Skip to content

Review Orbit

Review Orbit turns the dashboard into a repeatable review workflow. Choose Review in the top bar to open one keyboard-accessible workspace; on a narrow screen it becomes a full-height sheet. Tab stays inside while it is open, and closing returns focus to the control that opened it. Escape closes the current layer first: an exact restore confirmation is cancelled before another Escape closes Review Orbit. At phone widths all seven destination tabs wrap into view; Left and Right Arrow still move between them. Plan, Records, and Backups form the Plan & Protect part of the same workspace rather than a second dashboard. The last tab, Inbox filter, and Month/Quarter Review Pack choice are remembered in local browser/app storage. If a stored value is missing or invalid, Review Orbit safely starts at Inbox, All, and Month.

The Inbox combines attention that was previously scattered across the dashboard:

  • Price gaps that make current Portfolio totals partial or unavailable
  • Pending DCA contributions still waiting in the simulated ledger
  • Missing, due-soon, or overdue theses
  • Upcoming earnings within 30 days
  • Verdict snapshots still collecting calibration history

Urgent data gaps come first, then items needing a decision, then quiet calendar/calibration context. Use All, Data gaps, Needs review, or On the radar to narrow the visible list. The Review badge and header keep the full count; filtering never dismisses, snoozes, or changes an item. Choose an item to open the relevant Review tab, holding, thesis editor, or DCA ledger. The Inbox itself makes no mutations.

The Trust tab answers the question to ask before reading a confident number: how much of this view is actually covered?

Area What complete means Source or boundary
Position prices Every invested position has a positive usable quote Yahoo Finance through the local market-data cache
Quote metadata The active rows returned provider metadata Yahoo Finance through yfinance
Fund fees Every held ETF/fund has a plausible expense ratio Provider expense-ratio fields; unknown never means free
Dividend classification The active rows returned a usable full quote Provider forward-dividend fields; non-payers stay explicit
ETF overlap Published top holdings were available for each held ETF Top holdings only; reported as a floor on real overlap
Theses Every active holding has local thesis text Local SQLite only
Stored history At least one daily Portfolio snapshot exists Local SQLite only

Complete, partial, unavailable, and not applicable are data states—not grades. The most limited relevant area sets the orbit’s overall status.

Choose Save data health CSV to keep a local coverage receipt with the generation time, overall quality, snapshot freshness, area counts, missing tickers, sources, and caveats. Saving runs a fresh read-only coverage check, so the receipt can differ from a Trust view that has been left open while provider data changes. Foreign-priced positions are named separately and remain excluded from USD totals; unavailable values are never filled.

Choose Month or Quarter to assemble:

  • Current value, cost basis, realized and unrealized P&L
  • The stored opening snapshot and snapshot coverage
  • Realized trades during the selected period
  • The largest current P&L contributors
  • Theses that need attention

Save print-ready HTML to open or print to PDF, or CSV for a spreadsheet. The report calls raw start-to-end movement value change because deposits and withdrawals can move that number; it is not mislabeled as a time-weighted investment return. The exact stored opening-snapshot date appears beside the comparison, and history is marked partial when that snapshot is more than three days from the requested month or quarter boundary.

Choose Save review bundle to carry the active Month/Quarter review as one local ZIP instead of four loose files. It contains:

  • review-pack.html and review-pack.csv
  • data-health.csv
  • target-plan.csv
  • manifest.json with app/format versions, UTC generation time, data-quality context, per-area trust gaps, missing and foreign-priced tickers, byte lengths, and SHA-256 hashes for the four non-manifest review artifacts

The hashes help detect member corruption. They do not authenticate the ZIP or prove who created it.

The rolling latest-main build also includes Verify saved bundle. Choose a Review Bundle ZIP and FolioOrb checks the fixed five-member layout, bounded ZIP size, v1 manifest shape, recorded byte lengths, and all four SHA-256 hashes. The selected archive is read by the local FolioOrb process; it is not imported into the portfolio and no database or setting is changed. A passing result still means integrity against the included manifest, not proof of who created it.

The four review artifacts reuse one in-memory quote response set. Assembly is read-only: it does not record a daily snapshot or change holdings, trades, targets, DCA rows, settings, or backups. If target inputs differ from the saved course, the bundle stays blocked until you save or restore the draft.

Foreign-priced positions remain named and excluded from USD totals; there is no FX conversion. The 8 MiB cap bounds both the uncompressed member set and final ZIP. Treat the archive as sensitive review material. It is not a FolioOrb restore file, tax form, recommendation, or trade instruction.

From a thesis item in the Inbox:

  1. Write or update the reason to own or watch the holding.
  2. Choose no cadence, 30, 60, 90, 180, or 365 days.
  3. Select Save & mark reviewed.

The review timestamp and interval stay in local SQLite. They control only when the thesis returns to the Inbox; they do not change P&L, allocation, a verdict, or an action plan. Claude never reads or writes thesis text.

Plan starts with one row per Portfolio: its known USD value, quote coverage, and the tickers that keep it incomplete. The aggregate is deliberately known value, not account-level performance. One provider failure stays attached to its Portfolio and does not blank the other books.

Targets use integer basis points: 10,000 bps = 100%. An eligible target row is active, owned (positive shares), and not watchlisted. A complete target course must include every eligible row and total exactly 10,000 bps; duplicate, stale, foreign, or ineligible IDs are rejected. A Portfolio with no eligible holdings is incomplete.

Changing shares or prices recomputes actual allocation and drift without erasing the target. Adding or removing an eligible holding makes the course incomplete until you save a new full set. If any required quote is missing, non-positive, non-finite, or not USD, FolioOrb names the gap and withholds all drift values instead of mixing known and unknown positions.

