Two-axis review found the shipped colour and three weak tests.
- --patina was a warm gold at the same hue family as --brass; the spec
asked for a cool blue-green so an unhealthy Lane is unmistakably not
ember. Now verdigris in both branches, with docs/design-system.md
stating why the far side of the wheel is the point.
- A Lane pass that returns before computing its figures carries the
previous pass's due count and gap forward instead of recording zeroes,
and Checked rides beside Due so a stopped Lane is distinguishable from
a quiet one.
- TestAdminPageWithoutAPollerSaysSo now separates the two causes it
conflated, TestOwnerClearsReaderMarks seeds real counters so the
clearing assertion can fail, and TestLaneStatus asserts Checked and
the carry-forward.
- backend/AGENTS.md records the one deliberate owner comparison outside
requireOwner and the carry-forward rule.
The only operational surface was /healthz and a fold-out roster inside the
owner's own reading page. This gives the owner a page: two sections of facts on
the same measured sheet, no cards.
- admin.go holds every route that reaches past the acting Reader, listed once
in adminRoutes() and wrapped in requireOwner at registration - a missing gate
is visible in the route list rather than hidden inside a handler. A non-owner
gets 404, the same answer revoke already gave.
- Lane figures arrive through the LaneReporter seam, so the page reads the
running poller rather than a table. newRouter converts a nil *Poller to a nil
interface: a typed nil would make the page claim a poller exists.
- The roster moves out of the reading page and gains the Sighting counters, the
blocked verdict and Clear marks. Clearing restores a privilege, so it is a
plain ghost button; --danger stays with revocation.
- --patina is the page's one accent, held at the weight of the other action
accents. Neither --ember (new chapter) nor --danger (destruction) is borrowed
for system health.