SIMT CosmosSPECIFICATION 2.4.0Plain text

00 / COMMON FOUNDATIONS

One universe.
A coherent language.

Warm depth, precise signals and generous quiet. Every platform shares the same meanings; each gives the task the space and input it needs.

Clarity at the center. Atmosphere at the edge.

THE COSMOS GRAMMAR
Quasar aperture

Frame one meaningful object.

01
Context spine

Where you are. What comes next.

02
Horizon ribbon

Time and distance, made legible.

03
Design specimen · illustrative data · static composition

Normative specification · v2.4.0 Inherited by all four platform parts. Conformance is recorded rule by rule in a release record.

01

Identity & authority

A useful spatial system, with room for imagination.

  1. C01MUST

    Task before spectacle

    Put the primary object, current state and next action in the first useful viewport. A decorative motif may frame them but cannot displace them. Use literal operational copy even when the visual language is celestial.

    Acceptance

    In grayscale, a first-time reader can identify the task, state and next step. Removing all ornament leaves a complete interface.

  2. C02MUST

    Shared core, four adapters

    Apply these common rules and the relevant platform part together. Product safety, privacy and accessibility requirements take precedence. Older prototypes and repository guides are migration evidence where they disagree with v2.

    Acceptance

    Each implementation brief names version 2.4.0, platform, applicable rule IDs, owner and any explicit exception with reason, evidence and review date.

  3. C03MUST

    Original composition

    Build visual identity from the focus aperture, context spine and horizon ribbon. An aperture frames one meaningful object and is drawn as a quasar: a solid core in the object's channel, a corona halo and, where space allows, an accretion ring. A spine connects current context to the next step; a ribbon orders actual time or distance. Compose with continuous fields and aligned rows before adding cards.

    Acceptance

    Every motif names the information it carries. One quasar aperture per screen marks the focal object. Cards contain individual records; no nested record cards or identical boxes around every page section.

02

Color with a job

The original Deep Space colors are preserved exactly.

  1. C04MUST

    Stable semantic channels

    Use Ember for primary agency, Rose for social attention, Violet for identity, Gold for focus/time/value, Cyan for live/location state and Moss for nature. Danger and Success are separate status channels. Limit competing large accents to one dominant and two supporting channels; categorized data may use the spectrum with labels.

    Acceptance

    Tokens resolve to the anchors below. A hue never supplies the only meaning. Category Moss cannot imply a successful operation; Rose cannot imply an error.

  2. C05MUST

    Contrast is composited

    Require 4.5:1 normal text, 3:1 large text and 3:1 essential control boundaries, focus and graphical objects against adjacent colors. Use boundary for necessary input outlines; line is decorative only. Check every gradient stop, translucent surface and hover/disabled distinction.

    Acceptance

    Measure the final composited pairs in each theme. The measurements are published once at contrast-pairs.json; fetch that document when introducing a colour, pairing a translucent or gradient surface or checking a theme, and do not expect a token payload to carry them. Document any inactive-control exception. Faint is supporting text only on a passing surface; Dim is never needed to complete a task.

  3. C06MUST

    Daylight, red and ambient

    Offer Daylight Nebula where supported. Dark remains the signature; a persisted explicit choice wins over the system preference, and with no choice the system preference is followed. Astronomy red is user-selected for instruments, uses only red luminance and retains text contrast. Watch ambient may use pure black for OLED efficiency. Theme adapters preserve the brand anchors and alter semantic role mappings, and an accent used as text takes the profile's accent-text role rather than its fill role.

    Acceptance

    Theme switches retain layout, focus, selection and data. Red never flashes white/cyan on entry, dialogs or loading. Dark controls use dark on-action text; the existing Daylight Ember requires dark text, not assumed white. Test astronomy text on its action fill.

  4. C29MUST

    One colour truth, two notations

    Author and verify colour in sRGB and publish an oklch projection for the web parts. The anchors, gradients, shadows and semantic roles stay sRGB in the specification, because contrast is defined on sRGB luminance and every published contrast pair is measured there. Web tokens may be written in oklch from the projection in platformAdapters, so one role can step lightness without re-picking a hue. Android and Wear read sRGB: neither toolkit has an Oklab colour space, so a converted value would be a hex with extra steps.