Choose Save plan CSV to snapshot the saved target basis points, current weights, descriptive drift, known USD value, valuation quality, and missing or foreign-priced tickers. Saving runs a fresh read-only valuation. If a target input has an unsaved change, export stays disabled until you save the target course or restore the saved value. The snapshot does not convert currencies or place a trade.

At 320–575 px the two Plan cards stack and stay inside the sheet. The wide all-Portfolios and target tables scroll within their own labelled region; they do not widen the Review workspace or the page.

A rehearsal accepts a positive USD cash amount with at most two decimal places and one eligible ticker already held in the active Portfolio. It uses the ticker’s current available positive USD quote and the same average-cost math as a real recorded buy. Projected allocation uses pre-buy known Portfolio value + external cash as its denominator.

The rehearsal writes no holding, trade, snapshot, DCA, target, or settings row. It cannot model a sale or trim, forecast a price, include taxes or fees, or recommend a trade. When the Portfolio valuation is incomplete, share and average-cost math can still be shown for a usable ticker quote, but projected allocation stays unavailable.

The displayed projection remains valid only for the exact holding and cash text that produced it. Editing either field immediately replaces the numbers with Preview outdated. FolioOrb also invalidates the pending request, so an older or out-of-order response cannot repaint a projection for inputs that are no longer on screen.

Choose a calendar year to export one row per stored sale. Each row uses its stored sale date, ticker, shares, proceeds, and average-cost basis—not the holding’s current state. Displayed gain/loss is displayed proceeds minus displayed basis, and the total sums those rounded row values. Formula-like ticker text is neutralized for spreadsheet safety.

This is a calendar-year bookkeeping recap, not a tax filing. It does not model tax lots, fees, holding periods, wash sales, or tax classification.

The archive is built from one consistent read transaction and contains deterministic CSVs for:

  • Portfolios
  • Holdings, including inactive/watchlist rows, notes, theses, and targets
  • Realized trades and Portfolio snapshots
  • DCA plans and DCA contributions
  • A manifest with format, schema and app versions, UTC generation time, row counts, checksums, exclusions, and warnings

Settings, secrets, AI caches, backups, and the SQLite database are excluded. The archive is human-readable and sensitive; it is not a Backup Vault snapshot and cannot be restored. FolioOrb emits no partial download if cumulative uncompressed data or the final compressed ZIP would exceed 64 MiB.

The 64 MiB rule bounds the emitted archive, not peak process memory: the local export currently materializes each ordered dataset before serialization. Very large books should be split or archived outside FolioOrb rather than relying on this inspection-oriented export.

Compare is deliberately limited to active Research mode rows:

  • Choose two or three stocks to compare stock fundamentals such as valuation, revenue growth, margins, free-cash-flow yield, and dividend yield.
  • Choose two or three ETFs to compare fund assets, expense ratio, holdings count, concentration, and top holdings.
  • A two-ETF comparison also shows overlap across the published top holdings, with the limitation stated beside it.

Mixed stock/ETF selections and owned-position tickers are rejected instead of being forced into one misleading table. Missing provider fields render as unavailable.

The Backups tab creates transactionally consistent SQLite snapshots with SQLite’s online backup API, then runs an integrity check and records the holding-row count.

Browsing the vault is a read-only operation: listing, verification, holding counts, export selection, and restore selection do not create or modify database sidecars. If a snapshot has a non-empty sibling -wal, FolioOrb treats it as incomplete and refuses it instead of ignoring committed pages. An absent vault directory is not created until a snapshot is actually written.

Manual vault snapshots contain the portfolio database only. They exclude .env, Claude API keys, update settings, and other config. Export uses a native Save dialog in the desktop app and a normal download in a browser.

The Backups tab reads the newest verified manual snapshot and labels it current (up to 7 days old), due (8–30 days), stale (more than 30 days), or missing. A corrupt newer file is skipped rather than making the status look healthy. Every vault file is still same-device protection unless you export or copy it elsewhere.

Automatic backup is off by default. If you opt in, launch schedules a best-effort attempt at most once per local calendar day. Creation, verification, publication, and pattern-scoped pruning are serialized across FolioOrb processes; a new file never replaces an existing destination. Automatic retention keeps seven verified auto-* snapshots and never prunes manual, update-safety, restore-safety, or exported copies. A claimed failed day is not retried silently; Create verified backup remains the explicit retry.

  1. Choose Restore… beside a verified snapshot and confirm the exact filename.
  2. Before choosing Queue restore, press Escape or choose Cancel to back out. Only the confirmation closes, and keyboard focus returns to the Restore control; Review Orbit stays open.
  3. After Queue restore is submitted, the confirmation becomes busy and cannot imply that the in-flight request was cancelled. Escape, Cancel, closing Review Orbit, and changing Review tabs wait for the response.
  4. FolioOrb queues the request instead of replacing an open database. An explicit server rejection re-enables retry and Cancel without changing the database. If the response is interrupted, FolioOrb reads Backup Vault status before making a claim: a confirmed queue stays visible, a confirmed absence becomes retryable, and an unreachable status remains locked as Status unknown until you reload and inspect Backup Vault.
  5. Quit/restart (the packaged app quits after queuing; reopen it).
  6. Before restore, FolioOrb creates and verifies a fresh safety copy of the current database.
  7. The requested snapshot is staged and verified again, then swapped into place.

If staging or verification fails, the live database is left untouched. The next launch reports whether the restore succeeded and names the retained safety backup. A queued restore remains visible in Backup Vault and disables another Restore action until the clean restart consumes it.