abandonment action remain visible without overlap. Touch can inspect the disabled reason and activate the separate abandonment action without precision gestures. Controller focus reaches the disabled Dismiss state, announces its reason, then advances to the separate action; default focus in OUT-006 is Cancel.

Simplified Chinese (zh_CN) may wrap actions to two lines. Components grow vertically within bounded layout tracks; type never shrinks to force a one-line label. Generated names support long Latin strings and multi-codepoint CJK without using name length to resize surrounding controls.

9. Endgame And Completion States

The following are separate, player-readable states:

  1. Active Contract with ordinary preparation available.
  2. Battle victory with unresolved knockout, reward, or recovery transaction.
  3. Battle loss with the Contract still viable.
  4. Retreat resolved with a changed preparation state.
  5. Contract ended by sourced failure, with progression receipt pending.
  6. Contract closed by explicit withdrawal, with no Recruit treated as ordinarily dismissed and one closure receipt pending or applied.
  7. First clear, with newly eligible persistent and postgame decisions.
  8. Completed Contract retained for records, not resumable as active play.
  9. Postgame Contract setup with all active modifiers reviewed.
  10. Postgame result with local clear, verified record, and reward receipt shown independently.
  11. Profile completion with no unclaimed transaction and the persistent Guild still available.

Credits, records, and postgame never trap the player. Each returns to Title or its explicit caller, and ordinary Contract creation remains visible wherever legal.

10. Coverage Gate

The screen authority is candidate-ready only when:

  • every ID in Section 5 has a canonical landscape composition;
  • every row has purpose, primary action, consequence, empty, loading, error, confirmation, interruption, and return behavior;
  • Shop, recruit, dismiss, equip, compare, active artifacts, party ordering, risk commitment, automatic battle, pause, speed, inspect, retreat, result, death, reward, recovery, progression, Settings, and postgame form complete paths;
  • all product values appear through Section 2 bindings or an integrated source;
  • SYS-005 remains one page while covering four unique stable provisional offers, no-Coin Inspect/Compare, exactly-two selection, revision, creation review, invalid/empty/loading/error, interruption, and first-Market handoff;
  • the 0:00-3:00 onboarding path produces one provisional choose-two receipt and two separate affordable first-Market hire receipts without recommending or auto-selecting the opening build;
  • Party-line preparation and battle stage protected rear on the left and exposed position 0 front on the right; larger numbers extend leftward and protection remains explicit;
  • no interaction inserts a combat action into the automatic timeline;
  • every destructive or costly action has a stale-preview and duplicate-receipt path;
  • ordinary dismissal is disabled at one total live Recruit across deployed and reserve; its stale confirmation rejects with zero mutation and zero rebate;
  • explicit run abandonment uses OUT-006, and ordinary dismissal never creates a zero-live-Recruit preparation state;
  • landscape phone/tablet, touch/controller, English/Simplified Chinese, 130%, reduced motion/flashes, mute, high contrast, and low-power states are covered;
  • onboarding uses the real screens and ends with an independent player decision;
  • no screen implies authored story leads; recruits remain generated run participants; and
  • design coverage is not described as implementation, device, comprehension, fun, packaging, store, or release acceptance.

Aetherbound Guild: UI And Visual System

Authority: player-facing landscape composition, information hierarchy, reusable UI grammar, semantic color, type, input feedback, responsive behavior, and accessibility presentation.

Companion: 03_PAGES_AND_UX.md.

Product source: 01_GAME_DESIGN.md. Visual direction: 04_ART_ANIMATION_AUDIO.md.

Evidence boundary: this is a production specification, not rendered UI, final media, runtime proof, device acceptance, or human validation.

1. Visual Thesis

A field guild making consequential plans at the edge of a vivid, unstable fantasy world.

The first viewport presents the actual decision surface: generated recruits at a muster table, physical equipment under comparison, an ordered expedition line, a dangerous destination, or a battle already resolving. The world and its actors remain the primary composition. UI surfaces attach to a desk edge, tool rack, field ledger, route frame, or screen edge instead of floating as a wall of panels.

The visual language combines hand-painted 2D Japanese fantasy environments, clean cel-shaped actors, dark ink structure, bright mineral pigments, cool paper-white labels, enamel action plates, woven position markers, and precise engine-rendered type. It feels practical and repaired, not royal, luxurious, or collectible-first.

Generated recruits read as individuals through their sourced name, modular appearance, profession silhouette, one trait seal, equipment, condition, level, and survival marks. Presentation never implies that one recruit is an authored lead who must remain in the party.

1.1 Three-Second Reads

Moment First read Second read Third read Desired feeling
Title active guild threshold and distant unstable route current safe run state Continue and accessibility access invited, not advertised to
Initial Company four equally weighted provisional Recruit offers selected 0/2..2/2 and comparison Review Company then Create Company consequential one-time choice without a recommended build
Guild desk next pressure or opportunity what changed after the last result available preparation destinations purposeful freedom
Shop materially different offers cost and current fit refresh or return consequence constrained possibility
Recruit review profession responsibility and trait tradeoff rolled strengths and limitation price and party effect informed attachment without narrative obligation
Final-survivor dismissal disabled Dismiss and One member must remain separate run-abandonment action retained Recruit and zero-delta result protected consequence without a dead end
Equipment changed behavior and eligible wearer conflict or replacement cost and reversibility deliberate construction
Party line protected rear-left through numbered positions to exposed front-right protection, reach, movement, and target effects validation and undo readable planning
Risk choice known pressure and uncertainty reward class and recovery exposure committed party snapshot chosen tension
Battle most urgent event and affected actors why the current target or protection relation exists pause, speed, and inspect trust in automatic resolution
Result earliest meaningful divergence downstream losses and survivors next adaptation diagnosis, not spectacle alone
Knockout who left the current battle and what capability disappeared battle gap and retained equipment next-stage return and legal adaptation consequence without roster deletion
Reward which future decision changes current build interaction claim consequence earned redirection
Postgame active rule differences eligibility and record ordinary run remains available mastery with transparency

