# Final operational UAT — Phase 6F

Baseline: `master`, `49eb2e2`, initially clean. Phase 6F verification is complete
on 2026-10-04. Ready for Phase 6F review, with one documented LOW cosmetic item.
This is not certification of the subsequent full release-audit/deployment gate.

## Gap register

| ID | Persona / scenario | Expected | Observed before correction | Severity / category | Resolution / verification |
| --- | --- | --- | --- | --- | --- |
| 6F-02 | Front Desk: cancel customer-owned device registration, including invalid submission | An explicit route back to the authorized customer context | Registration form has only its submit button; abandoning registration requires browser history or unrelated navigation | MEDIUM / UX | RESOLVED: customer-context cancel link. Regression reproduced the missing link on GET and invalid POST before the fix. Final regression verifies the link, authorized destination and no registry writes; rendered checks pass at all three widths |
| 6F-01 | Engineer: open a job created from a walk-in's reported reason | Read the persisted intake remarks alongside complaint context | Front Desk correctly persists the reason as `ServiceCase.intake_note`, but none of the operational job screens displays it; a narrative-only intake loses its operational handoff context | HIGH / WORKFLOW | RESOLVED: existing intake remarks in Complaint & diagnosis and History, under the case-read boundary, labeled as intake evidence. No new query, diagnosis or structured complaint. Escaping/scope regression, unchanged query budgets and long-text browser checks pass |
| 6F-03 | All case-reading personas: service-center subtitle | Neutral separator between center code and name | The existing shared organization `__str__` uses a literal `?`, producing e.g. `CENTER ? Center` | LOW / UX (cosmetic) | Deferred: both identifiers remain fully readable and scope/state are unaffected. Confirmed in the fresh closed-job screenshot and `apps/organization/models.py:72`. No change to the shared frozen formatter |

## Personas and security matrix

The nine synthetic personas use the existing organization assignments and
permission-bearing business roles. Front Desk and Supervisor have company
scope; Engineer, Second Engineer, QC, Warehouse, Cashier and Financial Manager
have center scope. Only the global Administrator is a superuser. Additional
frozen regressions exercise sibling centers, foreign companies, departments,
inventory locations, revoked grants, staff-only users and split permission paths.

| Persona | Permitted interface / representative action | Inappropriate persona / enforcement exercised |
| --- | --- | --- |
| Front Desk | Customer/device lookup, registration, walk-in, intake, assignment, ready, handover and closure | Engineer denied intake; Cashier denied technical/delivery forms; foreign customer/device and replay checks |
| Engineer | Assigned queue, diagnosis, repair, parts request and consumption | Cashier denied GET and POST; engineer denied stock receipt, payment and QC authority |
| Second Engineer | Assignment/reassignment through the existing assignment workflow | Former engineer's stale actions fail after reassignment; unassignment removes active work access |
| Independent QC | Eligible queue, checks, complaint verification, pass/fail | Own-repair independence enforced; unauthorized engineer/cashier denied |
| Warehouse | Receive, approve, reserve, issue, return; transfer/count/recovery interfaces with explicit grants | Read-only user and unrelated center/location denied; signed commands cannot be borrowed |
| Cashier | Quotation, decisions, invoice reconciliation/finalization and receipt of payment | Engineer denied commercial forms; Cashier denied reversal and due-release authority |
| Financial Manager | Reversal and due release, with outstanding debt still visible | Cashier denied direct reversal/release requests; stale or duplicate financial evidence rejected |
| Supervisor | Scoped reporting, SLA and notification evidence | Staff/native permission and cross-company paths do not bypass business scope |
| Administrator | Administration discovery, registered master-data destinations, readiness | Ordinary operational users denied configuration POSTs and global Admin discovery |

The new primary journey checks inappropriate-persona GET and POST denial at
each technical, inventory, commercial and delivery form before the permitted
persona submits it. Existing tests separately cover CSRF, same-path permission
coupling and object scope. A hidden link alone is never treated as authorization.

