Mac editor · iPhone and iPad companion

User Guide

Build the operational record on your Mac, keep it privately synchronized through iCloud, and carry the handoff view with you on iPhone and iPad.

macOS

Start with one environment and one system

  1. Open Operations Binder on the Mac. The Mac app is the authoritative editor for your workspace.
  2. Create an environment. Choose New Environment, then use Environment Details in the toolbar to set its name, type, status, owner, purpose, and boundaries.
  3. Add a system. Select the environment, choose the add button above the system list, and replace the default name with the real system or service name.
  4. Record the operational facts. Fill the Overview sections for identity, host and network, access boundary, health and recovery, and safety.
  5. Choose Save Changes. Then open Handoff to see which important facts are present, missing, or stale.
Want a safe walkthrough first?

Choose Load Demo only in an empty workspace. The documentation-safe demo is repeatable and does not contact or modify external systems.

The operating model

Organize durable context, not active work

1

Workspace

The private boundary for one organization, company, lab, household, or customer context. Use Data → Workspace Settings to edit its name and owner.

2

Environment

A durable operating context such as production, staging, a private LAN, a lab, a hosted-services estate, or a recovery target.

3

System

A host, application, service, appliance, network component, storage target, or operational capability that someone must understand and maintain.

4

System handoff

A read-only assessment of recorded ownership, access, dependencies, warnings, risks, sources, backup guidance, recovery evidence, and review state.

Active incidents belong in an incident-response tool. Release checklists belong in a release workflow. Operations Binder is for the system and environment knowledge that remains after either event ends.

macOS · Overview

Record what an operator can verify

Identity

Name the system, owner, criticality, lifecycle, and purpose. Use concrete language that helps distinguish the record from similarly named hosts or services.

Host and network

Record hostname, primary address, platform, network context, and exposure. Describe the boundary; do not paste firewall secrets or private keys.

Access boundary

Document the approved access method and where the credential is retrieved. Store a Keychain service name or password-manager item label—not the password, token, key, or recovery code.

Health and recovery

Explain where health is observed, how the system is backed up, and what an operator should do to recover it.

Safety

Enable Do not touch without approval when appropriate and state the warning, approval owner, and safe next step.

Choose Save Changes after editing. Operations Binder does not infer missing fields or query the system for you.

macOS · Handoff

Use the handoff view as a review surface

The Handoff tab calculates a deterministic status from the facts currently recorded. It is a completeness signal, not a claim that the system is healthy, safe to power on, or ready for a production change.

  • Handoff Ready means the required operational context is present and current enough for the rules being evaluated.
  • Handoff Review means important context needs review, is stale, or contains open operational concerns.
  • Handoff Blocked means a blocking gap prevents a responsible handoff.

Review the Operator Snapshot, Handoff Gaps, and Open Risk Context. After verifying the record against the real system and trusted sources, choose Mark Reviewed.

Completeness is not runtime status.

A powered-down or intentionally isolated system can have a complete handoff record. Always follow the recorded lifecycle, warnings, and approval path before taking action.

macOS · Context

Connect the facts around the system

Dependencies

Record an external vendor or capability, or link another system already in the workspace. Include direction, failure impact, and operational notes.

Risks

Capture status, severity, impact, treatment, owner, and the next review date. A treated risk may remain open and visible.

Trusted Sources

Record the title, path or URL, owner, canonicality, sensitivity, ingestion boundary, approved summary, and verification date.

Recovery Evidence

Record the exercise, result, evidence location, checksum, summary, and verification date. The record points to proof; it does not embed the backup archive.

Operational Decisions

Preserve a durable choice, rationale, owner, decision date, review date, and current state.

Use the add button in each Context section. Deleting a context record requires confirmation and creates an owner-only logical workspace backup before the change is saved.

A hard boundary

Record retrieval handles, never secrets

Operations Binder is designed to preserve how an approved operator obtains access without becoming a credential store.

  • Safe: a Keychain service name, password-manager item label, vault path, access role, approval owner, or retrieval procedure.
  • Unsafe: passwords, access tokens, API keys, private keys, recovery codes, raw environment files, or copied credential values.
  • Review exported packets and archives before sharing them. They can contain sensitive infrastructure metadata even when they contain no secret values.
Secret-shaped imports are rejected.