1.2 Anti-Goals

  • No detached dark rectangles covering a decorative background.
  • No portrait-card wall as the primary roster, planning, or battle view.
  • No oversized headings inside compact operational surfaces.
  • No rarity color as the main argument for recruiting or choosing an item.
  • No one-hue fantasy wash; semantic colors stay distinct from region art.
  • No beige parchment monoculture, full-screen blur, ornamental glow spheres, decorative gradients, or particle haze.
  • No tiny actors whose profession, order, target, health, and death state vanish at play size.
  • No icon-only unfamiliar resource, trait, status, or destructive action.
  • No animated decoration that resembles danger, a legal target, a reward, or a successful transaction.
  • No font sizing tied to viewport width, negative letter spacing, text baked into art, or forced one-line localized controls.
  • No nested decorative cards. Repeated offers and items may use bounded rows; page sections remain unframed or edge-docked.

2. Cross-Workstream Presentation Bindings

Gameplay values use the binding registry in the companion screen map. Media identity uses the following named bindings until the art and audio authorities are integrated:

Binding Required presentation contract Source authority
BIND:ART_RECRUIT_PRESENTATION modular body, face, hair, garment, condition, and survival-mark layers art/animation catalog
BIND:ART_PROFESSION_PRESENTATION silhouette, tool/weapon, pose, emblem, and action-read vocabulary for each profession art/animation catalog
BIND:ART_EQUIPMENT_PRESENTATION inventory object, equipped read, comparison view, and conflict marker art/animation catalog
BIND:ART_REGION_PRESENTATION environment, route material, weather, and readable ground contrast per region art/animation catalog
BIND:ART_ENEMY_PRESENTATION identity, threat source, target projection, status, injury, and death/exit reads art/animation catalog
BIND:ART_EFFECT_LANGUAGE anticipation, target, impact, mitigation, status, death, reward, and recovery event roles art/animation catalog
BIND:AUDIO_EVENT_CATALOG UI commit, shop, order, battle, casualty, result, reward, recovery, and error cues audio catalog

Design fixtures may use labeled geometric stand-ins. They may not invent final silhouettes, asset counts, music, voice scope, prices, formulas, or content identities.

3. Canvas, Safe Areas, And Responsive Tracks

The interface is designed in logical pixels. Layout changes by available height and aspect, not by scaling the entire canvas.

Class Required fixture Safe area Structural policy
Short landscape phone 1280x720 56 sides, 40 top/bottom plus device insets compact top rail, full-height decision surface, bottom action dock; detail replaces secondary region
Wide landscape phone 1560x720 device insets plus 56 keep short-height control sizes; reveal world laterally
Landscape tablet 1366x1024 and 2048x1536 64 all edges plus device insets main decision area plus persistent contextual rail when useful
Reference landscape 1920x1080 96 all edges canonical composition and two-region comparison
Large landscape 2560x1440 128 all edges constrained UI tracks; reveal environment and longer lists

The major tracks are stable:

  • top status rail: 56-72 high, one row at 100%, two bounded rows at 130%;
  • main subject: at least 62% of usable width and 68% of usable height;
  • context rail: 360-520 wide when docked, or a full-height replacement surface on a short phone;
  • bottom action dock: 72-96 high, with one primary action aligned to the decision rather than centered by habit;
  • inspect surface: up to 42% of width on tablet/reference, full screen on a short phone at 130%; and
  • settings category rail: 224-272 wide when persistent; a top selector when the scaled label set would narrow content below its minimum.

Control and text dimensions do not stretch on large screens. Environment art, world spacing, and list length absorb extra room. Cutouts and home indicators may move the action dock inward but never cover a focus outline or consequence.

3.1 Responsive Priority

When height or text space is constrained, retain in this order:

  1. objective or decision name;
  2. current state and selected stable identity;
  3. cost, consequence, and reversibility;
  4. primary action and Back;
  5. comparison delta or urgent causal explanation;
  6. supporting history and flavor.

Items 1-5 remain in the first viewport. Item 6 may move to Inspect. No layout solves overflow by reducing type below its token or actors below their minimum readable silhouette.

4. Information Hierarchy

Decision surface Primary Secondary Deferred to inspect
Guild desk upcoming pressure, latest change, preparation readiness sourced resources and open decisions complete run history
Initial Company four stable provisional identities, Profession job, Trait benefit/cost, selected count five attributes and starting item state unrelated catalog, Contract setup and future progression
Shop offer behavior, price, immediate fit future eligibility and refresh consequence full discovery provenance
Recruit review profession responsibility, trait benefit/cost, rolled constraint individual level/XP, one current item, survival history full attribute derivation
Dismissal/abandonment eligibility and affected scope returned equipment, rebate or run-close consequence unrelated Recruit history
Equipment changed behavior, wearer, replacement, conflict secondary derived effects and acquisition unrelated collection record
Party line position, exposure, target/protection/reach change alternate order and unresolved warning cosmetic identity detail
Risk known threat, uncertainty, entry cost, reward class current coverage and recovery exposure unrelated progression
Battle urgent event, affected actor, objective, playback state aggregate party condition long-form build explanation
Result first divergence, decisive interaction, knockouts and next resolution contribution and complete event list collection celebration
Recovery viable paths, full transaction, next planning state longer-term replacement implications unrelated records
Progression newly opened decisions and prerequisites path preview and reset consequence unrelated catalog entries

The same mechanical noun and icon must be used in preview, battle, result, and records. A tooltip cannot rename a rule or hide a consequence behind flavor.

