Zarah at Home

Where the pilot stands

Last updated Fri 25 Sep, 12:29

Testing9stories

7The phone rings when the server says, never on its own clock1 check passes in part, 8 not yet tested

1The invitation reaches the nurse and opens the app1 check failed, 5 pass in part, 5 not yet tested

2First open on the phone tells her what happened6 checks pass in part, 2 not yet tested

3A signed-out nurse signs in where she stands when an alarm reaches her2 checks failed, 6 pass in part, 9 not yet tested

5Every nurse on shift owns the task27 checks not yet tested

6The alarm ladder runs on the ruled numbers3 checks pass in part, 4 not yet tested

12The admin corrects a wrong record6 checks failed, 3 pass in part, 4 not yet tested

10The morning summary arrives at 08:009 checks not yet tested

11The nurse closes her shift, and is nagged, never blocked, if she forgets5 checks failed, 3 pass in part, 8 not yet tested

Parked1story
Blocked0stories
Your hand this week0to do
  1. Nothing needs your hand this week.

Status

  • Done · every check passes, no open problems
  • Testing · built, and checks are being run
  • Built · code finished and added to the app, no test run yet
  • Building · design settled, code in progress
  • Not started · no work yet
  • Parked · a known failure whose fix you ruled for a later date
  • Blocked · stopped by something outside the story

What a story can depend on

  • Waits on another story (test evidence) · testing it first would give misleading results
  • Needs the owner's hand · a decision or action only you can take
  • Needs a repair first · something already in the app has to be fixed
Words used on this page 29
  • Alarm ladder · the fixed sequence an unanswered alarm follows: the nurse's phone chimes at set gaps, then the family admins are told.
  • Being judged · a problem the independent check found that still needs a fix or a second look.
  • Channel · a named route the phones get app updates from; a phone only receives updates from its own.
  • Check · one thing the story must do, marked pass or fail. Inside a story: acceptance criteria.
  • CI · the automatic checks that run every time the code changes.
  • Development profile · a special build of the app made only for developers to test with.
  • End-to-end · a test that goes through the whole flow the way a person would, from the first tap to the last screen.
  • Escalation · an alarm nobody answered in time being passed up so that the family admins are told; escalated means it has reached that step.
  • Green · every automatic check has passed.
  • Independent check · someone who did not build the story reads the evidence and marks each check.
  • Inline · shown as part of the normal screen, not as a pop-up or an interruption.
  • Item 0 · a piece of work that is not a numbered story, so it has no list of checks of its own; it is listed first.
  • Live board · the admin website's live page that says who is on shift.
  • Logs · the app's own technical record of what happened, not something a nurse or admin normally sees.
  • Names in a check · made-up example people, not real ones.
  • Pipeline · the automatic steps that check and build the code every time it changes.
  • Record · the saved notes and screenshots from a test run.
  • Retired · a check that a later ruling has taken away; it no longer has to pass.
  • Roster · the list of which nurse is on which shift.
  • Ruled numbers · the delays and counts the owner has decided, such as the gap between chimes.
  • Ruling · a decision the owner has recorded; its number is shown in bold.
  • Server · the part of our system that runs on our own computers, not on a phone: it decides who is rung, when, and who is told.
  • Styled and plain-text email · the morning email carries two versions of itself: a designed one with colours and layout (styled) and a bare-text one with no design (plain-text).
  • Suite · a group of automatic tests that run together.
  • Test run · one line of a story's Test runs table: a try on the phones or on the website, a check of the running system, or an independent person's check of the saved evidence.
  • TestFlight · Apple's service for putting a test version of an app on iPhones.
  • The board · the admin site's live screen for tasks that need attention.
  • The order we work in · stories below are listed in that order.
  • Tier · an alarm's importance level (critical, important or routine); each level has its own timings.

Stories

Listed in the order we work in. Open a story to see what it must do, how each check went, open problems, what it depends on and the decisions behind it.

Item 0 Stale alarm cards clear from the phonesDone 22 Sep Not one of the 23 pilot stories; an earlier fix tracked here. A cancelled alarm now clears from a sleeping phone within minutes; one serious problem found on the way — a phone that had quietly signed the nurse out showed the sign-in page and stayed silent — is parked by the owner until it happens again, and two smaller points were accepted as not met to the letter. Waits onnothing

No checks listed · 7 test runs · no open findings

1Acceptance criteria 0

None. This is a piece of work, not a story, so it has no list of checks of its own; the test runs below show what was tried.

2Test runs 7

DateWhat was testedResultRecord
22 SepThe closing record written after the fourth passClosed on this run; 5 items noted.Record
22 SepFourth test on the Samsung: the alarm was cancelled while the phone was asleep with its screen offThe phone woke, and all three armed alarms were gone within six minutes; nothing rang afterwards.Record
22 SepAn independent check of the fourth passThe clearing check is proven in substance, the count check passes as written, the third was not tried.Record
22 SepThird test on the Samsung: the alarm fired three times and was closed by skipping itEvery check has saved evidence, but none is a clean pass.Record
22 SepSecond test on the SamsungThe test could not start: no signed-in account that could make changes was available in that session.Record
22 SepAn independent check of the first passNo check passed, two were not proven and one failed; a serious sign-in problem was found.Record
22 SepFirst test on the Samsung: a critical alarm was cancelled and the phone watchedAn independent reader found no check passing, two not proven and one failing.Record

3Open findings 0

None.

