The situation on a timeline
KAIROS renders every operation as a synchronisation matrix: rows for sectors, assets or topics - each with separate SOLL and IST tracks. Everything here is the feature set of today's app, with no promises about tomorrow.
SOLL and IST on every row
Blocks are drawn directly on the track, moved and resized - on a 15-minute grid. Planning looks like the operation, not like a form.
- Blocks with title, time range, category colours and notes
- "Copy to IST" links plan and reality
- Multi-day blocks, zoom, time navigator and foldable time ranges
- Draft mode: plan locally, commit once
Deviations reveal themselves
The matrix answers the situation question before it is asked:
- Ghost + delta chip: linked IST blocks show the SOLL position and the deviation in minutes
- Delay at the now line: if a SOLL runs without a documented IST, a warning hatch grows - and the now line counts all delays, one click jumps to them
- Running blocks fill up to the now line and pulse
The watchkeeper reports early
KAIROS watches the situation itself: the bell counts, the report centre sorts, one click jumps to the block. Thresholds are configurable per row.
- Overdue blocks and delay above the threshold
- Upcoming SOLL starts as an early warning
- For briefings: the situation centre as an unattended wall display - large type, the view follows the now line
Day view with a personal column
ONE calendar day on a vertical timeline: a chosen operation row on the left (SOLL/IST side by side), your personal column for private entries on the right - its own encryption scope, visible to no one else, never in a report.
- Collisions between the situation and your own day at a glance
- Same block editor, same permissions
- Deliberately not a private calendar: no recurring events, no calendar sync
Live as a team, permissions per row
Changes appear for everyone authorised without reloading. Roles set the frame, row permissions decide the detail: read, write and manage SOLL and IST separately on every row.
- The activity feed shows who changed what and when - with a jump to the block
- Conflicts resolved fairly: both versions side by side, merge field by field or adopt one - nothing is lost silently
- Blocks from participants appear as subtle echo outlines in your own row
Search
Ctrl+F finds blocks across the whole operation - with a jump to the match.
Fold time
Fold quiet night hours, named sub-operations as sections.
Time navigator
Overview strip with a draggable viewport window across the whole operation.
Milestones
Point events for everyone - with colour and a line through all tracks.
Sequences & templates
Compose action sequences relative to T0 and place them as linked blocks.
Situation report
Print/PDF on A4/A3: a hand-over ready report instead of a screenshot.
Device transfer via QR
Your private key moves safely to a new device via QR code.
Row groups
Group, order and structure rows by drag - up to three levels.
Three devices, three jobs
The desktop plans, the tablet leads with touch gestures, the phone reads and captures IST - with its own agenda and day views instead of a shrunken matrix. KAIROS can be installed like an app on your home screen.
- Agenda: what is running, what is overdue, what comes next - as a tappable list
- Day view: your day in portrait, segment List|Day
- IST capture on the go: quick capture from NOW, permission-aware
- Bottom navigation instead of hidden toolbars
The server sees only ciphertext
Content is encrypted and decrypted in your browser before it leaves KAIROS. The server distributes encrypted packages - only those authorised can read them.
Readable only in your browser (encrypted)
- Block titles, start/end, notes and categories
- Row names, milestone titles and times
- Personal entries (their own key scope)
- Operation metadata, where provided
Encrypted with row and operation keys that only authorised members can unwrap.
Visible on the server (envelope)
- Who saved an event and when (account, timestamp)
- Which operation, row and track it belongs to (as IDs)
- Members' e-mail addresses and roles
- Key versions and event types
Passwords are hashed server-side with Argon2id and never stored in plain text.
Your device
Your private key is created in the browser and stays on the device. For moving, there is the QR transfer and the key file with recovery code - only both together restore access.
Key packages
Operation and row keys are wrapped individually per person - only your key opens your package. Revoking access leads to new keys (rotation).
Access by invitation only
There is no open registration. New members are invited by the administration - with a role and prepared row permissions.
Honestly: the limits
- Metadata is visible. The operator can see that and when work happens - just not what it is about.
- There is no password reset by e-mail. Without the key file + recovery code (or a second device already set up), encrypted content cannot be restored - not even by us. That is by design.
- Encryption protects content, not availability. Backups and operations remain the operator's responsibility.
- Whoever has read access can read. E2EE is no substitute for careful permission management.
Technical details
- Content encryption
- AES-GCM-256, 96-bit random nonces (nonce registry)
- Key wrapping
- RSA-OAEP-4096 with SHA-256
- Private keys
- IndexedDB, non-extractable CryptoKey (Web Crypto)
- Login passwords
- Argon2id (server-side)
- Device transfer
- QR transfer via a short-lived one-time drop (encrypted); alternatively key file + recovery code
- Access revocation
- Key rotation, new packages only for authorised members
- Transparency
- Audit log for permission- and security-relevant actions
Ready for the next situation?
Invitation-based and end-to-end encrypted. The crypto diagnostics in the app show every account its own key status.
Sign in