5. Semantic Palette

Region art supplies local color. UI semantics use a small, stable set that is readable over both bright and dark scenes.

Token Color Meaning Required non-color cue
ink-950 #182127 primary text, deepest structural edge solid weight
ink-760 #34424A docked instrument and inactive surface inset border
mist-050 #F3F6F2 primary text field and selected ledger surface raised plane
mist-180 #D7E0DD secondary surface and divider woven grain
route-teal #13818A legal flow and navigation path paired continuous lines
work-gold #D6A72E primary decision and selected destination key-notch edge
safe-jade #27845E health, retained state, safe completion upward leaf-chevron
danger-coral #C94E52 urgent harm, invalid destructive consequence split triangle
focus-cobalt #4169B1 focus, inspect, information action double square contour
uncertain-plum #855579 uncertainty and incomplete forecast broken ring
neutral-silver #88969B disabled or not applicable cross-pin and text reason
focus-white #FFFFFF controller/keyboard outer focus paired outer and ink inner line

Semantic color occupies no more than one quarter of a large component surface. Health, danger, uncertainty, eligibility, selection, and completion use shape, text, and pattern in addition to hue. Body text meets 4.5:1 contrast and large text plus meaningful component boundaries meet 3:1 in all approved region fixtures.

Rarity, when supplied by content, is secondary metadata. It may change a small corner stamp or texture but never the size, brightness, or order of an offer.

6. Typography, Numbers, And Localization

Display text uses a licensed Japanese/Latin-capable humanist sans only for the product name, region arrival, and run ending. Functional UI uses a highly legible Japanese/Latin sans with tabular numerals. Font selection remains pending glyph, license, fallback, and device rendering review.

Reference tokens at 1920x1080, 100%:

Style Size / line Use
Display 46 / 58 product name or region arrival only
Screen title 32 / 40 page or major decision name
Section title 24 / 32 one bounded content region
Body 20 / 29 consequence and explanation
UI label 18 / 24 actions, tabs, fields, position markers
Caption 16 / 22 noncritical metadata
Battle label 18 / 22 attached event, value, timer, status

Letter spacing is 0. All numeric values use tabular numerals. A changed value uses a named before -> after, signed delta, or before/after bar. A percentage never appears without the affected rule and sourced base consequence.

At 115% and 130%, font and control tokens increase independently of viewport. Labels may wrap to two lines. Screen titles, buttons, tabs, generated names, prices, consequences, and state labels do not ellipsize. Noncritical history may truncate only when an adjacent Inspect action exposes the complete accessible string.

English (en) and Simplified Chinese (zh_CN) share hierarchy and action order. Chinese mechanical text remains engine-rendered, uses localized punctuation, and is tested without inserting spaces between ideographs. Dates, numbers, and unit order use locale formatting, while stable diagnostic IDs remain ASCII.

7. Shape, Material, And Icon Grammar

Meaning Shape/material
Global navigation squared enamel tab with one clipped corner
Recruit identity upright woven marker plus unframed full or half figure
Profession stamped tool silhouette backed by a square field
Trait single hexagonal seal with benefit edge and cost notch
Equipment physical object silhouette on a shallow metal tray
Artifact shared-rule emblem on a full-width ledger strip, visually separate from equipment
Party position numbered stitched marker joined to one horizontal cord
Known threat angular forecast sheet with a pointed time edge
Uncertainty broken outer contour and explicit confidence text
Safe completion closed contour, receipt stamp, and named result
Destructive consequence split edge and warning sentence; not a solid red fill
Locked cross-pin plus named requirement; never an unexplained lock icon

Cards have at most 8 px corner radius. Cards are reserved for repeated shop offers, repeated reward choices, and transaction reviews. A card contains rows and dividers, not more cards. Page sections remain edge-docked or unframed.

Familiar tools use familiar symbols from the implementation's approved icon library: Back, close, settings, pause, play, speed, inspect, compare, filter, sort, search, undo, speaker, controller, download, and warning. Unfamiliar profession, trait, status, resource, or threat icons always pair with localized text and expose a tooltip or touch Inspect action.

Icon envelopes are 24, 32, and 48 logical pixels with a consistent reference stroke. Filled/outline alone may not distinguish two state meanings.

8. Core Components

8.1 Action Control

One primary action appears in each decision region. The label uses an explicit verb and includes cost or outcome when sourced: Recruit - [price], not Confirm.

Variant Composition Behavior
Primary gold enamel edge, ink label, leading familiar icon performs or opens the named decision
Inspect mist surface, cobalt double contour opens reversible detail
Safe commit jade completion edge and closed contour states retained result
Risk commit mist surface with coral split and uncertainty mark states exposure and next state
Destructive neutral surface, coral split, full consequence nearby requires explicit review gesture
Disabled intact material with cross-pin and reason remains inspectable; no press or success cue
Pending stable width, progress label, controls locked to operation ID cannot submit twice

The touch target is at least 48x48; primary and destructive actions target 56 high on touch layouts. Press feedback begins within 50 ms; confirmed local feedback begins within 100 ms of authoritative receipt. Pending state does not change component dimensions.