Noted when closed 5

  • While the test alarm was live, two other test phones dropped scheduled alarms because the app can hold only 64 at a time, and nobody was watching them. (noted 22 Sep)
  • None of the four admins had a phone registered on the test phones, so the alarm's steps for admins reached nobody's phone. (noted 22 Sep)
  • The tester's record says the app never ran during the fourth pass; an independent check found in the phone's own activity record that it woke when the alert arrived and then resumed. (noted 22 Sep)
  • The fourth pass did not read how deeply the phone was asleep, so what a long idle does to it is not known. (noted 22 Sep)
  • The first check asks for a "sent" line in the system's own record of what it sent, but the code writes no such line when it quietly closes a card on a phone, so only a code change could meet the check as written. (noted 22 Sep)

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: docs/qa/stale-alarm-cards-clear-on-bench-phones/, pilot-launch-readiness/item0-capture-4-2026-09-22.md, pilot-launch-readiness/item0-capture-3-2026-09-22.md, pilot-launch-readiness/item0-capture-2-2026-09-22.md, pilot-launch-readiness/item0-capture-2026-09-22.md, docs/qa/pilot-launch-readiness/item0-done-record-2026-09-22.mdCommit: 47087ba2A later record (22 Sep): the closing record accepts this clause on the phone's own record and files a follow-up story for the missing line docs/qa/pilot-launch-readiness/item0-done-record-2026-09-22.md:9

0 The pipeline is green before any story startsDone 23 Sep Every check that still applies passes, and two others are retired. One point outside the checks was noted when it closed. Waits onnothing

All 9 criteria pass · 3 test runs · no open findings

1Acceptance criteria 9

  1. 1The latest run on the story's own copy of the code is green, every automatic check that runs therePass 23 Sep
  2. 2The database-permissions test passes without being loosenedPass 23 Sep
  3. 3The four database suites run, and pass, on the database layout the automatic checks buildPass 23 Sep
  4. 4"Green" is written down as a commandPass 23 Sep
  5. 5there is no development profileRetired
  6. 6The ordinary test build goes onto the test phone from a cable and talks to the test systemPass 23 Sep
  7. 7The same on the Samsung — without wiping what is on itPass 23 Sep
  8. 8The build publishes nothing and adds no channelPass 23 Sep
  9. 9CI runs on every story's own copy of the codePass 23 Sep
  10. 10Every file the automatic scanner flagged leaves the code storePass 23 Sep
  11. 11the trial run ran, failed, and is a record this story citesRetired

2Test runs 3

DateWhat was testedResultRecord
23 SepAn independent check of the evidenceClosed on this run; 1 item noted.Record
22 SepA second person re-read every live check against the running systemRead-only; each check is marked in the record.Record
3 SepAn independent check of the evidence7 pass, 2 pass in partRecord

3Open findings 0

None.

Noted when closed 1

  • When the story was closed, the shared copy of the code was failing one automatic test on the server, so no later story could be shown green while it stayed red. (noted 23 Sep)

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 15

D303 The automatic checks run on every story's own copy of the code, not only on the shared ones.Replaced by a later ruling
D304 The raw Android phone logs that the automatic password-and-key scanner flags (checked: false alarms) are moved out of the code store, keeping only the excerpts the independent checks cite.
D133 Tests use the real database and the real server; only what leaves our system to a third party (email, phone alerts, Apple, Google) is faked.
D134 A fake that cannot answer a question must fail loudly and by name, never return something that looks like an answer.
D217 Whether a ruling is built is answered by running a command against the real code, never by reading a status written down; a ruling with nothing behind it reports as unproven.
D327 No special build made only for developers to test with is added to the phone app.
D168 The screenshot that showed a password is removed from the files but not from the history, and an automatic scanner for passwords and keys is added to catch the next one.
D193 A password or key exposed during testing is not replaced on the spot; all of them are replaced together, once, after the pilot has been tested.
D215 The pilot phones get their app updates from a channel of their own that nothing else publishes to.
D216 The test builds that skip the real sign-in stay as they are for now, but must never be on a channel a pilot phone can read.
D239 The test builds and the pilot builds keep sharing one channel for the pilot; separating them is work for after the pilot.Replaced by a later ruling
D126 “Deploy” with no qualifier always means the test environment.
D263 The cloud database the code store is connected to while developing is never the live one, and a guard refuses any link to a live or unknown one.
D240 The Android test phone is wiped and the app reinstalled properly, accepting that the signed-in session and every permission granted during setup are lost and have to be walked through again.
D165 A piece of work may not claim the delivery-process exemption if it produces a document or file; the gate must refuse the claim, not merely warn.

