Getting started
Sign-in & account
KAIROS first asks for your e-mail and derives what comes next: enter a password, create an account or redeem an invitation code. The first user of a system automatically becomes system admin; everyone else joins by invitation only. Setup is guided by a stepper (code → account → backup) with a password strength indicator.
- Enter your e-mail – KAIROS determines the state (known / invited / first user).
- Set or enter your password – with an invitation, the invitation code first; an invitation link scanned via QR prefills the code automatically.
- The first time, your browser generates your key pair (E2EE) automatically.
- Complete the backup (chapter 2) – after that the app is unlocked.
- KAIROS can be installed as a PWA (Add to Home Screen) and then starts full-screen.
- When signing out you can optionally remove keys and local settings from the device (foreign/shared device) – with a warning if no backup is on record.
Key backup & device transfer
All content is encrypted and decrypted in the browser; the server stores only ciphertext. So you never lose access, you secure your key with a key file + recovery code. You also get onto a second device via QR transfer – with no file and no code at all.
- Export the key file and store it safely (
kairos.private-key-backup.v1). - Note the recovery code separately – file and code together unlock the key.
- Confirm the backup with the checkmark; the hint disappears afterwards.
- Changing devices: in Security → "Transfer to mobile device" show the QR, scan it on the new device – the key travels encrypted and is imported automatically.
- Important: file or code alone is not enough – both are needed.
Setting up an operation
Operation, duration & sections
An operation is the working document – a synchronisation matrix for a deployment or an exercise. You can run several, switch between them and archive them. In the Administration (zone Settings) you define how the matrix starts for everyone.
- Create and name an operation in the Administration.
- Set the polling interval (how often the app checks for changes, 5 s–5 min).
- Set the operation duration – it becomes the matrix’s default time range – and optionally define sections (sub-operations, phases, days; one can be the default).
- Adjust the matrix zoom levels (hour values) if needed.
- For large operations create a snapshot – an encrypted intermediate state for faster loading; nothing is deleted.
- Archive operations no longer needed (instead of deleting – traceable).
People & invitations
People join via an invitation code. Members and open invitations sit in one people list with status (invitation open, ready for activation, revoked, expired). Each person gets a role; the concrete effect is governed by the row permissions (chapter 6). Invitations can carry prepared row permissions via a preset.
- Admin – manages the operation, people, teams, rows and settings; sees and edits every row even without own row permissions, and sees hidden rows.
- Planner – may additionally create rows and set milestones; on the rows themselves only the row permissions apply.
- Live recorder – intended for capturing the ACTUAL situation; effect via row permissions only.
- Reader – intended for following the situation; effect via row permissions only.
- Live recorder and reader carry the same role rights – the difference is what is expected of the person; whether somebody may actually record is decided by the row permissions. The same overview unfolds in the app above the list under "What sets the roles apart?".
- Create an invitation; prepare row permissions via a preset (Observe / Plan / Record / Plan + record / Manage) and optionally pre-assign teams – on activation the person joins the pre-assigned teams and receives their row keys (chapter 6).
- After creation the handover card in the drawer shows the code large, a ready-made handover text and a locally generated QR code (opens sign-in with the code prefilled). The code is retrievable only in this session – "Open handover" in the people list brings the card back, "Create new" replaces an invitation whose code was lost (the old code becomes invalid).
- "Rights" in the person row opens the user rights: all rows of one person in a single drawer (tier row per row, chapter 6); "Set all rows to …" only upgrades, rows without your own manage permission appear dimmed ("managers only").
- Later: remove members or revoke invitations – the affected row keys are rotated (chapter 25).
- Revoked and expired invitations leave the list and sit collected at its end under "Show … closed invitations" – they are kept (traceable) but no longer fill up the overview.
Rows, groups & categories
Rows are the horizontal tracks of the matrix (e.g. sectors, assets, topics). They can be coloured, bundled into groups, sorted and collapsed. Categories give blocks a colour. Per row, admins use the row settings to set defaults for new blocks, the watchkeeper thresholds (chapter 17) and the visibility (hide the row or release it at a set time). With the star you mark your rows – the lane scope "My lanes" narrows the matrix down to them.