8.2 Status Rail

The top rail contains only information needed by the current decision:

  • Guild: BIND:RUN_PHASE, relevant BIND:RUN_RESOURCES, readiness, save health;
  • Shop: spendable value, refresh status, offer validity;
  • Party: capacity binding, validation, selected pressure;
  • Battle: objective, playback state, urgent condition, save/snapshot state; and
  • Result: outcome receipt and unresolved next transaction.

Each resource has localized name on focus/tap, icon, exact value, recent delta, and pending/confirmed state. Unknown and zero are visually and semantically different.

8.3 Shop Offer Row

Recruit offer order is: figure or portrait, generated name, profession, trait benefit/cost, two decision-relevant rolled reads, price, and Inspect. Item offer order is: object, name, behavior, eligibility/conflict, price, and Inspect.

Rows share stable height per text scale. Selection adds an external contour and comparison region; it does not push adjacent rows. Sold, expired, unaffordable, and selected states keep the original stable ID visible.

The first-Market variant marks at least two sourced base-Profession Recruit offers as affordable without marking either recommended. A persistent opening status reads owned Company separately from Line capacity and updates only from authoritative hire receipts: Company 2 | Line capacity 4, Company 3 | Line capacity 4, then Company 4 | Line capacity 4. Each hire keeps its own review, cost, receipt, and focus return; no combined Hire two action exists.

8.4 Provisional Recruit Selector

SYS-005 uses a dedicated provisional variant, not the Shop offer row. It renders exactly four stable positions from BIND:PROVISIONAL_RECRUIT_OFFERS and never shows price, refresh, lock, rarity promotion, or purchase language.

Each overview marker has stable dimensions and contains:

  • generated name and stable offer ID;
  • Recruit figure/portrait at the common marker scale;
  • base Profession icon, localized job sentence, and target/reach read;
  • Trait seal with one benefit and one cost;
  • one decision-relevant rolled distribution read;
  • No Coin cost;
  • a Select checkbox with a checkmark that does not imply Party-line order; and
  • a separate Inspect icon with accessible label.

Touch activation on Select toggles Company selection; tapping the marker only focuses it and opens no destructive state. Controller focus enters offers in stable source order; Select toggles the focused offer, while Inspect opens and closes its full details without changing selection. Compare is a separate command: it pins offer A, then offer B, and opens an aligned Profession, Trait, attribute, individual level, and one-starting-item comparison. The A/B pair may use any two offer IDs and never changes the two Company checkboxes.

The selected-count component has fixed dimensions and explicit states:

State Label and control state Result
none Choose two - 0/2; Review Company disabled Inspect, Compare, Back, and first selection remain legal
one Choose one more - 1/2; one stable ID checked selecting a second enables review
two Company selected - 2/2; both stable IDs checked; Review Company enabled either selection may be cleared or replaced before review
third attempt Two already selected; current two remain unchanged focus moves to the selected-count explanation; no automatic eviction
invalid source expected four/received count or affected stable ID; all Select controls disabled Retry Same Set or Return to Title
loading four fixed skeleton positions, named operation, no identity or selection resolved stable ID stays in its original position

Review replaces details without discarding the four-offer strip. The selected two occupy the main Company comparison; the two unchosen stable IDs remain in a quiet Provisional offer not chosen summary. Revise Recruits returns to the same four positions, selected IDs, A/B comparison, and focus. Create Company is the only primary action and enters a fixed-size pending state, so a spinner or long localized status cannot shift Revise, Cancel, or offer markers.

On a short landscape phone, the four markers form a fixed 2 x 2 layout; the selected marker's details replace the context rail. On tablet/reference they form one four-marker row above one comparison region. At 130%, generated names may wrap to two lines and the Profession/Trait text moves to Inspect, but all four identities, checked state, 0/2..2/2, Select, Inspect, Compare, Back, and Review Company remain visible. English (en) and Simplified Chinese (zh_CN) share offer order and control geometry.

No offer starts selected, pulses as preferred, receives a larger portrait, sorts by a hidden score, or gains a tutorial arrow. Teaching may highlight the Select and Inspect controls as a group, never one Recruit.

8.5 Recruit Identity

The component has four canonical scales supplied by BIND:ART_RECRUIT_PRESENTATION:

Scale Required reads
Marker stable portrait/silhouette, profession emblem, trait seal, level, condition
Roster generated name, profession, level, one-item state, trait tradeoff, readiness, deployed state
Planning figure full silhouette, level, one equipped-item read, order number, health/condition
Battle actor profession/tool silhouette, target/protection relation, health, urgent status, death/exit

The generated name and stable ID are text. Profession is never inferred from color alone. Trait shows exactly one benefit edge and one cost notch before its expanded mechanical sentence. Survival history uses a small set of sourced marks and never becomes a fixed personal-story track.

8.6 Equipment Row And Comparison

An item row shows object, name, form from BIND:EQUIPMENT_RULES, current wearer, one behavior sentence, eligibility, and relevant sourced delta. Every Recruit has one universal slot; form does not create another slot. Comparison aligns current and candidate by mechanical field; unchanged fields remain visible but quiet. Conflicts name the wearer, Profession, position or shared rule.

Apply does not enable until the one-slot replacement, returned prior item or null, invalidated reference, and reversibility are known. Raw power score, rarity, or price is never the sole or largest comparison read.

8.7 Dismissal And Run Abandonment

Dismiss is a destructive text-and-icon action below routine Recruit actions. Its state comes from BIND:DISMISSAL_ELIGIBILITY, which uses the total live Recruits across deployed and reserve rather than only the prepared party.

