Go to file
Yashas 4c210c7e09 console: a page to monitor from, and words an operator would use
Three problems, and the first one is the reason the other two were hard
to see.

THERE WAS NO DASHBOARD. "/" redirected to the underwriting queue — one
stage, usually empty, and belonging to somebody else. Every screen in
the app answered "show me this queue"; none answered "how is the book
doing, and is anything waiting on me?", which is the only question a
person has before they have picked a queue.

So: a Today page. Three blocks, in the order somebody cares about them.
What is waiting on a person, as three cards that colour only when they
have something in them. Renewals running out, worst first, capped at 30
days because a renewal six months away is not a thing to look at today.
Then every stage with its count, zeroes included — a stage quietly
receiving nothing is only visible if its zero is on screen.

It is one list call, counted in the browser. That is honest at this size
and it is the same call the queues already make. If the book outgrows it
the answer is a counts endpoint, not a bigger page.

THE WORDS WERE WRITTEN FOR WHOEVER BUILT THE WORKFLOW. "What happens
next" was followed by "these are the only activities this state allows
— but the workflow decides, server-side, whether you may". A failed list
said "this queue has no record view yet". Panels were called "Flow
details". A closed lead read "nothing runs from here". None of that is
wrong; all of it is addressed to the wrong reader.

Now: "What you can do", "Lead details", "History", "This queue could not
be loaded". Queue names say what they want — "Documents needed",
"Underwriter to review", "Payment to confirm". The sidebar group called
"Not yet" says "Not due yet", and "Running by itself" says "The agents
have it", which is the actual claim being made.

THE QUEUE HAD NINE COLUMNS AND LED WITH THE WRONG ONE. Two were internal
vocabulary: attribution status renders "clear" or "contested" and means
nothing to an operator, and the channel is background rather than
something anyone scans a queue for. Both fold into a subtitle under the
customer. That leaves six columns and puts the renewal countdown — the
number that decides whether to act today — second instead of fifth.

Also: the timeline printed a raw slug when a step came back without a
name. It is the screen this product is demonstrated on, so a
"zk-act-doc-reminder" in the middle of an otherwise readable story is
expensive. It now reads as English.
2026-09-07 16:13:13 +05:30
public/brand Wire the console to the platform and make it deployable 2026-08-24 15:20:13 +05:30
src console: a page to monitor from, and words an operator would use 2026-09-07 16:13:13 +05:30
.env.example Wire the console to the platform and make it deployable 2026-08-24 15:20:13 +05:30
.gitignore Updated to new frontend specifications 2026-09-04 13:26:20 +05:30
CLAUDE.md Updated to new frontend specifications 2026-09-04 13:26:20 +05:30
eslint.config.js Empty vite-react project 2026-08-24 12:27:21 +05:30
index.html fix(build): add BASE_HREF placeholder + config.js tag to index.html 2026-08-24 15:47:26 +05:30
package-lock.json Wire the console to the platform and make it deployable 2026-08-24 15:20:13 +05:30
package.json Wire the console to the platform and make it deployable 2026-08-24 15:20:13 +05:30
README.md Wire the console to the platform and make it deployable 2026-08-24 15:20:13 +05:30
vite.config.js Wire the console to the platform and make it deployable 2026-08-24 15:20:13 +05:30

Zurich Kotak — Lead Desk

Operator console for the Zurich Kotak "Lead to Policy" demo. Leads arrive through three channels — direct, bancassurance and agency — and run one state machine to policy issuance. The agents do the work; a person appears at one queue.

Workflow config is seeded from sm2/custom-apps/zurich-kotak/ (org 84, app 536, workflow zk_wf_lead). Design doc: sm2/app-designs/zurich-kotak/design.html. Workflow spec PDF: sm2/custom-apps/zurich-kotak/zurich-kotak-workflow.pdf.

Run it

npm install
npm run dev          # http://localhost:5175
npm run build        # → dist/

.env carries the API host for local dev only:

VITE_ZINO_API_URL=https://dev.getzino.in

Logins (all password ZurichKotak@2026, org 84):

Email Role Can do
sanjay.uw@zurichkotak.example SME Underwriter Clear / Decline Referral — the only human decision
meera.rm@zurichkotak.example Bancassurance RM Submit a Partner Bank Lead
arjun.posp@zurichkotak.example POSP / Broker Submit a Partner Agent Lead
kavya.csr@zurichkotak.example Direct / Call centre Submit a Self-Serve Lead
deepa.ops@zurichkotak.example Operations Cross-channel visibility

Sign in as Sanjay to land in Referred to Underwriting, which is where the demo happens.

How it talks to the platform

Everything goes through src/api/client.js:

  • POST /usr/login — auth. org_id must be a string; a number returns cannot unmarshal number into Go struct field LoginRequest.org_id.
  • POST /app/536/view/recordview — every queue is one record view (zk-rv-leads) filtered server-side on current_state_name.
  • POST /app/536/view/form-screens then POST /app/536/activity — forms are read from the live activity schema and submitted straight back.

Forms are not defined in this repo

Whatever /view/form-screens returns is what renders — labels, types, select options, which fields are mandatory. Add a field to an activity in Studio, redeploy, and it appears here with no frontend change. That is deliberate: the workflow is the source of truth, and a hardcoded form would quietly diverge from it.

Permissions are never enforced here

The console does not hide a button to stop someone using it. Every permission decision is the workflow's, made server-side on each submission — the platform refuses and this app reports what it said. Two refusals worth knowing: /activity answers 403, /start answers 400, and both carry permission denied.

The runtime-config contract

VITE_ZINO_API_URL is read at runtime from a config.js the server writes when it places the build — never compiled in. One artifact is promoted between environments unchanged, so a build-time URL would point every environment at whichever backend happened to build it. requireConfigValue throws if it is missing, so a production build with no config.js fails loudly rather than calling the wrong backend.

vite.config.js uses base: './' and the router takes its basename from the <base href> the server writes, so one build serves any mount path. Do not reintroduce a build-time base.

This is also why the fonts and logo live under src/assets/ and not public/. Vite rewrites bundled asset URLs to be relative; a public/ file referenced as /fonts/… stays absolute and 404s under the /zurich-kotak/ mount path. The favicon is the one exception — it stays in public/brand/ and is referenced relatively from index.html.

Deployment

Registered with frontgen by sm2/custom-apps/zurich-kotak/05_frontgen_project.sql (slug zurich-kotak, repo_name zurich_kotak, org 84). A push to main builds and serves at https://preview-dev.getzino.in/zurich-kotak/.

The webhook only fires on a new push — a push made before the frontgen project row existed matched no project and did nothing.

State of the build

Piece Status
Brand — Zurich Sans, palette, logo done (kept from the original scaffold)
Sign-in against the real gateway done
Runtime config, relative base, router done
Pipeline sidebar (mirrors tbl_wf_states) done
Queue lists waiting on the zk-rv-leads record view
Lead file, activity forms, attribution panel waiting on zk-dv-lead + form screens