## Why The existing six-page dashboard mixes PostgreSQL authority with retired compatibility files, producing contradictory queue counts and incomplete time-window statistics. Operators need one fast, obvious view that answers the same questions as the current manual status checks and can locate a finding without exposing raw credentials. ## What Changes - Replace the visible multi-page dashboard with one PostgreSQL-authoritative observability page. - Add accurate preset and custom time windows applied in SQL before aggregation or row limits. - Show scanner activity, findings, errors, new and current alive credentials, queue state, and compact runtime health in one view. - Add unified lookup by pasted credential, SHA-256 identity, finding ID/UID, target, path, commit, or other redacted metadata. - Hash credential-like lookup input immediately and never query or render raw secret columns. - Remove legacy queue-file, global runner-state, TSV-gated, log-browsing, and advanced/debug panels from the visible interface. - Keep the dashboard read-only, loopback-only, and supervisor-managed. ## Capabilities ### New Capabilities - `single-page-observability`: Accurate time-window scanner statistics, current runtime state, alive credential summaries, and safe finding lookup on one page. ### Modified Capabilities None. ## Impact - Primary implementation: `app/dashboard.py`. - Focused behavior and security coverage: `tests/test_dashboard_behavior.py` and `tests/test_dashboard_secret_guard.py`. - PostgreSQL remains authoritative; no database migration, mutation endpoint, new service, or external API is introduced. - Existing supervisor lifecycle and disabled-by-default startup policy remain unchanged.