When that total equals one:

  • Dismiss retains its stable control dimensions and destructive icon but uses the policy-disabled cross-pin state;
  • LOC:DISMISS_LAST_LIVE_RECRUIT renders beside it with the invariant meaning One member must remain;
  • touch activation on the disabled control announces or expands the reason and changes no state;
  • controller focus reaches the control, announces action plus disabled reason, and does not open a confirmation; and
  • Review run abandonment is a separate secondary action with its own focus stop, route, accessible name, and OUT-006 destructive review.

The abandonment action is not painted inside the disabled control and does not target the selected Recruit. OUT-006 uses a full run-level consequence sheet, default focus on Cancel, a run identifier rather than a Recruit identifier, and one explicit Abandon run confirmation. No dismissal-rebate read appears in that review.

If REC-003 becomes stale and commit-time eligibility reports one live Recruit, the sheet closes without a success transition. Recruit Detail keeps the Recruit visible, returns focus to disabled Dismiss, announces One member must remain, and shows a neutral zero-delta receipt: no Recruit removed, no equipment moved, no rebate granted. This rejection uses no success color, ownership motion, or transaction sound.

At 130% on a short landscape phone, Dismiss, its two-line reason, and the separate abandonment action occupy three stable rows. They do not overlap the Recruit name, Back, or safe-area inset. The Simplified Chinese (zh_CN) fixture may wrap each label to two lines without merging the two actions.

8.8 Party-Line Editor

One horizontal cord runs from Protected rear at left to Exposed front at right. The rightmost occupied marker is authoritative position 0; larger position numbers extend leftward toward the rear. Every prepared Recruit occupies a stable numbered marker joined to that cord. The component renders the count from BIND:PARTY_CAPACITY; it never labels capacity as owned Company.

Each marker has a fixed aspect ratio and minimum size. At dense target widths, all order markers remain visible while the selected recruit expands into the context rail; nonselected figures use simplified but distinct silhouettes. If future sourced capacity cannot fit at minimum size, the cord scrolls by whole positions with sticky Rear/Front indicators, position 0 pinned at the right edge indicator, and a full miniature order strip.

Selecting a recruit then a destination previews only sourced changes:

  • expected exposure and likely targets;
  • protection given or received;
  • reach and healing access;
  • movement behavior; and
  • replacement behavior after death or exit.

Changed relations draw direct shaped connectors above the cord and list the same changes in text. Undo and Reset are familiar icon controls with tooltips. Drag is optional; tap-select/tap-destination and controller move are complete.

Protection connectors point from the protected Recruit toward contributing actors ahead of it on the right. Front and rear use icon, localized text, edge shape, and position number; color or reading direction alone is insufficient. English, Simplified Chinese, touch, controller, and screen-reader fixtures keep the same spatial orientation rather than mirroring the line by locale or input.

8.9 Active Artifact Ledger

Artifacts are presented as run-wide rule modifiers, never as equipment attached to a recruit. Each ledger row shows sourced emblem, name, changed rule, acquisition receipt, active/inactive state, interactions, conflicts, and lifecycle from BIND:ARTIFACT_RULES. Inspect uses the same vocabulary in Shop, Reward, Guild, Battle, Result, and Records. Missing rules block dependent commitment instead of reducing an artifact to rarity or flavor.

8.10 Risk Choice

Risk options are aligned by known pressure, uncertainty, entry cost, reward class, recovery exposure, and current coverage. Options use different threat silhouettes and comparison rows rather than promotional art or rarity frames.

The selected option expands in place. The commitment surface remains attached to it and displays the accepted party snapshot. Unknown information is a sourced uncertainty state, not an empty value or hidden tooltip.

8.11 Battle Actor And Event Projection

The battlefield owns at least 68% of usable area. Player actors stage from protected rear at left to exposed position 0 front at right and face the enemy across the central action gap. Enemy staging faces toward that front. Order remains legible through numbered ground marks and target/protection connectors; the planning cord itself is not drawn as a large HUD over combat.

Actor-attached information is limited to:

  • health or other sourced survival state;
  • urgent status icon and short label;
  • current target relation when relevant; and
  • order marker for allied recruits.

Only the greatest immediate danger expands automatically. Other values remain compact and are available through Inspect. Event projections originate at the acting subject, name affected targets, include time/order, and keep actors visible.

8.12 Playback And Inspect Tools

Pause, play, speed, and inspect use symbol-first controls with tooltips and accessible labels. Speed is a segmented symbol control populated by BIND:BATTLE_SPEEDS; changing it never looks like a combat action. Retreat is inside Pause and separated from Resume by layout and review.

Inspect freezes or preserves playback according to sourced rules and opens:

  1. selected event and source;
  2. target and order reason;
  3. equipment, profession, trait, or status contribution;
  4. immediately preceding cause; and
  5. downstream event when already known.

On short phones or at 130%, this becomes a full-screen linear view. Closing it restores the exact prior playback state.

8.13 Causal Timeline

Result uses a two-track timeline: expected responsibilities from the accepted party snapshot above, actual events below. The first meaningful divergence has the strongest contour and direct connectors to affected recruits, enemy event, equipment, and order relation. Totals and rankings are secondary.

Every event has a stable icon, timestamp/order, source, target, outcome, and accessible text. Cause unavailable is an error state. A neutral result may state that no preventable divergence was detected.

8.14 Death And Party Gap

Loss presentation is quiet and explicit. The affected recruit remains visible at a respectful readable scale with generated name, stable ID, profession, trait, level, survival marks, equipment disposition, and committed receipt. The adjacent party cord shows the new gap and sourced replacement behavior.