    Acceptance

    Every published web oklch resolves back to the sRGB value it came from within one 8-bit step, and every contrast claim is measured against the sRGB value. A colour is changed once, in hex, and both notations move together; no theme or component carries a colour absent from the registry.

Deep Space token registry
TokensRGBoklch (web)Role
void#120A14oklch(16.10% 0.0242 319.45deg)Page and immersive field
void-edge#1F1126oklch(20.77% 0.0447 313.68deg)Depth at the edge of the field
hull#1D1220oklch(20.34% 0.0317 318.9deg)Standard opaque surface
hull-raised#2A1830oklch(24.45% 0.0506 317.34deg)Raised or selected surface
hull-highest#352040oklch(28.55% 0.0626 313.19deg)Highest temporary surface
ember#FF8C42oklch(75.36% 0.1637 50.4deg)Primary agency: create, continue, commit
ember-soft#FFB27Coklch(82.54% 0.1139 55.48deg)Supporting warm emphasis
rose#FF7E8Aoklch(74.38% 0.1570 15.89deg)Social participation and attention
violet#C9A0FFoklch(77.84% 0.1380 303.2deg)Identity, roles and transformation
gold#FFC766oklch(86.11% 0.1307 79.28deg)Focus, time, precision and value
cyan#00E5FFoklch(84.42% 0.1457 209.29deg)Live, connected and located
moss#83B692oklch(73.03% 0.0750 153.51deg)Outdoor and natural categories
danger#FF6978oklch(71.17% 0.1827 17.02deg)Destructive action and failure
success#71D5A4oklch(79.88% 0.1186 160.71deg)Confirmed completion
petrol#102C2Doklch(27.21% 0.0338 198.5deg)Map ground
water#123D42oklch(33.30% 0.0470 205.97deg)Map water
ink#FFF8F2oklch(98.29% 0.0110 63.36deg)Primary text on Deep Space
muted#BBAEBBoklch(76.57% 0.0233 325.8deg)Supporting text
faint#9A8B9Aoklch(65.48% 0.0280 325.89deg)Secondary metadata; check actual surface
dim#90839Aoklch(62.93% 0.0371 310.51deg)Inactive ornament; not essential text
boundary#9A8B9Aoklch(65.48% 0.0280 325.89deg)Essential control outlines on dark surfaces
03

Light with a job

Eight gradients and two shadows. Each one is a named instrument, never a texture.

  1. C27MUST

    Gradient & glow grammar

    Use only the published gradient and shadow tokens, each for its stated job: field for root depth, nebula for one atmospheric field, corona and accretion for the single focal object, horizon for 1–2 px light lines, rim for the border light of the focal or selected surface, action for the one primary action and spectrum for the brand signature. A screen has at most one corona, one accretion ring and one nebula. Light carries depth and focus, never status, selection or the only boundary, and text never takes a gradient fill. In Full tier the hero figure runs one ambient motion: the focal object's accretion disc revolves once every 40–90 s about the core, and every other light is static — including the accretion ring itself, because a boundary that moves stops being a boundary. Sky drift (C11) is the one alternative a screen may take instead. Deep Space uses the whole grammar, Daylight keeps horizon and spectrum, and astronomy red and watch ambient use none. A gradient token a profile does not run resolves to no gradient, so the element falls back to its flat role color instead of borrowing another profile's light.

    Acceptance

    Every gradient and shadow in code resolves to a token name and its published geometry. Text over a gradient passes against every stop as an opaque pair. Removing all light leaves hierarchy, selection and boundaries intact. The revolving disc moves only `rotate` or `transform`, never a length, and is the only animation on the screen. Forced colors and astronomy red replace light with solid system or semantic borders.

