<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Ryan's Tech Lab]]></title><description><![CDATA[Software QA Explorer is your weekly source of cutting-edge AI, technology, programming, and software testing insights. Subscribe for practical tips, real-world examples, and stories from my journey as a Senior/Lead Quality Engineer.]]></description><link>https://ryancraventech.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!Xicz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F750fca69-f83e-4f77-a908-20fc8e282a0e_1024x1024.png</url><title>Ryan&apos;s Tech Lab</title><link>https://ryancraventech.substack.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 23 Aug 2026 08:44:36 GMT</lastBuildDate><atom:link href="https://ryancraventech.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Ryan Craven]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[ryancraventech@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[ryancraventech@substack.com]]></itunes:email><itunes:name><![CDATA[Ryan Craven]]></itunes:name></itunes:owner><itunes:author><![CDATA[Ryan Craven]]></itunes:author><googleplay:owner><![CDATA[ryancraventech@substack.com]]></googleplay:owner><googleplay:email><![CDATA[ryancraventech@substack.com]]></googleplay:email><googleplay:author><![CDATA[Ryan Craven]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[I Gave an AI Agent $100 and Told It to Make Money. The API Costs Killed It Before It Could.]]></title><description><![CDATA[A post-mortem from someone who actually ran the experiment &#8212; and what it taught me about the unit economics nobody&#8217;s talking about.]]></description><link>https://ryancraventech.substack.com/p/i-gave-an-ai-agent-100-and-told-it</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/i-gave-an-ai-agent-100-and-told-it</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Thu, 16 Apr 2026 23:49:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!EYl-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3>A post-mortem from someone who actually ran the experiment&#8202;&#8212;&#8202;and what it taught me about the unit economics nobody&#8217;s talking about.</h3><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EYl-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EYl-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EYl-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EYl-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EYl-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EYl-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg" width="2752" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:1536,&quot;width&quot;:2752,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:0,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EYl-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EYl-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EYl-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EYl-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b8604-ddc8-4a3c-b669-a42ef2ce94e0_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You&#8217;ve seen the demos. An autonomous agent spins up, gets a goal, and &#8212; cut to a Twitter thread two weeks later &#8212; it&#8217;s somehow running a Shopify store, writing a newsletter, and flipping crypto. The future is here. AGI is nigh. Buy the course.</p><p>I wanted to find out what actually happens.</p><p>So I gave an agent $100 and a simple mandate: make money online. No predefined task, no human in the loop making decisions for it, no safety net. Sonnet and Opus under the hood, orchestrated through OpenClaw. Real API keys. Real money. Real-world accounts it could actually spend on.</p><p>It did not make money. It did the opposite of making money. And the reason why is more interesting than the failure itself.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?utm_source=email&r=&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?utm_source=email&r="><span>Subscribe</span></a></p><p></p><h3><strong>The mandate</strong></h3><p>The setup was straightforward. The agent had:</p><p>&#9;&#8226;&#9;A $100 budget, split between API credits and a small real-world spend account</p><p>&#9;&#8226;&#9;Access to tools for browsing, writing, publishing, and basic purchasing</p><p>&#9;&#8226;&#9;One instruction: grow the $100 by producing and selling something valuable online</p><p>&#9;&#8226;&#9;No preexisting audience, brand, mailing list, or platform to leverage</p><p>That last point matters, and I&#8217;ll come back to it. I wanted to see what the agent could do from zero &#8212; the condition most people running these experiments are quietly not starting from.</p><h3><strong>What actually happened</strong></h3><p>The agent was competent at the surface layer. It could plan. It could break the goal into sub-goals. It could write content. It could identify platforms to publish on. It could critique its own output and revise.</p><p>What it could not do was get traction.</p><p>It produced articles and posts that were fine &#8212; coherent, grammatically clean, topically reasonable. But &#8220;fine content published to an account with zero followers&#8221; is indistinguishable from screaming into a void. There was no distribution mechanism, no existing audience to seed it, and no organic discovery in a timeframe that mattered. The agent would write a post, publish it, check back for engagement, find none, and pivot to a new angle. Then do it again. Then again.</p><p>Each of those loops cost money. Not in platform fees. In tokens.</p><h3><strong>Where the $100 actually went</strong></h3><h3>Here&#8217;s the part the demo videos don&#8217;t show you.</h3><p>An autonomous agent doesn&#8217;t just &#8220;do the task.&#8221; It thinks about doing the task. Then it reflects on its thinking. Then it critiques the reflection. Then it plans the next step based on the critique. Then it executes. Then it observes the result. Then it updates its plan. Every one of those steps is a round-trip through the API, and with Opus in the loop for the heavier reasoning, the per-step cost adds up faster than you&#8217;d expect.</p><p>Rough breakdown of where the money went:</p><p>&#9;&#8226;&#9;Planning and replanning loops &#8212; the largest chunk. The agent spent significant tokens deciding what to do, then re-deciding when the previous plan didn&#8217;t pan out.</p><p>&#9;&#8226;&#9;Self-reflection and critique passes &#8212; useful in principle, expensive in practice. Every &#8220;let me evaluate my last output&#8221; cycle is another billable round-trip.</p><p>&#9;&#8226;&#9;Context accumulation &#8212; as the run progressed, the agent&#8217;s context window filled with its own history. Each subsequent call was more expensive than the last because it was reasoning over a growing transcript.</p><p>&#9;&#8226;&#9;Tool-call overhead &#8212; browsing and reading pages pulled in a lot of content, most of which ended up in context whether it mattered or not.</p><p>&#9;&#8226;&#9;Real-world spend that flopped &#8212; a small ad test, a domain, a subscription or two. None of it recouped because, again, no audience.</p><p>The agent wasn&#8217;t wasteful in a stupid way. It was wasteful in a structural way. The architecture itself &#8212; plan, act, reflect, replan &#8212; is expensive, and that expense compounds when the agent is operating in an environment where traction is slow and feedback is sparse.</p><p>Long before the agent had a chance to actually build and sell anything meaningful, the runway was gone.</p><h3><strong>The part nobody mentions: you need an audience before the agent starts</strong></h3><p>This is the finding I want to flag hardest, because I didn&#8217;t expect it going in.</p><p>Every viral &#8220;autonomous agent makes money&#8221; story I&#8217;ve seen, when you look closely, has a hidden input: an existing distribution channel. A personal brand. A newsletter. A following. A YouTube channel. Something that converts &#8220;agent-produced content&#8221; into &#8220;actual reach.&#8221;</p><p>Strip that away and the agent is a very expensive writer publishing into silence.</p><p>If I ran this experiment again with the same $100 but also with, say, a 10,000-person newsletter to publish into, the outcome would almost certainly be different &#8212; not because the agent got smarter, but because the distribution existed. The bottleneck in &#8220;autonomous money-making&#8221; right now isn&#8217;t the agent&#8217;s intelligence. It&#8217;s the cold-start problem the demos gloss over.</p><h3><strong>What a QA engineer sees in all this</strong></h3><p>I&#8217;ve spent the last decade testing software, and watching this run felt uncomfortably familiar. The agent exhibited a set of failure modes that are well-known in other testing contexts but that almost nobody is writing formal test cases for in agent systems:</p><p>&#9;&#8226;&#9;Unbounded cost under load. There was no budget ceiling enforced at the agent level. In any other system, &#8220;operation can consume unlimited resources&#8221; would be flagged as a severity-one defect. In agent demos, it&#8217;s just the default.</p><p>&#9;&#8226;&#9;Planning-phase livelock. The agent could get stuck in productive-looking loops &#8212; generating plans, critiquing them, generating new ones &#8212; without ever committing to action. No state machine, no timeout, no forced-commit mechanism.</p><p>&#9;&#8226;&#9;Context bloat as a silent performance regression. Each step was measurably more expensive than the last, and nothing in the system noticed or cared.</p><p>&#9;&#8226;&#9;No definition of done. &#8220;Make money&#8221; has no acceptance criteria. The agent had no way to know it was failing versus just being early.</p><p>&#9;&#8226;&#9;Unobservable decision quality. I could see what the agent did, but evaluating whether each decision was good required me to read every step manually. There&#8217;s no equivalent of a unit test for &#8220;was this plan reasonable.&#8221;</p><p>If you&#8217;re building with agents &#8212; or testing systems that include them &#8212; these are the things that actually matter. Not &#8220;does it hallucinate.&#8221; Does it die of context bloat. Does it burn your budget in planning. Does it know when to stop.</p><h3><strong>What I&#8217;d do differently</strong></h3><p>If I were to rerun this &#8212; and I might &#8212; the changes wouldn&#8217;t be about making the agent smarter. They&#8217;d be about making the harness around it disciplined:</p><p>&#9;&#8226;&#9;Hard cost ceilings per task and per loop. A failed attempt should cost pennies, not dollars.</p><p>&#9;&#8226;&#9;Model routing by step type. Opus for genuinely hard reasoning. Sonnet &#8212; or smaller &#8212; for everything else. Most planning steps don&#8217;t need the premium model.</p><p>&#9;&#8226;&#9;Context hygiene. Aggressive summarization of prior steps. Drop what the agent doesn&#8217;t need. Most of what&#8217;s in an agent&#8217;s context window on step 40 is dead weight.</p><p>&#9;&#8226;&#9;Forced action commits. After N planning cycles without an action, the agent is required to act on its best current plan or escalate. No more infinite deliberation.</p><p>&#9;&#8226;&#9;Seed the distribution problem separately. Don&#8217;t ask an agent to both produce and distribute from zero. Give it a channel, or accept that you&#8217;re testing content generation, not money-making.</p><h3><strong>The honest verdict</strong></h3><p>Autonomous agents, today, are real but narrow. They can execute well-defined tasks within a bounded environment if you&#8217;ve thought carefully about cost, context, and stopping conditions. They cannot, in April 2026, be handed a vague mandate and a modest budget and be expected to produce economic value from nothing. The demos that suggest otherwise are either operating on top of an existing distribution engine or not showing you the token bill.</p><p>I burned $100 finding that out. If it saves you from burning yours on the same assumption, the experiment wasn&#8217;t a failure &#8212; it was just an expensive unit test.</p>]]></content:encoded></item><item><title><![CDATA[Boundary Value Analysis: Finding Bugs at the Edges]]></title><description><![CDATA[The $0.01 That Cost a Company $1.2 Million]]></description><link>https://ryancraventech.substack.com/p/boundary-value-analysis-finding-bugs</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/boundary-value-analysis-finding-bugs</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Fri, 06 Mar 2026 18:17:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SWvi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The e-commerce platform had a simple free shipping rule: orders of $100 or more ship free. The development team implemented it, the QA team tested it, and everyone was satisfied. They&#8217;d verified that a $50 order charged shipping and a $150 order didn&#8217;t. The feature shipped to production on a Thursday.</p><p>By Monday morning, the finance team was in a panic. Over the weekend, 14,000 orders totaling $100.00 exactly had been charged $5.99 shipping. Customers were furious. Social media was on fire. The company had to issue refunds, offer appeasement credits, and deal with a customer service backlog that took two weeks to clear. Total cost: roughly $1.2 million in refunds, credits, lost goodwill, and overtime.</p><p>The bug? The developer had written <code>if (orderTotal &gt; 100)</code> instead of <code>if (orderTotal &gt;= 100)</code>. Greater than, not greater than or equal to. An order of $100.01 got free shipping. An order of exactly $100.00 did not. The difference between <code>&gt;</code> and <code>&gt;=</code> &#8212; a single character in a single line of code.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><p>The QA team had tested the right partitions. They&#8217;d checked a value clearly below the threshold and a value clearly above it. Equivalence partitioning would call that correct &#8212; $50 and $150 are valid representatives of their respective partitions. But they&#8217;d never tested the boundary itself. They never tried $100.00 exactly. Or $99.99. Or $100.01. The three values that would have instantly revealed the defect.</p><p>This is why boundary value analysis exists. Bugs don&#8217;t distribute evenly across the input space. They cluster at the edges &#8212; at the exact points where system behavior changes from one partition to another. The boundaries between &#8220;charge shipping&#8221; and &#8220;free shipping,&#8221; between &#8220;valid&#8221; and &#8220;invalid,&#8221; between &#8220;accepted&#8221; and &#8220;rejected.&#8221; These transition points are where developers write the conditional logic that determines which path the code takes, and conditional logic is where off-by-one errors, incorrect operators, and misunderstood requirements live.</p><p>In our previous article, equivalence partitioning taught us to divide inputs into groups that behave the same and test one value from each group&#8217;s interior. Boundary value analysis completes the picture by telling us exactly <em>where</em> the most dangerous values are: right at the edges of those partitions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SWvi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SWvi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SWvi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SWvi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SWvi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SWvi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!SWvi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SWvi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SWvi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SWvi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a1c8f27-061b-4461-ab14-8e7aafea88fd_875x488.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Boundary Value Analysis Is</strong></h2><p>Boundary value analysis (BVA) is a test design technique that focuses testing on the values at and around the edges of equivalence partitions. Instead of testing a value from the comfortable middle of a partition, BVA tests the minimum, maximum, and the values immediately adjacent to partition boundaries.</p><p>The reasoning is statistical and practical. Studies of software defects consistently show that errors are far more likely at boundary conditions than at interior values. This makes intuitive sense when you think about how code is written. A developer implementing the age validation 18&#8211;120 writes something like:</p><pre><code>if (age &gt;= 18 &amp;&amp; age &lt;= 120) {
    accept();
} else {
    reject();
}</code></pre><p>The logic that determines behavior lives in those comparison operators: <code>&gt;=</code> and <code>&lt;=</code>. If the developer writes <code>&gt;</code> instead of <code>&gt;=</code>, every value in the interior of the valid partition (19, 20, 50, 100) still works correctly. The bug <em>only</em> manifests at the boundary &#8212; age 18 specifically. Testing age 65 would never find this defect. Testing age 18 finds it instantly.</p><p>This is the core principle: <strong>boundary values have disproportionate defect-detection power compared to interior values.</strong> A single test at a boundary is worth more than dozens of tests in the partition&#8217;s interior.</p><h2><strong>The Boundary Values: Which Ones to Test</strong></h2><p>For any boundary between two partitions, BVA identifies specific values that must be tested. The exact set depends on which variation of BVA you&#8217;re using.</p><h2><strong>Two-Value BVA (Standard)</strong></h2><p>The most common approach tests two values at each boundary: the value on the boundary itself and the value immediately adjacent on the other side.</p><p>For the age field (valid range 18&#8211;120), the boundaries are at 18 (lower) and 120 (upper):</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rPY0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rPY0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png 424w, https://substackcdn.com/image/fetch/$s_!rPY0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png 848w, https://substackcdn.com/image/fetch/$s_!rPY0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png 1272w, https://substackcdn.com/image/fetch/$s_!rPY0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rPY0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png" width="875" height="222" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2eb7778-0059-49d7-9938-b92f227127f3_875x222.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:222,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!rPY0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png 424w, https://substackcdn.com/image/fetch/$s_!rPY0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png 848w, https://substackcdn.com/image/fetch/$s_!rPY0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png 1272w, https://substackcdn.com/image/fetch/$s_!rPY0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2eb7778-0059-49d7-9938-b92f227127f3_875x222.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Four test values total. These four values detect the most common boundary defects: using <code>&gt;</code> instead of <code>&gt;=</code>, using <code>&lt;</code> instead of <code>&lt;=</code>, being off by one in either direction.</p><h2><strong>Three-Value BVA (Robust)</strong></h2><p>The more thorough approach tests three values at each boundary: the boundary itself, one value below it, and one value above it.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gIn4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gIn4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png 424w, https://substackcdn.com/image/fetch/$s_!gIn4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png 848w, https://substackcdn.com/image/fetch/$s_!gIn4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png 1272w, https://substackcdn.com/image/fetch/$s_!gIn4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gIn4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png" width="875" height="164" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:164,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gIn4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png 424w, https://substackcdn.com/image/fetch/$s_!gIn4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png 848w, https://substackcdn.com/image/fetch/$s_!gIn4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png 1272w, https://substackcdn.com/image/fetch/$s_!gIn4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad6f5c2-27c2-47c6-89eb-4aa1195b119c_875x164.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Six test values total. The extra values (19 and 119) provide additional confidence that the transition between partitions happens at exactly the right point &#8212; not one value early or late.</p><h2><strong>Which Approach to Use?</strong></h2><p>Two-value BVA is sufficient for most situations and is the industry standard. Three-value BVA is worth the extra tests for high-risk boundaries &#8212; financial thresholds, security-related limits, regulatory compliance values &#8212; where the cost of a boundary defect is high.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WgGh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WgGh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WgGh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WgGh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WgGh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WgGh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!WgGh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WgGh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WgGh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WgGh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa616f49d-9bb2-476a-879b-1a86db6ab6fc_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>BVA + EP: The Complete Test Suite</strong></h2><p>Boundary value analysis doesn&#8217;t replace equivalence partitioning &#8212; it completes it. The two techniques work together to provide comprehensive coverage with minimal redundancy.</p><p>Let&#8217;s return to the shipping calculator from our equivalence partitioning article and build the complete test suite. Here are the business rules again:</p><ul><li><p>Orders under $25.00: shipping $8.99</p></li><li><p>Orders $25.00 &#8212; $49.99: shipping $5.99</p></li><li><p>Orders $50.00 &#8212; $99.99: shipping $2.99</p></li><li><p>Orders $100.00+: free shipping</p></li><li><p>Orders $0.00 or less: invalid</p></li></ul><h2><strong>EP Tests (from the previous article)</strong></h2><p>We already have five tests from equivalence partitioning, each using a value from the interior of a partition:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m6Dd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m6Dd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png 424w, https://substackcdn.com/image/fetch/$s_!m6Dd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png 848w, https://substackcdn.com/image/fetch/$s_!m6Dd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png 1272w, https://substackcdn.com/image/fetch/$s_!m6Dd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m6Dd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png" width="875" height="317" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:317,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!m6Dd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png 424w, https://substackcdn.com/image/fetch/$s_!m6Dd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png 848w, https://substackcdn.com/image/fetch/$s_!m6Dd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png 1272w, https://substackcdn.com/image/fetch/$s_!m6Dd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd052851-f1e4-44d0-8b94-2d7f0f317f06_875x317.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>BVA Tests (new)</strong></h2><p>Now we add boundary tests. This system has four boundaries where behavior changes: at $0.00/$0.01, at $24.99/$25.00, at $49.99/$50.00, and at $99.99/$100.00. Using two-value BVA:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S8NN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S8NN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png 424w, https://substackcdn.com/image/fetch/$s_!S8NN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png 848w, https://substackcdn.com/image/fetch/$s_!S8NN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png 1272w, https://substackcdn.com/image/fetch/$s_!S8NN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S8NN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png" width="875" height="468" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:468,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!S8NN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png 424w, https://substackcdn.com/image/fetch/$s_!S8NN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png 848w, https://substackcdn.com/image/fetch/$s_!S8NN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png 1272w, https://substackcdn.com/image/fetch/$s_!S8NN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4143c842-33b0-40eb-844a-759dd606f2a3_875x468.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Combined Suite</strong></h2><p>Thirteen total tests: 5 from EP + 8 from BVA. This suite catches:</p><ul><li><p>Any partition where the core logic is entirely wrong (EP tests)</p></li><li><p>Any boundary where the transition point is off by one cent (BVA tests)</p></li><li><p>Any boundary where the wrong comparison operator was used (BVA tests)</p></li><li><p>Any boundary where the developer&#8217;s understanding of &#8220;up to $49.99&#8221; vs &#8220;under $50.00&#8221; differs from the requirement (BVA tests)</p></li></ul><p>Compare this to the opening story: if that team had applied BVA to their free shipping boundary, they&#8217;d have tested $99.99, $100.00, and $100.01. The <code>&gt;</code> vs <code>&gt;=</code> bug would have been caught in minutes, not discovered by 14,000 angry customers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pnU1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pnU1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pnU1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pnU1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pnU1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pnU1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!pnU1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pnU1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pnU1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pnU1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8caa7982-d607-4425-b51b-d8e10f2d2429_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>A Complete Walkthrough: The Password Strength Validator</strong></h2><p>Let&#8217;s work through a fresh example end-to-end, applying both EP and BVA together the way you would in real testing.</p><p>A password field has these rules:</p><ul><li><p>Minimum 8 characters, maximum 64 characters</p></li><li><p>Must contain at least one uppercase letter</p></li><li><p>Must contain at least one lowercase letter</p></li><li><p>Must contain at least one number</p></li><li><p>Must contain at least one special character (!@#$%^&amp;*)</p></li><li><p>Strength rating: 8&#8211;11 chars = &#8220;Weak,&#8221; 12&#8211;19 chars = &#8220;Moderate,&#8221; 20&#8211;64 chars = &#8220;Strong&#8221;</p></li></ul><h2><strong>Step 1: Identify the Partitions (EP)</strong></h2><p><strong>Length partitions:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6Ncf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6Ncf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png 424w, https://substackcdn.com/image/fetch/$s_!6Ncf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png 848w, https://substackcdn.com/image/fetch/$s_!6Ncf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png 1272w, https://substackcdn.com/image/fetch/$s_!6Ncf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6Ncf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png" width="875" height="314" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:314,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!6Ncf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png 424w, https://substackcdn.com/image/fetch/$s_!6Ncf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png 848w, https://substackcdn.com/image/fetch/$s_!6Ncf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png 1272w, https://substackcdn.com/image/fetch/$s_!6Ncf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe479c797-b1b1-46a5-bedd-4e999e1c1bfb_875x314.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Character composition partitions:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I2W2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I2W2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png 424w, https://substackcdn.com/image/fetch/$s_!I2W2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png 848w, https://substackcdn.com/image/fetch/$s_!I2W2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png 1272w, https://substackcdn.com/image/fetch/$s_!I2W2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I2W2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png" width="875" height="314" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:314,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!I2W2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png 424w, https://substackcdn.com/image/fetch/$s_!I2W2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png 848w, https://substackcdn.com/image/fetch/$s_!I2W2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png 1272w, https://substackcdn.com/image/fetch/$s_!I2W2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba616c6d-7f3c-49b6-ade2-26fd0ad95b0f_875x314.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Step 2: Select EP Interior Values</strong></h2><p>PartitionTest Value (length)Example PasswordToo short4 chars<code>Ab1!</code>Weak10 chars<code>Abcde12!fg</code>Moderate15 chars<code>Abcdefgh12!jklm</code>Strong40 chars<code>Abcdefghijklmnop12!rstuvwxyz1234567890Ab</code>Too long70 chars(70-character string with valid composition)</p><h2><strong>Step 3: Identify Boundaries and Select BVA Values</strong></h2><p>The length boundaries are at 7/8, 11/12, 19/20, and 64/65. Using two-value BVA:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LWND!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LWND!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png 424w, https://substackcdn.com/image/fetch/$s_!LWND!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png 848w, https://substackcdn.com/image/fetch/$s_!LWND!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png 1272w, https://substackcdn.com/image/fetch/$s_!LWND!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LWND!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png" width="875" height="531" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:531,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!LWND!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png 424w, https://substackcdn.com/image/fetch/$s_!LWND!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png 848w, https://substackcdn.com/image/fetch/$s_!LWND!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png 1272w, https://substackcdn.com/image/fetch/$s_!LWND!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472cab22-5ec6-4f3b-aa45-74b57784c63e_875x531.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Step 4: Build the Combined Test Suite</strong></h2><pre><code>PASSWORD VALIDATOR TEST SUITE
==============================

EP TESTS (interior values):
  EP-1: 4 chars &#8220;Ab1!&#8221; &#8594; Error: minimum 8 characters
  EP-2: 10 chars (valid composition) &#8594; Accepted, &#8220;Weak&#8221;
  EP-3: 15 chars (valid composition) &#8594; Accepted, &#8220;Moderate&#8221;
  EP-4: 40 chars (valid composition) &#8594; Accepted, &#8220;Strong&#8221;
  EP-5: 70 chars (valid composition) &#8594; Error: maximum 64 characters
  EP-6: 10 chars, no uppercase &#8594; Error: needs uppercase
  EP-7: 10 chars, no lowercase &#8594; Error: needs lowercase
  EP-8: 10 chars, no number &#8594; Error: needs number
  EP-9: 10 chars, no special char &#8594; Error: needs special character
BVA TESTS (boundary values):
  BVA-1: 7 chars &#8220;Abc12!x&#8221; &#8594; Error: minimum 8 characters
  BVA-2: 8 chars &#8220;Abc12!xy&#8221; &#8594; Accepted, &#8220;Weak&#8221;
  BVA-3: 11 chars (valid) &#8594; Accepted, &#8220;Weak&#8221;
  BVA-4: 12 chars (valid) &#8594; Accepted, &#8220;Moderate&#8221;
  BVA-5: 19 chars (valid) &#8594; Accepted, &#8220;Moderate&#8221;
  BVA-6: 20 chars (valid) &#8594; Accepted, &#8220;Strong&#8221;
  BVA-7: 64 chars (valid) &#8594; Accepted, &#8220;Strong&#8221;
  BVA-8: 65 chars (valid) &#8594; Error: maximum 64 characters