The Acknowledge action does not suggest reversal. Recovery and replacement are separate next decisions supplied by their bindings. No celebratory particles, rarity framing, or generic red overlay accompanies death.

8.15 Reward Choice

Rewards appear as actual object, profession, recruit, or rule presentations supplied by content and media bindings. Equal-size decision regions prevent object scale from implying value. Each option names:

  • the next decision it changes;
  • current eligible target or party interaction;
  • conflict or opportunity cost;
  • claim destination; and
  • skip outcome when legal.

Claim animation begins only after receipt. The final state is a persistent named ownership change, not particles alone.

8.16 Recovery Choice

Recovery options are unframed paths leaving the causal result: reconfigure, replace, restore, or end the run only when supplied by BIND:RECOVERY_OPTIONS. Each shows full cost, retained state, recruits affected, and next destination. Unavailable paths remain inspectable with reason.

8.17 Empty, Error, Notice, And Receipt

Component Required content Forbidden behavior
Empty state what is empty, why, legal next action decorative illustration with no action
Loading state named operation, blocked scope, progress when known generic spinner over active controls
Inline error plain cause, retained state, retry/alternate raw internal exception or vanished content
Binding error binding name in diagnostics, player-facing affected feature, safe exit invented zero/default value
Notice one changed fact and optional Inspect stacking duplicate transient messages
Receipt stable operation, committed result, timestamp/order, duplicate behavior success feedback before authority confirms
Confirmation target, before, after, cost, risk, undo policy vague Are you sure? alone

Notices reserve layout space or overlay noncritical world space. They never cover the primary action, Back, playback tools, target projection, or focus.

9. Canonical Layout Families

9.1 Title And Run Screens: SYS-003..007

  • Full-bleed working guild threshold; the product name occupies no more than one fifth of frame height.
  • Continue and verified run summary sit together at lower-left on clear ground.
  • Run ledger uses one unframed vertical list and one details rail.
  • Accessibility, Settings, and run selection are compact tools, always visible.
  • Save recovery uses an aligned lineage comparison, not competing alert cards.
  • SYS-005 gives its main surface to four equally weighted provisional Recruit markers and a stable 0/2..2/2 selection status. Inspect/Compare uses the context region; Review Company is the only primary action after 2/2.
  • The creation review keeps the four-offer strip, expands the selected two, labels the unchosen two Provisional offer not chosen, and separates Revise Recruits from Create Company. Pending/error states cannot rearrange or replace offer IDs.

9.2 Guild Desk And Forecast: HUB-001/002

  • Current pressure is represented in the world and repeated in concise text.
  • Shop, Roster, Equipment, Party Line, and Risk are stable edge destinations.
  • The prepared party occupies a shallow muster strip that reflects current profession, condition, equipment, and order.
  • The first-Market variant keeps Company count and Line capacity separate and exposes two individual affordable-hire reviews; no visual treatment chooses either base-Profession offer for the player.
  • Latest result change uses one attached receipt strip and disappears only after inspection, not on a timer.

9.3 Shop And Recruit: SHP-001..003

  • Left/main: scrollable offer rows on a physical requisition surface.
  • Right/context: selected offer at planning scale with tradeoff, fit, and cost.
  • Filters are icon+text tools; option sets use menus, not clouds of rounded text.
  • Refresh is visually secondary and always displays sourced consequence.
  • Recruit and Buy actions appear only inside their review state.

9.4 Roster And Recruit Detail: REC-001..003

  • Roster uses a muster wall or line of markers plus one selected planning figure.
  • Filters prioritize deployed state, profession, trait, readiness, and condition.
  • Detail organizes Identity, Mechanics, Equipment, Position, and History as tabs or a compact category rail; no biography-first hero page.
  • Dismissal is isolated below routine preparation actions. At one total live Recruit it stays visible, policy-disabled, and paired with One member must remain; a separate secondary action opens OUT-006.
  • A stale final-survivor confirmation closes back to Recruit Detail with no ownership motion, rebate cue, or success state.

9.5 Equipment: EQP-001/002

  • Selected recruit remains visible; eligible inventory forms one scroll track.
  • Current and candidate objects align around the recruit, not inside nested panels.
  • Behavior delta is the first comparison read; eligibility and conflicts are adjacent to Apply.
  • At 130% on phone, item list and comparison become two explicit views with a persistent selected-item summary.
  • ART-001 uses a separate full-width shared-rule ledger; it never reuses the per-recruit equipment silhouette or Apply flow.

9.6 Party Line And Readiness: PTY-001/002

  • The ordered cord spans the main surface from protected Rear at left to exposed Front at right. Position 0 is the rightmost front; larger position numbers extend left toward the rear.
  • Available recruits use a lower muster strip; selected recruit expands in the context rail without changing marker positions.
  • Protection/target/reach connectors use distinct patterns, name their numbered endpoints, and remain under a text summary.
  • Readiness replaces editing with a frozen party snapshot and grouped warnings.
  • Save Order is the only primary action; undo/reset are icon tools.

9.7 Risk Board: RSK-001/002

  • Choices occupy distinct parts of a region scene and align to one comparison band below.
  • The band compares known threat, uncertainty, cost, reward class, recovery exposure, and coverage in that order.
  • Commitment slides from the selected option and keeps party snapshot visible.

9.8 Battle: BAT-001..006

  • Player actors stage rear-left to front-right, with position 0 and the enemy- facing action gap at the right; actors and event projections dominate the scene while UI follows edges.
  • Objective and next urgent event sit top-left; pause/speed/inspect sit top-right.
  • Actor markers attach to subjects and collapse when not urgent.
  • Inspect uses the context rail or a full-screen linear surface at 130%/phone.
  • Retreat exists only inside Pause and uses a separated destructive review.
  • Resume Review is static: verified timestamp, speed, pending event, and Resume.