6Evidence

Record folders: docs/qa/the-pipeline-is-green-before-any-story-starts/, close-2026-09-23.md, e2e-verdict.mdCommit: 580159e0

7 The phone rings when the server says, never on its own clockTesting The latest Android check (25 Sep) found that a killed app restarts and rings when the server says, and that all three Android phones reschedule properly after a pause, closing two earlier problems; the Pixel's earlier blank-screen crash did not happen again this time, so the fix built and installed on the three Android phones is still not proven. On 25 Sep a test-only switch forced the crash on the Pixel: the blank screen is now fixed with the app in front of her, and with the app in front of her the safety net now proves the phone still rings while the app is crashed, and the double ring heard after that crash is gone — on the re-test the same morning the phone rang once; the crash's own cause is still open, and a crash with the phone locked has not been tried. Separately, a locked iPhone rang on all four of the server's pushes, but whether it was truly locked was not independently checked. On the iPhone, locked, every alert rang and showed on the lock screen, witnessed by the owner on 25 Sep. Waits onnothing

Of 11 criteria, 2 pass, 1 passes in part, and 8 are not yet tested · 34 test runs · 13 open findings

1Acceptance criteria 11

  1. 1Every ring on her phone is one the server sentPass 25 Sep the run on the earlier buildNot yet tested the latest build
  2. 2Offline, the phone still rings what it was already given — and nothing moreNot yet tested
  3. 3Back online, the phone follows the server, not its old listNot yet tested
  4. 4The phone never escalates on its ownNot yet tested
  5. 5Opening the app late does not make it ringNot yet tested
  6. 6A snooze re-arms at the server's momentNot yet tested
  7. 7The phone has no numbers of its own to ring onNot yet tested
  8. 8Whose phone rings is the server's callNot yet tested
  9. 9After a locked-phone reboot, what re-arms is the list as last givenNot yet tested
  10. 10One moment, one ring — never twoPass 25 Sep
  11. 11What her phone says at each ring is what has happened — never what the ladder will doPass 25 Sep

2Test runs 34

DateWhat was testedResultRecord
25 SepAn independent check of the evidenceOn the locked iPhone every server alert rang and the alert showed over the lock screen, witnessed by the owner; the screen's words were not captured.Record
25 SepA test run on the phonesTried; judged in the independent check of 25 Sep. On the locked iPhone every server alert rang and the alert showed over the lock screen, witnessed by the owner; the screen's words were not captured.Record
25 SepAn independent check of the evidence2 pass, 1 not yet testedRecord
25 SepA test run on the phonesTried; judged in the independent check of 25 Sep.Record
25 SepAn independent check of the evidenceThe safety net rang on time with the screen crashed; the screen came back; but that alarm sounded twice, so one check fails until the fix is re-tested.Record
25 SepA test run on the phonesTried; judged in the independent check of 25 Sep. The safety net rang on time with the screen crashed; the screen came back; but that alarm sounded twice, so one check fails until the fix is re-tested.Record
25 SepAn independent check of the evidenceThe blank screen is fixed with the app in front of her; ringing after a crash not proven; the crash's cause still open.Record
25 SepA test run on the phonesTried; judged in the independent check of 25 Sep. The blank screen is fixed with the app in front of her; ringing after a crash not proven; the crash's cause still open.Record
25 SepAn independent check of the evidence3 pass, 8 not yet testedRecord
25 SepA test run on the phonesTried; judged in the independent check of 25 Sep.Record
25 SepAn independent check of the evidence3 fail, 8 not yet testedRecord
25 SepA test run on the phonesTried; judged in the independent check of 25 Sep.Record
24 SepAn independent check of the evidence1 pass, 10 not yet testedRecord
24 SepA test run on the phonesTried; judged in the independent check of 24 Sep.Record
24 SepAn independent check of the evidence1 pass, 10 not yet testedRecord
24 SepA test run on the phonesTried; judged in the independent check of 24 Sep.Record
24 SepAn independent check of the evidence11 not yet testedRecord
24 SepA test run on the phonesTried; judged in the independent check of 24 Sep.Record
23 SepA test run on the phonesTried, not yet judged.Record
23 SepA test run on the phonesTried, not yet judged.Record
23 SepA test run on the phonesTried, not yet judged.Record
23 SepAn independent check of the evidence11 not yet testedRecord
23 SepA test run on the phonesTried; judged in the independent check of 23 Sep.Record
23 SepAn independent check of the evidence1 pass in part, 10 not yet testedRecord
23 SepSixth try, after the fix: one nurse, two phones, four ringsRan to the end. One ring per moment on both phones, sound confirmed; what the phone shows was not counted.Record
23 SepAn independent check of the evidence11 not yet testedRecord
23 SepRing run on the iPhone alone, recorded on a microphoneRan through, but there was no usable recording or phone log, so no check could be marked.Record
23 SepRing run on the iPhone alone, first tryStopped before the test began; nothing rang.Record
23 SepAn independent check of the evidence1 fail, 10 not yet testedRecord
23 SepFifth try: one nurse, two phones, four ringsRan to the end. One phone rang twice for one moment, so the one-ring check failed.Record
23 SepFourth try of the ring runStopped before the test began: the same set-up check failed, so nothing rang.Record
23 SepThird try of the ring runStopped before the test began: one set-up check failed, so nothing rang.Record
23 SepSecond try of the ring runStopped before the test began: two set-up checks failed, so nothing rang.Record
23 SepFirst ring run on the Android phones, recorded on a microphoneStopped before the test began: the microphone check failed, so no test alarm was created and nothing rang.Record