Gradient registry
TokenGeometryStopsJobProfiles
gradient.fieldRadial 120% × 90% at 50% 0%void-edge → void @72%Root depth behind every Deep Space screen. Opaque, so text is measured against void-edge and void.deepSpace
gradient.nebulaRadial 50% × 50% at 50% 50%violet 26% → rose 13% @36% → ember 6% @64% → ember 0%One atmospheric field per screen, behind the focal object or a section entry; never behind reading text.deepSpace
gradient.coronaRadial 50% × 50% at 50% 50%gold 90% → ember 45% @14% → rose 12% @42% → rose 0%The only glow: the halo of the single focal object, painted in a box four to six times its diameter.deepSpace
gradient.accretionConic from 0° at 50% 50%ember → gold @25% → rose @50% → violet @75% → emberA 1–2 px ring around the focal object. Never progress, status or a control outline.deepSpace
gradient.horizonLinear 90°ember 0% → ember @20% → gold @50% → violet @80% → violet 0%Light lines of 1–2 px: the top light of a surface, the horizon ribbon, a section signature.deepSpace, daylight
gradient.rimLinear 135°ember 55% → ink 10% @45% → violet 50%A 1 px border light for the focal or selected surface, beside its essential boundary rather than replacing it.deepSpace
gradient.actionLinear 180°ember-soft → ember @55%Fill of the one primary action. The Void label passes on every stop.deepSpace
gradient.spectrumLinear 90°ember → rose @20% → violet @40% → gold @60% → cyan @80% → mossThe brand signature line. Category legends use solid labelled swatches instead.deepSpace, daylight
04

Stars at the edge

One deterministic sky per screen, generated the same way on every platform.

  1. C11MUST

    One deterministic sky

    A screen, hero, panel or dialog background may own one edge star layer from the published starfield algorithm: stars only in the outer 20% band, area / 7,500 stars clamped 24–160 for screens and area / 10,000 clamped 12–72 for dialogs, three magnitudes, at least 70% Ink, no accent above 10% and at most three diffraction-spiked stars. Seed it from a stable surface ID and a 160 px/dp size bucket. Drop stars within 16 px/dp of known text or controls after generation; never reseed to avoid them. Records, maps, media, data canvases, sky charts and watch screens own no stars.

    Acceptance

    The same surface ID and bucket reproduce the published fixture on every platform. The layer is one cached bitmap, texture or compositor layer, never an element or view per star. Full tier may drift the whole layer once per 90–160 s by at most 1.5% of the shorter edge; Reduced, Static, Save-Data and hidden states freeze it, and low power draws 40% of the stars. Removing the layer changes no semantics or available task.

Atmosphere by surface
SurfaceField & nebulaStar layerFocal lightLines
Web page heroField and one nebula behind the focal objectScreen density; masked from the narrative columnCorona and accretion on the emblem or selected recordHorizon top light; spectrum signature
Web page readingField onlyNoneNoneHorizon section signature
Web app shellField; no nebulaDialog density on sign-in, onboarding and empty states; never over a map or listCorona on the selected markerHorizon top light on the context pane
Mobile instrumentField and one Full-tier nebulaScreen density, cached once per screenCorona and accretion on the targetHorizon top light on sheets
Mobile sheet & dialogInherits the screen fieldDialog densityNoneHorizon top light; rim on the focal sheet
Mobile sky & orreryField onlyNone: every mark is dataCorona on the selected bodyNone
Watch interactiveSolid VoidNoneOne static corona on the bearing or target markerNone
Watch ambientPure blackNoneNoneNone
DaylightFlat backgroundNoneNoneHorizon and spectrum
Astronomy redFlat red backgroundNoneNoneSolid red boundaries only
05

Readable at every scale

A confident display voice, with a quieter reading voice.

  1. C07MUST

    Families & language

    Use Space Grotesk for Latin titles and instrumentation, Source Sans 3 for web reading and form text, native system body type on Android, and El Messiri for Arabic roles. Bundle fonts, declare fallbacks and reserve fallback geometry. Use zero tracking by default; uppercase and spaced labels are Latin-only enhancements.

    Acceptance

    No third-party font requests. Arabic has no mixed-script heading caused by an unsupported font. Font fallback and final font both retain unclipped text and controls.

  2. C08MUST

    Roles & number semantics

    Use the roles below and rem/sp for text. Body line-height is 1.5–1.65; Arabic uses at least 1.6 with tested diacritic room. Reading columns are 55–72 characters. Instrument digits use tabular numerals, visible units and stable width; precision follows actual sensor/data accuracy.

    Acceptance

    Web reflows at 400% on a 1280 CSS px viewport and text zoom at 200%; Android fontScale 2.0; watch largest system text. No essential label is clipped or replaced by an ellipsis-only value.

