# Unified experience and domain entry

Many domains are brand assets, a few official entries carry the applications, and ordinary features use in-app paths — never one website per feature.

> Document ID: MYRILUM-DOC-ARCH-002
> Document type: concept
> Product: NOT_APPLICABLE
> Version: 0.1.0
> Region: GLOBAL
> Visibility: PUBLIC
> Publication: PUBLISHED_GLOBAL
> Content maturity: VALIDATED
> Governance: APPROVED
> Capability state: IN_DEVELOPMENT
> Availability: NOT_AVAILABLE
> Authorization: PUBLIC_INFORMATION
> Freshness: CURRENT
> Safety class: INFORMATIONAL
> Owner: Web3Capital Documentation Steward
> Approvers (assignment only; not approval evidence): Stephen
> Canonical authority: SRC-ARCHITECTURE-ATLAS-V2-2
> Source commit: 882487dec08bc4ca204510e166217478fa8f68ec
> Content digest: f2de183f0be5bf2092f0117560918c62a0fb8039fcf77974ef130934803ea596
> Effective: NOT_SET
> Expires: NOT_SET
> Last verified: 2026-09-23
> Review due: 2026-10-23
> Command authority: NONE
> Canonical URL: /en/architecture/experience-and-entry

<a id="overview"></a>

## What this map shows

![Unified experience and domain entry diagram (A02)](/figures/atlas-v2-2/A02.png)

*MYRILUM architecture map v2.2 · A02 (public edition). Labels are in Chinese; every element is listed in English below. Select the diagram to open it at full size.*

This is MYRILUM's target architecture. It does not mean everything on the map is live; whether a capability can be used today is stated in “Current availability”.

Many domains are brand assets; a few official entries carry the applications, and ordinary features prefer in-app paths.

Reserve many domains, keep a few official entries and one primary customer workspace; never one website per feature.

<a id="part-1"></a>

## Domain asset management

| Field | Value |
|---|---|
| Asset register | Full domain, holder, renewal and owner |
| Official main entry | Each application or content version has exactly one canonical main address |
| Brand aliases and redirects | Used as needed once holding is confirmed; accounts and databases are never copied |
| Reserve and protection | Holding a domain without using it is fine; no product is built just to use a domain |

<a id="part-2"></a>

## Customer experience: one workspace

| Field | Value |
|---|---|
| Main customer workspace | One official entry per region |
| Home / Agents | Goals, continuing work, choosing capabilities and shaping requests |
| Workspace | Progress, materials, evidence, results, revisions and acceptance |
| Discover / Me | Product content; identity, entitlements, usage and settings |

> **Do not conflate** — A domain ≠ a product; a path ≠ a security boundary; a subdomain ≠ a separate deployment; signing in ≠ permission to a resource.

<a id="part-3"></a>

## Ordinary features use in-app paths, not separate websites

| Field | Value |
|---|---|
| /research · /work | Research and project delivery; shared task and result records |
| /store | Product selection and licensing |
| /team · /integrations | Organization workspace and connector authorization |
| /account · /billing | Account, service credits, entitlements, billing and contributions |

> **Security lifecycle** — A new entry checks certificates, callbacks, sessions and rollback; removing an application also removes its dangling DNS records.

<a id="part-4"></a>

## Isolated entries where risk requires them

| Field | Value |
|---|---|
| Identity service | Central authentication with a separate session per application; callbacks registered exactly |
| Staff workspace | Customer and staff sessions are separate; least privilege |
| Public API / status | The API is enabled only once it opens; the status page gets its own failure boundary |
| Untrusted content preview | Isolated execution and storage; private files are still authorized on every access |

<a id="source"></a>

## Source

This page follows A02 of the MYRILUM architecture map v2.2 (public edition: restricted products and internal open items are left out).

---

This document is read-only, grants no command authority, and does not authorize deployment, payment, provider modification, or any other real-world action.
