I reframed an early in-car UI exercise into an L3–L4 journey-interaction system and working prototype, with explicit ODD and validation boundaries.
Five connected tasks and four exception branches keep planning, autonomy, ODD exit, takeover, recovery, and arrival inside one trust model.
NAV keeps route intent, next maneuver, arrival, system state, and evidence provenance glanceable.
DRIVE opens the forward field, grounds the ego vehicle, and preserves the same route and geographic world beneath the camera change.
ODD EXIT, TAKEOVER, LIMITED, MINIMAL_RISK, RECOVERY, and UNAVAILABLE explain why capability changes, what the vehicle will do, and what the driver must do next.
HUD owns immediate action, the cluster owns continuous driving state, and the center display owns journey explanation and cabin context.
Music, podcasts, calls, climate, energy, assistant, and temporary profiles remain connected to the journey while safety states retain priority.
The browser prototype proves interaction and state logic. AAOS, QNX or Automotive Linux migration—and perception, localization, planning and control—remain explicit external production programs.