Type roles; size / line height
RoleWebMobileWatch
Narrative display48–88 / 1.05, fluid rem40–48sp / 1.1, entry onlyNot used
Primary instrument48–72 / 1.148–64sp / 1.132–40sp / 1.1
Page title28–36 / 1.228–32sp / 1.218–20sp / 1.25
Section title20–24 / 1.320–24sp / 1.316–18sp / 1.3
Body16–18 / 1.616sp / 1.514–16sp / 1.4
Supporting14 / 1.514sp / 1.4512–14sp / 1.4
Control label14–16 / 1.314–16sp / 1.314–16sp / 1.3
06

Field, spine, aperture

Geometry should organize attention, not create visual noise.

  1. C09MUST

    Rhythm & mapped shape

    Use 4, 8, 12, 16, 20, 24, 32, 40, 48, 64, 80, 96, 128 units. One unit is a CSS px or native dp, so the same numbers serve every platform and none of them publishes a spacing scale of its own. Take corner geometry from the platform mapping published in tokens.json rather than from a local scale: 8 px / 16 px / 24 px on web, 8 dp / 10 dp / 14 dp / 20 dp / 28 dp on Android, and the native round and capsule shapes on Wear, which publish no dp radius at all. A part that needs another role adds it to the mapping first. Circles denote instruments or compact icon controls, not paragraph containers.

    Acceptance

    Spacing and shape map to named tokens, and a component's corner radius matches its role in the mapping for the part it ships in. No screen carries an ad-hoc px or dp corner value, and a native shape is expressed as the native shape rather than approximated with a number. The Wear layout fits its round screen instead of shrinking its targets. Small-screen compression first removes ornament and gutters; it does not shrink the readable type or hit target.

  2. C10MUST

    Surface budget

    Use opaque Hull for reading and work. A panel, sheet or dialog may carry a horizon top light inset from its corners; only the focal surface adds a rim border. Canopy translucency is optional for one header or contextual overlay, with at least 88% opacity over imagery and an opaque fallback. Allow at most one backdrop blur region per visible screen, capped at 12px on web; disable it when measured costly. Borders establish hierarchy before light.

    Acceptance

    The screen remains legible with blur unsupported or disabled. No live blur behind scrolling long copy, dialog inside a blurred sheet, or full-screen animated haze. Top light never touches a rounded corner at full intensity.

  3. C25MUST

    Icons, imagery & diagrams

    Use one consistent icon family per platform: Lucide on web or the established native library. Standard marks are 20–24px/dp with a consistent stroke; the target remains 44px/48dp. Custom marks are reserved for concepts without a familiar equivalent. Images show the real object/place/person with a declared crop and reserved aspect ratio; diagrams have text equivalents.

    Acceptance

    Decorative icons are hidden from assistive technology. Icon-only controls have localized names; unfamiliar commands retain visible labels. Mirror navigational arrows only. No duplicate icon font, raster text, misleading geographic imagery or unsupported scientific precision.

  4. C26MUST

    Layering & scroll ownership

    Keep field, persistent chrome, contextual popover, modal and urgent feedback in that semantic order using a shared layer registry. Give each pane one scroll owner; the whole page reflows before adding nested scrolling. Bounded overflowing lists expose native scrolling and a visible edge/next-item or explicit navigation affordance. A fade cannot cover essential labels or intercept input.

    Acceptance

    Popover/dialog/focus are never clipped by a record or overflow ancestor. Touch, wheel, keyboard and rotary reach all content. Scroll position and focus survive return from detail; closing a layer restores the correct owner. Reduced mode uses static scroll cues.

Platform geometry mapping
RoleWeb page / web appAndroidWear
Control — compact control, chip, field8 px8 dpround
Secondary — inline affordance—10 dp—
Emphasis — inline emphasis—14 dp—
Record — card or list row16 px20 dpround
Overlay — sheet or dialog24 px28 dpcapsule
Circle — instrument or compact icon control—roundround
07

Component contracts

The same behavior travels; shape and density adapt.

  1. C12MUST

    Actions & selection

    Give a task region one visually dominant Ember action, filled with the action gradient and resting on the action shadow. Destructive actions use Danger and consequence-first confirmation where irreversible. Buttons expose default, hover, pressed, focus, pending, disabled, error and confirmed states. Selection uses shape/check plus aria-pressed, aria-selected or native semantics, while Gold focus is independent.

    Acceptance

    Click/Enter/Space trigger once. Pending preserves the accessible name and width, exposes busy state and prevents duplicates. Confirm only after success; error restores safe retry without losing input.