3Open findings 13

  1. 1A nurse on the Samsung, rostered to cover the shift, saw her own phone say she was not on shift today while another phone at the same moment correctly showed her on shift; whether this is a real problem or a quirk of this one test account has not been checked. (found 24 Sep)
  2. 2None of the admins had a phone registered to receive alerts during this run, so the escalation's admin step and the point where the family is told were never reached. (found 24 Sep)Being judged
  3. 3Whether a nurse's second phone also stays quiet when the task is closed is not yet ruled; it did not ring at the close in this run. (found 24 Sep)Being judged
  4. 4Outside this story, in story 5: the "Done" notice on another nurse's phone carries the same tag as the alarm card, and closing the task from the phone removed it quickly. (found 24 Sep)Being judged
  5. 5On the OnePlus the alarm notification shows only the app's name, not the task's own words, unlike the Pixel and Samsung. (found 24 Sep)Being judged
  6. 6On the Pixel, the app once crashed to a blank screen as the alarm opened over the locked screen, gave one short ring at the first moment and then stayed silent through every later scheduled and pushed ring until a nurse force-stopped it, with no automatic error report sent; the blank screen and the silence are now fixed and proven, and the crash's own cause is parked by the owner until it happens again on its own. (found 25 Sep)Being judged
  7. 7In this run the OnePlus was meant to be locked but was found sitting unlocked at its own home screen the whole time, so its rings do not prove a locked phone ringing. (found 25 Sep)Being judged
  8. 8In this run the OnePlus's own installed test-build id was never read from the phone itself, only assumed from the other phones. (found 25 Sep)Being judged
  9. 9The script that reads a phone's scheduled alarms only looks for one of the two ways the OnePlus writes them, so its scheduled entries were not checked in this run. (found 25 Sep)Being judged
  10. 10The quiet close that should have reached the OnePlus while it was asleep never reached it before it was force-stopped, so whether an asleep phone receives that quiet close is still unmeasured. (found 25 Sep)Being judged
  11. 11A task created while every phone is asleep reaches the phones only through the server's alert until they next wake; not yet ruled. (found 25 Sep)Being judged
  12. 12On a nurse's second phone, two alarm cards for tasks that are already finished stay in the notification tray and never clear. (found 25 Sep)
  13. 13A locked iPhone's critical alarm ring was measured at close to full loudness regardless of the phone's own volume setting; not yet ruled. (found 24 Sep)Being judged

4Depends on

Waits on: nothing.

Three stories wait on this one:

Story 5Story 6Story 8

5Rulings that apply 6

D046 The server decides when care is due, when to alarm, when to escalate and when to stop.
D100 When the phone cannot reach the server, the app says plainly that recording is paused and asks the nurse to note the time and enter it when she is back online.Partly replaced by D555
D252 A signed-out nurse gets an in-place sign-in on the error screen itself — she keeps her cached day and her local alarm schedule is never torn down to reach a login.
D260 On a PIN-locked phone after a reboot, the alarm that comes back names the patient and the task before anyone unlocks, rather than saying "unlock to see it".
D256 Error copy never promises what the system will do next.
D213 Four places where the app asserts something it does not know are fixed before the pilot, not after.

6Evidence

Record folders: docs/qa/the-phone-rings-when-the-server-says/, run-2-2026-09-25/v6, run-1-2026-09-25/v16, run-1-2026-09-25/v15, run-1-2026-09-25/v14, run-1-2026-09-25/v13, run-1-2026-09-25/v12, run-2-2026-09-24/v5, run-1-2026-09-24/v10, run-1-2026-09-24/v9, run-2-2026-09-23/v4, run-1-2026-09-23/v8, run-1-2026-09-23/v7, run-2-2026-09-23/v3, run-1-2026-09-23/v6, run-2-2026-09-23/v2, run-2-2026-09-23, run-1-2026-09-23/v5, run-1-2026-09-23/v4, run-1-2026-09-23/v3, run-1-2026-09-23/v2, run-1-2026-09-23, judge-run-1-2026-09-23.md, judge-run-1-v10-2026-09-24.md, judge-run-1-v12-2026-09-25.md, judge-run-1-v13-2026-09-25.md, judge-run-1-v14-2026-09-25.md, judge-run-1-v15-2026-09-25.md, judge-run-1-v16-2026-09-25.md, judge-run-1-v6-2026-09-23.md, judge-run-1-v9-2026-09-24.md, judge-run-2-2026-09-23.md, judge-run-2-v3-2026-09-23.md, judge-run-2-v5-2026-09-24.md, judge-run-2-v6-2026-09-25.mdCommit: e8f13628

1 The invitation reaches the nurse and opens the appTesting Dead links and downloads work, but the invitation page names who invited the nurse without saying her role, and the iPhone steps are still to be tried. Waits onnothing

Of 13 criteria, 2 pass, 5 pass in part, 1 fails, and 5 are not yet tested · 4 test runs · 8 open findings

1Acceptance criteria 13

  1. 1The link opens the app on AndroidNot yet tested
  2. 2The link opens the app on iPhoneNot yet tested
  3. 3The link falls back to the web when the app is not thereFail 10 Sep
  4. 4The link the email carries is one the app claimsNot yet tested
  5. 5A dead link says so before she signs inPass 10 Sep Android and the websiteNot yet tested iPhone
  6. 6Every install button goes somewhere realPass 10 Sep AndroidNot yet tested iPhone
  7. 7The Android button downloads our own build from our own site, today and next weekPass 10 Sep the download itselfNot yet tested the rest
  8. 8Where nothing real exists yet, no button pretendsNot yet tested
  9. 9The page never gives an instruction she cannot followPass 10 Sep the states triedNot yet tested the states not tried
  10. 10Each state of the page says what happened and what to doPass 10 Sep three of five statesNot yet tested the loading and could-not-load states
  11. 11Farida fixes a wrong address, and the wrong one is deadPass 10 Sep
  12. 12…and the right address goes out without a fightPass 10 Sep
  13. 13She can find the fix without being toldNot yet tested