Packet import screens common credential-value patterns before preview or apply. That safeguard does not replace your own review.

macOS · Portability

Export and import one system safely

Export a system packet

  1. Select the system and choose Export Operations Packet in the toolbar.
  2. Choose a private destination for the versioned JSON file.
  3. Review the packet before transferring it. It includes the selected system and its owned context records.

Import a system packet

  1. Choose Data → Import System Packet.
  2. Select the JSON packet. Operations Binder validates its schema, relationships, and common secret patterns.
  3. Read the preview describing creates, updates, and child-record replacement.
  4. Choose Apply Import only when the plan matches your intent.

If an existing system is updated, the app writes its previous packet to a private local backup before applying the change.

macOS · Recovery

Protect the complete workspace

Export

Choose Data → Export Workspace Archive to save a complete logical archive containing workspaces, environments, systems, dependencies, risks, sources, recovery evidence, decisions, and provenance.

Verify

Choose Data → Verify Workspace Archive. The app restores the selected archive into a disposable persisted store and reconciles every record count. Verification does not change your live workspace.

Restore

Restore Workspace Archive is available only when the destination workspace is completely empty. The archive is verified before the app offers final confirmation.

Keep archives private and independently backed up.

A logical archive contains the operational record. Store it according to the sensitivity of the environments it describes, and verify important archives on a regular schedule.

iOS and iPadOS

Connect the read-only companion

  1. Use the same Apple Account. The Mac, iPhone, and iPad must be signed into the same iCloud account for private CloudKit continuity.
  2. Enable iCloud Drive. Confirm iCloud Drive is available on each device and that the device has network access.
  3. Open Operations Binder on the Mac. Allow the authoritative Mac workspace to finish saving and exporting its current records.
  4. Open Operations Binder on iPhone or iPad. The companion creates its private local cache and receives the workspace through iCloud.
  5. Compare the record. Confirm environment names, system counts, warnings, risks, trusted sources, and recovery evidence match the Mac.

The mobile app is intentionally read-only. Create, edit, import, restore, and delete operations remain on the Mac.

iPhone and iPad

Carry the handoff view with you

On iPhone

  1. Select an environment from the Environments screen.
  2. Select a system from the system list.
  3. Review the warning banner first when a do-not-touch boundary is present.
  4. Scroll through Handoff, System, Access Boundary, Health and Recovery, Dependencies, Risks, Trusted Sources, Recovery Evidence, and Operational Decisions.

On iPad

Use the split view to keep the environment, system list, and selected system context visible together. Collapse or reveal columns with the standard sidebar controls as space and orientation change.

Previously synchronized records remain available from the device cache when you are offline. Changes made on the Mac while the mobile device is offline arrive after connectivity returns and CloudKit completes synchronization.

Private iCloud continuity

Understand when a change appears

CloudKit synchronization is eventually consistent. A Mac save is durable locally before it necessarily finishes exporting to iCloud.

  1. Keep the Mac and mobile device online.
  2. After saving on the Mac, give the app time to export. Switching to another app or allowing Operations Binder to resign active can prompt a pending export.
  3. Open or foreground Operations Binder on iPhone or iPad and allow time for the private database change to arrive.
  4. Verify the exact field instead of relying only on a list count.
A mobile refresh control cannot force a pending Mac export.

If the change has not left the Mac, reopening the iPhone or iPad app cannot retrieve it yet. Confirm the Mac save completed, then let the Mac app export before troubleshooting the receiving device.

Troubleshooting

Common issues

No data appears on mobile

Confirm every device uses the same Apple Account, iCloud Drive is enabled, the Mac has a populated signed workspace, and both devices are online. Then leave the apps open briefly.

A recent Mac edit is missing

Save on the Mac, switch away from the Mac app or let it resign active, and wait for the export before reopening the mobile app. CloudKit changes are not guaranteed to appear instantly.

Old data remains offline

That is expected. The companion preserves its last synchronized local cache. Reconnect to the network and allow CloudKit to deliver the change.

Restore is unavailable

Workspace restore is enabled only when every local record family is empty. Export the current workspace before removing or replacing data.

An import is rejected

Read the validation message. Unsupported schema versions, invalid relationships, conflicting identities, or secret-shaped values stop the import before it changes the store.

You still need help

Email support@operationsbinder.com with the app version and build, device model, operating-system version, affected screen, expected result, and observed result. Do not send credentials or sensitive infrastructure exports.