/* NOTE: the approver buttons are .who-pick, NOT .who. The identity block above already uses .who
   for the agent name, and a shared class meant the first .who on the page was the wrong element.

   Additions to the operations palette for the console home: the question each scenario answers,
   and the approver picker. Everything else is inherited from operate.css so the two pages cannot
   drift into looking like different products. */
.job .jq { font-size: 13.5px; color: var(--ink-dim); margin-top: 5px; font-style: italic; }
.job .jd { margin-top: 6px; }

.approver { border: 1px solid var(--line); border-radius: var(--radius); background: var(--panel); padding: 16px 18px; margin-bottom: 26px; }
.who-list { display: grid; gap: 10px; grid-template-columns: repeat(auto-fit, minmax(240px, 1fr)); margin-top: 12px; }
.who-pick { display: block; text-align: left; background: var(--panel-2); border: 1px solid var(--line); border-radius: 10px; padding: 12px 14px; color: inherit; font: inherit; cursor: pointer; }
.who-pick:hover { border-color: var(--line-strong); }
.who-name { display: block; font-weight: 620; }
.who-role { display: block; font-size: 12.5px; color: var(--ink-quiet); margin-top: 2px; }
.who-id { display: block; font-family: var(--mono); font-size: 11.5px; color: var(--ink-quiet); margin-top: 4px; }

/* The approval, on the orchestrator. Deliberately the loudest thing in a run, because a run that is
   waiting on a person and does not say so is a run that ends in a timeout nobody understands. */
.approve-box { margin-top: 12px; border: 1px solid rgba(232,196,106,.45); background: rgba(232,196,106,.06); border-radius: 10px; padding: 12px 14px; }
.approve-q { font-size: 13px; color: var(--wait); font-weight: 600; margin-bottom: 10px; }
.approve-row { display: flex; gap: 10px; flex-wrap: wrap; }
.approve-yes, .approve-no { font: inherit; font-size: 13.5px; font-weight: 600; border-radius: 8px; padding: 8px 18px; cursor: pointer; border: 1px solid transparent; }
.approve-yes { background: var(--ok); color: #04120f; }
.approve-no { background: transparent; color: var(--no); border-color: rgba(239,122,114,.5); }
.approve-yes:disabled, .approve-no:disabled { opacity: .45; cursor: not-allowed; }
.approve-link { display: inline-block; margin-top: 10px; font-size: 12px; color: var(--ink-quiet); }
.approve-out { margin-top: 10px; font-size: 11.5px; color: var(--ink-dim); white-space: pre-wrap; }
.approve-out.mono { font-family: var(--mono); background: #030d0b; border: 1px solid var(--line); border-radius: 8px; padding: 10px; max-height: 220px; overflow: auto; }
.approve-note { font-size: 12px; color: var(--ink-quiet); line-height: 1.5; margin: -4px 0 10px; max-width: 74ch; }

/*
 * A POLICY REFUSAL IS NOT A FAILURE, SO IT DOES NOT GET THE FAILURE COLOUR.
 *
 * The run ends without the agent doing the work, but what it showed is a resource server making its
 * own decision against its own published policy, separately from the authorisation server that
 * issued the token. Red says the demonstration broke. This reads as deliberate, because it is.
 */
.verdict.policy { color: var(--wait); }

.result.policy {
  border-left: 3px solid var(--wait);
  padding-left: 14px;
}
.result.policy p { margin: 6px 0 0; }
.result.policy .mono.tiny { opacity: 0.72; }