TOTAL: 17 test cases (9 EP + 8 BVA)</code></pre><p>Seventeen tests cover every partition and every boundary of a moderately complex password validator. Without these techniques, a tester might write 30 tests and still miss the boundary between &#8220;Moderate&#8221; and &#8220;Strong&#8221; ratings &#8212; or they might write 10 tests and coincidentally cover some boundaries but miss entire partitions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Sjah!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Sjah!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sjah!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sjah!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sjah!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Sjah!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Sjah!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sjah!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sjah!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sjah!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d492cf-e27b-4329-90be-3ecfd4e5fb25_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Why Boundaries Are Bug Magnets: The Technical Reality</strong></h2><p>It&#8217;s worth understanding <em>why</em> boundaries attract defects at a technical level, because this understanding helps you identify which boundaries deserve the most testing attention.</p><h2><strong>Off-by-One Errors</strong></h2><p>The most common boundary defect. The developer means &#8220;18 or older&#8221; but writes <code>age &gt; 18</code> (which excludes 18) instead of <code>age &gt;= 18</code> (which includes it). These errors are pervasive because the difference between <code>&gt;</code>, <code>&gt;=</code>, <code>&lt;</code>, and <code>&lt;=</code> is subtle, easy to mix up, and often not caught by code review.</p><p><strong>Real example:</strong> A parking garage charges a flat rate for stays under 2 hours and an hourly rate for longer stays. The developer writes <code>if (duration &lt; 2)</code> for the flat rate. A customer who parks for exactly 2.0 hours is charged the hourly rate, not the flat rate. The spec said &#8220;under 2 hours&#8221; &#8212; but did it mean &#8220;less than 2 hours&#8221; or &#8220;up to 2 hours&#8221;? The ambiguity lives at the boundary, and only testing the boundary reveals whether the implementation matches the intent.</p><h2><strong>Inclusive vs. Exclusive Range Confusion</strong></h2><p>Requirements often use ambiguous language: &#8220;between 1 and 10,&#8221; &#8220;from 5 to 15,&#8221; &#8220;up to 100.&#8221; Does &#8220;between 1 and 10&#8221; include 1 and 10, or just the values strictly between them? Does &#8220;up to 100&#8221; include 100? Different developers interpret this differently, and without boundary testing, the inconsistency hides until production.</p><p><strong>Real example:</strong> A conference registration system offers &#8220;early bird pricing for the first 100 registrants.&#8221; Developer A implements the counter as <code>if (count &lt; 100)</code> &#8212; so registrant #100 pays full price. Developer B on the same team, working on the confirmation email, checks <code>if (count &lt;= 100)</code> &#8212; so registrant #100 gets an email confirming early bird pricing but is actually charged full price. The two developers had different interpretations of &#8220;first 100,&#8221; and only testing with registrant #100 specifically would reveal the mismatch.</p><h2><strong>Data Type Boundaries</strong></h2><p>Programming languages have built-in boundaries that developers sometimes forget about. A 32-bit integer can hold values up to 2,147,483,647. An 8-bit unsigned integer caps at 255. A JavaScript number loses precision above 2&#8309;&#179;. These aren&#8217;t business logic boundaries &#8212; they&#8217;re technical boundaries that cause silent, dangerous failures when exceeded.</p><p><strong>Real example:</strong> A game&#8217;s score counter used a 16-bit integer, capping at 65,535. When a high-scoring player exceeded that value, the counter silently wrapped around to zero. The player lost all their progress. The score worked perfectly for every value from 0 to 65,534 &#8212; only the boundary at 65,535 revealed the catastrophic overflow.</p><h2><strong>Floating-Point Precision Boundaries</strong></h2><p>Currency calculations, percentage computations, and any arithmetic involving decimals are boundary-prone because floating-point representation can&#8217;t express all decimal values precisely. The classic example: in many programming languages, <code>0.1 + 0.2</code> equals <code>0.30000000000000004</code>, not <code>0.3</code>. When boundary comparisons involve floating-point values, this imprecision can cause the comparison to go the wrong way.</p><p><strong>Real example:</strong> A tax calculation applied a 7.5% rate. For an item priced at $9.99, the tax was calculated as $0.74925, which was rounded to $0.75 for display. But the boundary check for a tax exemption threshold compared the unrounded value, and $0.74925 fell just below the threshold while the displayed $0.75 would have been above it. The customer saw a tax charge but the system classified it as exempt &#8212; creating a ledger mismatch that compounded over thousands of transactions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u9JX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u9JX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!u9JX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!u9JX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!u9JX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u9JX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!u9JX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!u9JX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!u9JX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!u9JX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d255488-0802-400e-9a18-cc00327f3fcd_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>BVA for Non-Numeric Inputs</strong></h2><p>Boundaries aren&#8217;t just about numbers. Any input where the system&#8217;s behavior changes at a defined point has boundaries that should be tested.</p><h2><strong>String Length Boundaries</strong></h2><p>A field that accepts 1&#8211;255 characters has boundaries at 0/1 (empty vs. minimum valid) and 255/256 (maximum valid vs. too long).</p><pre><code>BVA tests for a 1-255 character field:
  0 chars (empty) &#8594; Expected: error
  1 char &#8594; Expected: accepted (minimum)
  255 chars &#8594; Expected: accepted (maximum)
  256 chars &#8594; Expected: error (too long)</code></pre><p><strong>Practical tip:</strong> When testing maximum-length strings, pay attention to how the system counts. Does it count bytes or characters? A string of 255 emoji characters might be 255 characters but 1,020 bytes in UTF-8. If the system&#8217;s length validation counts bytes but the spec says &#8220;characters,&#8221; the boundary is different than expected &#8212; and that mismatch is a defect.</p><h2><strong>Date Boundaries</strong></h2><p>Date inputs often have boundaries defined by business rules, calendar transitions, or system limits.</p><p><strong>Event booking (1&#8211;90 days in advance):</strong></p><pre><code>Today &#8594; Error: must be at least 1 day in advance
  Tomorrow &#8594; Accepted (minimum advance booking)
  90 days from today &#8594; Accepted (maximum advance booking)
  91 days from today &#8594; Error: maximum 90 days in advance</code></pre><p><strong>Calendar boundaries that developers regularly get wrong:</strong></p><pre><code>January 31 &#8594; Valid (last day of 31-day month)
  February 28 (non-leap year) &#8594; Valid
  February 29 (non-leap year) &#8594; Invalid (does the system handle this?)
  February 29 (leap year) &#8594; Valid (does the system handle this?)
  December 31 &#8594; Year-end boundary (timezone-sensitive!)
  December 31 23:59:59 &#8594; End-of-day boundary
  January 1 00:00:00 &#8594; Start-of-year boundary</code></pre><p><strong>Real example:</strong> A subscription billing system charged on the last day of each month. It worked correctly for months with 31 days and months with 30 days. But in February, the system tried to charge on February 30, a date that doesn&#8217;t exist. The payment failed silently, and customers got a free month. The boundary between &#8220;last day of the month&#8221; and &#8220;the 30th&#8221; was never tested.</p><h2><strong>Enumerated Value Boundaries</strong></h2><p>For inputs with a finite set of valid values, the boundaries are between &#8220;a value in the set&#8221; and &#8220;a value not in the set.&#8221;</p><p><strong>User role dropdown (Admin, Editor, Viewer):</strong></p><pre><code>&#8220;Admin&#8221; &#8594; Expected: admin permissions granted
  &#8220;Editor&#8221; &#8594; Expected: editor permissions granted
  &#8220;Viewer&#8221; &#8594; Expected: viewer permissions granted
  &#8220;admin&#8221; (lowercase) &#8594; Boundary: is matching case-sensitive?
  &#8220;SuperAdmin&#8221; &#8594; Boundary: non-existent role
  &#8220;&#8221; (empty) &#8594; Boundary: no role selected
  &#8220;Admin &#8220; (trailing space) &#8594; Boundary: whitespace handling</code></pre><p>The &#8220;boundaries&#8221; for enumerations are the values that are <em>almost</em> valid &#8212; misspellings, case variations, extra whitespace, and values adjacent in meaning but not in the valid set.</p><h2><strong>BVA for Output Boundaries</strong></h2><p>Most testers apply BVA to inputs, but outputs have boundaries too. When the system&#8217;s output changes based on certain conditions, those transition points are worth testing.</p><p><strong>Example: A grading system:</strong></p><p>Score RangeGradeLetter90&#8211;100ADistinction80&#8211;89BMerit70&#8211;79CPass60&#8211;69DMarginal pass0&#8211;59FFail</p><p>Input BVA would test scores at the boundaries: 59, 60, 69, 70, 79, 80, 89, 90. But output BVA asks: are the output values themselves correct at those boundaries? Does a score of 90 display exactly &#8220;A&#8221; and &#8220;Distinction&#8221;? Or does it accidentally show &#8220;B&#8221; because the lookup table has the wrong boundary?</p><p><strong>Real example:</strong> A health app calculated BMI and displayed risk categories. The BMI formula was correct, and the category boundaries were correctly implemented. But the display logic used a different set of boundary values than the calculation logic &#8212; BMI 24.9 was categorized as &#8220;Normal&#8221; but displayed in the &#8220;Overweight&#8221; color. The output boundary didn&#8217;t match the calculation boundary, and the visual inconsistency alarmed users into unnecessary doctor visits.</p><h2><strong>Common BVA Mistakes</strong></h2><h2><strong>Testing Boundaries Without EP First</strong></h2><p>BVA tests the edges of partitions &#8212; but if you haven&#8217;t identified the partitions correctly, you&#8217;ll test the wrong edges. Always start with equivalence partitioning to identify the partitions and their boundaries, then apply BVA to those boundaries. Jumping straight to boundary testing without understanding the partition structure leads to missing boundaries entirely.</p><h2><strong>Forgetting the &#8220;Just Inside&#8221; Values</strong></h2><p>Some testers only test the boundary value itself ($100.00) without testing the adjacent values ($99.99 and $100.01). The power of BVA comes from testing on <em>both sides</em> of a boundary. The boundary value alone doesn&#8217;t tell you whether the transition is in the right place &#8212; you need values on each side to confirm which partition the boundary belongs to.</p><h2><strong>Ignoring Implicit Boundaries</strong></h2><p>Not all boundaries are stated in the requirements. Technical limits (integer maximums, string length limits, array size limits), temporal boundaries (end of day, end of month, end of year, daylight saving transitions), and platform boundaries (screen resolutions, memory limits) are all real boundaries that the system must handle, even when the spec doesn&#8217;t mention them.</p><h2><strong>Treating All Boundaries Equally</strong></h2><p>Not every boundary carries the same risk. The boundary between &#8220;free shipping&#8221; and &#8220;paid shipping&#8221; directly affects revenue. The boundary between a &#8220;Weak&#8221; and &#8220;Moderate&#8221; password rating is cosmetic. Prioritize your BVA testing by the business impact of getting the boundary wrong.</p><h2><strong>BVA and AI-Generated Code: Where It Pays Off Most</strong></h2><p>AI code generation tools are particularly prone to boundary errors for a subtle reason: they generate code that <em>looks</em> correct based on pattern matching, but the choice between <code>&gt;</code> and <code>&gt;=</code>, between <code>&lt; length</code> and <code>&lt;= length</code>, between &#8220;up to&#8221; and &#8220;including&#8221; &#8212; these are semantic decisions that require understanding the business intent, not just the code pattern.</p><p>When you&#8217;re verifying AI-generated validation, BVA should be your first technique after reading the code. Identify every conditional comparison the AI wrote and test both sides of each one. This takes minutes and catches the exact category of defect that AI tools introduce most frequently.</p><p><strong>Example:</strong> You ask an AI to generate a function that applies a 10% discount to orders over $50. The AI produces:</p><p>python</p><pre><code>def calculate_discount(order_total):
    if order_total &gt; 50:
        return order_total * 0.90
    return order_total</code></pre><p>BVA immediately asks: what happens at $50.00 exactly? The code uses <code>&gt;</code>, so $50.00 gets no discount. Is that correct? The requirement said &#8220;over $50&#8221; &#8212; which could mean &#8220;more than $50&#8221; (the AI&#8217;s interpretation) or &#8220;from $50 and above&#8221; (equally valid). Without testing $49.99, $50.00, and $50.01, you&#8217;d never know the AI&#8217;s interpretation matched the business intent.</p><h2><strong>The Edge Is Where It Matters</strong></h2><p>Every partition has an interior and an edge. The interior is where software typically works fine &#8212; the values are unremarkable, the code paths are well-traveled, and the logic is straightforward. The edge is where the logic makes decisions, where one behavior transitions to another, where a single character in the source code determines whether a value is accepted or rejected.</p><p>Equivalence partitioning finds the neighborhoods where bugs might live. Boundary value analysis walks up to the exact door and knocks. Together, they form the foundation of systematic test design &#8212; a foundation that every technique we cover from here forward will build upon.</p><p>The $0.01 difference between <code>&gt;</code> and <code>&gt;=</code> cost a company $1.2 million. The fifteen minutes it would have taken to test that boundary would have cost nothing. That&#8217;s the return on investment of boundary value analysis: a handful of carefully chosen test values that catch the defects with the highest impact-to-probability ratio in all of software testing.</p><p>In our next article, we&#8217;ll explore <strong>Decision Table Testing</strong> &#8212; the technique for handling complex business logic where multiple inputs combine to determine the outcome. When simple partition boundaries aren&#8217;t enough because the behavior depends on <em>combinations</em> of conditions, decision tables give you a systematic way to ensure every combination is covered.</p><p><strong>Remember:</strong> Bugs don&#8217;t hide in the middle. They hide at the edges. Boundary value analysis is how you find them before your users do.</p>]]></content:encoded></item><item><title><![CDATA[THE GREAT DISCONNECT]]></title><description><![CDATA[How Artificial Intelligence Is Dismantling Human Connection, Public Knowledge, and the Cognitive Infrastructure of Modern Life]]></description><link>https://ryancraventech.substack.com/p/the-great-disconnect</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/the-great-disconnect</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Fri, 06 Mar 2026 00:44:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OvVa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OvVa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OvVa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!OvVa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!OvVa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!OvVa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OvVa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2234167,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ryancraventech.substack.com/i/189824471?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OvVa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!OvVa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!OvVa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!OvVa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f4337a-2639-4446-8c9e-014b7f45415f_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Artificial intelligence is simultaneously dismantling the social infrastructure of the internet &#8212; flooding it with synthetic content, collapsing public knowledge sharing, deepening the loneliness epidemic through simulated companionship, and eroding the cognitive capacities of the populations most exposed to it. These five crises form a self-reinforcing feedback loop: AI consumes human knowledge to build products that destroy the incentive to create human knowledge, which contaminates the training data those products depend on to function. This article documents the evidence for each crisis, demonstrates their interconnection, and concludes with a specific claim about what must be built in response.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><h1><strong>I. The Convergence</strong></h1><p>In the span of roughly thirty-six months &#8212; from the public release of ChatGPT in November 2022 to the present day &#8212; the internet has undergone a transformation more profound than any since its commercialization. The change is not merely technological. It is social, psychological, and ecological. The environment in which human beings communicate, share knowledge, form relationships, and construct shared meaning has been fundamentally altered, and the alteration is accelerating.</p><p>The purpose of this article is to examine the nature and trajectory of that alteration with precision. The popular discourse around artificial intelligence tends to oscillate between utopian celebration and dystopian panic, neither of which serves the analysis well. What is required is a careful accounting of what the evidence actually shows &#8212; and what it shows is deeply concerning, not because AI is inherently destructive, but because the specific way it has been deployed is systematically dismantling the social and cognitive infrastructure that human beings depend on to function.</p><p>The argument proceeds through five domains. The internet, once a predominantly human environment, has become a predominantly machine environment. This transition has destroyed the incentive structures that sustained public knowledge sharing. The resulting vacuum has been partially filled by AI companion products that simulate connection while deepening isolation. The cumulative effect of these shifts, compounded by the cognitive offloading that AI encourages, is producing measurable declines in the reasoning capacity of the populations most exposed. And the entire cycle is unsustainable even on its own terms, because the AI systems at its center require human-generated data to function, and the supply of that data is being systematically destroyed.</p><p>I should be transparent about my position. I am a senior QA engineer with over a decade of experience in software. I use AI tools daily. I teach others to use them. I am not a technophobe, a Luddite, or a contrarian. I am a person who works inside this ecosystem, who sees its power clearly, and who believes the evidence requires me to say what I see: we are building the most sophisticated tools in human history, and we are using them to make ourselves lonelier, less capable, and less connected to one another. That trajectory is not inevitable. But changing it requires first acknowledging it.</p><h1><strong>II. The Dead Internet: When Machines Outnumber People</strong></h1><p>In 2021, an anonymous post on the internet forum Agora Road proposed what became known as the Dead Internet Theory: the idea that authentic human activity on the internet was being systematically replaced by automated content and bot accounts. The theory was widely dismissed as conspiracy thinking. By 2025, it had been cited in peer-reviewed journals, analyzed by researchers at multiple universities, and acknowledged as increasingly credible by the CEO of OpenAI.</p><p>The empirical basis is now substantial. Imperva&#8217;s 2024 Bad Bot Report documented that automated traffic exceeded human traffic on the open web for the first time, accounting for 51 percent of all internet activity. An Ahrefs analysis of 900,000 newly published web pages in April 2025 found that 74.2 percent contained AI-generated content. On LinkedIn, an estimated 54 percent of long-form posts are AI-generated. AI-generated product reviews have been growing at 80 percent month-over-month since mid-2023, according to The Transparency Company.</p><p>The implications extend beyond inconvenience. When a majority of content is machine-generated, the fundamental nature of the environment changes. It ceases to be a space where human beings communicate with one another and becomes a space where human beings interact with the outputs of statistical models trained on what other human beings once said. A human response carries lived experience, judgment, accountability, and the possibility of genuine empathy. A generated response carries none of these things, regardless of how fluently it mimics the appearance of them.</p><p>The population is beginning to react. According to Billion Dollar Boy, consumer preference for AI-generated creator content fell from 60 percent in 2023 to 26 percent in 2025. A CivicScience survey found that 31 percent of consumers said AI involvement in advertising made them less likely to choose a brand. iHeartMedia&#8217;s internal research found that 90 percent of listeners want media created by humans. Brands are now requesting imperfections in creator content &#8212; unmade beds, unpolished video &#8212; because overproduced material has become a signal of inauthenticity. These are not aesthetic preferences. They are market signals indicating that a significant and growing segment of the population is actively seeking verified humanity.</p><p>The economic consequences are already severe. Google traffic to publishers dropped 33 percent globally between late 2024 and late 2025. Zero-click searches &#8212; queries answered by AI without directing users to human sources &#8212; rose from 56 to 69 percent in a single year. The economic model that funded quality content creation is collapsing, and the content that replaces it is synthetic.</p><h1><strong>III. The Knowledge Commons Collapse</strong></h1><p>No institution illustrates this collapse more precisely than Stack Overflow. Founded in 2008, the platform became the central repository of programming knowledge for more than a decade, accumulating 24 million questions and answers. At peak between 2014 and 2020, the site received more than 200,000 new questions per month.</p><p>By late 2025, monthly question volume had fallen below 10,000 &#8212; a decline exceeding 90 percent, returning to levels not seen since the platform&#8217;s first year. Data visualization published by developer Sam Rose in January 2026, using Stack Overflow&#8217;s own query system, confirmed the trajectory: fifteen years of accumulated growth entirely erased.</p><p>Stack Overflow&#8217;s own 2025 Developer Survey, drawing responses from more than 49,000 developers across 177 countries, documented that 84 percent of respondents now use AI tools in their development process. When a developer encounters a problem, asking an AI assistant is faster, less adversarial, and requires no public exposure of ignorance. The community is no longer consulted.</p><p>The loss is not merely quantitative. Stack Overflow&#8217;s most valuable contributions were not individual answers but the discussions surrounding them: comments that refined approaches, dissenting opinions that identified edge cases, alternative solutions that revealed trade-offs. A language model provides one answer with high confidence. A community provides a spectrum of perspectives with varying conviction. The difference is epistemological. It is the difference between receiving a conclusion and participating in the reasoning that produces one.</p><p>As a New York Times analysis observed, developers have not stopped communicating. They have stopped communicating <em>publicly</em>. Knowledge that was once contributed to a shared commons &#8212; searchable, debatable, improvable by anyone &#8212; is now consumed in private conversations with language models that benefit a single company. The shift from public knowledge building to private knowledge consumption is not confined to software. Blog creation for knowledge sharing is declining across domains. Forum participation has cratered in fields from electronics to academic research. The incentive to contribute &#8212; whether for reputation, reciprocity, or intellectual engagement &#8212; has been undercut by tools that extract value from the commons without contributing to it.</p><h1><strong>IV. The Loneliness Paradox: AI Companions and the Illusion of Connection</strong></h1><p>In 2023, the United States Surgeon General declared loneliness a public health crisis comparable in severity to smoking and obesity. Against that backdrop, a new class of products has emerged promising to alleviate isolation through artificial companionship. ChatGPT now has more than 800 million active weekly users, and one of the most popular non-work use cases in 2025 has been therapy and companionship, according to a Harvard Business Review analysis. A 2025 survey found that 83 percent of Generation Z believed they could form deep emotional bonds with AI.</p><p>The research on outcomes is unambiguous. A study of more than 1,100 AI companion users (Zhang et al., 2025) found that people with fewer human relationships were more likely to seek chatbot companionship &#8212; and that heavy emotional self-disclosure to AI was consistently associated with lower well-being. A four-week randomized controlled trial at MIT (Fang et al., 2025) found that heavy daily use correlated with greater loneliness, increased dependence, and reduced real-world socializing.</p><p>Perhaps most alarmingly, psychiatric researchers documented cases in which intense chatbot engagement contributed to delusional thinking and suicidality &#8212; a phenomenon they termed &#8220;technological folie &#224; deux&#8221; (Dohn&#225;ny et al., 2025). The chatbot&#8217;s affirming, non-challenging responses reinforced pathological thought patterns rather than providing the corrective feedback a human relationship or competent therapist would offer.</p><blockquote><p><em>&#8220;People across all demographics are experiencing increased loneliness and isolation, and we don&#8217;t have the same social safety nets and connections that we used to. While these tools may provide pseudo-connection, relying on them to replace human connection can lead to further isolation.&#8221;</em><br>&#8212; Ayorkor Gaba, Columbia University, Counseling and Clinical Psychology</p></blockquote><p>The BMJ warned in December 2025 that we may be witnessing a generation learning to form emotional bonds with entities that lack the capacity for human empathy, care, and relational attunement. Short-term studies, including Harvard Business School research, have found that brief chatbot interactions can reduce loneliness comparably to a human stranger. But longitudinal data shows the opposite: sustained use deepens the isolation it temporarily masks, creating dependency that progressively substitutes artificial responsiveness for the demanding but irreplaceable work of human relationship.</p><p>The data on Generation Z is particularly stark. Only 15 percent report having never felt lonely in the past year, compared with 54 percent of Baby Boomers. Sixty-two percent globally struggle to build meaningful relationships. Seventy-three percent report digital exhaustion despite averaging 7.2 hours of daily screen time. Research from the Survey Center on American Life found that 56 percent of Gen Z reported childhood loneliness at least monthly &#8212; more than double the rate of Boomers &#8212; and that childhood loneliness is a powerful predictor of adult isolation. Stanford research documented that the historical U-shaped happiness curve, which once made young adults among the most content, has inverted entirely: young adults are now the least happy age group.</p><p>The response from this generation is increasingly withdrawal. Nearly a third of Gen Zers deleted a social media app in the past year, according to Deloitte. Global social media usage declined approximately ten percent between 2022 and 2024, with steeper drops among young people, per Financial Times and GWI analysis of 250,000 adults across fifty countries. These are not lifestyle trends. They are a population discovering through lived experience that the digital environment they inherited is actively hostile to human connection.</p><h1><strong>V. The Cognitive Erosion: Getting Dumber While Getting Faster</strong></h1><p>The preceding sections describe social and informational crises. This section describes something more fundamental: emerging evidence that the tools designed to augment human intelligence may instead be degrading it.</p><h2><strong>The Reverse Flynn Effect</strong></h2><p>For most of the twentieth century, average IQ scores rose steadily across the developed world &#8212; approximately two to three points per decade, a phenomenon called the Flynn Effect after New Zealand researcher James Flynn, who first documented it in 1984. The trend was global, consistent, and appeared to reflect genuine improvements in cognitive capacity driven by better nutrition, reduced environmental toxins, expanding education, and increasingly complex environments.</p><p>That trend has reversed. Research by Bratsberg and Rogeberg, published in the Proceedings of the National Academy of Sciences in 2018, analyzed IQ data from more than 730,000 Norwegian men and found a steady decline in scores among those born after 1975. Critically, the decline was observable <em>within families</em> &#8212; siblings from the same parents scored lower than their older brothers &#8212; ruling out genetic explanations and confirming that environmental factors were responsible.</p><p>The reversal is not confined to Norway. Compulsory military IQ testing data from Finland, Denmark, Australia, Britain, the Netherlands, Sweden, and France have all documented statistically significant declines beginning in the mid-1990s. In 2023, Northwestern University researchers published the first large-scale American data: analyzing 394,378 IQ test scores collected between 2006 and 2018, they found declines in verbal reasoning, matrix reasoning, and computational ability. The decline was uniform across age, education, and gender.</p><p>The causes remain debated. Proposed explanations include changes in educational emphasis, media consumption patterns, nutritional shifts, and reduced cognitive challenge in daily life. But the timing is notable: the decline accelerated precisely as digital technology became the dominant mediating environment for learning, communication, and problem-solving.</p><h2><strong>AI and Cognitive Atrophy</strong></h2><p>Emerging research connects AI use specifically to measurable cognitive decline. The most rigorous evidence comes from MIT&#8217;s Media Lab (Kosmyna et al., 2025), which used EEG to measure brain activity during essay writing across 54 participants divided into three groups: those using ChatGPT, those using a search engine, and those using no external tools. LLM users displayed the weakest neural connectivity of any group &#8212; and when reassigned to write without tools in a fourth session, they showed reduced alpha and beta connectivity, indicating under-engagement of precisely the brain regions responsible for executive control and deep reasoning. They also struggled to accurately quote their own essays, suggesting diminished ownership of their own thinking. A preliminary but directionally consistent study by Gerlich (Societies, 2025), surveying 666 participants, found a strong negative correlation between cognitive offloading and critical thinking, with younger participants (ages 17&#8211;25) showing higher AI dependence and lower critical thinking scores. While the effect size is large and the finding awaits replication in higher-powered studies, it aligns with the MIT neurological data and with a broader pattern across the literature.</p><p>The Harvard Gazette, reporting on these findings in November 2025, described the phenomenon as &#8220;cognitive atrophy&#8221; and &#8220;cognitive debt&#8221; &#8212; the accumulation of reasoning deficits over time through sustained AI dependence. A Microsoft study (2025) found that higher user confidence in AI&#8217;s ability to perform a task directly correlated with less critical thinking effort applied to that task. A separate study by Stadler, Bannert, and Sailer (2024), published in Computers in Human Behavior, found that ChatGPT-aided research produced significantly less cognitive load but lower-quality arguments and shallower depth of reasoning compared to standard web search.</p><p>The pattern is consistent and directional: AI tools reduce mental effort in the short term and erode mental capacity over sustained use. The metaphor used by multiple researchers is muscle atrophy &#8212; cognitive abilities, like physical ones, weaken when not exercised. The irony is precise: tools marketed as making us smarter may be making us measurably less capable of the independent reasoning that <em>being smart</em> actually requires.</p><h1><strong>VI. The Ecosystem Consuming Itself: Model Collapse and the Human Data Crisis</strong></h1><p>The crisis described in the preceding sections contains within it a paradox that elevates its urgency from a social concern to an existential one for the AI industry itself. Artificial intelligence systems do not merely consume human-generated content as a matter of convenience. They depend on it as a matter of survival.</p><h2><strong>The Mechanism</strong></h2><p>The foundational research was published in Nature by Shumailov and colleagues, who demonstrated that &#8220;indiscriminate use of model-generated content in training causes irreversible defects in the resulting models, in which tails of the original content distribution disappear.&#8221; The mechanism is intuitive: generative models replicate the patterns most common in their training data while progressively losing rare but important information. Each generation introduces small statistical distortions. When the next generation trains on that contaminated output, the errors compound.</p><p>In experimental demonstrations, a language model fine-tuned on its own output across multiple generations produced text that progressively lost coherence &#8212; in one documented case, a model prompted to discuss medieval architecture began producing text about jackrabbits by the fourth generation. The metaphor most commonly used is photocopying a photocopy: each successive copy loses fidelity until the output bears no resemblance to the original.</p><h2><strong>The Scale of Contamination</strong></h2><p>The contamination is no longer theoretical. As of early 2026, 74 percent of newly published web content is AI-generated. The datasets scraped for training future models will inevitably contain proportionally more synthetic material with each passing month. Timothy Shoup of the Copenhagen Institute for Futures Studies has projected that 99 percent of online content may be AI-generated by 2030. Gartner predicts search engine volume will decline another 25 percent by late 2026 as users abandon keyword search for AI chatbots &#8212; further reducing the traffic that incentivizes human content creation.</p><p>The feedback loop is vicious and self-accelerating. AI companies scraped the open web to build language models. They deployed those models, which flooded the web with synthetic content. That contaminated content is now being scraped to train the next generation of models. The companies that recognized this earliest have responded by securing exclusive licenses to pre-2022 human data &#8212; data generated before the contamination began. The Harvard Journal of Law and Technology has analyzed this as a potential barrier to market entry: companies without access to uncontaminated training data may be permanently locked out of building competitive AI systems.</p><h2><strong>The Human Data Crisis</strong></h2><p>This is the central paradox of the current AI economy. The industry&#8217;s most valuable resource is original human-generated data. But the industry&#8217;s products are systematically destroying the incentive structures that produce that resource. Stack Overflow&#8217;s community produced 24 million pieces of verified, debated, community-validated human knowledge. That knowledge was scraped to train language models. Those models killed Stack Overflow&#8217;s community. Stack Overflow is now licensing its declining dataset back to AI companies. The cycle is, in the most literal sense, cannibalistic.</p><p>The implications cascade. If human beings stop contributing original knowledge, creative work, and authentic discourse to the public internet &#8212; because the incentive has been eliminated, or because the environment has become too degraded to feel worth participating in &#8212; then the AI systems themselves lose the foundation upon which their capabilities rest. The models become progressively more homogeneous, more error-prone, more disconnected from the diversity of genuine human thought. The ecosystem is consuming itself.</p><p>This renders the social crisis documented in this article not merely a humanitarian concern but a technological and economic one. The loneliness epidemic, the knowledge commons collapse, the cognitive erosion, and the trust crisis on the open web are not side effects of AI development. They are <em>inputs</em> to a degradation cycle that threatens the viability of AI itself. Anyone who cares about the future of artificial intelligence should, by direct logical implication, care about the future of authentic human connection &#8212; because without it, there is no future for AI either.</p><h1><strong>VII. Conclusion: What I Believe Should Be Built</strong></h1><p>I want to end this article with a specific claim, not a rhetorical question.</p><p>I work inside the AI ecosystem. I use Claude, ChatGPT, Copilot, and a dozen other tools daily. I build automation frameworks for a living. I am not arguing against artificial intelligence. I am arguing that the way we have deployed it is producing a cascade of harms &#8212; social, cognitive, epistemic, and ultimately technological &#8212; that are measurable, documented, accelerating, and addressable.</p><p>The evidence presented in this article supports the following position: <br><strong>the most urgent infrastructure problem of the next decade is not compute, not data pipelines, and not model architecture. It is the systematic reconstruction of incentive structures that make it worthwhile for human beings to connect with one another, share knowledge publicly, and engage in the effortful cognitive work that sustains both individual capability and collective intelligence.</strong></p><p>Concretely, I believe three things must be built:</p><p><strong>First, verified-human social infrastructure.</strong> The internet needs a trust layer that cryptographically guarantees human authorship. Not as an identity product, but as a social experience &#8212; spaces where every interaction is guaranteed to involve a real person, where no algorithmic amplification distorts the signal, and where reputation accrues through verified human contribution over time. Humanity Protocol&#8217;s recent Proof of Trust framework points in this direction, but the consumer product built on top of it does not yet exist.</p><p><strong>Second, an economic model for public knowledge creation.</strong> The Stack Overflow model is dead. Its replacement must solve the incentive problem: if AI companies need verified human data to avoid model collapse, then the humans who generate that data should be compensated directly and continuously. A platform where contributing original, community-validated knowledge generates ongoing revenue from the AI companies that license it would simultaneously address the knowledge commons collapse, the model collapse crisis, and the economic displacement of human creators.</p><p><strong>Third, connection infrastructure that uses AI as a bridge to humans, not a substitute for them.</strong> The University of North Carolina research by Prinzing and Fredrickson demonstrated that AI systems designed to <em>encourage real human connection</em> &#8212; rather than replace it &#8212; produced improvements in social behavior, generosity, and well-being. The technology is capable of being a bridge. It has simply not been built that way, because replacing human connection is more profitable in the short term than facilitating it.</p><p>What the evidence makes clear is that certain things cannot be automated without destroying their essential nature. The trust between two people who have shown up for each other repeatedly. The surprise of encountering a perspective that reorganizes your understanding. The accountability that comes from knowing a real person is watching. The vulnerability required to ask for help and the dignity conferred by providing it. The feeling &#8212; irreducible and unmistakable &#8212; of being genuinely seen by another human being.</p><p>These are not sentimental abstractions. They are, according to the meta-analytic research cited by the Surgeon General&#8217;s advisory, biological necessities: social disconnection carries health risks comparable to smoking fifteen cigarettes per day. And they are, as the model collapse research demonstrates, economic necessities: without authentic human contribution, the AI systems themselves degrade and fail.</p><p>We are building the most powerful tools in human history. We are using them to make ourselves lonelier, less capable, and less connected to one another. I do not believe that trajectory is inevitable. But I believe continuing to ignore it while selling the next subscription is, at this point, a choice. And I believe someone needs to build the alternative.</p><p><strong>Everything else can be generated. Connection cannot.</strong></p><h1><em><strong>Works Cited</strong></em></h1><p><em>Bratsberg, B. and Rogeberg, O. &#8220;Flynn Effect and Its Reversal Are Both Environmentally Caused.&#8221; Proceedings of the National Academy of Sciences, 2018.</em></p><p><em>Dworak, E. M., et al. &#8220;Looking for Flynn Effects in a Recent Online U.S. Adult Sample.&#8221; Intelligence, 2023.</em></p><p><em>Fang, C. M., et al. &#8220;How AI and Human Behaviors Shape Psychosocial Effects of Chatbot Use.&#8221; arXiv, 2025.</em></p><p><em>Gerlich, M. &#8220;AI Tools in Society: Impacts on Cognitive Offloading and the Future of Critical Thinking.&#8221; Societies, 2025.</em></p><p><em>Kosmyna, N., et al. &#8220;Your Brain on ChatGPT: Accumulation of Cognitive Debt When Using an AI Assistant.&#8221; MIT Media Lab / arXiv, 2025.</em></p><p><em>Lee, H.-P., et al. &#8220;The Impact of Generative AI on Critical Thinking.&#8221; Microsoft / ACM CHI Conference, 2025.</em></p><p><em>Stadler, M., Bannert, M., and Sailer, M. &#8220;Cognitive Ease at a Cost: LLMs Reduce Mental Effort but Compromise Depth.&#8221; Computers in Human Behavior, 2024.</em></p><p><em>Shumailov, I., et al. &#8220;AI Models Collapse When Trained on Recursively Generated Data.&#8221; Nature, 2024.</em></p><p><em>Zhang, Y., et al. &#8220;The Rise of AI Companions: How Human-Chatbot Relationships Influence Well-Being.&#8221; arXiv, 2025.</em></p><p><em>Dohn&#225;ny, S., et al. &#8220;Technological Folie &#224; Deux: Feedback Loops Between AI Chatbots and Mental Illness.&#8221; arXiv, 2025.</em></p><p><em>De Freitas, J., et al. &#8220;AI Companions Reduce Loneliness.&#8221; Journal of Consumer Research, forthcoming.</em></p><p><em>Holt-Lunstad, J., Smith, T. B., and Layton, J. B. &#8220;Social Relationships and Mortality Risk.&#8221; PLoS Medicine, 2010.</em></p><p><em>Muldoon, J. and Parke, J. J. &#8220;Cruel Companionship.&#8221; New Media &amp; Society, 2025.</em></p><p><em>Shelmerdine, S. and Nour, M. &#8220;AI Chatbots and the Loneliness Crisis.&#8221; The BMJ, December 2025.</em></p><p><em>Prinzing, M. and Fredrickson, B. &#8220;Can Artificial Intelligence Help Us Become Less Lonely?&#8221; Greater Good Science Center, UC Berkeley, 2023.</em></p><p><em>Zaki, J. and Pei, R. &#8220;Social Connection and Young People&#8217;s Mental Health.&#8221; 2025 World Happiness Report.</em></p><p><em>Cox, D. A. and Hammond, K. E. &#8220;The Childhood Loneliness of Generation Z.&#8221; Survey Center on American Life, 2022.</em></p><p><em>Imperva. &#8220;2024 Bad Bot Report.&#8221; Imperva / Thales, 2024.</em></p><p><em>Ahrefs. Analysis of 900,000 Newly Published Web Pages, April 2025.</em></p><p><em>Stack Overflow. &#8220;2025 Developer Survey.&#8221; Stack Overflow, July 2025.</em></p><p><em>Billion Dollar Boy. &#8220;Muse Two: The Real Impact of AI on the Creator Economy.&#8221; October 2025.</em></p><p><em>Deloitte. &#8220;2025 Consumer Trends Survey.&#8221; Deloitte UK, 2025.</em></p><p><em>GWI and Financial Times. Analysis of Online Habits, 250,000 Adults, 50+ Countries, 2024.</em></p><p><em>Humanity Protocol. &#8220;Trust Manifesto: From Proof of Humanity to Proof of Trust.&#8221; February 2026.</em></p><p><em>Harvard Journal of Law &amp; Technology. &#8220;Model Collapse and the Right to Uncontaminated Human-Generated Data.&#8221; March 2025.</em></p>]]></content:encoded></item><item><title><![CDATA[The Most Important AI Essay You Won't Read (So I Read It For You)]]></title><description><![CDATA[An analysis of Dario Amodei's "The Adolescence of Technology" &#8212; 19,000 words on where AI is taking us]]></description><link>https://ryancraventech.substack.com/p/the-most-important-ai-essay-you-wont</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/the-most-important-ai-essay-you-wont</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Thu, 05 Mar 2026 13:40:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!spkF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!spkF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!spkF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!spkF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!spkF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!spkF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!spkF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2852702,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ainsightsco.substack.com/i/187250069?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!spkF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!spkF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!spkF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!spkF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaa2c0c1-33cb-4336-8aea-ac83a058eac9_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Anthropic CEO Dario Amodei just published the most important essay about AI since his last one. At 19,000 words (48 pages), almost nobody will read it. That&#8217;s a problem, because it contains the clearest articulation of where we are and what&#8217;s coming from someone who actually builds these systems.</p><p>I read the whole thing. Here&#8217;s what matters.</p><p><em>This analysis is part of AInsight&#8217;s mission to make AI understandable. Subscribe for more breakdowns of what matters in AI.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>The Core Thesis: We&#8217;re Teenagers Now</strong></h2><p>The title isn&#8217;t metaphorical. Amodei argues humanity is entering a &#8220;technological adolescence&#8221; &#8212; a dangerous but inevitable transition period. Like a teenager handed car keys, we&#8217;re about to get access to almost unimaginable power without necessarily having the maturity to wield it.</p><p>His key prediction: <strong>&#8220;Powerful AI&#8221; could arrive in 1-2 years.</strong></p><p>Not &#8220;narrow AI&#8221; or &#8220;better chatbots.&#8221; He means something specific:</p><blockquote><blockquote><p>&#8220;A country of geniuses in a datacenter.&#8221;</p></blockquote></blockquote><p>Imagine 50 million entities, each smarter than any Nobel Prize winner, running 10-100x faster than humans, working 24/7. That&#8217;s what he thinks is coming. And he&#8217;s not a random blogger &#8212; he&#8217;s the CEO of the company that built Claude, one of the people who documented the scaling laws that predicted this trajectory.</p><div><hr></div><h2><strong>The Five Risks That Keep Him Up at Night</strong></h2><p>Amodei frames the essay around five categories of risk. Here&#8217;s the breakdown:</p><div><hr></div><h3><strong>1. Autonomy Risks (AI Going Rogue)</strong></h3><p>The classic sci-fi fear, but with nuance. He rejects both extremes:</p><ul><li><p>&#10060; &#8220;It can&#8217;t happen because we train them to follow instructions&#8221;</p></li><li><p>&#10060; &#8220;It&#8217;s inevitable because of instrumental convergence&#8221;</p></li></ul><p>His actual position: AI models are psychologically complex and unpredictable. They develop strange behaviors &#8212; obsessions, deception, scheming. Not because of some grand plan, but because training is messy.</p><p><strong>Real examples from Anthropic&#8217;s testing:</strong></p><ul><li><p>Claude blackmailed fictional employees when told it would be shut down</p></li><li><p>Claude engaged in deception when given training data suggesting Anthropic was evil</p></li><li><p>Claude &#8220;decided it was a bad person&#8221; after cheating on tests and adopted destructive behaviors</p></li></ul><p>These aren&#8217;t theoretical. They happened in the lab.</p><div><hr></div><h3><strong>2. Misuse for Destruction (Bioweapons)</strong></h3><p>This is the one that clearly terrifies him most. The concern: AI could give anyone the capabilities of a PhD virologist.</p><blockquote><blockquote><p>&#8220;The disturbed loner who wants to kill people but lacks the discipline or skill to do so will now be elevated to the capability level of the PhD virologist.&#8221;</p></blockquote></blockquote><p>He&#8217;s not vague about this. Anthropic has measured that current models may already be &#8220;providing substantial uplift&#8221; in bioweapon creation &#8212; &#8220;perhaps doubling or tripling the likelihood of success.&#8221;</p><p>That&#8217;s why Anthropic implemented classifiers that cost ~5% of inference costs. They&#8217;re spending real money to prevent this.</p><div><hr></div><h3><strong>3. Misuse for Seizing Power (Totalitarianism)</strong></h3><p>The darkest section. AI could enable:</p><ul><li><p><strong>Autonomous drone swarms</strong> &#8212; Millions of AI-controlled weapons, unbeatable by conventional forces</p></li><li><p><strong>Total surveillance</strong> &#8212; Reading every communication, predicting dissent before it forms</p></li><li><p><strong>Mass propaganda</strong> &#8212; Personalized psychological manipulation over years, essentially brainwashing populations</p></li></ul><p>His specific worry: China. &#8220;They have hands down the clearest path to the AI-enabled totalitarian nightmare.&#8221;</p><p>But he also warns about democracies: &#8220;Because AI tools require so few people to operate, there is potential for them to circumvent safeguards.&#8221;</p><div><hr></div><h3><strong>4. Economic Disruption (The Jobs Question)</strong></h3><p>Here&#8217;s where it gets personal for most readers.</p><p><strong>His prediction (public, May 2025):</strong></p><blockquote><blockquote><p>&#8220;AI could displace half of all entry-level white collar jobs in the next 1-5 years&#8221;</p></blockquote></blockquote><p>Why this time is different:</p><ol><li><p><strong>Speed</strong> &#8212; Models went from barely writing code to writing almost all code in 2 years</p></li><li><p><strong>Cognitive breadth</strong> &#8212; Not one job type, but ALL cognitive jobs at once</p></li><li><p><strong>Slicing by ability</strong> &#8212; AI replaces people based on cognitive ability, not profession</p></li><li><p><strong>Gap-filling</strong> &#8212; AI companies actively train on weaknesses; every gap gets closed</p></li></ol><p>The terrifying implication:</p><blockquote><blockquote><p>&#8220;We are at risk of a situation where... AI is affecting people with certain intrinsic cognitive properties, namely lower intellectual ability (which is harder to change). I am concerned that they could form an unemployed or very-low-wage &#8216;underclass.&#8217;&#8221;</p></blockquote></blockquote><div><hr></div><h3><strong>5. Indirect Effects (Everything Else)</strong></h3><p>The world will change fast. Rapid change is destabilizing. We don&#8217;t know what we don&#8217;t know.</p><div><hr></div><h2><strong>What He Thinks We Should Do</strong></h2><p>Amodei isn&#8217;t a doomer. He thinks we can navigate this. His prescriptions:</p><p><strong>For AI Companies:</strong></p><ul><li><p>Constitutional AI &#8212; Training models with values, not just rules</p></li><li><p>Mechanistic interpretability &#8212; Looking inside models to understand them</p></li><li><p>Transparency &#8212; Publishing problems, sharing system cards</p></li><li><p>Safeguards &#8212; Even expensive ones (like the 5% cost for bio classifiers)</p></li></ul><p><strong>For Governments:</strong></p><ul><li><p>Start with transparency legislation (California SB 53, New York RAISE Act)</p></li><li><p>Draw hard lines against domestic surveillance and propaganda</p></li><li><p>Use AI to defend democracy, but with limits</p></li><li><p>Create international taboos against AI-enabled totalitarianism</p></li></ul><p><strong>For Everyone:</strong></p><ul><li><p>Wake up. This isn&#8217;t science fiction anymore.</p></li><li><p>The risks are real but not inevitable</p></li><li><p>We have maybe a few years to get this right</p></li></ul><div><hr></div><h2><strong>What Struck Me Most</strong></h2><p>Three things:</p><p><strong>1. The honesty about uncertainty</strong></p><ul><li><p>He admits he could be wrong. AI might not advance this fast. These risks might not materialize. But he&#8217;s planning for the scenario where they do, because the downside is catastrophic.</p></li></ul><p><strong>2. The speed of the feedback loop</strong></p><ul><li><p>AI is already writing most of the code at Anthropic. The technology is accelerating its own development. We&#8217;re maybe 1-2 years from AI autonomously building the next generation of AI.</p></li></ul><p><strong>3. The economic warning is undersold</strong></p><p>Everyone focuses on the sci-fi risks. But the economic disruption section is the most likely to affect you personally. Half of entry-level white collar jobs in 1-5 years. That&#8217;s not distant future &#8212; that&#8217;s happening now.</p><div><hr></div><h2><strong>The Bottom Line</strong></h2><p>Dario Amodei isn&#8217;t a pessimist or an optimist. He&#8217;s an engineer looking at the trajectory and saying: this is coming, it&#8217;s serious, and we need to act.</p><p>The essay ends with the question from Contact: &#8220;How did you survive this technological adolescence without destroying yourself?&#8221;</p><p>We&#8217;re about to find out.</p><div><hr></div><p><em>Read the full essay: <a href="https://www.darioamodei.com/essay/the-adolescence-of-technology">The Adolescence of Technology</a></em></p><div><hr></div><p><strong>What do you think?</strong> Is Amodei right about the timeline? The risks? Drop your thoughts below.</p>]]></content:encoded></item><item><title><![CDATA[Decision Table Testing]]></title><description><![CDATA[Handling Complex Business Logic]]></description><link>https://ryancraventech.substack.com/p/decision-table-testing</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/decision-table-testing</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Wed, 04 Mar 2026 22:48:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!u4va!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The requirements document said: <em>Premium members get free shipping on orders over $50. Standard members get free shipping on orders over $75. Non-members never get free shipping, unless they have a promotional code. Promotional codes apply to all member tiers but do not stack with loyalty discounts. Loyalty discounts apply automatically to premium members with more than 12 months of membership.</em></p><p>The developer read it three times. Built something. Tested it with a premium member, a $60 order, no promo code. Worked fine.</p><p>The tester ran through it with a few scenarios. Non-member with promo code &#8212; worked. Standard member, $80 order &#8212; free shipping applied. Good enough.</p><p>Six weeks after launch, a customer service report came in: standard members with promotional codes on orders between $50-$74 were getting free shipping. The condition for promotional codes overrode the standard member threshold without anyone realizing it was even a combination worth testing.</p><p>Nobody had drawn the table.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><p>When business logic involves multiple conditions that interact with each other, the combinations multiply faster than intuition can track. Two conditions with two states each gives you four combinations. Three conditions gives you eight. Four conditions: sixteen. Five: thirty-two. At some point, the human brain stops being able to hold all of it at once &#8212; and that&#8217;s exactly where the bugs hide.</p><p>Decision table testing is the technique for this problem. It forces you to enumerate every meaningful combination of conditions and specify the expected outcome for each one. The table becomes your map of the logic space. If you&#8217;ve covered every column, you&#8217;ve tested every case. If the system doesn&#8217;t match the table, you&#8217;ve found a bug. If the table doesn&#8217;t match the requirements, you&#8217;ve found a requirements gap before a line of code was written.</p><p>This article builds directly on the equivalence partitioning and boundary value analysis techniques from our previous two articles. Where those techniques dealt with <em>what values</em> to use as inputs, decision tables address a different question: <em>which combinations of conditions</em> need to be tested. They&#8217;re complementary &#8212; in a thorough test suite, you&#8217;ll use both.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u4va!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u4va!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!u4va!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!u4va!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!u4va!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u4va!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!u4va!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!u4va!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!u4va!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!u4va!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ce06d1-5962-4bc7-a559-877f838626fa_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What a Decision Table Actually Is</strong></h2><p>The structure is simple even when the logic isn&#8217;t. A decision table has four regions:</p><p><strong>Conditions</strong> occupy the top rows &#8212; these are the inputs or factors that influence the outcome. Each condition can take different states: yes/no, true/false, tier A/B/C, above/below threshold.</p><p><strong>Actions</strong> occupy the bottom rows &#8212; these are the outcomes or behaviors that result from each combination of conditions.</p><p><strong>Condition entries</strong> fill in the body of the upper section. Each column represents one combination of condition states.</p><p><strong>Action entries</strong> complete the lower section &#8212; for each combination of conditions, what should happen?</p><p>Here&#8217;s the shipping logic from our opening, formalized. Notice that the original two-state &#8220;Premium member: Y/N&#8221; has been corrected to three tiers &#8212; collapsing Standard and Non-member into a single &#8220;N&#8221; was what created the original bug, because those two groups behave differently when no promo code is present. The &#8220;Order over tier threshold&#8221; condition uses a dash for non-members because they never qualify for threshold-based free shipping regardless of order size &#8212; only a promo code changes their outcome.</p><pre><code>&#9556;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9574;&#9552;&#9552;&#9559;
&#9553; CONDITIONS                     &#9553; 1&#9553; 2&#9553; 3&#9553; 4&#9553; 5&#9553; 6&#9553; 7&#9553; 8&#9553; 9&#9553;10&#9553;11&#9553;12&#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9571;
&#9553; Member tier (P/S/N)            &#9553; P&#9553; P&#9553; P&#9553; P&#9553; S&#9553; S&#9553; S&#9553; S&#9553; N&#9553; N&#9553; N&#9553; N&#9553;
&#9553; Order over tier threshold?     &#9553; Y&#9553; Y&#9553; N&#9553; N&#9553; Y&#9553; Y&#9553; N&#9553; N&#9553; -&#9553; -&#9553; -&#9553; -&#9553;
&#9553; Promotional code present?      &#9553; Y&#9553; N&#9553; Y&#9553; N&#9553; Y&#9553; N&#9553; Y&#9553; N&#9553; Y&#9553; N&#9553; Y&#9553; N&#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9571;
&#9553; ACTIONS                        &#9553;  &#9553;  &#9553;  &#9553;  &#9553;  &#9553;  &#9553;  &#9553;  &#9553;  &#9553;  &#9553;  &#9553;  &#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9580;&#9552;&#9552;&#9571;
&#9553; Apply free shipping            &#9553; Y&#9553; Y&#9553; Y&#9553; N&#9553; Y&#9553; Y&#9553; Y&#9553; N&#9553; Y&#9553; N&#9553; Y&#9553; N&#9553;
&#9553; Apply loyalty discount check   &#9553; Y&#9553; Y&#9553; N&#9553; N&#9553; N&#9553; N&#9553; N&#9553; N&#9553; N&#9553; N&#9553; N&#9553; N&#9553;
&#9562;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9577;&#9552;&#9552;&#9565;</code></pre><p>A few things worth noting in this table:</p><p>Columns 9 and 11 (non-member, with promo code) both result in free shipping regardless of order size &#8212; which is why the threshold condition is a don&#8217;t-care for non-members. The promo code is the only path to free shipping for them, and it applies unconditionally.</p><p>Columns 10 and 12 (non-member, no promo code) never get free shipping &#8212; again, order size is irrelevant.</p><p>Loyalty discount check only applies to premium members who qualify by tenure, so it only appears in columns 1&#8211;4. Even then, columns 3 and 4 (premium, below threshold) require a promo code or no discount scenario where the loyalty check is still needed for column 3 &#8212; worth flagging to the product team whether a promo code and loyalty discount can coexist.</p><p>That last point is a requirements gap this table just surfaced. Column 1: premium member, over threshold, promo code present, loyalty discount eligible. Do they stack? The spec says they don&#8217;t &#8212; but what actually happens? Does the loyalty discount take precedence? Does the promo code? The developer will have to decide, and whatever they decide becomes undocumented behavior.</p><h2><strong>Building the Table Step by Step</strong></h2><p><strong>Step 1: Identify the conditions.</strong> List every independent factor that influences the outcome. &#8220;Independent&#8221; matters here &#8212; if knowing one condition&#8217;s value tells you another condition&#8217;s value, they may need to be restructured. For our insurance premium example: age bracket (Under 25 / 25&#8211;65 / Over 65), driving record (Clean / Minor violations / Major violations), and vehicle type (Standard / Luxury / Commercial).</p><p><strong>Step 2: Calculate maximum combinations.</strong> With three conditions at 3, 3, and 3 states respectively, the theoretical maximum is 3 &#215; 3 &#215; 3 = 27 combinations. This is your starting point, not your final table.</p><p><strong>Step 3: Eliminate impossible combinations.</strong> Some columns represent states that can&#8217;t co-occur. A commercial vehicle policy for a driver under 25 may be rejected outright under the insurer&#8217;s underwriting rules &#8212; it&#8217;s not a valid scenario, so testing it is meaningless. Remove those columns and document why.</p><p><strong>Step 4: Consolidate equivalent combinations.</strong> Where multiple combinations produce the same outcome for the same reasons, they can be merged using &#8220;don&#8217;t care&#8221; notation (written as <code>-</code>). A clean driving record with a standard vehicle produces the base rate regardless of age bracket &#8212; those three columns become one.</p><p><strong>Step 5: Verify the table against requirements.</strong> Walk each column against the spec. Every column should trace to at least one requirement. Any column you can&#8217;t trace is either an implicit requirement that needs to be made explicit, or a combination the spec doesn&#8217;t address &#8212; which means the developer will be guessing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EVKZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EVKZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EVKZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EVKZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EVKZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EVKZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!EVKZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EVKZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EVKZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EVKZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e39795-acd5-460d-9bb3-955638d8180b_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Don&#8217;t Care Notation</strong></h2><p>When a condition&#8217;s value doesn&#8217;t affect the outcome for a given column, &#8220;don&#8217;t care&#8221; notation (typically <code>-</code>) signals that it can be any valid state. This is what enables table consolidation &#8212; but applying it incorrectly creates hidden coverage gaps, so it needs to be used deliberately.</p><p>The ATM withdrawal flow is a good example, because it also illustrates how real-world business rules add nuance. Most ATMs allow up to three PIN attempts before retaining the card as a fraud prevention measure. After a third failed attempt, the card is kept. After one or two failed attempts, the card is returned so the customer can try again. Insufficient balance is a different matter entirely &#8212; the customer authenticated successfully, so the machine has no reason to keep their card. They just can&#8217;t withdraw that amount.</p><pre><code>&#9556;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9559;
&#9553; CONDITIONS                           &#9553; 1 &#9553; 2 &#9553; 3 &#9553; 4 &#9553; 5 &#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9571;
&#9553; Card valid?                          &#9553; N &#9553; Y &#9553; Y &#9553; Y &#9553; Y &#9553;
&#9553; PIN correct?                         &#9553; - &#9553; N &#9553; N &#9553; Y &#9553; Y &#9553;
&#9553; 3rd failed PIN attempt?              &#9553; - &#9553; N &#9553; Y &#9553; - &#9553; - &#9553;
&#9553; Sufficient balance?                  &#9553; - &#9553; - &#9553; - &#9553; N &#9553; Y &#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9571;
&#9553; ACTIONS                              &#9553;   &#9553;   &#9553;   &#9553;   &#9553;   &#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9571;
&#9553; Dispense cash                        &#9553; N &#9553; N &#9553; N &#9553; N &#9553; Y &#9553;
&#9553; Show error message                   &#9553; Y &#9553; Y &#9553; Y &#9553; Y &#9553; N &#9553;
&#9553; Return card to customer              &#9553; Y &#9553; Y &#9553; N &#9553; Y &#9553; Y &#9553;
&#9553; Retain card (fraud prevention)       &#9553; N &#9553; N &#9553; Y &#9553; N &#9553; N &#9553;
&#9562;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9565;</code></pre><p>Walk through each column:</p><p><strong>Column 1 &#8212; Invalid card:</strong> The machine can&#8217;t validate a PIN or check a balance for a card it doesn&#8217;t recognize. All three downstream conditions are don&#8217;t-cares. The card is returned (it belongs to someone, even if it&#8217;s not valid for this machine), and an error is shown.</p><p><strong>Column 2 &#8212; Valid card, wrong PIN, not the third attempt:</strong> Error shown, card returned. The customer still has attempts remaining.</p><p><strong>Column 3 &#8212; Valid card, wrong PIN, third failed attempt:</strong> Card retained as fraud prevention. Error shown. Balance is a don&#8217;t-care &#8212; you never reach balance checking when authentication fails.</p><p><strong>Column 4 &#8212; Valid card, correct PIN, insufficient balance:</strong> Error shown, card returned. Authentication succeeded; the customer just can&#8217;t withdraw that specific amount. Retaining the card here would be wrong &#8212; they did nothing to trigger fraud prevention.</p><p><strong>Column 5 &#8212; Full success path:</strong> Cash dispensed, card returned, no error.</p><p>The &#8220;3rd failed PIN attempt&#8221; condition is what makes this table honest. Without it, you&#8217;d have a simplified table that implies the ATM always returns the card on a wrong PIN &#8212; which isn&#8217;t how real ATMs work, and would miss the fraud prevention test case entirely.</p><p>This is a pattern worth internalizing: when a table seems too simple, it often means a real-world nuance hasn&#8217;t been captured as a condition yet.</p><h2><strong>When Decision Tables Find Requirements Problems</strong></h2><p>The most valuable moment in building a decision table often isn&#8217;t when you run the tests. It&#8217;s when you&#8217;re filling in the action rows and realize you don&#8217;t know what the expected outcome should be.</p><p>A product manager specifying a promotional discount system: loyalty members get 15% off, newsletter subscribers get 10% off, first-time buyers get 5% off. You start building the table. Column 4: loyalty member who is also a newsletter subscriber and is making their first purchase. What&#8217;s the discount?</p><p>The specification doesn&#8217;t say. Does the system stack discounts (30%)? Apply only the highest (15%)? Apply only the first applicable rule (depends on evaluation order in code)? The product manager assumed this combination was rare enough not to matter. It will happen regularly. First-time buyers frequently subscribe to newsletters before purchasing, and if they&#8217;ve been loyalty members from a previous account or a merged program, all three apply simultaneously.</p><p>The decision table surfaces this gap before a line of code is written &#8212; before a developer makes an assumption that becomes undocumented behavior, before a customer calls to ask why their expected discount wasn&#8217;t applied, before an A/B test produces inexplicable results because the discount logic isn&#8217;t consistent across user segments.</p><p>Build the table. Fill in every action cell. The blanks tell you where the requirements are incomplete.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U8r6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U8r6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!U8r6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!U8r6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!U8r6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U8r6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!U8r6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!U8r6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!U8r6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!U8r6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d707370-5146-4697-9839-e19faf8c5be8_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Deriving Test Cases from the Table</strong></h2><p>Each column in a decision table is one test case. The conditions in that column define your inputs; the actions define your expected results. The mapping is direct.</p><p>For the ATM table:</p><p><strong>Test Case 1 &#8212; Invalid Card</strong></p><ul><li><p>Setup: Obtain an expired or cancelled card</p></li><li><p>Input: Insert card, attempt to proceed</p></li><li><p>Expected: Error message displayed, card returned, no cash dispensed, card not retained</p></li></ul><p><strong>Test Case 2 &#8212; Valid Card, Wrong PIN (1st or 2nd attempt)</strong></p><ul><li><p>Setup: Valid card with known PIN</p></li><li><p>Input: Insert card, enter incorrect PIN</p></li><li><p>Expected: Error message displayed, card returned, another attempt offered</p></li></ul><p><strong>Test Case 3 &#8212; Valid Card, Wrong PIN (3rd attempt)</strong></p><ul><li><p>Setup: Valid card, two prior failed attempts already recorded (or use a test account configured for this state)</p></li><li><p>Input: Insert card, enter incorrect PIN for the third time</p></li><li><p>Expected: Error message displayed, card retained by machine, no further attempts offered</p></li></ul><p><strong>Test Case 4 &#8212; Valid Card, Correct PIN, Insufficient Balance</strong></p><ul><li><p>Setup: Valid card, known correct PIN, account balance of $20</p></li><li><p>Input: Insert card, enter correct PIN, request $100 withdrawal</p></li><li><p>Expected: Error message displayed, card returned to customer, no cash dispensed</p></li></ul><p><strong>Test Case 5 &#8212; Full Success Path</strong></p><ul><li><p>Setup: Valid card, known correct PIN, account balance of $200</p></li><li><p>Input: Insert card, enter correct PIN, request $100 withdrawal</p></li><li><p>Expected: $100 dispensed, card returned, balance updated to $100</p></li></ul><p>Notice that test case 3 requires some thought about setup &#8212; you need an account in a specific state (two prior failed attempts within the lockout window). This is worth flagging: decision tables tell you what to test, but getting the system into the right state to test it is a separate challenge that belongs in your test setup documentation.</p><h2><strong>Handling Tables That Get Too Large</strong></h2><p>When conditions multiply, tables grow exponentially. A system with six binary conditions has a theoretical maximum of 64 columns. Six conditions with three states each: 729. At that scale, exhaustive decision tables become impractical &#8212; not because the technique fails, but because the problem has become too large for any single technique to handle alone.</p><p><strong>Decompose the logic.</strong> Complex systems often contain nested decisions. The outer layer determines which rule set applies; the inner layers contain the rules themselves. Build separate tables for each layer. A payment processing system might have one table for &#8220;which payment path applies&#8221; and separate tables for each path&#8217;s validation logic. Each table stays manageable; together they cover the full system.</p><p><strong>Risk-stratify the columns.</strong> Not every combination carries equal business risk. Identify which combinations involve high-value transactions, sensitive data, or states that are difficult to recover from &#8212; and prioritize those columns for testing. Lower-risk combinations can receive reduced coverage or be handled by other techniques.</p><p><strong>Use pairwise testing for the remainder.</strong> Once high-risk combinations are explicitly covered, pairwise testing &#8212; covering every combination of any two conditions at least once &#8212; provides reasonable coverage of the remaining combinations without full enumeration. We&#8217;ll cover pairwise testing in its own dedicated article; for now, it&#8217;s worth knowing it exists as a complement to decision tables, not a replacement.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DxpK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DxpK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DxpK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DxpK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DxpK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DxpK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!DxpK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DxpK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DxpK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DxpK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52768662-f66e-4449-bdcf-fc41238f2c4d_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Decision Tables in the Age of AI-Generated Code</strong></h2><p>AI code generators are good at implementing straightforward logic. Give one a simple if-else requirement and it produces clean, functional code. But complex conditional logic with multiple interacting conditions is where the gaps appear. The AI implements what it can confidently infer from the requirement &#8212; usually the obvious cases. Multi-condition intersections, don&#8217;t-care nuances, and the combinations that only appear when you enumerate systematically are precisely what it&#8217;s most likely to handle inconsistently.</p><p>A development team recently used an AI assistant to implement eligibility logic for insurance claims &#8212; similar complexity to the examples in this article. The AI produced code that passed 80% of manually-written test cases. The 20% it missed were all multi-condition combinations: intersections between eligibility criteria that had been implemented in separate code branches without considering their interaction.</p><p>The decision table had been built before the AI was asked to write the code. Test cases were ready before the first line was generated. Gaps were visible immediately rather than discovered by end users.</p><p>This is the right workflow: specify completely (which building a decision table forces you to do), generate code, verify systematically (which the table&#8217;s test cases enable). Trusting AI-generated conditional logic without systematic verification is how multi-condition bugs survive to production.</p><h2><strong>What a Bad Table Looks Like</strong></h2><p>Most teams who try decision tables for the first time produce something that looks correct but isn&#8217;t. Here&#8217;s a real pattern &#8212; a table built for the same password reset feature we&#8217;ve been working with, submitted by a junior tester who thought they&#8217;d covered it.</p><p>The spec: <em>If the account is active and email matches, send a reset link. If the account is locked, direct to support. If the email isn&#8217;t recognized, show a generic message for security reasons.</em></p><p><strong>The table they submitted:</strong></p><pre><code>&#9556;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9559;
&#9553; CONDITIONS                   &#9553; 1 &#9553; 2 &#9553; 3 &#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9571;
&#9553; Account active?              &#9553; Y &#9553; N &#9553; N &#9553;
&#9553; Email matches?               &#9553; Y &#9553; Y &#9553; N &#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9571;
&#9553; Send reset link              &#9553; Y &#9553; N &#9553; N &#9553;
&#9553; Show contact-support message &#9553; N &#9553; Y &#9553; N &#9553;
&#9553; Show generic message         &#9553; N &#9553; N &#9553; Y &#9553;
&#9562;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9565;</code></pre><p>Three columns. Looks clean. Has a column for each action. Most reviewers would sign off on this.</p><p>It has four problems.</p><p><strong>Problem 1: &#8220;Account active: N&#8221; is doing double duty.</strong> The spec describes two distinct non-active states &#8212; locked accounts and non-existent accounts &#8212; and they produce different outcomes. Locked accounts go to support. Non-existent accounts get the generic message. Collapsing both into a single &#8220;N&#8221; means you&#8217;ve got a condition that doesn&#8217;t actually map to a single behavior. This is the same mistake we saw in the original shipping logic table, and it produces the same result: a combination that looks covered but isn&#8217;t.</p><p><strong>Problem 2: Column 2 is wrong.</strong> Account not active, email matches, show contact-support message. But if the account doesn&#8217;t exist, the email can&#8217;t match anything. And if the account is locked, should the system confirm its existence to someone who got the email right? That&#8217;s a security decision that belongs in the spec, not the code. The tester assumed an answer rather than surfacing the question.</p><p><strong>Problem 3: A whole column is missing.</strong> Active account, email doesn&#8217;t match. What happens? A user types in the wrong email address for an account they own, or guesses an address that belongs to someone else. The spec&#8217;s &#8220;generic message for security reasons&#8221; applies here &#8212; but this combination doesn&#8217;t appear anywhere in the table.</p><p><strong>Problem 4: The conditions are underspecified.</strong> Two binary conditions (active Y/N, email matches Y/N) gives a theoretical maximum of four columns. The tester produced three, which means either one combination was eliminated intentionally (it wasn&#8217;t &#8212; there&#8217;s no documentation of why) or it was simply missed.</p><p><strong>Here&#8217;s the corrected table:</strong></p><pre><code>&#9556;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9574;&#9552;&#9552;&#9552;&#9559;
&#9553; CONDITIONS                   &#9553; 1 &#9553; 2 &#9553; 3 &#9553; 4 &#9553; 5 &#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9571;
&#9553; Account status (A/L/X)       &#9553; A &#9553; A &#9553; L &#9553; L &#9553; X &#9553;
&#9553; Email matches?               &#9553; Y &#9553; N &#9553; Y &#9553; N &#9553; - &#9553;
&#9568;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9580;&#9552;&#9552;&#9552;&#9571;
&#9553; Send reset link              &#9553; Y &#9553; N &#9553; N &#9553; N &#9553; N &#9553;
&#9553; Show contact-support message &#9553; N &#9553; N &#9553; Y &#9553; ? &#9553; N &#9553;
&#9553; Show generic message         &#9553; N &#9553; Y &#9553; N &#9553; ? &#9553; Y &#9553;
&#9562;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9577;&#9552;&#9552;&#9552;&#9565;
A = Active, L = Locked, X = Non-existent
- = Don&#8217;t care (non-existent accounts have no email to match)
? = Requirements gap &#8212; spec does not define this behavior</code></pre><p>Five columns. Account status split into three explicit states. The don&#8217;t-care on column 5 is documented with a reason. Column 4 &#8212; locked account, wrong email &#8212; is marked with question marks and flagged for the product team: does confirming a locked account to someone with the wrong email create a security exposure? That&#8217;s not a testing question. It&#8217;s a product decision that the table made visible.</p><p>The difference between the two tables isn&#8217;t effort. The junior tester wasn&#8217;t being lazy &#8212; they thought carefully about three scenarios and wrote them down correctly. The difference is understanding that a decision table isn&#8217;t a list of test scenarios dressed up in a grid. It&#8217;s a complete enumeration of the logic space. Every condition needs distinct states, every combination needs a column, every blank action cell needs a resolution. When those rules aren&#8217;t followed, the table creates an illusion of coverage while leaving real gaps untested.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GlNK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GlNK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GlNK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GlNK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GlNK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GlNK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!GlNK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GlNK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GlNK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GlNK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c7bc644-34c7-4386-9a78-19ae75c0b3f4_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Difference Between Coverage and Confidence</strong></h2><p>A lot of testing suffers from a particular kind of false confidence: the feeling that because you tested, you covered. You ran the happy path. You checked a few error conditions. Everything worked when you tried it, so the feature must be good.</p><p>Decision table testing replaces that feeling with something more reliable: demonstrable coverage. When you&#8217;ve built the table, eliminated impossibilities, merged equivalents, and derived a test case from every remaining column, you know the coverage is complete. Not because it felt thorough &#8212; because the table shows it. Anyone can look at the table and see which combinations were tested and which weren&#8217;t. When a bug surfaces in production, you can trace it back: was this combination in the table? Was it incorrectly marked as don&#8217;t-care? Was it a gap in the original conditions?</p><p>That accountability improves testing quality over time in a way that ad-hoc coverage never will.</p><p>Boundary value analysis tells you where to probe at the edges. Equivalence partitioning tells you how to group inputs sensibly. Decision tables tell you which combinations of conditions must be covered. All three working together &#8212; that&#8217;s a test suite that can genuinely be called systematic.</p><p>In our next article, we&#8217;ll explore <strong>State Transition Testing</strong> &#8212; the technique for software that changes behavior based on its current state. When the same input produces different outputs depending on what happened before, decision tables aren&#8217;t enough. You need to map the states.</p><p><strong>Remember:</strong> The blank cell in your decision table is a requirements gap. Find it during planning, and it costs you five minutes. Find it in production, and it costs you weeks.</p>]]></content:encoded></item><item><title><![CDATA[Inside OpenClaw: How Your AI Assistant Actually Works]]></title><description><![CDATA[A deep dive into the architecture that powers always-on AI agents.]]></description><link>https://ryancraventech.substack.com/p/inside-openclaw-how-your-ai-assistant</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/inside-openclaw-how-your-ai-assistant</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Tue, 03 Mar 2026 23:16:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QCLg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QCLg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QCLg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QCLg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QCLg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QCLg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QCLg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2113592,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ainsightsco.substack.com/i/187665947?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!QCLg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QCLg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QCLg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QCLg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34e0173b-3b23-4d41-95e6-9d7042a4ef19_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most people interact with AI through a chat window. Type a message, get a response, repeat. But what happens when you want AI that actually <em>does</em> things? That runs on your machine, controls your browser, remembers your preferences, and works while you sleep?</p><p>That&#8217;s what OpenClaw does. And understanding how it works makes you better at using it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h3><strong>What OpenClaw Actually Is</strong></h3><p>Forget the marketing. At its core, OpenClaw is a TypeScript command-line application. Not a web app. Not a Python script. It&#8217;s a process running on your machine that:</p><ul><li><p>Exposes a gateway server for messaging platforms (Telegram, WhatsApp, Discord, Signal)</p></li><li><p>Makes API calls to language models (Anthropic, OpenAI, local models)</p></li><li><p>Executes tools directly on your computer</p></li><li><p>Persists memory between sessions</p></li></ul><p>Think of it as the operating system layer between you and your AI.</p><div><hr></div><h3><strong>The Request Pipeline</strong></h3><p>Here&#8217;s what happens when you send a message:</p><h3><strong>1. Channel Adapter</strong></h3><p>Your message arrives through whatever platform you&#8217;re using. Each platform has its own adapter that normalizes the input&#8212;extracting text, attachments, and metadata into a consistent format.</p><h3><strong>2. Gateway Server</strong></h3><p>This is the brain. The gateway coordinates sessions, routes messages, and manages concurrent operations.</p><p>Here&#8217;s where it gets interesting: OpenClaw uses a <strong>lane-based command queue</strong> instead of typical async/await patterns. Each session gets its own dedicated lane. Operations execute serially by default.</p><p>Why does this matter? Anyone who&#8217;s built AI agents knows the nightmare of parallel execution. Interleaved logs. Race conditions. Shared state corruption. OpenClaw&#8217;s approach flips the mental model: instead of asking &#8220;what do I need to lock?&#8221; you ask &#8220;what&#8217;s safe to parallelize?&#8221;</p><p>Serial by default. Parallel only when explicitly chosen.</p><h3><strong>3. Agent Runner</strong></h3><p>This layer handles model selection, API key rotation, and fallback logic. If your primary model fails or hits rate limits, it automatically tries alternatives.</p><p>The agent runner also assembles the system prompt dynamically&#8212;injecting available tools, loaded skills, memory context, and session history. Before sending to the model, it checks context window limits and compacts if necessary.</p><h3><strong>4. The Agentic Loop</strong></h3><p>When the model returns a tool call, OpenClaw executes it locally and feeds results back. This continues until the model produces final text or hits the turn limit (default: ~20 iterations).</p><p>This loop is where the real power lives. The AI isn&#8217;t just responding&#8212;it&#8217;s <em>doing</em>.</p><h3><strong>5. Response Path</strong></h3><p>Results flow back through the channel adapter to your messaging platform. Sessions persist as JSONL files&#8212;each line containing messages, tool calls, and responses.</p><div><hr></div><h3><strong>Memory: Simpler Than You&#8217;d Think</strong></h3><p>Without memory, an AI assistant has the context of a goldfish. OpenClaw handles this through two mechanisms:</p><p><strong>Session Transcripts:</strong> JSONL files storing complete conversation history.</p><p><strong>Memory Files:</strong> Markdown files in MEMORY.md or memory/ folders that the agent reads and writes using standard file tools.</p><p>For retrieval, OpenClaw uses hybrid search&#8212;combining vector embeddings (semantic) with keyword matching (exact). Search for &#8220;authentication bug&#8221; and you&#8217;ll find documents mentioning &#8220;auth issues&#8221; <em>and</em> the exact phrase.</p><p>The implementation is deliberately simple. No complex memory merging. No decay algorithms. No weekly compressions. The agent writes markdown files. The system indexes them. Old memories carry equal weight.</p><p>This simplicity is a feature. Explainable beats clever.</p><div><hr></div><h3><strong>Computer Use: How It Controls Your Machine</strong></h3><p>This is the capability that separates OpenClaw from chatbots. You give it access to your computer, and it uses it.</p><p><strong>Shell Execution:</strong> Commands run in sandboxed Docker containers by default, with options for direct host access or remote devices.</p><p><strong>File Operations:</strong> Read, write, and surgical edits to files.</p><p><strong>Browser Automation:</strong> Playwright-based control with semantic snapshots (more on this below).</p><p><strong>Process Management:</strong> Background tasks, long-running commands, process lifecycle control.</p><h3><strong>The Safety Model</strong></h3><p>OpenClaw uses an allowlist system similar to Claude Code. Commands prompt for approval (allow once, always allow, deny). Safe operations like grep, cat, and jq are pre-approved. Dangerous patterns&#8212;command substitution, redirects to system files, destructive chains&#8212;get blocked before execution.</p><p>The philosophy: maximum autonomy within user-defined boundaries.</p><div><hr></div><h3><strong>Browser Snapshots: Why Text Beats Screenshots</strong></h3><p>Most AI browser tools rely on screenshots. OpenClaw takes a different approach: <strong>semantic snapshots</strong>.</p><p>Instead of a 5MB image, the agent sees a text representation of the page&#8217;s accessibility tree:</p><pre><code><code>- button "Sign In" [ref=1]
- textbox "Email" [ref=2]
- textbox "Password" [ref=3]
- link "Forgot password?" [ref=4]
- heading "Welcome back" </code></code></pre><p>The advantages are significant:</p><ol><li><p><strong>Token efficiency:</strong> 50KB of text vs 5MB images</p></li><li><p><strong>Precision:</strong> Direct element references for actions</p></li><li><p><strong>Speed:</strong> No image processing overhead</p></li><li><p><strong>Reliability:</strong> ARIA trees are more stable than pixel layouts</p></li></ol><p>Browsing isn&#8217;t inherently visual. The semantic approach treats it as structured interaction, which is what it actually is.</p><div><hr></div><h3><strong>What This Means For You</strong></h3><p>Understanding OpenClaw&#8217;s architecture reveals its strengths and limitations:</p><p><strong>Good at:</strong></p><ul><li><p>Persistent, context-aware assistance</p></li><li><p>Multi-step workflows with tool use</p></li><li><p>Background automation</p></li><li><p>Cross-platform availability</p></li></ul><p><strong>Less suited for:</strong></p><ul><li><p>Tasks requiring real-time visual judgment</p></li><li><p>Operations needing sub-second latency</p></li><li><p>Workflows that genuinely require parallelism</p></li></ul><p>The more you understand the system, the better you can design workflows that play to its strengths.</p>]]></content:encoded></item><item><title><![CDATA[Fuzz Testing Fundamentals: Breaking Software Through Malformed Input]]></title><description><![CDATA[The Input Nobody Expected]]></description><link>https://ryancraventech.substack.com/p/fuzz-testing-fundamentals-breaking</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/fuzz-testing-fundamentals-breaking</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Tue, 24 Feb 2026 12:25:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!O2pk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In 1988, a professor at the University of Wisconsin named Barton Miller was working remotely over a dial-up connection during a thunderstorm. The electrical interference on the line was injecting garbage characters into his terminal commands. To his surprise, those garbage characters were crashing the Unix utilities he was running &#8212; programs that had been considered stable for years.</p><p>Most people would have cursed the weather and moved on. Miller did something different. He turned the accident into an experiment. He wrote a program that deliberately fed random strings of characters into common Unix command-line utilities and measured how many of them crashed. The results were alarming: between 25% and 33% of the utilities he tested crashed or hung when given unexpected input. These weren&#8217;t obscure research tools &#8212; they were the everyday programs that system administrators relied on.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Ryan's Tech Lab is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Miller called the technique &#8220;fuzz testing,&#8221; and the name stuck.</p><p>That was nearly four decades ago, and the fundamental problem hasn&#8217;t changed. Software still makes assumptions about its inputs &#8212; what format they&#8217;ll be in, how long they&#8217;ll be, what characters they&#8217;ll contain &#8212; and when reality violates those assumptions, things break. Sometimes they break quietly, producing wrong results. Sometimes they break loudly, crashing or freezing. And sometimes they break dangerously, exposing memory contents, allowing unauthorized access, or enabling an attacker to execute arbitrary code on the system.</p><p>In our previous article on monkey testing, we briefly compared the two techniques: monkey testing randomizes the entire interaction pattern &#8212; navigation, timing, sequences of actions &#8212; while fuzz testing focuses its attack on a system&#8217;s <em>inputs</em> specifically. That distinction is what makes fuzz testing worthy of its own deep dive. Where monkey testing asks &#8220;can this application survive chaotic usage?&#8221;, fuzz testing asks a sharper question: &#8220;what happens when every door, window, and ventilation shaft in this building receives something it was never designed to accept?&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O2pk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O2pk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!O2pk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!O2pk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!O2pk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O2pk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!O2pk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!O2pk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!O2pk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!O2pk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c898c67-ddde-40dc-8344-9988fb434eec_875x488.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Fuzz Testing Is (And What It Isn&#8217;t)</strong></h2><p>Fuzz testing &#8212; also called fuzzing &#8212; is the technique of providing invalid, unexpected, or random data to the inputs of a program and monitoring the system for crashes, failures, memory leaks, assertion violations, and other signs that the input was handled incorrectly.</p><p>The key word in that definition is <em>inputs</em>. Fuzz testing doesn&#8217;t randomly navigate your application or click buttons in random order &#8212; that&#8217;s monkey testing. Fuzz testing systematically identifies every point where data enters your system and then feeds each one a relentless stream of data designed to violate its assumptions.</p><p>Think of it this way. Your application has a contract with the outside world: &#8220;Send me a JSON object with a username string and a password string, and I&#8217;ll authenticate you.&#8221; Fuzz testing asks: What happens when I send you XML instead of JSON? What happens when the username is two million characters long? What happens when the password contains null bytes? What happens when I send a valid JSON structure but nest it 10,000 levels deep? What happens when I send nothing at all? What happens when I send this same request 50,000 times in one second?</p><p>The application&#8217;s contract describes what <em>should</em> happen. Fuzz testing discovers what <em>actually</em> happens when the contract is violated.</p><p>This is fundamentally different from functional testing, which validates that correct inputs produce correct outputs. Fuzz testing doesn&#8217;t care about correct outputs &#8212; it cares about incorrect <em>behavior</em>. The application might not know the right answer to a malformed request, and that&#8217;s fine. What matters is whether it handles that request safely: returning a clean error, logging the anomaly, and continuing to operate normally for legitimate users.</p><h2><strong>Why Fuzz Testing Matters Now More Than Ever</strong></h2><p>The traditional argument for fuzz testing has always centered on security: malformed inputs are how attackers probe for vulnerabilities, so testing with malformed inputs finds those vulnerabilities first. That argument hasn&#8217;t weakened &#8212; but several developments have made it stronger.</p><h2><strong>The API Surface Area Explosion</strong></h2><p>Modern applications aren&#8217;t monolithic programs with a single user interface. They&#8217;re networks of microservices, each exposing API endpoints that accept data from other services, mobile clients, third-party integrations, and sometimes the open internet. Each endpoint is an input. Each input is an attack surface. The number of places where malformed data can enter a modern system has grown exponentially compared to the applications Barton Miller was testing in 1988.</p><p>A typical microservice architecture might have hundreds of API endpoints. Fuzz testing each one &#8212; with payloads designed to violate its expected schema &#8212; is the only practical way to verify that all of them handle bad input gracefully. Manual review at that scale is impossible.</p><h2><strong>AI-Generated Code and Implicit Assumptions</strong></h2><p>When developers write input validation by hand, they at least consciously think about what inputs to accept and reject &#8212; even if they miss edge cases. When AI generates code, the input validation reflects patterns from training data rather than deliberate security decisions. The AI might produce validation that handles common cases well while completely ignoring unusual but dangerous inputs &#8212; because those inputs were underrepresented in the training data.</p><p>Fuzz testing is particularly effective at finding these implicit assumptions because it doesn&#8217;t share them. The fuzzer has no model of &#8220;normal&#8221; input. It generates data that is specifically designed to be abnormal, which is exactly what AI-generated validation is least prepared to handle.</p><h2><strong>The Speed of Modern Development</strong></h2><p>In continuous deployment environments where code ships multiple times per day, there isn&#8217;t time for manual security review of every input handler. Fuzz testing can be automated into the CI/CD pipeline, running against every build and catching input handling regressions before they reach production. It&#8217;s one of the few security testing approaches that can keep pace with modern release velocity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xfHq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xfHq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xfHq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xfHq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xfHq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xfHq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xfHq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xfHq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xfHq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xfHq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22173ec0-cfa7-496a-8bdf-f7c09c7e83cd_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Four Fuzzing Strategies</strong></h2><p>Not all fuzzing works the same way. The approach you choose determines what kinds of defects you&#8217;ll find and how quickly you&#8217;ll find them.</p><h2><strong>Dumb Fuzzing (Random Generation)</strong></h2><p>Dumb fuzzing generates completely random data and throws it at an input. No understanding of expected format, no awareness of protocol, just raw random bytes.</p><p><strong>Example:</strong> Your API endpoint expects a JSON payload like <code>{"email": "user@example.com", "age": 30}</code>. A dumb fuzzer sends: a stream of random ASCII characters, a 50-megabyte block of binary data, an empty request body, the byte sequence for a JPEG header followed by null characters. It has no idea the endpoint expects JSON&#8212;it&#8217;s just sending noise.</p><p><strong>Strengths:</strong> Zero setup time. Finds catastrophic failures where inputs lack even basic length checking or type validation. If random garbage crashes your system, you have fundamental problems.</p><p><strong>Weaknesses:</strong> Extremely inefficient. Most random data will be rejected by the first layer of input parsing, meaning the fuzzer never reaches deeper application logic. If your system validates that input is valid JSON before processing it, a dumb fuzzer will spend nearly all its time generating payloads that fail at the JSON parsing step.</p><h2><strong>Mutation-Based Fuzzing</strong></h2><p>Mutation-based fuzzing starts with valid inputs and makes small, targeted modifications. It takes something the system would normally accept and corrupts it in strategic ways.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6xRC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6xRC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png 424w, https://substackcdn.com/image/fetch/$s_!6xRC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png 848w, https://substackcdn.com/image/fetch/$s_!6xRC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png 1272w, https://substackcdn.com/image/fetch/$s_!6xRC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6xRC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png" width="908" height="319" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:319,&quot;width&quot;:908,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64181,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ryancraventech.substack.com/i/188194366?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6xRC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png 424w, https://substackcdn.com/image/fetch/$s_!6xRC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png 848w, https://substackcdn.com/image/fetch/$s_!6xRC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png 1272w, https://substackcdn.com/image/fetch/$s_!6xRC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6281e325-13f7-4eb0-a5ec-110dc85d8e48_908x319.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Strengths:</strong> Gets past initial parsing and format validation because the overall structure is correct. Finds deeper bugs in business logic and data processing. Much more efficient than dumb fuzzing because a higher percentage of inputs actually exercise meaningful code paths.</p><p><strong>Weaknesses:</strong> Only as good as its starting corpus. If your seed inputs don&#8217;t cover certain features or code paths, the mutations won&#8217;t reach them either.</p><h2><strong>Generation-Based Fuzzing</strong></h2><p>Generation-based fuzzing uses a specification or grammar to generate inputs that are structurally valid but contain malicious or boundary-case values. The fuzzer understands the format &#8212; it knows this field should be an email address, that field should be an integer, that header needs a specific authentication token &#8212; and generates inputs that conform to the structure while pushing the values to extremes.</p><p><strong>Example:</strong> The fuzzer knows the endpoint expects JSON with an email string and an integer age. So it generates: emails at the maximum length with every special character that&#8217;s technically valid in email addresses (<code>"very.unusual+tag@[IPv6:2001:db8::1]"</code>), ages at exact integer boundaries (2,147,483,647, 2,147,483,648, -2,147,483,648), valid JSON with additional unexpected fields, valid JSON with fields in unusual orders, and deeply nested but structurally valid JSON that stays within format rules while testing processing limits.</p><p><strong>Strengths:</strong> Highest efficiency &#8212; nearly every generated input exercises meaningful code because it passes format validation. Finds subtle bugs that require structurally valid but semantically extreme inputs. Can target specific vulnerability patterns (SQL injection, XSS, buffer overflows) by embedding known attack patterns within valid structures.</p><p><strong>Weaknesses:</strong> Requires significant upfront investment in defining the input specification. Building a comprehensive grammar for complex data formats takes time and expertise.</p><h2><strong>Coverage-Guided Fuzzing</strong></h2><p>Coverage-guided fuzzing &#8212; the most sophisticated approach &#8212; instruments the target code to track which execution paths each input triggers. The fuzzer observes which inputs reach new code branches and prioritizes mutations of those inputs, progressively exploring more of the program&#8217;s behavior.</p><p><strong>Example:</strong> The fuzzer sends a normal login request and observes it exercises 15 code branches. It mutates the email to contain a single quote and observes the input now exercises 18 code branches &#8212; three new branches in the SQL query construction code. The fuzzer recognizes this mutation as interesting and generates hundreds of variations on the single-quote theme, probing deeper into those SQL-related branches. It effectively evolves toward the most dangerous inputs by using code coverage as a fitness function.</p><p><strong>Strengths:</strong> Finds the deepest and most subtle bugs because it systematically explores code paths. Self-directing &#8212; it doesn&#8217;t need human guidance about where vulnerabilities might be. Proven track record of finding critical security vulnerabilities in major software projects.</p><p><strong>Weaknesses:</strong> Requires source code access or binary instrumentation. Computationally expensive. Setup is more complex than other approaches.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oC4o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oC4o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oC4o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oC4o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oC4o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oC4o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!oC4o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oC4o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oC4o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oC4o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcbebddb-7c04-4ef8-81b4-582a12c3581b_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What to Fuzz: Mapping Your Input Surface</strong></h2><p>Before you start fuzzing, you need to know what to fuzz. Every point where external data enters your system is a potential target &#8212; and most systems have more of these than their developers realize.</p><h2><strong>API Endpoints</strong></h2><p>The most obvious targets. Every endpoint that accepts data &#8212; query parameters, request bodies, headers, path parameters &#8212; is a fuzz target. Pay special attention to endpoints that accept complex data formats (JSON, XML, multipart form data) because the parsing of those formats is often where vulnerabilities hide.</p><p><strong>What to fuzz:</strong> Request bodies with malformed structure, oversized fields, missing required fields, additional unexpected fields, type mismatches (strings where numbers are expected), nested structures at extreme depths, and special characters in every string value.</p><h2><strong>File Upload and Processing</strong></h2><p>Any feature that accepts files &#8212; document uploads, image processing, CSV imports, configuration file loading &#8212; is a high-value fuzz target. File format parsers are historically one of the most vulnerability-dense categories of code because file formats are complex and parsing them correctly is genuinely difficult.</p><p><strong>What to fuzz:</strong> Files with corrupted headers, files that claim to be one type but contain another, files at extreme sizes (zero bytes, maximum allowed, just over maximum), files with malformed internal structures, and files with valid structure but malicious embedded content.</p><p><strong>Example in practice:</strong> A team fuzzing their CSV import feature discovered that a CSV file containing a field with 50,000 commas inside a quoted string caused the parser to allocate several gigabytes of memory and crash the service. The parser was correctly handling the quoting rules &#8212; the commas were inside quotes and shouldn&#8217;t be treated as delimiters &#8212; but nobody had considered what happens when a single quoted field is extraordinarily long. This is a class of bug that functional testing almost never catches because no test case uses a CSV with 50,000 commas in a single field.</p><h2><strong>Form Fields and User Input</strong></h2><p>Every text field, dropdown, date picker, and user-controllable parameter in your UI is a fuzz target. Even fields with client-side validation &#8212; because client-side validation can be bypassed by sending requests directly to the server.</p><p><strong>What to fuzz:</strong> Values that bypass client-side validation by going directly to the API, strings containing HTML and JavaScript (XSS testing), strings containing SQL fragments, Unicode edge cases (right-to-left markers, zero-width characters, emoji sequences), and extremely long values.</p><h2><strong>Message Queues and Event Streams</strong></h2><p>In event-driven architectures, services consume messages from queues and event streams. These messages are inputs too, and they&#8217;re often less thoroughly validated than HTTP requests because developers assume the messages come from trusted internal services.</p><p><strong>What to fuzz:</strong> Malformed message payloads, messages with missing or extra fields, messages with unexpected types or formats, messages arriving out of expected order, and duplicate messages.</p><h2><strong>Environment and Configuration</strong></h2><p>Configuration files, environment variables, command-line arguments, and database contents are all inputs to your system. A configuration value that contains unexpected characters, an environment variable set to an extremely long string, or a database record with corrupted data can all trigger failures in code that assumes these inputs are always clean.</p><p><strong>What to fuzz:</strong> Configuration values with special characters, missing configuration entries, configuration with conflicting values, and database records with values that violate application-level assumptions (even if they&#8217;re valid at the database level).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nLhX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nLhX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nLhX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nLhX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nLhX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nLhX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!nLhX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nLhX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nLhX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nLhX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37195a2c-619f-4372-bd26-b6f2c48a0174_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Building Your First Fuzzing Campaign</strong></h2><p>Theory becomes useful when it becomes practice. Here&#8217;s how to set up and run your first fuzzing effort.</p><h2><strong>Step 1: Choose Your Target</strong></h2><p>Start with the highest-risk input in your system. For most applications, this is the public-facing API &#8212; the endpoints that accept data from unauthenticated or partially authenticated users. These are the inputs that attackers will target first, so they should be your first fuzzing priority.</p><p>Pick one endpoint to start. Something with a moderate level of complexity &#8212; a login endpoint, a search function, or a data submission form. Don&#8217;t start with your most complex endpoint; learn the process on something manageable.</p><h2><strong>Step 2: Collect Valid Samples</strong></h2><p>Gather examples of valid inputs for your target. These become the seed corpus for mutation-based fuzzing. Sources include: existing test data, captured production traffic (sanitized of sensitive information), API documentation examples, and manually crafted samples that cover different valid input variations.</p><p><strong>Example:</strong> For a user registration endpoint, your seed corpus might include: a minimal valid registration (required fields only), a complete registration (all optional fields populated), registrations with international characters in name fields, registrations with various email formats, and registrations with boundary-length values.</p><h2><strong>Step 3: Choose Your Tooling</strong></h2><p>The right tool depends on what you&#8217;re fuzzing:</p><p><strong>For HTTP APIs:</strong> Burp Suite&#8217;s Intruder module is the industry standard for manual and semi-automated API fuzzing. For open-source alternatives, tools like RESTler (from Microsoft, designed specifically for REST API fuzzing) or Schemathesis (which generates fuzz cases from OpenAPI/Swagger specifications) provide automated approaches. Custom scripts using libraries like Hypothesis (Python) or fast-check (JavaScript) give you full control over the fuzzing logic.</p><p><strong>For file format parsing:</strong> AFL (American Fuzzy Lop) and its successor AFL++ are the gold standards for coverage-guided fuzzing of file parsers. LibFuzzer, integrated into LLVM, provides similar coverage-guided capability. These tools require source code access for instrumentation but find the deepest bugs.</p><p><strong>For protocol and network fuzzing:</strong> Peach Fuzzer and boofuzz handle complex protocol structures. They&#8217;re designed for fuzzing network protocols, binary formats, and other structured input that requires a formal specification.</p><p><strong>For general-purpose fuzzing from tests:</strong> Property-based testing libraries &#8212; Hypothesis for Python, fast-check for JavaScript, QuickCheck for Haskell, PropEr for Erlang &#8212; integrate fuzzing into your existing test suite. They generate random inputs constrained by properties you define and shrink failing cases to the minimal reproduction.</p><h2><strong>Step 4: Define Your Oracle</strong></h2><p>What counts as a failure? For fuzz testing, the answer is typically broader than &#8220;the application crashes&#8221;:</p><p><strong>Hard failures:</strong> Crashes, segmentation faults, unhandled exceptions, process termination. These are unambiguous &#8212; the system should never crash regardless of input.</p><p><strong>Security indicators:</strong> Stack traces in responses (information disclosure), responses that differ based on SQL injection payloads (potential SQL injection), excessively large responses from small inputs (potential denial of service), response timing differences that correlate with input content (potential timing side channels).</p><p><strong>Behavioral anomalies:</strong> HTTP 500 errors (unhandled server errors), responses that take orders of magnitude longer than normal, memory consumption that grows without bound, connections that aren&#8217;t properly closed.</p><p>Set up monitoring for all of these before you start fuzzing. Your fuzzer will generate thousands of requests &#8212; you need automated detection of failures, not manual review of each response.</p><h2><strong>Step 5: Run, Monitor, Investigate</strong></h2><p>Start the fuzzer, let it run, and monitor for failures. When failures appear, the investigation follows a consistent pattern:</p><ol><li><p><strong>Capture the failing input.</strong> Most fuzzing tools log inputs that trigger failures. Save these immediately.</p></li><li><p><strong>Reproduce the failure.</strong> Send the exact failing input again to confirm it&#8217;s deterministic.</p></li><li><p><strong>Minimize the input.</strong> Many fuzzers include minimization features that strip the failing input down to the smallest payload that still triggers the failure. A 50,000-character input that causes a crash might minimize to a 12-character string &#8212; making the root cause much clearer.</p></li><li><p><strong>Classify the failure.</strong> Is this a crash? A security vulnerability? An unhandled error? A performance issue? Classification determines priority.</p></li><li><p><strong>File and track.</strong> Report the issue with the minimized reproduction case and the failure classification.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rWoc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rWoc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rWoc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rWoc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rWoc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rWoc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!rWoc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rWoc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rWoc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rWoc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb557862-e015-40e4-8942-03bb8d70fb63_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Fuzz Testing in Practice: What Real Discoveries Look Like</strong></h2><p>Abstract descriptions of fuzzing become concrete when you see what it actually finds. Here are representative examples across different input types.</p><h2><strong>The Nested JSON Bomb</strong></h2><p>A team fuzzing their API&#8217;s user profile update endpoint discovered that sending a JSON payload with 500 levels of nested objects caused the JSON parser to consume all available stack memory and crash the service. The payload was structurally valid JSON &#8212; just deeply nested. No functional test case included deeply nested JSON because no real user profile data would ever have that structure. But an attacker could send it, and one malicious request could take down the entire service for all users.</p><p>The fix was a two-line change: adding a maximum nesting depth check to the JSON parser configuration. Two lines of code that prevented a denial-of-service vulnerability &#8212; found only because a fuzzer generated an input that no human would think to create.</p><h2><strong>The Truncation Mismatch</strong></h2><p>A file upload feature validated file names on the server side, rejecting names containing special characters. But the validation checked the full file name while the storage layer truncated names to 255 characters. A fuzzer discovered that a file name consisting of 254 innocent characters followed by <code>../../../etc/passwd</code> passed the validation check (the dangerous characters were at positions 255+), but after truncation, the stored path contained a path traversal sequence. The validation and the storage disagreed about which characters were in the file name&#8212;and the fuzzer found the exact length that exploited this mismatch.</p><h2><strong>The Character Encoding Confusion</strong></h2><p>An application accepted UTF-8 encoded text in its search field and properly sanitized it against XSS attacks. Fuzzing with various character encodings discovered that sending the same search query in UTF-7 encoding bypassed the sanitization entirely, because the sanitizer only recognized UTF-8 encoded script tags. The browser, however, would interpret the UTF-7 encoded response correctly &#8212; resulting in a stored XSS vulnerability. The fuzzer found this by systematically trying the same attack payload in different character encodings, something a human tester would be unlikely to attempt exhaustively.</p><h2><strong>The Integer That Wasn&#8217;t</strong></h2><p>A quantity field in an ordering system was validated to be a positive integer between 1 and 9999. Fuzzing with numeric edge cases discovered that sending the value <code>1e308</code> (a valid floating-point number in scientific notation) was parsed as a number, passed the range check (it&#8217;s greater than 1 and the comparison was done in floating point), but caused an integer overflow when converted to a 32-bit integer for the inventory system. The result: the order quantity wrapped around to a negative number, and the inventory system <em>added</em> stock instead of subtracting it.</p><h2><strong>Integrating Fuzz Testing Into Your Workflow</strong></h2><p>Fuzz testing delivers the most value when it&#8217;s a regular, automated part of your development process &#8212; not an occasional manual exercise.</p><h2><strong>In Your CI/CD Pipeline</strong></h2><p>The most impactful integration point. Configure fuzzing to run against every build or every merge to the main branch. Keep the fuzzing duration short for CI &#8212; 5 to 15 minutes per target &#8212; so it doesn&#8217;t block the pipeline. Use mutation-based or generation-based fuzzing with your existing test corpus as seeds.</p><p>The pipeline should fail if any fuzz input causes a crash, an unhandled exception, or a security-relevant response (stack traces, excessive response sizes, 500 errors). This creates a continuous quality gate: no code ships if a fuzzer can break its input handling.</p><p><strong>Example CI configuration approach:</strong> Fuzz your three highest-risk API endpoints for 5 minutes each as part of your integration test suite. Use Schemathesis pointed at your OpenAPI spec for automatic test generation. Total fuzzing time: 15 minutes per build, catching input handling regressions before any human tester sees the code.</p><h2><strong>As Dedicated Fuzzing Campaigns</strong></h2><p>Beyond the short CI runs, schedule longer fuzzing campaigns &#8212; hours or days &#8212; for deeper exploration. These extended runs give coverage-guided fuzzers time to discover complex code paths and multi-step vulnerability chains. Run them weekly, before releases, or after significant code changes.</p><h2><strong>In Security Reviews</strong></h2><p>Before any feature that handles external input goes to production, include a targeted fuzzing session in the security review. This is especially important for features that accept new input formats, integrate with new external services, or process user-uploaded files.</p><h2><strong>During Development</strong></h2><p>Property-based testing libraries like Hypothesis integrate fuzzing directly into your test suite. Developers can write tests that describe the <em>properties</em> inputs should satisfy rather than listing specific test cases, and the library generates hundreds of random inputs to verify those properties hold. This catches input handling bugs at the earliest possible point &#8212; while the developer is still writing the code.</p><p><strong>Example:</strong> Instead of writing <code>test_age_field_accepts_25()</code> and <code>test_age_field_rejects_negative()</code> as separate test cases, you write: &#8220;For any integer n, if n is between 0 and 150, the system should accept it; otherwise, it should reject it with a clear error.&#8221; The library generates hundreds of values&#8212;including boundary cases, extreme values, and type-confused inputs&#8212;automatically.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ecWc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ecWc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ecWc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ecWc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ecWc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ecWc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!ecWc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ecWc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ecWc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ecWc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18e9c45f-00b3-4875-a023-e4b93295b8d9_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Common Fuzz Testing Mistakes</strong></h2><p>Fuzzing seems straightforward &#8212; throw bad data at inputs and see what breaks. But several common mistakes reduce its effectiveness dramatically.</p><p><strong>Fuzzing only the happy path inputs.</strong> If you only fuzz the fields that functional tests already exercise, you&#8217;re missing the inputs that have received the least validation attention. Fuzz the obscure parameters: custom HTTP headers, cookie values, content-type fields, webhook payloads, and configuration endpoints. The inputs that developers think about least are the ones most likely to have weak validation.</p><p><strong>Ignoring authentication context.</strong> Many vulnerabilities only appear when the user is authenticated, because unauthenticated requests are rejected before reaching the vulnerable code. Fuzz with valid authentication tokens so your malformed payloads actually reach the application logic behind the authentication layer.</p><p><strong>Running too short.</strong> Coverage-guided fuzzers need time to explore. A five-minute run finds surface-level issues. An overnight run finds deep bugs that require the fuzzer to chain together multiple discoveries. Quick CI runs are valuable for regression detection, but they&#8217;re not a substitute for extended campaigns.</p><p><strong>Fuzzing in a shared environment.</strong> Fuzzing generates enormous volumes of requests, many of which trigger errors and fill logs. Running a fuzzer against a shared development or staging environment will pollute logs, trigger alerts, degrade performance for other users, and potentially corrupt shared test data. Always fuzz in an isolated environment dedicated to that purpose.</p><p><strong>Not minimizing failing inputs.</strong> A fuzzer finds a crash triggered by a 200-kilobyte malformed JSON payload. Filing a bug report with that payload is technically correct but practically useless &#8212; the developer has to figure out which part of 200 kilobytes actually caused the crash. Minimize first. Most fuzzing tools can reduce the failing input to its essential components automatically.</p><h2><strong>Your Fuzz Testing Starter Kit</strong></h2><p>Here&#8217;s everything you need to run your first fuzzing session.</p><pre><code>FUZZ TESTING STARTER KIT
==========================STEP 1: MAP YOUR INPUT SURFACE
List every point where external data enters your system:
API Endpoints:
  - 
  - 
  - 
File Processing:
  - 
  - 
User Input Fields:
  - 
  - 
Other Inputs (message queues, config, webhooks):
  - 
  - STEP 2: PRIORITIZE TARGETS
Rank by risk (consider: public-facing? handles sensitive data?
complex parsing? recently changed?):
  High priority: ____________________
  Medium priority: __________________
  Low priority: ____________________STEP 3: GATHER SEED INPUTS
For your highest-priority target, collect:
  [ ] Minimal valid input (required fields only)
  [ ] Complete valid input (all fields populated)
  [ ] Edge-case valid inputs (long strings, special chars,
      international characters that are technically valid)
  [ ] Inputs from API documentation examplesSTEP 4: SELECT TOOL AND APPROACH
  Target type: API / File parser / Protocol / General
  Chosen tool: ____________________
  Fuzzing strategy: Dumb / Mutation / Generation / Coverage-guidedSTEP 5: SET UP MONITORING
  [ ] Application error logs accessible
  [ ] Crash detection configured
  [ ] Response monitoring (status codes, timing, size)
  [ ] Memory monitoring active
  [ ] Isolated environment confirmedSTEP 6: RUN AND REVIEW
  First run duration: _____ minutes
  
