The dashboard is your own institution's home. It says who you are and how to correct the figures, what is waiting on you, where to look first, and where you stand this quarter — in that order, on one printable page. It is also where the Work ledger states its next step, so this page covers both. Institutional and above
Whose bank it is, and why that is not a link parameter
The subject is resolved from your organization's recorded relation to a certificate, server-side. It is never taken from the address bar. A home surface that could be pointed at somebody else's bank by a parameter would be a page titled yours showing figures that are not — so the resolution is structural rather than polite. If your account has no institution on record, the page says exactly that and sends you to Settings instead of guessing.
Update your institution
The first thing under the identity line is the update lane. When you hold figures newer than the filing — a month-end close, a restated balance — you enter them against the figures they replace and the whole rule book re-runs on them. It is one lane, not two systems: the dashboard links it rather than rebuilding it, because a second place to enter your own numbers is a second set of numbers.
What comes back is a change register — only the rules that moved, with the filed value and word beside your value and word — and it requires an as-of date, because an undated recomputation is undatable evidence. It writes no findings and it does not replace the filing. See Prepare for the engine behind it.
Next steps — the top of your queue, in the ledger’s own order
The strip states 3steps at most, taken from the top of the Work confirm queue. It does not re-rank them: the ledger already ordered the queue, and a second ranking on the home page would be a second answer to a settled question. The verb on each step comes from the lane the ledger assigned it, and the ledger's own sentence for why the row is waiting travels with it, verbatim.
Nothing on the strip closes anything. Every step links into the ledger, where a person decides. An empty strip says that nothing is waiting on you — which is a fact about the queue and about nothing else, and the empty state says so in those words rather than reading as an all-clear.
Where to look first
Below the steps sits the priority strip: the most severe adverse reading across the summarised domains, linking to the surface that produced it. If nothing is adverse it says so. A quiet quarter is a result, not an empty state.
The position summary
One object where there used to be two. The scoreboard is its evidence and the brief is its prose, under one heading with one export.
- Worst-of, per domain.One card per analytical domain, showing that domain's most severe evaluated reading, the measure driving it, and how many of the domain's signals carried a state at all — "3 of 6 signals evaluated", so a subset is never shown as the whole. Rows that state a fact without a verdict are excluded from the ranking and counted out loud.
- The cards are grouped by the domain the figures came from, not by a governance body. The lens picker that used to group them by who was in the room retired with the surface that hosted it; every measure it grouped is still here.
- 4 domains here, all eight on the institution view.The summary states its own scope and links onward. Widening it would double the reads on the product's home page to fill cards nobody asked for.
- A domain that could not be read is not evaluated — never a clean bill, never a card quietly left out.
- The brief, inline. Field Notes is a source-anchored regulatory read of your latest filing, generated on request beside the figures it describes. Any narrative prose is validated first: every numeric token has to trace to a canonical figure, and where it does not, the deterministic summary is substituted. Institutional and above
Print / save as PDF prints the page. That is the honest export and not a shortcut: the merged artifact does not exist anywhere else, so printing through a generator would hand you a document whose numbers disagree with the screen that produced it. What prints is the canonical figures, the brief generated beside them, and the provenance under both.
The board summary PDF is still offered, below, labelled with its own source line. It is a different document from a different feed — a landscape deck with a scoreboard, the flagged metrics with citations, peer comparison, enforcement, quarterly changes, board questions, and a closing boundary slide that is always last. Slide numbering is computed, so a conditional section cannot leave a gap. Institutional and above
What the engine last recorded
The page closes on the run line: when findings were last recorded for this institution, and the way into the engine. It has no invented third state — a run that finds nothing writes nothing, so an empty record is either a rule book with nothing to record or an engine that has not been run here, and the line says which it cannot tell apart rather than reporting a zero.
The Work ledger behind the next steps
Work is one ledger: one object, one lifecycle, five sources. It opens on the confirm queue — the things waiting on a human — and every other way of asking what you owe is a facet of the same list, addressable as a URL. An examination finding used to live on one page, a supervisor inquiry on another, a rule finding on a third, a posture gap on a fourth and a mock-examiner gap on a fifth; the five registers are facets now, and the surfaces that do the work kept their own routes, because a register is not a workflow.
The ledger has its own row on the institution view — panel 11, which carries this institution's slice of it — and its facets are linked from there and from every next step above.
The confirm queue, and its three lanes
- Awaiting confirmation — the ledger will not treat these as a record until a human decides. Nothing here was machine-classified with confidence, which is exactly why it is waiting.
- Input changed — awaiting human review — an amendment moved an input under an existing obligation. None of them moved state, and none will: an amendment that clears a condition never auto-closes anything.
- Recorded by rule — not yet reviewed — deterministic rule flags record themselves; the human act is the decision to dismiss. Nobody has made one on these, so they are shown rather than hidden.
An empty queue is not an all-clear, and the empty state says so itself — it names how many of the five sources actually project.
Four actions, and no close
- Confirm — a human accepted this. The lifecycle state is untouched.
- Dismiss — a human said no. The obligation stays in the ledger as that record. Nothing is deleted and nothing is marked resolved.
- Defer — not now. It stays in the ledger and leaves the queue until it is touched again.
- Acknowledge the change — a human looked at the changed input. Changes no column, and never closes.
There is deliberately no close action and no delete — not on a row, not in bulk, not behind a menu. A compliance record that can be closed by clicking is a record whose absences mean nothing.
The facets: two axes, both in the address bar
One axis is the lifecycle state; the other is the source. A third narrowing takes a single measure, which is what a signal row on your own institution viewlinks into when you follow "the work this implies". Every combination is a URL you can bookmark, cite in an email, or hand to a colleague.
