One request, twenty six checkpoints, deny by default
An enterprise policy edge, laid out as a site you can walk around. One JSON-RPC request arrives from a wallet or a permissioned app and drives through every check the Gateway makes before anything reaches the chain: six checks on the caller before the request body is even read, three on the request itself, ten dimensions of a single policy decision, a dispatch lane chosen by method class, a hop across the boundary to the private chain endpoint, a filter on the answer, and one audit record at the exit.
There is no rule anywhere in this park that forbids anything. Access is the union of three things that grant it: capabilities fixed in code and handed out through roles, contract permissions scoped to a firm and typed down to the arguments, and operator-managed account attributes. If none of them says yes, the answer is no. That is why the evaluator has ten gates and every one of them must stamp the board: a request is allowed because something specific permitted it, never because nothing objected.
The ten gates are one decision, not ten. The evaluator is a pure function with no database, no network and no chain access at all: it is handed a snapshot view, a subject and a normalised action, and it returns a verdict carrying every dimension it required and every dimension that failed. Driving it as a ring is a way to see that the dimensions are checked in an order that matters, with the operator layer ahead of anything the firm itself wrote.
The taped-off shed with the hazard barrier and the #53 board is the function
lane, and it is drawn that way because that is its real state on main. Run
eth_call and watch: every gate passes, the decision desk stamps ALLOW, and
the lane still answers a policy denial and writes no audit record at all, so the request
is both refused and invisible. It is an unfinished edge rather than a design decision.
Issue #53 owns it and PR #242 closes it. The other two lanes work end to end today.
Every checkpoint is read aloud. The voice is a clone of an English narration reference, rendered offline by a local Chatterbox multilingual TTS server, one MP3 per checkpoint, about nineteen minutes in total. The site fetches a clip only when the cart actually reaches that checkpoint, so nothing is downloaded until it is needed.
When narration is on, a checkpoint waits for the length of its clip rather than for an estimate from the word count, so a sentence is never cut off by the cart pulling away. The speed slider changes the playback rate as well as the pace, which keeps the two in step: at 2× the words and the movement both finish together. Narration plays on the slow first pass and on any checkpoint you ride to on purpose. Once everything has been explained the site runs at a watching pace, and talking over that would only produce interrupted half-sentences, so it stays quiet.
Browsers refuse to make sound before you have interacted with the page. The first click,
tap or key press lifts that, and until then the dock says so. N turns narration off
and on. The site works exactly as well silent: with no audio/ directory the
layer disables itself and the tour uses its own reading times.
With narration off, the first time the cart reaches a checkpoint it waits between 10 and 24 seconds, scaled to how much there is to read, and a bar under the panel text shows how long is left. Once every checkpoint has been explained there is nothing new to read, so the site speeds up to a watchable pace. Space holds any checkpoint for as long as you like, S skips to the next one, and the speed slider scales everything, reading stops included.
The order of the checks, the names of the ten dimensions, the eight method classes, the blocked and operator-only namespaces, the status codes, and the reason codes are taken from the implementation rather than invented. So is the shape of the failures: a stale snapshot really does refuse everything, a valid key on a disabled account really does answer 403 rather than 401, and the function lane really does authorise and then refuse. Scaled down for the sake of the ride: one request at a time instead of many in parallel, a batch of one, and a site you can cross in a minute.
No build step, no dependencies, no network calls. Every shape on screen is drawn from plain polygons in a canvas. The isometric engine is shared with a sibling project, ChipTycoon, which lays out a chip factory the same way.