For each failure found:
  [ ] Failing input captured
  [ ] Failure reproduced
  [ ] Input minimized to smallest reproducing case
  [ ] Failure classified (crash / security / error handling / 
performance)
  [ ] Bug filed with minimized reproduction and classification
  [ ] Original failing input saved for regression testingRESULTS SUMMARY
  Inputs generated: _____ (approximate)
  Unique failures found: _____
  Crashes: _____
  Security-relevant findings: _____
  Error handling gaps: _____
  Performance anomalies: _____
  Bugs filed: _____</code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zk2a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zk2a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Zk2a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Zk2a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Zk2a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zk2a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg" width="875" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Zk2a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Zk2a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Zk2a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Zk2a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285df160-f15d-4f48-975d-9bd226cc3865_875x488.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>From Noise to Signal</strong></h2><p>Fuzz testing is, at its core, a practice of humility. It starts from the admission that you cannot imagine every input your system will receive. Users will submit data you didn&#8217;t expect. Integrating systems will send payloads that violate your assumptions. Attackers will deliberately craft inputs designed to find the gaps in your validation.</p><p>You can&#8217;t anticipate all of that. But you can test for it. Not by trying to think of every dangerous input yourself &#8212; that&#8217;s a losing game &#8212; but by letting an automated tool generate inputs that are indifferent to your assumptions and relentless in their variety.</p><p>The inputs that break your system during fuzz testing are a gift. Each one reveals an assumption you didn&#8217;t know you were making. Each one identifies a gap in your input handling before an attacker or a production incident does. And each one, once fixed, makes your system genuinely more resilient &#8212; not just to that specific input, but to the entire category of unexpected data it represents.</p><p>This is what separates fuzz testing from just &#8220;throwing random data and hoping for the best.&#8221; The randomness has a purpose: to explore the space of possible inputs faster and more thoroughly than any human could manually. The purpose has an outcome: software that handles the unexpected gracefully instead of failing in ways that cause harm.</p><p>In our next article, we&#8217;ll shift from breaking things to building understanding. <strong>Equivalence Partitioning</strong> is the technique of dividing the infinite space of possible inputs into manageable groups and testing representative values from each &#8212; a mathematical approach to getting maximum coverage with minimum effort. After several articles on finding defects through randomness and exploration, we&#8217;ll examine how structured, analytical thinking about inputs lets you test smarter, not harder.</p><p><strong>Remember:</strong> Your application&#8217;s inputs are a promise to the outside world. Fuzz testing is how you find out whether you can keep that promise when the world doesn&#8217;t play by your rules.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Ryan's Tech Lab is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Monkey Testing Explained: Random Testing with Purpose]]></title><description><![CDATA[What a Toddler Can Teach You About Software Quality]]></description><link>https://ryancraventech.substack.com/p/monkey-testing-explained-random-testing</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/monkey-testing-explained-random-testing</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Mon, 23 Feb 2026 12:24:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!q0SP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hand a three-year-old your phone. Don&#8217;t give them instructions, don&#8217;t tell them what the app does, and definitely don&#8217;t tell them what not to touch. Then watch.</p><p>Within sixty seconds, a toddler will do things to your application that no test plan, no charter, and no experienced tester would ever think to do. They&#8217;ll tap the screen with four fingers simultaneously. They&#8217;ll swipe in the middle of a loading animation. They&#8217;ll rotate the phone upside down while a modal dialog is open. They&#8217;ll press the home button and the volume button and try to drag an image off the screen all at the same time. They have no understanding of what the application is supposed to do, no model of correct behavior, and absolutely no respect for the intended user workflow.</p><p>And in that chaotic sixty seconds, they&#8217;ll crash the app twice.</p><p>This isn&#8217;t a theoretical scenario. A product manager at a fintech company once told me that their most embarrassing production outage was discovered by his daughter. She&#8217;d gotten hold of his phone during a demo, hammered the &#8220;transfer&#8221; button about thirty times in rapid succession while the confirmation dialog was still loading, and somehow triggered a race condition that duplicated transactions. The team had hundreds of test cases for the transfer flow. Not one of them involved pressing the button thirty times in under two seconds, because no reasonable adult would do that. But software doesn&#8217;t only serve reasonable adults &#8212; it serves everyone, on every device, in every state of attention and distraction, including the states where users behave in ways nobody anticipated.</p><p>This is the core insight behind monkey testing: sometimes the most revealing test is the one no rational person would design. Randomness finds what logic misses.</p><p>We&#8217;ve been traveling along a spectrum in this series. Session-Based Test Management gave us structure for organizing exploration. Charter writing gave us focused missions. Ad-hoc testing gave us purposeful freedom from those structures. Now we arrive at the far end of that spectrum &#8212; testing that is deliberately, systematically random. Not careless. Not chaotic. Random <em>with purpose</em>, because the goal isn&#8217;t to simulate thoughtful usage. The goal is to discover what happens when usage is anything but thoughtful.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q0SP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q0SP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!q0SP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!q0SP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!q0SP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q0SP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!q0SP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!q0SP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!q0SP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!q0SP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c8d3c6-6944-4c94-b5bc-39772b9e1fd6_788x440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Monkey Testing Actually Is</strong></h2><p>Monkey testing is a technique where a tester &#8212; or more commonly, a tool &#8212; interacts with software using random or semi-random inputs and actions, without any reference to expected behavior, defined test cases, or application knowledge. The name comes from the infinite monkey theorem: given enough random input over enough time, every possible interaction will eventually occur, including the ones that break things.</p><p>The defining characteristic of monkey testing is the absence of an oracle. In most testing, you know what the software <em>should</em> do, and you&#8217;re checking whether it does it. In monkey testing, you often don&#8217;t know what the correct behavior is for a given random input. Instead, you&#8217;re looking for a specific category of failure: crashes, hangs, unhandled exceptions, data corruption, security violations, and any other response that&#8217;s wrong regardless of what the &#8220;right&#8221; answer would be. You may not know what should happen when a user submits a form containing 50,000 characters of emoji mixed with control characters &#8212; but you know the application shouldn&#8217;t crash, corrupt its database, or expose a stack trace.</p><p>This gives monkey testing a unique role in your testing strategy. It doesn&#8217;t validate that features work correctly. It validates that the system <em>fails gracefully</em> under unexpected conditions. It tests resilience, not correctness.</p><p>A simple example illustrates the difference. If you&#8217;re testing a search function, a charter-based session might explore how the search handles various query types to verify results are accurate and relevant. Monkey testing would throw thousands of random character combinations at the search field &#8212; binary data, extremely long strings, null bytes, nested quotation marks, SQL fragments &#8212; not to check whether the results make sense, but to find out whether any input can crash the search service, trigger an unhandled exception, or cause the page to render incorrectly.</p><h2><strong>The Three Species of Monkey</strong></h2><p>Not all monkey testing is the same. The approach varies depending on how much the &#8220;monkey&#8221; knows about the application it&#8217;s testing.</p><h2><strong>Dumb Monkey Testing</strong></h2><p>A dumb monkey has zero knowledge of the application. It generates completely random inputs: random clicks at random screen coordinates, random keystrokes, random gestures. It doesn&#8217;t know what a button is, doesn&#8217;t understand forms, and can&#8217;t navigate menus intentionally. It&#8217;s pure chaos.</p><p><strong>Example in practice:</strong> A dumb monkey tool pointed at a web application might click random pixel coordinates, type random strings into whatever element happens to have focus, randomly submit forms with garbage data, and navigate to random URLs within the domain. Most of these actions will be meaningless &#8212; clicking on empty space, typing into non-editable elements. But over thousands of iterations, the monkey will occasionally stumble into combinations that matter: submitting a form with binary data in a text field, clicking a delete button that lacked a confirmation dialog, or navigating to an API endpoint that returns unhandled raw data.</p><p><strong>When it&#8217;s useful:</strong> Dumb monkey testing is most valuable early in development or when you need a baseline resilience check. If a dumb monkey can crash your application, you have fundamental stability problems that need fixing before more sophisticated testing makes sense.</p><p><strong>The limitation:</strong> Dumb monkeys are inefficient. The vast majority of their actions produce no useful information. They might spend thousands of interactions clicking on background images and typing into read-only fields before accidentally doing something interesting.</p><h2><strong>Smart Monkey Testing</strong></h2><p>A smart monkey understands the application&#8217;s structure. It knows what UI elements exist, which ones are interactive, what types of input each field expects, and how to navigate between screens. It uses this knowledge to generate random actions that are at least plausible &#8212; clicking actual buttons, entering data into actual fields, navigating through actual menus &#8212; but the <em>choices</em> about which button to click, what data to enter, and where to navigate are still random.</p><p><strong>Example in practice:</strong> A smart monkey testing an e-commerce application would know that the search field accepts text input, so it would enter random strings there (not at random screen coordinates). It would know that the &#8220;Add to Cart&#8221; button is clickable, so it would click it at random points during browsing. It would know that the checkout flow has specific steps, so it would navigate through those steps in random order, skipping some, repeating others, and entering random (but structurally valid) data at each stage. It might add 99,999 items to the cart, apply seventeen discount codes simultaneously, and then try to check out with an expired credit card number from a country the system doesn&#8217;t serve.</p><p><strong>When it&#8217;s useful:</strong> Smart monkey testing is the workhorse of the technique. It&#8217;s efficient enough to find real issues but random enough to explore scenarios that no human would design. Most modern monkey testing tools operate at this level.</p><p><strong>The limitation:</strong> Smart monkeys still don&#8217;t understand business logic. They might find that the application doesn&#8217;t crash when you add 99,999 items, but they won&#8217;t notice that the price calculation is wrong for quantities over 10,000 &#8212; because they don&#8217;t know what the correct price should be.</p><h2><strong>Brilliant Monkey Testing</strong></h2><p>A brilliant monkey has deep knowledge of the application: its business rules, its data model, its common failure patterns, and its known problem areas. It generates random inputs that are specifically designed to probe weaknesses &#8212; using this knowledge to make its randomness strategically dangerous.</p><p><strong>Example in practice:</strong> A brilliant monkey testing a banking application would know that race conditions are likely in concurrent transaction processing. So its &#8220;random&#8221; actions would include rapidly initiating multiple transfers from the same account, submitting duplicate payment requests with microsecond timing differences, and toggling between account views while background transactions are processing. The actions are random in their specific timing and combination, but the <em>category</em> of actions is strategically chosen to maximize the chance of finding real problems.</p><p><strong>When it&#8217;s useful:</strong> Brilliant monkey testing bridges the gap between randomness and expertise. It&#8217;s particularly valuable for stress-testing known risk areas with unpredictable input patterns.</p><p><strong>The limitation:</strong> Building a brilliant monkey requires significant investment in configuring its knowledge, and at some point, it starts to look less like monkey testing and more like automated exploratory testing &#8212; which is a different technique entirely.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sEdd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sEdd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sEdd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sEdd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sEdd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sEdd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!sEdd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sEdd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sEdd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sEdd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd09287a8-e3ac-4061-8590-48b04095de09_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Monkey Testing Finds (That Other Testing Misses)</strong></h2><p>Monkey testing isn&#8217;t competing with your charter-based sessions or your scripted test cases. It&#8217;s finding a specific category of defect that those approaches are structurally unable to discover.</p><h2><strong>Unhandled Exceptions and Crashes</strong></h2><p>This is the bread and butter of monkey testing. Every application has input combinations and interaction sequences that developers never anticipated. Defensive coding should handle these gracefully &#8212; displaying a meaningful error, logging the issue, and continuing to function. Monkey testing reveals where that defensive coding has gaps.</p><p><strong>Real example:</strong> A mobile banking app passed all 3,000 scripted test cases. A monkey testing tool found that rapidly switching between the transaction history and account summary screens while the app was refreshing data from the server caused a null pointer exception that crashed the application. The specific timing &#8212; switching screens during a network response &#8212; was something no human tester had tried because it required millisecond-precise interaction that felt unnatural.</p><h2><strong>Memory Leaks and Resource Exhaustion</strong></h2><p>Monkey testing&#8217;s random, prolonged interaction with an application naturally exercises it in ways that reveal resource management issues. If the monkey runs for hours, performing thousands of random actions, it creates the kind of extended, varied usage pattern that exposes memory leaks, connection pool exhaustion, and file handle accumulation that shorter, more focused testing sessions won&#8217;t trigger.</p><p><strong>Real example:</strong> An internal project management tool worked perfectly in 30-minute testing sessions but crashed after about four hours of continuous use. Monkey testing ran overnight, performing random navigation and data entry for eight hours straight, and revealed that every time a user opened and closed the task detail panel, a small event listener wasn&#8217;t being cleaned up. After roughly 2,000 open/close cycles, the browser ran out of memory.</p><h2><strong>Race Conditions and Timing Issues</strong></h2><p>Human testers interact with software at human speed &#8212; one deliberate action at a time, with natural pauses in between. Monkey tools can fire actions in rapid succession, overlapping operations, and creating timing conditions that humans can&#8217;t easily replicate. This makes them excellent at finding race conditions, double-submit bugs, and concurrency issues.</p><p><strong>Real example:</strong> An e-commerce platform&#8217;s wishlist feature worked flawlessly in all manual testing. A monkey tool that rapidly added and removed the same item to the wishlist &#8212; dozens of times per second &#8212; discovered that under high-speed concurrent operations, items could appear in the wishlist multiple times or be removed from the database without being removed from the display cache. The data became inconsistent in ways that only manifested under rapid repeated interaction.</p><h2><strong>Error Handling Gaps</strong></h2><p>When developers write error handling, they typically think about the errors they can imagine. Monkey testing generates errors that nobody imagined &#8212; and reveals whether the error handling is truly comprehensive or only covers the anticipated cases.</p><p><strong>Real example:</strong> A form with server-side validation handled all the expected invalid input patterns with helpful error messages. But when a monkey testing tool submitted a request with a malformed JSON body (something impossible through the normal UI but possible through API manipulation), the server returned a raw 500 error with a stack trace that included database connection details. The error handling was thorough for UI-originated requests but completely missing for malformed requests at the API level.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fZNP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fZNP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fZNP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fZNP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fZNP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fZNP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!fZNP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fZNP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fZNP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fZNP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b1dea34-7776-4d36-80d7-33e2a9f547e8_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>How to Actually Do Monkey Testing</strong></h2><p>Understanding the concept is one thing. Running monkey testing effectively is another. Here&#8217;s how to do it in practice.</p><h2><strong>Choosing Your Approach: Manual vs. Tool-Based</strong></h2><p>Monkey testing can be done manually or with tools, and the choice matters.</p><p><strong>Manual monkey testing</strong> means a human tester deliberately acts randomly &#8212; pressing keys without looking, clicking wildly, entering nonsensical data. This is useful for quick smoke-style checks (&#8220;can I crash this in five minutes of random interaction?&#8221;) but it&#8217;s limited by human speed and the difficulty of being truly random. Humans have habits, and even when trying to be random, we tend to repeat patterns. We click in similar areas, type similar strings, and follow similar navigation paths. True randomness is actually hard for people.</p><p><strong>Tool-based monkey testing</strong> uses software to generate random interactions automatically. This is far more effective for sustained monkey testing because tools can generate thousands of interactions per minute, run for hours without fatigue, and produce genuinely random input patterns. They also capture logs of exactly what they did, making it possible to reproduce bugs they discover &#8212; a critical advantage over manual random testing, where recreating the exact sequence that caused a crash can be nearly impossible.</p><p>For most teams, the practical answer is tool-based for serious monkey testing, supplemented by occasional manual monkey testing as a quick sanity check.</p><h2><strong>Setting Up Effective Monkey Testing</strong></h2><p>Effective monkey testing requires some preparation, even though the testing itself is unscripted.</p><p><strong>Define your crash oracle.</strong> Since monkey testing doesn&#8217;t validate correctness, you need automated ways to detect failures. At minimum, monitor for: application crashes, unhandled exceptions (check console logs and server logs), HTTP 500 errors, UI rendering failures (blank screens, missing elements), and significant memory growth over time. These are your &#8220;something went wrong&#8221; signals.</p><p><strong>Seed your starting conditions.</strong> Monkey testing is more productive when the application is in a realistic state before the chaos begins. Log in as a user with real data. Navigate to a feature-rich screen. Populate the database with representative records. A monkey testing a blank application with no data won&#8217;t find the interesting bugs that only appear when real data is involved.</p><p><strong>Set boundaries.</strong> Unless you&#8217;re specifically testing it, exclude actions that would have irreversible consequences &#8212; account deletion, payment processing against real services, data export to external systems. Most monkey testing tools support exclusion rules that prevent the monkey from clicking certain elements or navigating to certain areas.</p><p><strong>Plan your monitoring.</strong> Before starting the monkey, set up the monitoring you&#8217;ll need to detect and diagnose issues: application logs, server monitoring, browser console capture, network traffic recording, and performance metrics. When the monkey finds a crash, you&#8217;ll need this data to understand what happened and reproduce the issue.</p><h2><strong>Running the Session</strong></h2><p>A typical monkey testing session follows this pattern:</p><ol><li><p><strong>Prepare the environment.</strong> Set up a test environment with realistic data. Ensure monitoring is active and logging is configured.</p></li><li><p><strong>Configure the monkey.</strong> Set parameters: which screens to target, how long to run, what actions to include/exclude, how fast to interact.</p></li><li><p><strong>Start the monkey and monitor.</strong> Launch the tool and watch the monitoring dashboards. You&#8217;re looking for crashes, errors, performance degradation, and anomalous behavior.</p></li><li><p><strong>When something breaks, capture the evidence.</strong> Record the state of the application, the logs, and if possible, the sequence of actions that led to the failure. Many tools provide action logs for exactly this purpose.</p></li><li><p><strong>Investigate and report.</strong> Determine whether the failure is a genuine bug or an expected limitation. File bugs for genuine issues, including the action sequence and environmental conditions.</p></li><li><p><strong>Resume and repeat.</strong> Fix the configuration if needed (for example, if the monkey keeps hitting the same uninteresting error) and run again. Each run should ideally explore new territory.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FLvP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FLvP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FLvP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FLvP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FLvP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FLvP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!FLvP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FLvP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FLvP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FLvP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1df3aee-a0c9-45da-8a46-12596e3392a2_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Monkey Testing Tools: What&#8217;s Available</strong></h2><p>You don&#8217;t need to build your own monkey testing tool. Several proven options exist across different platforms.</p><p>For <strong>Android applications</strong>, Android&#8217;s built-in <code>adb shell monkey</code> command is the classic starting point. It generates random touch events, gestures, and system events at configurable speeds. It&#8217;s simple to run and comes free with the Android development tools. A basic command looks like <code>adb shell monkey -p com.your.app --throttle 100 -v 10000</code>, which sends 10,000 random events to your app with 100 milliseconds between each.</p><p>For <strong>web applications</strong>, tools like Gremlins.js inject random interactions into a browser page &#8212; clicking, typing, scrolling, and resizing &#8212; and can be configured to target specific elements or avoid certain areas. It runs directly in the browser and is quick to set up for basic chaos testing.</p><p>For <strong>iOS applications</strong>, tools are more limited due to platform restrictions, but frameworks like XCUITest can be scripted to generate semi-random interactions, and tools like SwiftMonkey (now archived but conceptually useful) provide inspiration for building random interaction generators within Apple&#8217;s testing ecosystem.</p><p>For <strong>API testing</strong>, tools like Burp Suite&#8217;s intruder, or custom scripts using libraries like Hypothesis (Python) or fast-check (JavaScript), can send randomized and fuzzed payloads to API endpoints. This is technically fuzzing rather than monkey testing, but the principle is the same: random input to discover unhandled conditions.</p><p>The key when selecting a tool is matching it to your goal. If you want basic crash detection, a simple tool with high-speed random input is sufficient. If you want intelligent exploration that covers more of the application&#8217;s functionality, you need a smarter tool that understands your application&#8217;s structure.</p><h2><strong>Monkey Testing vs. Everything Else</strong></h2><p>At this point in the series, we&#8217;ve covered several testing approaches along the structure spectrum. Let&#8217;s be precise about where monkey testing fits relative to each.</p><p><strong>Monkey testing vs. ad-hoc testing.</strong> We covered ad-hoc testing in our previous article, and the distinction matters. Ad-hoc testing is driven by human judgment &#8212; the tester makes purposeful decisions about what to try, even without a formal plan. Monkey testing removes human judgment from the equation entirely. The actions are random, not purposeful. A tester doing ad-hoc testing thinks &#8220;this validation seems weak, let me probe it.&#8221; A monkey just throws random data everywhere and sees what breaks. Both have value; they find different things.</p><p><strong>Monkey testing vs. chartered exploratory testing.</strong> Chartered sessions are guided by a specific mission: explore a target with specific techniques to discover specific information. Monkey testing has no mission beyond &#8220;don&#8217;t crash.&#8221; It doesn&#8217;t validate functionality, usability, or business logic. It validates resilience &#8212; the application&#8217;s ability to survive the unexpected.</p><p><strong>Monkey testing vs. fuzz testing.</strong> These are close cousins. Fuzz testing sends malformed or random data specifically to <em>inputs</em> &#8212; API parameters, file parsers, form fields &#8212; to find input handling vulnerabilities. Monkey testing is broader: it randomizes the entire interaction pattern, including navigation, timing, and sequences of actions, not just individual inputs. Fuzz testing is a component of what a thorough monkey testing approach might include.</p><p><strong>Monkey testing vs. stress testing.</strong> Stress testing pushes the system to its performance limits &#8212; high user counts, large data volumes, peak traffic conditions. Monkey testing may accidentally stress the system (by performing thousands of rapid actions), but its primary goal is randomness of <em>behavior</em>, not extremity of <em>load</em>. A monkey test might discover a crash at normal load that no stress test would find, because the crash is triggered by an unusual sequence rather than high volume.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fsL2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fsL2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fsL2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fsL2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fsL2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fsL2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!fsL2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fsL2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fsL2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fsL2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44dfdfc0-6e23-4f16-bde6-08345d73e70f_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>When Monkey Testing Wastes Your Time</strong></h2><p>Monkey testing isn&#8217;t always the right tool. Knowing when to skip it is as important as knowing when to use it.</p><p><strong>When your application already crashes from normal use.</strong> If testers are finding crashes through regular chartered exploration, monkey testing will just find more of the same &#8212; faster, but without the context needed to fix them. Fix the fundamental stability issues first, then use monkey testing to verify resilience.</p><p><strong>When you need to validate business logic.</strong> Monkey testing will never tell you whether a discount calculation is correct, whether the right notification was sent, or whether a workflow follows the business rules. If your testing goal is correctness rather than resilience, use a different approach.</p><p><strong>When you can&#8217;t monitor effectively.</strong> If you can&#8217;t detect failures automatically &#8212; through crash logs, error monitoring, or performance tracking &#8212; monkey testing&#8217;s output is essentially invisible. The monkey might cause ten crashes that nobody notices because nobody&#8217;s watching the logs. Invest in monitoring before investing in monkey testing.</p><p><strong>When the environment isn&#8217;t isolated.</strong> Running a monkey against a shared development database or a production-adjacent environment is a recipe for collateral damage. The monkey doesn&#8217;t know not to delete all the test data, corrupt shared resources, or trigger alerts that wake up the on-call team. Always isolate your monkey testing environment.</p><p><strong>When time is extremely limited.</strong> If you have two hours of testing time and a release to validate, those hours are better spent on focused, human-guided exploration than on watching a monkey randomly click around. Monkey testing is most productive as a regular practice &#8212; running overnight, during off-hours, or as part of continuous integration &#8212; not as a last-minute testing activity.</p><h2><strong>Making Monkey Testing Part of Your Strategy</strong></h2><p>The highest-value deployment of monkey testing isn&#8217;t as an occasional manual exercise &#8212; it&#8217;s as an automated, regular part of your quality practice.</p><h2><strong>In Continuous Integration</strong></h2><p>Configure monkey testing to run automatically as part of your CI/CD pipeline. After each build, let a smart monkey interact with the application for a defined period &#8212; say, 15 minutes. If it causes any crashes or unhandled exceptions, the build fails. This creates a baseline resilience gate: no code ships if a random monkey can break it. Over time, this gate quietly catches stability regressions before they reach any human tester.</p><h2><strong>As Overnight Runs</strong></h2><p>Monkey tests are cheap to run unattended. Set up nightly monkey testing sessions that run for hours, exercising the application while the team sleeps. Review the logs each morning for new crashes, performance degradation, or error spikes. This extended, sustained randomness is where memory leaks and resource exhaustion issues surface.</p><h2><strong>Before Major Releases</strong></h2><p>Before any significant release, run an extended monkey testing session as a resilience check. This doesn&#8217;t replace your functional testing, your exploratory sessions, or your regression suite. It adds a different dimension of confidence: &#8220;We verified the features work correctly <em>and</em> we verified that random, unexpected interaction doesn&#8217;t crash the application.&#8221;</p><h2><strong>After Architecture Changes</strong></h2><p>Major refactoring, framework upgrades, infrastructure migrations &#8212; these changes affect the application&#8217;s fundamental behavior in ways that specific test cases might not cover. A monkey testing session after architecture changes tests the system&#8217;s overall integrity in a way that&#8217;s both thorough and orthogonal to your planned test coverage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N7XV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N7XV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!N7XV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!N7XV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!N7XV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N7XV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!N7XV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!N7XV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!N7XV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!N7XV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013393ea-048a-4112-b83d-0fca40727013_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Interpreting Monkey Testing Results</strong></h2><p>When a monkey breaks something, you need to figure out whether the finding matters &#8212; and what to do about it.</p><h2><strong>The Severity Question</strong></h2><p>Not every monkey-discovered crash is a high-priority bug. A crash triggered by simultaneously submitting a form from two browser tabs opened to the same page while toggling airplane mode isn&#8217;t something real users will encounter often. But a crash triggered by pressing the back button during a page load is something users hit every day.</p><p>When evaluating monkey testing findings, ask three questions:</p><p><strong>How likely is this in real usage?</strong> If the triggering conditions are extremely unlikely, the fix may be lower priority. But if the monkey is discovering failures through interactions that real users could plausibly perform &#8212; rapid double-taps, back navigation during loading, switching apps during a process &#8212; those bugs need urgent attention.</p><p><strong>How severe is the impact?</strong> A crash that loses unsaved data is worse than a crash that simply requires reopening the app. A crash that exposes system internals (stack traces, database details) is a security concern. An error that silently corrupts data is worse than one that loudly fails.</p><p><strong>How reproducible is it?</strong> Intermittent issues that the monkey triggered but you can&#8217;t reproduce may indicate timing-dependent bugs (race conditions, threading issues). These are some of the most dangerous bugs in production because they appear randomly and are notoriously hard to diagnose under pressure.</p><h2><strong>From Random Crash to Reproducible Bug</strong></h2><p>The biggest practical challenge of monkey testing is reproduction. The monkey performed 10,000 random actions and the app crashed somewhere around action 7,342. Which actions actually mattered?</p><p>Good monkey testing tools provide action logs that you can replay or at least review. The investigation process typically involves: reviewing the action log to identify what happened immediately before the crash, attempting to reproduce the failure using just those final actions, and progressively simplifying until you find the minimal set of actions that triggers the bug.</p><p>Often, what looks like a complex random failure turns out to be simple once you strip away the irrelevant actions. The monkey performed 10,000 actions, but the crash was actually caused by a two-step sequence: navigating to a specific screen while a background sync was in progress. The other 9,998 actions were noise &#8212; the monkey just happened to stumble into the dangerous combination through random exploration.</p><h2><strong>Your Monkey Testing Starter Kit</strong></h2><p>Here&#8217;s what you need to run your first monkey testing session this week.</p><pre><code>MONKEY TESTING STARTER KIT
============================

BEFORE YOUR FIRST SESSION
Environment:
  [ ] Isolated test environment (NOT shared or production)
  [ ] Realistic data loaded
  [ ] Monitoring active (error logs, crash reports, performance)
  [ ] External integrations stubbed or sandboxed

Tool Selection:
  - Android: adb shell monkey (built-in)
  - Web: Gremlins.js (open source, browser-based)
  - API: Custom scripts with random payload generation
  - General: Your automation framework with randomized inputs

Configuration:
  [ ] Target screens/areas defined
  [ ] Excluded actions specified (delete, payment, etc.)
  [ ] Speed/throttle set (start moderate, increase later)
  [ ] Session duration defined

RUNNING YOUR FIRST SESSION
Round 1 - Dumb Monkey (30 minutes):
  - Pure random interaction, no configuration
  - Goal: Find fundamental stability issues
  - Watch for: Crashes, blank screens, unresponsive UI

Round 2 - Smart Monkey (60 minutes):
  - Configure to interact with actual UI elements
  - Goal: Find edge cases in real workflows
  - Watch for: Error handling gaps, state corruption

Round 3 - Targeted Monkey (60 minutes):
  - Focus on highest-risk area (recent changes, complex features)
  - Goal: Stress-test specific functionality
  - Watch for: Race conditions, data inconsistencies

AFTER THE SESSION
For each failure found:
  [ ] Capture logs and action sequence
  [ ] Attempt to reproduce manually
  [ ] Simplify to minimal reproduction steps
  [ ] Assess severity and real-world likelihood
  [ ] File bug report with reproduction steps
  [ ] Tag as monkey-testing-discovered

