Changing focus, stopping work, and cancelling disclosure
Cancellation is meaningful only when attached to an operation and a phase. A keyboard gesture, a rejected promise, a cancelled job row, and a hidden late result can describe very different outcomes.
The shared question is not “Did I press Escape?” It is which component owned that input, what work had already started, and which effect was actually stopped?
Name the thing being stopped
| Control or event | Intended boundary | Do not infer |
|---|---|---|
| Ordinary Escape in focused Tan chat | Clears nonempty draft text; otherwise returns the view to Main. | The tan or its job was cancelled. Higher-priority panels or loop handling may own Escape instead. |
| Automatic return from Tan focus | Changes the recipient surface after parking, abortion, or removal. | A draft still belongs to the tan, or a submitted message needs replaying. |
| Turn interruption | Requests an end to the current attempt. | Queue erasure, durable agent termination, or rollback of tool effects. |
| Cancellation of the initial background job | Marks and signals the identified running job. | The explicit-kill tombstone was written, or every external process stopped. |
| Explicit Hub kill | Requests terminal agent release with a tombstone and retained transcript. | The job must say cancelled, or earlier edits were undone. |
| Main session reset or transition | Changes session state and may clear queues or cancel owned work according to that path. | It is merely a view change, or every failure phase is transactional. |
| Sharing-loader Escape | Restores the editor and suppresses later result display/opening. | A started upload or custom-handler effect was aborted or revoked. |
These distinctions explain why whole-application controls are poor substitutes for leaving a focused tangent. They also explain why a remembered job ID is unsafe for later cancellation: job rows are short-lived handles, whereas the conversation transcript may remain.
Compare two asynchronous cancellations
Review Desk explicitly retires pending authority. Its invalidateAuthority() increments a generation, clears the grant, and aborts the pending presentation. A late positive confirmation is accepted only if it still belongs to the current generation. The recorded RPC scenario demonstrated that the old response could not recreate authority.
The sharing controller has a different contract. Its loader receives cancellation, but the inspected path does not pass that loader signal into default shareSession or the custom callback. The recorded held operation completed after Escape while its late URL was suppressed. That observation supports a warning about possible late completion; it is not evidence of a real upload or a revocation service.
The lesson is not that one cancellation word is reliable and another is not. It is that signal propagation, stale-result rejection, committed effects, and UI restoration must each be designed and checked.
Use a phase-aware recovery record
When an operation is uncertain, record five things before retrying:
- Surface: which chat, overlay, loader, or mode owned the input?
- Identity: which agent, job, session, process, or dialog was targeted?
- Phase: had work only been requested, had it started, or had an effect already committed?
- Observation: what receipt, lifecycle state, journal entry, or file effect is actually available?
- Remainder: what can still be running or retained outside that component?
For a tan, inspect both agent and job state and any relevant external process. For a session switch, distinguish settings preflight, hook veto, guarded target-load failure, and post-switch reconciliation. For a share, treat a cancelled or ambiguous result as possibly completed; do not resend merely to obtain a visible URL.
This is a reading and recovery discipline, not a request to manufacture a destructive or networked test. The original failure cards and intercepted reports provide the comparison safely.
Source trail: Leave and switch safely, Interrupt, cancel, or kill, Decision Desk refusals and failures, and Sharing. Relevant cited symbols include SessionFocusController, AgentLifecycleManager.release, AsyncJobManager.cancel, and CommandController.handleShareCommand; the supplied examples/review-desk/index.ts contains invalidateAuthority().
Related chapters:
- 5. Leave and switch safely
- 7. Continue a finished tan
- 8. Interrupt, cancel, or kill
- 12. State and control reference
- Decision Desk resetting deliberately
- Decision Desk refusals and failures
- Sharing is a separate disclosure decision
- Review Desk: edit and decide locally
- Background work and owner-addressed delivery
Connections and next steps · Unified editorial chapter; connects the recorded source material without rerunning it.