Behavioural invariants
Five rules every RC3 surface must satisfy. Properties, not opt-in patterns — layouts can vary; these hold.
Safety in one tap
“Safety actions are reachable within one tap from any live state.”
Operator stress and time-critical recovery cannot tolerate menu-diving. The e-stop, override, and abort affordances stay in the first interaction layer whenever a platform is live — never collapsed into overflow, never hidden behind a mode.
Comms always visible
“Comms and health are visible whenever a live platform is connected.”
A degraded link is information the operator needs before deciding anything. RC3 surfaces keep link state, signal strength, and platform health on screen for every connected platform — not in a settings panel.
Active context unambiguous
“The active context — which platform, group, or mission is in focus — is unambiguous on screen.”
The same command word means different things at different scopes. Every RC3 surface anchors the operator with a clear active-context indicator so a tap that means “move” cannot be misread as moving the wrong thing.
Deliberate transitions
“Autonomy transitions, takeover, and override require deliberate confirmation.”
Handing control to autonomy, taking it back, or overriding a running command are mode-shifts with operational consequence. None of them happen on a single accidental tap — each requires an explicit confirm gesture.
Telemetry never silently stale
“Telemetry never goes silently stale. Degraded data states are visible, not masked.”
A frozen number that looks fresh is worse than no number. When data goes stale, the surface marks it stale with a timestamp — operators see the degradation before they act on it.