# Product ## Platform web ## Users Control-plane operators use the browser workspace to inspect connected desktop Clients, verified WeChat accounts, conversations, contacts, and task outcomes. Administrators manage persistent workspace users and assign Desktop Agent/Node access; members can access only their assigned Nodes. ## Product Purpose WxAgent coordinates desktop Agents and exposes their authorized, normalized read-only data through a control plane. The workspace helps operators select a Client context and review its messages and operational state. The workspace supports persistent multi-user administration and assigns remote Desktop Agent/Node access to users. ## Positioning The existing system connects a remote control plane to desktop Agents and verified accounts; user-facing data is read through authorized account-scoped APIs. In this project, “Agent” assignment means access to remote Desktop Agent/Node records and their verified WeChat accounts; it does not mean AI Flow assignment. ## Operating Context The browser application is React/Vite, served as static assets embedded by the Go control plane. Operators authenticate through the existing `/v1/auth/login` endpoint. Existing Client, task, event, audit, contact, conversation, and message reads use current control-plane APIs. ## Capabilities and Constraints - Preserve the existing real login and Client/message/contact/task/diagnostic API workflows. - Add a persistent user directory, role-aware authentication, user-management APIs, and user-to-Node assignments. - Existing environment-configured Web accounts are bootstrapped as administrators when the identity database is first initialized; later account management is database-backed. - Administrators can manage users and access all Nodes; ordinary members can access only explicitly assigned Nodes and their authorized account data. - Keep Client/account data isolated; show only normalized authorized data. Do not expose raw WeChat databases, keys, or unredacted UI snapshots. - Keep Node assignment distinct from unsupported AI Flow assignment; do not expose other users' Nodes or account data through any API. - The current message send control remains unavailable until its separate real-device acceptance is complete. ## Brand Commitments The product name is WxAgent. For this requested WebUI replacement, use the Ant Design Pro official design conventions and Ant Design X conversation components as the binding interface system. ## Evidence on Hand Existing API handlers and current WebUI implement login, Client selection, message/conversation and contact reads, task/event/audit views, and read-coverage-aware state merging. Before this change, login credentials came from environment configuration and all authenticated users shared global access; there was no persistent user-management table or per-user Node authorization. Existing environment-configured Web accounts will bootstrap as administrators. User records and Node assignments will be persisted and managed through real APIs. ## Product Principles - Preserve real Client/account isolation and the existing read-only trust boundary. - Clearly distinguish backend-backed information from synthetic demo controls and data. - Prefer explicit states and recoverable read errors over silently hiding stale or partial data. - Treat desktop Agent availability and business-Agent assignment as distinct concepts.