Part of #589.
CONTEXT
With login in place, this issue builds the dashboard itself: server-rendered HTML plus a session-authed JSON overview endpoint. hydraorganization acts as backend-for-frontend: it holds the downstream admin and bearer tokens in its config and does all org filtering server-side. No downstream token ever reaches the browser. No downstream service gains org scoping in v1; that stays a platform follow-up (#545 direction).
SCOPE
ACCEPTANCE CRITERIA
FILES
DEPLOY
Tag, push, CI, host auto-update, hydrarelease verify --project hydraorganization. Then run the end-to-end acceptance against the live dashboard with the real visit-flanders membership and post the result on the master issue.
Visitor ratings added to the dashboard contract and the mock preview (hydraorganization v0.3.1, live). Overview, Venue, and Experience each carry an optional rating {average, responses}; the UI shows a summary tile, a Rating row per venue card, and a Rating column on the experiences table. Real source is hydranps (#565): per-venue and per-experience aggregates over rated sessions only, excluding disconnected sessions per the #565 design. This issue connects it; the panels render only when rating data is present, so shipping without #565 is safe.
LIVE DATA SHIPPED in hydraorganization v0.5.1 (2026-08-31). internal/dashboard.Live replaces Mock as the default provider; ?mock=1 still serves examples.
WIRED: venue roster from hydravenues (?organization=, no token); heads from hydracluster /api/v1/heads and bodies from /api/v1/nodes filtered on the hydrabody role (admin token); experiences from hydraexperiencelibrary /api/v1/experiences joined client side on venue id (admin token); reliability from hydrastreamingmonitor /api/v1/intelligence plus /api/v1/health (no token). Verified live: 4 venues, 1/8 heads and 3/3 bodies online, 4 experiences, 9/11 services healthy, all four sources ok.
DELIBERATELY ABSENT, not faked: session counts, streamed time, visitor ratings and the date-range selector. Probing found streaming sessions carry no venue and survive only in an in-memory ring (#595), and hydranps holds 208 records of which exactly ONE has a score and none has a venue, with no writes since 2026-03-23 (#565). health extra.rating_count is a session count, not a rating count. Unknown values are pointers plus Known flags so an absent number is never serialised as a confident zero, and a venue whose fleet could not be read reports unknown rather than offline.
TWO BUGS THE LIVE DATA EXPOSED, both fixed: hydrastreamingmonitor /api/v1/intelligence reports full uptime for a service that is down right now, because an outage is only counted once it closes, so /api/v1/health is now required alongside it and the percentages are dropped for any currently-down service; and the experience venue join needed dedup, since a venue repeats across district entries and listed cloud-seven four times for one experience.
KNOWN WEAKNESS: the fleet join is a bare string match on hydracluster node.venue, which nothing enforces against hydravenues ids. Unmatched cluster venue values are logged (#594). Experiences answer "deployed at your venues", not "owned by you", because the library has no organization link (#593).
FIELDS RESTORED as hyphens in v0.6.1, per the owner. Sessions, streamed time and visitor ratings are back on the page and in the contract as pointers: the UI renders a hyphen when there is no source, and the JSON OMITS the keys rather than sending 0, so unknown stays distinguishable from none. The date-range selector was NOT restored: it would be a control that changes nothing until session history exists (#595). Live now shows real fleet numbers next to hyphens for the unrecorded fields, which makes the gap visible on the page rather than hidden.
CLOSING as done at hydraorganization v0.7.0. Live at https://hydraorganization.experiencenet.com/dashboard behind iamnim sign-in.
Delivered: venue roster, per-venue head and body counts, deployed experiences and platform reliability, all from the live services; mobile-first UI with a card deck for venues and experiences; org dropdown for people with more than one membership; sessions, streamed time and ratings present as fields showing a hyphen until their sources exist.
Still blocking real numbers in this page: #595 (session persistence plus venue stamp) for sessions and streamed time, #565 for visitor ratings, #593 for a real org link on experiences, #594 for trustworthy node.venue. The page is honest about all four today rather than guessing.
UI shipped ahead of the data work as a MOCK DATA preview: https://hydraorganization.experiencenet.com/dashboard (hydraorganization v0.3.0, deployed 2026-08-28). internal/dashboard.Overview is the contract; internal/dashboard.Mock fills it today and this issue replaces Mock with real aggregation over hydravenues, hydraexperiencelibrary, hydracluster, and hydrastreamingmonitor. The JSON shape is live at GET /api/v1/organizations/visit-flanders/overview with mock:true. Templates stay as they are; only the provider changes. The page is public while it shows mock data only; it must go behind the iamnim middleware from #596 before real data connects.