2Test runs 4

DateWhat was testedResultRecord
10 SepAn independent check of the evidenceThe story did not pass this check.Record
10 SepAn independent check of the evidenceThe story did not pass this check.Record
10 SepAn independent check of the evidenceThe story did not pass this check.Record
9 SepAn independent check of the evidence1 pass, 6 pass in part, 2 fail, 4 not yet testedRecord

3Open findings 8

  1. 1The already-accepted invitation screen tells the nurse the app will ask for her invite code after she signs in, which may be untrue for a nurse who is already on the team. (found 10 Sep)Being judged
  2. 2A real-looking personal email address appears in committed screenshots of the admins table; whether it is a made-up test identity has not been confirmed. (found 10 Sep)Being judged
  3. 3The page a nurse lands on from an invitation names who invited her but never says her role. (found 10 Sep)Being judged
  4. 4One saved picture of the last website check is filed as showing the page after the answer arrived, but it is identical to the loading picture, so it shows nothing; it needs re-taking or its citation correcting. (found 10 Sep)Being judged
  5. 5After a second, impossible revoke, the family's invitation dialog stays open with its button still live, over a list that has not refreshed. (found 10 Sep)Being judged
  6. 6One line of the story's list of controls names an error message for sending an invite that the app does not have (the message exists only for resending); the list, not the app, needs correcting. (found 10 Sep)Being judged
  7. 7Five of the story's controls still fail their check: three need a real phone or a Google sign-in, one is the invitation page's missing role, and one needs a temporary copy of the system built only for the check. (found 10 Sep)Being judged
  8. 8The recorded demonstration is only done for its first three steps; the steps on real phones are still owed. (found 10 Sep)Being judged

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 7

D188 The invitation email's link opens the app directly when the app is installed, and falls back to the web page when it is not.
D114 There is no short code an admin can read out over the phone.
D299 "Correct the address and resend" means revoking the failed invitation and sending a new one to the right address; the address is not edited in place.
D300 The pilot install route is a TestFlight link that anyone who has it can open on iOS, and a download link to our own signed build on Android.
D301 The invitation's six-digit code is NOT shown on the web fallback page.
D137 An action that cannot succeed is never shown as available, and the screen says what is blocking it, never a save that fails after she commits.
D289 Each phone shows only the sign-in that works on it: the iPhone shows Sign in with Apple and not Google, Android shows Google and not Apple.

6Evidence

Record folders: docs/qa/the-invitation-reaches-the-nurse-and-opens-the-app/, e2e-verdict.mdCommit: 172373a0

2 First open on the phone tells her what happenedTesting Most checks pass, or pass in part, on the Android phones, but the iPhone half has not been tried at all. Waits onnothing

Of 16 criteria, 8 pass, 6 pass in part, and 2 are not yet tested · 3 test runs · 10 open findings

1Acceptance criteria 16

  1. 1The Do Not Disturb step is there, and it takesPass 5 Sep
  2. 2…on the Samsung tooPass 5 Sep Samsung, earlier buildNot yet tested Samsung, latest build
  3. 3She says Not now and is not left guessingPass 5 Sep
  4. 4The phone says it gave the server its addressPass 5 Sep AndroidNot yet tested iPhone
  5. 5When the phone could not register, she is told what happenedPass 5 Sep
  6. 6She fixes it and the line followsPass 4 Sep the earlier buildNot yet tested the latest build
  7. 7The summary never claims more than the phone can doPass 5 Sep AndroidNot yet tested iPhone
  8. 8A phone that changes hands keeps one registration — the new nurse'sNot yet tested
  9. 9Reinstalling on Android does not make the phone a strangerPass 5 Sep
  10. 10Skipping the tour asks firstPass 5 Sep
  11. 11"Show it again" means it comes backPass 5 Sep
  12. 12"Don't show it again" means it stays away, and stays findablePass 5 Sep one phoneNot yet tested across phones
  13. 13Finishing the tour is not leaving itPass 5 Sep
  14. 14Closing the app mid-tour decides nothingPass 5 Sep
  15. 15When trying again cannot help, she knows who to tell — and can call herPass 5 Sep the Alarm health screenNot yet tested the first-run summary
  16. 16Two things wrong, and the headline leads with the one she cannot fixNot yet tested

2Test runs 3

DateWhat was testedResultRecord
5 SepAn independent check of the evidence8 pass, 5 pass in part, 2 not yet testedRecord
4 SepAn independent check of the evidence10 pass, 3 pass in part, 1 fail, 1 not yet testedRecord
3 SepAn independent check of the evidence9 pass, 3 pass in part, 3 not yet testedRecord

