Route authority
OwnsActive route revision and ordered maneuvers
Must not inferAccessory sensor proposal cannot invent maneuver
Glanceable guidance that never outlives its route, owner, power or safety evidence.
Bind every presentation to current ownership, pairing, route revision, maneuver sequence, power/thermal state and device capability across cluster, HUD and accessory surfaces.
Every layer exposes an authoritative responsibility and an explicit non-authority boundary.
OwnsActive route revision and ordered maneuvers
Must not inferAccessory sensor proposal cannot invent maneuver
OwnsCurrent owner, visible code and session capability
Must not inferPrior owner or code alone cannot pair
OwnsEligibility, sequence, expiry, power and thermal gating
Must not inferPresentation record is not physical output
OwnsAllowlisted controls and declared visual/tactile capability
Must not inferSunlight layout is not a readability or safety claim
Each transition names both the action and the identity or version evidence that makes it reproducible.
Validate current owner, visible code, device state and capability.
owner/device/session · code expiry · policyBind exact route, sequence, expiry and content/runtime versions.
route revision · maneuver ID · sequenceCheck phone presence, battery, thermal, display and declared output capability.
health/config · observed time · capabilityChoose permitted layout and record reference presentation without physical claim.
presentation revision · layout · false output boundaryAccept allowlisted debounced controls; update via health-gated rollback lifecycle.
control/idempotency · release/config · healthOwner/device/code/session/capability and revocation.
Route, maneuver, sequence, expiry, versions and validity.
Surface layout, capability, revision and allowlisted intents.
Config/release, preflight, health, commit and rollback.
Make every presentation unavailable rather than repeat stale guidance.
Fail separately and hold presentation until authoritative recovery.
Protect accessory independently and declare reduced/unavailable capability.
Suppress duplicate control without changing route state.
Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.
Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.