Skip to the lesson
CivOps AI Academy · F11Supervisor Review and the Manager View
0%

F11 · Foundation Session 11

Two more surfaces

The operator records. The supervisor decides whether the record stands. The manager acts on what the records add up to. This element builds the second and third surfaces on the record the first one made.

8 min5 chapters≈ 1¾ hours3 hands-on exercises12-question assessment · 80% passes

By the end of this chapter you can

  • Explain how the operator, supervisor and manager surfaces share one record and one set of access rules.
  • Describe how this element is scored.
  • Know what you will build: a review queue and a manager board for first-off checks.

One record, three jobs

In Session 10 you built the operator screen for the first-off check on Line 3 of Acme's press shop (an illustrative plant). Each check is now a row in the database. Two people need it next. The supervisor on the shift must decide, quickly, whether a check with a value outside its limits means stop and adjust the die, or whether it can stand. The manager must see, at a glance and without asking anyone, whether the press shop is starting its batches right, and what changed when it is not.

Three surfaces, one recordOperator, supervisor and manager surfaces each shaped for its job, all reading the same record under the same access rules. Operatorenters one checkphone or tablet, arm's lengthSupervisorreviews the differencephone, tablet or deskManageracts on the measurewall board or deskOne record, one set of access rules from the matrix,three screens shaped for three jobs
Three surfaces, one record. Each screen is shaped for its job; the record and the access rules underneath are the same.

Neither surface needs new data. Both are views on the same records under the same Role and Exposure Matrix from Session 6. The supervisor's role may write a review; the manager's role may read totals; neither may edit what the operator entered. That is what makes the numbers trustworthy.

How it is scored

5chapters, each opened at least once
3exercises on your own platform
12assessment questions
80%to pass (10 of 12)

The element is complete when you have opened every chapter and taken the assessment, and passed at 80% or more. Homework 3 (three surfaces) is due at the end of week 4; this element and Session 10 together cover it.

Knowledge check

Why do the supervisor and manager surfaces not need new data entry?

Chapter 1 · Approve, reject, and the difference shown

The review queue

A review is a decision, and a decision needs three things on the screen: what was entered, what was expected, and the difference between them. Then a reason, a name and a time, kept for good.

30 min4 decisions1 required reason0 self-reviews

By the end of this chapter you can

  • Design a review card that shows the entry, the limits and the difference.
  • Record every decision as a new row with who, when and why, and never overwrite one.
  • Enforce separation of duties in the database.
  • Handle a rejected record so it is corrected, linked and counted correctly.

What review is for

Without a review step, every entry goes straight into the charts, including the mis-tap and the check done on the wrong press. With a review step that only says approve or reject, supervisors approve everything because the screen gives them nothing to judge by. A good review queue makes the decision easy and the record of it permanent.

Review statesA record moves from submitted to in review, then approved, rejected or approved by concession; a rejected record is corrected and resubmitted. A record's review states. Every arrow writes a new review row; nothing is overwritten.Submittedby the operatorIn reviewclaimed by a supervisorApprovedcounts in the chartsConcessionapproved out of limitRejectedreason requiredCorrectednew entry, linkedresubmitted to the queue
Review states. Each arrow is a new review row. A rejected check is never edited; a corrected check is a new entry linked to it.

Show the difference

The card shows each measure, the value entered, the limits from the drawing and the difference, computed by the server. Values inside their limits stay quiet. A value outside is the only thing in colour, with the amount and direction in words: +0.11 above limit. The last result on the same press sits underneath, because a sudden jump means something different from a slow drift.

Anatomy of a review cardA review card for a first-off check shows each measure, the entered value, the limits and the difference; flange height is highlighted 0.11 mm above its limit, with approve, reject and a required reason. First-off check · Line 3 · Press 02 · bracket 7741Entered by operator 1187 · 06:42 · Shift B · 18 minutes waitingMeasureEnteredLimitsDifferenceHole position (mm)12.0411.90 – 12.10insideFlange height (mm)25.3124.80 – 25.20+0.11 above limitBurrnonenone allowedinsideLast check on this press: 25.06 (pass), 2 days agoApproveRejectReason (required)
Anatomy of a review card. The supervisor sees in two seconds which measure is out, by how much, and what the press did last time.
DecisionWhenReasonWho may make it
ApproveEverything inside limits and the entry is plausibleOptionalSupervisor, per the matrix
RejectA value is out, the wrong press or part, or an implausible entryRequired: what is wrong and what to doSupervisor
ConcessionA value is out but the batch may run, under a documented deviationRequired, with the deviation numberQuality engineer only, per the matrix
Correct (by the operator)After a rejection: re-measure and enter a new checkLinked to the rejected oneOperator

Keep every decision

Each decision is a new row in a reviews table: which record, who decided, what, why and when. Nobody can change or delete a review. The current state of a check is simply its latest review. Regulated manufacturers will recognise this: the FDA's rule for electronic records requires secure, computer-generated, time-stamped audit trails that record who did what and when, where a change never hides the earlier entry [1], and its data integrity guidance asks that records be attributable, legible, contemporaneous, original and accurate (ALCOA) [2]. Even outside regulated industries it is the right design: a decision nobody can trace is a decision nobody owns.