9.9 Result And Recovery: OUT-001..006

  • Causal timeline owns the center; outcome and unresolved transaction remain in a compact top strip.
  • Affected recruits remain visible beside the event that changed them.
  • Death review isolates one loss at a time with a persistent multi-loss index.
  • Reward objects or rules use equal decision regions under the diagnosis.
  • Recovery paths are distinct exits with complete transactions, not three decorative cards.
  • Run abandonment is a separate run-level sheet invoked from Guild desk or Result; it never reuses a Recruit dismissal sheet or selected-Recruit art.

9.10 Progression, Records, And Postgame: PRO-001..PST-003

  • Progression emphasizes the decision each unlock opens and its prerequisite, not a giant ornamental branching illustration.
  • Records use one category rail, one entry list, and one large detail subject.
  • Unknown content differentiates not encountered, partially known, and deliberately undisclosed.
  • Postgame setup keeps active modifiers, eligibility, Company and ordinary Contract access visible before commitment.

9.11 Settings: SET-001..009

  • Settings is a quiet unframed workspace with category navigation and a live preview where useful.
  • Binary values use switches or checkboxes; small mutually exclusive sets use a segmented control; larger option sets use menus; numbers use sliders with displayed values; remapping uses dedicated input rows.
  • Reset and deletion sit at the bottom of their own category, separated from routine controls.
  • Caller and Back destination remain visible: Title, Guild, or paused Battle.

10. Interaction And Focus

10.1 Focus Order

Focus begins at screen heading, then the current state summary, primary content, context rail, primary action, and secondary tools. The primary action is not automatically focused after a destructive warning. Modal focus begins on Cancel. Focus never follows moving actors or animation.

Controller focus uses a 3 px white outer and 2 px ink inner contour plus a small cobalt corner mark. Touch selection uses the same contour and a selected label. Pointer hover may preview focus but cannot reveal unique content.

In SYS-005, focus enters Contract/difficulty, then the four offers in stable source order, selected count, Compare, Review Company, and Back. Inspect returns to the invoking offer; comparison returns to its last pinned offer; Revise returns to the first selected offer still present. Offer focus order never changes because of selection, generated-name length, loading completion, or a tutorial highlight.

A policy-disabled destructive control remains focusable so its reason is readable. It is skipped only after the same reason has been announced by an adjacent required notice. Focus order never treats the separate abandonment action as activation of disabled Dismiss. After a stale dismissal rejection, focus returns to Dismiss, announces the zero-delta reason once, then moves to the separate abandonment action on the player's next navigation input.

10.2 Ordering And Selection

  • Selection and commitment are separate states.
  • Provisional Company checkboxes, A/B comparison pins, and Create Company are three separate state machines; changing one never silently changes another.
  • All drag operations have tap-select/tap-destination and controller paths.
  • Reorder controls preserve stable IDs and announce old/new numbered positions, front/rear meaning, and movement left/rear or right/front.
  • Lists retain focus through sort/filter when the stable ID remains visible; otherwise focus moves to Clear Filters or the first result with an announcement.
  • Double tap/press is not required for any essential action.

10.3 Feedback And Haptics

Visual feedback always carries meaning without audio or vibration. Haptics, when available and enabled, distinguish focus movement, legal selection, confirmed receipt, and blocked action. They never announce battle information that lacks a visual and text equivalent.

11. Motion, Effects, And Low Power

Motion communicates source, direction, urgency, commitment, and final state. Layout dimensions do not animate.

Event Normal Reduced motion Reduced flashes Low power
Select 90 ms edge lift and contour instant contour and marker unchanged geometry, no luminance spike final selected state only
Recruit/equip receipt source travels to roster/wearer, then stamped receipt direct crossfade to final state plus receipt no bright burst final state and receipt only
Reorder marker follows cord, relation connectors redraw immediate position swap with numbered before/after no flash immediate final order
Risk commit selected path tightens and scene advances final selected route plus direction arrow solid edge instead of pulse static committed state
Event warning authored anticipation and target projection stepped poses and persistent geometry capped luminance; no full-screen white essential source/target frames only
Impact short response and exact value/status change no shake or hit pause contour/value change; reduced particles final actor state and event row
Death readable exit followed by stable loss marker direct final pose/marker no fade-to-white final pose/marker
Reward ownership path then receipt direct placement and receipt no sparkle burst receipt plus final placement

Reduced motion removes camera travel, parallax, continuous UI motion, and nonessential ambient loops. Reduced flashes removes full-screen flashes, alternating high-contrast frames, and rapid particle bursts. Low power lowers ambient update frequency, effect density, and nonessential layer animation; it does not change event order, timing rules, target clarity, decisions, or receipts.

Only one nonessential ambient focal process and two background loops run on a short phone. They freeze under overlays and never resemble event warnings.