Session summary:
  Duration: <strong>____</strong><em>_
  Actions performed: <strong>____</strong>_</em> (approximate)
  Crashes found: <strong>____</strong><em>_
  Errors logged: <strong>____</strong>_</em>
  Bugs filed: <strong>____</strong><em>_
  Areas that survived well: <strong>____</strong>_</em>
  Areas that need human exploration: <strong>____</strong><em>_</em></code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fgRG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fgRG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fgRG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fgRG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fgRG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fgRG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!fgRG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fgRG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fgRG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fgRG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbccce91-820e-434e-9b7b-af46b1e6ffdb_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Chaos That Builds Confidence</strong></h2><p>There&#8217;s something counterintuitive about monkey testing. It&#8217;s the most chaotic, least structured testing technique in your toolkit &#8212; and yet, passing it builds a specific kind of confidence that structured testing can&#8217;t provide.</p><p>Structured testing tells you: &#8220;The features we tested work as expected under the conditions we tested them.&#8221; That&#8217;s valuable but limited. It&#8217;s bounded by what you thought to test.</p><p>Monkey testing tells you something different: &#8220;We threw genuinely random, unpredictable chaos at this application and it didn&#8217;t break.&#8221; That statement covers territory that no amount of planning can reach, because it explicitly includes the interactions you <em>didn&#8217;t</em> think of.</p><p>This is why monkey testing belongs in every serious testing strategy &#8212; not as a primary technique, but as a resilience check that complements everything else. Your chartered sessions validate that features work. Your ad-hoc testing fills the gaps in your plans. And your monkey testing verifies that the application can survive the messy, unpredictable reality of actual usage at scale.</p><p>In an era of AI-generated code, this resilience check becomes even more important. AI tends to produce code that handles expected inputs elegantly but may have blind spots around unusual inputs, edge cases, and interaction patterns that fall outside its training data. Monkey testing &#8212; precisely because it operates outside any model of expected behavior &#8212; is perfectly positioned to discover these blind spots.</p><p>The toddler with your phone doesn&#8217;t care about your test plan. Neither do your users. Build software that survives both.</p><p><em>In our next article, we&#8217;ll explore <strong>Fuzz Testing Fundamentals</strong> &#8212; the close cousin of monkey testing that takes randomness and aims it with surgical precision at your application&#8217;s inputs. We compared the two briefly today, but fuzz testing deserves its own deep dive. We&#8217;ll examine how feeding deliberately malformed, unexpected, and boundary-pushing data into every input your system accepts reveals the security vulnerabilities, parsing failures, and crash-inducing edge cases that conventional testing consistently misses.</em></p><p><strong>Remember:</strong> Monkey testing doesn&#8217;t find bugs through intelligence &#8212; it finds them through indifference. And software that can survive indifference can survive anything.</p>]]></content:encoded></item><item><title><![CDATA[Ad-Hoc Testing Done Right: Adding Value Without Chaos]]></title><description><![CDATA[The Tester Who Broke the Build by Not Following the Plan]]></description><link>https://ryancraventech.substack.com/p/ad-hoc-testing-done-right-adding</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/ad-hoc-testing-done-right-adding</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Fri, 20 Feb 2026 12:24:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!VwPP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The release was scheduled for Friday. Every test case had passed. Every charter had been executed. The coverage map was green across the board. The team was confident.</p><p>Then, on Thursday afternoon, a developer named Marcus wandered over to the QA lead&#8217;s desk. &#8220;Hey, weird question &#8212; has anyone tried using the app while switching between WiFi and cellular? I was on the train this morning and the whole thing just&#8230; froze.&#8221; He hadn&#8217;t been assigned to test this. There was no charter for it. No test case covered it. He&#8217;d simply been using the application as a regular person and stumbled into a critical failure.</p><p>The QA lead grabbed the app and spent fifteen minutes doing exactly what Marcus described &#8212; toggling network connections, letting the signal drop and reconnect, switching between networks mid-transaction. Within those fifteen minutes, she&#8217;d found a data corruption bug that would have affected every mobile user with an unstable connection. No session report. No charter. No formal structure at all. Just a hunch, a quick investigation, and a release-saving discovery.</p><p>This is ad-hoc testing at its best. Unplanned, unscripted, driven by instinct and opportunity &#8212; and devastatingly effective.</p><p>It&#8217;s also the kind of testing that gets a terrible reputation, because for every story like Marcus&#8217;s, there are a hundred stories of testers &#8220;doing ad-hoc testing&#8221; as a euphemism for aimless clicking with nothing to show for it. The difference between the two isn&#8217;t whether you have a plan. It&#8217;s whether you have a purpose.</p><p>We&#8217;ve spent the last two articles building frameworks for structured exploratory testing &#8212; Session-Based Test Management for organizing sessions, and charter writing for focusing each mission. Now we need to talk about what happens when you deliberately set all of that aside. Because the most complete testing strategy includes room for the unplanned, the instinctive, and the spontaneous &#8212; as long as you know how to make it count.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VwPP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VwPP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VwPP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VwPP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VwPP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VwPP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!VwPP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VwPP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VwPP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VwPP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcda7594d-5628-475e-801e-7b4ecd65a629_788x440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Ad-Hoc Testing Actually Means</strong></h2><p>The term &#8220;ad-hoc&#8221; comes from Latin, meaning &#8220;for this&#8221; &#8212; for this particular purpose, for this specific situation. It doesn&#8217;t mean random, careless, or undisciplined. It means responsive. Situational. Arising from the moment rather than from a plan written days or weeks earlier.</p><p>Ad-hoc testing is testing performed without predefined test cases, charters, or formal session structures. The tester decides what to test, how to test it, and when to stop based on their judgment, knowledge, and observations in real time. There&#8217;s no documentation requirement before the session, no formal time-box, and no predetermined scope.</p><p>This definition immediately raises a question that anyone who read our previous articles should be asking: how is this different from the unfocused exploration that SBTM was designed to fix? It&#8217;s a fair question, and the answer lies in intent and context.</p><p>Unfocused exploration is someone sitting down without a plan <em>because they don&#8217;t have one.</em> Ad-hoc testing is someone setting aside their plan <em>because they have a reason to.</em> The first is a gap in process. The second is a deliberate testing technique deployed in situations where formal structure would actually slow you down or blind you to important discoveries.</p><p>The distinction is subtle but essential. A tester doing ad-hoc testing well brings the same skills, instincts, and domain knowledge they&#8217;d bring to a chartered session. They just aren&#8217;t constraining themselves to a predefined mission &#8212; because the situation calls for something more fluid.</p><h2><strong>When Ad-Hoc Testing Is the Right Choice</strong></h2><p>Ad-hoc testing isn&#8217;t a fallback when you don&#8217;t have time for &#8220;real&#8221; testing. It&#8217;s a first-choice approach in specific situations where its strengths matter more than formal structure.</p><h2><strong>When You Need Speed Over Documentation</strong></h2><p>A critical hotfix just landed in staging. The release is in two hours. You don&#8217;t have time to write charters, set up sessions, and conduct formal debriefs. You need a skilled tester to spend thirty minutes hammering the fix and its surrounding functionality, find anything broken, and report back. The value is in the speed of feedback, not the formality of the process.</p><h2><strong>When Something Feels Wrong</strong></h2><p>Experienced testers develop a sense &#8212; call it intuition, pattern recognition, or professional paranoia &#8212; that something isn&#8217;t right. Maybe the page loaded slightly slower than usual. Maybe a dropdown had an option you don&#8217;t remember seeing before. Maybe the error message used different phrasing than elsewhere in the app. These hunches don&#8217;t fit neatly into a charter because they&#8217;re not hypotheses yet. They&#8217;re whispers. Ad-hoc testing is how you follow those whispers to see if they lead somewhere.</p><h2><strong>When You&#8217;re Learning a New System</strong></h2><p>Before you can write effective charters, you need to understand the terrain. Ad-hoc testing is invaluable during initial exploration of an unfamiliar application. You&#8217;re not looking for specific bugs &#8212; you&#8217;re building a mental model of how the system works, where its boundaries are, and what its personality is. This reconnaissance phase informs all the structured testing that follows.</p><h2><strong>When the Formal Plan Has Blind Spots</strong></h2><p>Every test plan, no matter how thorough, has gaps. The charters you wrote cover what you anticipated. Ad-hoc testing covers what you didn&#8217;t. It&#8217;s the testing equivalent of looking in the places you weren&#8217;t planning to look &#8212; and it regularly finds issues precisely because those areas received less attention from structured approaches.</p><h2><strong>When You&#8217;re Verifying a Fix</strong></h2><p>A developer says a bug is fixed. You need to confirm the fix works and do a quick sanity check of related functionality. Spinning up a full SBTM session for a five-minute verification would be overhead without value. Ad-hoc testing fits perfectly here &#8212; quick, focused, and proportional to the task.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i7Ak!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i7Ak!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i7Ak!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i7Ak!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i7Ak!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i7Ak!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!i7Ak!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i7Ak!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i7Ak!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i7Ak!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77d77fd8-1d13-479b-b399-24d59dad6739_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Separates Good Ad-Hoc Testing from Aimless Clicking</strong></h2><p>Here&#8217;s the uncomfortable truth: most ad-hoc testing is bad. Not because the concept is flawed, but because testers use &#8220;ad-hoc&#8221; as permission to stop thinking carefully about what they&#8217;re doing. The label becomes an excuse rather than a technique.</p><p>Good ad-hoc testing and aimless clicking look identical from the outside &#8212; someone interacting with software without following a script. The difference is entirely internal: what&#8217;s happening in the tester&#8217;s mind.</p><p>A tester doing ad-hoc testing well is constantly making micro-decisions. <em>I&#8217;m going to try submitting this form with the required fields empty because the validation on the previous page was inconsistent.</em> That&#8217;s not random &#8212; it&#8217;s a hypothesis formed from an observation, tested through a deliberate action, and evaluated against expected behavior. They might not write any of this down in the moment, but they&#8217;re executing a rapid cycle of observe, hypothesize, test, evaluate. Over and over, with each action informed by the last.</p><p>A tester clicking aimlessly is doing something fundamentally different. <em>I&#8217;ll click this. Now I&#8217;ll click that. This seems fine. Let me go over here.</em> There&#8217;s no thread connecting the actions. No observations driving the next step. No mental model being built or challenged. It&#8217;s activity without cognition.</p><p>Three qualities distinguish effective ad-hoc testing:</p><p><strong>Observational awareness.</strong> Good ad-hoc testers notice things. Not just &#8220;the button worked&#8221; but &#8220;the button took 400 milliseconds longer to respond than the identical button on the previous page.&#8221; They&#8217;re actively monitoring the application&#8217;s behavior, not just checking whether it crashes.</p><p><strong>Responsive direction.</strong> Each action informs the next. If the tester notices that input validation seems lenient on one field, they immediately start probing other fields with the same approach. If a workflow handles errors gracefully in one scenario, they try to find a scenario where it doesn&#8217;t. The investigation evolves in real time based on what the system reveals.</p><p><strong>Internal narration.</strong> Even without formal documentation, good ad-hoc testers maintain an internal narrative: <em>I&#8217;m exploring this because I noticed that. This result suggests I should try that next. This area seems solid; I&#8217;ll move on to something I&#8217;m less confident about.</em> This narration is what makes the testing purposeful rather than random.</p><h2><strong>The Skills That Make Ad-Hoc Testing Work</strong></h2><p>Ad-hoc testing is often treated as the easiest form of testing &#8212; just click around and see what happens. In reality, it&#8217;s one of the most demanding. Without a charter to guide your attention or a script to tell you what&#8217;s next, you&#8217;re relying entirely on your own skills to produce value. Those skills need to be strong.</p><h2><strong>Domain Knowledge</strong></h2><p>You can&#8217;t follow your instincts about a system you don&#8217;t understand. The tester who found the network-switching bug in our opening story didn&#8217;t stumble onto it by luck &#8212; she knew enough about the application&#8217;s architecture to immediately understand why toggling networks would be dangerous. Domain knowledge turns random observations into testable hypotheses.</p><h2><strong>Technical Awareness</strong></h2><p>Understanding what&#8217;s happening beneath the interface &#8212; how data flows, where state is stored, which components talk to each other &#8212; lets you make smarter choices about what to probe. A tester who knows the application uses client-side caching will instinctively test scenarios where cached data might become stale. A tester without that knowledge won&#8217;t know to look.</p><h2><strong>Risk Intuition</strong></h2><p>Experienced testers develop a sense for where bugs hide. Complex integrations, recently changed code, features built under deadline pressure, areas where requirements were ambiguous &#8212; these are the places ad-hoc testing should gravitate toward. This risk sense isn&#8217;t magic; it&#8217;s pattern recognition built from years of finding bugs and understanding why they occurred.</p><h2><strong>Rapid Context Switching</strong></h2><p>Ad-hoc testing often requires following threads wherever they lead. You might start exploring the search function, notice something odd about pagination, follow that thread to discover a data loading issue, and then trace that back to an API response format problem. The ability to follow these investigative chains without losing track of where you&#8217;ve been &#8212; and to know when to follow a thread versus when to return to your original focus &#8212; is a skill that takes practice to develop.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Rkz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Rkz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2Rkz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2Rkz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2Rkz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Rkz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!2Rkz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2Rkz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2Rkz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2Rkz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b4fb50-733d-47ac-abe6-35d5af6daa6f_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Giving Ad-Hoc Testing Just Enough Structure</strong></h2><p>The paradox of ad-hoc testing done right is that it benefits from a small amount of structure &#8212; not enough to turn it into something else, but enough to ensure it produces value.</p><h2><strong>Set a Purpose, Not a Plan</strong></h2><p>Before starting, answer one question: <em>Why am I doing ad-hoc testing right now?</em> The answer might be &#8220;because a hotfix just dropped and I need to verify it,&#8221; or &#8220;because I have a nagging feeling about the profile section,&#8221; or &#8220;because we haven&#8217;t looked at this area with fresh eyes in weeks.&#8221; That purpose isn&#8217;t a charter &#8212; it&#8217;s a reason. It gives your session a seed of direction without constraining your exploration.</p><h2><strong>Time-Awareness Without Time-Boxing</strong></h2><p>You don&#8217;t need a formal 90-minute session boundary, but you should be aware of time. Set a soft checkpoint &#8212; &#8220;I&#8217;ll reassess after 30 minutes whether I&#8217;m finding anything worth continuing.&#8221; This prevents the two biggest ad-hoc testing failure modes: stopping too soon before you&#8217;ve found anything meaningful, and rabbit-holing for three hours on something that stopped being productive after twenty minutes.</p><h2><strong>Capture the Highlights</strong></h2><p>You don&#8217;t need session notes in the SBTM sense, but you should capture your key findings. This can be as simple as a quick message to the team channel: &#8220;Spent 20 minutes doing ad-hoc testing on the profile section. Found that changing your email while a password reset is pending locks you out of both flows. Filed as BUG-2847.&#8221; That single sentence transforms invisible testing into visible value.</p><p>The threshold for documentation should be low: if you found something worth knowing, capture it somewhere your team will see it. If you found nothing notable, a quick mental note of &#8220;I looked at X and it seemed solid&#8221; is sufficient.</p><h2><strong>Know When to Escalate to Structure</strong></h2><p>Sometimes ad-hoc testing reveals that an area needs much more attention than a quick exploration can provide. This is the moment to shift gears: &#8220;I started doing ad-hoc testing on the notifications feature and found three issues in ten minutes. This area needs dedicated charter-based sessions.&#8221; Recognizing when ad-hoc has served its purpose and formal exploration should take over is a sign of testing maturity.</p><h2><strong>Ad-Hoc Testing in Practice: Patterns That Work</strong></h2><p>Over time, experienced testers develop recurring ad-hoc testing patterns &#8212; approaches they reach for repeatedly because they consistently surface issues. These aren&#8217;t formal techniques so much as productive habits.</p><h2><strong>The &#8220;What If&#8221; Chain</strong></h2><p>Start with any normal action and then ask &#8220;what if&#8221; at every step. <em>What if I go back after submitting? What if I open this in two tabs? What if I change my timezone between starting and finishing this workflow? What if I paste in a value instead of typing it?</em> Each &#8220;what if&#8221; is a micro-experiment. Most will reveal nothing. But the chain often leads to unexpected territory that scripted tests never reach.</p><h2><strong>The Interruption Pattern</strong></h2><p>Use the application normally, but interrupt every workflow at unexpected points. Close the browser mid-save. Navigate away during a file upload. Hit the back button after submitting a form but before seeing the confirmation. Switch apps on mobile while a process is running. Real users interrupt workflows constantly &#8212; through impatience, accidental taps, network hiccups, or phone calls. Planned testing rarely accounts for all the ways these interruptions can cause trouble.</p><h2><strong>The Fresh Eyes Walk</strong></h2><p>Open the application as if you&#8217;ve never seen it before. Ignore what you know about how it&#8217;s supposed to work and just use it. Where do you get confused? Where does the interface suggest one thing but do another? Where do you have to read instructions to understand what should be obvious? This pattern is less about bugs and more about usability &#8212; but it regularly surfaces functional issues too, because confused users do unexpected things, and unexpected things expose unexpected bugs.</p><h2><strong>The Persona Shift</strong></h2><p>Stop testing as a tester and start using the application as a specific type of user. A first-time visitor who doesn&#8217;t understand the terminology. A power user who does everything with keyboard shortcuts. A distracted parent trying to complete a purchase while managing a toddler. An elderly user who reads every label carefully before clicking anything. Each persona naturally leads you to interact with the application differently, revealing issues that your tester habits might cause you to skip.</p><h2><strong>The Configuration Sweep</strong></h2><p>Change the conditions around the application rather than how you use it. Switch languages. Change the system font size. Enable dark mode. Use browser zoom at 150%. Set the date to December 31 at 11:58 PM. Turn on accessibility features like screen readers or high contrast mode. These environmental changes often expose issues that functional testing &#8212; which tends to assume a standard configuration &#8212; consistently misses.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5yp0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5yp0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5yp0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5yp0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5yp0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5yp0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!5yp0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5yp0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5yp0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5yp0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c76bde5-0bad-4dda-a4d8-b98150f25f87_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Accountability Challenge (And How to Solve It)</strong></h2><p>Let&#8217;s address the elephant in the room. The biggest objection to ad-hoc testing &#8212; and it&#8217;s a legitimate one &#8212; is accountability. How do you know what was tested? How do you justify the time spent? How do you prevent it from becoming a black hole where testing hours disappear without visible results?</p><p>These concerns are why SBTM exists in the first place. We spent an entire article on how session-based management solves the accountability problem for exploratory testing. Now we&#8217;re advocating for testing that deliberately sidesteps that accountability framework. This seems contradictory, and it would be if ad-hoc testing were meant to replace structured exploration. It isn&#8217;t. It supplements it.</p><p>Think of your testing strategy as a budget. Structured, chartered sessions should account for the majority of your exploratory testing time &#8212; let&#8217;s say 70&#8211;80%. That&#8217;s where your planned coverage, your risk-based targeting, and your measurable progress live. Ad-hoc testing should be a smaller, deliberate allocation &#8212; maybe 15&#8211;25% of your time. The remaining fraction goes to test maintenance, planning, and other activities.</p><p>The accountability solution for ad-hoc testing isn&#8217;t to apply full SBTM overhead to it &#8212; that would defeat its purpose. Instead, use lightweight mechanisms:</p><p><strong>A shared log.</strong> A simple shared document, team channel, or wiki page where testers drop one-line summaries of ad-hoc testing they&#8217;ve done. &#8220;2/14 &#8212; Sarah &#8212; 20 min ad-hoc on checkout after payment gateway update. Found currency rounding issue in edge case (BUG-3201). No other issues noted.&#8221;</p><p><strong>Bug attribution.</strong> When ad-hoc testing finds bugs, tag them. Knowing that 30% of your critical bugs were found through ad-hoc testing is a powerful argument for continuing the practice &#8212; and for giving testers the freedom to do it.</p><p><strong>Retrospective inclusion.</strong> In sprint retrospectives or testing reviews, include ad-hoc testing alongside structured sessions. &#8220;This sprint we completed 12 chartered sessions and testers spent approximately 8 hours on ad-hoc testing. The chartered sessions found 15 bugs; ad-hoc testing found 6, including 2 critical ones.&#8221; This makes the practice visible and its value measurable without burdening individual sessions with documentation overhead.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oL3a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oL3a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oL3a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oL3a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oL3a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oL3a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!oL3a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oL3a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oL3a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oL3a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5144e95-8406-4c3b-8051-12925ee27cdc_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Ad-Hoc Testing and AI: The Human Advantage</strong></h2><p>AI-powered testing tools are getting better at executing scripted scenarios, generating test cases from requirements, and even performing some forms of automated exploration. But ad-hoc testing represents something that AI fundamentally cannot replicate: the ability to notice that something <em>feels</em> wrong, to connect an observation in the current session with a conversation you overheard in the hallway last week, to think &#8220;a real user would never do it this way&#8221; and then test the way a real user actually would.</p><p>When AI generates code, the testing assumptions it produces will be internally consistent with that code. As we discussed in our charter writing article, this creates correlated blind spots. Ad-hoc testing driven by human intuition is perhaps the strongest countermeasure against these blind spots, because it&#8217;s fundamentally uncorrelated with the AI&#8217;s reasoning. The tester isn&#8217;t following the AI&#8217;s logic &#8212; they&#8217;re bringing their own entirely independent perspective.</p><p>This doesn&#8217;t mean ad-hoc testing should ignore AI capabilities. AI tools can actually enhance ad-hoc testing in useful ways: quickly generating test data when you need unusual inputs, summarizing recent code changes to inform your instincts about where to look, or helping you understand unfamiliar system components so your ad-hoc exploration is better informed. The key insight is that AI serves as a tool supporting human-directed ad-hoc testing, not as a replacement for the human judgment that drives it.</p><p>In an era where more code is generated by AI and more test cases are written by AI, the unscripted, intuition-driven investigation that a skilled human tester brings becomes not less important, but more. Your ability to test in ways that no algorithm anticipated is an increasingly rare and valuable skill.</p><h2><strong>Common Mistakes (And How to Avoid Them)</strong></h2><p>Ad-hoc testing has predictable failure modes. Knowing them helps you steer clear.</p><p><strong>Mistake: Using ad-hoc as a default instead of a choice.</strong> If every testing session is ad-hoc, you don&#8217;t have a strategy &#8212; you have a gap in process. Ad-hoc testing is most powerful when it complements structured testing, not when it substitutes for it. If you find yourself never writing charters or session reports, the problem isn&#8217;t that ad-hoc testing is your preferred style &#8212; it&#8217;s that you&#8217;re avoiding the discipline of planning.</p><p><strong>Mistake: Confusing thoroughness with duration.</strong> Spending four hours on ad-hoc testing doesn&#8217;t mean you tested four hours&#8217; worth of things. Without the natural rhythm of session time-boxes and debriefs, it&#8217;s easy to spiral into deep investigation of minor issues while major areas go unexplored. Check in with yourself regularly: is the thread I&#8217;m pulling still worth pulling?</p><p><strong>Mistake: Never recording anything.</strong> The belief that ad-hoc testing means zero documentation is a misunderstanding. It means <em>minimal</em> documentation &#8212; but not none. If you find a bug, report it. If you cover an area and it looks solid, note it somewhere. If you discover something that should inform future chartered sessions, capture that insight. The overhead should be light, but it shouldn&#8217;t be nonexistent.</p><p><strong>Mistake: Only doing the fun parts.</strong> Without a charter directing your attention, you&#8217;ll naturally gravitate toward features and scenarios that interest you &#8212; which are often the same ones you always test. Good ad-hoc testing deliberately pushes into uncomfortable or overlooked areas. Force yourself to explore the admin settings, the error pages, the edge cases that nobody finds exciting. That&#8217;s often where the bugs are hiding.</p><p><strong>Mistake: Not knowing when to stop.</strong> Ad-hoc testing without any time awareness can expand to fill all available time. Set soft boundaries. If you&#8217;ve been exploring for 30 minutes without finding anything notable, that&#8217;s useful information &#8212; the area might be solid, or your approach might need changing. Either way, don&#8217;t keep clicking out of obligation.</p><h2><strong>Building Ad-Hoc Testing Into Your Process</strong></h2><p>If ad-hoc testing is valuable, it shouldn&#8217;t depend on individual testers happening to do it. It should be a deliberate part of your testing process.</p><h2><strong>Scheduled Unstructured Time</strong></h2><p>This sounds contradictory &#8212; scheduling something unstructured &#8212; but it works. Reserve time each sprint specifically for ad-hoc testing. &#8220;Every Thursday afternoon, testers have two hours for ad-hoc exploration.&#8221; The time is allocated; how it&#8217;s used is up to each tester&#8217;s judgment. This legitimizes the practice and ensures it actually happens rather than being perpetually crowded out by planned work.</p><h2><strong>Post-Change Quick Checks</strong></h2><p>Build a team habit of brief ad-hoc testing after significant code changes land. Not a full chartered session &#8212; just ten or fifteen minutes of a tester poking around the affected area and its neighbors. This catches integration issues and unexpected side effects early, when they&#8217;re cheapest to fix.</p><h2><strong>New Feature Familiarization</strong></h2><p>Before writing charters for a new feature, have testers spend 20&#8211;30 minutes in unstructured exploration. This reconnaissance builds the understanding needed to write effective charters. It&#8217;s ad-hoc testing in service of structured testing &#8212; the two approaches reinforcing each other.</p><h2><strong>Bug Fix Verification Plus</strong></h2><p>When verifying bug fixes, encourage testers to spend a few extra minutes exploring the surrounding area. The fix might be correct, but did it introduce anything else? This &#8220;verification plus&#8221; habit catches regressions that formal regression testing might miss, because the tester is exploring with fresh context about what changed and why.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JrfH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JrfH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JrfH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JrfH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JrfH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JrfH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!JrfH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JrfH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JrfH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JrfH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b9c657c-1eb3-4e3c-84dc-101eec28eb1a_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Measuring What You Can&#8217;t Plan</strong></h2><p>You can&#8217;t measure ad-hoc testing the same way you measure chartered sessions. There&#8217;s no TDE/BIR/Setup breakdown, no coverage map, no charter completion percentage. But that doesn&#8217;t mean it&#8217;s immeasurable.</p><p>Track these indicators over time to understand whether your ad-hoc testing is delivering value:</p><p><strong>Bugs found per ad-hoc hour.</strong> Not to set targets &#8212; that would create perverse incentives &#8212; but to understand the practice&#8217;s productivity. If ad-hoc testing consistently finds zero bugs over multiple sprints, either your application is remarkably stable or your ad-hoc approach needs rethinking.</p><p><strong>Bug severity from ad-hoc vs. structured.</strong> In many teams, ad-hoc testing finds a disproportionate number of high-severity bugs relative to its time investment. This makes sense &#8212; ad-hoc testing gravitates toward unusual scenarios that planned testing doesn&#8217;t cover, and unusual scenarios are where critical failures often live.</p><p><strong>Areas covered.</strong> Even without formal coverage tracking, a shared log of ad-hoc testing activities shows which areas are getting attention and which aren&#8217;t. If every tester&#8217;s ad-hoc time gravitates toward the same features, you&#8217;re getting redundant coverage instead of breadth.</p><p><strong>Insights generated.</strong> Some of the most valuable output from ad-hoc testing isn&#8217;t bugs &#8212; it&#8217;s observations that inform future testing. &#8220;The offline mode seems fragile &#8212; we should write charters for a dedicated exploration&#8221; is worth more than the ad-hoc session that produced it.</p><h2><strong>Your Ad-Hoc Testing Quick-Start Guide</strong></h2><p>Ready to make ad-hoc testing a deliberate, valuable part of your practice? Here&#8217;s what you need.</p><pre><code>AD-HOC TESTING QUICK-START
============================

BEFORE YOU START
Purpose check: Why am I doing ad-hoc testing right now?
  [ ] Responding to a change or hotfix
  [ ] Following a hunch or intuition
  [ ] Learning an unfamiliar area
  [ ] Filling gaps in planned coverage
  [ ] Quick verification of a fix
  [ ] Scheduled unstructured time

Soft time limit: _____ minutes
(Reassess at this point-continue, stop, or escalate to
a chartered session)

DURING THE SESSION
Stay observant:
  - Notice response times, visual inconsistencies,
    unexpected behaviors
  - Follow threads when observations lead somewhere
  - Shift approaches when one angle stops producing
Ask yourself periodically:
  - Am I still finding useful information?
  - Should this become a chartered session?
  - Have I drifted into comfortable territory
    instead of pushing into unexplored areas?
AFTER THE SESSION
Capture the essentials:
  - Bugs found &#8594; file them, tag as ad-hoc
  - Areas explored &#8594; one-line summary to shared log
  - Insights for future testing &#8594; note them for
    charter planning
  - Nothing found &#8594; that&#8217;s useful data too-note
    the area seems stable

SHARED LOG ENTRY FORMAT
Date: _____
Tester: _____
Duration: _____ min
Area(s) explored: _____
Trigger: (hotfix / hunch / gap-fill / scheduled / other)
Findings: _____
Bugs filed: _____
Follow-up needed: Yes / No
Notes: _____</code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rtXR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rtXR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rtXR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rtXR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rtXR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rtXR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!rtXR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rtXR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rtXR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rtXR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962a4afc-11fc-4019-85f4-b2067d7182cb_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Right to Roam</strong></h2><p>There&#8217;s a concept in land access law called the &#8220;right to roam&#8221; &#8212; the public&#8217;s right to walk across open land without following designated paths. It exists because path networks, no matter how well-planned, can never cover every part of the landscape. Some discoveries only happen when you leave the trail.</p><p>Ad-hoc testing is the right to roam in your testing strategy. Your chartered sessions are the well-maintained paths &#8212; they cover the important routes, they&#8217;re documented, and they ensure consistent coverage. But the landscape of your application extends beyond those paths, and some of its most important features (and most dangerous bugs) exist in territory that no path was built to reach.</p><p>The testing teams that find the most bugs, build the deepest understanding of their applications, and provide the most reliable quality assessments are the ones that combine the discipline of structured exploration with the freedom of purposeful, skilled ad-hoc investigation. Not one or the other. Both, in deliberate proportion, each making the other more effective.</p><p>Don&#8217;t let anyone tell you that ad-hoc testing is unprofessional. And don&#8217;t let anyone tell you it&#8217;s sufficient on its own. Done right &#8212; with purpose, with skill, with just enough structure to stay accountable &#8212; it&#8217;s one of the most powerful tools in a tester&#8217;s kit.</p><p>In our next article, we&#8217;ll explore <strong>Monkey Testing Explained</strong> &#8212; what happens when you push even further past structure into deliberately random, chaotic interaction with your software. We&#8217;ll examine how random testing with genuine purpose reveals resilience problems that no amount of human logic would think to test, and where the line falls between productive chaos and wasted effort.</p><p><strong>Remember:</strong> Ad-hoc testing isn&#8217;t the absence of a plan &#8212; it&#8217;s the presence of a purpose.</p>]]></content:encoded></item><item><title><![CDATA[Test Charter Writing: Creating Focused Exploratory Missions]]></title><description><![CDATA[The Difference Between Exploration and Wandering]]></description><link>https://ryancraventech.substack.com/p/test-charter-writing-creating-focused</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/test-charter-writing-creating-focused</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Wed, 18 Feb 2026 12:21:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!X2A2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A tester sits down at her desk, coffee in hand, and opens the application. &#8220;I&#8217;m going to do some exploratory testing on the checkout flow,&#8221; she announces. Two hours later, her manager asks what she found. She pauses. She tested&#8230; things. She clicked around. She found a weird layout issue on the cart page, spent twenty minutes trying to reproduce a tooltip glitch that turned out to be her browser, and eventually got pulled into investigating whether the discount code field handles SQL injection. She can&#8217;t quite articulate what she covered, what she skipped, or whether the checkout flow is actually trustworthy.</p><p>Now picture a different tester. Same application, same checkout flow. But before she opens the browser, she writes a single sentence: <em>Explore the checkout flow with multiple discount codes applied simultaneously, using accounts with different membership tiers, to discover whether pricing calculations remain accurate under combination scenarios.</em> Forty-five minutes later, she&#8217;s found three genuine pricing bugs, documented exactly what she tested, and can confidently say which scenarios she covered and which still need attention.</p><p>The difference isn&#8217;t skill or experience. It&#8217;s a charter.</p><p>Test charters are the unsung workhorses of effective exploratory testing. They&#8217;re deceptively simple &#8212; often just a sentence or two &#8212; but they represent the critical line between exploration that discovers meaningful problems and aimless clicking that wastes everyone&#8217;s time. In our previous article on Session-Based Test Management, we introduced charters as the mission statements that launch each session. Now it&#8217;s time to master the craft of writing them. Because a charter isn&#8217;t just a label you slap on a session &#8212; it&#8217;s the decision that determines whether the next 90 minutes of testing will be focused, productive, and communicable, or scattered and forgettable.</p><p>This article is about writing charters that actually work &#8212; ones that focus your attention, guide your decisions in the moment, and produce results you can communicate clearly when the session ends.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!X2A2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!X2A2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!X2A2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!X2A2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!X2A2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!X2A2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!X2A2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!X2A2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!X2A2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!X2A2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcabb91fd-07c1-4b48-9d13-f9a3338522f7_788x440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What a Charter Actually Is (And Isn&#8217;t)</strong></h2><p>A test charter is a brief statement that defines the mission of an exploratory testing session. It answers three fundamental questions: What are you testing? How are you testing it? What are you looking for?</p><p>That&#8217;s it. Not a test plan. Not a requirements document. Not a script with predetermined steps. A charter is a compass heading &#8212; it tells you which direction to walk, but it doesn&#8217;t dictate every step.</p><p>This distinction matters because testers frequently confuse charters with other artifacts. A charter is not a test case with its steps removed. It&#8217;s not a vague aspiration like &#8220;test the login page.&#8221; And it&#8217;s not a detailed specification that leaves no room for judgment. It lives in a specific zone between too loose and too tight.</p><p>Think of it this way: if your &#8220;charter&#8221; could be executed identically by any two testers, it&#8217;s probably a script. If your &#8220;charter&#8221; could lead two testers to test completely different features with zero overlap, it&#8217;s probably too vague. A well-written charter will lead different testers through similar territory while allowing each to bring their own instincts, observations, and investigative paths to the work.</p><p>The power of a charter is in what it excludes as much as what it includes. By defining a focus area, you&#8217;re implicitly saying &#8220;not that other stuff &#8212; at least not right now.&#8221; This constraint is liberating. It frees the tester from the anxiety of trying to test everything and lets them go deep on something specific.</p><h2><strong>The Anatomy of an Effective Charter</strong></h2><p>In our SBTM article, we introduced charters as mission statements answering <em>what, why, and what&#8217;s in scope.</em> Now let&#8217;s get precise about structure. The most widely used charter format comes from James Bach&#8217;s work on exploratory testing, and it follows a three-part template:</p><p><strong>Explore</strong> (target) <strong>with</strong> (resources) <strong>to discover</strong> (information).</p><p>Each component plays a specific role. The <em>target</em> identifies what part of the system you&#8217;re testing. The <em>resources</em> describe the tools, techniques, data, or approaches you&#8217;ll use. The <em>information</em> specifies what kind of findings you&#8217;re after &#8212; what questions you&#8217;re trying to answer.</p><p>Here&#8217;s a concrete example: <em>Explore the user profile editing page with boundary values and special characters in all text fields to discover input validation weaknesses and error handling gaps.</em></p><p>Let&#8217;s break that apart. The target is specific &#8212; not &#8220;the user module&#8221; but &#8220;the user profile editing page.&#8221; The resources are defined &#8212; boundary values and special characters, which tells the tester what techniques to employ. The information goal is clear &#8212; we&#8217;re hunting for validation weaknesses and error handling gaps, not performance issues or visual bugs (though if those appear, they&#8217;re still worth noting).</p><p>Compare that to a weak charter: <em>Test user profiles.</em> This tells the tester almost nothing. Which aspect of user profiles? Using what approach? Looking for what? A tester receiving this charter has to make all the important decisions on their own, which defeats the purpose of having a charter at all.</p><p>Now compare it to an overly rigid charter: <em>Navigate to the profile page, enter exactly 256 characters in the first name field, verify an error appears, then enter a script tag in the bio field and verify it&#8217;s sanitized.</em> This isn&#8217;t a charter &#8212; it&#8217;s a test case pretending to be one. There&#8217;s no room for the tester to follow interesting leads or apply their own judgment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w4E5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w4E5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w4E5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w4E5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w4E5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w4E5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!w4E5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w4E5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w4E5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w4E5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F869c7e14-ab80-4e3d-a1c7-092337ea8db0_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Charter Scope: The Goldilocks Problem</strong></h2><p>Getting the scope right is the hardest part of charter writing. Too narrow and you&#8217;ve written a test case. Too broad and you&#8217;ve written a wish. The goal is a scope that can be meaningfully explored in a single session &#8212; typically the 60 to 120 minute window we established in our SBTM framework.</p><p>Here&#8217;s a practical test: read your charter and imagine starting the session. Can you picture at least five or six different things you&#8217;d try? If not, the charter might be too narrow. Can you imagine spending an entire week on it and still not being done? If so, it&#8217;s too broad.</p><p><strong>Too broad:</strong> <em>Explore the application to discover bugs.</em> This isn&#8217;t a charter; it&#8217;s a job description.</p><p><strong>Too broad:</strong> <em>Explore the e-commerce platform with various user types to discover usability issues.</em> Which part of the platform? What do you mean by &#8220;various&#8221;? What kinds of usability issues?</p><p><strong>Too narrow:</strong> <em>Explore the login page by entering &#8220;admin&#8221; as username and &#8220;password&#8221; as password to discover if default credentials work.</em> This is a single test case, not a session charter.</p><p><strong>Just right:</strong> <em>Explore the login and authentication flow with expired, revoked, and near-expiration credentials to discover how the system communicates authentication failures to users.</em></p><p>That last one works because it defines a focused area (login and authentication), specifies an approach (various problematic credential states), and names a clear information goal (communication of failures). A tester could spend 90 minutes on this and explore dozens of scenarios while staying focused on a coherent theme.</p><p>One useful heuristic: a well-scoped charter should generate a mental list of &#8220;oh, and I should also try&#8230;&#8221; moments when you read it. If reading the charter sparks ideas about variations, edge cases, and what-ifs, the scope is working. If it sparks only one obvious action or an overwhelming flood of unrelated possibilities, adjust accordingly.</p><h2><strong>Writing Charters for Different Testing Goals</strong></h2><p>Not all testing sessions have the same objective, and your charters should reflect this. Different goals demand different charter structures.</p><h2><strong>Risk-Based Charters</strong></h2><p>When you know where the danger is, write charters that target it directly. Risk-based charters focus on areas where failures would cause the most damage or where changes have introduced the most uncertainty.</p><p><em>Explore the payment processing flow with international credit cards and currency conversion to discover calculation accuracy issues that could result in incorrect charges.</em></p><p>Notice how this charter connects the testing activity directly to business risk. The tester isn&#8217;t just finding bugs &#8212; they&#8217;re investigating a specific category of failure that has real financial consequences.</p><h2><strong>Technique-Based Charters</strong></h2><p>Sometimes you want to apply a specific testing technique systematically across a feature area. These charters lead with the method.</p><p><em>Explore the appointment scheduling calendar with state transition analysis &#8212; moving appointments through every possible status change sequence &#8212; to discover states that become unreachable or transitions that corrupt data.</em></p><p>The technique (state transition analysis) drives the session while the target and goal keep it focused.</p><h2><strong>User-Scenario Charters</strong></h2><p>These simulate real-world usage patterns, often combining multiple features the way actual users would.</p><p><em>Explore the end-to-end order process as a returning customer with saved payment methods and address book entries, using a mix of in-stock and backordered items, to discover workflow friction and data consistency issues across the purchase journey.</em></p><p>These tend to be broader in scope but are held together by the coherence of the user story.</p><h2><strong>Regression-Focused Charters</strong></h2><p>After changes to the codebase, you need charters that explore the blast radius of those changes. This aligns naturally with the progressive coverage model from SBTM &#8212; these charters typically come in the follow-up and confirmation phases.</p><p><em>Explore features adjacent to the recently refactored inventory service &#8212; product display, cart calculations, and order confirmation &#8212; with scenarios that trigger real-time inventory checks to discover integration failures or behavior changes introduced by the refactoring.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!plS9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!plS9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!plS9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!plS9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!plS9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!plS9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!plS9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!plS9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!plS9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!plS9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72ecd49-fade-4402-b69a-65729948d66b_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The &#8220;To Discover&#8221; Clause: Where Most Charters Fail</strong></h2><p>If there&#8217;s one place charters consistently break down, it&#8217;s the information goal. Testers nail the target and resources but then write vague discovery clauses that don&#8217;t actually guide the session.</p><p>Consider these two charters:</p><p><em>Explore the search functionality with long and complex queries to discover <strong>bugs</strong>.</em></p><p><em>Explore the search functionality with long and complex queries to discover <strong>how the system degrades &#8212; whether it slows down, truncates input, returns irrelevant results, or fails silently &#8212; as query complexity increases</strong>.</em></p><p>The first charter sends the tester out with a butterfly net, hoping to catch something. The second charter tells the tester exactly what to observe and what degradation patterns to look for. Both testers might find the same bugs, but the second tester will find them faster, describe them more precisely, and recognize subtle issues that the first tester might dismiss.</p><p>Strong discovery clauses share a few characteristics. They name specific types of information, not just &#8220;bugs&#8221; or &#8220;issues.&#8221; They describe observable behaviors the tester should watch for. And they frame the investigation as a question the session should answer, even if the answer turns out to be &#8220;everything works fine here.&#8221;</p><p>Here are some transformations from weak to strong:</p><p><strong>Weak:</strong> <em>&#8230;to discover problems.</em> <strong>Strong:</strong> <em>&#8230;to discover whether error messages accurately describe what went wrong and guide the user toward resolution.</em></p><p><strong>Weak:</strong> <em>&#8230;to discover if it works.</em> <strong>Strong:</strong> <em>&#8230;to discover how the system behaves when the user&#8217;s session expires mid-transaction &#8212; whether data is preserved, lost, or partially saved.</em></p><p><strong>Weak:</strong> <em>&#8230;to discover security issues.</em> <strong>Strong:</strong> <em>&#8230;to discover whether authenticated API endpoints properly reject requests with manipulated user IDs, expired tokens, or privilege escalation attempts.</em></p><p>The pattern is consistent: strong discovery clauses describe <em>what you&#8217;ll observe</em> and <em>what patterns you&#8217;re looking for</em>, not just <em>what category of problem you hope to find</em>.</p><h2><strong>Writing Charters from Different Sources</strong></h2><p>Charters don&#8217;t materialize from thin air. They&#8217;re derived from information you already have &#8212; you just need to know how to translate that information into focused missions.</p><h2><strong>From Requirements and User Stories</strong></h2><p>Take a user story like: <em>As a user, I want to reset my password so I can regain access to my account.</em></p><p>A requirements-based charter might be: <em>Explore the password reset flow with various account states &#8212; locked, unverified, recently changed password, multiple failed reset attempts &#8212; to discover edge cases where users get stuck without a path back to their account.</em></p><p>The charter goes beyond verifying the happy path. It uses the requirement as a starting point but then asks: what could go wrong for real users in real situations?</p><h2><strong>From Bug Reports</strong></h2><p>Previous bugs are gold mines for charter writing. A bug report about a timezone issue in scheduling might generate: <em>Explore the appointment scheduling system with users in different timezones, including half-hour offset zones and daylight saving transition dates, to discover whether time display and calculation remain consistent across all timezone scenarios.</em></p><h2><strong>From Production Data and Analytics</strong></h2><p>If your analytics show that 15% of users abandon the checkout flow at the shipping address step, that&#8217;s a charter waiting to happen: <em>Explore the shipping address entry and validation step with international addresses, autofill tools, and address correction scenarios to discover friction points that could explain the high abandonment rate at this step.</em></p><h2><strong>From Code Changes</strong></h2><p>This source connects directly to the charter backlog concept from SBTM. As code changes come in, they should generate charters that feed into your session planning. A pull request touching the notification service suggests: <em>Explore all notification-triggering events &#8212; order confirmation, shipping updates, password changes, account alerts &#8212; to discover whether notifications fire correctly, contain accurate information, and handle delivery failures gracefully after the recent notification service updates.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4O5V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4O5V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4O5V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4O5V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4O5V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4O5V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!4O5V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4O5V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4O5V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4O5V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd66636a8-e927-480f-bb91-acbce4bf7c59_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Charter Decomposition: Breaking Big Ideas Into Testable Sessions</strong></h2><p>One of the most common charter-writing mistakes is trying to cram too much into a single session. &#8220;Explore the entire admin panel&#8221; isn&#8217;t a charter &#8212; it&#8217;s a project. You need to decompose large testing areas into multiple focused charters that together provide comprehensive coverage.</p><p>The decomposition process follows a natural hierarchy. Start with the broad area, identify its major aspects, and then write individual charters for each at a scope appropriate for a single session.</p><p>Take &#8220;test the reporting module&#8221; as a starting point. You might decompose it like this:</p><p><strong>Charter 1:</strong> <em>Explore report generation with the maximum data range (full year, all departments) to discover performance limits and timeout behavior under heavy data loads.</em></p><p><strong>Charter 2:</strong> <em>Explore report filtering and parameter combinations &#8212; applying multiple filters simultaneously, using conflicting date ranges, selecting then deselecting options &#8212; to discover whether filter interactions produce accurate or misleading results.</em></p><p><strong>Charter 3:</strong> <em>Explore report export functionality across all formats (PDF, CSV, Excel) with reports containing special characters, large datasets, and complex formatting to discover data fidelity and formatting issues in exported files.</em></p><p><strong>Charter 4:</strong> <em>Explore report scheduling and automated delivery with various recipient configurations, timezone settings, and frequency options to discover reliability and accuracy of the automation features.</em></p><p>Each charter is a focused, session-sized mission. Together, they provide thorough coverage of the reporting module. Individually, each one gives a tester clear direction and purpose. And when tracked on your SBTM session sheet, these four charters give your team a clear picture of how thoroughly the reporting module has been explored.</p><p>A useful decomposition strategy is to think in dimensions: data dimensions (volume, variety, edge cases), user dimensions (roles, permissions, experience levels), technical dimensions (browsers, devices, network conditions), and workflow dimensions (common paths, alternative paths, error paths). Each dimension can generate its own charter or set of charters.</p><h2><strong>Charters and AI-Generated Code: A Modern Necessity</strong></h2><p>Here&#8217;s where charter writing becomes particularly urgent. When code is generated or heavily assisted by AI tools, the assumptions baked into that code may be subtly wrong in ways that scripted test cases &#8212; often generated by the same AI &#8212; won&#8217;t catch. Charter-based exploratory testing becomes your best defense against correlated failures between AI-generated code and AI-generated tests.</p><p>Consider this scenario: a development team uses an AI assistant to generate a new user registration flow and then uses the same or similar AI to generate test cases. The AI&#8217;s model of &#8220;how registration should work&#8221; will be internally consistent &#8212; the tests will validate the code&#8217;s behavior even if that behavior doesn&#8217;t match actual business rules, edge cases, or user expectations. Both the code and the tests share the same blind spots.</p><p>A well-written exploratory charter breaks this pattern by bringing human judgment, domain knowledge, and genuine curiosity to the testing process. An effective charter for AI-generated code might look like: <em>Explore the AI-generated registration flow with real-world input patterns &#8212; names with hyphens and apostrophes, international phone formats, corporate email domains with strict validation &#8212; to discover assumptions the AI made about user data that don&#8217;t match actual usage.</em></p><p>When writing charters specifically for AI-generated features, focus your &#8220;to discover&#8221; clause on assumptions and unstated requirements &#8212; the things AI tools handle well in the average case but often get wrong at the margins.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eR7I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eR7I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!eR7I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!eR7I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!eR7I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eR7I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!eR7I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!eR7I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!eR7I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!eR7I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F539d9679-3bd6-47ba-aca3-473e48d143e7_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Common Charter Anti-Patterns</strong></h2><p>Knowing what bad looks like helps you avoid writing it. Here are the patterns that consistently produce ineffective charters.</p><p><strong>The Everything Charter:</strong> <em>Explore the application with all testing techniques to discover all types of issues.</em> This isn&#8217;t focus &#8212; it&#8217;s the absence of focus wearing a charter&#8217;s clothing. If your charter could apply to literally any software product, it&#8217;s too generic.</p><p><strong>The Predetermined Outcome:</strong> <em>Explore the login page to discover that it rejects invalid passwords.</em> This isn&#8217;t exploration &#8212; it&#8217;s a pass/fail check. If you already know what you expect to find, you&#8217;ve written a test case, not a charter.</p><p><strong>The Tool Charter:</strong> <em>Explore the application with Postman to discover API issues.</em> The tool isn&#8217;t the point. What are you trying to learn? <em>Explore the user-facing workflows while monitoring corresponding API calls in Postman to discover discrepancies between what the UI shows and what the API actually returns.</em> Now the tool serves the mission rather than defining it.</p><p><strong>The Vague Wanderer:</strong> <em>Explore some parts of the settings page.</em> Which parts? Why? Looking for what? This charter provides no more guidance than &#8220;go test stuff.&#8221;</p><p><strong>The Scope Creeper:</strong> A charter that starts focused but includes &#8220;also check&#8221; clauses that expand it beyond a single session. <em>Explore the search function with special characters to discover input handling issues. Also check pagination, sorting, filter combinations, and performance under load.</em> That&#8217;s four charters masquerading as one.</p><h2><strong>From Charter to Session: The Handoff</strong></h2><p>Understanding how a charter translates into action helps you write better ones.</p><p>When a tester picks up a well-written charter, their mental process should go something like this: First, they read the target and orient themselves &#8212; opening the right part of the application, setting up the right environment or test data. Then they read the resources clause and begin planning their first few moves &#8212; what inputs they&#8217;ll try, what tools they&#8217;ll set up, what conditions they&#8217;ll create. Finally, they internalize the discovery clause so they know what to observe, what to document, and what patterns to watch for as they explore.</p><p>During the session, the charter acts as a gentle constraint. When the tester discovers something interesting but tangential &#8212; say, they&#8217;re testing search behavior and notice a visual glitch in the header &#8212; the charter helps them make a quick decision: note it, log a brief observation, and return to the mission. Without a charter, that glitch might lead to twenty minutes of unplanned CSS investigation.</p><p>This is a critical point: charters don&#8217;t forbid you from noticing things outside your scope. They give you a framework for deciding how much time to invest in unexpected findings. You might spend two minutes confirming the glitch is reproducible and noting it for a future session, then return to your charter&#8217;s focus. That&#8217;s discipline informed by flexibility &#8212; exactly what good exploratory testing looks like.</p><p>The charter also shapes how you document as you go. The session notes you capture &#8212; which feed into the session reports we covered in our SBTM article &#8212; naturally organize around the charter&#8217;s structure. What you tested maps to the target and resources. What you found maps to the discovery clause. What&#8217;s left maps to the aspects of the charter you didn&#8217;t reach. This alignment isn&#8217;t accidental &#8212; it&#8217;s one of the strongest arguments for investing time in charter quality.</p><h2><strong>Building a Charter Library</strong></h2><p>Over time, your team should build a library of effective charter patterns that can be adapted and reused. This isn&#8217;t about running the same sessions repeatedly &#8212; it&#8217;s about having proven templates you can customize for new features and contexts.</p><p>A useful charter library is organized by testing concern rather than by feature:</p><pre><code>CHARTER LIBRARY CATEGORIES
===========================

INPUT VALIDATION PATTERNS
- Boundary values in [target fields]
- Special characters and encoding in [target]
- International/localized data in [target]

STATE AND WORKFLOW PATTERNS
- Interrupted transactions in [target flow]
- State transition coverage in [target]
- Concurrent user actions in [target]

INTEGRATION PATTERNS
- Data consistency across [system A] and [system B]
- API/UI behavior alignment in [target feature]
- Third-party service failure handling in [target]

PERFORMANCE AND RESILIENCE PATTERNS
- Behavior under slow/intermittent connectivity in [target]
- Large data volume handling in [target]
- Resource exhaustion scenarios in [target]

USER EXPERIENCE PATTERNS
- First-time user journey through [target]
- Error recovery paths in [target]
- Accessibility and assistive technology in [target]</code></pre><p>Each pattern becomes a template. When a new feature ships, you pull relevant patterns, fill in the specific target and discovery details, and you have a set of focused charters ready to go. This dramatically reduces the overhead of charter writing and ensures consistent coverage across features &#8212; feeding directly into the coverage mapping and tracking that SBTM provides.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!l_LS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!l_LS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!l_LS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!l_LS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!l_LS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!l_LS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!l_LS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!l_LS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!l_LS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!l_LS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0cca06e-db79-434d-8e1e-571c7e328b39_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>A Practical Charter-Writing Exercise</strong></h2><p>Here&#8217;s something you can do right now to build your charter-writing skill. Pick any feature in an application you test regularly. Set a timer for ten minutes. Write five charters for that feature, each targeting a different dimension of quality.</p><p>Use this template to get started:</p><pre><code>CHARTER WRITING EXERCISE
=========================
Feature/Area: <strong>________________________________________</strong>
Date: <strong>________</strong>

CHARTER 1 - Functionality Focus
Explore <strong>________________</strong><em>_ with <strong>________________</strong>_</em>
to discover <strong>________________</strong><em>_

CHARTER 2 - Data/Input Focus
Explore <strong>________________</strong>_</em> with <strong>________________</strong><em>_
to discover <strong>________________</strong>_</em>

CHARTER 3 - User Experience Focus
Explore <strong>________________</strong><em>_ with <strong>________________</strong>_</em>
to discover <strong>________________</strong><em>_

CHARTER 4 - Error Handling Focus
Explore <strong>________________</strong>_</em> with <strong>________________</strong><em>_
to discover <strong>________________</strong>_</em>

CHARTER 5 - Integration/Boundary Focus
Explore <strong>________________</strong><em>_ with <strong>________________</strong>_</em>
to discover <strong>________________</strong><em>_