3Open findings 10

  1. 1The story's list of controls names no way to force the "refused" state, so a tester cannot reach check 15 without using the admin site's Deactivate and Reactivate buttons, which the list does not mention. (found 5 Sep)Being judged
  2. 2The Check-again button on the Alarm health screen was not tried on a phone after its layout was rebuilt. (found 5 Sep)Being judged
  3. 3The Samsung could not reach the sign-in service and showed the app as signed out; the note puts this in story 3, not in one of this story's checks. (found 5 Sep)Being judged
  4. 4The compact first-run summary for a refused or missing alarm address has never been produced on a phone, in five rounds of checking. (found 5 Sep)Being judged
  5. 5Three of the story's controls still have no record of being tried, and a fourth was written off on a claim the check disproved. (found 5 Sep)Being judged
  6. 6One of the story's checks (number 8) is still unproven, because the tests named to prove it have never been run. (found 5 Sep)Being judged
  7. 7Whether the "Check volume & channel settings" link opens the phone's settings is unsettled, because the test that would settle it was asked for and not run. (found 5 Sep)Being judged
  8. 8The saved pictures from the last phone check include black shots, identical pairs and shots named for screens they do not show. (found 5 Sep)Being judged
  9. 9A real personal email address is among the made-up people loaded into the test system, and shows in screenshots. (found 5 Sep)Being judged
  10. 10Old escalated test tasks on the test system keep ringing real alarms on a fully set-up test phone, so a phone left set up can go off by itself days later. (found 5 Sep)

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 26

D247 The phone itself is identifiable, with an installation identity that survives a reinstall or a data clear and is handed over cleanly when the account on it changes.
D120 The app's guided walkthroughs are per screen, each versioned on its own and remembered against the person rather than the device.
D194 The Android Do Not Disturb deferral is lifted.
D305 When a nurse's phone cannot be registered to receive alarms, the next step the screen offers is to tell the family admin, by name and with a tap-to-call, not "contact support".
D331 When no phone number is on file for the family admin, the screen names the admin and says plainly that no number is on file, with no call button and no substitute route.
D385 On the first-open summary, when a phone has both a permission off AND no alarm address (registration failed), the headline leads with REGISTRATION - no alarm address, tell the admin - and the permission row still shows below with its Fix.
D399 When a permission is off and the phone's alarm address was refused, the registration line leads and the permission row shows below with its Fix, on all three screens that share the summary's copy.
D306 The nurse's Today screen shows NO transient 'checking' banner about alarm registration.
D324 The 'Alarms armed' line on the phone's alarm-health summary claims only what has been proven on a phone.
D325 The phone's no-alarm-address screen says nothing about the app's foreground poll.
D065 The app checks whether the phone can really make a noise (notifications off, Do Not Disturb, a muted alarm setting, critical alerts off), says plainly what is switched off and what it costs, and reports it so the roster can show it.
D137 An action that cannot succeed is never shown as available, and the screen says what is blocking it, never a save that fails after she commits.
D256 Error copy never promises what the system will do next.
D041 The app speaks inline when it is only telling her something, and interrupts only when she is choosing, or when what happens next is not what she would assume.
D052 Critical alarms break through Do Not Disturb on the nurse's phone.
D226 The app carries an installation identity of its own that survives a reinstall or a data clear, so the system can tell one phone from two and can see when an account's alert registration has gone stale.
D128 A phone registration cannot be shared by several accounts — a uniqueness rule is added, and it is applied only after the matching server change is deployed.
D261 Two phones signed in as the same nurse are both allowed and kept in sync: every phone she is signed in on receives the alerts and shows the same state, not only the last one to sign in.
D198 No background health-checking of a nurse's phone.
D118 Admins run the product from a web browser for the first release, but an admin still installs the mobile app — not to administer anything, but to be reachable.
D240 The Android test phone is wiped and the app reinstalled properly, accepting that the signed-in session and every permission granted during setup are lost and have to be walked through again.
D302 For the pilot, an iPhone that has been reinstalled arrives as a new phone, because the server cannot tell it is the same phone.
D289 Each phone shows only the sign-in that works on it: the iPhone shows Sign in with Apple and not Google, Android shows Google and not Apple.
D170 The product is called "Zarah at Home".
D400 Nurses bring their own phones and the app is installed on their personal devices, so one nurse signing in on another nurse's phone is not a case the product designs for.
D393 A refused alarm registration becomes one more state of the alarm-address row on the phone ("another phone holds your address, tell the admin"), with an honest retry.Replaced by a later ruling

6Evidence

Record folders: docs/qa/first-open-on-the-phone-tells-her-what-happened/, e2e-verdict-2.md, e2e-verdict.md, verdict-3.mdCommit: 6b68b3b4A later record (22 Sep): the Samsung was found already signed in and holding its session docs/qa/pilot-launch-readiness/item0-capture-2-2026-09-22.md:26

3 A signed-out nurse signs in where she stands when an alarm reaches herTesting Two checks pass and two fail, and the last check never reached the signed-out ringing screen, so the fixes for the two failing checks were not seen working. Waits onnothing

Of 19 criteria, 2 pass, 6 pass in part, 2 fail, and 9 are not yet tested · 1 test run · 2 open findings