- Create and name a row (the name is stored encrypted).
- Set a row colour – it appears as the left edge of the row header.
- Sort rows by drag or nest them in groups; expand/collapse groups.
- Maintain categories in the Administration – they colour the SOLL outline and IST solid.
- Row settings (also in the matrix’s row context menu): default category and "Do not track blocks by default" for new blocks of this row.
- Visibility (admins only, in the row settings): "Hidden" hides the row from everyone except admins – permissions and keys remain in place, everything reappears the moment the row is shown again. "Visible from" releases it automatically at the chosen time (server time; others see it at the latest when they next load the operation). Admins see hidden rows dimmed and tagged and can keep planning; lateness, watchkeeper, situation bar, day view, quick capture and print leave them out. Hiding is organisation, not a permission revocation. New rows can be created "hidden initially".
- My lanes: the star on the row header (appears on hover) or the context-menu entry "Add to my lanes" makes a row a favourite. The scope pill in the top bar (next to the time-range picker) switches between "My lanes" and "All lanes"; when the scope hides rows, a footer at the end of the matrix honestly says how many – "Show all" lifts the filter. Default: the rows you can write; the choice is stored per device and operation. Briefing and situation centre always show all rows.
Row permissions
Per person and row it is finely controlled who may read and write SOLL and IST – and who manages the row’s permissions. The permission drawer shows one tier row per person: the six tiers (None · Observe · Plan · Record · Full · Manage) as a one-click segment with the active tier always visible; "Fine-tune" expands the five individual permissions. Plus Quick grant; saving happens in one batch. Reachable from the Administration and the matrix’s row context menu.
- Read/write SOLL – see or edit the plan.
- Read/write IST – see or record the situation.
- Manage – grant this row’s permissions.
- Custom – a manual setting via "Fine-tune" (combine the five individual permissions freely); the row then carries the Custom chip.
- Revoking – if a person loses all access, the row shows the Key rotation chip before saving (chapter 25).
- History included – whoever newly receives read access to a row gets the keys of all previous states of that row and therefore also sees entries written before an earlier key rotation. If something stays locked anyway, Administration › Monitoring shows the gap under Keys & coverage with "Distribute".
- User rights – the mirrored view per person: the Rights button in the people list (chapter 4) opens all rows of one person; the names link both editors (stacked drawer).
- Teams – row permissions per group of people instead of per person: operation admins create teams under Administration › People ("New team"), assign members and grant row permissions on the team ("Team rights", tiers up to Full – managing remains an individual right per person). Members receive the team rights automatically; the highest right always applies, combining direct and team rights. The rights drawer shows the team base as a "via team" chip; what you edit there is still the direct right.
- Joining/leaving a team – whoever joins a team automatically receives the row keys of the team rows; whoever leaves without any other read right triggers a key rotation – the confirmation lists the affected rows beforehand. Whoever keeps reading via a team loses nothing when a direct right is revoked (no rotation).
Planning (SOLL)
Matrix & time range
The matrix is the main work surface: rows with SOLL/IST tracks on a timeline. You pick the displayed time range in the header picker ("Auto"): today, last 24 h, whole operation, a custom from/to span or a defined section. The View menu bundles display, mode and output.
- Zoom with Ctrl+mouse wheel (anchor-centred) or via the zoom levels; pan by scrolling/dragging.
- Now jump: click the now line or the "now" edges at the border.
- The axis head has two fixed storeys: the calendar row on top (day chip + time of day), below it the marker band with the now pill, fold capsules and milestone pins. When markers touch, the less important one dims (now > capsule > milestone) – it stays clickable.
- In the View menu: deviation, stacking, planning mode, fold time, time navigator, category colour (Area fills the block / Code shows a short label chip – personal per device).
- Click a block → the right-hand work panel (editor) opens.
- The category legend at the bottom filters on click (non-matching blocks dimmed).
Planning blocks
A block is an undertaking with a start and an end. You draw it on the SOLL track and fill in the right-hand work panel: title, time trio (start/end/duration) with quick chips ("From now", "Until now", "15 min" ...), category, note. The toggle "Block is tracked" separates undertakings from pure information.