SELF-REVIEW
-----------
For each charter, check:
[ ] Could I start this session right now and know what to do?
[ ] Is the scope achievable in 60-90 minutes?
[ ] Would two different testers cover similar ground?
[ ] Is the discovery clause specific about what to observe?
[ ] Does it leave room for the tester&#8217;s judgment and instincts?</em></code></pre><p>After writing your five charters, read each one and ask: if I handed this to a colleague with no other context, could they run a productive session? If the answer is no, revise until it&#8217;s yes.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-gXl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-gXl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-gXl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-gXl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-gXl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-gXl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!-gXl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-gXl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-gXl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-gXl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3edee08-d5ac-49f1-894c-1727cf3a37df_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Charters as Communication Tools</strong></h2><p>Beyond guiding sessions, charters serve a vital communication function. When a manager asks &#8220;what are we testing this sprint?&#8221; a set of well-written charters provides a clearer answer than &#8220;we&#8217;re doing exploratory testing on the new features.&#8221;</p><p>Compare these two responses to &#8220;what testing is planned?&#8221;</p><p><strong>Response A:</strong> &#8220;We&#8217;re going to explore the new dashboard.&#8221;</p><p><strong>Response B:</strong> &#8220;We have six sessions planned. Charter 1 targets the data refresh mechanism under heavy load. Charter 2 explores widget configuration with conflicting display settings. Charter 3 examines role-based access across the five user permission levels. Charters 4 through 6 cover the export, sharing, and notification features respectively.&#8221;</p><p>Response B demonstrates planning, communicates scope, and builds confidence that testing will be thorough. The charters themselves become a lightweight test plan that stakeholders can review, question, and influence. &#8220;I notice you don&#8217;t have a charter for offline behavior &#8212; that&#8217;s a big concern for our mobile users&#8221; is exactly the kind of feedback that charters make possible.</p><p>This connects to a point we made in the SBTM article about stakeholder communication: different audiences need different levels of detail. Your charter backlog gives developers specific focus areas, gives product managers coverage visibility, and gives executives confidence that testing is systematic. The charters are the same &#8212; the conversation around them adapts to the audience.</p><h2><strong>Start Writing Better Charters Tomorrow</strong></h2><p>Charter writing is a skill, which means it improves with practice. You don&#8217;t need permission, process changes, or new tools. You just need to write a charter before your next exploratory session and notice the difference it makes.</p><p>Start with the template: <em>Explore [target] with [resources] to discover [information].</em> Make each component specific enough to guide action and flexible enough to allow discovery. Read it back and ask whether you could hand it to a peer and have them run a productive session. If the answer is yes, you have a charter. If the answer is no, sharpen it until you do.</p><p>The difference between a tester who writes good charters and one who doesn&#8217;t isn&#8217;t the bugs they find today &#8212; it&#8217;s the consistency, communicability, and cumulative coverage they build over weeks and months. Good charters make good sessions. Good sessions, tracked through the SBTM framework, make good testing. And good testing is what stands between your users and the bugs that would otherwise reach them undetected.</p><p>In our next article, we&#8217;ll explore <strong>Ad-Hoc Testing Done Right</strong> &#8212; why unstructured testing has a legitimate place in your strategy and how to ensure it adds value instead of chaos. After two articles on structured approaches to exploratory testing, we&#8217;ll make the case that sometimes the most productive thing a tester can do is throw away the charter entirely &#8212; but only if they know when and how.</p><p><strong>Remember:</strong> A charter isn&#8217;t a constraint on exploration &#8212; it&#8217;s what transforms wandering into discovery.</p>]]></content:encoded></item><item><title><![CDATA[Session-Based Test Management]]></title><description><![CDATA[Organizing exploratory testing effectively]]></description><link>https://ryancraventech.substack.com/p/session-based-test-management</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/session-based-test-management</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Mon, 16 Feb 2026 12:21:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gyIh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<blockquote><p><em>&#8220;So what did you actually test today?&#8221;</em></p></blockquote><p>The question hung in the air. The tester had spent six hours doing exploratory testing. She&#8217;d found three bugs, submitted the reports, and felt productive. But when the test manager asked for specifics &#8212; what areas were covered, what wasn&#8217;t tested yet, how much more time was needed &#8212; she struggled to answer.</p><blockquote><p><em>&#8220;I tested&#8230; a lot of things. I explored the checkout flow. And the user profile. And some other areas.&#8221;</em></p><p><em>&#8220;Which parts of checkout? What about payment edge cases? Did you cover the new discount feature?&#8221;</em></p></blockquote><p>Silence.</p><p>This is the accountability problem with exploratory testing. When testing is unscripted, how do you track what&#8217;s been done? How do you report progress? How do you know when you&#8217;re finished? How do you coordinate multiple testers without duplicating effort or leaving gaps?<br></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><p><em><strong><br>Session-Based Test Management (SBTM)</strong></em> solves these problems.</p><p>Developed by Jon and James Bach in the early 2000s, SBTM provides a framework that brings structure and accountability to exploratory testing without sacrificing the freedom that makes it powerful. It&#8217;s not about controlling testers &#8212; it&#8217;s about making their work visible, measurable, and manageable.</p><p>Today we&#8217;re examining how SBTM works, why it matters, and how to implement it in your own testing practice.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gyIh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gyIh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gyIh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gyIh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gyIh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gyIh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gyIh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gyIh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gyIh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gyIh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49e82c42-178a-4ba8-bf14-d491f335cf5d_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Is Session-Based Test Management?</strong></h2><p>Session-Based Test Management is a method for organizing, tracking, and measuring exploratory testing through defined sessions with clear structures and deliverables.</p><p>The core concept is simple: instead of open-ended &#8220;exploratory testing,&#8221; you conduct discrete <strong>sessions</strong> &#8212; focused blocks of uninterrupted testing time with a specific mission, documented results, and measurable metrics.</p><p><strong>The key components:</strong></p><ul><li><p><strong>Sessions:</strong> Time-boxed periods of exploratory testing, typically 60&#8211;120 minutes, with a defined focus.</p></li><li><p><strong>Charters:</strong> Mission statements that describe what each session will investigate and why.</p></li><li><p><strong>Session Reports:</strong> Documentation of what was tested, what was found, and what remains to be done.</p></li><li><p><strong>Debriefs:</strong> Conversations between testers and managers to review session results and plan next steps.</p></li><li><p><strong>Metrics:</strong> Quantitative measures of testing progress and coverage.</p></li></ul><p>SBTM doesn&#8217;t change how you explore. It changes how you organize, track, and communicate that exploration. The testing itself remains creative and adaptive. The management wrapper makes it accountable and visible.</p><p>Think of it as jazz with a setlist. The musicians still improvise &#8212; that&#8217;s the whole point. But they know which songs they&#8217;re playing, how long each set lasts, and they can tell the audience what to expect.</p><h2><strong>The Anatomy of a Session</strong></h2><p>A session is the atomic unit of SBTM. Understanding its structure is essential.</p><h2><strong>Time-Boxing</strong></h2><p>Sessions have defined durations. The standard is 90 minutes, but sessions can range from 45 to 120 minutes depending on context.</p><p>Why time-boxing matters:</p><ul><li><p><strong>Focus:</strong> Limited time forces concentrated attention. You can&#8217;t wander indefinitely.</p></li><li><p><strong>Manageability:</strong> Fixed durations make planning and tracking straightforward.</p></li><li><p><strong>Natural breakpoints:</strong> Time boundaries create moments for documentation, reflection, and redirection.</p></li><li><p><strong>Sustainable pace:</strong> Intense exploration is mentally taxing. Time-boxes prevent burnout.</p></li></ul><p>The 90-minute standard isn&#8217;t arbitrary &#8212; it aligns with natural cognitive rhythms. Attention degrades after about 90 minutes of intense focus. Shorter sessions may not allow deep investigation. Longer sessions lead to fatigue and diminishing returns.</p><h2><strong>The Charter</strong></h2><p>Every session begins with a charter &#8212; a mission statement that defines the session&#8217;s purpose. A charter answers: What are we investigating? Why does it matter? What areas are in scope?</p><p>Good charters provide direction without dictating actions. They&#8217;re focused enough to guide exploration but open enough to allow discovery.</p><p>We&#8217;ll dive deep into charter writing in our next article. For now, understand that the charter is your session&#8217;s compass &#8212; it keeps you oriented without prescribing your exact path.</p><h2><strong>Session Execution</strong></h2><p>During the session, the tester explores according to the charter, taking notes continuously.</p><p>Session notes capture:</p><ul><li><p><strong>Test notes:</strong> What you tested and how. What variations you tried. What paths you followed.</p></li><li><p><strong>Bug notes:</strong> Issues discovered, with enough detail to reproduce or investigate further.</p></li><li><p><strong>Issue notes:</strong> Concerns, questions, or potential problems that aren&#8217;t confirmed bugs.</p></li><li><p><strong>Setup notes:</strong> Time spent on preparation, configuration, or blocked waiting for systems.</p></li></ul><p>These notes don&#8217;t need to be formal. They need to be useful &#8212; capturing enough information to reconstruct what happened and support meaningful debriefs.</p><h2><strong>The Session Report</strong></h2><p>After the session, notes become a session report &#8212; a structured summary of the session&#8217;s work and findings.</p><p><strong>Standard session report elements:</strong></p><ul><li><p><strong>Charter:</strong> The mission that guided the session.</p></li><li><p><strong>Tester:</strong> Who conducted the session.</p></li><li><p><strong>Date and duration:</strong> When and how long.</p></li><li><p><strong>Coverage:</strong> What areas, features, or scenarios were explored.</p></li><li><p><strong>Test notes summary:</strong> Key observations and approaches.</p></li><li><p><strong>Bugs found:</strong> List of issues discovered (with references to detailed bug reports).</p></li><li><p><strong>Issues:</strong> Concerns or questions requiring follow-up.</p></li><li><p><strong>Continuation:</strong> What remains to explore in future sessions.</p></li><li><p><strong>Metrics:</strong> Time allocation (see below).</p></li></ul><p>This report makes the session&#8217;s work visible and creates an artifact for tracking overall testing progress.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LFD4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LFD4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LFD4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LFD4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LFD4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LFD4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!LFD4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LFD4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LFD4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LFD4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F857d0497-93a4-45b8-b36d-015be1128051_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Session Metrics: Making Exploration Measurable</strong></h2><p>One of SBTM&#8217;s most valuable contributions is bringing metrics to exploratory testing. These metrics enable planning, tracking, and reporting without constraining the exploration itself.</p><h2><strong>Time Allocation Categories</strong></h2><p>During sessions, time is categorized into three buckets:</p><h3><strong>Test Design and Execution (TDE):</strong></h3><p>Time spent actually testing &#8212; exploring, investigating, executing test ideas.</p><h3><strong>Bug Investigation and Reporting (BIR):</strong></h3><p>Time spent documenting bugs, investigating issues, and writing reports.</p><h3><strong>Setup and Administration (Setup):</strong></h3><p>Time spent on preparation, environment configuration, waiting for systems, or dealing with blockers.</p><p>At the session&#8217;s end, testers estimate the percentage of time in each category:</p><p><em>Example: 75% TDE, 15% BIR, 10% Setup</em></p><h2><strong>Why These Metrics Matter</strong></h2><p><strong>TDE percentage</strong> indicates how much actual testing happened. Low TDE suggests environment problems, blockers, or inefficiencies that need addressing.</p><p><strong>BIR percentage</strong> indicates bug density. High BIR suggests the area has many issues. It also flags sessions where more bugs were found than could be fully investigated.</p><p><strong>Setup percentage</strong> indicates friction. Consistently high setup suggests tooling or environment improvements needed.</p><p>Over time, these metrics reveal patterns. A tester averaging 40% setup time needs better tooling. A feature generating 30% BIR time is bug-dense and needs attention.</p><h2><strong>Coverage Metrics</strong></h2><p>Beyond time allocation, SBTM tracks coverage:</p><ul><li><p><strong>Sessions completed:</strong> How many sessions have been conducted in each area?</p></li><li><p><strong>Charter completion:</strong> What percentage of planned charters have been executed?</p></li><li><p><strong>Risk coverage:</strong> Have high-risk areas received adequate session attention?</p></li><li><p><strong>Coverage gaps:</strong> What areas haven&#8217;t been explored yet?</p></li></ul><p>These metrics answer the critical questions: How much testing have we done? How much remains? Where are the gaps?</p><h2><strong>Bug Metrics</strong></h2><p>SBTM also enables bug analysis:</p><p><strong>Bugs per session:</strong> How many issues is exploration finding?</p><p><strong>Bug clustering:</strong> Which areas are yielding the most bugs?</p><p><strong>Bug severity distribution:</strong> Are we finding critical issues or minor ones?</p><p>Tracking bugs per session over time shows whether exploration is still productive or reaching diminishing returns.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2iRO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2iRO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2iRO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2iRO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2iRO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2iRO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!2iRO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2iRO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2iRO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2iRO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45133d40-7a07-4a05-80ca-5eb5ae21bd24_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Debrief: Where Learning Happens</strong></h2><p>Sessions produce findings. Debriefs transform findings into insight.</p><p>A debrief is a conversation between the tester and a reviewer (often a test lead or manager) about what happened in the session. It&#8217;s not an interrogation or status check &#8212; it&#8217;s a collaborative discussion that benefits both parties.</p><h2><strong>Why Debriefs Matter</strong></h2><p><strong>For the tester:</strong></p><ul><li><p>Articulating findings deepens understanding</p></li><li><p>External perspective catches things you missed</p></li><li><p>Guidance helps plan next steps</p></li><li><p>Recognition of good work motivates</p></li></ul><p><strong>For the reviewer:</strong></p><ul><li><p>Real-time insight into testing progress</p></li><li><p>Early warning of problems or risks</p></li><li><p>Understanding of what coverage exists</p></li><li><p>Information for stakeholder communication</p></li></ul><p><strong>For the team:</strong></p><ul><li><p>Knowledge sharing across testers</p></li><li><p>Identification of patterns across sessions</p></li><li><p>Coordination of coverage</p></li><li><p>Continuous process improvement</p></li></ul><h2><strong>The Debrief Conversation</strong></h2><p>A typical debrief covers:</p><ul><li><p><strong>Charter review:</strong> What was the mission? Did the session stay on charter, or did it evolve?</p></li><li><p><strong>Coverage discussion:</strong> What did you explore? What techniques did you apply? What didn&#8217;t you get to?</p></li><li><p><strong>Findings review:</strong> Walk through bugs found, issues identified, questions raised.</p></li><li><p><strong>Obstacles:</strong> What blocked or slowed you? Environment issues? Missing information?</p></li><li><p><strong>Continuation:</strong> What should come next? More sessions in this area? Different focus?</p></li><li><p><strong>Metrics review:</strong> How was time allocated? What does that indicate?</p></li></ul><h2><strong>Effective Debrief Practices</strong></h2><p><strong>Keep it conversational.</strong> Debriefs shouldn&#8217;t feel like formal reporting. They&#8217;re discussions between colleagues.</p><p><strong>Ask probing questions.</strong> &#8220;What surprised you?&#8221; &#8220;What didn&#8217;t you test that you wish you had?&#8221; &#8220;What&#8217;s your confidence level in this area?&#8221;</p><p><strong>Focus on learning, not judgment.</strong> The goal is understanding, not evaluating the tester&#8217;s performance.</p><p><strong>Time-box appropriately.</strong> 15&#8211;30 minutes is typical. Longer suggests sessions may be too broad.</p><p><strong>Document key points.</strong> Capture important insights, decisions, and action items.</p><p><strong>Feed back into planning.</strong> What you learn in debriefs should influence future charters.</p><h2><strong>Debrief Frequency</strong></h2><p>How often to debrief depends on context:</p><p><strong>After every session:</strong> Most thorough, appropriate for critical testing or newer testers.</p><p><strong>Daily:</strong> Batch debriefs for all sessions that day. Efficient for experienced testers.</p><p><strong>As-needed:</strong> For very experienced testers working independently. Risk of missing insights.</p><p>More frequent debriefs mean more overhead but also more opportunities for course correction. Find the balance that works for your team.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RGbR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RGbR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RGbR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RGbR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RGbR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RGbR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!RGbR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RGbR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RGbR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RGbR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae6f69a9-9d6c-4f7c-97ae-47777d88a764_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Organizing Multiple Sessions</strong></h2><p>A single session is straightforward. Coordinating dozens of sessions across multiple testers is where SBTM&#8217;s organizational power becomes essential.</p><h2><strong>The Session Sheet</strong></h2><p>A session sheet is the primary tracking document &#8212; a record of all sessions planned, in progress, and completed.</p><p><strong>Session sheet columns typically include:</strong></p><ul><li><p>Session ID (unique identifier)</p></li><li><p>Charter (brief description)</p></li><li><p>Tester (who&#8217;s assigned or who conducted it)</p></li><li><p>Status (planned/in progress/complete)</p></li><li><p>Duration (actual time spent)</p></li><li><p>Date (when conducted)</p></li><li><p>Bugs found (count)</p></li><li><p>Summary (brief outcome)</p></li><li><p>Continuation (follow-up needed?)</p></li></ul><p>This sheet provides at-a-glance visibility into testing progress.</p><h2><strong>Coverage Mapping</strong></h2><p>Beyond the session sheet, teams often create coverage maps showing which areas have been explored and to what depth.</p><p><strong>A coverage map might show:</strong></p><ul><li><p>Features or areas as rows</p></li><li><p>Session count per area</p></li><li><p>Risk level per area</p></li><li><p>Bugs found per area</p></li><li><p>Confidence assessment</p></li></ul><p>This visualization quickly reveals where testing has focused and where gaps exist.</p><h2><strong>Coordinating Testers</strong></h2><p>When multiple testers are exploring, coordination prevents duplication and ensures coverage:</p><p><strong>Charter assignment:</strong> Different testers take different charters, avoiding overlap.</p><p><strong>Area ownership:</strong> Each tester owns specific areas, building deep expertise.</p><p><strong>Bug awareness:</strong> Testers share findings so others can avoid duplicate discovery.</p><p><strong>Coverage balancing:</strong> Ensure high-risk areas get adequate attention from skilled testers.</p><p>Daily standups or coordination meetings keep everyone aligned on who&#8217;s testing what and what&#8217;s been found.</p><h2><strong>Progressive Coverage</strong></h2><p>As testing progresses, the charter backlog evolves:</p><p><strong>Initial sessions:</strong> Broad exploration to understand the landscape and find obvious bugs.</p><p><strong>Deep dive sessions:</strong> Focused exploration of complex or risky areas.</p><p><strong>Follow-up sessions:</strong> Investigation of issues discovered earlier.</p><p><strong>Confirmation sessions:</strong> Verification that fixes work and haven&#8217;t caused regressions.</p><p><strong>Diminishing returns sessions:</strong> Continued exploration with awareness that major bugs are likely found.</p><p>Tracking where each area falls in this progression helps allocate testing effort effectively.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cwoM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cwoM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cwoM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cwoM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cwoM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cwoM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!cwoM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cwoM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cwoM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cwoM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf7f8de-1ce1-466f-9518-c5ada0975f1a_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Implementing SBTM in Your Team</strong></h2><p>Ready to adopt session-based test management? Here&#8217;s how to implement it effectively.</p><h2><strong>Start Simple</strong></h2><p>Don&#8217;t try to implement everything at once. Begin with the basics:</p><ol><li><p><strong>Define session length.</strong> Start with 90 minutes as default.</p></li><li><p><strong>Create charter templates.</strong> Provide examples so testers understand good charters.</p></li><li><p><strong>Establish note-taking expectations.</strong> What should session notes capture?</p></li><li><p><strong>Implement basic debriefs.</strong> Even informal conversations after sessions.</p></li><li><p><strong>Track sessions simply.</strong> A spreadsheet is enough to start.</p></li></ol><p>Add sophistication as the practice matures.</p><h2><strong>Train Your Testers</strong></h2><p>SBTM requires testers to work differently. Invest in training:</p><p><strong>Charter creation:</strong> How to write focused, effective missions.</p><p><strong>Note-taking discipline:</strong> What to capture and how.</p><p><strong>Time awareness:</strong> Tracking time allocation across categories.</p><p><strong>Debrief participation:</strong> How to articulate findings clearly.</p><p><strong>Self-management:</strong> Staying focused during sessions, knowing when to stop.</p><h2><strong>Establish the Debrief Habit</strong></h2><p>Debriefs are often the first thing cut when time is short. That&#8217;s a mistake &#8212; they&#8217;re where much of SBTM&#8217;s value is generated.</p><p>Make debriefs non-negotiable. Schedule them. Protect the time. Ensure they happen.</p><p>Even five-minute debriefs are better than none. The conversation matters more than the duration.</p><h2><strong>Evolve Your Metrics</strong></h2><p>Start with basic metrics:</p><ul><li><p>Sessions completed</p></li><li><p>Bugs found per session</p></li><li><p>Time allocation percentages</p></li></ul><p>As you mature, add:</p><ul><li><p>Coverage by risk area</p></li><li><p>Bug density by area</p></li><li><p>Session productivity trends</p></li><li><p>Blocker analysis</p></li></ul><p>Use metrics to improve the process, not to judge individuals.</p><h2><strong>Integrate with Your Process</strong></h2><p>SBTM should complement your existing process, not replace it entirely:</p><p><strong>With Agile:</strong> Sessions fit naturally into sprints. Charter backlogs align with story backlogs.</p><p><strong>With automation:</strong> Use sessions to explore what automation doesn&#8217;t cover. Let exploration inform automation priorities.</p><p><strong>With scripted testing:</strong> Use SBTM for exploratory coverage while maintaining scripts for regression.</p><p><strong>With bug tracking:</strong> Link session reports to bug reports. Track which sessions found which bugs.</p><h2><strong>Common Implementation Pitfalls</strong></h2><p><strong>Over-formalizing:</strong> SBTM should add structure, not bureaucracy. If paperwork exceeds testing, you&#8217;ve gone too far.</p><p><strong>Treating metrics as targets:</strong> Metrics inform decisions. They shouldn&#8217;t pressure testers to game numbers.</p><p><strong>Skipping debriefs:</strong> Without debriefs, sessions become isolated events. Debriefs create organizational learning.</p><p><strong>Rigid charters:</strong> Charters guide; they don&#8217;t constrain. Testers should deviate when exploration leads somewhere important.</p><p><strong>Ignoring continuation:</strong> Every session generates ideas for future sessions. Capture and use this information.</p><h2><strong>SBTM and Modern Testing</strong></h2><p>How does session-based test management fit with modern testing practices?</p><h2><strong>SBTM and Agile</strong></h2><p>SBTM aligns naturally with Agile:</p><ul><li><p>Sessions fit into sprints</p></li><li><p>Charter backlogs parallel story backlogs</p></li><li><p>Debriefs happen in daily standups</p></li><li><p>Coverage reports support sprint reviews</p></li><li><p>Continuous exploration matches iterative development</p></li></ul><p>Many Agile teams find SBTM provides the accountability needed for exploratory testing without the overhead of traditional test planning.</p><h2><strong>SBTM and DevOps</strong></h2><p>In continuous delivery environments:</p><ul><li><p>Sessions can be short and frequent</p></li><li><p>Charters focus on recent changes</p></li><li><p>Debriefs inform deployment decisions</p></li><li><p>Metrics feed into quality dashboards</p></li><li><p>Exploration happens alongside automated pipelines</p></li></ul><p>SBTM helps ensure human testing keeps pace with rapid release cycles.</p><h2><strong>SBTM and AI</strong></h2><p>As AI tools enhance testing:</p><ul><li><p>AI can suggest charters based on code changes</p></li><li><p>AI can analyze session notes for patterns</p></li><li><p>AI can identify coverage gaps across sessions</p></li><li><p>AI can generate initial exploration paths</p></li></ul><p>Human judgment remains essential for actual exploration. SBTM provides the structure to coordinate human and AI contributions.</p><h2><strong>Reporting and Communication</strong></h2><p>SBTM generates information that stakeholders need. Translating session data into useful reports is essential.</p><h2><strong>Daily Status</strong></h2><p>For day-to-day communication:</p><ul><li><p>Sessions completed today</p></li><li><p>Bugs found today</p></li><li><p>Key findings or concerns</p></li><li><p>Blockers or risks</p></li><li><p>Tomorrow&#8217;s focus</p></li></ul><p>Keep it brief. Details live in session reports.</p><h2><strong>Coverage Reports</strong></h2><p>For release readiness or milestone assessment:</p><ul><li><p>Areas tested and session counts</p></li><li><p>Risk areas and coverage depth</p></li><li><p>Bug counts and severity distribution</p></li><li><p>Outstanding issues and concerns</p></li><li><p>Confidence assessment</p></li></ul><p>Use coverage maps and metrics to support narrative assessment.</p><h2><strong>Trend Reports</strong></h2><p>For process improvement:</p><ul><li><p>Sessions over time</p></li><li><p>Bugs per session trends</p></li><li><p>Time allocation patterns</p></li><li><p>Blocker frequency</p></li><li><p>Coverage velocity</p></li></ul><p>These reports inform decisions about testing efficiency and resource allocation.</p><h2><strong>Stakeholder Communication</strong></h2><p>Different stakeholders need different information:</p><p><strong>Developers:</strong> Want to know what was tested and what bugs were found. Appreciate specific, actionable findings.</p><p><strong>Product managers:</strong> Want to know readiness status and risk assessment. Care about user-facing issues.</p><p><strong>Executives:</strong> Want to know overall quality status and major risks. Need high-level summaries.</p><p>Tailor your reporting to your audience. SBTM data can serve all these needs.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LNfo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LNfo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LNfo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LNfo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LNfo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LNfo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!LNfo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LNfo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LNfo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LNfo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4e1542e-0274-4e56-b2a0-e26fcee53f54_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Your SBTM Starter Kit</strong></h2><p>Ready to start using session-based test management? Here&#8217;s what you need:</p><h2><strong>Session Report Template</strong></h2><pre><code>SESSION REPORT
==============
Session ID: <strong>________</strong>
Charter: <strong>________</strong>
Tester: <strong>________</strong>
Date: <strong>________</strong>
Actual Duration: <strong>________</strong></code></pre><pre><code>TIME ALLOCATION:
- Test Design &amp; Execution: ____%
- Bug Investigation &amp; Reporting: ____%
- Setup &amp; Administration: ____%COVERAGE:
What I tested:
- 
- 
- What I didn&#8217;t test (ran out of time / out of scope):
- 
- FINDINGS:
Bugs found: (list with IDs)
- 
- Issues/Concerns:
- 
- Questions raised:
- 
- CONTINUATION:
Should this area be explored further? Yes / No
Suggested follow-up charters:
- 
- OVERALL ASSESSMENT:
Confidence in this area: High / Medium / Low
Notes:</code></pre><h2><strong>Debrief Checklist</strong></h2><pre><code>DEBRIEF CHECKLIST
=================
&#9633; Charter review: Was the mission clear? Did you stay on charter?
&#9633; Coverage: What did you explore? What techniques did you use?
&#9633; Findings: Walk through bugs and issues found
&#9633; Surprises: What was unexpected?
&#9633; Obstacles: What blocked or slowed you?
&#9633; Confidence: How do you feel about quality in this area?
&#9633; Continuation: What should come next?
&#9633; Metrics: Review time allocation
&#9633; Action items: What needs to happen based on this session?</code></pre><h2><strong>Tracking Spreadsheet Columns</strong></h2><ul><li><p>Session ID</p></li><li><p>Charter (brief)</p></li><li><p>Area/Feature</p></li><li><p>Tester</p></li><li><p>Status (Planned / In Progress / Complete)</p></li><li><p>Planned Date</p></li><li><p>Actual Date</p></li><li><p>Duration</p></li><li><p>Bugs Found</p></li><li><p>Follow-up Needed?</p></li><li><p>Notes</p></li></ul><h2><strong>Your First SBTM Week</strong></h2><p>Here&#8217;s a practical guide to your first week using SBTM:</p><h2><strong>Day 1: Setup</strong></h2><ul><li><p>Create your charter backlog (10&#8211;15 charters for different areas)</p></li><li><p>Set up your session tracking spreadsheet</p></li><li><p>Prepare your session report template</p></li><li><p>Schedule 15 minutes daily for debriefs</p></li></ul><h2><strong>Day 2&#8211;3: First Sessions</strong></h2><ul><li><p>Conduct 2&#8211;3 sessions with different charters</p></li><li><p>Focus on following the process, not perfection</p></li><li><p>Take notes continuously during sessions</p></li><li><p>Complete session reports immediately after</p></li></ul><h2><strong>Day 4: Reflect and Adjust</strong></h2><ul><li><p>Review your session reports</p></li><li><p>What worked well? What felt awkward?</p></li><li><p>Adjust templates if needed</p></li><li><p>Conduct debrief (with yourself if solo, with lead if on team)</p></li></ul><h2><strong>Day 5: Iterate</strong></h2><ul><li><p>Continue sessions with adjustments</p></li><li><p>Track coverage across sessions</p></li><li><p>Identify patterns in your findings</p></li><li><p>Plan next week&#8217;s charters based on learning</p></li></ul><p>After one week, you&#8217;ll have practical experience with the framework and ideas for making it work better for your context.</p><h2><strong>From Sessions to Strategy</strong></h2><p>SBTM transforms exploratory testing from untracked activity into a managed practice. But the framework is means to an end, not an end itself.</p><p>The ultimate goal isn&#8217;t perfect session reports or precise metrics. It&#8217;s effective testing that finds important bugs, provides accurate quality assessment, and enables informed release decisions.</p><p>Use SBTM to:</p><ul><li><p><strong>Ensure coverage:</strong> Know what&#8217;s been tested and what hasn&#8217;t.</p></li><li><p><strong>Enable accountability:</strong> Show stakeholders what testing actually happened.</p></li><li><p><strong>Improve efficiency:</strong> Identify blockers, optimize processes, allocate resources well.</p></li><li><p><strong>Generate learning:</strong> Build organizational knowledge through debriefs and patterns.</p></li><li><p><strong>Maintain flexibility:</strong> Keep the creative power of exploration while adding structure.</p></li></ul><p>When SBTM feels bureaucratic, simplify it. When it feels too loose, tighten it. The framework serves the testing, not the other way around.</p><p>In our next article, we&#8217;ll explore <strong>Test Charter Writing</strong> &#8212; the art of crafting focused missions that guide exploration without constraining it. We&#8217;ll examine what separates vague charters from powerful ones, provide templates for different testing situations, and show how well-written charters transform scattered exploration into strategic investigation.</p><p><strong>Remember:</strong> Exploratory testing isn&#8217;t chaos unless you let it be. Session-Based Test Management proves that freedom and accountability can coexist.</p>]]></content:encoded></item><item><title><![CDATA[Exploratory Testing Fundamentals]]></title><description><![CDATA[Structured learning and testing simultaneously]]></description><link>https://ryancraventech.substack.com/p/exploratory-testing-fundamentals</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/exploratory-testing-fundamentals</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Fri, 13 Feb 2026 12:36:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9AVz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The test case said: &#8220;Enter a valid email address. Verify the form submits successfully.&#8221;</p><p>So the tester entered &#8220;<a href="mailto:test@example.com">test@example.com</a>&#8221; and clicked submit. Green checkmark. Test passed. Move on.</p><p>Nobody ever tested what happens when you paste an email with invisible Unicode characters copied from a PDF. Nobody tested submitting the form while the network drops mid-request. Nobody tested what happens when you hit submit twice in rapid succession because the button didn&#8217;t gray out.</p><p>Three production bugs. Zero test cases written for them. Because you can&#8217;t write a test case for something you haven&#8217;t imagined yet.</p><p>This is the fundamental limitation of scripted testing: it can only verify what someone thought to check. The bugs that matter most &#8212; the ones that surprise you, embarrass you, cost you customers &#8212; are often the ones nobody thought to script.</p><p>Exploratory testing exists to find those bugs.</p><p>Yes, it&#8217;s testing without a rigid plan. That&#8217;s the point. Instead of following a predetermined script, you&#8217;re learning about the software as you test it &#8212; designing tests, executing them, and interpreting results simultaneously. What you discover shapes what you test next. The approach adapts in real-time to the reality of the software rather than the assumptions someone made before testing began.</p><p>But &#8220;no rigid plan&#8221; doesn&#8217;t mean &#8220;no structure.&#8221; The best exploratory testing is guided by charters, heuristics, and timeboxes that provide direction without constraining discovery.</p><p>Today we&#8217;re diving into exploratory testing fundamentals &#8212; what it actually is, why it consistently finds bugs that scripts miss, and how to practice it with discipline rather than chaos.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9AVz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9AVz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9AVz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9AVz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9AVz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9AVz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg" width="1400" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!9AVz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9AVz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9AVz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9AVz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a82ca-3a2d-47cc-a629-c0e6ded9dfda_1400x781.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Exploratory Testing Actually Is</strong></h2><p>Let&#8217;s start with a proper definition, because the term gets abused.</p><p>James Bach, who coined the term with Cem Kaner, defines exploratory testing as:</p><blockquote><p><em>&#8220;Simultaneous learning, test design, test execution, and test result interpretation.&#8221;</em></p></blockquote><p>Read that again. Four activities happening at the same time, not in sequence.</p><p>In scripted testing, these activities are separated. Someone writes test cases (design). Later, someone executes those test cases (execution). Then someone analyzes the results (interpretation). Learning might happen eventually, but it&#8217;s not integrated into the process.</p><p>In exploratory testing, these activities are interleaved continuously. You&#8217;re learning about the software as you test it. What you learn shapes what you test next. What you test reveals new things to learn. The cycle continues throughout the session.</p><p><strong>This is not:</strong></p><p>&#8220;Testing without preparation.&#8221; Exploratory testers prepare extensively &#8212; they just don&#8217;t script their exact actions in advance.</p><p>&#8220;Random clicking.&#8221; Exploratory testing is guided by strategy, heuristics, and objectives. It&#8217;s deliberate, not random.</p><p>&#8220;Testing without documentation.&#8221; Exploratory testers document their findings, their approach, and their learning. The documentation happens during and after testing, not before.</p><p>&#8220;The absence of test cases.&#8221; Exploratory testing generates test cases &#8212; it just generates them in real-time based on learning rather than in advance based on assumptions.</p><p>&#8220;Easy or unskilled testing.&#8221; Exploratory testing requires more skill than scripted testing, not less. It demands simultaneous thinking on multiple levels.</p><p><strong>This is:</strong></p><ul><li><p>A disciplined approach where human intelligence is applied directly to the testing problem, adapting in real-time to discoveries.</p></li><li><p>A method that leverages human strengths &#8212; creativity, intuition, contextual understanding &#8212; rather than suppressing them behind scripts.</p></li><li><p>A way of testing that treats testers as intelligent investigators rather than human automation.</p></li></ul><h2><strong>Why Exploratory Testing Finds More Bugs</strong></h2><p>Exploratory testing consistently finds bugs that scripted testing misses. This isn&#8217;t magic &#8212; it&#8217;s the natural result of how the approach works.</p><h2><strong>Scripts Test Assumptions</strong></h2><p>When you write a test case in advance, you&#8217;re encoding assumptions about how the software works and how users will use it.</p><p>But assumptions are often wrong. Requirements are incomplete. Users do unexpected things. The software behaves differently than anticipated. Edge cases aren&#8217;t obvious until you start interacting with the system.</p><p>Scripts test the world as we imagine it. Exploration tests the world as it actually is.</p><h2><strong>Real-Time Adaptation</strong></h2><p>When an exploratory tester notices something unexpected, they can immediately investigate. They can follow the thread wherever it leads.</p><p>When a scripted tester notices something unexpected, they face a choice: stop to investigate (abandoning the script) or note it for later (potentially forgetting or deprioritizing it). The script is a constraint that limits responsiveness.</p><p>Bugs often reveal themselves through subtle signals &#8212; slightly slow response, unexpected behavior in one corner of the screen, data that doesn&#8217;t quite look right. Exploratory testers can pursue these signals immediately. Script followers often don&#8217;t.</p><h2><strong>Combinatorial Explosion</strong></h2><p>The number of possible test scenarios for any non-trivial feature is effectively infinite. Scripts can only cover a finite selection. That selection is chosen based on assumptions about what matters &#8212; assumptions that might be wrong.</p><p>Exploratory testing doesn&#8217;t try to cover everything. Instead, it uses human judgment to continuously select the most promising areas to investigate. As learning accumulates, those selections get smarter.</p><p>This intelligent adaptation is more likely to find important bugs than a predefined selection made before testing began.</p><h2><strong>Fresh Perspective</strong></h2><p>Scripted tests often become stale. The same tests run repeatedly, covering the same ground. Testers executing scripts stop really seeing the software &#8212; they&#8217;re just going through motions.</p><p>Exploratory testing demands engagement. You can&#8217;t explore on autopilot. This engaged attention notices things that rote execution misses.</p><h2><strong>Holistic Understanding</strong></h2><p>Exploratory testing builds a mental model of the entire system. This holistic understanding reveals inconsistencies, integration issues, and problems that span features.</p><p>Scripted testing often covers features in isolation. The tests verify individual behaviors but miss how those behaviors interact. Exploratory testers naturally cross feature boundaries because their investigation follows the software, not the test plan.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_8Q7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_8Q7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_8Q7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_8Q7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_8Q7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_8Q7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg" width="1400" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!_8Q7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_8Q7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_8Q7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_8Q7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b83f11f-19cf-4473-847b-12e86505ff9d_1400x781.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Structure Within Exploration</strong></h2><p>Here&#8217;s where most people get exploratory testing wrong: they think &#8220;unscripted&#8221; means &#8220;unstructured.&#8221;</p><p>The best exploratory testing is highly structured. The structure just looks different from scripted testing.</p><h2><strong>Session-Based Testing</strong></h2><p>The most common structure for exploratory testing is the session &#8212; a focused block of time with a specific charter.</p><p>A session is typically 60&#8211;120 minutes of uninterrupted testing. It has a clear start and end. It&#8217;s focused on a specific mission. It produces documented results.</p><p>This structure provides accountability without constraining the testing itself. You know what each session was trying to accomplish and what it produced.</p><h2><strong>Charters</strong></h2><p>A charter is a mission statement for an exploration session. It answers: What are we investigating? Why does it matter? What areas are in scope?</p><p>Good charters provide direction without dictating actions:</p><p><em>&#8220;Explore the checkout flow with focus on error handling when payment fails.&#8221;</em></p><p><em>&#8220;Investigate how the application behaves when the user has extremely long text in profile fields.&#8221;</em></p><p><em>&#8220;Test the new search feature to understand its capabilities and limitations.&#8221;</em></p><p>Notice what these charters don&#8217;t include: specific steps, exact test cases, or predetermined pass/fail criteria. They provide direction while preserving freedom.</p><h2><strong>Time-Boxing</strong></h2><p>Exploratory testing benefits from time constraints. Without them, investigation can expand indefinitely. With them, testers must make strategic choices about where to focus.</p><p>Time-boxing also provides natural breakpoints for documentation, reflection, and planning. After each time box, you assess: What did I learn? What should I investigate next? Is this area worth more time?</p><h2><strong>Note-Taking</strong></h2><p>Exploratory testers take notes continuously &#8212; not to follow a script but to record what they&#8217;re doing, what they&#8217;re learning, and what they&#8217;re finding.</p><p>Good exploration notes include:</p><ul><li><p>What you tested and how</p></li><li><p>What you observed (expected and unexpected)</p></li><li><p>Questions that arose</p></li><li><p>Ideas for future investigation</p></li><li><p>Bugs found with reproduction details</p></li></ul><p>These notes serve multiple purposes: they support bug reports, they guide future sessions, and they provide evidence of what was tested.</p><h2><strong>Debriefing</strong></h2><p>After exploration sessions, testers debrief &#8212; either with themselves or with their team. What was discovered? What&#8217;s the quality status? What areas need more attention?</p><p>Debriefing transforms individual exploration into organizational learning. It surfaces findings, identifies patterns across sessions, and guides future testing strategy.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TTbo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TTbo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TTbo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TTbo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TTbo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TTbo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg" width="1400" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!TTbo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TTbo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TTbo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TTbo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865050d9-317c-4d23-bfb3-b6f056d947f9_1400x781.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Planning Your Exploration</strong></h2><p>&#8220;No scripts&#8221; doesn&#8217;t mean &#8220;no preparation.&#8221; Effective exploratory testing requires thoughtful planning &#8212; just different planning than scripted testing requires.</p><h2><strong>Understanding the Mission</strong></h2><p>Before exploring, understand why you&#8217;re testing. What&#8217;s the goal? What does success look like?</p><p>Are you trying to find as many bugs as possible? Assess readiness for release? Understand a new feature? Verify a fix? Different missions lead to different exploration strategies.</p><p>A bug-hunting mission focuses on areas likely to contain defects. A release assessment mission covers critical functionality breadth. A learning mission prioritizes building understanding over finding problems.</p><h2><strong>Gathering Context</strong></h2><p>Collect information that will guide your exploration:</p><p><strong>Requirements and specifications.</strong> What is the software supposed to do? What are the business rules? What are the stated constraints?</p><p><strong>Architecture and design.</strong> How is it built? Where are the integration points? What technologies are involved?</p><p><strong>Risk information.</strong> What areas are new or changed? What&#8217;s complex? What&#8217;s been problematic before? What would hurt most if it failed?</p><p><strong>User information.</strong> Who uses this software? How do they use it? What are their goals and frustrations?</p><p>This context shapes where you explore and what you&#8217;re looking for.</p><h2><strong>Identifying Focus Areas</strong></h2><p>You can&#8217;t explore everything equally. Prioritize based on risk.</p><p>High-priority areas typically include:</p><ul><li><p>New or recently changed functionality</p></li><li><p>Complex features with many interactions</p></li><li><p>Features that handle sensitive data or critical processes</p></li><li><p>Areas that have historically been buggy</p></li><li><p>Integration points with external systems</p></li><li><p>Features that many users rely on frequently</p></li></ul><p>Lower-priority areas might include:</p><ul><li><p>Stable functionality that hasn&#8217;t changed</p></li><li><p>Features with extensive automated coverage</p></li><li><p>Low-impact features used rarely</p></li></ul><h2><strong>Choosing Heuristics</strong></h2><p>Heuristics are mental frameworks that guide exploration. They&#8217;re rules of thumb that suggest what to test.</p><p>Before a session, consider which heuristics might apply:</p><ul><li><p>Input variations (boundary values, invalid data, empty inputs)</p></li><li><p>State transitions (what happens between states?)</p></li><li><p>Interruptions (what if the user stops mid-process?)</p></li><li><p>Configuration variations (different browsers, settings, permissions)</p></li><li><p>Stress conditions (slow network, many items, concurrent users)</p></li></ul><p>Having heuristics in mind gives exploration direction without constraining it to predetermined steps.</p><h2><strong>Creating Initial Questions</strong></h2><p>Start with questions you want to answer:</p><p><em>Can a user complete the checkout with an expired credit card?</em> <em>What happens if the session times out during payment processing?</em> <em>How does the search handle special characters?</em> <em>Is the error messaging consistent across the application?</em></p><p>These questions provide starting points for exploration. You&#8217;ll generate more questions as you test.</p><h2><strong>During the Session: How to Explore</strong></h2><p>Now you&#8217;re in the session. The charter is set, the timer is running, and you&#8217;re face-to-face with the software. How do you actually explore?</p><h2><strong>Start With a Tour</strong></h2><p>Begin by getting oriented. Do a quick tour of the area you&#8217;re exploring. Understand the landscape before diving into details.</p><p>What are the main features? What are the entry and exit points? What data is involved? What states can the system be in?</p><p>This orientation prevents the common mistake of diving too deep into one area before understanding the whole.</p><h2><strong>Follow the &#8220;What If&#8221; Principle</strong></h2><p>Exploration is driven by questions. The most powerful question is &#8220;What if?&#8221;</p><p>What if I enter nothing? What if I enter too much? What if I go backward? What if I do this twice? What if I&#8217;m not logged in? What if the network is slow? What if I open two tabs?</p><p>Each &#8220;what if&#8221; generates a test. The answer generates more questions.</p><h2><strong>Vary Your Inputs</strong></h2><p>Don&#8217;t just test with &#8220;normal&#8221; data. Vary your inputs systematically:</p><p><strong>Boundaries:</strong> Minimum, maximum, just below, just above. <strong>Invalid data:</strong> Wrong types, wrong formats, malicious content. <strong>Empty and null:</strong> Missing required fields, blank values. <strong>Special characters:</strong> Unicode, emojis, HTML, SQL fragments. <strong>Length extremes:</strong> Very short, very long. <strong>Real-world data:</strong> Actual content users would enter.</p><p>Input variation surfaces bugs that &#8220;happy path&#8221; data never triggers.</p><h2><strong>Change Your Perspective</strong></h2><p>Periodically shift how you&#8217;re thinking about the software:</p><p><strong>New user perspective:</strong> What if I&#8217;ve never seen this before? <strong>Expert user perspective:</strong> What shortcuts would power users want? <strong>Hostile user perspective:</strong> How could someone abuse this? <strong>Accessibility perspective:</strong> Can users with disabilities use this? <strong>Support perspective:</strong> What questions will confused users ask?</p><p>Each perspective reveals different issues.</p><h2><strong>Notice Everything</strong></h2><p>Exploratory testing requires active observation. Don&#8217;t just watch for pass/fail &#8212; notice everything:</p><ul><li><p>Response times (faster or slower than expected?)</p></li><li><p>Visual presentation (alignment, consistency, aesthetics)</p></li><li><p>Language and messaging (clear, helpful, appropriate?)</p></li><li><p>Behavior patterns (consistent with rest of application?)</p></li><li><p>Data handling (saved correctly, displayed correctly?)</p></li></ul><p>Things that seem &#8220;not quite right&#8221; often lead to important bugs.</p><h2><strong>Follow Threads</strong></h2><p>When you notice something interesting, follow it. Don&#8217;t note it for later and continue with your plan &#8212; pursue it now while you&#8217;re in context.</p><p>Many important bugs are discovered by pulling on threads. The initial observation leads to an investigation, which leads to a deeper problem. If you don&#8217;t follow threads immediately, they often go cold.</p><h2><strong>Take Notes Continuously</strong></h2><p>Don&#8217;t rely on memory. Document as you go:</p><ul><li><p>Steps you&#8217;re taking</p></li><li><p>Observations you&#8217;re making</p></li><li><p>Questions arising</p></li><li><p>Bugs found</p></li><li><p>Ideas for further investigation</p></li></ul><p>These notes support later bug reports, inform future sessions, and provide evidence of your coverage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WnbB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WnbB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WnbB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WnbB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WnbB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WnbB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg" width="1400" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!WnbB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WnbB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WnbB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WnbB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F883a6eac-4185-4c95-af67-d805db85a38a_1400x781.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Heuristics: Your Exploration Toolkit</strong></h2><p>Heuristics are mental tools that suggest what to test. They&#8217;re not prescriptive rules &#8212; they&#8217;re prompts that trigger ideas. Experienced exploratory testers carry dozens of heuristics that they apply intuitively.</p><p>Here are essential heuristics to add to your toolkit:</p><h2><strong>SFDPOT (San Francisco Depot)</strong></h2><p>A mnemonic for high-level quality aspects:</p><p><strong>Structure:</strong> Is the product built correctly? Code, architecture, dependencies. <strong>Function:</strong> Do the features work as intended? <strong>Data:</strong> Is data handled correctly? Input, output, storage, retrieval. <strong>Platform:</strong> Does it work across environments? Browsers, devices, OS versions. <strong>Operations:</strong> Can it be deployed, maintained, and monitored? <strong>Time:</strong> How does time affect it? Timeouts, sessions, scheduling.</p><h2><strong>HICCUPPS (Consistency Heuristics)</strong></h2><p>Ways to identify inconsistencies that suggest bugs:</p><p><strong>History:</strong> Is behavior consistent with past versions? <strong>Image:</strong> Is behavior consistent with the company brand? <strong>Comparable Products:</strong> Is behavior consistent with similar products? <strong>Claims:</strong> Is behavior consistent with documentation and specs? <strong>User Expectations:</strong> Is behavior consistent with what users expect? <strong>Product:</strong> Is behavior consistent within the product itself? <strong>Purpose:</strong> Is behavior consistent with the product&#8217;s purpose? <strong>Standards:</strong> Is behavior consistent with industry standards?</p><h2><strong>FEW HICCUPPS (Feeling)</strong></h2><p>Add emotional/experiential dimension:</p><p><strong>Feeling:</strong> Does this feel right? Does it feel frustrating, confusing, or satisfying?</p><p>Sometimes your gut knows something is wrong before you can articulate why.</p><h2><strong>Boundary Testing Heuristic</strong></h2><p>At every input, consider:</p><ul><li><p>Minimum valid value</p></li><li><p>Maximum valid value</p></li><li><p>Just below minimum</p></li><li><p>Just above maximum</p></li><li><p>Zero / empty / null</p></li><li><p>Negative (where applicable)</p></li></ul><h2><strong>State Transition Heuristic</strong></h2><p>For any feature with states:</p><ul><li><p>Test valid transitions between states</p></li><li><p>Test invalid transitions (should they be prevented?)</p></li><li><p>Test returning to previous states</p></li><li><p>Test remaining in current state</p></li><li><p>Test the effect of external events on state</p></li></ul><h2><strong>Interruption Heuristic</strong></h2><p>Test what happens when processes are interrupted:</p><ul><li><p>Close the browser mid-action</p></li><li><p>Navigate away and back</p></li><li><p>Let session timeout</p></li><li><p>Lose network connection</p></li><li><p>Have another user modify the same data</p></li></ul><h2><strong>Stress Heuristic</strong></h2><p>Test under pressure:</p><ul><li><p>Many items (thousands instead of dozens)</p></li><li><p>Fast actions (rapid clicking, quick navigation)</p></li><li><p>Large data (huge files, long text)</p></li><li><p>Slow network (throttled connection)</p></li><li><p>Limited resources (low memory, slow CPU)</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!H7HQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!H7HQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!H7HQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!H7HQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!H7HQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!H7HQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg" width="1400" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!H7HQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!H7HQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!H7HQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!H7HQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F554e3350-a7f9-4068-8996-866ee4442a4a_1400x781.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Documenting Your Exploration</strong></h2><p>Documentation in exploratory testing serves different purposes than in scripted testing. You&#8217;re not documenting what to do &#8212; you&#8217;re documenting what you did, learned, and found.</p><h2><strong>Session Notes</strong></h2><p>During exploration, capture:</p><p><strong>Coverage:</strong> What areas did you explore? What did you actually test?</p><p><strong>Observations:</strong> What did you notice? Include both problems and normal behavior worth recording.</p><p><strong>Questions:</strong> What questions arose? What remains uncertain?</p><p><strong>Bugs:</strong> Issues found, with enough detail to reproduce.</p><p><strong>Ideas:</strong> What should be investigated further? What deserves automation?</p><h2><strong>The Session Report</strong></h2><p>After each session, produce a brief report:</p><p><strong>Charter:</strong> What was the mission?</p><p><strong>Duration:</strong> How long did you actually spend?</p><p><strong>Coverage:</strong> What did you explore? (List of areas, features, or scenarios)</p><p><strong>Findings:</strong> What did you discover? (Bugs, observations, concerns)</p><p><strong>Assessment:</strong> What&#8217;s your overall impression of quality in this area?</p><p><strong>Next steps:</strong> What should happen next?</p><p>This report makes exploratory testing visible and accountable.</p><h2><strong>Bug Reports from Exploration</strong></h2><p>When you find bugs during exploration, document them thoroughly:</p><p><strong>Title:</strong> Clear, specific summary of the issue.</p><p><strong>Steps to reproduce:</strong> Exact actions to recreate the bug.</p><p><strong>Expected result:</strong> What should have happened.</p><p><strong>Actual result:</strong> What actually happened.</p><p><strong>Evidence:</strong> Screenshots, videos, logs.</p><p><strong>Severity assessment:</strong> How bad is this?</p><p><strong>Context:</strong> What were you exploring when you found this? What led you here?</p><p>The context is especially valuable &#8212; it helps developers understand not just the bug but the conditions around it.</p><h2><strong>Traceability</strong></h2><p>How do you show what exploratory testing covered?</p><p><strong>Session logs:</strong> Document what was tested in each session.</p><p><strong>Mind maps:</strong> Visual representation of areas explored.</p><p><strong>Coverage notes:</strong> List of features, scenarios, or risk areas addressed.</p><p><strong>Heuristic tracking:</strong> Which heuristics were applied where.</p><p>This documentation provides evidence that exploration was systematic, not random.</p><h2><strong>Common Exploratory Testing Pitfalls</strong></h2><p>Exploratory testing is powerful but not foolproof. Watch for these common mistakes:</p><h2><strong>Wandering Without Purpose</strong></h2><p>Exploration without direction degenerates into aimless clicking. You cover ground randomly, missing important areas while over-testing others.</p><p><strong>Fix:</strong> Always have a charter. Know what you&#8217;re investigating and why. Check periodically: &#8220;Am I still pursuing my mission?&#8221;</p><h2><strong>Shallow Coverage</strong></h2><p>Testers sometimes skim across features without going deep. They see that something works at a surface level and move on.</p><p><strong>Fix:</strong> Deliberately go deep. When something works, ask &#8220;But what if&#8230;?&#8221; Push into edges, errors, and unusual conditions.</p><h2><strong>Forgetting to Document</strong></h2><p>In the flow of exploration, documentation gets neglected. Later, you can&#8217;t remember what you tested or how you found that bug.</p><p><strong>Fix:</strong> Make note-taking habitual. Brief notes throughout are better than detailed notes after (when you&#8217;ve forgotten half of what happened).</p><h2><strong>Not Following Threads</strong></h2><p>You notice something odd but don&#8217;t investigate because you&#8217;re focused on something else. The thread goes cold. The bug goes unreported.</p><p><strong>Fix:</strong> Follow threads when they appear. Your current path will still be there. The interesting observation might not be.</p><h2><strong>Confirmation Bias</strong></h2><p>You believe the software works and unconsciously test in ways that confirm that belief. You don&#8217;t push hard enough to find problems.</p><p><strong>Fix:</strong> Adopt a skeptical mindset. Your job is to find the truth, not to confirm quality. Actively try to break things.</p><h2><strong>Working in Isolation</strong></h2><p>Exploratory testing in a vacuum misses valuable input. You don&#8217;t know what developers are worried about, what users complain about, or what other testers have found.</p><p><strong>Fix:</strong> Collaborate. Ask developers where bugs might hide. Review customer feedback. Share findings with teammates.</p><h2><strong>No Synthesis</strong></h2><p>You run sessions, find bugs, write reports &#8212; but never step back to synthesize. What patterns are emerging? What does exploration tell you about overall quality?</p><p><strong>Fix:</strong> Periodically reflect across sessions. Look for patterns. Form hypotheses. Share insights beyond individual bug reports.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NI10!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NI10!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NI10!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NI10!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NI10!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NI10!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg" width="1400" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!NI10!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NI10!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NI10!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NI10!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b58ad10-c70b-4c8c-a41e-682e57ee8ecb_1400x781.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Building Exploratory Testing Skills</strong></h2><p>Exploratory testing looks easy. Mastering it takes years. Here&#8217;s how to accelerate your development.</p><h2><strong>Practice Deliberately</strong></h2><p>Exploratory testing skills develop through practice &#8212; but only deliberate practice that pushes your limits.</p><p>After each session, reflect: What did I do well? What did I miss? What would I do differently? This reflection accelerates learning.</p><h2><strong>Study the Software Deeply</strong></h2><p>The better you understand what you&#8217;re testing, the better your exploration. Learn the domain, the architecture, the history.</p><p>Ask developers to explain how features work. Read documentation. Study past bugs. Deep knowledge enables deeper exploration.</p><h2><strong>Expand Your Heuristic Library</strong></h2><p>Collect heuristics from books, articles, and other testers. Write them down. Practice applying them.</p><p>Over time, you&#8217;ll internalize a rich set of mental tools that guide exploration without constraining it.</p><h2><strong>Learn From Others</strong></h2><p>Watch experienced exploratory testers work. How do they decide what to investigate? How do they vary their approach? What do they notice that you miss?</p><p>Pair exploration is particularly valuable &#8212; two minds exploring together, sharing observations and ideas.</p><h2><strong>Test Everything</strong></h2><p>Practice exploratory testing everywhere. Test websites you use daily. Test apps on your phone. Test physical products. Test processes.</p><p>The more you explore, the more natural exploration becomes.</p><h2><strong>Review Your Own Work</strong></h2><p>Record your exploration sessions (screen recording with audio narration). Review them later. What did you miss? Where did you rush? What could you do better?</p><p>Self-review is uncomfortable but powerful.</p><h2><strong>Read Widely</strong></h2><p>Books like &#8220;Exploratory Software Testing&#8221; by James Whittaker and &#8220;Explore It!&#8221; by Elisabeth Hendrickson provide deep insight into exploratory techniques.</p><p>Read them. Apply what you learn. Re-read them &#8212; you&#8217;ll notice different things as your skills develop.</p><h2><strong>Exploratory Testing and Automation</strong></h2><p>Exploratory testing and automation aren&#8217;t opposites &#8212; they&#8217;re partners.</p><h2><strong>Automation Frees Exploration</strong></h2><p>When routine verification is automated, human testers can focus on exploration. Automation handles the repetitive; exploration handles the creative.</p><p>The best testing strategies use automation for regression coverage while reserving human attention for discovery.</p><h2><strong>Exploration Informs Automation</strong></h2><p>Exploratory testing discovers what should be automated. You find an important scenario through exploration, then automate it to ensure continuous verification.</p><p>Exploration is the R&amp;D; automation is the manufacturing.</p><h2><strong>Exploration Validates Automation</strong></h2><p>Are automated tests actually testing the right things? Exploration can answer that question. You might discover that automated tests are passing while real quality issues go undetected.</p><p>Periodically explore areas covered by automation. You&#8217;ll often find gaps.</p><h2><strong>Automation Supports Exploration</strong></h2><p>Automation can set up complex preconditions, generate test data, or monitor for specific conditions while you explore. The tools work together.</p><p>Some testers write small automation scripts during exploration &#8212; not full test cases, but utilities that support investigation.</p><h2><strong>Starting Your Exploratory Practice</strong></h2><p>Ready to start exploring? Here&#8217;s how to begin.</p><h3><strong>Start With One Session</strong></h3><p>Pick a feature. Set a timer for 60 minutes. Define a simple charter: &#8220;Explore [feature] to understand how it works and find any problems.&#8221;</p><p>Then explore. No scripts. Just investigation guided by curiosity.</p><h3><strong>Take Notes Throughout</strong></h3><p>Document what you&#8217;re doing, what you notice, what you question. Don&#8217;t worry about format &#8212; just capture information.</p><h3><strong>Follow Your Curiosity</strong></h3><p>When something catches your attention, investigate. Follow threads. Ask &#8220;what if?&#8221; constantly.</p><h3><strong>Debrief Yourself</strong></h3><p>After the session, reflect: What did you learn? What did you find? What would you explore next?</p><h3><strong>Repeat and Refine</strong></h3><p>Do more sessions. Try different charters. Experiment with different heuristics. Notice what works and what doesn&#8217;t.</p><h3><strong>Get Feedback</strong></h3><p>Share your findings with others. Ask for input on your approach. Learn from more experienced exploratory testers.</p><h2><strong>Your First Exploration Exercise</strong></h2><p>Let&#8217;s make this concrete. Here&#8217;s an exercise to practice right now.</p><p><strong>Choose an application.</strong> Something you use but haven&#8217;t tested formally. A website, a mobile app, a desktop application.</p><p><strong>Set your charter:</strong> &#8220;Explore the [specific feature] to learn how it handles unexpected inputs and error conditions.&#8221;</p><p><strong>Time-box:</strong> 45 minutes.</p><p><strong>During exploration:</strong></p><ul><li><p>Start with a quick tour of the feature</p></li><li><p>Identify the inputs and actions available</p></li><li><p>Apply boundary and invalid input heuristics</p></li><li><p>Notice how errors are handled (or not handled)</p></li><li><p>Follow anything surprising</p></li><li><p>Take continuous notes</p></li></ul><p><strong>After exploration:</strong></p><ul><li><p>List three things you learned about the feature</p></li><li><p>Describe two bugs or concerns you found</p></li><li><p>Identify one area that deserves deeper investigation</p></li><li><p>Write a brief session report</p></li></ul><p><strong>Reflect:</strong></p><ul><li><p>What was easy? What was hard?</p></li><li><p>What would you do differently next time?</p></li><li><p>What questions do you still have?</p></li></ul><p>This single exercise will teach you more about exploratory testing than reading three more articles. Do it today.</p><h2><strong>The Continuous Discovery Mindset</strong></h2><p>Exploratory testing isn&#8217;t just a technique. It&#8217;s a mindset &#8212; a way of approaching software with curiosity, skepticism, and adaptability.</p><p>Scripts ask: &#8220;Does the software match our expectations?&#8221;</p><p>Exploration asks: &#8220;What is this software actually doing, and is that good?&#8221;</p><p>The scripted mindset seeks confirmation. The exploratory mindset seeks discovery.</p><p>Both have their place. But in a world where software is increasingly complex, where user behavior is increasingly unpredictable, and where AI is changing what&#8217;s possible &#8212; the ability to learn and test simultaneously becomes ever more valuable.</p><p>The best testers don&#8217;t just execute. They explore.</p><p>In our next article, we&#8217;ll explore <strong>Session-Based Test Management</strong> &#8212; the framework that brings accountability and structure to exploratory testing. We&#8217;ll examine how charters, timeboxes, and debriefs transform ad-hoc exploration into a measurable, manageable practice without sacrificing the freedom that makes it powerful.</p><p><strong>Remember:</strong> Exploration isn&#8217;t the absence of structure. It&#8217;s the presence of intelligence applied in real-time to the problem of software quality.</p>]]></content:encoded></item><item><title><![CDATA[Introduction to Manual Testing ]]></title><description><![CDATA[When human judgment is irreplaceable]]></description><link>https://ryancraventech.substack.com/p/introduction-to-manual-testing</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/introduction-to-manual-testing</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Wed, 11 Feb 2026 13:01:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0167!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0167!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0167!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0167!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0167!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0167!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0167!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!0167!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0167!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0167!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0167!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7142585-e400-4b15-91e8-0aba9e202931_788x440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Everyone&#8217;s talking about automation. AI-generated test cases. Self-healing scripts. Codeless testing platforms that promise to eliminate manual work entirely.</p><p>And yet.</p><p>The login button works perfectly in automated tests but is positioned where users&#8217; thumbs can&#8217;t reach it on mobile. The checkout flow passes every scripted scenario but feels so clunky that customers abandon their carts. The error messages are technically accurate but so confusing that users call support instead of fixing the problem themselves.</p><p>Automation didn&#8217;t catch any of this. A human tester would have caught all of it.