1Acceptance criteria 19

  1. 1The alarm screen tells her before she taps, and the way in is on itFail 5 Sep
  2. 2When the app only finds out at her tap, the same screen appearsNot yet tested
  3. 3She signs in there and finishes what she was doingPass 5 Sep escalated alarmsNot yet tested the paused ringing screen
  4. 4From the lock screen, the alarm comes back and the way in is on itNot yet tested
  5. 5Today says so, and keeps her day on screenPass 5 Sep
  6. 6Nothing on Today pretends it can savePass 5 Sep most of TodayNot yet tested admin Reassign and Retry
  7. 7Every screen that says it offers the way inPass 5 Sep the screens triedNot yet tested the admin's Schedule screen
  8. 8After she signs in, the day is current at oncePass 5 Sep the day refreshing at onceNot yet tested the last-synced time
  9. 9Cancelling or failing the sign-in leaves her where she wasNot yet tested
  10. 10No connection and signed out: the no-connection words winPass 5 Sep the no-connection wordsNot yet tested the ringing screen offline
  11. 11Her alarms never stop for the tripNot yet tested
  12. 12If the app was closed, the sign-in screen says why she is there — however she arrivesPass 5 Sep
  13. 13Choosing Sign out ends this phone onlyNot yet tested
  14. 14A different nurse signs in, and the phone is hersNot yet tested
  15. 15After a closed-app sign-in, the task rings again at its next slot — not beforePass 5 Sep the next ringNot yet tested the rest
  16. 16An alarm already answered by someone else, while she is signed outNot yet tested
  17. 17When the sign-in will not complete, I'm on it still quiets this phoneFail 5 Sep
  18. 18A failure to reach the server never signs her outNot yet tested
  19. 19A change to who she is reaches the phone at its next open — never mid-taskNot yet tested

2Test runs 1

DateWhat was testedResultRecord
5 SepAn independent check of the evidence2 pass, 6 pass in part, 2 fail, 5 not yet testedRecord

3Open findings 2

  1. 1The seven problems found in the first check still stood at the second: none of them was tried again. (found 5 Sep)Being judged
  2. 2The lock-screen notification offers "I'm on it" on a ring that has not escalated, and the tap cannot succeed; the note thinks this is story 5's or story 7's problem. (found 5 Sep)Being judged

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 21

D252 A signed-out nurse gets an in-place sign-in on the error screen itself — she keeps her cached day and her local alarm schedule is never torn down to reach a login.
D328 When a different person signs in on a signed-out phone, the app simply proceeds — the phone becomes hers, the previous nurse's cached day is replaced by hers at once, and nothing refuses or warns.
D329 After a nurse signs back in from a closed app, the alarm she tapped is not re-rung on that phone at once; the task shows as still due on Today and rings again at its next scheduled slot if still undone.
D332 On a signed-out phone the ringing alarm screen always offers 'I'm on it', and it works even when the sign-in cannot complete: it quiets this phone alone for the tier's snooze length and sends nothing to the server, so the item stays open and rings again on schedule.
D353 Only a real revoke signs anyone out.
D341 The phone app reads the phone's real network connection, so the offline words the product requires reflect whether the phone is truly offline, not a request that happened to fail.
D418 The cold sign-out marker is written on EVERY path by which the app arrives at a signed-out state, not only the one the nurse happened to take, so the screen that tells her she was signed out says the same thing however she got there.
D419 When she is signed out AND offline AND an alarm is ringing, the sign-in control is absent because it cannot work without a connection, the words on screen say that is why, and 'I'm on it' stays available so she can still quiet the phone at the bedside.
D440 Sign-out on one phone releases THAT phone's registration and THAT phone's session only; her other signed-in phone stays signed in and keeps ringing.
D352 For the pilot it is acceptable that a removed or signed-out nurse's phone keeps ringing for up to about 41 minutes (sometimes longer) until the server's revoke reaches it; stories 3 and 4 close on that basis.
D249 The signed-out screen gets its own words.
D289 Each phone shows only the sign-in that works on it: the iPhone shows Sign in with Apple and not Google, Android shows Google and not Apple.
D446 Until Google sign-in is built into the app itself, the browser Google sign-in always asks which Google account to use: one extra tap on every browser sign-in, never silently the wrong person.
D137 An action that cannot succeed is never shown as available, and the screen says what is blocking it, never a save that fails after she commits.
D408 The testing roles never sign in themselves (no typed password, no account picker, no consent screen, no one-time code); another role prepares the signed-in state for them.Partly replaced by D432 D485
D432 Agents never sign in, on any story: every end-to-end sign-in uses real Google and Apple accounts and the owner performs it himself.Replaced by a later ruling
D447 The owner's test-phone window is a fixed daily hour, 14:00–15:00 Eastern time, extendable to a second hour when asked by 09:00 that day.Partly replaced by D480 D483
D448 The six password-only test nurse accounts on the test system are deactivated, never deleted, and the test data points at the real Google and Apple nurse accounts.Partly replaced by D531
D213 Four places where the app asserts something it does not know are fixed before the pilot, not after.
D256 Error copy never promises what the system will do next.
D100 When the phone cannot reach the server, the app says plainly that recording is paused and asks the nurse to note the time and enter it when she is back online.Partly replaced by D555

6Evidence

Record folders: docs/qa/a-signed-out-nurse-signs-in-where-she-stands/, verdict-2.mdCommit: 4afb9ffd

4 The opening screen follows the phone's light or dark settingParked until after the pilot month On the two Android phones the dark opening screen looks right, but on the light one the clock and battery marks at the top of the screen show white on a light background for a moment at the start on the Samsung and at the end on both phones, so the check that they stay readable fails; the iPhone has not been tried at all. On 22 Sep the owner ruled that a failed run would park the fix until after the pilot month. Waits onnothing

