:root{
  /* --- color: a ledger, not a dashboard --- */
  --ink:        #0B0C10;   /* page background */
  --ledger:     #14171F;   /* panel background */
  --ledger-2:   #191D27;   /* raised panel background */
  --rule:       #262B36;   /* hairline rules */
  --rule-soft:  #1D212B;

  --owe:        #3D8B7A;   /* Debit — muted teal, what the business now owes */
  --owe-dim:    #23433B;
  --entrust:    #D9A441;   /* Credit — aged gold, what has been entrusted */
  --entrust-dim:#4A3A1C;

  --parchment:  #EDE7D8;   /* primary text — warm, not stark white */
  --parchment-dim: #9B9789;
  --danger:     #C1594B;

  /* --- type --- */
  --font-display: 'Fraunces', Georgia, serif;
  --font-body:    'Inter', -apple-system, sans-serif;
  --font-mono:    'IBM Plex Mono', 'SF Mono', monospace;

  /* --- scale --- */
  --sp-1: 4px;  --sp-2: 8px;  --sp-3: 12px; --sp-4: 16px;
  --sp-5: 24px; --sp-6: 32px; --sp-7: 48px; --sp-8: 64px; --sp-9: 96px;

  --radius: 14px;
  --radius-sm: 8px;

  --ease: cubic-bezier(.22,.9,.32,1);

  /* --- forensic-audit fix -----------------------------------------
     These five tokens are referenced by the Scenario Universe and
     Learner Testing screens (screens.css) but were never defined
     anywhere in the codebase. An undefined var() falls back to the
     property's initial value, not to anything visible — so those
     cards were silently rendering with no background, no border
     color, no shadow, and undimmed secondary text. Aliasing them to
     the existing ledger palette restores the intended look without
     inventing a second color system. --------------------------- */
  --line:      var(--rule);
  --surface:   var(--ledger);
  --surface-2: var(--ledger-2);
  --muted:     var(--parchment-dim);
  --shadow-sm: 0 8px 20px rgba(0,0,0,.16);

  /* --- second pass: two more undefined tokens ------------------------
     Found by tools/qa-ui-dom.js, which resolves every var() in every
     stylesheet against every token declaration. Both of these were used
     with a literal fallback, so unlike the five above they did render —
     which is why they survived the first sweep. They were wrong rather
     than invisible.

     --accent had the fallback #4aa3ff: a saturated blue, and the only
     blue anywhere in the product. It coloured the "Forgot password?"
     link, so the one off-palette element sat on the password-recovery
     modal — a high-trust surface where looking like a default template
     costs the most. Every other interactive accent in the app is gold.

     --gold had the fallback #D9A441, which is correct, but hardcodes
     --entrust's hex instead of referencing it. That is how palettes
     drift: change --entrust and this one silently stays behind.

     Aliased rather than given new values, so there remains exactly one
     source of truth for the palette. -------------------------------- */
  --accent:    var(--entrust);
  --gold:      var(--entrust);
}
