Drivable UI

App Control

SpecifiedUI

Not the product Control Plane. A debug/test adapter: identifiers, GET /state, POST /action, GET /screenshot. Same methods the buttons call. Loopback, env-gated, typed enum — never a second HTTP host.

Product Control Plane

The six-pillar Andromeda window / capability curtain. Real product surface.

App Control

Debug/test drivability: identifiers + /state /action /screenshot. Env-gated, loopback, not a second product server.

  1. Do not add a second HTTP host. App Control is new routes on the existing AndromedaHTTP router, env-gated (ANDROMEDA_APP_CONTROL=1), loopback or the same bearer as /mcp.
  2. Identifiers: andromeda.<pane>.<control>. Identifier ≠ accessibility label.
  3. Typed ControlAction enum — unknown action is a loud 422, never a silent 200. Dispatcher calls the same methods the buttons call.
  4. Screenshots via ImageRenderer / off-screen AppKit — never screencapture.
  5. CLI / MCP / OSA are translators after Gate 1 (curl proves human click ≡ POST /action). OSA waits for a real Andromeda.app bundle.