## Journey and functional coverage

`apps.operations.uat.test_final` adds an operational-form journey starting with
customer search, following the customer-to-device-registration link, registering
explicit ownership, then a walk-in and intake. It proceeds through assignment,
NULL-root-cause diagnosis, repair planning, customer quotation/approval, receipt,
request/reservation/issue, one consumed and one returned part, completed repair,
independent QC, ready, invoice, full payment, handover and closure. Each action
is discovered on its owning workspace and its redirect is followed successfully.
The final invoice is 100 BDT, outstanding balance zero, stock one and job CLOSED.
These are synthetic scenario values, not production metrics.

The separate frozen `test_journeys` suite retains its structured-complaint,
appointment, SLA and communication fixtures and verifies full cross-domain
reconciliation. Fixture preparation is not represented as a UI action.

| Area | Targeted evidence |
| --- | --- |
| Front Desk | Appointment/check-in, walk-in, local dates, queue transitions, lookup, registration validation, intake replay, recent jobs, invalid appointment states and scope (`frontdesk.tests`, operations workspaces and UAT) |
| Engineer | Assigned queue, unknown cause, technical evidence, repair planning/performance, reassignment and stale actor denial (operations workspaces and UAT) |
| Warehouse | Receiving/serialization, compatible parts, reservation vs custody vs consumption vs unused return, defective recovery, transfer dispatch/receive, count/reconciliation, adjustment, immutable history, scope and signed replay (`test_inventory_workspace`, UAT, selected usage concurrency tests) |
| QC | Independent eligibility, checks and structured complaint verification, failed history, rework and resubmission (`service.test_quality_control`, operations workspaces and UAT) |
| Commercial | Approved/rejected/revised quotations, original decision history, invoice preparation/reconciliation/finalization, partial/full payment and original receipt preservation after reversal (`test_commercial_workspace`, `commercial.test_payment`, UAT) |
| Financial Manager / delivery | Unpaid and partially paid blocked; settled and sufficiently due-released permitted; reversal restores debt and can block handover. Release creates no payment and does not reduce debt (`commercial.test_payment`, UAT and selected payment/handover races) |
| SLA | Received-at start; warning/due/overdue; exact-due on-time and late completion; authoritative readied-at stop; cancellation; immutable policy snapshot (`SlaTests`, `CompletionTests`, UAT) |
| Communications | Appointment/intake/quotation/ready/payment hooks; fake acceptance, definite rejection, unknown outcome; snapshots, attempts, masking and failure isolation (`CommunicationTests`, `CommercialHookTests`, UAT) |
| Administration | People/access, organization, service masters, appointment configuration, SLA, templates and readiness; direct boundary checks (`configuration.test_workspace`, configuration/readiness tests) |
| Search | Job, customer/contact, exact device identity, appointment UUID, quotation, invoice, payment/receipt, parts; inaccessible records remain absent (`operations.tests`, new appointment search test, inventory/commercial workspaces) |
| Consistency | Original status, history, posted ledger and settlement evidence reused across workspaces; no inferred stock state, synthetic timeline, financial coverage or delivery claim |
| Empty/error states | Per-persona empty dashboards, empty inventory/commercial/configuration lists, no search results, required fields, overpayment, mismatched variant/part, stale revisions, duplicate commands, scope denial and long escaped intake remarks |

## Disclosure and immutable evidence

The targeted suites cover company/center/department isolation; warehouse location
and transfer endpoint scope; identifiers requiring device visibility on overview
and search; independent QC history; separate quotation, invoice and payment
permissions; receipt snapshots; notification masking; and restricted configuration
discovery. Technical workflow forms retain their existing case-context contract.
This phase does not redefine it or grant broader identifier-search rights.