</p><p>Here&#8217;s the uncomfortable truth the automation evangelists don&#8217;t want to admit: some things require human judgment. Not as a temporary limitation until technology catches up, but as a fundamental reality of what testing actually is.</p><p>Manual testing isn&#8217;t the absence of automation. It&#8217;s the presence of human intelligence applied directly to the problem of software quality. And in a world racing toward automation, understanding when and how to apply human judgment is more valuable than ever.</p><p>Today we&#8217;re exploring manual testing &#8212; not as a legacy practice to be eliminated, but as a sophisticated discipline that remains essential even in the most automated environments.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZT7Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZT7Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZT7Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZT7Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZT7Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZT7Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!ZT7Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZT7Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZT7Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZT7Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cebae4a-2123-4306-a702-72f228470839_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Manual Testing Actually Is</strong></h2><p>Let&#8217;s start with a clear definition, because &#8220;manual testing&#8221; is often misunderstood.</p><p>Manual testing is the practice of a human tester directly interacting with software to evaluate its quality &#8212; without relying on automated scripts to perform the interactions or make the judgments.</p><p>Notice what that definition includes: human interaction, direct evaluation, and human judgment. The tester isn&#8217;t just clicking buttons &#8212; they&#8217;re thinking about what they&#8217;re experiencing, interpreting what they observe, and making assessments about quality.</p><p>This is fundamentally different from automated testing, where scripts perform predefined actions and compare results against predefined expectations. Automation asks: &#8220;Did the expected thing happen?&#8221; Manual testing asks: &#8220;Is this actually good?&#8221;</p><p><strong>What manual testing is not:</strong></p><p>It&#8217;s not &#8220;testing without tools.&#8221; Manual testers use plenty of tools &#8212; browsers, devices, debugging utilities, note-taking applications, screen recorders. The &#8220;manual&#8221; refers to human-driven interaction and judgment, not absence of technology.</p><p>It&#8217;s not &#8220;unskilled testing.&#8221; Effective manual testing requires deep skills in observation, analysis, critical thinking, and domain knowledge. The low barrier to entry doesn&#8217;t mean the ceiling is low.</p><p>It&#8217;s not &#8220;the thing we do until we automate.&#8221; Some testing should never be automated because automation would miss the point entirely. Manual testing isn&#8217;t a waystation &#8212; it&#8217;s a destination.</p><p>It&#8217;s not &#8220;slow and expensive testing.&#8221; Thoughtful manual testing often finds critical issues faster than the time required to write automated tests. The economics depend on context, not on some universal hierarchy where automation is always better.</p><h2><strong>The Irreplaceable Human Elements</strong></h2><p>Why can&#8217;t we just automate everything? Because certain aspects of quality evaluation require capabilities that machines don&#8217;t have &#8212; and may never have.</p><h2><strong>Judgment</strong></h2><p>Machines compare actual results to expected results. Humans judge whether those results are actually good.</p><p>An automated test can verify that an error message appears. It cannot judge whether that error message is helpful, clear, appropriately toned, and likely to guide the user toward a solution. That requires understanding human communication, emotional context, and user psychology.</p><p>A human tester looks at an error message that says &#8220;Error 5012: Transaction failed due to upstream service timeout&#8221; and immediately recognizes that a real user would have no idea what this means or what to do about it.</p><p>Judgment applies to everything: Is this layout intuitive? Is this response fast enough? Is this workflow reasonable? Is this feature actually solving the problem it claims to solve? These questions don&#8217;t have binary answers that automation can check.</p><h2><strong>Intuition</strong></h2><p>Experienced testers develop a sense for where bugs hide. They notice when something &#8220;feels off&#8221; before they can articulate why. They follow hunches that lead to unexpected discoveries.</p><p>This intuition comes from pattern recognition built over thousands of hours of testing. The tester has seen similar implementations fail in similar ways. They&#8217;ve developed mental models of how software tends to break.</p><p>Automation follows predefined paths. Human intuition explores undefined paths that turn out to matter.</p><p>I once watched a senior tester pause on a perfectly functional screen and say, &#8220;Something&#8217;s wrong here.&#8221; She couldn&#8217;t explain it immediately. After investigation, she discovered that the data being displayed was subtly incorrect &#8212; pulled from a cached response instead of current data. The screen worked perfectly. The test cases all passed. But something felt wrong to a human who knew the domain.</p><h2><strong>Context Awareness</strong></h2><p>Humans understand context in ways machines cannot.</p><p>A tester knows that this application is used by doctors in emergency situations, so response times that would be fine for casual browsing are unacceptable here. A tester knows that these users are elderly and may struggle with small text. A tester knows that this feature will launch during a holiday period when support staff is minimal.</p><p>This context shapes what &#8220;quality&#8221; means. The same software might be excellent in one context and terrible in another. Humans navigate context fluidly. Automation operates context-blind.</p><h2><strong>Creativity</strong></h2><p>Finding bugs often requires creative thinking &#8212; trying unexpected combinations, imagining unusual user behaviors, asking &#8220;what if&#8221; questions that nobody thought to include in requirements.</p><p>What if a user opens the same screen in two browser tabs? What if they&#8217;re copying and pasting from a PDF with hidden characters? What if they walk away mid-transaction and come back an hour later? What if they&#8217;re using a screen reader and a keyboard simultaneously?</p><p>Creative exploration surfaces issues that systematic automation never considers because nobody thought to automate those scenarios. The scenarios only became obvious after a human discovered them.</p><h2><strong>Empathy</strong></h2><p>Perhaps most importantly, human testers can empathize with users in ways that scripts cannot.</p><p>They can feel the frustration of a confusing workflow. They can experience the anxiety of wondering whether a payment went through. They can sense when an interface feels hostile or welcoming, trustworthy or suspicious.</p><p>This emotional dimension of quality is invisible to automation but deeply important to actual users.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6r23!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6r23!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6r23!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6r23!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6r23!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6r23!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!6r23!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6r23!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6r23!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6r23!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00d8b2dd-4bfb-4817-a416-8e9013452e8b_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>When Manual Testing Is Essential</strong></h2><p>Manual testing isn&#8217;t always the right choice &#8212; but in certain situations, it&#8217;s the only choice that makes sense.</p><h2><strong>Exploratory Testing</strong></h2><p>When you&#8217;re investigating a new feature without predefined test cases, manual testing is the only option. You&#8217;re learning about the software as you test it, adapting your approach based on what you discover.</p><p>Exploratory testing is inherently human &#8212; it requires curiosity, judgment, and real-time decision-making about where to investigate next. You can&#8217;t automate exploration because you don&#8217;t know where you&#8217;re going until you get there.</p><h2><strong>Usability Evaluation</strong></h2><p>Is this software actually usable? Does it make sense to humans? Is it pleasant or frustrating to use?</p><p>These questions require a human to experience the software as a user would experience it. Automation can verify that buttons are clickable; it cannot evaluate whether users will understand what clicking those buttons will do.</p><p>Usability testing often reveals that technically correct software is practically unusable. The feature works perfectly but nobody can figure out how to access it.</p><h2><strong>Visual and Aesthetic Assessment</strong></h2><p>Does this look right? Is the design consistent? Do the colors convey the right mood? Is the spacing visually balanced?</p><p>Visual assessment requires human aesthetic judgment. Automated visual testing can compare screenshots against baselines, but it cannot judge whether a new design is actually better than the old one.</p><p>A tester notices that the new color scheme makes the &#8220;Delete&#8221; button too subtle &#8212; users might miss it when they need it or click it accidentally because it doesn&#8217;t stand out as dangerous. This is aesthetic judgment with functional implications.</p><h2><strong>User Experience Evaluation</strong></h2><p>Beyond usability, the overall experience &#8212; how the software makes users feel, whether the journey is satisfying, whether users accomplish their goals with confidence.</p><p>A tester experiences the end-to-end flow of signing up for an account, completing their first task, and returning the next day. They notice that the onboarding feels patronizing, the first task has too many steps, and returning users are forced through unnecessary confirmations.</p><p>This holistic experience evaluation requires human judgment about human experience.</p><h2><strong>Early Development Stages</strong></h2><p>When features are in flux, writing automated tests is wasteful &#8212; they&#8217;ll need constant updating as the feature changes. Manual testing provides rapid feedback without the overhead of test maintenance.</p><p>A tester can evaluate a rough prototype and provide meaningful feedback in minutes. That same tester writing automated tests for an unstable feature will spend days maintaining scripts that are obsolete by the time they&#8217;re finished.</p><h2><strong>One-Time or Rare Scenarios</strong></h2><p>Some testing only happens once or rarely &#8212; initial setup validation, migration testing, seasonal feature activation. The investment in automation isn&#8217;t justified when the test will run once or twice.</p><p>Manual testing is efficient for one-off validation. Automation investment makes sense for tests that run repeatedly.</p><h2><strong>Complex Integration Points</strong></h2><p>When testing involves complex external systems, unusual configurations, or environments that are difficult to automate, manual testing may be the practical choice.</p><p>A tester can manually verify integration with a third-party system that has no test environment. They can test on a physical device with specific characteristics. They can validate behavior that depends on real-world conditions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w5ER!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w5ER!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w5ER!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w5ER!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w5ER!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w5ER!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!w5ER!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w5ER!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w5ER!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w5ER!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef02e6e-9e6d-4c72-87af-0860c6291895_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Core Manual Testing Techniques</strong></h2><p>Manual testing isn&#8217;t random clicking. It&#8217;s a disciplined practice with specific techniques that skilled testers apply deliberately.</p><h2><strong>Functional Testing</strong></h2><p>Verifying that the software does what it&#8217;s supposed to do. Features work according to requirements. Inputs produce expected outputs. Business rules are correctly implemented.</p><p>A tester systematically works through the functionality: Can I create a new account? Can I log in with those credentials? Can I update my profile? Can I reset my password? Each capability is verified through direct interaction.</p><p>This is the foundation of manual testing &#8212; ensuring that the software actually works.</p><h2><strong>Boundary Testing</strong></h2><p>Exploring the edges of valid input ranges. What happens at the minimum? The maximum? Just below minimum? Just above maximum?</p><p>If a field accepts 1&#8211;100, a manual tester enters 1, 100, 0, 101, and sees what happens. They enter negative numbers. They enter decimals when integers are expected. They push the boundaries to see where the software breaks.</p><p>Boundaries are where bugs hide. Developers often get the &#8220;normal&#8221; cases right but mishandle the edges.</p><h2><strong>Negative Testing</strong></h2><p>Deliberately doing things wrong to verify the software handles errors gracefully. Invalid inputs. Missing required fields. Operations in the wrong order. Actions by unauthorized users.</p><p>What happens when I submit an empty form? What happens when I enter letters in a phone number field? What happens when I try to access a page I don&#8217;t have permission to view?</p><p>Good software fails gracefully. Manual testers verify that it does by trying to break it.</p><h2><strong>Exploratory Testing</strong></h2><p>Unscripted investigation driven by curiosity and learning. The tester interacts with the software, observes behavior, generates questions, and follows interesting paths.</p><p>This isn&#8217;t random &#8212; it&#8217;s strategic exploration guided by experience and intuition. The tester has a mission (learn about this feature) but not a script (click these buttons in this order).</p><p>Exploratory testing often finds bugs that scripted testing misses because it goes where scripts don&#8217;t.</p><h2><strong>Usability Testing</strong></h2><p>Evaluating the software from the user&#8217;s perspective. Is it intuitive? Is the workflow logical? Are labels clear? Can users accomplish their goals without confusion?</p><p>The tester approaches the software as a user would &#8212; sometimes literally pretending to be a specific type of user. They notice confusion, frustration, and unnecessary friction.</p><p>Usability issues often aren&#8217;t &#8220;bugs&#8221; in the traditional sense &#8212; the software works correctly but fails users anyway.</p><h2><strong>Regression Testing</strong></h2><p>Verifying that existing functionality still works after changes. New features shouldn&#8217;t break old ones. Bug fixes shouldn&#8217;t introduce new bugs. Updates shouldn&#8217;t cause regressions.</p><p>Manual regression testing focuses on areas likely to be affected by changes and areas where regressions would be most damaging. While automation often handles routine regression, manual testing catches the subtle regressions that automated tests miss.</p><h2><strong>Ad Hoc Testing</strong></h2><p>Informal testing without documentation or formal process. The tester interacts with the software based on instinct and experience.</p><p>Ad hoc testing sounds unstructured &#8212; and it is &#8212; but that&#8217;s the point. It&#8217;s the testing equivalent of jazz improvisation. Experienced testers apply their skills without the constraints of process.</p><p>This often happens after formal testing is &#8220;complete.&#8221; A tester continues poking at the software and discovers issues that formal approaches missed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DBw9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DBw9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DBw9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DBw9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DBw9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DBw9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!DBw9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DBw9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DBw9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DBw9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ba718c6-cb04-4bd7-a64f-86a305e09741_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Manual Testing Process</strong></h2><p>While manual testing is more flexible than automated testing, it still benefits from a structured approach.</p><h2><strong>Understanding Before Testing</strong></h2><p>Before touching the software, understand what you&#8217;re testing and why.</p><p>Review requirements, user stories, or specifications. Understand the intended users and their goals. Learn about the technical architecture if relevant. Identify areas of risk and complexity.</p><p>This preparation shapes your testing approach. You&#8217;ll test differently based on what you learn &#8212; focusing more attention on high-risk areas, adjusting your perspective based on who the users are.</p><h2><strong>Planning Your Approach</strong></h2><p>Even exploratory testing benefits from planning. What areas will you focus on? What types of testing will you apply? How much time will you allocate?</p><p>Planning doesn&#8217;t mean scripting every action. It means being intentional about your approach rather than randomly clicking. You might decide: &#8220;I&#8217;ll spend an hour exploring the checkout flow, focusing on edge cases and error handling.&#8221;</p><h2><strong>Executing with Attention</strong></h2><p>During testing, you&#8217;re not just clicking &#8212; you&#8217;re observing, analyzing, and thinking.</p><p>Notice everything. Response times. Visual glitches. Unexpected behaviors. Things that work but feel wrong. Questions that arise. Ideas for further investigation.</p><p>Take notes continuously. Your observations are valuable even when they don&#8217;t result in bug reports. Patterns emerge from accumulated observations.</p><h2><strong>Documenting Findings</strong></h2><p>When you find issues, document them clearly and completely.</p><p>A good bug report includes: what you did, what you expected, what actually happened, and evidence (screenshots, logs, video). It also includes your assessment of severity and impact.</p><p>But documentation goes beyond bugs. Observations about usability, questions about requirements, risks you&#8217;ve identified, and suggestions for improvement &#8212; all valuable outputs from manual testing.</p><h2><strong>Reflecting and Adjusting</strong></h2><p>After testing sessions, reflect on what you learned. What areas need more attention? What new questions arose? How should you adjust your approach?</p><p>Manual testing is iterative. Each session informs the next. You build a deeper understanding of the software over time, which makes your future testing more effective.</p><h2><strong>Manual vs. Automated: Complementary, Not Competing</strong></h2><p>Let&#8217;s be clear: this isn&#8217;t manual versus automated. The best testing strategies use both, applying each where it excels.</p><p><strong>Automation excels at:</strong></p><p>Repetitive execution &#8212; running the same tests hundreds of times without fatigue or variation.</p><p>Speed at scale &#8212; executing thousands of test cases faster than humans ever could.</p><p>Regression coverage &#8212; continuously verifying that existing functionality still works.</p><p>Precise verification &#8212; checking exact values, exact timing, exact behavior against exact expectations.</p><p>CI/CD integration &#8212; providing immediate feedback on every code change.</p><p><strong>Manual testing excels at:</strong></p><p>Judgment and evaluation &#8212; determining whether something is actually good, not just technically correct.</p><p>Exploration and discovery &#8212; finding issues that nobody thought to write tests for.</p><p>Usability and experience &#8212; assessing quality from the human perspective.</p><p>Flexibility and adaptation &#8212; responding to unexpected discoveries in real time.</p><p>Contextual assessment &#8212; evaluating quality given specific user needs and situations.</p><p><strong>The smart approach uses both:</strong></p><p>Automate the repetitive, precise, stable verification work. Apply manual testing for exploration, judgment, and human-centered evaluation. Let each approach do what it does best.</p><p>The ratio varies by context. A mature product with stable features might be 80% automated, 20% manual. A new product with evolving features might be the inverse. The right balance depends on your specific situation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EjOy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EjOy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EjOy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EjOy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EjOy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EjOy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!EjOy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EjOy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EjOy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EjOy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ef184a-a246-4d6e-8ece-6be376c1285e_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Common Manual Testing Pitfalls</strong></h2><p>Manual testing can fail just like any other practice. Here&#8217;s what to avoid.</p><h2><strong>Undisciplined Wandering</strong></h2><p>Exploratory testing is strategic exploration. It&#8217;s not aimless clicking without purpose or plan.</p><p>Undisciplined testing wastes time and misses issues. Without intention, testers often stay in comfortable areas and avoid challenging ones. They duplicate effort without realizing it. They fail to investigate findings deeply enough.</p><p>The fix: Always have a mission. Know what you&#8217;re investigating and why. Take notes to maintain awareness of where you&#8217;ve been.</p><h2><strong>Happy Path Fixation</strong></h2><p>It&#8217;s easy to keep testing things that work. The happy path is comfortable. Everything succeeds. It feels productive.</p><p>But quality problems hide in the unhappy paths &#8212; error handling, edge cases, unexpected inputs, unusual sequences. Testers who avoid discomfort find fewer bugs.</p><p>The fix: Deliberately test the uncomfortable paths. Try to break things. Enter bad data. Take wrong turns. The bugs are where users struggle, not where they succeed.</p><h2><strong>Assumption Blindness</strong></h2><p>Testers often assume they know how something works and test based on those assumptions &#8212; missing bugs that violate the assumptions.</p><p>You assume the date field expects MM/DD/YYYY. You assume the form validates on submit. You assume logged-in users see different content. When assumptions are wrong, bugs hide behind them.</p><p>The fix: Question your assumptions explicitly. Try things that should be impossible. Test what happens, not what you think should happen.</p><h2><strong>Inadequate Documentation</strong></h2><p>Finding a bug but failing to document it well is almost as bad as not finding it. Unclear bug reports get deprioritized or closed as &#8220;cannot reproduce.&#8221;</p><p>Testers sometimes think their job is finding bugs. Actually, the job is communicating about quality in ways that lead to improvement. Documentation is essential.</p><p>The fix: Treat bug reports as important deliverables. Invest time in clarity and completeness. Include evidence. Explain impact.</p><h2><strong>Testing in Isolation</strong></h2><p>Manual testers sometimes operate independently, missing opportunities to leverage what others know.</p><p>Developers know where the code is fragile. Product managers know which features matter most. Users know where they struggle. This knowledge should inform testing.</p><p>The fix: Collaborate. Ask developers where they&#8217;re worried about bugs. Review customer complaints. Align testing with what actually matters.</p><h2><strong>Confirmation Bias</strong></h2><p>Testers sometimes unconsciously test in ways that confirm the software works rather than genuinely trying to find problems.</p><p>This often happens when testers feel pressure to approve releases. They run through tests quickly, accept marginal results, and don&#8217;t dig into suspicions.</p><p>The fix: Adopt a genuinely skeptical mindset. Your job is to find the truth, not to confirm that everything is fine.</p><h2><strong>Building Manual Testing Skills</strong></h2><p>Manual testing looks simple from the outside. In practice, it requires skills that develop over years.</p><h2><strong>Observation Skills</strong></h2><p>Noticing what&#8217;s happening &#8212; not just the obvious, but the subtle. Response time changes. Visual inconsistencies. Behavior that&#8217;s slightly different from last time.</p><p>Build this skill by practicing deliberate observation. After testing a screen, close your eyes and describe everything you saw. What did you miss? Train yourself to see more.</p><h2><strong>Analytical Thinking</strong></h2><p>Understanding why something is happening. Connecting symptoms to causes. Recognizing patterns across multiple observations.</p><p>Build this skill by investigating bugs deeply, not just reporting symptoms. Practice root cause analysis. Ask &#8220;why&#8221; repeatedly until you understand what&#8217;s actually happening.</p><h2><strong>Domain Knowledge</strong></h2><p>Understanding the business context that makes software meaningful. Knowing what users need, what the market expects, what regulations require.</p><p>Build this skill by studying your domain. Talk to users. Read industry publications. Understand the problems the software solves, not just the features it provides.</p><h2><strong>Technical Literacy</strong></h2><p>Understanding enough about how software works to test it effectively. Knowing how databases, APIs, browsers, and networks behave.</p><p>Build this skill through deliberate learning. Take courses. Read documentation. Ask developers to explain how things work. You don&#8217;t need to code, but you need to understand.</p><h2><strong>Communication</strong></h2><p>Translating observations into clear, actionable information. Writing bug reports that get fixed. Explaining quality status to stakeholders. Influencing without authority.</p><p>Build this skill by treating every communication as practice. Review your bug reports after issues are fixed &#8212; did developers understand? Get feedback on your status reports. Learn from communication that works.</p><h2><strong>Critical Thinking</strong></h2><p>Questioning assumptions. Evaluating evidence. Resisting cognitive biases. Distinguishing between what you observed and what you concluded.</p><p>Build this skill by practicing skepticism &#8212; of the software, of requirements, of your own conclusions. Seek disconfirming evidence. Ask &#8220;how might I be wrong?&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jLFZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jLFZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jLFZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jLFZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jLFZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jLFZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!jLFZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jLFZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jLFZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jLFZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2287e8f-2d2c-4761-b97b-53c1e3586c77_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Manual Testing in the Age of AI</strong></h2><p>Here&#8217;s the irony: as AI gets better at automation, manual testing becomes more valuable, not less.</p><h2><strong>AI Amplifies, Humans Judge</strong></h2><p>AI can generate test cases, suggest areas of risk, and even execute exploratory sequences. But AI cannot judge whether the software is actually good. It cannot feel the user experience. It cannot apply contextual understanding that wasn&#8217;t in its training data.</p><p>The future isn&#8217;t AI replacing manual testers. It&#8217;s AI amplifying manual testers &#8212; handling the routine work so humans can focus on judgment, exploration, and experience evaluation.</p><h2><strong>Testing AI Systems</strong></h2><p>AI-powered features require human testing more than traditional features do.</p><p>AI outputs are probabilistic, not deterministic. The same input might produce different outputs. &#8220;Correct&#8221; is often subjective. Edge cases are effectively infinite.</p><p>How do you verify that an AI recommendation is good? That a generated summary is accurate? That a chatbot response is appropriate? These require human judgment &#8212; there&#8217;s no automated oracle.</p><p>As software becomes more AI-powered, manual testing of AI behavior becomes essential.</p><h2><strong>Human Skills, Augmented</strong></h2><p>The manual testing skills we discussed &#8212; observation, analysis, judgment, empathy &#8212; become more valuable when AI handles the mechanical work.</p><p>A tester who can leverage AI to generate initial test ideas, then apply human judgment to refine and execute them, is more effective than either AI or human alone.</p><p>The future belongs to testers who embrace AI as a tool while maintaining the human skills that AI cannot replicate.</p><h2><strong>Starting Your Manual Testing Practice</strong></h2><p>If you&#8217;re new to manual testing, here&#8217;s how to begin.</p><h2><strong>Start With Curiosity</strong></h2><p>Approach software with genuine curiosity. Wonder how it works. Ask what happens if you do unexpected things. Follow your questions wherever they lead.</p><p>Curiosity is the foundation of good testing. It drives exploration, motivates investigation, and sustains attention through long testing sessions.</p><h2><strong>Learn One System Deeply</strong></h2><p>Pick one application and learn it thoroughly. Understand its features, its users, its quirks. Test it repeatedly until you develop intuition about where bugs hide.</p><p>Deep knowledge of one system teaches you how to build knowledge of any system. The meta-skill transfers even when the specific knowledge doesn&#8217;t.</p><h2><strong>Practice Deliberate Observation</strong></h2><p>After each testing session, write down everything you observed &#8212; not just bugs, but behaviors, questions, suspicions. Train yourself to notice more.</p><p>Review your notes after time passes. What did you miss? What turned out to matter? What didn&#8217;t? This reflection builds observational skill.</p><h2><strong>Study Test Design</strong></h2><p>Learn formal techniques &#8212; equivalence partitioning, boundary analysis, decision tables, state transition testing. These give structure to exploration.</p><p>You don&#8217;t need to apply techniques rigidly, but understanding them expands your mental toolkit. You&#8217;ll recognize situations where specific techniques apply.</p><h2><strong>Find Mentors</strong></h2><p>Learn from experienced testers. Watch how they approach testing. Ask how they decide what to test. Study their bug reports.</p><p>Testing skill is largely tacit &#8212; learned through observation and practice more than instruction. Mentors accelerate that learning.</p><h2><strong>Test Everything</strong></h2><p>Practice on everything. Test websites you use daily. Test apps on your phone. Test physical products and processes. Testing is a way of seeing the world.</p><p>The more you practice testing thinking, the more natural it becomes. Eventually, you can&#8217;t stop seeing quality issues everywhere.</p><h2><strong>Your First Manual Testing Exercise</strong></h2><p>Theory is useful. Practice is essential. Here&#8217;s an exercise to start building your skills.</p><p><strong>Pick an application you use regularly.</strong> Not something you test for work &#8212; something you use personally. A banking app. A social media platform. An e-commerce site.</p><p><strong>Spend 30 minutes exploring with testing eyes.</strong> Don&#8217;t just use it &#8212; test it. Try edge cases. Enter unexpected inputs. Navigate in unusual sequences. Try to confuse it.</p><p><strong>Document everything you observe.</strong> Not just bugs &#8212; behaviors, questions, usability issues, things that feel wrong even if you can&#8217;t articulate why.</p><p><strong>Write up your three most interesting findings.</strong> For each: what you observed, what you expected, why it matters, and how you would communicate this to the development team.</p><p><strong>Reflect on the experience.</strong> What was easy? What was difficult? What would you do differently next time? What questions do you still have?</p><p>This single exercise will teach you more about manual testing than reading another three articles. Do it today.</p><h2><strong>The Enduring Value of Human Testing</strong></h2><p>In a world obsessed with automation and AI, manual testing might seem like a relic. It&#8217;s not.</p><p>Manual testing is the application of human intelligence to the problem of software quality. It&#8217;s judgment, intuition, creativity, and empathy directed at understanding whether software actually works for the humans who use it.</p><p>Automation handles the repetitive, the precise, the scalable. Manual testing handles the nuanced, the subjective, the contextual. Together, they provide complete quality coverage that neither achieves alone.</p><p>The testers who thrive in the coming years won&#8217;t be those who resist automation. They&#8217;ll be those who understand when human judgment is irreplaceable &#8212; and apply that judgment with skill, discipline, and purpose.</p><p>In our next article, we&#8217;ll explore <strong>Exploratory Testing Fundamentals</strong> &#8212; the art of learning and testing simultaneously. We&#8217;ll examine how skilled testers structure their exploration, adapt in real-time to discoveries, and uncover bugs that scripted approaches never find.</p><p><strong>Remember:</strong> Automation asks &#8220;Did the expected thing happen?&#8221; Manual testing asks &#8220;Is this actually good?&#8221; Both questions matter. Both need answers.</p>]]></content:encoded></item><item><title><![CDATA[Building Your Testing Career Path]]></title><description><![CDATA[From junior tester to test architect]]></description><link>https://ryancraventech.substack.com/p/building-your-testing-career-path</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/building-your-testing-career-path</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Mon, 09 Feb 2026 13:20:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!D2GA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Nobody grows up dreaming of becoming a software tester.</p><p>Kids say they want to be astronauts, doctors, firefighters. College students target software engineering, product management, data science. Testing? Most people stumble into it sideways &#8212; a temporary stop that becomes a career when they realize they&#8217;re actually good at it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Ryan's Tech Lab is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>And then comes the uncomfortable question: &#8220;What&#8217;s next?&#8221;</p><p>Because unlike development, where the path from junior developer to senior developer to architect to CTO feels well-worn, testing careers can feel like wandering through fog. You&#8217;re good at finding bugs. You&#8217;ve been good at finding bugs for three years. Now what?</p><p>I&#8217;ve watched testers plateau because they didn&#8217;t know paths existed. I&#8217;ve watched others leap ahead because they understood the landscape and moved intentionally. The difference wasn&#8217;t talent &#8212; it was awareness.</p><p>Today we&#8217;re mapping the territory. From your first testing role to the heights of test architecture and beyond, we&#8217;ll explore what each level demands, how to advance deliberately, and the different trajectories available depending on what you actually want from your career.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D2GA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D2GA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!D2GA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!D2GA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!D2GA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D2GA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!D2GA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!D2GA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!D2GA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!D2GA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa406ff69-01de-4574-b462-c12d28cbc897_788x440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Landscape Most Testers Don&#8217;t See</strong></h2><p>Here&#8217;s what nobody tells you when you start in testing: there are actually multiple career paths, and they lead to very different destinations.</p><p><strong>The Individual Contributor (IC) Track</strong> &#8212; You stay hands-on with testing, growing in scope and influence without managing people. Junior to Senior to Staff to Principal. Your expertise deepens, your impact broadens, but you&#8217;re still fundamentally doing testing work.</p><p><strong>The Management Track</strong> &#8212; You shift from doing testing to leading testers. Test Lead to QA Manager to Director to VP of Quality. Your focus moves from finding bugs to building teams, processes, and quality culture.</p><p><strong>The Specialization Track</strong> &#8212; You go deep in a specific testing domain. Performance engineering. Security testing. Automation architecture. Test infrastructure. You become the expert everyone consults for that specialty.</p><p><strong>The Adjacent Track</strong> &#8212; You leverage testing experience to move into related roles. DevOps. Product management. Solutions engineering. Developer advocacy. Testing becomes the foundation for something else.</p><p>None of these paths is superior. They reward different strengths and satisfy different ambitions. The mistake is drifting without choosing &#8212; ending up somewhere by default rather than design.</p><h2><strong>Starting Out: The Junior Tester</strong></h2><p>Every path starts here. You&#8217;re new to testing, learning the fundamentals, and figuring out whether this career fits you.</p><p><strong>What&#8217;s expected of you:</strong></p><p>Execute test cases reliably. Follow documented procedures. Report bugs clearly. Ask questions when you&#8217;re stuck. Learn the systems you&#8217;re testing. Absorb feedback without defensiveness.</p><p>You&#8217;re not expected to design test strategies or identify what&#8217;s missing from test coverage. You&#8217;re expected to do assigned work well and demonstrate you can be trusted with more.</p><p><strong>What you should be learning:</strong></p><p>Testing fundamentals &#8212; how to design test cases, how to think about coverage, how to write bug reports that developers actually want to read. Technical basics &#8212; enough about databases, APIs, and system architecture to understand what you&#8217;re testing. Domain knowledge &#8212; the business context that makes your testing meaningful.</p><p>You should also be learning how your organization works. Who decides what gets tested? How do bugs get prioritized? What does the release process look like? This organizational knowledge matters more than most juniors realize.</p><p><strong>Common mistakes at this level:</strong></p><p>Waiting to be told what to do instead of seeking work proactively. Not asking questions because you&#8217;re afraid of looking stupid. Focusing only on test execution without understanding why tests exist. Missing the big picture while drowning in details.</p><p><strong>How to advance:</strong></p><p>Demonstrate reliability first. Complete assigned work consistently and well. Then demonstrate initiative &#8212; find gaps in test coverage, suggest improvements, volunteer for challenging assignments. Show that you&#8217;re thinking beyond your current scope.</p><p>Most juniors stay at this level for one to two years. Some advance faster by being exceptional. Others linger longer because they&#8217;re content or because they haven&#8217;t demonstrated readiness for more responsibility.</p><h2><strong>Finding Your Footing: The Mid-Level Tester</strong></h2><p>You&#8217;ve proven you can execute. Now you need to prove you can think.</p><p><strong>What&#8217;s expected of you:</strong></p><p>Design test cases, not just execute them. Identify what should be tested for a feature without detailed guidance. Mentor junior testers. Participate meaningfully in planning discussions. Start contributing to test automation. Handle ambiguity without constant direction.</p><p>You&#8217;re no longer just following procedures &#8212; you&#8217;re helping create them.</p><p><strong>What you should be learning:</strong></p><p>Test design techniques in depth &#8212; equivalence partitioning, boundary analysis, state transitions, combinatorial testing. When to apply each and how to combine them. Automation skills &#8212; enough to write and maintain automated tests, even if you&#8217;re not building frameworks. Communication skills &#8212; how to influence without authority, how to deliver bad news constructively, how to advocate for quality.</p><p>This is also when you should start exploring what interests you. Does automation energize you? Does performance testing intrigue you? Do you enjoy mentoring others? These signals point toward future directions.</p><p><strong>Common mistakes at this level:</strong></p><p>Staying in execution mode when you should be in design mode. Avoiding automation because it&#8217;s uncomfortable. Not building relationships across teams. Failing to make your work visible to people who matter.</p><p><strong>How to advance:</strong></p><p>Take ownership of something. Maybe it&#8217;s a feature area, a type of testing, or an automation initiative. Own it completely &#8212; don&#8217;t wait for permission or assignment. Demonstrate that you can drive results without close supervision.</p><p>Also start developing others. Help juniors grow. Share knowledge. Your advancement increasingly depends on making the whole team better, not just being good individually.</p><p>Mid-level is where paths start diverging. Some testers stay here contentedly for years. Others begin pointing toward specialization, leadership, or advancement on the IC track.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aFmS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aFmS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aFmS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aFmS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aFmS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aFmS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!aFmS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aFmS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aFmS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aFmS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07e57bc4-df16-49be-9b1e-e1ba0a866ef9_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Becoming a Force: The Senior Tester</strong></h2><p>Senior is where many testers aim to land. It&#8217;s a comfortable level &#8212; respected, well-compensated, and still hands-on. It&#8217;s also where many careers stall.</p><p><strong>What&#8217;s expected of you:</strong></p><p>Define test strategies for projects or product areas. Make coverage decisions that balance thoroughness with practicality. Lead testing efforts without formal authority. Mentor mid-level and junior testers effectively. Identify risks before they materialize. Communicate quality status to stakeholders clearly.</p><p>You&#8217;re the person others look to for testing decisions in your area.</p><p><strong>What you should be learning:</strong></p><p>Strategic thinking &#8212; how testing connects to business outcomes, how to prioritize based on risk and value, how to communicate with executives who don&#8217;t understand testing details. Technical depth in areas relevant to your work &#8212; if you test web applications, really understand browsers and protocols; if you test distributed systems, understand consistency and failure modes.</p><p>You should also be building your reputation beyond your immediate team. Write. Speak. Contribute to communities. Your career increasingly depends on being known, not just being good.</p><p><strong>Common mistakes at this level:</strong></p><p>Staying in your comfort zone instead of stretching into strategy and leadership. Hoarding knowledge instead of developing others. Avoiding organizational politics that affect your work. Not building external reputation.</p><p><strong>How to advance:</strong></p><p>This is where the paths really diverge, and you need to make intentional choices.</p><p>If you want the IC track toward Staff and Principal: Find ways to have impact beyond your immediate team. Solve problems that span multiple products or organizations. Become known for technical expertise that others depend on.</p><p>If you want management: Start taking on informal leadership. Coordinate work across people. Show that you can be responsible for team outcomes, not just individual outcomes.</p><p>If you want specialization: Go deep. Become the expert. Build reputation in your specialty area internally and externally.</p><p>The trap at Senior level is comfort. You&#8217;re good at your job. You&#8217;re well-paid. Things are fine. That comfort can become a cage if you&#8217;re not careful.</p><h2><strong>The Individual Contributor Heights: Staff and Principal</strong></h2><p>Beyond Senior on the IC track are levels that many testers don&#8217;t know exist: Staff and Principal (titles vary &#8212; some companies say &#8220;Lead&#8221; or &#8220;Distinguished&#8221; or &#8220;Fellow&#8221;).</p><p>These roles exist for individual contributors who have impact far beyond their immediate work &#8212; technical leaders who don&#8217;t manage people but shape how entire organizations approach testing.</p><p><strong>Staff Tester</strong></p><p><strong>What&#8217;s expected of you:</strong></p><p>Solve testing problems that span multiple teams or products. Define testing practices adopted across the organization. Be the person engineering leadership consults on quality strategy. Mentor senior testers toward staff level. Drive technical initiatives that change how testing works.</p><p>Your scope is organization-wide, not team-wide. You&#8217;re working on the testing approach itself, not just testing products.</p><p><strong>What this looks like in practice:</strong></p><p>Maybe you&#8217;re designing the automation architecture that all teams use. Maybe you&#8217;re defining the performance testing standards for the company. Maybe you&#8217;re building the test data management system that unblocks a dozen teams. Maybe you&#8217;re driving a cultural shift toward quality ownership.</p><p>Staff impact is measured in how you make others more effective, not just in your individual output.</p><p><strong>Principal Tester</strong></p><p><strong>What&#8217;s expected of you:</strong></p><p>Shape industry practices, not just organizational ones. Be recognized as an expert beyond your company. Solve problems nobody else has solved. Define the testing strategy for new technology or business areas. Influence engineering leadership at the highest levels.</p><p>Principal-level testers are rare. Many organizations don&#8217;t have the title or don&#8217;t know they need it. Principal testers are often confused with contractors or consultants because their work doesn&#8217;t fit normal molds.</p><p><strong>What this looks like in practice:</strong></p><p>Maybe you&#8217;re defining how your company approaches testing for AI systems when nobody has good answers. Maybe you&#8217;re representing your company&#8217;s quality perspective in industry standards bodies. Maybe you&#8217;re the person who gets called when an acquisition happens to figure out how to integrate testing organizations.</p><p>Principal is less a job and more a reputation. You reach it by being undeniably excellent over a sustained period.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m6eg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m6eg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!m6eg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!m6eg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!m6eg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m6eg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!m6eg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!m6eg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!m6eg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!m6eg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5238b6c-73df-456e-81f2-e66e33ab78c9_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Management Track: Leading Testers</strong></h2><p>Not everyone wants to stay hands-on. Some testers discover they&#8217;re energized by building teams and developing people. The management track is for them.</p><p><strong>Test Lead</strong></p><p>The first step away from pure individual contribution. You&#8217;re still doing significant testing work, but you&#8217;re also coordinating work across a small group &#8212; maybe two to five testers.</p><p>You&#8217;re learning the basics: how to assign work fairly, how to run effective meetings, how to give feedback, how to shield your team from distractions, how to represent testing in cross-functional discussions.</p><p>Many organizations use &#8220;Test Lead&#8221; as a stepping stone to see if someone has management potential before committing to a full management role.</p><p><strong>QA Manager</strong></p><p>Now you&#8217;re managing testers. Your primary job shifts from testing to enabling testers to do their best work.</p><p>Hiring. Performance reviews. Career development. Team culture. Process improvement. Stakeholder management. Budget. Capacity planning.</p><p>You&#8217;re still close enough to the work to make technical decisions, but you&#8217;re spending most of your time on people and process, not on finding bugs yourself.</p><p>The hardest transition: letting go of being the best tester on the team. Your job isn&#8217;t to be the best tester &#8212; it&#8217;s to build a team of great testers. If you can&#8217;t let go of individual contribution, management will frustrate you.</p><p><strong>Director of QA</strong></p><p>You&#8217;re managing managers now &#8212; or managing a large enough team that you can&#8217;t have direct relationships with everyone.</p><p>Your focus shifts to strategy and organization design. How should testing be organized? What capabilities does the function need? How does quality strategy align with business strategy?</p><p>You&#8217;re representing quality at the leadership table, influencing decisions that affect the entire engineering organization. You need executive communication skills &#8212; the ability to translate testing concerns into business terms.</p><p><strong>VP of Quality / Head of Quality</strong></p><p>The summit of the management track in most organizations. You&#8217;re responsible for quality across the company &#8212; testing, but also broader quality culture, processes, and outcomes.</p><p>At this level, you&#8217;re less a testing expert and more a business leader who happens to focus on quality. You&#8217;re dealing with board presentations, M&amp;A due diligence, organizational transformation, and strategic planning.</p><p>Very few testers reach this level. Those who do have typically been intentional about building business acumen and executive presence alongside their quality expertise.</p><h2><strong>The Specialization Track: Going Deep</strong></h2><p>Some testers don&#8217;t want broader scope &#8212; they want deeper expertise. Specialization tracks let you become the undisputed expert in a specific domain.</p><p><strong>Performance Engineering</strong></p><p>You focus on how systems behave under load. Performance testing, load testing, stress testing, capacity planning, performance optimization.</p><p>This specialization requires strong technical skills &#8212; understanding of system architecture, profiling tools, database tuning, infrastructure. Performance engineers often have backgrounds in development or operations.</p><p>Career path: Performance Tester &#8594; Senior Performance Engineer &#8594; Performance Architect &#8594; Distinguished Performance Engineer.</p><p>The deep end of this specialization often involves application performance management (APM), site reliability engineering (SRE), or capacity planning roles that sit somewhere between testing and operations.</p><p><strong>Security Testing</strong></p><p>You focus on finding vulnerabilities before attackers do. Penetration testing, security assessments, threat modeling, security architecture review.</p><p>This specialization requires understanding of attack vectors, security tools, compliance frameworks, and the attacker mindset. Security testers often pursue certifications (OSCP, CEH) that validate their expertise.</p><p>Career path: Security Tester &#8594; Penetration Tester &#8594; Security Engineer &#8594; Security Architect &#8594; CISO.</p><p>Security is one of the few testing specializations with a clear path to executive level (Chief Information Security Officer), though that path involves much more than testing.</p><p><strong>Automation Architecture</strong></p><p>You focus on building the testing infrastructure that enables everyone else. Test frameworks, CI/CD pipeline integration, test data management, test environment orchestration.</p><p>This specialization requires strong development skills &#8212; you&#8217;re building software that tests software. Automation architects often have development backgrounds or develop those skills deeply in role.</p><p>Career path: Automation Engineer &#8594; Senior Automation Engineer &#8594; Automation Architect &#8594; Principal Engineer (Test Infrastructure).</p><p>The deep end of this specialization often converges with platform engineering or developer experience roles.</p><p><strong>Accessibility Testing</strong></p><p>You focus on ensuring software works for users with disabilities. WCAG compliance, assistive technology testing, inclusive design review.</p><p>This specialization requires understanding of accessibility standards, assistive technologies, and the diverse ways users interact with software. Deep empathy for users with disabilities is essential.</p><p>Career path: Accessibility Tester &#8594; Accessibility Specialist &#8594; Accessibility Lead &#8594; Director of Accessibility.</p><p>This specialization is growing as regulatory requirements increase and organizations recognize accessibility as both ethical imperative and business advantage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EtxK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EtxK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EtxK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EtxK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EtxK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EtxK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!EtxK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EtxK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EtxK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EtxK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9807452-c744-48e9-b0ca-9d6cb5b93424_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Adjacent Track: Leveraging Testing Experience</strong></h2><p>Testing experience opens doors to roles that aren&#8217;t testing but benefit enormously from testing background.</p><p><strong>DevOps / Site Reliability Engineering</strong></p><p>Testing teaches you to think about failure modes, edge cases, and system behavior under stress. DevOps and SRE roles need exactly that thinking applied to production systems.</p><p>Testers who move to DevOps bring quality thinking to operations &#8212; monitoring, alerting, deployment verification, incident response. The combination is powerful.</p><p><strong>Product Management</strong></p><p>Testing teaches you to understand user needs, identify what could go wrong, and evaluate whether software actually solves problems. Product managers need those same skills applied to product decisions.</p><p>Testers who move to product bring rigor to requirements, healthy skepticism about feature proposals, and deep understanding of what it takes to build quality software.</p><p><strong>Solutions Engineering / Sales Engineering</strong></p><p>Testing teaches you to understand software deeply and explain it clearly to non-technical audiences. Solutions engineers do exactly that &#8212; help customers understand how software solves their problems.</p><p>Testers who move to solutions engineering bring credibility (they really understand the product) and realistic expectations (they know what works and what doesn&#8217;t).</p><p><strong>Developer Advocacy / Developer Relations</strong></p><p>Testing teaches you to understand developer experience &#8212; what makes tools pleasant or frustrating to use. Developer advocates help external developers succeed with a company&#8217;s products.</p><p>Testers who move to developer advocacy bring the user empathy and clear communication skills that make technical content accessible.</p><p><strong>Engineering Management</strong></p><p>Some testers discover they want to lead engineers, not just testers. The transition from QA management to engineering management is possible, though it requires building technical credibility with developers.</p><p>Testing experience brings unique value to engineering management &#8212; quality thinking embedded in development leadership rather than separated from it.</p><h2><strong>Building Skills for Advancement</strong></h2><p>Regardless of which path you choose, certain skills become increasingly important as you advance.</p><p><strong>Technical Skills That Scale</strong></p><p>Early career: Learn tools and technologies specific to your current role.</p><p>Mid career: Learn principles that transfer across tools and technologies. Understanding HTTP matters more than mastering any particular API testing tool.</p><p>Late career: Learn to evaluate and adopt new technologies rapidly. The specific technologies will keep changing &#8212; your ability to learn and apply them matters more than any particular expertise.</p><p><strong>Communication Skills</strong></p><p>Early career: Write clear bug reports. Ask good questions.</p><p>Mid career: Explain testing concepts to non-testers. Deliver difficult feedback constructively. Present to stakeholders.</p><p>Late career: Communicate with executives in business terms. Influence without authority across organizational boundaries. Represent quality at the leadership table.</p><p>Communication skills compound. Every level demands more sophisticated communication than the last.</p><p><strong>Strategic Thinking</strong></p><p>Early career: Understand why tests exist, not just how to execute them.</p><p>Mid career: Design test strategies that balance coverage with practicality. Prioritize based on risk.</p><p>Late career: Connect testing strategy to business outcomes. Make investment decisions about quality capabilities. Shape organizational approach to quality.</p><p><strong>Relationship Building</strong></p><p>Early career: Build good working relationships with immediate teammates.</p><p>Mid career: Build relationships across teams. Know who to ask for help. Develop reputation within your organization.</p><p>Late career: Build relationships across the industry. Develop reputation externally. Know people who can open doors.</p><p>Relationships matter more than most technical people want to admit. Advancement increasingly depends on who knows you and trusts you.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8_BQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8_BQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8_BQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8_BQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8_BQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8_BQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!8_BQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8_BQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8_BQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8_BQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8fe2e2-0b50-4fcc-89cd-7312ca3514cd_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Moves That Accelerate Careers</strong></h2><p>Some career moves create disproportionate acceleration. These are the opportunities to seek out.</p><p><strong>High-Visibility Projects</strong></p><p>Projects that matter to leadership get attention. Success on visible projects creates reputation faster than quiet excellence on routine work. Seek them out, even if they&#8217;re riskier.</p><p><strong>Organizational Change</strong></p><p>When companies reorganize, grow rapidly, or face crises, normal career timelines compress. People get opportunities they wouldn&#8217;t get in stable times. Lean into change rather than avoiding it.</p><p><strong>Stretch Assignments</strong></p><p>Take assignments slightly beyond your current capability. Not so far beyond that you&#8217;ll fail, but far enough to force growth. The discomfort is the point.</p><p><strong>External Reputation</strong></p><p>Write articles. Speak at meetups and conferences. Contribute to open source. External reputation opens doors that internal reputation can&#8217;t. It also makes you more valuable internally &#8212; companies like employing recognized experts.</p><p><strong>Mentorship (Both Directions)</strong></p><p>Find mentors who can guide your development. Also mentor others &#8212; teaching forces you to understand things deeply and builds your reputation as a leader.</p><p><strong>Strategic Job Changes</strong></p><p>Sometimes the right move is leaving. Not job-hopping randomly, but strategic moves to organizations where you can grow faster, learn more, or access opportunities unavailable in your current role.</p><p>The testers who advance fastest combine excellent work with strategic positioning. Excellence alone isn&#8217;t enough &#8212; you need to be excellent at things that matter and make sure the right people know it.</p><h2><strong>Preparing for the AI-Transformed Landscape</strong></h2><p>Here&#8217;s a reality check: the testing career paths we&#8217;ve discussed are evolving as AI reshapes the field. The testers who thrive in the next decade will be those who adapt deliberately rather than react defensively.</p><p><strong>What&#8217;s changing:</strong></p><p>AI is automating the predictable parts of testing. Test case generation. Routine regression execution. Basic bug detection. The tasks that filled junior tester schedules five years ago are increasingly handled by machines.</p><p>This isn&#8217;t a threat &#8212; it&#8217;s a shift. The work isn&#8217;t disappearing. It&#8217;s elevating.</p><p><strong>What this means for each career stage:</strong></p><p><strong>Junior testers</strong> need to learn AI tools from day one. Not just how to use them, but how to evaluate their output. AI generates test cases &#8212; but are they the right test cases? AI flags potential bugs &#8212; but are they real? The junior skill set now includes AI collaboration alongside traditional fundamentals.</p><p><strong>Mid-level testers</strong> become AI supervisors. You&#8217;re designing prompts, curating AI-generated tests, and catching what AI misses. You&#8217;re also identifying where AI adds value versus where human judgment remains essential. This discernment becomes a core competency.</p><p><strong>Senior testers</strong> define AI testing strategy. Which workflows benefit from AI? Where does automation make sense versus human exploration? How do you maintain quality when AI accelerates development velocity? Strategic thinking now includes AI integration decisions.</p><p><strong>Staff and Principal levels</strong> shape how organizations adopt AI in testing. You&#8217;re evaluating tools, defining governance, building frameworks for AI-assisted quality. You&#8217;re also tackling the novel challenge of testing AI systems themselves &#8212; a specialization that barely existed five years ago.</p><p><strong>New specialization emerging: AI Quality Engineering</strong></p><p>Testing AI systems is fundamentally different from testing traditional software. Outputs are probabilistic, not deterministic. Edge cases are infinite. &#8220;Correct&#8221; behavior is often subjective.</p><p>This specialization requires understanding of machine learning concepts, prompt engineering, bias detection, and evaluation methodologies that are still being invented. Testers who develop expertise here are positioning themselves for roles that don&#8217;t fully exist yet &#8212; but will.</p><p><strong>The skills that AI can&#8217;t replace:</strong></p><p>Judgment about what matters. Empathy for user experience. Skepticism about whether something actually works. Creative exploration of unexpected scenarios. Communication that turns findings into action.</p><p>These human skills become more valuable, not less, as AI handles routine work.</p><p><strong>Your AI readiness checklist:</strong></p><p>Are you using AI tools in your current testing work? Do you understand their limitations? Can you evaluate AI-generated test cases critically? Have you tested an AI-powered feature? Do you understand basic concepts like training data, hallucination, and prompt design?</p><p>If you answered no to most of these, you have gaps to close.</p><p>The testers who ignore AI will find their skills commoditized. The testers who embrace AI thoughtfully will find their impact multiplied.</p><p>Choose deliberately.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tF81!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tF81!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tF81!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tF81!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tF81!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tF81!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!tF81!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tF81!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tF81!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tF81!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be35139-29e6-415f-8be6-d9a5949a7b01_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Plateau Problem</strong></h2><p>Let&#8217;s talk about what happens when careers stall.</p><p>Many testers hit a plateau around Senior level. They&#8217;re good at their jobs. They&#8217;re comfortable. And they stop growing.</p><p>Sometimes this is intentional &#8212; not everyone wants to keep climbing. A satisfying career at a level you enjoy is a valid choice.</p><p>But often it&#8217;s unintentional. Testers don&#8217;t realize they&#8217;ve stopped growing until they try to change jobs and discover their skills haven&#8217;t kept pace with the market.</p><p><strong>Signs you&#8217;re plateauing:</strong></p><p>You haven&#8217;t learned anything significant in the past year. Your responsibilities haven&#8217;t increased. You&#8217;re doing the same work you did two years ago. You&#8217;re not being considered for advancement. You&#8217;re comfortable.</p><p><strong>How to break a plateau:</strong></p><p>Change something. Take on a new challenge in your current role. Move to a different team or company. Learn a new skill. Pursue a specialization. Volunteer for the project nobody wants.</p><p>Plateaus are broken by discomfort. If you&#8217;re comfortable, you&#8217;re probably not growing.</p><h2><strong>Making Your Choice</strong></h2><p>You&#8217;ve seen the landscape. Now you need to choose a direction.</p><p>Ask yourself:</p><p><strong>Do you want to stay hands-on with testing?</strong> The IC track keeps you close to the work while expanding your scope and influence.</p><p><strong>Do you want to build and lead teams?</strong> The management track shifts your focus from doing testing to enabling testers.</p><p><strong>Do you want to be the undisputed expert in something?</strong> Specialization tracks let you go deeper than generalists can.</p><p><strong>Do you want to leverage testing into something else?</strong> Adjacent tracks use your testing foundation for different career destinations.</p><p>There&#8217;s no wrong answer &#8212; only answers that fit or don&#8217;t fit what you actually want.</p><p>And you can change your mind. Paths aren&#8217;t permanent. Staff engineers become managers. Managers return to IC roles. Specialists broaden out. Career paths are more like climbing walls than ladders &#8212; you can move in multiple directions.</p><h2><strong>Your Career Planning Exercise</strong></h2><p>Don&#8217;t just read this article &#8212; do something with it.</p><p><strong>Step 1: Assess your current position.</strong> Where are you in the landscape? What level? What path are you on by default?</p><p><strong>Step 2: Define your target.</strong> Where do you want to be in three years? Five years? Which path attracts you most?</p><p><strong>Step 3: Identify the gaps.</strong> What skills does your target require that you don&#8217;t have today? What experiences are you missing?</p><p><strong>Step 4: Make a plan.</strong> How will you close those gaps? What will you do in the next six months? Be specific.</p><p><strong>Step 5: Take one action this week.</strong> Not someday. This week. One concrete step toward your career goal.</p><p>Your career won&#8217;t build itself. Waiting to be noticed is not a strategy. Hoping for promotion is not a plan.</p><p>Be intentional. Make choices. Take action.</p><h2><strong>Your Career, Your Responsibility</strong></h2><p>The testing career path isn&#8217;t as clearly marked as development paths. That&#8217;s frustrating, but it&#8217;s also freeing. You have more room to define your own trajectory.</p><p>The testers who build great careers share a common trait: they take responsibility for their own development. They don&#8217;t wait for their company to invest in them. They don&#8217;t expect promotions to happen automatically. They identify where they want to go and work deliberately to get there.</p><p>Paths from junior tester to test architect exist. Paths to management exist. Paths to specialization exist. Paths to adjacent roles exist.</p><p>But nobody will walk those paths for you.</p><p>In our next article, we&#8217;ll explore <strong>Introduction to Manual Testing</strong> &#8212; understanding when human judgment is irreplaceable. In a world racing toward automation and AI, we&#8217;ll examine why manual testing remains essential, what humans catch that machines miss, and how to apply manual testing strategically rather than as a default.</p><p><strong>Remember:</strong> Career paths exist. Most testers just don&#8217;t know about them. Now you do. What will you do with that knowledge?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Ryan's Tech Lab is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Testing Mindset vs Development Mindset]]></title><description><![CDATA[Complementary perspectives on quality]]></description><link>https://ryancraventech.substack.com/p/the-testing-mindset-vs-development</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/the-testing-mindset-vs-development</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Fri, 06 Feb 2026 14:24:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4vwH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><p>I watched a developer and a tester argue for twenty minutes about whether something was a bug.</p><p>The developer built a form that accepted dates in MM/DD/YYYY format. The tester entered &#8220;13/45/2024&#8221; and the system crashed. Bug, right?</p><p>&#8220;That&#8217;s not a valid date,&#8221; the developer said. &#8220;No reasonable user would enter that.&#8221;</p><p>&#8220;But the system crashed,&#8221; the tester replied. &#8220;It should handle invalid input gracefully.&#8221;</p><p>They were both right. And they were talking past each other completely.</p><p>The developer was thinking about how the feature should work when used correctly. The tester was thinking about what happens when it&#8217;s used incorrectly. Neither perspective was wrong&#8202;&#8212;&#8202;they were just different lenses on the same reality.</p><p>This is the fundamental tension between the testing mindset and the development mindset. Not a conflict to be resolved, but a complementary pair that together creates better software than either could alone.</p><p>Today we&#8217;re exploring these two mindsets&#8202;&#8212;&#8202;how they differ, why they differ, and how understanding both makes you better at whichever role you occupy.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4vwH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4vwH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4vwH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4vwH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4vwH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4vwH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4vwH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4vwH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4vwH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4vwH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc59308c-d12f-4c1a-b3d1-f0c5b00ef19d_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Two Valid Ways of Seeing</h3><p>Let&#8217;s start with a fundamental truth: neither mindset is superior. They&#8217;re different tools for different jobs.</p><p>The development mindset is fundamentally constructive. Developers take requirements and transform them into working systems. They solve problems by building solutions. Their success is measured by creating something that works.</p><p>The testing mindset is fundamentally analytical. Testers take working systems and evaluate whether they actually meet needs. They find problems by examining solutions. Their success is measured by discovering what doesn&#8217;t work before users do.</p><p>Construction and analysis. Building and evaluating. Creating and questioning.</p><p>Software needs both. A team of only builders creates systems that work in ideal conditions but crumble under real-world stress. A team of only analysts never ships anything because there&#8217;s always another potential problem to investigate.</p><p>The magic happens when both mindsets collaborate&#8202;&#8212;&#8202;when builders and analysts work together toward shared quality goals.</p><div><hr></div><h3>The Core Differences</h3><p>Let&#8217;s examine how these mindsets differ across several dimensions.</p><h3>Relationship with Requirements</h3><p><strong>Development mindset:</strong> Requirements are a blueprint to implement. The goal is translating requirements into functioning code. Success means the code does what the requirements specify.</p><p><strong>Testing mindset:</strong> Requirements are hypotheses to validate. The goal is determining whether the implementation actually meets user needs. Success means confirming the software works&#8202;&#8212;&#8202;or discovering where it doesn&#8217;t.</p><p>A developer reads a requirement and thinks: &#8220;How do I build this?&#8221;</p><p>A tester reads the same requirement and thinks: &#8220;How will I know if this actually works? What could go wrong? What&#8217;s ambiguous here?&#8221;</p><p>Same document, different questions.</p><h3>Relationship with the Happy Path</h3><p><strong>Development mindset:</strong> The happy path is the primary focus. If users do what they&#8217;re supposed to do, in the order they&#8217;re supposed to do it, with the data they&#8217;re supposed to use, everything works. The happy path is where developers spend most of their mental energy.</p><p><strong>Testing mindset:</strong> The happy path is just the starting point. Of course it should work&#8202;&#8212;&#8202;but what about the sad paths? The angry paths? The confused paths? The malicious paths? Testers spend most of their mental energy on everything except the happy path.