- Draw on free SOLL space – a new block is created.
- Set title, time (15-minute grid, multi-day blocks possible) and category.
- Optionally add a note, participants (chapter 20) and the tracking toggle.
- Save – or via the context menu duplicate, copy to IST, end now, archive.
- Untracked blocks step back quietly: no delay, no status-panel/watchkeeper entry.
- The editor shows the block’s history at the bottom (all events expandable).
- Read-only? Then the work panel ("View block (read-only)") shows quiet values instead of input fields: title, start/end with date, duration, category, note and participants – just "Close" at the bottom.
Milestones
Point events without a duration (readiness established, hand-over, situation briefing) are milestones: pins in the always-present marker band below the calendar row, with a line through all rows.
- In the header’s + New menu choose "New milestone".
- Set time, title and colour.
- The pin appears in the axis’s marker band; a click opens it again. If the now pill sits over a pin, the pin dims briefly (chapter 7) – it stays clickable.
Sequences & templates
Recurring action sequences are planned as a sequence: several steps with a duration, anchored relatively (offset from T0 or after the predecessor with a buffer). When placing you choose the T0 time, target row and track – KAIROS creates all blocks at once.
- In the + New menu choose "Place sequence" and compose the steps.
- Optionally "Keep linked": the group stays connected – moving the anchor pulls the dependants along; in the block editor "Detach link" detaches one block or all.
- Save sequences as a template: personal (this device only) or shared (for everyone, by admins).
Fold time & time navigator
Long operations have quiet stretches. Fold time collapses nights, breaks and empty spans into narrow bands (a click expands them briefly). The time navigator is an overview strip of the whole time span with a draggable viewport window – click jumps, dragging moves, the mouse wheel zooms.
- In the View menu open "Fold time": presets (nights, weekends), an auto suggestion for empty spans, your own daily rules and fixed spans.
- Admin rules apply shared to everyone; in addition you can fold personally or hide shared rules locally.
- Expand/collapse the time navigator; renderer in the View menu: Auto / Blocks (mini map) / Profile (density).
- The fold capsule (label + duration + hidden counter) sits in the axis head’s marker band; under the now pill or the "now" edge marker it dims briefly but stays clickable (chapter 7).
- Participant echoes appear faded in the blocks renderer in the participant row; clicking focuses the origin block in its row. The density profile deliberately does not count echoes (the same work would appear twice).
Planning & draft mode
Two modes lighten planning: planning mode hides all IST tracks (half row height, more overview). Draft mode collects changes locally on your device – nothing leaves until you finish; only then is exactly one event written per block.
- Both modes live in the View menu (zones Display and Mode).
- In draft mode a status bar shows the state ("3 open · 2 new · 1 changed") with Finish / Discard; the draft even survives a reload.
- Draft blocks are marked as "Draft: new/changed"; conflict resolutions are deliberately always saved immediately.
Search & filter
The search (magnifier in the header or Ctrl+F) searches the decrypted blocks client-side by title and note. Matches are highlighted in amber; Enter jumps to the next, Shift+Enter to the previous, Esc closes.
- The jump centres the match – even outside the visible range.
- Blocks without read permission or without a key are honestly not searchable.
- In addition, the category legend at the bottom filters the matrix on click.
Situation tracking (IST)
Logging IST
What actually happens goes on the IST track. Fastest with quick capture (key N, the "Log IST" entry in the + New menu, on the phone More → "Log IST"): one line of text, one IST block starting now. From the SOLL there are Copy to IST and Start on IST now. Recording requires the IST write permission.
- Quick capture:
What happens? @row #category +duration– e.g.Catering arrived @log #cat +45; Enter creates the block, the bar stays open for the next report. - Or click a SOLL block → context menu "Copy to IST" / "Start on IST now" (the copy starts at the now line).
- Finish running IST blocks with "End now"; edit afterwards if needed.
- The copy remembers its source – the comparison feeds on it (chapter 16).