Intake remarks use the same authorized case-read boundary as reported complaints.
They appear only in Complaint & diagnosis and History, remain autoescaped, and
do not fabricate structured complaints or diagnostic findings. Existing guidance
against recording credentials in intake text still applies.

Inventory is reconciled from its existing ledger. Invoice value is not revenue;
reversal is not deletion; due release is neither payment nor settlement. Customer
ownership, original decisions, receipts, failed QC and prior assignments remain
authoritative history. Frozen reporting checks reconcile those distinctions.

## Query and performance gate

No SQL construction changed. Intake remarks read an already-loaded scalar field;
the cancel link reverses an existing route. All frozen Phase 3D and 6A–6E budget
and growth tests passed unchanged in the targeted run:

| Surface | Fresh query count |
| --- | --- |
| Dashboard scoped / all capabilities | 9 / 22 |
| Navigation / search / job overview | 4 / 8 / 31 |
| Front Desk / engineer queue / QC queue | 24 / 8 / 8 |
| Diagnosis / repair / QC / parts / commercial | 12 / 11 / 12 / 15 / 13 |
| Scoped history / populated history | 16 / 31 |
| Inventory positions / history / receipts / transfers | 15 / 10 / 11 / 11 |
| Commercial quotations / other populated queues | 8 / 9 (empty release collection 7) |
| Administration global / company / center / slots | 13 / 8 / 7 / 9 |
| Reporting cases / engineer | 20 / 20, each within budget 24 |
| Reporting complaint / diagnosis / invoice / outstanding | 9 each, within budget 10 |
| Reporting stock positions | 8, budget 8 |

Existing growth checks remained constant at their frozen comparison sizes and
preview caps. In particular, the changed diagnosis/history presentation retained
its prior query counts. No budget was loosened.

## Browser and accessibility method

Fresh synthetic HTML captures are generated by the actual Django views during
tests, with the repository CSS and JavaScript inlined for local rendering.
Headless Microsoft Edge renders them at 390, 768 and 1366 pixels. The browser
checks page-level overflow, action bounds/touch size, expanded filters, keyboard
focus, drawer open/Escape/focus restoration, labels, error associations and
receipt print output. Screenshots and PDF stay outside the repository under the
temporary `ccare-phase6f-ui` directory.

These are rendered-browser layout checks paired with authenticated Django-client
GET/POST workflow tests, not a claim of live-browser network form submissions or
human screen-reader certification.

Final result: **197 screens x three widths = 591 rendered-browser checks, zero
layout/focus/drawer failures**. The separate accessibility result scan reports
zero missing main H1s, unlabelled form controls, broken invalid-field error
associations, missing skip links or missing visible focus outlines. Representative
headings, text status labels and link/button semantics were also reviewed.
No custom modal workflow was introduced or needed.

Coverage includes login, dashboard, search, Front Desk, Service Job, engineer and
QC queues/sections, inventory, commercial/receipt, SLA, communications and
Administration, including empty states, validation errors and long text. The
receipt's print view hides navigation/actions and produces a one-page PDF.
Visual inspection included registration errors, closed job, SLA, Administration,
receipt and the long escaped intake remarks. The cosmetic center separator is
recorded separately as 6F-03; automated layout success does not hide that finding.

An earlier six-screen/three-width preflight passed 18 checks. Three supplemental
intake-remarks renders supplied full-height screenshots. These are not added to
the final 591 count.

## Known limits and out-of-scope items

- The new narrative-only walk-in uses the supported intake remarks. It does not
  manufacture a ComplaintSymptom; existing structured complaint verification is
  exercised in the frozen QC/UAT fixtures. Adding a new structured-intake editor
  would be feature work outside this correction.
- No real SMS/email delivery, provider deployment, load test, production data
  migration or full release audit is performed. Fake ACCEPTED is not delivered,
  and UNKNOWN is not retried as though rejection were certain.
- Automated keyboard/layout checks and screenshot review are not a comprehensive
  assistive-technology audit across all browsers or devices.
- The pre-existing `?` separator in organization labels remains a LOW cosmetic
  issue (6F-03); it does not alter identity, permissions, state or amounts.
- The full audit belongs to the subsequent release-candidate gate after review
  and commit. This phase cannot certify that later gate.

