Screens over your APIs, for the people who only use them.
An app is an item in a project that turns its requests into screens: fields, tables, cards, charts, buttons. The operations desk, the support team, the person at the plant who needs one number and one button — they open the app full screen and never see a request. A runner seat sends exactly what the app sends and nothing else, and the backend makes sure of it.
At a glance
Start from the request, or from the whole project.
A new screen asks "what does it call?" and builds a field for every unfilled variable and a table or a card from the answer's shape.
A whole app in one step
A container per folder, a screen per request — up to 80 — and a Home dashboard. With an OpenAPI document attached: enums become choices, ids become dropdowns of the related list, passwords and secrets become hidden fields.
Functions
JavaScript, Go or Python kept with the app. app.call runs a request of the project; app.publish sends to a broker or writes a device tag; app.read reads tags now. Say, notify, go to a screen, open a popup, keep a value. A write happens only from a button a person pressed, or from a watcher allowed to send changes.
Watchers
Every few seconds, or at set times on chosen days, or listening on a broker topic or a device tag. When it fails, when a value holds, changes, when something new arrives, or when a function says so. Then a desktop notification, a popup, a screen, a badge, a request, a function, a message published. One clock for every open app; backs off while the API fails.
Settings
A pinned environment, a start screen, inputs logged or not, a brand colour and a logo. Screens refresh every 5 seconds or more. Hidden screens open only from other screens.
Themis builds apps
Ask, and Themis creates the app, its containers and screens, a dashboard, a watcher, a function — and tries them before handing them over.
Themis AIDashboards
Number cards and charts, grouped by a field that repeats in the answer. Auto-refresh. Export the table under a chart.
A seat that runs apps and nothing else.
An app runner is a user whose only permission is "Run apps", with the apps ticked. The boundary is in Go, and a test fails the build if a new window binding is neither guarded nor on the allow list.
What a runner sees
The app, full screen. An Applications dropdown. A toolbar with the licensed-to line, change password and log out. No projects, no collaboration, no Discover, no cookies, no network page, no terminal, no Themis.
What a runner can send
Only the requests its apps use, exactly as stored — method, host, path, parameters, headers, body fields, auth. Values change only where the app's own run fills them. A function calling a request by a computed name is refused. Brokers, devices and tunnels only by the exact reference the app holds.
What a runner cannot do
Save anything but its own tunnel login. Export anything but the app's Excel and CSV. Reach any other backend operation — every one is refused and kept refused by a test. Every app run goes to the activity log with its screen and how it went.