Now line, running & delay
A continuous now line travels across the matrix. A block whose time is currently running fills up to "now" and pulses. If a SOLL is due without any IST recorded, it tips into delay (warning hatch + duration chip); a counter at the now line bundles all delays.
- Running – green fill + pulse (SOLL and IST alike).
- Delay – yellow hatch of the elapsed share, chip "+N min" or "no IST".
- Counter at the now line jumps to the delays one after another. The now pill (time of day + counter) sits firmly in the axis head’s marker band and never reaches into the rows.
SOLL/IST deviation
The core question – "are we on plan?" – KAIROS answers right at the block: on the IST track the linked SOLL block appears as a dashed ghost, plus a delta chip with the deviation (late = warning colour, early/on plan = green).
- The prerequisite is the link from "Copy to IST" (chapter 14).
- The ghost shows where the plan was; the chip the difference in minutes.
- Toggled in the View menu via "SOLL/IST deviation".
Watchkeeper
The watchkeeper monitors the situation for you: the bell in the header counts new alerts from the delay watch. The report centre knows three kinds: No IST recorded (SOLL end elapsed), Delay over threshold and Starting soon. Admins set the thresholds per row in the row settings; they apply to everyone.
- Open the bell; per alert: Jump to block, Log IST (opens quick capture pre-filled) or Mute lane.
- "Mark all as seen" clears the badge; seen state and mutes apply per device.
- Optionally enable browser notifications for critical alerts (only while the tab is hidden).
Resolving conflicts
If two people edit the same block at the same time, KAIROS detects it via the editing base and shows the banner "This block was edited concurrently." in the editor. The "Resolve conflict" drawer puts both versions side by side – you decide per field what applies.
- The conflict block is clearly marked; "Resolve conflict" opens the comparison.
- For each differing field (title, start, end, category, note) choose the version; the original base sits alongside as a silent reference. Shortcuts: "All from ...".
- Save result writes a consistent merge; identical fields are adopted automatically, "end before start" is checked live.
Collaboration & output
Activity & live sync
Several people work at the same time; the app fetches changes at the configured interval (sync ring in the header, click = immediately). The activity feed shows who changed what and when – with filters, grouping, change diffs and a jump to the block.
- Open Activity at the top; a badge shows new, unread entries ("New since last view").
- Filter by event type (created/changed/archived/not decryptable) or row; group chronologically or by row; bulk changes are bundled.
- Entries show diffs ("Start 10:00 → 10:30"); tapping jumps to the block.
Participants (echo blocks)
A block can appear in further rows as a participant without being copied there: the master carries the participant list, in the target rows a read-only echo appears. Clicking the echo shows the master content.
- In the block editor under Participants choose further rows.
- A hatched echo with an origin hint appears there (read-only) – in the matrix as well as in the day view (chapter 24), there even when the master's row is not currently chosen as a column.
- Only the master makes changes – the echo mirrors automatically.
Briefing & situation display
For projector and situation wall there are two read-only full-screen modes: the briefing mode for attended presenting (follow mode keeps "now" centred, status panel on the right, ESC exits) and the situation display (wall screen) for unattended continuous operation: info header with sync indicator, E2EE state and follow status, status panel as a bottom bar or ticker – "Follow" heals itself.
- Both modes start in the View menu (zone Mode).
- Briefing: Follow on/off, delay chip, show/hide the status panel; the header shows the active section.
- Situation display: switch it on and leave it hanging – outages (sync/keys) are reported honestly by the header.
Print / Export
The matrix can be output as paper or PDF (View menu, zone Output; printing via the browser dialog). The export drawer covers everything from a quick A4 print to the wall strip (mm/h, strips with a glue edge) and a report with a cover sheet and appendices.
- Paper & scope: A4/A3, landscape/portrait; whole operation, visible section or from/to – also as a blank form (IST empty for handwriting).
- Rows & tracks: row selection, distribution mode (no notes/internal hints), SOLL+IST or SOLL only.
- Display: scale Auto/Overview/Standard/Detail/Wall strip; colour or greyscale; header/footer, legend, now line, deviation/delay, milestones.