## Verification boundaries

Synthetic test data only, in a uniquely named PostgreSQL test database. No
production business data changes or real notification sends. Existing frozen
tests and query budgets remain unchanged. No full audit, migration creation,
staging, commit, push or tag is authorized for this phase.

## Final verification and recommendation

- **563 tests passed, zero failures/errors, in 1384.332 seconds**, in one complete
  targeted run after both production corrections. Exit status 0. The manifest
  below covers operations, Front Desk, service, inventory, commercial, SLA,
  communications, configuration, authorization, reporting and UAT.
- Five tests added: customer-context cancel without writes; scoped appointment
  UUID search; full operational-form journey with cross-role denials; escaped and
  scoped intake remarks without fabricated evidence; nine-persona setup and
  representative empty-workspace/login rendering.
- All 22 frozen UAT journeys passed. Twelve explicitly selected PostgreSQL races
  passed, plus the two existing concurrent communication creation/send tests.
  They cover check-in/intake, competing issue/consumption/return/recovery,
  payment/reversal/release versus delivery, and competing handovers.
- The initial one-test red run reproduced 6F-02 with two failing subtests. An
  intervening focused run was interrupted and has no final summary; it is not
  counted as a completed suite. Its uniquely named, inactive test database was
  removed after checking ownership and zero connections. The final runner
  destroyed its own separate test database normally.
- `python manage.py check`: passed, zero issues.
- `python manage.py makemigrations --check`: passed, no changes detected.
- `git diff --check`: passed. Untracked additions were separately checked for
  trailing whitespace and normal EOF termination.
- JavaScript was not changed; a separate syntax rerun was not required. Existing
  JavaScript executed in the fresh browser checks.
- No migrations, frozen-test edits, domain-service edits, secrets, debug code,
  screenshots, PDFs or synthetic business data were added to the repository.
  HTML/screenshots/PDF and execution logs remain temporary external evidence.
- No full audit, staging, commit, push or tag was performed. HEAD remains
  `49eb2e2` on `master`.

Gap totals: zero BLOCKER; one HIGH/WORKFLOW resolved; one MEDIUM/UX resolved;
one LOW/UX cosmetic deferred. No unresolved HIGH or data-integrity/security
finding. Scope exclusions are listed above, not silently implemented.

Files for review: `apps/operations/job_workspace.py`,
`apps/operations/templates/operations/device_registration.html`,
`apps/operations/uat/test_final.py`, `docs/OPERATIONAL_UI.md`, and this document.

Recommendation: **READY FOR PHASE 6F REVIEW**. Normal journeys and required
security/data-integrity checks pass; frozen budgets remain intact. Review and
commit precede the separate full release-candidate audit.