  2. C13MUST

    Inputs & validation

    Keep visible labels; connect hint, requirement, counter and error. Use real input/select/radio/checkbox/switch semantics. A nonempty editable single-line field exposes a 44px web/48dp native Clear button that returns focus to the field. Do not add it to password, read-only or disabled fields. Validate on submit or meaningful exit without announcing every keystroke.

    Acceptance

    Keyboard autofill, paste, password managers, IME and RTL text work. Invalid fields expose invalid state and a text error; submit focuses the first error or linked error summary. Safe values survive retries.

  3. C14MUST

    Records & navigation

    Keep records in aligned rows unless media/object identity justifies a card. Do not wrap nested links/buttons in another interactive target. Back follows history; Close dismisses a layer. Selected navigation combines label, boundary and programmatic current state. Navigation persists where the task does.

    Acceptance

    Tab order matches reading order. Route navigation moves focus to a named destination heading; dialogs return focus to a surviving trigger. Back/forward restore filter, position and context as applicable.

  4. C15MUST

    Dialog, sheet & popover

    Use one modal layer with a visible title, Close action, safe dismissal policy and actions in reading order. Web uses native dialog or an audited equivalent with focus containment, Escape and background inertness. Mobile uses platform back and inset-aware sheets. Popovers anchor to triggers and reflow before viewport clipping.

    Acceptance

    Focus cannot enter the background of a modal. Unsaved edits get an explicit discard decision. Last action is reachable with the keyboard open and large text. Tooltips never contain the only critical instruction.

  5. C16MUST

    Feedback at the source

    Use inline errors for local failures, a banner for screen-wide degraded state, and status/toast for confirmed transient results. Every primary surface designs first load, refresh/stale, empty, denied, offline, recoverable error, terminal unavailable and success. Loading reserves real geometry; shimmer is optional and never indefinite.

    Acceptance

    Screen readers hear concise changes once; high-rate sensor updates are not live-announced each frame. Error copy says what happened, what remains safe and which action recovers. A toast is never the sole record of a failure.

Shared state matrix
StateVisible treatmentBehavior / announcementOpted out by
Default · C12Opaque surface, legible label, essential boundaryReal enabled semanticsevery component declares it
Hover · C12Tonal lift; no movement of layoutOptional; a pointer that cannot hover simply never shows it12 × notInteractive
Pressed · C12Inset tone; no movement of layoutEquivalent to hover for touch and keyboard7 × notInteractive
Focus · C12, C192px Gold ring + dark separation, 3px offsetVisible, unclipped and not obscured by sticky UI10 × notFocusable
Pending · C12Stable label and small progress markBusy, duplicate guard; cancel if operation allows6 × notAsync
Disabled · C12Muted label, disabled semantics, adjacent reason if usefulNo opacity reduction of all ancestor content10 × alwaysAvailable
Error · C13, C16Danger icon, explicit text and retryPreserve safe inputs; error related to source10 × noFailureMode
Confirmed · C12Success check and specific confirmationRetain durable result in the surface13 × confirmedElsewhere
Selected · C12, C14Check, leading marker or tonal boundary; rim light may accompany, never replace itSelected / pressed / current state as appropriate13 × notSelectable
Stale · C16Muted surface and an age label beside the valueThe value stays readable and carries its age; never a pulse10 × notFetched
Offline · C16Dimmed live surfaces and an offline notice with what is still availableCached content stays readable; recovery names the retry11 × notNetworkBound
Component index
ComponentRules
Primary actionC12, C19, C26
Secondary actionC12, C19
Destructive actionC12, C15, C19
Field with ClearC13, C19, C20
Chips and selectionC12, C14, C19
Record rowC14, C10, C19
SheetC15, C26, M07, C19
DialogC15, C19
BannerC16, C21, C19
ToastC16, C19
Empty stateC16, C01, C19
Reading and statC08, C21, C19
Compass dialM03, M10, W06, C18, C19
Target markerC18, M03, M05, W05, C27
Context spineA02, C26, C10
Horizon ribbonA04, C27, C26
Watch action capsuleW02, W05, W03, C19
08

Motion earns its place

Use movement to explain a change. Silence is a valid finish.

  1. C17MUST

    Three effective tiers

    Full uses 150ms feedback, 300ms local state, 500ms context change and the curve published for the part (C30). Reduced removes spatial travel and ambient loops; optional opacity feedback lasts at most 150ms. Static applies final state immediately. Explicit Static wins; reduced-motion, data saving, low power, thermal pressure and visibility can only lower the tier.