- Report: cover sheet (occasion, distribution list, marking e.g. "EXERCISE" on every sheet), chronology appendix, delay/deviation appendix; notes as footnotes or in the appendix.
Tablet & phone
Three devices, three jobs: the desktop plans, the tablet leads (selection-first gestures, dockable status panel), the phone tracks – through the day view (chapter 24). Bottom navigation Day · Activity · More, plus the status header with alert bell and sync dot.
- Day – the day view is the phone's view: ONE calendar day on a vertical time axis with an operation row and your personal column (chapter 24).
- Activity – the operation's changes as a sheet, with a jump to the day.
- More – tool deck with a create zone (including "Log IST", the quick capture), reload plus area and account zones (switch operation, language, sign out); installable as a PWA.
- Matrix & agenda list – being reworked for the phone and temporarily hidden there; unchanged on desktop and tablet.
- Tablet – toolbar as an icon deck, status panel docked permanently on the right via the dock button.
Personal, security & operations
Day view & personal entries
The day view puts ONE calendar day on a vertical time axis (time runs downwards): on the left a freely selectable operation row with SOLL/IST half-columns – on the desktop up to three operation rows side by side –, pinned on the right your personal column – single-track, encrypted for you alone, visible in no shared view.
- Desktop: user menu → Day view; phone: the Day tab in the bottom navigation (the phone's start view).
- Page with previous day / next day or swipe left/right; tapping the date opens the calendar to jump straight to a day. The crosshair icon jumps back to today and always keeps its place (dimmed on the current day; keys ← → T). You pick the operation row in the column header. On the desktop, "+ Lane" in the header places up to three operation rows as columns side by side; the × in a column header ("Remove column") takes a column out again. The selection is remembered per device and operation; the phone always shows the first row. The track chips S/I in the column header switch each column between SOLL, IST or both tracks (at least one stays on); a single track uses the full column width. If the SOLL track is hidden while a delay is open there, the header shows a red dot. On the phone the column header opens a selection sheet with row and tracks (SOLL | both | IST); an active single track shows as a small tag next to the row name.
- Create personal entries via + (title, start, end, note) – they never appear in the matrix, activity, print or briefing.
- Participant echoes (chapter 20) also appear hatched in the day view – in every column whose row is a participant, even when the master's row is not currently a column. A tap opens the read-only participant view.
Security view
The Security view shows in plain language whether encryption works, whether your backup is in place and whether recommendations are open – technical details (fingerprints, IDs) sit below. Here you change your password, start the QR device transfer, rotate keys and see the crypto log.
- Status first: "Encryption works" instead of raw numbers.
- Check the key backup, change the password, "Transfer to mobile device" (QR).
- Key rotation: after revoking access/compromise distribute new keys. For rows everyone who keeps read access keeps the existing entries readable – only whoever loses access loses them. For the operation-wide rotation this does not (yet) hold for milestones: they are shown as undecryptable afterwards. KAIROS shows such old events honestly instead of hiding them.
- Forgot the password: a system admin sets a one-time password under Administration › User accounts via "Reset password" (shown only once, all of the person’s sessions are signed out). The E2EE key is not affected – password and key are decoupled, no data is lost. Change the password here afterwards.
Monitoring (administration)
The admin zone Monitoring shows the operational state of the operation: key figures (events, active/archived blocks, open conflicts, undecryptable items), the event trend, open conflicts, quiet rows, keys & coverage (missing key packages with "Distribute"), the team table (last activity, permissions, backup status) and the audit log.
- Visible only to operation admins; system admins additionally see the system monitoring of the whole installation (users, event log, failed sign-in attempts, migration status).
- Same philosophy as everywhere: honest display – whatever is not decryptable or not covered is listed instead of disappearing.
That completes the arc: commissioning (sign-in, keys) → setup (operation, people, rows, permissions) → planning (matrix, blocks, sequences, time tools) → situation tracking (IST, delay, deviation, watchkeeper, conflicts) → collaboration & output (activity, situation wall, print, mobile devices) through to personal, security and operations. All features follow the same principle: calm, dense, honest – and end-to-end encrypted.