12. Audio-Independent And Visual Accessibility

  • Master mute changes no mechanic, event order, target visibility, transaction, or available decision.
  • Captions name event, source, direction, and outcome using BIND:AUDIO_EVENT_CATALOG; environmental captions remain visually quieter than dangerous battle events.
  • Output loss raises one nonblocking notice and keeps captions plus event geometry active.
  • Mono compatibility is verified by ensuring no necessary cue depends on stereo position alone.
  • Color-independent patterns distinguish safe, harmful, uncertain, selected, disabled, and complete.
  • High contrast simplifies region textures behind labels and actors without replacing region identity.
  • Screen-reader order follows the focus order. Party positions are announced as position [index], [front/rear meaning], [name], [profession], [condition]; position 0 is announced as exposed front/right and larger positions as progressively rear/left. Battle events announce source, action, target, outcome, and time/order.
  • SYS-005 announces four offers, the current checked count, each offer's stable position and checked state, Profession job, Trait benefit/cost, no-Coin cost, Compare A/B state, and whether Review Company is available.
  • A pauseable full-screen event log provides all urgent automatic battle information in chronological text.
  • Controls retain at least 48x48 targets at every scale and do not overlap device insets, captions, notices, or each other.
  • LOC:DISMISS_LAST_LIVE_RECRUIT and LOC:OPEN_RUN_ABANDONMENT_REVIEW are tested in English (en) and Simplified Chinese (zh_CN) at 100/115/130%. The first communicates the one-member requirement; the second communicates voluntary closure of the whole run.

13. State Grammar

Every reusable actionable component implements these semantics consistently:

State Visual/text contract Input result
Available full subject, action verb, sourced cost/effect opens inspect/review or commits only where explicitly allowed
Focused double contour, corner marker, complete accessible name first activation selects or invokes the stated tool
Selected raised edge/check, selected label, stable dimensions enables review; activation alone does not spend
Pending operation name and progress, unchanged geometry duplicate input ignored; Cancel only if source allows
Active active label and persistent state marker inspectable; does not restart
Unaffordable current and required values plus shortfall inspectable; commit disabled
Incompatible conflicting stable subject/rule and correction path inspectable; commit disabled
Policy-disabled intact control, cross-pin, visible rule, separate legal alternative activation announces reason only; alternative has its own focus and action
Locked named prerequisite and where to meet it opens requirement when legal
Temporarily unavailable reason and restoring event inspectable; no success feedback
Complete named result and receipt mark opens result; cannot claim again
Recoverable error plain cause, retained state, Retry/Alternate retries with operation identity
Blocking error affected binding/integrity boundary and safe exit cannot continue dependent workflow

State words in localized copy must remain semantically distinct. Disabled opacity alone is insufficient, and disabled text still meets contrast targets.

14. Design Tokens And Handoff

space: 4, 8, 12, 16, 24, 32, 48, 64
radius: 0, 4, 8
control_min: 48
touch_primary_min: 56
stroke: 1, 2, 3
safe_phone: 56x40 + device insets
safe_tablet: 64 + device insets
safe_reference: 96
context_rail: 360, 420, 520
motion_select: 90ms
motion_commit: 180ms
motion_receipt: 360ms
focus_outer: 3px white
focus_inner: 2px ink
text_scale: 100%, 115%, 130%

The later prototype and runtime theme must declare stable component IDs, screen IDs, localized strings, semantic tokens, focus order, icon IDs, operation IDs, and binding references in structured data. Screen-specific styling may select a region material but may not redefine state, color semantics, transaction rules, focus, or accessibility behavior.

Every gallery frame must record:

  • screen ID and state;
  • viewport and safe-area fixture;
  • language and text scale;
  • input mode and focus target;
  • motion, flash, audio, contrast, and power settings;
  • resolved and intentionally unresolved bindings; and
  • source revision plus whether the frame is static or interactive.

15. Presentation Acceptance Checklist

  • The actual shop, recruit, equipment, artifact, party, risk, battle, result, death, reward, recovery, progression, Settings, and postgame decisions dominate their pages.
  • Generated recruits remain replaceable run participants and still read as distinct mechanical identities at roster, planning, and battle scales.
  • SYS-005 visibly holds four unique stable provisional offers, separate Inspect/Compare/Select controls, exactly-two gating, review/revision, no-Coin and unchosen-not-retained consequences, complete invalid/loading/ error/interruption states, and no tutorial-selected build.
  • The 0:00-3:00 path commits one choose-two run creation and then two separate affordable first-Market hires, ending at Company/Line capacity labels Company 4 | Line capacity 4 without combining purchases or preselecting an offer.
  • At one total live Recruit across deployed and reserve, Dismiss is visible and disabled with One member must remain; explicit abandonment is a separate run-level action and review.
  • A stale final-survivor dismissal confirmation closes with no Recruit or equipment mutation, no rebate, a readable reason, and deterministic focus.
  • The ordered party is immediately readable from protected rear at left to exposed position 0 front at right on landscape phone and tablet; larger numbers extend left and protection contributors remain explicit.
  • Automatic battle prioritizes urgent cause, affected actors, objective, playback state, and inspect; no control implies insertion of an attack or skill into the timeline.
  • Result names the earliest meaningful divergence before totals or rewards.
  • Every action exposes state, target, cost, consequence, reversibility, pending state, receipt, and safe return where applicable.
  • Every screen remains functional at required phone/tablet fixtures, English, Simplified Chinese, and 130% text/UI scale.
  • Touch, controller, and keyboard/mouse support the same complete verbs; no essential action depends on drag, hover, double tap, or pointer precision.
  • English, Simplified Chinese, and 130% fixtures keep disabled Dismiss, its reason, and the separate abandonment action visible without overlap.
  • Reduced motion, reduced flashes, mute/captions, high contrast, screen reader order, and low power preserve decisions and causal information.
  • Cards remain limited to repeated items and reviews; world/actors are the primary surface and components do not nest decorative containers.
  • Gameplay values and media identities remain sourced bindings until their owning authorities integrate them.
  • No design fixture is described as implementation, final media, device, comprehension, fun, packaging, store, or release acceptance.