## Targeted regression manifest

The following labels are loaded in one Django test run using
`apps.reporting.management.commands.audit_project.isolated_test_database`.
The outer settings override disables configured communication providers and uses
the in-memory email backend; provider-specific tests use their own fake/mocked
adapters. No full-audit command is invoked.

```text
apps.operations.tests
apps.operations.test_ui
apps.operations.test_workspaces
apps.operations.test_inventory_workspace
apps.operations.test_commercial_workspace
apps.operations.uat.test_journeys
apps.operations.uat.test_final
apps.frontdesk.tests.FrontdeskTests
apps.service.test_quality_control
apps.service.test_handover
apps.commercial.test_payment
apps.sla.tests.SlaTests
apps.sla.tests.CompletionTests
apps.communications.tests.CommunicationTests
apps.communications.tests.CommercialHookTests
apps.configuration.test_workspace
apps.configuration.tests.ConfigurationTests
apps.configuration.tests.ReadinessAndSeedTests
apps.access.test_authorization
apps.access.test_authorization_audit
apps.reporting.tests.test_reports
apps.frontdesk.tests.FrontdeskConcurrencyTests.test_simultaneous_checkin_is_single_entry
apps.frontdesk.tests.FrontdeskConcurrencyTests.test_simultaneous_intake_creation_is_single_case
apps.inventory.test_usage_concurrency.UsageConcurrencyTests.test_double_issue
apps.inventory.test_usage_concurrency.UsageConcurrencyTests.test_consumption_wins_over_unused_return
apps.inventory.test_usage_concurrency.UsageConcurrencyTests.test_return_wins_over_consumption
apps.inventory.test_usage_concurrency.UsageConcurrencyTests.test_recovery_duplicate_command_race
apps.commercial.test_payment_concurrency.PaymentConcurrencyTests.test_final_payment_before_delivery
apps.commercial.test_payment_concurrency.PaymentConcurrencyTests.test_unpaid_delivery_attempt_before_final_payment
apps.commercial.test_payment_concurrency.PaymentConcurrencyTests.test_final_payment_reversal_before_delivery
apps.commercial.test_payment_concurrency.PaymentConcurrencyTests.test_delivery_before_unsecured_reversal
apps.commercial.test_payment_concurrency.PaymentConcurrencyTests.test_due_release_before_delivery
apps.service.test_handover_concurrency.HandoverConcurrencyTests.test_two_users_handover_same_case
```

## Phase 6F.1 freeze review

The review retained both production corrections unchanged. Finding identifiers
are aligned with the freeze request: 6F-01 is HIGH/WORKFLOW intake remarks;
6F-02 is MEDIUM/UX customer-context cancellation. Both are resolved. The existing
LOW cosmetic organization formatter issue remains deferred.

The five new tests remain five tests. Review extended their coverage for malformed
model input, invalid model/variant combinations, retained form values and cancel
context, foreign customers, sibling-center and foreign-company case denial,
unauthorized actors, escaped remarks, unrelated-page/navigation disclosure,
unchanged persisted case data, and empty/populated remarks query equality.
No existing frozen test or production behavior was changed during review.

Fresh focused verification: 25 tests passed in one run (220.491 seconds), using
an isolated PostgreSQL test database, disabled configured communication providers
and an in-memory email backend. The selection included all five Phase 6F tests,
two existing device registration tests, JobWorkspaceTests, the technical queue
and section budget test, assignment presentation and AuthorizationAuditTests.
Diagnosis used 11 queries with either empty or populated remarks; technical-only
history used 16 with either. Existing ceilings were not raised.

The recorded Phase 6F run of 563 tests (1,384.332 seconds) and browser artifacts
were reviewed, not rerun or represented as fresh Phase 6F.1 execution. The browser
results contain 591 successful width/state checks across 197 states at 390, 768
and 1366 pixels. Representative screenshots and receipt print evidence were
reviewed; the receipt PDF has one page. This remains rendered-page interaction
and accessibility smoke verification, not screen-reader certification or a full
release-candidate audit. Existing scoped journeys and evidence preserve financial
clearance, inventory operations, independent QC, SLA and communication semantics.

Final Django system check, migration-drift check and whitespace checks passed.
No BLOCKER, HIGH, material unresolved MEDIUM, security/disclosure failure,
data-integrity failure, authorization bypass, financial-clearance bypass,
inventory regression, migration drift or frozen query-budget regression was
identified. Only the same five Phase 6F files remain changed and unstaged;
review additions are regression coverage and this documentation. No migrations,
browser artifacts or domain-service edits were introduced. No full audit,
staging, commit, push or tag was performed.

Proposed commit: `test: complete final operational UAT hardening`.
Freeze recommendation: **READY TO COMMIT PHASE 6F**.