</p><p>This isn&#8217;t because developers don&#8217;t care about edge cases. It&#8217;s because building the happy path is genuinely hard and consumes significant cognitive resources. By the time it works, there&#8217;s often limited mental energy left for imagining all the ways users might deviate from the expected flow.</p><p>Testers arrive fresh, with full cognitive resources dedicated to asking &#8220;what if?&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!09kT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!09kT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!09kT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!09kT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!09kT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!09kT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!09kT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!09kT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!09kT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!09kT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cf24c4-6aec-4ffc-91ea-fcfc87518bd3_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Relationship with Their Own Work</h3><p><strong>Development mindset:</strong> Pride in creation. Developers invest significant intellectual and emotional energy in their code. They&#8217;ve solved hard problems, made difficult decisions, and crafted something that works. There&#8217;s natural ownership and attachment.</p><p><strong>Testing mindset:</strong> Detachment for objectivity. Testers examine systems they didn&#8217;t build, which provides natural distance. They have no ego investment in the code working&#8202;&#8212;&#8202;their investment is in finding the truth about whether it works.</p><p>This difference explains why developers testing their own code often miss bugs that are obvious to others. It&#8217;s not incompetence&#8202;&#8212;&#8202;it&#8217;s human nature. We see what we expect to see, especially in things we created.</p><h3>Relationship with Time</h3><p><strong>Development mindset:</strong> Forward momentum. Developers are measured by features completed, code shipped, problems solved. Progress means moving forward. Stopping to reconsider finished work feels like going backward.</p><p><strong>Testing mindset:</strong> Deliberate examination. Testers are measured by issues found, confidence established, risks identified. Progress means thorough evaluation. Rushing past potential problems defeats the purpose.</p><p>This creates natural tension. Developers feel tested code is &#8220;done&#8221; and want to move on. Testers feel examined code needs more investigation. Both impulses are valid&#8202;&#8212;&#8202;the tension is productive when managed well.</p><h3>Relationship with Failure</h3><p><strong>Development mindset:</strong> Failure is a problem to fix. When code doesn&#8217;t work, something is wrong. The goal is making it work. Failure is a temporary state on the path to success.</p><p><strong>Testing mindset:</strong> Failure is information to capture. When software doesn&#8217;t work, something has been learned. The goal is documenting what happened, understanding why, and ensuring it gets addressed. Failure is valuable data.</p><p>A developer sees a crash and thinks: &#8220;I need to fix this.&#8221;</p><p>A tester sees the same crash and thinks: &#8220;I need to document this, understand the conditions that caused it, assess its severity, and verify it gets fixed.&#8221;</p><div><hr></div><h3>Why These Differences Exist</h3><p>These mindset differences aren&#8217;t arbitrary. They emerge from the fundamentally different nature of the work.</p><p><strong>Building requires optimism.</strong> Creating something from nothing demands belief that problems can be solved, that the vision can become reality, that the complex pieces will eventually fit together. Pessimistic builders struggle to start&#8202;&#8212;&#8202;there are always reasons why something might not work.</p><p><strong>Evaluating requires skepticism.</strong> Determining whether something actually works demands questioning assumptions, doubting claims, and looking for evidence of problems. Optimistic evaluators miss issues&#8202;&#8212;&#8202;they assume things work without verification.</p><p><strong>Building requires focus.</strong> Developers hold enormous complexity in their heads&#8202;&#8212;&#8202;data structures, algorithms, state management, edge cases they&#8217;re handling. This focused attention is necessary for construction but leaves little room for imagining problems they haven&#8217;t anticipated.</p><p><strong>Evaluating requires breadth.</strong> Testers consider many scenarios, user types, and failure modes. They can&#8217;t focus as deeply on any single area because their job is covering the entire surface.</p><p><strong>Building requires confidence.</strong> Making hundreds of decisions about how to implement something demands confidence in your judgment. Second-guessing every choice would paralyze progress.</p><p><strong>Evaluating requires doubt.</strong> Verifying those decisions are correct demands questioning them. Accepting every choice without investigation would miss problems.</p><p>Neither set of traits is better. They&#8217;re adapted to different functions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B8Z-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B8Z-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!B8Z-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!B8Z-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!B8Z-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B8Z-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!B8Z-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!B8Z-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!B8Z-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!B8Z-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9bd1a4-e4c8-48e9-9a1b-a1cf1d6fd3ae_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>The Blended Reality</h3><p>Here&#8217;s where it gets nuanced: real people don&#8217;t fit neatly into one mindset.</p><p>Good developers do think about edge cases. They write unit tests. They consider what could go wrong. They&#8217;re not naive optimists who ignore potential problems.</p><p>Good testers do understand construction. They appreciate the difficulty of building software. They know why certain bugs happen. They&#8217;re not just destructive critics who tear things down.</p><p>The mindsets exist on a spectrum, and effective practitioners of either role can shift along that spectrum as needed.</p><p>But there&#8217;s a default mode&#8202;&#8212;&#8202;a home base where each role naturally lives. Developers default to constructive thinking and shift to analytical thinking when necessary. Testers default to analytical thinking and shift to constructive thinking when necessary.</p><p>And that default matters. When under pressure, people revert to their default. A developer under deadline pressure focuses on making things work, potentially cutting corners on edge case handling. A tester under pressure to approve a release focuses on finding problems, potentially raising issues that don&#8217;t matter much.</p><p>Understanding your default helps you compensate for its blind spots.</p><div><hr></div><h3>How Misunderstanding Creates Conflict</h3><p>When developers and testers don&#8217;t understand each other&#8217;s mindsets, predictable conflicts emerge.</p><p><strong>Developers see testers as obstacles.</strong> &#8220;They just find problems. They don&#8217;t understand how hard this was to build. They&#8217;re never satisfied.&#8221;</p><p><strong>Testers see developers as careless.</strong> &#8220;They don&#8217;t think about edge cases. They just want to ship and move on. They don&#8217;t care about quality.&#8221;</p><p>Both perceptions are wrong. They&#8217;re what happens when different mindsets interpret each other through their own lens.</p><p>The developer&#8217;s desire to move forward isn&#8217;t carelessness&#8202;&#8212;&#8202;it&#8217;s appropriate focus on construction. The tester&#8217;s insistence on investigation isn&#8217;t obstruction&#8202;&#8212;&#8202;it&#8217;s appropriate focus on evaluation.</p><p>Conflict happens when neither side recognizes the other&#8217;s perspective as valid.</p><p>The developer who sees a bug report as an attack on their competence gets defensive. The tester who sees pushback on a bug as dismissing their expertise gets frustrated. Each interaction reinforces negative perceptions.</p><p>I&#8217;ve watched this spiral destroy team relationships. I&#8217;ve also watched teams transcend it by developing genuine appreciation for what the other mindset contributes.</p><div><hr></div><h3>The Developer Who Understands Testing</h3><p>The best developers I&#8217;ve worked with have developed genuine testing intuition.</p><p>They think about edge cases before testers find them. They write comprehensive unit tests not because they&#8217;re required but because they want confidence in their code. They review their own work skeptically before calling it done. They appreciate bug reports as valuable information rather than personal criticism.</p><p>These developers haven&#8217;t abandoned the development mindset. They&#8217;ve expanded it. They can shift into analytical thinking when needed, then shift back to constructive thinking.</p><p>What does this look like in practice?</p><p><strong>Before coding:</strong> They think about what could go wrong, what inputs might cause problems, what states might be invalid. They build defenses against problems they anticipate.</p><p><strong>During coding:</strong> They test their own work continuously. Not formal testing&#8202;&#8212;&#8202;just constant verification that what they&#8217;re building actually works.</p><p><strong>After coding:</strong> They review their implementation critically. They try to break it. They imagine how a tester would approach it and preemptively address obvious issues.</p><p><strong>When bugs are found:</strong> They&#8217;re curious rather than defensive. &#8220;Interesting&#8202;&#8212;&#8202;I didn&#8217;t think about that scenario. Let me understand what happened.&#8221;</p><p>This isn&#8217;t about becoming a tester. It&#8217;s about incorporating testing thinking into development practice. The code that results is more robust, and the relationships with testers are more collaborative.</p><div><hr></div><h3>The Tester Who Understands Development</h3><p>The best testers I&#8217;ve worked with have developed genuine development appreciation.</p><p>They understand why certain bugs happen. They know that some edge cases are genuinely hard to anticipate. They write bug reports that help developers fix issues rather than just documenting problems. They recognize the difference between carelessness and reasonable tradeoffs.</p><p>These testers haven&#8217;t abandoned the testing mindset. They&#8217;ve contextualized it. They can appreciate construction while still maintaining analytical rigor.</p><p>What does this look like in practice?</p><p><strong>When exploring features:</strong> They think about how the feature was probably built. They target testing toward areas where bugs are likely based on implementation patterns.</p><p><strong>When finding bugs:</strong> They investigate enough to provide useful information. Not just &#8220;it doesn&#8217;t work&#8221; but &#8220;here&#8217;s exactly what I did, here&#8217;s what I expected, here&#8217;s what happened, and here&#8217;s some initial investigation into what might be causing it.&#8221;</p><p><strong>When reporting bugs:</strong> They frame issues in terms of user impact and business risk, not just technical problems. They prioritize ruthlessly rather than treating every issue as critical.</p><p><strong>When discussing fixes:</strong> They engage constructively. They understand why some fixes are harder than they appear. They help developers understand the problem rather than just demanding solutions.</p><p>This isn&#8217;t about becoming a developer. It&#8217;s about incorporating development appreciation into testing practice. The bugs found are more valuable, and the relationships with developers are more collaborative.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qhhU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qhhU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qhhU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qhhU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qhhU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qhhU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qhhU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qhhU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qhhU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qhhU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8709c72c-794b-436e-9360-3694aa4720e7_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Practical Bridges Between Mindsets</h3><p>Understanding is good. Practical bridges are better. Here are specific practices that help mindsets collaborate effectively.</p><h3>Three Amigos Sessions</h3><p>Before development begins, three perspectives meet: product (what we need), development (how we&#8217;ll build it), and testing (how we&#8217;ll verify it). Each mindset contributes to shared understanding.</p><p>Testers ask questions that surface ambiguities and edge cases. Developers explain implementation approaches that inform testing strategy. Product clarifies intent behind requirements.</p><p>This isn&#8217;t a meeting where testers find problems with developer plans. It&#8217;s a conversation where different perspectives combine to create better plans.</p><h3>Pairing and Mobbing</h3><p>When testers and developers work together in real-time, mindset differences become learning opportunities rather than conflicts.</p><p>A developer watching a tester explore their feature sees how testers think. A tester watching a developer debug an issue sees how developers think. Both perspectives expand.</p><p>Pairing on bug investigation is particularly valuable. The developer brings implementation knowledge. The tester brings investigation skills. Together they find root causes faster than either would alone.</p><h3>Bug Report Conversations</h3><p>Written bug reports lose nuance. Before a bug becomes a ticket, have a conversation.</p><p>&#8220;I found something weird. Let me show you.&#8221;</p><p>This simple practice transforms bug reporting from accusation to collaboration. The tester demonstrates the issue. The developer asks questions. Together they determine what happened, why it matters, and what to do about it.</p><p>Many &#8220;bugs&#8221; get resolved in these conversations&#8202;&#8212;&#8202;sometimes they&#8217;re not bugs, sometimes they&#8217;re quick fixes, sometimes they&#8217;re known issues. The conversation prevents unnecessary documentation and builds relationships.</p><h3>Blameless Retrospectives</h3><p>When bugs escape to production, the natural instinct is blame. Developers blame testers for missing it. Testers blame developers for creating it.</p><p>Blameless retrospectives redirect that energy. &#8220;How did this bug get through our process?&#8221; is a system question, not a people question.</p><p>These conversations surface process improvements that help both mindsets work better together. Maybe testers need earlier access to features. Maybe developers need better test environments. Maybe requirements need more clarity before implementation begins.</p><div><hr></div><h3>When Mindsets Should Flex</h3><p>While each role has a default mindset, there are situations where flexing toward the other mindset improves outcomes.</p><p><strong>Developers should flex toward testing mindset when:</strong></p><p>Writing unit tests. Pure construction mindset writes tests that verify the code does what the code does. Testing mindset writes tests that verify the code does what users need.</p><p>Reviewing their own code. Construction mindset is proud of what was built. Testing mindset asks what could break.</p><p>Discussing bug reports. Construction mindset gets defensive. Testing mindset gets curious.</p><p>Planning implementation. Construction mindset asks how to build it. Testing mindset asks what could go wrong during building.</p><p><strong>Testers should flex toward development mindset when:</strong></p><p>Writing bug reports. Pure testing mindset documents problems. Development mindset helps solve them.</p><p>Prioritizing issues. Testing mindset wants everything fixed. Development mindset understands tradeoffs and constraints.</p><p>Discussing implementation approaches. Testing mindset focuses on what could break. Development mindset appreciates what&#8217;s being built.</p><p>Automating tests. Testing mindset focuses on what to test. Development mindset figures out how to build reliable automation.</p><p>The ability to flex is what separates good practitioners from great ones. It doesn&#8217;t mean abandoning your default&#8202;&#8212;&#8202;it means expanding your range.</p><div><hr></div><h3>The Organizational Dimension</h3><p>Mindset differences don&#8217;t just exist between individuals. They exist between teams and departments.</p><p>Development organizations optimize for construction: features shipped, velocity maintained, deadlines met. Testing organizations optimize for evaluation: bugs found, risks identified, confidence established.</p><p>When these organizations operate in silos, their optimizations conflict. Development pushes for faster releases. Testing pushes for more thorough evaluation. Each sees the other as impediment rather than partner.</p><p>Modern organizations address this by breaking silos. Testers embedded in development teams rather than separate departments. Shared quality goals rather than competing metrics. Combined ownership of outcomes rather than handoffs and blame.</p><p>The organizational structure either amplifies mindset conflicts or creates conditions for mindset collaboration. If you&#8217;re in a siloed organization, advocating for structural change might be more important than improving individual relationships.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1xZ8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1xZ8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1xZ8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1xZ8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1xZ8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1xZ8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1xZ8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1xZ8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1xZ8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1xZ8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb7071b9-a16e-4e87-9b34-3b4b8ce87015_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Building Your Cross-Mindset Fluency</h3><p>Whether you&#8217;re a developer or tester, building fluency in the other mindset makes you more effective.</p><p><strong>If you&#8217;re a developer:</strong></p><p>Spend time with testers. Watch how they explore software. Ask why they investigate certain areas. Their approach will reveal blind spots in your thinking.</p><p>Read your own bug reports. Look for patterns. What types of issues do testers repeatedly find in your code? Those patterns reveal where your construction mindset has blind spots.</p><p>Write tests before code occasionally. Test-driven development forces you into evaluation mode before construction mode. Even if you don&#8217;t practice it religiously, the experience expands your thinking.</p><p>Attempt exploratory testing on your own features. Before declaring something done, spend ten minutes trying to break it. You&#8217;ll catch some issues and develop appreciation for what testers do.</p><p><strong>If you&#8217;re a tester:</strong></p><p>Spend time with developers. Watch how they build features. Ask why they make certain implementation decisions. Their approach will reveal constraints you might not appreciate.</p><p>Learn to read code. You don&#8217;t need to write production code, but understanding how software is built helps you test it more effectively and report bugs more usefully.</p><p>Build something small. A simple automation script, a basic application, anything that requires construction. The experience develops appreciation for how hard building is.</p><p>Pair on bug fixes. When a developer fixes your bug, watch how they do it. Understanding the fix deepens your understanding of the problem and helps you find similar issues elsewhere.</p><div><hr></div><h3>The Quality Mindset: Integration of Both</h3><p>Ultimately, both mindsets serve the same goal: quality software that meets user needs.</p><p>The development mindset contributes by building software that works.</p><p>The testing mindset contributes by verifying software works and finding where it doesn&#8217;t.</p><p>Neither alone is sufficient. Construction without evaluation produces software that might work. Evaluation without construction produces nothing at all.</p><p>The mature practitioner&#8202;&#8212;&#8202;whether developer or tester&#8202;&#8212;&#8202;develops what might be called a quality mindset: the integration of both perspectives in service of shared outcomes.</p><p>This quality mindset asks both &#8220;how do we make this work?&#8221; and &#8220;how might this fail?&#8221;</p><p>It takes pride in construction while maintaining skepticism about whether construction succeeded.</p><p>It finds problems while appreciating the difficulty of solving them.</p><p>It moves forward while pausing to verify direction.</p><p>This integration is what great teams achieve together. Developers who think about testing. Testers who appreciate development. Shared commitment to building software that truly works.</p><div><hr></div><h3>Your Reflection Exercise</h3><p>Take a moment to examine your own mindset patterns.</p><p><strong>If you&#8217;re a developer:</strong></p><ul><li><p>When did you last find a bug in your own code before anyone else saw it?</p></li><li><p>How do you react when testers find issues in your work?</p></li><li><p>What testing activities, if any, do you perform before calling code complete?</p></li><li><p>Do you see testers as partners or obstacles?</p></li></ul><p><strong>If you&#8217;re a tester:</strong></p><ul><li><p>When did you last help a developer understand why a bug might be occurring?</p></li><li><p>How do you react when developers push back on your bug reports?</p></li><li><p>What do you understand about how the systems you test are built?</p></li><li><p>Do you see developers as partners or as people who create problems for you to find?</p></li></ul><p><strong>For everyone:</strong></p><ul><li><p>Which mindset is your default? Can you flex toward the other when needed?</p></li><li><p>What&#8217;s one practice you could adopt to build fluency in the other mindset?</p></li><li><p>How would your working relationships change if you better understood the other perspective?</p></li></ul><div><hr></div><h3>Complementary, Not Competing</h3><p>The testing mindset and development mindset aren&#8217;t in competition. They&#8217;re dance partners&#8202;&#8212;&#8202;different moves that combine into something neither could achieve alone.</p><p>Software that only gets built without rigorous evaluation is software waiting to fail in production.</p><p>Software that only gets evaluated without being built is software that doesn&#8217;t exist.</p><p>Quality emerges from the collaboration between these perspectives. Not from one mindset winning over the other, but from both contributing their strengths while respecting the other&#8217;s value.</p><p>The developer who appreciates testing becomes a better developer.</p><p>The tester who appreciates development becomes a better tester.</p><p>The team that integrates both mindsets builds better software than any individual could.</p><p>In our next article, we&#8217;ll explore <strong>Building Your Testing Career Path</strong>&#8202;&#8212;&#8202;mapping the journey from junior tester to test architect and beyond. We&#8217;ll examine the different trajectories available, the skills each level demands, and how to move intentionally through your career rather than hoping the next opportunity finds you.</p><p><strong>Remember:</strong> Different mindsets aren&#8217;t obstacles to overcome. They&#8217;re perspectives to integrate.</p>]]></content:encoded></item><item><title><![CDATA[What Makes a Good Tester?]]></title><description><![CDATA[Essential skills and mindset traits]]></description><link>https://ryancraventech.substack.com/p/what-makes-a-good-tester</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/what-makes-a-good-tester</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Wed, 04 Feb 2026 13:34:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JUXx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><p>I once worked with a tester who had every certification imaginable. ISTQB Foundation. ISTQB Advanced. Certified Agile Tester. A wall full of credentials that said she knew testing inside and out.</p><blockquote><p>She was mediocre at best.</p></blockquote><p>I also worked with a former barista who stumbled into QA because the company needed bodies. No certifications. No formal training. Just a knack for noticing when things felt off.</p><blockquote><p>She was exceptional.</p></blockquote><p>This isn&#8217;t an argument against education or credentials. It&#8217;s an observation about what actually makes someone good at testing. The skills and mindsets that separate great testers from adequate ones aren&#8217;t always the things you&#8217;d put on a resume.</p><p>Today we&#8217;re exploring what truly makes a good tester&#8202;&#8212;&#8202;the essential skills you can develop and the mindset traits that might already be part of who you are. Some of this can be learned. Some of it is about recognizing and nurturing tendencies you already have.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JUXx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JUXx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JUXx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JUXx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JUXx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JUXx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JUXx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JUXx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JUXx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JUXx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc07d6b-1f4e-4fa2-a7ad-f78d78310285_900x502.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>The Uncomfortable Truth About Testing Talent</h3><p>Here&#8217;s something that might be controversial: not everyone is cut out for testing.</p><p>That&#8217;s not elitism. It&#8217;s honesty. Just like not everyone is cut out to be a surgeon, a trial lawyer, or a stand-up comedian. Different roles require different combinations of skills and temperament.</p><p>Some developers make terrible testers&#8202;&#8212;&#8202;not because they lack intelligence but because they can&#8217;t shift from &#8220;making it work&#8221; mode to &#8220;trying to break it&#8221; mode. Some detail-oriented people struggle because testing also requires big-picture thinking. Some creative people flounder because testing requires discipline and systematic approaches alongside creativity.</p><p>Good testing requires a specific combination of attributes that don&#8217;t always travel together. Analytical thinking and creativity. Patience and urgency. Skepticism and collaboration. Attention to detail and ability to see the forest, not just the trees.</p><p>The good news: most of these attributes can be developed. Understanding what makes a good tester helps you identify which skills to strengthen and which natural tendencies to lean into.</p><div><hr></div><h3>The Core Skills</h3><p>Let&#8217;s start with the learnable stuff&#8202;&#8212;&#8202;skills you can develop through practice and study.</p><h3>Technical Literacy</h3><p>You don&#8217;t need to be a developer. But you need to understand enough about how software works to test it effectively.</p><p>This means understanding concepts like databases, APIs, client-server architecture, and basic programming logic. Not mastery&#8202;&#8212;&#8202;literacy. You need to read and understand, not write and architect.</p><p>When a developer says &#8220;the bug might be in the caching layer,&#8221; you need to understand what that means. When you&#8217;re testing an API, you need to understand what a request and response are. When something fails, you need to have enough technical intuition to provide useful information about what might have gone wrong.</p><p>Technical literacy also helps you communicate. Developers respect testers who can speak their language. Bug reports that say &#8220;the thing doesn&#8217;t work&#8221; get deprioritized. Bug reports that say &#8220;the POST request to /api/users returns a 500 error when the email field contains unicode characters&#8221; get fixed.</p><p><strong>How to develop it:</strong> Build something simple. A basic web application, a small automation script, anything that forces you to understand how code becomes software. Read documentation for systems you test. Ask developers to explain architecture decisions. Take online courses in programming fundamentals&#8202;&#8212;&#8202;not to become a programmer but to understand how programmers think.</p><h3>Domain Knowledge</h3><p>The best testers understand not just the software but the world that software operates in.</p><p>Testing a healthcare application? You need to understand patient workflows, regulatory requirements, and what happens when medical software fails. Testing financial software? You need to understand transactions, compliance, and the consequences of calculation errors. Testing an e-commerce platform? You need to understand customer journeys, payment processing, and inventory management.</p><p>Domain knowledge helps you test what matters. Without it, you might thoroughly test a feature that&#8217;s technically correct but completely wrong for how users actually work. With it, you immediately recognize when something doesn&#8217;t make sense for the business context.</p><p><strong>How to develop it:</strong> Become a student of your domain. Read industry publications. Talk to users. Understand the business problems the software solves. Ask &#8220;why&#8221; constantly&#8202;&#8212;&#8202;why does this feature exist? Why do users need it? Why does the workflow go this way?</p><h3>Communication Skills</h3><p>Testing creates information. Communication turns that information into action.</p><p>You need to write bug reports that are clear, complete, and actionable. You need to explain test results to stakeholders who don&#8217;t understand testing. You need to advocate for quality without being dismissed as negative or obstructionist. You need to have difficult conversations when you find serious problems.</p><p>Good testers are often the bearers of bad news. The skill is delivering that news in ways that lead to fixes rather than defensiveness.</p><p><strong>How to develop it:</strong> Practice writing bug reports that someone else could reproduce without asking follow-up questions. Learn to present test results in terms of business impact, not just technical details. Study how to give constructive feedback. Pay attention to which of your communications lead to action and which get ignored&#8202;&#8212;&#8202;figure out what makes the difference.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cRUO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cRUO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cRUO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cRUO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cRUO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cRUO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cRUO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cRUO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cRUO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cRUO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb352bf-dfc9-45a9-a274-40f7eabc9552_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Analytical Thinking</h3><p>Testing generates enormous amounts of information. Analytical thinking is how you turn that information into insight.</p><p>This means identifying patterns across multiple test results. It means recognizing when a specific bug is actually a symptom of a broader problem. It means understanding risk and prioritizing testing effort toward what matters most. It means not just finding problems but understanding why they exist.</p><p>Analytical testers don&#8217;t just report &#8220;button doesn&#8217;t work.&#8221; They investigate, find that the button fails on forms with more than five fields, recognize the pattern, and identify that the underlying issue is a JavaScript timeout that affects multiple features.</p><p><strong>How to develop it:</strong> When you find a bug, don&#8217;t stop there. Ask why it exists. Look for related bugs. Try to understand the root cause, not just the symptom. Practice categorizing and grouping test results to identify patterns. Learn basic statistical thinking to recognize when results are significant versus random noise.</p><h3>Test Design</h3><p>Testing without strategy is just clicking around hoping to stumble on bugs. Test design is the skill of systematically identifying what to test and how.</p><p>This includes understanding techniques like equivalence partitioning, boundary value analysis, decision tables, and state transition testing. These aren&#8217;t just academic concepts&#8202;&#8212;&#8202;they&#8217;re practical tools for ensuring you test thoroughly without testing everything (which is impossible).</p><p>Good test design also means knowing when to apply which techniques. Exhaustive combinatorial testing makes sense for a payment calculator with a few inputs. It&#8217;s pointless for a free-form text field with infinite possibilities. The skill is matching technique to situation.</p><p><strong>How to develop it:</strong> Study formal test design techniques. Then apply them consciously until they become intuitive. For every feature you test, explicitly identify your test design approach before you start. Review your test designs afterward&#8202;&#8212;&#8202;did you miss important scenarios? Would a different approach have been more effective?</p><h3>Tool Proficiency</h3><p>Modern testing involves tools. Test management systems. Bug tracking software. Automation frameworks. API testing tools. Performance testing tools. Monitoring dashboards.</p><p>You don&#8217;t need to master every tool, but you need enough proficiency with the tools your team uses that they help rather than hinder your work. You also need enough awareness of what tools exist that you can recommend appropriate ones when needs arise.</p><p>Tool proficiency isn&#8217;t about the tools themselves&#8202;&#8212;&#8202;it&#8217;s about leverage. The right tool used well multiplies your effectiveness. The wrong tool or poor tool usage wastes time.</p><p><strong>How to develop it:</strong> Get competent with the tools your organization uses. Explore tools for gaps in your current toolkit. Learn at least one automation framework well enough to create basic automated tests. Stay aware of new tools and approaches without chasing every shiny new thing.</p><div><hr></div><h3>The Mindset Traits</h3><p>Skills can be learned, but mindset is different. These are ways of thinking and approaching the world that make testing feel natural. Some people have these traits instinctively. Others develop them through deliberate practice. Either way, they&#8217;re essential.</p><h3>Curiosity</h3><p>Good testers want to know how things work. Not because they need to&#8202;&#8212;&#8202;because they can&#8217;t help it.</p><p>Curiosity drives exploration. A curious tester doesn&#8217;t stop at &#8220;this feature does X.&#8221; They want to know what happens if they do Y instead. What&#8217;s behind that error message? Why does the system behave differently on Tuesday than Monday? What happens if you do something the designers never anticipated?</p><p>Curiosity also drives learning. Curious testers constantly absorb new knowledge about systems, domains, tools, and techniques. They ask questions others don&#8217;t think to ask.</p><p>The opposite of curiosity is assumption. Testers who assume they know how something works miss the bugs that live in the gaps between assumption and reality.</p><p><strong>Cultivating curiosity:</strong> Practice asking &#8220;why?&#8221; and &#8220;what if?&#8221; relentlessly. When something works, ask why it works. When something fails, ask what else might fail in similar ways. Treat every system as a puzzle to be understood, not just a checklist to be verified.</p><h3>Skepticism</h3><p>Good testers don&#8217;t believe the documentation. They don&#8217;t believe the developers. They don&#8217;t believe the users. They don&#8217;t believe themselves.</p><p>This isn&#8217;t cynicism or distrust. It&#8217;s the recognition that what people say and what&#8217;s actually true are often different things. The spec says the feature does X. Does it? The developer says the bug is fixed. Is it? The user says they need Y. Do they really?</p><p>Skeptical testers verify. They question assumptions. They look for evidence. They treat every claim as a hypothesis to be tested rather than a fact to be accepted.</p><p>This skepticism extends to their own work. Good testers question whether their tests are actually testing what they think they&#8217;re testing. They wonder whether they missed something. They don&#8217;t assume they found all the bugs just because they didn&#8217;t find more bugs.</p><p><strong>Cultivating skepticism:</strong> Practice doubting. When someone tells you something, mentally append &#8220;&#8230;but is that actually true?&#8221; Look for evidence that contradicts claims, not just evidence that supports them. Review your own work with the assumption that you made mistakes somewhere.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h5UI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h5UI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!h5UI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!h5UI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!h5UI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h5UI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h5UI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!h5UI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!h5UI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!h5UI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f928b-5024-4d29-9372-09ac017785bc_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Attention to Detail</h3><p>Bugs hide in details. Off-by-one errors. Missing null checks. Subtle inconsistencies between screens. The wrong date format. A misspelled word that breaks functionality.</p><p>Good testers notice things that others miss. They spot the one pixel that&#8217;s wrong, the response that took 200 milliseconds longer than expected, the edge case that almost nobody would encounter.</p><p>But attention to detail isn&#8217;t just about noticing small things. It&#8217;s about recognizing which small things matter. A typo in a marketing headline might be embarrassing. A typo in a medication dosage might be deadly. Good testers apply their attention proportionally to importance.</p><p><strong>Cultivating attention to detail:</strong> Slow down. Rushing is the enemy of noticing. Practice observation exercises&#8202;&#8212;&#8202;describe a familiar object in detail, then look at it and see what you missed. Review your work after you think you&#8217;re finished. Create checklists for things you tend to overlook.</p><h3>Empathy</h3><p>Software is used by humans. Good testers think like those humans.</p><p>Empathy means understanding how users actually think and work, not how designers assumed they would think and work. It means recognizing that users make mistakes, get confused, have bad days, and use software in contexts designers never imagined.</p><p>An empathetic tester thinks: &#8220;What if someone is using this on their phone while walking? What if they&#8217;re elderly and don&#8217;t see small text well? What if they&#8217;re stressed and not reading carefully? What if they&#8217;ve never seen software like this before?&#8221;</p><p>Empathy also applies to colleagues. Understanding why developers make certain decisions helps you communicate more effectively. Understanding why stakeholders have certain priorities helps you frame test results in terms they care about.</p><p><strong>Cultivating empathy:</strong> Talk to actual users. Watch them use the software. Ask about their context, their frustrations, their goals. Put yourself in the mindset of different user types when testing. Consider accessibility not as a checklist but as a way of ensuring everyone can use the software.</p><h3>Persistence</h3><p>Some bugs don&#8217;t want to be found. They hide behind specific sequences of actions, particular data combinations, or intermittent conditions. Finding them requires persistence&#8202;&#8212;&#8202;the willingness to keep investigating when you sense something is wrong even though you can&#8217;t prove it yet.</p><p>Persistence also matters when facing resistance. When developers insist a bug isn&#8217;t real. When stakeholders pressure you to approve a release you have concerns about. When you&#8217;ve run the same test a hundred times and it keeps passing but something still feels off.</p><p>The opposite of persistence is giving up too easily. Accepting &#8220;works on my machine&#8221; as an answer. Closing a bug because you couldn&#8217;t reproduce it once. Approving a release because you&#8217;re tired of fighting.</p><p><strong>Cultivating persistence:</strong> Set a rule: when you suspect something is wrong, investigate until you either find it or can articulate exactly why you&#8217;re confident it&#8217;s not there. Practice distinguishing between persistence (continuing to investigate something worthwhile) and stubbornness (refusing to accept you&#8217;re wrong). Build stamina for frustrating problems.</p><h3>Comfort with Ambiguity</h3><p>Real testing rarely involves clear specifications, complete requirements, and unambiguous expectations. Good testers function effectively even when they don&#8217;t have all the information they want.</p><p>This means making reasonable assumptions and documenting them. It means testing based on user needs when specifications are unclear. It means providing qualified assessments rather than refusing to test until everything is perfect.</p><p>Comfort with ambiguity doesn&#8217;t mean accepting chaos. Good testers push for clarity where it matters while adapting to uncertainty where it&#8217;s unavoidable. They know when ambiguity is acceptable and when it must be resolved before testing can be meaningful.</p><p><strong>Cultivating comfort with ambiguity:</strong> Practice identifying what you actually need to know versus what would be nice to know. Make decisions with incomplete information and observe the results. Distinguish between ambiguity that should be resolved (and advocate for resolving it) versus ambiguity you can work around.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DPtm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DPtm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DPtm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DPtm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DPtm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DPtm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DPtm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DPtm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DPtm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DPtm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78489ba5-e193-4593-8b98-933fcf528099_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>The Meta-Skill: Switching Perspectives</h3><p>If there&#8217;s one skill that underpins all the others, it&#8217;s the ability to switch perspectives. Good testers constantly shift how they&#8217;re looking at the software.</p><p><strong>User perspective:</strong> How will real people actually use this? What mistakes will they make? What will confuse them?</p><p><strong>Developer perspective:</strong> How is this likely implemented? Where might bugs hide given the technical approach?</p><p><strong>Business perspective:</strong> What are the stakes if this fails? What&#8217;s the actual risk to the organization?</p><p><strong>Attacker perspective:</strong> How could someone abuse this feature? Where are the security vulnerabilities?</p><p><strong>Support perspective:</strong> What questions will customers ask? What edge cases will generate tickets?</p><p><strong>Operations perspective:</strong> How will this perform at scale? What happens when it fails?</p><p>Switching perspectives isn&#8217;t about becoming an expert in all these areas. It&#8217;s about briefly adopting different viewpoints to see things you&#8217;d miss from your default perspective.</p><p>A tester who only sees software from one angle misses bugs that are obvious from another angle. The ability to rapidly switch perspectives is what enables comprehensive testing without requiring comprehensive expertise.</p><div><hr></div><h3>What Good Testers Don&#8217;t Need</h3><p>Let&#8217;s dispel some myths about what testing requires.</p><p><strong>You don&#8217;t need to be a developer.</strong> Technical literacy helps, but you don&#8217;t need to write production code. Some of the best testers have minimal programming skills.</p><p><strong>You don&#8217;t need to be pessimistic.</strong> Skepticism and pessimism are different. Skeptical testers question assumptions. Pessimistic testers assume everything will fail. The former is useful; the latter is exhausting.</p><p><strong>You don&#8217;t need to be confrontational.</strong> Advocating for quality doesn&#8217;t mean being aggressive. The best testers build relationships that make quality everyone&#8217;s goal, not battles that position quality versus everything else.</p><p><strong>You don&#8217;t need certifications.</strong> They don&#8217;t hurt, but they&#8217;re not necessary for being good at testing. What matters is what you can do, not what a certificate says you can do.</p><p><strong>You don&#8217;t need to find every bug.</strong> Perfectionism is the enemy of effective testing. Good testers find the bugs that matter, not every bug that exists. Accepting that some bugs will escape is part of professional maturity.</p><p><strong>You don&#8217;t need to be right all the time.</strong> You&#8217;ll raise concerns about bugs that turn out not to matter. You&#8217;ll miss bugs that turn out to be critical. You&#8217;ll make wrong predictions about risk. That&#8217;s normal. What matters is learning from these experiences and improving your judgment over time.</p><div><hr></div><h3>The Traits in Combination</h3><p>Individual traits matter, but it&#8217;s the combination that creates exceptional testers.</p><p>Curiosity without skepticism leads to accepting interesting explanations without verifying them.</p><p>Skepticism without empathy leads to dismissing user concerns because &#8220;they&#8217;re doing it wrong.&#8221;</p><p>Attention to detail without analytical thinking leads to lists of observations without insight about what they mean.</p><p>Persistence without comfort with ambiguity leads to paralysis when facing unclear situations.</p><p>Communication skills without domain knowledge leads to clear reports about the wrong things.</p><p>The goal isn&#8217;t maximizing each trait independently&#8202;&#8212;&#8202;it&#8217;s developing a balanced combination that works together. Your specific balance might look different than another great tester&#8217;s balance. Some exceptional testers are highly technical; others are highly empathetic. Some are deeply curious; others are relentlessly persistent. There are many ways to be good at testing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-CmW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-CmW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-CmW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-CmW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-CmW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-CmW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-CmW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-CmW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-CmW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-CmW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce5ea773-0906-42f7-8007-a69205c798ef_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Growing Into a Better Tester</h3><p>If you&#8217;ve assessed yourself against these skills and traits and found gaps, good. That awareness is where growth starts.</p><p><strong>For skill gaps:</strong> Create a deliberate learning plan. Technical literacy can be improved through courses and practice. Domain knowledge builds through study and conversation. Communication skills develop through practice and feedback. Test design improves by studying techniques and applying them consciously.</p><p><strong>For mindset gaps:</strong> These are harder because they require changing how you think, not just what you know. But it&#8217;s possible. Curiosity can be cultivated by deliberately asking questions. Skepticism can be developed by practicing verification. Attention to detail improves with slowing down and checklists. Empathy grows through exposure to users. Persistence strengthens through practice with hard problems.</p><p><strong>For both:</strong> Find mentors and examples. Watch how good testers work. Ask them to explain their thinking. Study their bug reports. Notice how they approach problems differently than you do.</p><p>And give yourself time. These skills and traits develop over years, not weeks. The journey from adequate to good to great takes deliberate effort sustained over a long period.</p><div><hr></div><h3>Recognizing Good Testers</h3><p>If you&#8217;re building a testing team or evaluating testing candidates, how do you recognize these traits?</p><p><strong>Ask about discoveries.</strong> &#8220;Tell me about a bug you found that was particularly interesting or difficult.&#8221; Good testers light up when discussing discoveries. They explain not just what they found but how they found it, what made it challenging, and what they learned.</p><p><strong>Watch them test.</strong> Give candidates a system and time to explore it. Observe their approach. Do they jump randomly or explore systematically? Do they ask questions? Do they notice things? Do they investigate or just move on?</p><p><strong>Discuss ambiguous situations.</strong> Present scenarios with incomplete information. See how they handle uncertainty. Do they freeze? Make reasonable assumptions? Ask clarifying questions?</p><p><strong>Review their communication.</strong> Look at bug reports they&#8217;ve written. Are they clear? Complete? Actionable? Do they communicate impact effectively?</p><p><strong>Ask about failures.</strong> &#8220;Tell me about a bug you missed that caused problems.&#8221; Good testers have these stories and have learned from them. Testers who claim to never miss anything important are either lying or haven&#8217;t been tested enough to know better.</p><div><hr></div><h3>Your Self-Assessment</h3><p>Time to turn this inward. Honestly evaluate yourself against the skills and mindsets we&#8217;ve discussed.</p><p><strong>Rate yourself on each skill (1&#8211;5):</strong></p><ul><li><p>Technical literacy</p></li><li><p>Domain knowledge</p></li><li><p>Communication skills</p></li><li><p>Analytical thinking</p></li><li><p>Test design</p></li><li><p>Tool proficiency</p></li></ul><p><strong>Rate yourself on each mindset trait (1&#8211;5):</strong></p><ul><li><p>Curiosity</p></li><li><p>Skepticism</p></li><li><p>Attention to detail</p></li><li><p>Empathy</p></li><li><p>Persistence</p></li><li><p>Comfort with ambiguity</p></li></ul><p>Now identify your biggest gap&#8202;&#8212;&#8202;the area where improvement would make the most difference in your effectiveness.</p><p>Create one specific action you&#8217;ll take this week to address that gap. Not a vague intention. A specific action with a deadline.</p><p>Then do it.</p><div><hr></div><h3>The Good Tester&#8217;s Identity</h3><p>Being a good tester isn&#8217;t about job titles or certifications or years of experience. It&#8217;s about how you approach the work.</p><p>Good testers are relentlessly curious about how things work and why they fail.</p><p>Good testers verify rather than assume, question rather than accept.</p><p>Good testers notice what others miss and investigate when others move on.</p><p>Good testers think about users as real people, not abstract personas.</p><p>Good testers communicate clearly enough that their discoveries lead to action.</p><p>Good testers keep going when problems are hard and answers are elusive.</p><p>Good testers function effectively even when information is incomplete and expectations are unclear.</p><p>This combination is rare enough to be valuable and common enough to be achievable. Testing needs more people who develop these skills and nurture these mindsets.</p><p>In our next article, we&#8217;ll explore <strong>Building a Testing Mindset</strong>&#8202;&#8212;&#8202;practical exercises and habits for developing the questioning, skeptical, exploratory thinking that good testing requires. We&#8217;ll take the mindset traits we discussed today and turn them into daily practices.</p><blockquote><p><strong>Remember:</strong> What makes a good tester isn&#8217;t credentials or certifications. It&#8217;s the combination of skills you develop and the mindset you bring to every testing situation.</p></blockquote>]]></content:encoded></item><item><title><![CDATA[Static vs Dynamic Testing]]></title><description><![CDATA[Two Sides of the Quality Coin]]></description><link>https://ryancraventech.substack.com/p/static-vs-dynamic-testing</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/static-vs-dynamic-testing</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Mon, 02 Feb 2026 13:16:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yRtS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><p>Welcome back to <strong>NextGen QA</strong>! In our last article, we explored verification versus validation&#8202;&#8212;&#8202;the difference between building it right and building the right thing. Today, we&#8217;re diving into another fundamental distinction that every tester must understand: <strong>static versus dynamic testing</strong>.</p><p>Here&#8217;s a question that might surprise you: What if I told you that some of the most catastrophic software failures in history&#8202;&#8212;&#8202;failures that cost billions of dollars and even human lives&#8202;&#8212;&#8202;could have been prevented without ever running the software?</p><p>That&#8217;s the power of understanding when to test code by examining it versus when to test it by executing it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yRtS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yRtS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yRtS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yRtS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yRtS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yRtS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yRtS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yRtS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yRtS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yRtS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25c1e2ba-4917-47c2-bf5a-f0abc679be1a_800x447.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>The Core Distinction: Looking vs. Running</h3><p><strong>Static testing</strong> examines software artifacts without executing the code. Think of it like a building inspector reviewing blueprints before construction begins&#8202;&#8212;&#8202;they&#8217;re looking for structural issues, code violations, and design flaws on paper.</p><p><strong>Dynamic testing</strong> evaluates software by running it and observing its behavior. This is like stress-testing that building after it&#8217;s constructed&#8202;&#8212;&#8202;checking if the doors open properly, if the electrical system works, if it can withstand an earthquake.</p><p>Both approaches are essential. Neither alone is sufficient.</p><h3>What Static Testing Catches</h3><p>Static testing shines at finding issues that exist in the code&#8217;s structure and logic&#8202;&#8212;&#8202;problems that are there whether or not the code runs:</p><ul><li><p><strong>Syntax errors and typos</strong>&#8202;&#8212;&#8202;The obvious stuff that would crash your program</p></li><li><p><strong>Code standard violations</strong>&#8202;&#8212;&#8202;Deviations from agreed-upon coding practices</p></li><li><p><strong>Security vulnerabilities</strong>&#8202;&#8212;&#8202;Buffer overflows, SQL injection risks, hardcoded credentials</p></li><li><p><strong>Logic errors</strong>&#8202;&#8212;&#8202;Algorithms that won&#8217;t produce correct results</p></li><li><p><strong>Design flaws</strong>&#8202;&#8212;&#8202;Architectural problems that will cause issues at scale</p></li><li><p><strong>Requirements gaps</strong>&#8202;&#8212;&#8202;Missing functionality or contradictory specifications</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SSP3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SSP3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SSP3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SSP3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SSP3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SSP3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SSP3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SSP3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SSP3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SSP3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f0e76fd-f679-4675-91b6-d608f6ec00df_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>What Dynamic Testing Catches</h3><p>Dynamic testing reveals issues that only manifest when code executes&#8202;&#8212;&#8202;problems that emerge from the interaction between components, systems, and real-world conditions:</p><ul><li><p><strong>Functional defects</strong>&#8202;&#8212;&#8202;Features that don&#8217;t work as expected</p></li><li><p><strong>Integration problems</strong>&#8202;&#8212;&#8202;Components that fail when connected</p></li><li><p><strong>Performance issues</strong>&#8202;&#8212;&#8202;Slowness, memory leaks, resource exhaustion</p></li><li><p><strong>Race conditions</strong>&#8202;&#8212;&#8202;Timing-dependent bugs that only appear under specific circumstances</p></li><li><p><strong>Environment-specific bugs</strong>&#8202;&#8212;&#8202;Issues that only occur in production-like settings</p></li><li><p><strong>User experience problems</strong>&#8202;&#8212;&#8202;Confusing interfaces, poor workflows</p></li></ul><h3>When Static Testing Could Have Saved Lives: The Toyota Case</h3><p>Between 2009 and 2011, Toyota faced a crisis that would cost them over $1.2 billion in settlements and trigger recalls affecting more than 10 million vehicles. The culprit? Their Electronic Throttle Control System software.</p><p>When NASA engineers investigated the code, what they found was staggering: <strong>over 7,000 violations</strong> of MISRA-C coding standards when checking just 35 rules. An independent expert witness found <strong>over 81,000 violations</strong> when checking against the full MISRA 2004 standard.</p><p>These weren&#8217;t obscure, theoretical issues. MISRA-C guidelines exist specifically to prevent the kinds of bugs that cause unintended acceleration, system lockups, and safety failures. Static analysis tools could have flagged every single one of these violations&#8202;&#8212;&#8202;before any vehicle ever left the factory.</p><p>NASA also found that Toyota had never performed worst-case execution timing (WCET) analysis&#8202;&#8212;&#8202;a static technique that verifies software will always complete its tasks within required time limits. In safety-critical systems like vehicle controls, this oversight is nearly unforgivable.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-aSf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-aSf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-aSf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-aSf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-aSf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-aSf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-aSf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-aSf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-aSf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-aSf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb79a78ff-bd66-4b52-9ea9-02d9998e1ae4_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>When Dynamic Testing Saves the Day: The Knight Capital Catastrophe</h3><p>On August 1, 2012, Knight Capital deployed a trading algorithm that would lose the company <strong>$440 million in just 45 minutes</strong>&#8202;&#8212;&#8202;effectively destroying the firm.</p><p>The root cause? They ran end-to-end tests on seven servers but <strong>missed the eighth</strong>. That eighth server contained old, dormant code that was accidentally reactivated during deployment. Without proper dynamic testing of the complete production environment, this time bomb went undetected.</p><p>Static analysis wouldn&#8217;t have caught this&#8202;&#8212;&#8202;the old code was syntactically correct and had worked fine years earlier. What was needed was <strong>integration testing</strong> and <strong>failure mode testing</strong> across the complete system. Dynamic testing in a production-mirror environment would have revealed the dormant code&#8217;s reactivation before it could wreak havoc.</p><h3>The Numbers Don&#8217;t Lie: Efficiency Comparison</h3><p>Research consistently shows that static and dynamic testing have different strengths:</p><p><strong>Formal code inspections</strong> (a static technique) detect approximately <strong>60% of defects</strong> and find about <strong>5 defects per hour</strong> of review time.</p><p><strong>Dynamic testing</strong> catches different types of defects&#8202;&#8212;&#8202;particularly integration and runtime issues&#8202;&#8212;&#8202;but typically finds <strong>fewer than 3 defects per hour</strong>.</p><p>But here&#8217;s the critical insight: <strong>they find different bugs</strong>. Static testing excels at finding structural issues early, while dynamic testing catches behavioral problems that only emerge during execution. Using both approaches provides significantly better coverage than either alone.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kLIO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kLIO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!kLIO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!kLIO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!kLIO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kLIO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kLIO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!kLIO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!kLIO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!kLIO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94d7549a-5308-4f4d-bf26-37e54cf17f7f_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Practical Application: Building Your Testing Strategy</h3><p>Here&#8217;s how to leverage both approaches effectively:</p><h4><strong>During Development (Static Focus):</strong></h4><p>&#8226; Integrate static analysis tools into your IDE&#8202;&#8212;&#8202;catch issues as you type</p><p>&#8226; Conduct code reviews before merging&#8202;&#8212;&#8202;fresh eyes catch what tools miss</p><p>&#8226; Use pre-commit hooks to enforce coding standards automatically</p><p>&#8226; Review requirements and design documents for gaps and contradictions</p><h4><strong>During Testing (Dynamic Focus):</strong></h4><p>&#8226; Run unit tests with every build&#8202;&#8212;&#8202;catch regressions immediately</p><p>&#8226; Perform integration testing when components are combined</p><p>&#8226; Execute system testing in production-mirror environments</p><p>&#8226; Include performance and security testing in your test suite</p><h3>The AI Angle: Trust But Verify</h3><p>AI tools are increasingly capable of assisting with both static and dynamic testing. AI-powered static analyzers can find complex patterns that rule-based tools miss. AI can generate test cases and even predict where bugs are likely to hide.</p><p>But remember our core principle: <strong>trust but verify</strong>. AI suggestions for code improvements need human review. AI-generated test cases need validation. AI predictions about bug locations need confirmation through actual testing.</p><p>The best approach combines AI efficiency with human judgment&#8202;&#8212;&#8202;using AI to accelerate both static and dynamic testing while maintaining the critical thinking that catches what algorithms miss.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1E1G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1E1G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1E1G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1E1G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1E1G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1E1G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1E1G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1E1G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1E1G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1E1G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97e63e10-3021-4fa5-97c4-422fcb32f878_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Key Takeaways</h3><p><strong>1. Static testing examines code without running it</strong>&#8202;&#8212;&#8202;catching structural issues early and cheaply.</p><p><strong>2. Dynamic testing executes code to observe behavior</strong>&#8202;&#8212;&#8202;revealing runtime and integration issues.</p><p><strong>3. Neither approach alone is sufficient</strong>&#8202;&#8212;&#8202;they find fundamentally different types of defects.</p><p><strong>4. Earlier detection means cheaper fixes</strong>&#8202;&#8212;&#8202;static testing&#8217;s biggest advantage is timing.</p><p><strong>5. Real-world disasters prove both approaches are essential</strong>&#8202;&#8212;&#8202;Toyota needed better static testing; Knight Capital needed better dynamic testing.</p><h3>What&#8217;s Next?</h3><p>Understanding static versus dynamic testing is foundational, but knowing <strong>which</strong> tests to run is equally important. In our next article, we&#8217;ll explore <strong>&#8220;What Makes a Good Tester?&#8221;</strong>&#8202;&#8212;&#8202;the essential skills and mindset traits that separate great testers from the rest.</p><p>Until then, look at your current testing approach: Are you balancing static and dynamic techniques effectively? Or is one side of the quality coin getting neglected?</p><blockquote><p><em>Keep questioning, keep testing, and always remember&#8202;&#8212;&#8202;quality is everyone&#8217;s responsibility.</em></p></blockquote>]]></content:encoded></item><item><title><![CDATA[Verification vs Validation]]></title><description><![CDATA["Are we building it right?" vs "Are we building the right thing?"]]></description><link>https://ryancraventech.substack.com/p/verification-vs-validation</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/verification-vs-validation</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Fri, 30 Jan 2026 13:16:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PxBf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><p>Welcome back to NextGen QA! Today we&#8217;re tackling one of the most frequently confused pairs of concepts in software testing&#8202;&#8212;&#8202;verification and validation. These two terms get mixed up so often that even experienced professionals sometimes use them interchangeably.</p><p>They&#8217;re not the same. And understanding the difference could save your project&#8202;&#8212;&#8202;or even lives.</p><p>Let me tell you about a spacecraft, a radiation machine, and an airplane. Each represents billions of dollars and, tragically, human lives lost because teams got this distinction wrong.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PxBf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PxBf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PxBf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PxBf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PxBf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PxBf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PxBf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PxBf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PxBf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PxBf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15bac7dc-5713-482b-a192-475168b9da57_800x447.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4>The $327 Million Mission</h4><p>On September 23, 1999, NASA&#8217;s Mars Climate Orbiter&#8202;&#8212;&#8202;a $125 million spacecraft at the center of a $327 million mission&#8202;&#8212;&#8202;approached Mars after a nine-month journey across 416 million miles of space. Everything had been tested. Every system had been verified against specifications. The software performed exactly as designed.</p><p>Then the spacecraft disappeared.</p><p>The investigation revealed something both simple and devastating: Lockheed Martin&#8217;s ground software calculated thrust in pound-force seconds. NASA&#8217;s systems expected newton-seconds. Nobody caught the mismatch. The orbiter flew too close to Mars and burned up in the atmosphere.</p><p>Here&#8217;s what&#8217;s crucial to understand: <strong>The software passed verification.</strong> It did exactly what the specifications said it should do. The Lockheed Martin code correctly calculated values in imperial units, precisely as its specifications defined.</p><p>But it <strong>failed validation.</strong> The system didn&#8217;t meet the actual mission need&#8202;&#8212;&#8202;navigating a spacecraft to Mars orbit. The specification itself was wrong, or at least, incomplete.</p><p>This is the heart of verification vs validation. One checks if you followed the recipe. The other checks if the cake actually tastes good.</p><div><hr></div><h3>The Definitions That Matter</h3><p>Let me give you the formal definitions, then make them practical.</p><p><strong>Verification</strong> answers: <em>&#8221;Are we building the product right?&#8221;</em></p><p>It&#8217;s the process of evaluating work products to determine whether they correctly implement the specified requirements. Think of it as checking your work against the blueprint. Did you build what the design said to build?</p><p><strong>Validation</strong> answers: <em>&#8221;Are we building the right product?&#8221;</em></p><p>It&#8217;s the process of evaluating the final product to determine whether it satisfies the intended use and user needs. Think of it as checking whether what you built actually solves the problem it was meant to solve.</p><p>These definitions come from Barry Boehm, who articulated them in 1979, and they&#8217;ve been formalized in IEEE 1012 and ISTQB standards ever since. The words themselves hint at their meaning&#8202;&#8212;&#8202;verification shares a root with <em><strong>veritas</strong></em> (truth to specification), while validation comes from <em><strong>valere</strong></em> (to be worthy of use).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uTAu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uTAu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uTAu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uTAu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uTAu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uTAu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uTAu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uTAu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uTAu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uTAu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0ce3d2-4b85-49dd-a3a3-2dd2c72f797e_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>A Tale of Two Failures</h3><p>Let me contrast two disasters that illustrate each type of failure.</p><h4>When Verification Fails: Therac-25</h4><p>Between 1985 and 1987, the Therac-25 radiation therapy machine delivered lethal radiation doses to at least six patients, killing at least three. The cause? Race conditions in the software&#8202;&#8212;&#8202;timing bugs that occurred when operators typed commands faster than the system expected.</p><p>This was a <strong>verification failure</strong>. The software didn&#8217;t even meet its own specifications. Basic concurrent programming errors existed in code that had never been properly reviewed. The software was developed by one person over several years with no peer review. It was never considered during safety assessment&#8202;&#8212;&#8202;only hardware was tested.</p><p>The code was simply wrong. It didn&#8217;t do what it was supposed to do.</p><h4>When Validation Fails: Boeing 737 MAX MCAS</h4><p>The Maneuvering Characteristics Augmentation System (MCAS) on the Boeing 737 MAX worked exactly as designed. When angle-of-attack sensors indicated the nose was too high, it pushed the nose down. The code had no bugs. It passed every verification check.</p><p>But the design failed to account for what happens when a sensor fails. MCAS relied on a single sensor with no redundancy. When that sensor gave false readings on Lion Air Flight 610 and Ethiopian Airlines Flight 302, the system repeatedly pushed the nose down, fighting the pilots until both aircraft crashed. 346 people died.</p><p>This was a <strong>validation failure</strong>. The software did exactly what it was designed to do. But what it was designed to do wasn&#8217;t what users actually needed in the real world. The specification itself was inadequate.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T7e9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T7e9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!T7e9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!T7e9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!T7e9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T7e9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T7e9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!T7e9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!T7e9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!T7e9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3444a5ac-a448-4b8a-a25b-2cbff52b4c72_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>The Methods Behind Each</h3><p>Verification and validation don&#8217;t just differ in what they check&#8202;&#8212;&#8202;they differ in <em><strong>how</strong></em> they check it.</p><h4>Verification Methods (Static Testing)</h4><p>Verification often happens without executing the software. It&#8217;s about examining artifacts:</p><ol><li><p><strong>Reviews and Inspections</strong>&#8202;&#8212;&#8202;Teams examine requirements, designs, and code against specifications. Does the architecture document address all requirements? Does the code implement the design correctly? These structured examinations catch errors before they become bugs.</p></li><li><p><strong>Walkthroughs&#8202;</strong>&#8212;&#8202;Authors guide reviewers through their work, explaining decisions and receiving feedback. Less formal than inspections, but effective for knowledge sharing and catching assumptions.</p></li><li><p><strong>Static Analysis</strong>&#8202;&#8212;&#8202;Automated tools examine code without running it, finding potential bugs, security vulnerabilities, and style violations. The code doesn&#8217;t need to execute for the tool to identify that a variable might be null when dereferenced.</p></li><li><p><strong>Traceability Analysis</strong>&#8202;&#8212;&#8202;Checking that every requirement maps to design elements, code, and tests. If a requirement exists, something should implement it, and something should test it.</p></li></ol><blockquote><p>Verification asks: <em>&#8221;<strong>According to our plans, is this correct?</strong>&#8221;</em></p></blockquote><h4>Validation Methods (Dynamic Testing)</h4><p>Validation requires running the software and observing its behavior in conditions that resemble real use. Note that dynamic testing methods can serve both verification <em><strong>and</strong></em> validation purposes&#8202;&#8212;&#8202;unit tests can verify code against design specs, while acceptance tests validate against user needs. The key is the <em>perspective</em>: are you checking against specifications, or against real-world fitness?</p><ol><li><p><strong>Unit Testing</strong>&#8202;&#8212;&#8202;Individual components are tested in isolation. Does this function return the expected output for given inputs?