The state axis speaks the ledger's own words and no others:
- Identified · confirmed · in remediation · closed · dismissed · superseded— the six lifecycle states, verbatim. There is no "in progress", no "resolved", no "done".
- Open — the working set: identified, confirmed and in remediation together. It is the same set the deduplication rule treats as open, so a closed or dismissed row can never block a later re-detection of the same condition.
- Overdue — derived from a recorded due date that has passed, and it says so. There is no overdue state in the ledger, and an obligation with no due date can never appear here.
- All — no state filter at all. Closed and dismissed rows are records and are still here; nothing in the ledger is ever removed.
A value the contract does not recognise is refused, never quietly dropped. Answering a narrow question with a wide list — five sources to somebody who asked for one, with nothing on screen saying so — is worse than refusing the link, so the surface refuses it and names what it did not understand.
The five sources, and where the work is actually done
Each source facet names the page it replaced and links to the surface that still does the part that did not move — because the ledger is a register: nothing here logs an inquiry, writes a finding, runs the rule book or answers a mock-examination question.
- Rule flags — what the rule book raised against your filing. Recorded deterministically, which is why they skip the identified state. The engine cockpit is where the whole rule book lives; see Prepare.
- Posture gaps — gaps the readiness library found against your recorded posture. The posture editor is where you answer them; see Prepare.
- Mock-examiner findings — gaps a practice session recorded.
- Examination findings — the matters requiring attention, and matters requiring immediate attention, from your examination report. This facet is what the old Findings list became.
- Supervisor inquiries — regulator requests. This facet is what the old Inquiries register became.
There is deliberately no sixth source. Attestations are an input to the attestation rules, whose failures already arrive as rule flags — making them a source would count the same fact twice.
Logging a finding, and logging an inquiry
The two things you can only do at their own page stayed at their own page, and the source facet links straight to each. Redirecting them away would not have been a migration, it would have been a removal.
- Log an examination finding — enter a matter by hand, or paste the text of the examination report and let the extractor propose them. Each finding carries tasks with owners and due dates.
- Log an inquiry— record the regulator, the type, and the date the request arrived. From the inquiry's own page you draft the response against your posture as it stood at the inquiry date, section by section, and export it.
Two words on an inquiry carry weight, and the surface separates them because the alternative is an institution believing a response went out when it did not. In review means marking it ready, and sends nothing to anyone. Exportedis not submission: nothing here says the regulator has received anything. The inquiry's own six-state workflow is preserved verbatim on every projected row.
The re-audit
When the quarter turns and the filing catches up with the work, a re-audit re-runs the rules scoped to the examination areas your findings touch — the reading at the time of the examination beside the current reading, with the delta. Findings whose rule now passes, or can no longer be evaluated, are gathered into a list you resolve yourself. The engine surfaces the change; it does not close your finding for you, and resolution is gated on the tasks under the finding as well as on the rule. A rule that flipped and work that was never done is not a resolved matter.
What a row tells you, and what the detail adds
Title, severity, lifecycle state, and — where one exists — the examination book and area. Where none is assigned the row says so plainly: a human assigns it, and the ledger does not guess. The provenance names the source table and row it came from; the citation is a link where one resolves and an honest note where it does not. Open a row for its full trail, the evidence documents that cite it, and the surface that produced it.
The audit trail behind all of it
Work is a register of obligations. The trail is a register of events — one append-only stream across the surfaces that write to it, where a correction is a new event naming the event it corrects. Nothing is overwritten and nothing is deleted. It carries posture edits, vault activity, the inquiry workflow and mock-exam sessions, each deep-linkable, and every event type belongs to exactly one of those four, which is what makes the counts trustworthy.
The engine's runs and flags do not append to this stream, so they do not appear in it — the page states that in its own scope note rather than letting you conclude from an empty filter that nothing happened. Filter, search, page and session scope all live in the address bar and are applied server-side in one pass, so a view you are looking at is a view you can link to. Export produces exactly the selection on screen. The stream reads a bounded number of the most recent events and the provenance line says how many it read and how many exist: a trail that silently truncates is a trail that can be wrong without ever looking wrong.
Who can read it, and who can write to it
The ledger holds a tenant's own compliance record, not public data, so access climbs four rungs: a session, the entitlement, an organization, and a recorded relation between that organization and the institution. Every relation may read. Only an own or client relation may write — a watch or prospect relation renders read-only, up front, rather than letting you discover it by clicking. A filter narrows a list that was already scoped this way; no facet, source or measure can widen it, because none of them names an organization at all.
A first pass, in order
- Open the dashboard from the top of the rail. Check the identity line and the quarter before anything else.
- Read the next steps. If one of them is the reason you opened the product, follow it into the ledger and decide there.
- Read the summary cards, then follow "all eight domains" into the institution view for the measure that concerned you.
- Generate the brief if you want the prose, then print the page — that is the executive summary, figures and words together.
- If the filing is behind your own books, use the update lane and read the change register.
The engine cockpit, the posture editor, the vault and the inquiry register all state the same thing in their own copy: they do not write to the ledger. A projection runs on its own schedule and turns findings, inquiries, rule flags, mock-examination gaps and posture gaps into ledger rows. That separation is why the ledger can be a record rather than a side effect of browsing — and it is why every cross-reference on those surfaces is read-only, and reports not checked rather than no obligation when the lookup fails. Those two answers mean opposite things.
MDRM IQ is an informational and exam-preparation tool. A status word is a statement about a published line and a filed figure; a next step is a statement about what the ledger recorded. Neither is a rating, a compliance determination, or a prediction of what an examiner will find. The accuracy of figures you enter yourself is your institution's responsibility.