    Acceptance

    Preference changes apply during the session. Full/Reduced/Static produce identical outcomes. Hidden screens and background tabs stop animation and sensor presentation. Hardware concurrency alone never determines ability or tier.

  2. C18MUST

    Progress & moving data

    Animate transform/opacity for transitional UI, avoiding width/height/blur animation. Never auto-pan a map during a user gesture. Sensor smoothing cannot conceal stale/low-confidence data; separate visual interpolation from the stored/announced reading. Auto-updating content provides pause or stable inspection when applicable.

    Acceptance

    No flashing beyond accessibility limits, parallax-dependent meaning, autoplay sound or attention-pulsing CTA. Reduced motion does not disable accurate data. Waiting is stated as text, not inferred from a spinner.

  3. C30MUST

    Easing is published per part

    Use the easing set published for the part: web uses the standard curve with emphasis, entrance and exit for arriving and departing UI; Android and Wear use the standard curve with enter, exit and transform. Every part runs the same three durations; a part that needs another curve or duration publishes it in the mapping instead of defining one locally.

    Acceptance

    Every transition resolves to a published curve, arrival and departure use opposite curves from the same set, and the reduced and static tiers still reach the final state without a curve. No component hard-codes a cubic-bezier, and a curve change is a mapping change rather than a silent divergence.

  4. C31MUST

    One motif per state change

    Animate a state change by naming the published motif whose job is that change, and spend only the properties, duration and easing tokens that motif lists. A change with no motif does not animate. A new choreography is added as a motif with its own job rather than designed once inside a component. The motifs are published in motion.json, and the curve parity fixture in that document is how a native port proves it matches.

    Acceptance

    Every animated state change names a motif, and every motif in motion.json is reachable from at least one surface. No motif animates a property outside its allowed list, and none loops or repeats to hold attention: stale data dims and gains a label. Reduced removes travel and keeps an opacity change within the feedback duration; Static settles immediately and reaches the same final state as Full. A port reproduces the sampled curve values to the published precision, or the mapping is wrong.

Platform easing mapping
PurposeWeb page / web appAndroidWear
Standard — in-place transform and statecubic-bezier(0.2, 0, 0.2, 1)cubic-bezier(0.2, 0, 0.2, 1)cubic-bezier(0.2, 0, 0.2, 1)
Arrival — emphasis and entrancecubic-bezier(0.22, 1, 0.36, 1); cubic-bezier(0.16, 0.84, 0.44, 1)cubic-bezier(0.05, 0.7, 0.1, 1)cubic-bezier(0.05, 0.7, 0.1, 1)
Departure — exitcubic-bezier(0.4, 0, 0.7, 0.2)cubic-bezier(0.3, 0, 0.8, 0.15)cubic-bezier(0.3, 0, 0.8, 0.15)
Transform only—cubic-bezier(0.2, 0, 0, 1)cubic-bezier(0.2, 0, 0, 1)
Motion motifs
MotifJobDurationEasingReduced
targetAcquiredTell the person that the thing they were tracking is now the thing they have.300ms local statestandard, arrivalOpacity only, over the feedback duration; the ring appears already at its final angle.
listRevealShow that a set arrived, in an order a person can follow down.150ms feedbackarrivalOpacity only, staggered, over the feedback duration.
horizonSweepCarry time or progress across a wide surface without a spinner.500ms context changestandardThe band is placed at its final position and its opacity resolves over the feedback duration; no travel.
spineAdvanceMove context forward one step, so the person always knows which step they are on.300ms local statestandardThe connector is placed at its final length and the two steps cross-resolve in opacity over the feedback duration.
sheetRiseShow which context a layer came from, and leave it dismissible.300ms local statearrival, departureThe scrim resolves over the feedback duration and the surface is presented at its resting offset.
dataStaleSay that a reading is no longer fresh, without asking for attention.150ms feedbackstandardThe dim resolves over the feedback duration, opacity only, once.
routeChangeCarry the reader from one context to the next without losing the frame.500ms context changearrival, departureBoth resolve in opacity over the feedback duration, with no travel.
09

Everyone keeps their bearings

Input, language and physical access are part of the design.