SQL: an append-only reviews table with separation of duties
create table first_off_reviews (
  id          uuid primary key default gen_random_uuid(),
  check_id    uuid not null references first_off_checks(id),
  reviewer    uuid not null default auth.uid(),
  decision    text not null check (decision in ('approved', 'rejected', 'concession')),
  reason      text,
  decided_at  timestamptz not null default now(),
  check (decision = 'approved' or length(trim(coalesce(reason, ''))) >= 5)   -- a reject or concession says why
);
alter table first_off_reviews enable row level security;

-- Insert only: a supervisor approves or rejects, a quality engineer grants a concession, never on their own check. No update or delete policy exists.
create policy review_others on first_off_reviews for insert to authenticated with check (
  reviewer = auth.uid()
  and ((decision <> 'concession' and has_role('supervisor'))         -- has_role() is generated from the matrix in Session 7
       or (decision = 'concession' and has_role('quality_engineer')))
  and exists (select 1 from first_off_checks c where c.id = check_id and c.entered_by <> auth.uid())
);

With row-level security on and no policy for update or delete, Postgres refuses both for signed-in users [3]. The check constraint makes a reason compulsory for a rejection or a concession, in the database, where no screen can skip it.

Separation of duties

The person who enters a record must not be the person who approves it. Security frameworks call this separation of duties: dividing a task so no one person can complete it alone [4]. Hiding the Approve button on your own entries is not enough, because anyone can send a request without the button. The rule belongs in the database, as in the policy above, and a test proves it: sign in as the operator, try to review your own check, expect a refusal.

Separation of dutiesThe operator who enters a record cannot review it; the rule is enforced by the database, which refuses a self-review. Operator 1187enters the checkSupervisor 2204reviews itDatabase rulereviewer ≠ author1187 reviews ownrefused by the serverEnforced where it cannotbe skipped: in the database,not only by hiding a button
Separation of duties. The database refuses a self-review, whatever the screen shows.

Routing and waiting time

A queue that grows unseen is worse than no queue. Show each supervisor the checks for their shift and lines first (routing by shift or line is the exemplary level of Homework 3), sort the oldest at the top, and show how long each has waited. Put the age of the oldest waiting check on the manager board too: if checks wait longer than the time it takes to run a batch, the review is happening after the parts are made.

Review waiting timeBars of the oldest waiting record at each hour of a shift; two hours exceed the limit line. Oldest record waiting for review at each hour, minutes (limit 30)4069072208350912106113112813
How long checks wait. The oldest waiting check at each hour of a shift; at 09:00 and 12:00 it passed the 30-minute limit.

Knowledge check

A supervisor rejects a first-off check. What does the operator do next?

Knowledge check

Where must the rule 'you cannot review your own entry' be enforced?

Knowledge check

Why are reviews stored as new rows instead of a status column that is updated?

Exercise · Build and break the review queue30 minutes

You need: Your AI coding agent; your platform with two test users (an operator and a supervisor)

Have your agent build the review queue to the rules in this chapter, then try to break it.

Outcome: A review queue that shows the difference, requires a reason to reject, refuses self-review and keeps every decision.

References

  1. eCFR: 21 CFR Part 11, Electronic records; electronic signatures (§ 11.10(e) audit trails). https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
  2. U.S. FDA: Data Integrity and Compliance With Drug CGMP, Questions and Answers (guidance for industry). https://www.fda.gov/regulatory-information/search-fda-guidance-documents/data-integrity-and-compliance-drug-cgmp-questions-and-answers
  3. PostgreSQL documentation: Row security policies. https://www.postgresql.org/docs/current/ddl-rowsecurity.html
  4. NIST SP 800-53 Rev. 5, Security and Privacy Controls (AC-5 Separation of Duties). https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

Chapter 2 · Readable from across the room

The manager view

A manager view is not a report. It shows the few measures the intent names, readable at a glance from where people stand, and it keeps itself up to date without anyone pressing refresh.

