# XWUISuperAutomation

The workflow operations console: `workflow`, `trigger`, `action`, `run` and
`credential` items behind one provider. It is where a workflow is enabled, a failed run is
retried and a credential is rotated, without exposing the engine underneath.

## When to use

- A product with user-defined automations that need enable / disable / retry from the UI.
- Run history, with the failing step mounted into the detail pane.
- Credential management where secrets are never rendered, only referenced by id.

Never put a secret value into an item: items are projected straight into table rows. Reference
credentials by id and let the provider hold the material.

## Configuration surface

The constructor is `new XWUISuperAutomation(container, data, config)`. `data` is the state
you already hold; `config` is how the hub talks to your backend.

`config.provider` is the only integration point that matters:

- `list(query, signal)` -> `{ items, total?, nextCursor? }`. `query` carries
  `text`, `sectionId`, `cursor`, `limit` and `sort`; honour `signal`, because
  every new search, section switch or refresh aborts the in-flight request.
- `execute(request)` -> `{ message?, items?, refresh? }`, required by any entry
  in `config.actions`. An action with no `execute` fails with
  `XWUI_SUPER_ACTION_PROVIDER_REQUIRED` rather than silently doing nothing.
- `subscribe(listener)` is optional; when present the hub reloads on every
  push and unsubscribes on destroy.

The rest of `config`: `title` / `subtitle` / `className` for chrome;
`columns` (each `key` indexes the row built from the item's own fields plus its
`values` bag, so a custom column needs a matching `values` entry); `actions`
scoped `global` | `selection` | `item`, optionally `requiresConfirmation` and
`capability`; `confirmAction(action, items)` to gate confirmations (without it
a confirming action only emits `confirmationRequired`); `mountDetail` to own
the detail pane; `context` for the `XWUISuperContext` that authorizes
capabilities; plus `searchable`, `selectable`, `selectionMode`
(`single` | `multiple`), `autoLoad` (default true, loads on connect when a
provider exists), `refreshAfterAction` (default true), `pageSize` (default 50),
`density` (`compact` | `comfortable` | `spacious`) and a `labels` bag for every
piece of built-in copy.

Authorization is fail-closed: an action carrying a `capability` with no
`config.context` authorizer is **denied**, not allowed. Leave `capability` off
actions that genuinely need no permission.

`data` seeds and mirrors the view: `items`, `sections` (the tab strip),
`metrics` (the tile row), `query`, `activeSectionId`, `activeItemId`,
`selectedIds`, `loading`, `loadingMore`, `actionPendingId`, `error`, `total`,
`nextCursor` and `lastActionMessage`. Omit `columns` and the table falls back to
Title / Status / Updated.

## Automation

Workflow, trigger, action, run, and credential operations backed by host adapters.

```example
file: examples/BasicUsage.ts
html: examples/BasicUsage.html
title: Automation
description: Workflow, trigger, action, run, and credential operations backed by host adapters.
```

```api
```