  1. C19MUST

    Access baseline

    Target WCAG 2.2 AA on web and equivalent native behavior. Adopt 44×44 CSS px web targets and 48×48dp Android/Wear targets; design the round watch layout to fit rather than shrinking targets. Provide visible focus, names/roles/values, heading structure, error relationships, alternatives to dragging and a skip link.

    Acceptance

    Complete primary flows with keyboard, touch and a screen reader. Focus is not covered by sticky chrome. Forced colors preserves borders, icons and focus; controls use system colors where needed.

  2. C20MUST

    Direction & localization

    Use logical spacing and placement. Mirror navigation flow, never geography, north, compass mathematics or media playback. Isolate authored text, handles, coordinates and times. Localize visible copy, relative dates, plural counts, measurement units and accessible names. Persist unit preference independently of language.

    Acceptance

    Test English, French, Arabic RTL and Spanish with long content and 200% expansion fixtures. Geographic points and bearing values are identical across directions. Critical facts remain readable in the full detail view.

  3. C21MUST

    Privacy & honest content

    Represent accuracy, confidence, time zone, stale data, approximate location and permission state explicitly. Do not imply live data from decoration. Keep private coordinates, profile fields, draft text and sensitive actions out of URLs, crawled pages, analytics and error messages. Use illustrative labels for invented specimen data.

    Acceptance

    Privacy decisions are explained at the action. Public previews reveal only authorized data. A denied or blocked profile does not disclose which private condition caused its unavailability.

10

Structured delivery & release

Make the rules usable by people and machines.

  1. C22MUST

    One source & stable addresses

    Maintain this specification in cosmos/. Generate HTML, plain Markdown, the typed token file and the complete specification JSON together. Stable rule IDs and section URLs are public contracts, and each part publishes its own tokens and rules payload carrying the common foundations plus only its own adapter. Return real files with correct MIME types; machine requests must not silently receive the home page.

    Acceptance

    Generated-output drift fails verification. All routes, anchors, cross-links and downloads resolve in development, preview and production. Manifest includes version, status, scope, assets, platform inheritance and source provenance. A part payload is byte-identical to the canonical documents for everything it shares, carries exactly one adapter, and stays inside its published byte budget, so it cannot drift back into the union. A document needed only sometimes keeps its own address: composited contrast measurements are fetched from contrast-pairs.json instead of being embedded in a payload, and every published document states when to fetch it.

  2. C23MUST

    Performance is measured

    Use the platform budgets and release matrices. Web field targets are p75 LCP ≤2.5s, INP ≤200ms and CLS ≤0.1 for mobile and desktop cohorts. Lab tests are diagnostic, not a substitute for field results. Record route, build, device, browser/OS, network, locale, motion tier and method with evidence.

    Acceptance

    A release has a named owner and real measurements. Visual specifications and mockups are never labeled proof that unimplemented products meet their runtime targets.

  3. C24MUST

    Conformance & maintenance

    Release only after applicable rules pass contrast, input, localization, state and performance checks. Record exceptions with affected rule, product reason, accessible alternative, owner and expiry. A palette or semantic-rule change requires a version update and migration note; minor additions preserve stable IDs.

    Acceptance

    The release record links screenshots, accessibility findings, performance traces and resolved defects. Core maintainers review shared changes; platform maintainers review adapter changes. Broken required flows block acceptance.

Implementation content model
FieldRequired structurePurpose
Ruleid, title, level, requirement, acceptanceStable conformance mapping
Platformslug, description, sections, inheritanceA bounded adapter with common dependencies
Token$type, $value, $description; semantic adapterTyped values; explicit units and color space
Screen brieftask, privacy class, layout, states, input, data, rulesEnough context to implement without guessing
Evidenceversion, build, route, environment, result, ownerTraceable release decision

LIVE COMPONENT STUDY

Feel the difference.

Try the focus, field, selection and action states. This is a local demonstration; no data is sent.

Keep the label useful at a glance.

Ready to try.

Motion preference
+

Starfield reference

The algorithm behind C11. A port is correct when it reproduces the fixture published in tokens.json.