25 min3 to 5 measuresUpdated on its ownFreshness always shown

By the end of this chapter you can

  • Choose the measures for the board from the intent, and leave the rest off.
  • Lay out tiles that show value, target and status in words.
  • Keep the board fresh with polling or pushed changes, and show when it is stale.
  • Give a wall display a read-only role that sees totals only.

Start from the intent

Session 2's intent names the decision and the data it needs. Acme's manager decides each week which press needs die maintenance first, from first-pass yield on first-off checks and rejected checks by press. So the board shows first-pass yield against target, first-off checks done against due, and how long checks are waiting for review. It does not show every field in the table. A dashboard, in the sense the visualisation literature uses, is the most important information needed for one or more objectives, arranged on one screen so it can be monitored at a glance [1]. If a measure does not change a decision, it belongs in a report, not on the board.

The manager viewThree tiles (first-pass yield 96.8% against 98%, 31 of 32 first-off checks, 2 waiting for review) above a trend line that drops after a new steel coil lot. Press shop · today · updated 20 s agoFirst-pass yield96.8%target 98%First-off checks done31 / 321 overdue: Line 4Waiting for review2oldest 18 minFirst-pass yield, last 14 shifts, with what changednew steel coil lot
The manager view. Three tiles with value, target and status in words, and one trend that shows what changed.

Tiles that read at a glance

Part of a tileRuleExample
NamePlain words, the same as the intentFirst-pass yield
ValueThe largest thing on the tile, with its unit96.8%
ComparisonAgainst a target or the last period, alwaystarget 98%
StatusWords and an icon as well as colourBelow target · 1 overdue: Line 4
FreshnessWhen the number was last updatedupdated 20 s ago

Colour follows the same rule as the operator surface: quiet when normal, colour only when something needs attention, and never colour alone, because WCAG requires that colour is not the only way information is conveyed [2]. Lean plants have used the same idea for decades with andon boards: a signal anyone on the floor can read from a distance that says where help is needed [3].

Readable from across the room

The letter-height rule from Session 10 applies with a longer distance. At 22 minutes of arc, a capital letter must be about the viewing distance divided by 156: 19 mm at 3 m, 38 mm at 6 m. On a board read across a control room, that means one number per tile and very few words. Test it the same way: put the board where it will hang, stand where people will stand, and read every tile aloud.

Refresh on its own

A board that needs someone to press refresh shows yesterday. Two ways keep it fresh:

Keeping the board freshLeft: the board asks the server every 30 seconds. Right: the server pushes each change. Both show a freshness stamp. Poll every 30 secondsPushed when data changesBoardServerask 1ask 2ask 3ask 4BoardServerchangechangeSimple and robust; costs a request each timeInstant; needs a live connection and a fallbackEither way, show 'updated 20 s ago', and grey the board out if the stamp gets old.
Polling or pushed changes. Both work. Polling is simpler; pushed changes are instant. Show freshness either way.
WayHowGood forWatch out for
PollingThe board asks the server for the totals every 30 or 60 secondsMost boards; simple; works through any networkPause it when the tab is hidden, using the Page Visibility API, so a forgotten tab does not keep asking [4]
Pushed changesThe server sends each change as it happens, over a live connection such as Supabase Realtime [5]Queues and alarms where seconds matterConnections drop; fall back to polling and re-read the totals on reconnect

Whichever you choose, show updated 20 s ago on the board, and grey the whole board with the words Not updating if the stamp is older than three refresh periods. A frozen board that looks live is worse than a blank one. On a wall display, the Screen Wake Lock API keeps the screen from sleeping while the page is open [6].

Knowledge check

Which measure belongs on Acme's manager board?

Knowledge check

The board's 'updated' stamp is ten minutes old on a 30-second refresh. What should the board do?

Knowledge check

What should the role used by a wall display be allowed to do?

Exercise · The board, from the far wall25 minutes

You need: Your AI coding agent; a screen or TV where the board will hang; a tape measure

Build the manager board from your intent and test it where it will be read.

Outcome: A self-refreshing board, readable from where people stand, with its own read-only role and an honest freshness stamp.

References

  1. Perceptual Edge: articles and resources on dashboard design. https://www.perceptualedge.com/
  2. W3C: Understanding WCAG 2.2 Success Criterion 1.4.1 Use of Color. https://www.w3.org/WAI/WCAG22/Understanding/use-of-color.html
  3. Lean Enterprise Institute: Andon (Lean Lexicon). https://www.lean.org/lexicon-terms/andon/
  4. MDN Web Docs: Page Visibility API. https://developer.mozilla.org/en-US/docs/Web/API/Page_Visibility_API
  5. Supabase Docs: Realtime. https://supabase.com/docs/guides/realtime
  6. MDN Web Docs: Screen Wake Lock API. https://developer.mozilla.org/en-US/docs/Web/API/Screen_Wake_Lock_API

Chapter 3 · Signal, noise and the reason

Trends and what changed

A number on its own invites the wrong question. A trend with control limits shows whether something really changed; a note on the chart says what.