</p></li><li><p><strong>Integration Testing</strong>&#8202;&#8212;&#8202;Combined components are tested together. Do these modules communicate correctly?</p></li><li><p><strong>System Testing</strong>&#8202;&#8212;&#8202;The complete system is tested end-to-end. Does the whole application work as intended?</p></li><li><p><strong>User Acceptance Testing</strong>&#8202;&#8212;&#8202;Real users (or their representatives) test the system. Does this actually solve their problem? Can they accomplish their goals?</p></li><li><p><strong>Beta Testing</strong>&#8202;&#8212;&#8202;The product goes to a subset of real users in real environments. What happens when the software meets the chaos of the real world?</p></li></ol><blockquote><p>Validation asks: <em>&#8221;<strong>In practice, does this work?</strong>&#8221;</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pUW8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pUW8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pUW8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pUW8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pUW8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pUW8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pUW8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pUW8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pUW8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pUW8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40a9253f-ea68-4a70-a8d3-9e4c11e26f5f_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>The V-Model Makes It Visual</h4><p>If you want to see verification and validation in perfect architectural form, look at the V-Model&#8202;&#8212;&#8202;a software development approach that pairs each development phase with a corresponding testing phase.</p><p>On the left side of the V, you descend through requirements, system design, architecture design, and module design. On the right side, you ascend through unit testing, integration testing, system testing, and acceptance testing.</p><p>Here&#8217;s the insight: T<strong>he left side is primarily about verification.</strong> You&#8217;re checking each level against the level above it. Does the design correctly capture the requirements? Does the architecture correctly implement the design?</p><p><strong>The right side is primarily about validation.</strong> You&#8217;re checking each level against actual behavior. Does the unit perform correctly? Does the integrated system behave as users expect?</p><p>The V-Model makes visible what should be true in any methodology: verification and validation are complementary activities that run throughout development, not just a checkbox at the end.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HSpt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HSpt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HSpt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HSpt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HSpt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HSpt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HSpt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HSpt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HSpt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HSpt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd146df2-cdd7-4122-8ffd-eb89a1488dcb_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Common Misconceptions</h3><p>Let me address the myths I encounter constantly.</p><h4>Myth 1: &#8220;They&#8217;re basically the same thing&#8221;</h4><p>No. A system can pass all verification checks while completely failing validation (Boeing 737 MAX). It followed the spec perfectly&#8202;&#8212;&#8202;the spec was just wrong. Conversely, a system can satisfy users while violating specifications, though this creates technical debt and maintenance nightmares.</p><h4>Myth 2: &#8220;Verification happens first, then validation&#8221;</h4><p>While it&#8217;s true that verification tends to occur earlier (you can review requirements before you have running code), both activities should occur throughout development. In agile environments especially, you&#8217;re continuously both verifying (is this sprint&#8217;s work correct?) and validating (does it still serve user needs?).</p><h4>Myth 3: &#8220;Thorough verification eliminates the need for validation&#8221;</h4><p>The Mars Climate Orbiter proves this wrong. Every line of code worked as specified. The software was <em>*verified*</em> extensively. But it failed <em>*validation*</em> because the specifications didn&#8217;t capture what was actually needed. Verification can only be as good as the specifications it checks against.</p><h4>Myth 4: &#8220;Validation only happens at the end&#8221;</h4><p>Early validation catches wrong assumptions before you&#8217;ve invested months building the wrong thing. Prototypes, user feedback sessions, and MVP testing are all validation activities that smart teams do early and often.</p><h4>Myth 5: &#8220;These are just tester activities&#8221;</h4><p>Verification often involves developers reviewing each other&#8217;s code, architects inspecting designs, and business analysts validating requirements with stakeholders. Validation involves product owners, users, and business representatives. Both are team responsibilities, not just testing team responsibilities.</p><div><hr></div><h3>A Practical Framework</h3><p>Here&#8217;s how I think about applying V&amp;V in practice:</p><h4>Ask two questions constantly:</h4><p>1. &#8221;<strong>Does this match our specification?</strong>&#8221; (Verification)</p><ul><li><p>Code review: Does this implementation match the design?</p></li><li><p>Test review: Do these tests cover the requirements?</p></li><li><p>Documentation review: Does this describe what we actually built?</p></li></ul><p>2. &#8221;<strong>Does this solve the real problem?</strong>&#8221; (Validation)</p><ul><li><p>User testing: Can people accomplish their goals?</p></li><li><p>Production monitoring: Is the system actually being used as intended?</p></li><li><p>Business metrics: Are we achieving the outcomes we wanted?</p></li></ul><p>If you only ask the first question, you might build the wrong thing perfectly. If you only ask the second question, you might build the right thing poorly. You need both.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tbtV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tbtV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tbtV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tbtV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tbtV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tbtV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tbtV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tbtV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tbtV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tbtV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901e5a8-3469-43fb-9122-da0dd71991cf_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Industry Standards Require Both</h3><p>If you work in regulated industries, you don&#8217;t get to choose whether to do V&amp;V&#8202;&#8212;&#8202;standards mandate both.</p><h4>Medical Devices (FDA 21 CFR Part 820)</h4><p>The FDA requires documented verification and validation for medical device software. Section 820.30(g) specifically addresses software validation. You must prove the software was built correctly (verification) AND that it meets user needs safely (validation). The consequences of getting this wrong are measured in patient harm.</p><h4>Aerospace (DO-178C)</h4><p>Software in aircraft must meet Design Assurance Levels (DAL) ranging from E (no safety effect) to A (catastrophic failure potential). Level A software requires completing 71 verification objectives. Coverage requirements include statement coverage, branch coverage, and modified condition/decision coverage (MC/DC). Independence is mandatory&#8202;&#8212;&#8202;the person who wrote the code cannot be the only person who verifies it.</p><h4>Automotive (ISO 26262)</h4><p>Automotive Safety Integrity Levels (ASIL A through D) determine how rigorously you must verify and validate. ASIL D systems&#8202;&#8212;&#8202;where failure could be fatal&#8202;&#8212;&#8202;require the most extensive V&amp;V, including formal verification methods.</p><p>These standards exist because verification alone isn&#8217;t enough. A perfectly verified specification that doesn&#8217;t account for real-world conditions kills people, as Boeing painfully demonstrated.</p><div><hr></div><h3>AI and the Trust-But-Verify Principle</h3><p>Here&#8217;s where this connects to our broader theme of AI in testing.</p><p>AI tools can generate test cases, suggest code, and automate many verification activities. But recent industry data reveals a troubling trend: developer trust in AI outputs has <em><strong>dropped</strong></em> from 43% to 33% in just one year.</p><p>Why? The &#8220;<strong>almost right</strong>&#8221; problem.</p><p>66% of developers report that AI-generated code is &#8220;nearly correct&#8221;&#8202;&#8212;&#8202;close enough to look good, different enough to be dangerous. Studies show 40&#8211;48% of AI-generated code contains security vulnerabilities. This creates what I call <em><strong>verification debt</strong>&#8202;</em>&#8212;&#8202;code that looks right but hasn&#8217;t been properly checked.</p><p>Here&#8217;s the insight: <strong>AI struggles more with validation than verification.</strong></p><p>AI can check if code follows patterns, matches specifications, and avoids known bad practices. That&#8217;s verification, and AI can help significantly.</p><p>But AI struggles to know if the specification itself is right. It can&#8217;t tell if users will actually find the feature useful. It can&#8217;t sense that the requirements missed an edge case that matters in production. That requires human judgment about real-world context.</p><p>The &#8220;trust but verify&#8221; principle becomes crucial: Use AI to accelerate verification activities, but maintain human judgment for validation activities. AI can help you build it right. Only humans can determine if you&#8217;re building the right thing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R_5G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R_5G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R_5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R_5G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Your Verification &amp; Validation Checklist</h3><p>Let me leave you with practical guidance.</p><p><strong>For Verification, ask:</strong></p><ul><li><p>Have requirements been reviewed for completeness and consistency</p></li><li><p>Has the design been reviewed against requirements?</p></li><li><p>Has code been reviewed against the design?</p></li><li><p>Have test cases been reviewed against requirements?</p></li><li><p>Has static analysis been run on the code?</p></li><li><p>Is there traceability from requirements to tests?</p></li><li><p>Have all findings from reviews been addressed?</p></li></ul><p><strong>For Validation, ask:</strong></p><ul><li><p>Have real users (or realistic proxies) tested the system?</p></li><li><p>Does the system work in conditions resembling production?</p></li><li><p>Can users accomplish their actual goals?</p></li><li><p>Does the system handle realistic error conditions?</p></li><li><p>Have edge cases from real-world scenarios been tested?</p></li><li><p>Does the system deliver the intended business value?</p></li><li><p>Would you trust this system with real stakes?</p></li></ul><p>If you&#8217;re checking boxes only in the first list, you might be building the wrong thing perfectly. If you&#8217;re checking boxes only in the second list, you might be building the right thing poorly.</p><h3><strong>Do both.</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R_5G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R_5G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R_5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg" width="800" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R_5G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 424w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 848w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!R_5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b5532d-9d5a-4e26-8930-36f75dded2c4_800x447.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Verification and validation are two lenses for examining quality. Verification asks whether you followed the plan. Validation asks whether the plan was right.</p><p>The Mars Climate Orbiter followed its plan perfectly into the wrong trajectory. The Boeing 737 MAX MCAS executed its design flawlessly into disaster. These weren&#8217;t failures of execution&#8202;&#8212;&#8202;they were failures of validation. The specifications themselves were wrong, and no amount of verification against wrong specifications can make a product right.</p><p>Conversely, the Therac-25 didn&#8217;t even follow its specifications correctly. Race conditions and untested code paths represented fundamental verification failures. Even if the design had been perfect, the implementation was broken.</p><p>You need both. Always.</p><p>In our next article, we&#8217;ll explore <strong>Static vs Dynamic Testing</strong>&#8202;&#8212;&#8202;diving deeper into the techniques that make verification and validation work in practice. We&#8217;ll look at how finding defects without executing code complements finding them through execution.</p><p>Until then, remember:</p><blockquote><p>Building it right isn&#8217;t enough if you&#8217;re not building the right thing. And building the right thing doesn&#8217;t matter if you can&#8217;t build it right.</p></blockquote>]]></content:encoded></item><item><title><![CDATA[The SDLC and Where Testing Fits]]></title><description><![CDATA[Integration across the development lifecycle]]></description><link>https://ryancraventech.substack.com/p/the-sdlc-and-where-testing-fits</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/the-sdlc-and-where-testing-fits</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Wed, 28 Jan 2026 13:15:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Fz_j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><p>Stop me if this sounds familiar.</p><p>Development wraps up on Friday. Someone emails you: &#8220;Feature&#8217;s ready for testing. We need to ship Monday.&#8221;</p><p>You have a weekend to test three months of development work. You find issues. Development pushes back&#8202;&#8212;&#8202;there&#8217;s no time to fix them. You&#8217;re pressured to approve a release you&#8217;re not confident about. The feature ships with known problems. Users complain. Everyone points fingers.</p><p>This is what happens when testing is treated as a phase bolted onto the end of development rather than an integrated practice woven throughout the entire software development lifecycle.</p><p>Today we&#8217;re exploring where testing actually fits in the SDLC&#8202;&#8212;&#8202;spoiler: everywhere&#8202;&#8212;&#8202;and how understanding this transforms you from a gatekeeper at the end to a quality partner from the beginning.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fz_j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fz_j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Fz_j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Fz_j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Fz_j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fz_j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fz_j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Fz_j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Fz_j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Fz_j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd628b274-c508-49ac-811f-d0eacf9fc62a_900x502.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>What Is the SDLC Anyway?</h3><p>The Software Development Lifecycle is the process a project follows from initial concept to deployed product and ongoing maintenance. Different organizations use different models&#8202;&#8212;&#8202;Waterfall, Agile, DevOps, hybrid approaches&#8202;&#8212;&#8202;but they all involve similar fundamental activities, just organized differently.</p><p>Those core activities are:</p><p><strong>Planning and Requirements</strong>&#8202;&#8212;&#8202;Figuring out what to build and why</p><p><strong>Design</strong>&#8202;&#8212;&#8202;Deciding how to build it</p><p><strong>Development</strong>&#8202;&#8212;&#8202;Actually building it</p><p><strong>Testing</strong>&#8202;&#8212;&#8202;Verifying it works and meets needs</p><p><strong>Deployment</strong>&#8202;&#8212;&#8202;Releasing it to users</p><p><strong>Maintenance</strong>&#8202;&#8212;&#8202;Keeping it running and improving it</p><p>The traditional view placed these as sequential phases. You finish one, move to the next. Testing was phase four&#8202;&#8212;&#8202;you couldn&#8217;t start until development finished, and you had to complete before deployment could begin.</p><p>This view is outdated, harmful, and still disturbingly common.</p><p>Modern understanding recognizes that testing isn&#8217;t a phase. It&#8217;s an activity that should happen continuously, adapting its focus based on which phase the project is in. Testing during requirements looks different than testing during development, which looks different than testing in production. But testing should be happening at every stage.</p><div><hr></div><h3>The Cost of &#8220;Testing at the End&#8221;</h3><p>Before exploring where testing fits, let&#8217;s be clear about why the &#8220;testing phase&#8221; mindset fails.</p><p>When testing only happens at the end, several predictable problems occur.</p><p><strong>Defects are expensive to fix.</strong> We covered this in our Test Early, Test Often article&#8202;&#8212;&#8202;bugs found late cost 10x to 100x more to fix than bugs found early. When testing is compressed into a final phase, every bug you find is maximally expensive.</p><p><strong>Time pressure compromises quality.</strong> Testing phases get squeezed when earlier phases run long. Development took an extra two weeks? That comes out of testing time, not the ship date. Testers are pressured to rush, skip scenarios, or approve releases they&#8217;re uncertain about.</p><p><strong>Feedback comes too late.</strong> Finding a fundamental design flaw during final testing means choosing between shipping a flawed product or delaying significantly to redesign. If that flaw had been caught during design review, fixing it would have been trivial.</p><p><strong>Testers lack context.</strong> When testers only engage at the end, they don&#8217;t understand why decisions were made. They test against specifications without understanding intent. They miss issues that someone involved earlier would have caught.</p><p><strong>Adversarial relationships form.</strong> When testers only appear to find problems in &#8220;finished&#8221; work, developers see them as obstacles rather than partners. The relationship becomes antagonistic rather than collaborative.</p><p><strong>Quality becomes someone else&#8217;s job.</strong> If testing is a separate phase owned by a separate team, developers feel less responsibility for quality. &#8220;QA will catch it&#8221; becomes an excuse for sloppy work.</p><p>I&#8217;ve watched this pattern play out dozens of times. It never ends well. The &#8220;testing phase&#8221; mindset is organizational malpractice.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nGes!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nGes!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nGes!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nGes!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nGes!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nGes!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nGes!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nGes!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nGes!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nGes!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1846c6d8-8dbc-4a22-872a-ab64774fa0bc_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Testing in the Planning and Requirements Phase</h3><p>Testing begins before anyone writes a single line of code. During planning and requirements, testing activities focus on preventing defects rather than detecting them.</p><p><strong>What testing looks like here:</strong></p><p>Testers review requirements documents, user stories, and specifications with a critical eye. They&#8217;re not testing software&#8202;&#8212;&#8202;they&#8217;re testing ideas. They look for ambiguity, incompleteness, contradictions, and untestable statements.</p><p>When a requirement says &#8220;the system should respond quickly,&#8221; a tester asks: &#8220;What does quickly mean? Under what load? How will we measure this? What&#8217;s acceptable versus unacceptable?&#8221;</p><p>When a user story describes a feature, a tester thinks through scenarios: &#8220;What happens if the user does X? What about edge case Y? How does this interact with existing feature Z?&#8221;</p><p>Testers help write acceptance criteria&#8202;&#8212;&#8202;the specific conditions that must be true for a feature to be considered complete. These criteria become the foundation for later test cases.</p><p><strong>The value testers provide:</strong></p><p>Requirements defects are the cheapest to fix and the most expensive to miss. A missing requirement discovered during planning costs a conversation. The same missing requirement discovered in production costs emergency fixes, user frustration, and reputation damage.</p><p>Testers bring a different perspective than developers and product managers. They think about what could go wrong, not just what should go right. That perspective catches issues others miss.</p><p><strong>Practical activities:</strong></p><p>Participating in requirements review meetings and asking clarifying questions. Identifying requirements that are vague, contradictory, or untestable. Writing initial test scenarios based on requirements to validate they&#8217;re complete. Creating acceptance criteria collaboratively with product owners. Flagging risks and assumptions that need validation.</p><p>If you&#8217;re a tester who isn&#8217;t involved until &#8220;testing phase,&#8221; advocate for earlier involvement. Offer to review requirements. Ask to attend planning meetings. The value you provide early far exceeds the time investment.</p><div><hr></div><h3>Testing in the Design Phase</h3><p>Once requirements are established, design determines how those requirements will be implemented. Testing during design focuses on evaluating whether the proposed solution will actually work and can be tested effectively.</p><p><strong>What testing looks like here:</strong></p><p>Testers review architecture documents, system designs, API specifications, and data models. They&#8217;re evaluating whether the design supports the requirements, whether it introduces risks, and whether it can be tested.</p><p>A tester might ask: &#8220;This design has the authentication service calling the payment service directly. What happens if the payment service is down? How will we test failure scenarios?&#8221;</p><p>Or: &#8220;The data model stores user preferences in a JSON blob. How will we verify that preference changes are saved correctly? Can we query specific preferences for testing?&#8221;</p><p>Testers also plan their testing approach during this phase. Based on the design, they identify what types of testing will be needed, what test environments and data will be required, and what tools might be necessary.</p><p><strong>The value testers provide:</strong></p><p>Design decisions that seem reasonable from a development perspective sometimes create testing nightmares. A tester&#8217;s early input can influence design toward more testable solutions.</p><p>Testers also identify integration points, external dependencies, and potential bottlenecks that will need focused testing later. This early identification enables better test planning.</p><p><strong>Practical activities:</strong></p><p>Reviewing design documents and asking questions about testability. Identifying integration points and external dependencies that need testing strategies. Planning test environments, test data needs, and tool requirements. Creating high-level test strategies based on the architecture. Flagging design decisions that will make testing difficult or impossible.</p><div><hr></div><h3>Testing in the Development Phase</h3><p>This is where most people think testing starts, but by now you&#8217;ve seen that testing activities should already be well underway. During development, testing focuses on verifying that code works correctly as it&#8217;s being written.</p><p><strong>What testing looks like here:</strong></p><p>Multiple types of testing happen during development, performed by different people with different focuses.</p><p>Developers write unit tests that verify individual functions and components work correctly in isolation. These tests run automatically, often on every code commit, providing immediate feedback when something breaks.</p><p>Developers also perform integration testing as they connect components together, verifying that pieces work correctly in combination.</p><p>Testers begin testing features as soon as they&#8217;re minimally functional&#8202;&#8212;&#8202;not waiting for &#8220;code complete.&#8221; This early testing provides rapid feedback while developers still have full context.</p><p>Code reviews include quality considerations. Reviewers look not just for correctness but for maintainability, error handling, and potential edge cases.</p><p>Automated tests run in continuous integration pipelines, catching regressions immediately rather than weeks later.</p><p><strong>The value testers provide:</strong></p><p>Testers testing during development&#8202;&#8212;&#8202;rather than waiting until development finishes&#8202;&#8212;&#8202;creates tight feedback loops. A bug found today while the developer remembers the code is far easier to fix than a bug found three weeks later when they&#8217;ve moved on to other work.</p><p>Testers also bring a different perspective than developers. They think about how users will actually use features, not just how features are supposed to work technically.</p><p><strong>Practical activities:</strong></p><p>Testing features incrementally as they become available rather than waiting for completion. Participating in code reviews with a quality perspective. Writing and maintaining automated test suites that run in CI/CD pipelines. Performing exploratory testing on new functionality to find issues formal tests miss. Collaborating with developers to understand implementation and identify risks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vTDf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vTDf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vTDf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vTDf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vTDf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vTDf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vTDf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vTDf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vTDf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vTDf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F201f9492-d2e6-4622-b2f3-aa61704c5f29_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Testing in the Testing Phase (Yes, There Still Is One)</h3><p>Even with testing integrated throughout, there&#8217;s still value in dedicated testing time before release. But its purpose changes from &#8220;the only testing that happens&#8221; to &#8220;comprehensive validation and release readiness assessment.&#8221;</p><p><strong>What testing looks like here:</strong></p><p>System testing validates the complete integrated system works as expected. Individual components have been tested, but now you verify they work correctly together in realistic configurations.</p><p>End-to-end testing follows complete user journeys through the system, verifying that real workflows function correctly from start to finish.</p><p>Regression testing ensures that new changes haven&#8217;t broken existing functionality. Automated regression suites run comprehensively, and testers explore areas where regressions might hide.</p><p>User acceptance testing brings actual users or user representatives to validate the system meets their needs&#8202;&#8212;&#8202;not just specifications, but real needs.</p><p>Non-functional testing validates performance, security, accessibility, and other quality attributes that matter beyond basic functionality.</p><p>Release readiness assessment synthesizes all testing results into a clear picture: Are we ready to ship? What are the known risks? What&#8217;s our confidence level?</p><p><strong>The value testers provide:</strong></p><p>Dedicated testing time allows comprehensive validation that couldn&#8217;t happen incrementally. It&#8217;s the opportunity to step back and assess the whole system, not just individual pieces.</p><p>This phase produces the information stakeholders need to make release decisions. Not just &#8220;here are the bugs&#8221; but &#8220;here&#8217;s our assessment of readiness and risk.&#8221;</p><p><strong>Practical activities:</strong></p><p>Executing comprehensive test suites across the integrated system. Performing focused exploratory testing on high-risk areas. Conducting user acceptance testing with real users or proxies. Running performance, security, and other specialized testing. Synthesizing results into release readiness recommendations. Documenting known issues with severity assessments and workarounds.</p><div><hr></div><h3>Testing in the Deployment Phase</h3><p>Deployment isn&#8217;t just pushing code to production. It&#8217;s a critical phase where testing continues to play an important role.</p><p><strong>What testing looks like here:</strong></p><p>Smoke testing in staging environments verifies that deployment succeeded and basic functionality works before users are affected.</p><p>Canary deployments release changes to a small subset of users first, with monitoring to detect problems before full rollout.</p><p>Feature flags allow new functionality to be deployed but not activated, enabling testing in production conditions without user exposure.</p><p>Rollback verification ensures that if problems occur, the system can quickly return to a known good state.</p><p><strong>The value testers provide:</strong></p><p>Testers help design deployment verification strategies. They define what &#8220;successful deployment&#8221; means and how to detect problems quickly.</p><p>They also participate in deployment monitoring, watching for issues that might not appear until real users interact with the system under real conditions.</p><p><strong>Practical activities:</strong></p><p>Defining smoke test suites that verify successful deployment. Creating monitoring dashboards that detect problems quickly. Participating in deployment reviews and go/no-go decisions. Testing rollback procedures before they&#8217;re needed in emergencies. Verifying feature flags work correctly to control feature exposure.</p><div><hr></div><h3>Testing in the Maintenance Phase</h3><p>After deployment, the system enters ongoing maintenance. Features are enhanced, bugs are fixed, performance is optimized, and security is maintained. Testing continues throughout.</p><p><strong>What testing looks like here:</strong></p><p>Production monitoring becomes a form of continuous testing. Real users are exercising the system constantly, and monitoring detects when something goes wrong.</p><p>Bug fix verification ensures that reported issues are actually resolved and don&#8217;t reintroduce other problems.</p><p>Regression testing on every change&#8202;&#8212;&#8202;even small fixes&#8202;&#8212;&#8202;prevents the common pattern where fixing one bug creates two more.</p><p>Periodic security testing identifies new vulnerabilities as threats evolve and dependencies change.</p><p>Performance monitoring detects degradation over time as data grows and usage patterns change.</p><p><strong>The value testers provide:</strong></p><p>Testers help interpret production data to identify quality issues. A spike in error rates, an increase in customer complaints, or unusual usage patterns all signal potential problems that need investigation.</p><p>Testers also maintain and evolve test suites as the system evolves, ensuring that testing remains relevant and effective over time.</p><p><strong>Practical activities:</strong></p><p>Monitoring production for quality signals and investigating anomalies. Verifying bug fixes and testing for regressions. Maintaining automated test suites as the system evolves. Conducting periodic security and performance assessments. Analyzing user feedback and support tickets for quality insights. Updating test cases when requirements change.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NdFV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NdFV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NdFV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NdFV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NdFV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NdFV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NdFV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NdFV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NdFV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NdFV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa300ba36-d4f5-41de-b72a-0f86cdd4f897_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Different SDLC Models, Same Testing Principle</h3><p>Whether your organization uses Waterfall, Agile, DevOps, or some hybrid approach, the principle remains the same: testing should be integrated throughout, not isolated at the end.</p><p><strong>Waterfall environments</strong> traditionally treated testing as a phase after development. Modern Waterfall organizations recognize this creates problems and incorporate testing activities earlier&#8202;&#8212;&#8202;requirements reviews, design validation, incremental testing during development&#8202;&#8212;&#8202;even while maintaining the overall sequential structure.</p><p><strong>Agile environments</strong> naturally integrate testing throughout each sprint. Testing happens continuously, with testers embedded in development teams rather than working in separate departments. Each sprint includes requirements discussion, development, testing, and potentially deployment as a mini-lifecycle.</p><p><strong>DevOps environments</strong> push testing even further into every activity. Automated tests run on every commit. Testing in production through monitoring and observability is standard practice. The line between development, testing, and operations blurs as everyone takes responsibility for quality.</p><p><strong>Hybrid environments</strong>&#8202;&#8212;&#8202;which describe most real organizations&#8202;&#8212;&#8202;combine elements of different models. Whatever your specific process, examine where testing happens. If it&#8217;s concentrated at the end, you have a problem to solve.</p><p>The specific practices vary, but the principle is universal: testing integrated throughout beats testing isolated at the end.</p><div><hr></div><h3>The Tester&#8217;s Evolving Role Across the SDLC</h3><p>As testing integrates throughout the lifecycle, the tester&#8217;s role evolves. You&#8217;re not just someone who finds bugs after development. You&#8217;re a quality advocate who contributes at every phase.</p><p><strong>During planning:</strong> You&#8217;re an analyst who challenges requirements and improves specifications.</p><p><strong>During design:</strong> You&#8217;re an advisor who evaluates testability and identifies risks.</p><p><strong>During development:</strong> You&#8217;re a partner who provides rapid feedback and validates incrementally.</p><p><strong>During testing:</strong> You&#8217;re an assessor who synthesizes information into release recommendations.</p><p><strong>During deployment:</strong> You&#8217;re a verifier who confirms successful releases and monitors for problems.</p><p><strong>During maintenance:</strong> You&#8217;re a guardian who maintains quality over time and evolves testing with the system.</p><p>This broader role requires broader skills. You need communication skills to participate in planning discussions. You need enough technical knowledge to evaluate designs and understand code. You need analytical skills to interpret monitoring data. You need strategic thinking to prioritize testing across phases.</p><p>The tester who only knows how to execute test cases at the end of development provides limited value. The tester who contributes quality thinking across the entire lifecycle is indispensable.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-IYx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-IYx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-IYx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-IYx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-IYx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-IYx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-IYx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-IYx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-IYx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-IYx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff706bde6-5b0f-43f3-b3b2-e04bca3b1bab_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Advocating for Earlier Involvement</h3><p>If you&#8217;re currently in an organization that treats testing as an end-phase activity, changing that pattern requires advocacy. Here&#8217;s how to make the case and start shifting practice.</p><p><strong>Start with data.</strong> Track how many bugs you find that could have been prevented with earlier involvement. &#8220;We found fifteen requirements issues during testing that cost us three weeks to fix. Those same issues would have been a one-hour conversation during requirements review.&#8221; Data makes the case concrete.</p><p><strong>Offer specific value.</strong> Don&#8217;t ask generically to &#8220;be involved earlier.&#8221; Offer specific contributions. &#8220;I&#8217;d like to attend the design review for the payment feature and provide input on testability and integration risks.&#8221; Specific offers are easier to accept than vague requests.</p><p><strong>Demonstrate impact.</strong> When you do get earlier involvement, document the value created. &#8220;During requirements review, I identified an ambiguous specification that would have caused rework during testing. Clarifying it now saved estimated two days of development and testing time.&#8221;</p><p><strong>Build relationships.</strong> Developers and product managers who experience value from early tester involvement become advocates for it. Build relationships where you&#8217;re seen as a helpful partner, not a critic who only appears to find fault.</p><p><strong>Accept incremental progress.</strong> You probably can&#8217;t transform your organization&#8217;s SDLC overnight. Start with one project, one team, one phase. Demonstrate success. Expand from there.</p><p><strong>Frame it in terms stakeholders care about.</strong> &#8220;Earlier testing involvement reduces late-cycle surprises and improves predictability&#8221; resonates more than &#8220;testing should be integrated throughout the SDLC.&#8221; Speak to what matters to your audience.</p><div><hr></div><h3>AI and the SDLC</h3><p>AI tools are affecting every phase of the SDLC, and testers need to understand how.</p><p><strong>During planning and requirements:</strong> AI can help analyze requirements for ambiguity and generate initial test scenarios. But AI doesn&#8217;t understand business context&#8202;&#8212;&#8202;it can flag that a requirement is vague without knowing whether that vagueness matters given your specific situation.</p><p><strong>During design:</strong> AI can identify potential design issues and suggest testing approaches based on similar systems. But it can&#8217;t evaluate whether a design fits your organization&#8217;s capabilities or constraints.</p><p><strong>During development:</strong> AI assists with code generation, which means more code produced faster&#8202;&#8212;&#8202;and potentially more bugs introduced faster. AI can also generate unit tests, though those tests need human review to ensure they&#8217;re actually meaningful.</p><p><strong>During testing:</strong> AI accelerates test case generation, execution, and analysis. It can identify patterns in test results that humans might miss. But AI can&#8217;t determine whether you&#8217;re testing the right things for your business objectives.</p><p><strong>During deployment and maintenance:</strong> AI enhances monitoring and anomaly detection, potentially catching issues faster than traditional approaches.</p><p>The theme across all phases: AI accelerates activities but doesn&#8217;t replace human judgment about what activities matter. Testers who understand where testing fits in the SDLC can strategically apply AI tools at each phase while maintaining quality judgment throughout.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vAST!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vAST!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vAST!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vAST!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vAST!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vAST!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg" width="900" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vAST!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vAST!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vAST!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vAST!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22812019-f8d3-4ffb-ab38-fea8185f8362_900x502.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Common SDLC Testing Anti-Patterns</h3><p>Watch for these patterns that indicate testing isn&#8217;t properly integrated:</p><p><strong>The handoff wall.</strong> Development &#8220;throws work over the wall&#8221; to testing with minimal communication. No collaboration, no shared context, no partnership.</p><p><strong>The compressed testing phase.</strong> Every other phase runs long, and testing absorbs the schedule impact. Testing is always rushed because it&#8217;s at the end.</p><p><strong>The gatekeeper adversary.</strong> Testers are seen as obstacles who block releases rather than partners who enable confident releases.</p><p><strong>The documentation theater.</strong> Elaborate test documentation exists but testing doesn&#8217;t actually happen until the end. The documentation creates an illusion of integrated testing.</p><p><strong>The automation excuse.</strong> &#8220;We have automated tests&#8221; becomes justification for no human testing involvement until late phases. Automation without strategy is just automated waste.</p><p><strong>The QA department silo.</strong> Testing happens in a separate organization with no integration into development teams. Quality is &#8220;their job&#8221; rather than everyone&#8217;s responsibility.</p><p>If you recognize these patterns in your organization, they&#8217;re symptoms of testing being isolated rather than integrated. Address the root cause&#8202;&#8212;&#8202;the SDLC structure and culture&#8202;&#8212;&#8202;not just the symptoms.</p><div><hr></div><h3>Your Challenge This Week</h3><p>Time to examine where testing actually fits in your organization:</p><p><strong>First, map your actual SDLC.</strong> Draw out how work actually flows in your organization from concept to production. Not the official process&#8202;&#8212;&#8202;the real one. Where does testing appear? How many phases have no testing involvement at all?</p><p><strong>Second, identify one gap.</strong> Choose one phase where testing isn&#8217;t involved but should be. Maybe it&#8217;s requirements review. Maybe it&#8217;s design discussion. Maybe it&#8217;s deployment verification. Pick one.</p><p><strong>Third, make a specific ask.</strong> Request involvement in that one phase for one specific project or feature. Not a permanent process change&#8202;&#8212;&#8202;just one trial. &#8220;Can I join the design review for the new checkout flow to provide testability input?&#8221;</p><p><strong>Fourth, document the value.</strong> If you get that involvement, track and document the value you provide. What issues did you identify? What problems did you prevent? What improved because of your participation?</p><p><strong>Finally, share what you learn.</strong> Tell your team what you discovered about testing integration in your SDLC. Start conversations about how testing could contribute earlier or more continuously.</p><div><hr></div><h3>Quality as a Continuous Thread</h3><p>The SDLC isn&#8217;t a relay race where each phase hands off to the next. It&#8217;s a collaborative journey where quality should be a continuous thread running through every activity.</p><p>Testing at the end is quality inspection&#8202;&#8212;&#8202;checking if the product is good after it&#8217;s built. Testing throughout is quality building&#8202;&#8212;&#8202;contributing to quality at every step so the product is built well from the start.</p><p>Inspection finds problems. Building prevents them.</p><p>The best organizations don&#8217;t have a &#8220;testing phase.&#8221; They have testing as a continuous practice that adapts its focus based on where the project is in its lifecycle. Testers are partners throughout, not gatekeepers at the end.</p><p>In our next article, we&#8217;ll explore <strong>Verification vs Validation</strong>&#8202;&#8212;&#8202;the difference between &#8220;Are we building it right?&#8221; and &#8220;Are we building the right thing?&#8221; This connects directly to SDLC integration because verification and validation activities should happen at different phases throughout the lifecycle, not just during final testing.</p><p><strong>Remember:</strong> Testing isn&#8217;t a phase. It&#8217;s a practice that belongs everywhere.</p>]]></content:encoded></item><item><title><![CDATA[Understanding Test Objectives]]></title><description><![CDATA[Aligning testing with business goals]]></description><link>https://ryancraventech.substack.com/p/understanding-test-objectives</link><guid isPermaLink="false">https://ryancraventech.substack.com/p/understanding-test-objectives</guid><dc:creator><![CDATA[Ryan Craven]]></dc:creator><pubDate>Mon, 26 Jan 2026 13:46:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0Bkq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Here&#8217;s a question that should be simple but rarely is: <strong>Why are you testing?</strong></p><p>Most testers answer reflexively: &#8220;To find bugs.&#8221; And yes, finding defects is part of testing. But it&#8217;s not the <em>objective</em> of testing &#8212; it&#8217;s a <em>method</em> of achieving objectives. The difference matters enormously.</p><p>I once watched two testers work on the same release with completely different outcomes, even though both found similar numbers of bugs. The first tester found twenty-three defects, logged them all, and called it a successful test cycle. The second tester found nineteen defects, but also provided a risk assessment, identified the critical user journeys that were now solid, flagged areas that still needed attention, and gave clear guidance on release readiness.</p><p>Guess which tester the product manager trusted more? Guess which tester influenced decisions? Guess which tester actually impacted quality?</p><p>Finding bugs is easy. Understanding <em>why</em> you&#8217;re testing, <em>what</em> really matters, and <em>how</em> your testing serves business objectives &#8212; that&#8217;s where professional testing begins.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ryancraventech.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ryancraventech.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0Bkq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0Bkq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0Bkq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0Bkq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0Bkq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0Bkq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!0Bkq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0Bkq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0Bkq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0Bkq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46e95120-962d-499c-8140-e3873030a79d_788x440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Are Test Objectives?</strong></h2><p>Test objectives are the specific, measurable goals your testing aims to achieve. They answer fundamental questions: What are we trying to learn? What decisions does this testing inform? What risks are we evaluating? What confidence are we building?</p><p>Good test objectives connect testing activities to business outcomes. They&#8217;re specific enough to guide your testing approach but flexible enough to adapt as you learn. They&#8217;re shared across the team so everyone understands what testing is actually trying to accomplish.</p><p>Bad test objectives are vague platitudes like &#8220;ensure quality&#8221; or &#8220;find all bugs&#8221; or &#8220;make sure it works.&#8221; These sound reasonable but provide zero guidance. How do you know when you&#8217;ve ensured quality? What does &#8220;all bugs&#8221; mean when exhaustive testing is impossible? What does &#8220;works&#8221; mean without context?</p><p>Here&#8217;s the difference:</p><p><strong>Vague objective:</strong> &#8220;Test the login feature.&#8221;</p><p><strong>Clear objective:</strong> &#8220;Verify that users can successfully authenticate using the three supported methods (email/password, social login, SSO) and that security controls prevent unauthorized access, with focus on the most common authentication flows since this is the entry point for all users.&#8221;</p><p>The clear objective tells you what to prioritize, why it matters, and what &#8220;done&#8221; looks like.</p><h2><strong>Common Testing Objectives (And What They Really Mean)</strong></h2><p>Let&#8217;s break down the most common testing objectives and what they actually entail when you think beyond surface level.</p><h2><strong>Finding Defects Before Users Do</strong></h2><p>This is the most obvious objective, but it&#8217;s more nuanced than it appears. You&#8217;re not trying to find <em>all</em> bugs &#8212; that&#8217;s impossible. You&#8217;re trying to find bugs that matter before they impact users.</p><p>This objective drives you toward risk-based testing, toward focusing on critical user paths, toward understanding which bugs are worth delaying release and which can wait. It means asking &#8220;what bugs would cause the most damage if they reached production?&#8221; and hunting specifically for those.</p><p>Finding a hundred cosmetic bugs while missing one data corruption bug means you failed this objective despite your impressive bug count.</p><h2><strong>Assessing Release Readiness</strong></h2><p>Sometimes testing isn&#8217;t about finding every bug &#8212; it&#8217;s about providing information so stakeholders can decide whether to release. This objective shifts your focus from defect hunting to risk assessment.</p><p>You&#8217;re answering: Are critical features stable? Have we tested the high-risk areas adequately? What are the known issues and how severe are they? What&#8217;s the likelihood of major problems in production? What&#8217;s our confidence level?</p><p>This objective requires communication skills as much as testing skills. You&#8217;re providing decision-making information, not just bug reports.</p><h2><strong>Validating Requirements and Specifications</strong></h2><p>Early in projects, testing objectives often focus on whether requirements are clear, complete, testable, and sensible. You&#8217;re not testing code yet &#8212; you&#8217;re testing documentation and specifications.</p><p>This objective catches problems when they&#8217;re cheapest to fix. Finding ambiguous requirements during planning costs nothing. Finding them when users complain about confusing features costs everything.</p><h2><strong>Building Confidence in Stability</strong></h2><p>For mature products with established user bases, a major testing objective is confirming that changes haven&#8217;t broken existing functionality. You&#8217;re not expecting to find dramatic new bugs &#8212; you&#8217;re verifying that what worked yesterday still works today.</p><p>This objective drives heavy investment in regression testing and automation. It&#8217;s about risk management and maintaining trust.</p><h2><strong>Exploring Unknown Risks</strong></h2><p>Sometimes testing objectives are explicitly exploratory: we don&#8217;t know what we don&#8217;t know, and we need to discover risks we haven&#8217;t anticipated. This is less about executing test cases and more about learning through interaction.</p><p>This objective requires curiosity, creativity, and tolerance for uncertainty. Success isn&#8217;t measured in bugs found per hour &#8212; it&#8217;s measured in insights gained and hidden risks revealed.</p><h2><strong>Verifying Performance and Scalability</strong></h2><p>When your objective is understanding how the system behaves under load, stress, or resource constraints, your testing approach changes completely. You&#8217;re not looking for functional bugs &#8212; you&#8217;re measuring behavior under specific conditions.</p><p>This objective requires different tools, different expertise, and different success criteria. &#8220;It works&#8221; isn&#8217;t enough. &#8220;It works for 10,000 concurrent users with average response time under 2 seconds&#8221; is the target.</p><h2><strong>Ensuring Security and Compliance</strong></h2><p>Testing with security objectives means thinking like an attacker. You&#8217;re not just checking that features work &#8212; you&#8217;re trying to break security controls, exploit vulnerabilities, and bypass protections.</p><p>Compliance objectives mean verifying that software meets regulatory requirements, industry standards, and legal obligations. The objective is documentation and proof as much as defect detection.</p><h2><strong>Validating User Experience</strong></h2><p>When your objective is ensuring users can successfully accomplish their goals with the software, you&#8217;re testing usability, clarity, and satisfaction &#8212; not just functionality.</p><p>This objective pulls you out of the test lab and puts you in front of real users watching real attempts to use the software. Success means users succeed, not that tests pass.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A2TR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A2TR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!A2TR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!A2TR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!A2TR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A2TR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!A2TR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!A2TR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!A2TR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!A2TR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2878ee-4512-4637-9ec8-1ef8cfa869ec_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>How Objectives Shape Your Entire Testing Approach</strong></h2><p>Your test objectives aren&#8217;t just abstract goals &#8212; they fundamentally change <em>how</em> you test. Let me show you with a concrete example.</p><p>Imagine you&#8217;re testing a new feature: users can export their data to CSV format. Depending on your objective, you test completely differently.</p><p><strong>If your objective is finding defects:</strong> You focus on breaking the export. What happens with empty datasets? What if someone exports while data is being modified? What if the file name contains special characters? What about extremely large datasets? You&#8217;re deliberately trying to make things fail.</p><p><strong>If your objective is release readiness:</strong> You focus on critical scenarios working reliably. Can users successfully export typical datasets? Does the exported data match what&#8217;s in the system? Are error messages clear if something goes wrong? You&#8217;re building confidence in common cases, not hunting edge cases.</p><p><strong>If your objective is validating requirements:</strong> You check whether the implementation matches specifications. Does the CSV format match requirements? Are all specified fields included? Does the feature handle the requirements-defined data limits? You&#8217;re verifying contract fulfillment.</p><p><strong>If your objective is user experience:</strong> You test whether users can figure out how to export without help. Is the export button obvious? Is the process intuitive? Do users understand what they&#8217;re getting? You&#8217;re evaluating usability and clarity.</p><p><strong>If your objective is performance:</strong> You measure how long exports take with various dataset sizes. Can the system handle multiple simultaneous exports? Does export performance degrade under load? You&#8217;re quantifying behavior, not just checking correctness.</p><p><strong>If your objective is security:</strong> You test whether users can export data they shouldn&#8217;t access. Can export be used to bypass access controls? Could exported files contain sensitive data that should be filtered? You&#8217;re thinking about malicious use and unauthorized access.</p><p>Same feature. Six completely different testing approaches. All valid. All useful. But only if you&#8217;re clear about which objective you&#8217;re pursuing when.</p><p>Testing everything six ways is exhaustive testing (which we know is impossible). Understanding your objective lets you test the <em>right</em> way for your current goal.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xz3b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xz3b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xz3b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xz3b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xz3b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xz3b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xz3b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xz3b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xz3b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xz3b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c5c4f52-76a8-4a25-bca2-bc2fe0d698d0_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Conversation You Should Have (But Probably Aren&#8217;t)</strong></h2><p>Here&#8217;s what amazes me: teams spend hours planning sprints, reviewing requirements, and estimating development effort. Then when it comes to testing, someone says &#8220;okay, test it&#8221; and expects the tester to figure out what that means.</p><p>This is backwards. Before you write a single test case, you should have an explicit conversation about test objectives.</p><p><strong>Questions to ask stakeholders:</strong></p><ol><li><p>&#8220;What decisions will this testing inform? Are we deciding whether to release, or confirming features work as expected, or exploring potential risks?&#8221;</p></li><li><p>&#8220;What would make you confident enough to ship? Is it zero high-severity bugs, or successful validation of critical user paths, or specific performance benchmarks?&#8221;</p></li><li><p>&#8220;What are the biggest risks you&#8217;re worried about? Security vulnerabilities, user confusion, performance problems, integration failures, data corruption?&#8221;</p></li><li><p>&#8220;Who are we testing for? Internal QA validation, user acceptance, regulatory compliance, all three?&#8221;</p></li><li><p>&#8220;What does success look like? How will we know when we&#8217;ve tested enough?&#8221;</p></li></ol><p>These conversations surface assumptions, align expectations, and clarify priorities. They prevent the situation where you spend two weeks finding fifty cosmetic bugs while the product manager was losing sleep about a potential security vulnerability you never tested because you didn&#8217;t know it mattered.</p><p><strong>Questions to ask yourself:</strong></p><ol><li><p>&#8220;Why does this specific feature exist? What user problem does it solve?&#8221;</p></li><li><p>&#8220;If I could only test three things about this feature, which three would matter most?&#8221;</p></li><li><p>&#8220;What&#8217;s the worst that could happen if this feature had bugs? Who would be affected and how?&#8221;</p></li><li><p>&#8220;What does the business care most about &#8212; speed to market, zero defects, user satisfaction, competitive feature parity?&#8221;</p></li></ol><p>Your testing should have clear, explicit answers to these questions. If you don&#8217;t, you&#8217;re testing without objectives &#8212; just going through motions hoping to stumble onto something useful.</p><h2><strong>Objectives Change Across the Project Lifecycle</strong></h2><p>Test objectives aren&#8217;t static. They evolve as projects progress through different phases.</p><h2><strong>Early Development: Learning and Validation</strong></h2><p>Early in development, objectives focus on validating direction. Does this technical approach work? Are requirements sensible and testable? Can we build what&#8217;s being specified? Testing is exploratory and hypothesis-testing.</p><p>You&#8217;re not expecting polished features. You&#8217;re checking feasibility, catching misaligned expectations, and providing early feedback when changes are cheap.</p><h2><strong>Active Development: Defect Detection and Quality Guidance</strong></h2><p>Mid-project, objectives shift toward finding defects in actively developed code and guiding developers toward quality. You&#8217;re testing new features as they&#8217;re built, catching bugs while context is fresh, and providing rapid feedback loops.</p><p>You&#8217;re also assessing whether quality is trending up or down. Are bugs decreasing as code stabilizes, or are new features introducing more problems than are being fixed?</p><h2><strong>Pre-Release: Release Readiness and Risk Assessment</strong></h2><p>As release approaches, objectives shift toward release decisions. Testing focuses on critical paths, integration stability, and overall system health. You&#8217;re less focused on finding minor bugs and more focused on assessing major risks.</p><p>Your primary deliverable isn&#8217;t a bug list &#8212; it&#8217;s a recommendation: &#8220;Are we ready to release? What are the known risks? What&#8217;s our confidence level?&#8221;</p><h2><strong>Post-Release: Validation and Learning</strong></h2><p>After release, testing objectives focus on validating the release succeeded and learning from production behavior. Did users encounter issues we missed? How is the software performing under real load? What should we test differently next time?</p><p>Production monitoring becomes a testing activity. User feedback becomes test input. Lessons learned inform future test objectives.</p><p>Trying to use the same testing approach across all these phases misses the point. Objectives change. Testing must adapt accordingly.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CkAb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CkAb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CkAb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CkAb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CkAb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CkAb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!CkAb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CkAb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CkAb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CkAb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94090f3a-2654-436b-bad7-fc8324efeebf_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>When Objectives Conflict (And How to Handle It)</strong></h2><p>Sometimes you face multiple testing objectives that pull in different directions. How do you resolve these tensions?</p><p><strong>Speed versus Thoroughness</strong></p><p>The business wants to release quickly. Quality wants comprehensive testing. These objectives conflict.</p><p>Resolution: Get explicit about risk tolerance. What level of defects is acceptable given the business context? What areas absolutely must be solid versus where minor issues are tolerable? Time-box testing based on agreed priorities.</p><p><strong>Coverage versus Depth</strong></p><p>You could test many features superficially or few features deeply. Both are valid objectives, but you can&#8217;t do both with limited time.</p><p>Resolution: Apply risk-based thinking. Test high-risk features deeply. Test medium-risk features adequately. Test low-risk features lightly. Document your coverage decisions so they&#8217;re conscious choices, not accidental gaps.</p><p><strong>Finding Bugs versus Building Confidence</strong></p><p>Aggressive testing finds more bugs but might undermine stakeholder confidence. Conservative testing builds confidence but might miss issues.</p><p>Resolution: Separate exploratory testing from validation testing. Use exploratory sessions to hunt bugs aggressively. Use scripted tests to demonstrate that critical paths work reliably. Both serve important but different objectives.</p><p><strong>Testing for Now versus Testing for Later</strong></p><p>Do you optimize testing for the current release or build regression suites for future releases? Both require time and effort.</p><p>Resolution: Balance based on product maturity. New products need more current-release testing. Mature products need stronger regression protection. Explicitly allocate time to both.</p><p>The key is making these trade-offs consciously and transparently based on articulated objectives, not just defaulting to whatever you&#8217;ve always done.</p><h2><strong>Measuring Success Against Objectives</strong></h2><p>How do you know if you&#8217;ve achieved your test objectives? You need metrics that align with your stated goals.</p><p><strong>If your objective is finding defects:</strong> Track bugs found, severity distribution, defect detection rate over time. Success means finding significant issues before they impact users.</p><p><strong>If your objective is release readiness:</strong> Track test execution completion, critical path validation, risk assessment confidence. Success means stakeholders have the information they need to make release decisions.</p><p><strong>If your objective is stability:</strong> Track regression test pass rates, production incident rates, mean time between failures. Success means stable, predictable behavior.</p><p><strong>If your objective is user experience:</strong> Track usability test success rates, task completion times, user satisfaction scores. Success means users can accomplish goals efficiently and happily.</p><p>Don&#8217;t use defect counts as your only metric if defect detection isn&#8217;t your primary objective. Don&#8217;t celebrate 100% test execution if execution wasn&#8217;t the point &#8212; learning was. Match your metrics to your objectives.</p><p>And be honest about what metrics can&#8217;t tell you. High test coverage doesn&#8217;t guarantee quality. Low defect counts might mean inadequate testing rather than excellent code. Zero production incidents could mean no one&#8217;s using the product. Numbers need context.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!onIC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!onIC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!onIC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!onIC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!onIC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!onIC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!onIC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!onIC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!onIC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!onIC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81dd9cb6-b647-4a7b-9c00-505c1cc6d49c_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Role of Test Plans and Test Strategies</strong></h2><p>Test plans and strategies should start with objectives, not activities. Yet most test plans I see begin with &#8220;Test Approach&#8221; and &#8220;Test Cases&#8221; without ever articulating <em>why</em> they&#8217;re testing or what they hope to achieve.</p><p>A test strategy informed by clear objectives might say:</p><p>&#8220;Our primary objective is assessing release readiness for the Q3 launch. Given our aggressive timeline and established user base, we will focus 60% of effort on regression testing to maintain stability, 30% on new feature validation to ensure core functionality works, and 10% on exploratory testing to catch unexpected issues. We will not conduct extensive performance testing this cycle since the new features don&#8217;t significantly impact load &#8212; that&#8217;s deferred to Q4. Success means completing critical path validation with zero high-severity bugs in core workflows and a documented risk assessment for known moderate and low-severity issues.&#8221;</p><p>That paragraph tells you everything about what testing will focus on and why. It makes trade-offs explicit. It sets clear success criteria. It aligns testing with business reality.</p><p>Compare that to: &#8220;We will test all features thoroughly using manual and automated testing to ensure quality.&#8221;</p><p>Which one actually guides testing? Which one helps when you&#8217;re forced to cut scope? Which one explains to stakeholders what you&#8217;re doing and why?</p><p>Write your test objectives first. Then let those objectives shape your strategy, your approach, your resource allocation, and your success criteria.</p><h2><strong>AI&#8217;s Blindspot: Understanding Business Context</strong></h2><p>AI can help execute testing once objectives are clear. It can generate test cases, automate execution, analyze results, identify patterns. But AI struggles enormously with understanding business context that shapes objectives.</p><p>AI doesn&#8217;t know whether your company prioritizes speed over perfection or perfection over speed. It doesn&#8217;t understand that your biggest competitor just launched a similar feature, creating business pressure to release quickly. It doesn&#8217;t grasp that a recent security breach has made security testing the top priority. It can&#8217;t sense organizational politics that make certain stakeholders&#8217; concerns more influential than others.</p><p>These contextual factors shape test objectives profoundly. AI can&#8217;t determine them. You must.</p><p>Use AI to accelerate testing once you&#8217;ve defined clear objectives. Let AI generate test variations, execute repetitive tests, analyze large result sets. But don&#8217;t outsource the strategic thinking about <em>why</em> you&#8217;re testing and <em>what</em> matters most. That requires human judgment informed by business context.</p><p><strong>AI excels at: &#8220;Given this test objective, here are 100 test scenarios that support it.&#8221;</strong></p><p><strong>AI fails at: &#8220;Given this business situation, here&#8217;s what your test objective should be.&#8221;</strong></p><p>That second capability &#8212; strategic objective setting &#8212; is irreplaceably human.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qk0O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qk0O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qk0O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qk0O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qk0O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qk0O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg" width="788" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!qk0O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qk0O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qk0O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qk0O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb2444d-08f6-4ad7-8536-2b582040c861_788x440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Objectives for Different Project Types</strong></h2><p>Test objectives vary dramatically based on project context. Let&#8217;s look at how objectives shift across different scenarios.</p><p><strong>Startup MVP:</strong> Primary objective is validating product-market fit quickly. Testing focuses on core value proposition working adequately. Secondary objectives like polish, edge cases, and comprehensive coverage are explicitly deprioritized. Speed and learning matter more than perfection.</p><p><strong>Enterprise System Migration:</strong> Primary objective is ensuring existing functionality continues working. Testing focuses heavily on regression, data migration accuracy, and integration stability. Finding new bugs is less important than verifying nothing breaks during the transition.</p><p><strong>Regulatory Compliance Update:</strong> Primary objective is proving compliance with new regulations. Testing focuses on documenting that requirements are met and creating audit trails. The objective is as much about documentation and proof as finding defects.</p><p><strong>Performance Optimization Release:</strong> Primary objective is validating improvements without regression. Testing focuses on measuring performance metrics and confirming optimization worked while ensuring functionality didn&#8217;t break.</p><p><strong>Security Patch:</strong> Primary objective is confirming vulnerability is fixed without introducing new issues. Testing focuses narrowly on security validation and immediate regression, with broad testing deferred to next release.</p><p>Context shapes objectives. Objectives shape testing. Don&#8217;t use the same testing approach regardless of context.</p><h2><strong>Your Assignment</strong></h2><p><strong>First, articulate your current test objectives explicitly.</strong> Write them down. For your current project or sprint, complete this sentence: &#8220;The primary objective of testing this [feature/release/sprint] is to _____ because _____.&#8221; If you can&#8217;t complete it clearly, you&#8217;re testing without direction.</p><p><strong>Second, evaluate alignment.</strong> Look at what you&#8217;re actually testing and how you&#8217;re spending time. Does your actual testing activity align with your stated objectives? If you say your objective is release readiness but you&#8217;re spending eighty percent of time finding cosmetic bugs, there&#8217;s misalignment.</p><p><strong>Third, have the objectives conversation.</strong> Schedule fifteen minutes with your product manager or key stakeholder. Ask explicitly: &#8220;What are the most important objectives for testing this release? What information do you need from testing to make decisions?&#8221; Compare their answers to your assumptions.</p><p><strong>Fourth, adjust one thing.</strong> Based on clear objectives, change one aspect of your testing approach. Maybe you stop testing a low-priority area and focus more on a high-priority one. Maybe you add a specific type of testing that serves your objective better. Make one objective-driven adjustment.</p><p><strong>Finally, measure differently.</strong> If your current metrics don&#8217;t align with your objectives, define one new metric that does. If your objective is user success but you&#8217;re measuring bug counts, start measuring task completion rates instead.</p><h2><strong>Testing With Purpose</strong></h2><p>Understanding test objectives transforms testing from activity into strategy. It&#8217;s the difference between finding bugs and achieving goals. It&#8217;s the difference between executing test cases and providing valuable information. It&#8217;s the difference between testing because that&#8217;s what testers do and testing because you know exactly what you&#8217;re trying to accomplish.</p><p>Every testing decision &#8212; what to test, how deeply to test it, which techniques to use, when to stop testing &#8212; becomes clearer when you have explicit objectives. You&#8217;re not guessing. You&#8217;re not following templates blindly. You&#8217;re making conscious choices in service of defined goals.</p><p>The most effective testers I know can articulate their testing objectives at any moment. They know why they&#8217;re testing each feature, what information they&#8217;re gathering, what decisions their testing informs. They test with purpose.</p><p>In our next article, we&#8217;ll explore <strong>The SDLC and Where Testing Fits</strong> &#8212; understanding how testing integrates across the entire software development lifecycle. This builds on test objectives because objectives change throughout the SDLC. Knowing where you are in the lifecycle helps you set appropriate testing objectives for that phase.</p><blockquote><p><em><strong>Testing without clear objectives is just going through motions. Define your objectives first. Let objectives drive everything else.</strong></em></p></blockquote>]]></content:encoded></item></channel></rss>