  1. Bucket: bw = ceil(width / bucket) * bucket and bh likewise, in CSS px or dp.
  2. Seed: FNV-1a 32-bit over the UTF-8 bytes of "<surfaceId>@<bw>x<bh>"; random numbers come from mulberry32(seed) as uint32 / 2^32.
  3. Count: round-half-up(bw * bh / areaPerStar) clamped to [min, max] for the surface kind.
  4. Per star, in this order: one draw selects the magnitude, one the radius, one the alpha, one the color; then up to attempts (u, v) pairs.
  5. Color: draw < inkShare is ink; otherwise accents[min(3, floor((draw - inkShare) / ((1 - inkShare) / 4)))], demoted to ink when that accent already holds floor(count * maxAccentShare) stars or all accents hold floor(count * (1 - inkShare)).
  6. Position: reject (u, v) when both lie strictly inside (band, 1 - band), or when the squared bucket-pixel distance to an accepted star is below (2 * max(r, rOther))^2. A star with no accepted attempt is skipped.
  7. Spikes: the first maxSpikes accepted bright stars carry a four-point diffraction cross 5 * r long.
  8. Render at x = u * width, y = v * height. Exclusion zones filter accepted stars afterwards and never reseed.

Fixture: surface cosmos.reference at 390 × 844 lands in the 480 × 960 bucket, draws 61 stars and accepts 61, 0 of them spiked. The first three stars, to six decimals, are in tokens.json under starfield.

+

Explicit theme adapters

Existing palette roles, with accessible on-colors and essential boundaries.

daylight
RoleValue
background#FFF6EC
surface#FFF9F2
raised#F6E7DC
highest#F3E0F7
text#241A14
muted#52443C
faint#6B5F58
linergb(36 26 20 / 0.14)
action#D84E00
accentText#B04300
onAction#120A14
social#B83266
identity#7C4DBD
precision#8B5E00
live#006974
outdoors#356447
danger#9B2432
success#276442
focus#8B5E00
boundary#52443C
astronomy
RoleValue
background#0A0000
surface#1A0000
raised#2A0000
highest#330000
text#E88989
muted#D47575
faint#C06A6A
linergb(232 137 137 / 0.16)
action#8B0000
accentText#E88989
onAction#FFB3B3
social#E88989
identity#E88989
precision#E88989
live#E88989
outdoors#E88989
danger#FFB3B3
success#E88989
focus#E88989
boundary#D47575
watchAmbient
RoleValue
background#000000
surface#000000
text#BBAEBB
faint#9A8B9A
linergb(187 174 187 / 0.16)
bearing#FFC766

Astronomy foreground values are specified to retain contrast on the existing red surfaces. Watch ambient black is an explicit OLED exception. Measure all final component pairs; these values do not certify an entire screen.

+

Sources & repository provenance

The system is informed by real product responsibilities and primary platform standards. Existing implementations are evidence for migration, not proof of v2 conformance.

  • WCAG 2.2

    Web accessibility baseline; Cosmos adopts a stronger 44 CSS px target than the 24 CSS px AA minimum.

  • Core Web Vitals

    Field LCP, INP and CLS thresholds at the 75th percentile.

  • Wear accessibility

    Touch geometry, text and assistive input on round screens.

  • Wear always-on

    Ambient lifecycle, burn-in protection and battery-aware behavior.

  • Design Tokens format

    Typed token interchange; exported sRGB components retain exact hex anchors in extensions.

Repository review · 2 October 2026
ReferenceObservedDesign direction
simt-landing (superseded by simt-space)One large guide; page-owned animated star canvases and mixed native/web examples.Replace with a static, linked specification with measurable rules and one optional atmospheric owner.
simt-social-landingNarrative hero, activity atlas, role discovery, privacy and multilingual public content.Keep the human story and useful atlas; use editorial horizons and actual product evidence.
simt-socialCanonical warm palette, persistent social shell, map/list discovery, activity composer and moderation console.Preserve route responsibilities; improve context continuity, scanning, recovery and density.
simt-appNative instrument palette and typography; adaptive maps, dials and tools.Task-first instruments with stable reference frames, deliberate reach zones and system-owned back behavior.
simt-app/wearCompass, sky, geofence, plumb bob, targets and settings; cyan has a legacy tool-specific value.One-glance tools with shared signal meaning, round geometry and a genuinely quiet ambient state.

Detailed source paths are included in the JSON manifest and complete plain-text guide. Android and Wear physical-device validation belongs to the later product refactors.

CONFORMANCE RECORD

From specification to evidence.

Record the product build, applicable rule IDs, owner, fixtures, environment and results. Attach visual, accessibility and performance evidence before calling the implementation production-ready.

Download the release record template ↗
Continue through the system01 / Web page