20 minMean ± 3σSpec limits ≠ control limits1 note per change

By the end of this chapter you can

  • Tell a real change (special cause) from ordinary variation (common cause) with control limits.
  • Explain the difference between specification limits and control limits.
  • Put the events that change a process (die changes, material lots, maintenance) on the trend.

Not every dip is news

Every process varies. If the board turns red each time first-pass yield dips half a point, people learn to ignore it, or worse, chase noise. Statistical process control, which Walter Shewhart developed in the 1920s, separates common-cause variation, the ordinary scatter of a stable process, from special-cause variation, a real change with a reason worth finding [1]. The tool is the control chart: the data in time order, with a centre line at the mean and control limits, usually three standard deviations either side [2].

Run chart with control limitsLine chart of flange height over successive checks with mean and three-sigma limits; one point is above the upper limit after the annotated change. Flange height, first-off checks on Press 02 (mm): mean and ±3σ control limitsUCL25.15mean25.00LCL24.85new steel coil lot
A control chart with the change marked. Flange height drifts up after a new steel coil lot, and one check passes the upper control limit.

Control limits are not specification limits

Specification limitsControl limits
Come fromThe drawing or the customerThe process's own data
AnswerIs this part good?Has the process changed?
ExampleFlange height 24.80 to 25.20 mmMean 25.00, ±3σ = 24.85 to 25.15 mm
Where they belongThe operator screen and the review cardThe manager's trend

A point outside the control limits but inside specification is still a signal: the process has moved, and it will make bad parts if nobody looks. A process whose control limits sit outside the specification will make bad parts however carefully it is run, and the answer is to change the process, not to inspect harder. The NIST/SEMATECH handbook gives the rules for reading control charts, starting with the simplest: a single point beyond three standard deviations [2].

Say what changed

The exemplary level of Homework 3 asks the manager view to show the trend and what changed it. Keep a small table of process events (die change, new material lot, maintenance done, new operator on the press), entered where they happen, and draw them on the trend as labelled lines. A manager who sees yield fall right after the new coil lot asks the supplier the right question in one meeting instead of three.

SQL: the events drawn on the trend
create table process_events (
  id          uuid primary key default gen_random_uuid(),
  line        text not null,          -- the ISA-95 names from Session 5
  press       text,
  kind        text not null check (kind in ('die_change', 'material_lot', 'maintenance', 'other')),
  note        text not null,
  happened_at timestamptz not null,
  entered_by  uuid not null default auth.uid()
);
alter table process_events enable row level security;

Knowledge check

A first-off flange height sits above the upper control limit but inside the drawing's limits. What does it mean?

Knowledge check

Where do control limits come from?

Knowledge check

Why record process events such as a new material lot?

Exercise · Draw the change on the trend20 minutes

You need: Your AI coding agent; your platform with at least 20 synthetic first-off checks (Session 4's generator)

Add control limits and process events to the manager's trend.

Outcome: A manager trend with control limits and the events that explain its changes.

References

  1. ASQ: What is a control chart?. https://asq.org/quality-resources/control-chart
  2. NIST/SEMATECH e-Handbook of Statistical Methods: Process or product monitoring and control. https://www.itl.nist.gov/div898/handbook/pmc/pmc.htm

Chapter 4 · 12 questions · 80% passes

Final assessment

Twelve questions across the element. Score 80% (10 of 12) to pass. Your LMS records your score and each answer; you can review the chapters and try again.

15 min12 questions≈ 15 minutesRetake allowed

Choose one answer for each question, then submit. You will see the right answer and why for every question.

1. What three things must a review card show for the supervisor to decide well?
2. Which decision requires a reason in the database?
3. An operator's check is rejected. How is it corrected?
4. How are reviews made impossible to change or delete?
5. Separation of duties in the review queue means:
6. Which US rule requires secure, time-stamped audit trails for electronic records in FDA-regulated work?
7. How do you choose the measures on the manager board?
8. Why must a tile show status in words as well as colour?
9. The board's data stops arriving. What should it show?
10. What should a wall display's role be allowed to do?
11. What is the difference between control limits and specification limits?
12. Why draw process events such as die changes and material lots on the trend?