This guide points to the same I01–I13 fictional packets and F01–F08 findings already used in the report. More visible coverage does not mean additional checks were completed.
What the expanded areas do—and do not—establish
Authentication, accounts and permissions
Can customers regain access safely, and can each account reach only its own information?
The same fictional source, selected sign-in/session records and sampled isolation scenarios support this chapter.
Not verified: A complete account-lifecycle and role matrix is not represented. Applicable OAuth, recovery, account-linking and invitation variants need their own scoped evidence; unsupported features may be marked Not applicable.
Related existing evidence: I01, I03. No new finding or check is asserted.
Authentication, accounts and permissions · page 16
Backend, APIs and background processing
Does the work behind the interface finish correctly after an interruption or retry?
Selected source boundaries and the existing payment, generation and alert sequences are reused. F01 remains the same single payment finding.
Not verified: All API routes, edge functions, background jobs, concurrent operations and provider failure combinations have not been demonstrated.
Related existing evidence: I01, I04, I05, I08. No new finding or check is asserted.
Backend, APIs and background processing · page 33 · Payments & entitlements · page 22
Database design and data integrity
Will information stay correct and useful as records accumulate and requests overlap?
The system/data-boundary snapshot, interrupted entitlement write and recovery documentation provide context. They are not a complete schema or query-plan review.
Not verified: Complete relationship/constraint design, justified duplication, transaction behaviour, representative query plans and successful restore evidence remain unverified.
Related existing evidence: I01, I04, I12. No new finding or check is asserted.
Database design and data integrity · page 36 · Release & recovery · page 61
Critical email and notifications
Can customers actually receive the messages they need to sign in, recover access or confirm an action?
Selected session records and the existing rejected operator-alert example are related context. F07 is an operator-alert failure, not a proven password-reset delivery defect.
Not verified: End-to-end transactional email delivery, domain configuration, bounce handling and mailbox receipt are not evidenced.
Related existing evidence: I03, I08. No new finding or check is asserted.
Authentication, accounts and permissions · page 16 · Observability & support · page 42
Business-rule correctness
Do access, balances and limits remain correct when events arrive twice or out of order?
The existing interrupted paid-access sequence and single aligned cost period show two bounded problems.
Not verified: All entitlement transitions, quota boundaries, rounding/time-zone rules and simultaneous updates are not covered by those records.
Related existing evidence: I04, I09. No new finding or check is asserted.
Payments & entitlements · page 22 · Backend, APIs and background processing · page 33 · Database design and data integrity · page 36 · Testing & change safety · page 46
Capacity and operating limits
What is likely to slow down, fail or become unexpectedly expensive as usage grows?
Source/configuration context, one timeout sequence, lab page speed and one invoice period remain separate kinds of evidence.
Not verified: These records do not establish a concurrency ceiling, sustained load capacity, database connection headroom or production demand forecast.
Related existing evidence: I01, I05, I07, I09. No new finding or check is asserted.
Speed & performance · page 30 · Backend, APIs and background processing · page 33 · Database design and data integrity · page 36 · External services & operating costs · page 50
Safe support and administration
Can an authorised person resolve customer problems without making uncontrolled changes to live information?
Source ownership, sampled identity/isolation and instruction/handbook records identify relevant boundaries.
Not verified: A complete support-role matrix, privileged-action audit trail and end-to-end safe customer-repair exercise are not evidenced.
Related existing evidence: I01, I03, I11. No new finding or check is asserted.
Authentication, accounts and permissions · page 16 · Observability & support · page 42 · Codebase, documentation & ownership · page 11
Business continuity and ownership
Could another competent person operate and recover the service if the original builder were unavailable?
Ownership and instructions, a staging release record and documented rollback are represented in the fiction.
Not verified: Successful full restore, usable business-data export and an independent complete operating handover remain unverified.
Related existing evidence: I01, I11, I12. No new finding or check is asserted.
Codebase, documentation & ownership · page 11 · Database design and data integrity · page 36 · Release & recovery · page 61
AI output quality and control
Are generated plans useful and correctable, and are any AI-triggered actions appropriately limited?
Synthetic generation, timeout recovery and cost reconciliation show selected operational behaviour.
Not verified: Representative output-quality evaluation, adversarial inputs and the safety of any autonomous actions are not established by a successful generation or dry-run.
Related existing evidence: I05, I09, I11. No new finding or check is asserted.
External services & operating costs · page 50 · UX, interface & visual consistency · page 25 · Testing & change safety · page 46