Of 8 criteria, 7 pass in part, and 1 fails · 3 test runs · 5 open findings

1Acceptance criteria 8

  1. 1A dark-set phone opens on the warm-dark facePass 23 Sep the Pixel and the SamsungNot yet tested the iPhone
  2. 2A light-set phone opens on the light facePass 23 Sep the two Android phonesNot yet tested the iPhone
  3. 3Changing the setting changes the face — with no reinstall and no sign-outPass 23 Sep changing the setting by hand, and Battery Saver on the PixelNot yet tested the phone's schedule and the iPhone
  4. 4The clock and battery are readable on both facesFail 23 Sep
  5. 5The change from the opening screen to the next one stays clean on both facesPass 23 Sep the change from the opening screen to TodayNot yet tested the sign-in and first-time screens, and the iPhone
  6. 6The app's own screens did not changePass 23 Sep the seven screens reachedNot yet tested the seven screens not reached
  7. 7The phone's keyboard and dialogs inside the app follow the phonePass 23 Sep the standard and number keyboardsNot yet tested every dialog, the other keyboards and the iPhone
  8. 8Both faces are declared, so a rebuild can never lose onePass 5 Sep the runs on earlier buildsNot yet tested the latest build

2Test runs 3

DateWhat was testedResultRecord
23 SepAn independent check of the evidence6 pass in part, 1 fail, 1 not yet testedNot filed here yet
5 SepAn independent check of the evidence1 pass, 4 pass in part, 1 fail, 2 not yet testedNot filed here yet
4 SepAn independent check of the evidence1 pass, 5 pass in part, 1 fail, 1 not yet testedNot filed here yet

3Open findings 5

  1. 1On the light opening screen the clock and battery marks at the top of the screen are white on a light background for about a tenth of a second at the start on the Samsung and at the end on both phones, which fails the check that they stay readable as it is written; the owner's ruling parks that fix until after the pilot month, and whether it also covers the end-of-screen frames on both phones is not ruled. (found 23 Sep)Fix ruled for after the pilot month
  2. 2The tester wrote that no loading spinner shows during the change from the opening screen to Today, but the saved pictures show the app's own loading spinner through the fade. (found 23 Sep)Being judged
  3. 3Two of the run's saved pictures are the same file under two names, which the tester's own instructions forbid; the screen honestly looks the same in both. (found 23 Sep)Being judged
  4. 4The phone's own text-selection pop-up is not named in the story's list of controls, which names only the iPhone's; it follows the phone's setting correctly. (found 23 Sep)Being judged
  5. 5The Samsung used in the run was signed in as a personal account instead of the made-up test admin, which is also why the admin's Schedule screen could not be reached. (found 23 Sep)Being judged

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 5

D170 The opening screen follows the phone's light or dark setting rather than always showing the app's warm-dark face.
D330 Inside the app the phone's own keyboard and system dialogs follow the phone's light or dark setting; the app's own screens stay exactly as they are.
D370 On the Samsung (the family admin's phone), the one-frame light status-bar flash on the cream opening screen at a cold launch in light mode is accepted as the phone maker's own quirk - no further work.
D132 The assistant never invents how anything looks.
D479 The opening screen following the phone's light or dark setting gets exactly one more test run on the current build; if it passes the story closes, and if it fails again the fix waits until after the pilot month.

6Evidence

Record folders: docs/qa/the-opening-screen-follows-the-phone-setting/, verdict-4.md, e2e-verdict-2.md, verdict-3.mdCommit: 7c9c48b5

5 Every nurse on shift owns the taskTesting In the latest of the three phone checks listed below the task appeared on the Today card, but the ringing screen was not tried. Waits onStory 7

Of 27 criteria, 27 are not yet tested · 3 test runs · no open findings

1Acceptance criteria 27

  1. 1Farida puts two nurses on one shift, as equalsNot yet tested
  2. 2The same on her phoneNot yet tested
  3. 3One nurse cannot be in two placesNot yet tested
  4. 4A shift with nobody on it is shown, not judgedNot yet tested
  5. 5Amina's Today says she is on, and every task in the window is hersNot yet tested
  6. 6Her roster tab counts tonight as hersNot yet tested
  7. 7The Live board says who is on — all of themNot yet tested
  8. 8Both phones ring, at the same moment, with the same alarmNot yet tested
  9. 9The first to record it takes it, in her nameNot yet tested
  10. 10"I'm on it" quiets the whole shift, and says who has itNot yet tested
  11. 11…and comes back carrying her name if she does not finishNot yet tested
  12. 12When the admins are told, nobody drops offNot yet tested
  13. 21After the admins are told, "I'm on it" quiets her own phone onlyNot yet tested
  14. 27Farida, on the shift herself, keeps the nurse's screen after the family is toldNot yet tested
  15. 13The set is frozen at the due instantNot yet tested
  16. 14The extra time is unchanged: thirty minutes after her shift ends, a dose that came due in that window is still hers to recordNot yet tested
  17. 15Hers until the escalation diesNot yet tested
  18. 16Nobody on the shift at all reaches every admin at onceNot yet tested
  19. 17Two nurses record the same dose: the second is told the truthNot yet tested
  20. 18One rule for who may act, on both sidesNot yet tested
  21. 19No task can be assigned to a named nurse anywhereNot yet tested
  22. 20The nurse who cannot come leaves the set; the rest stay onNot yet tested
  23. 22A shift any of its nurses worked cannot be deletedNot yet tested
  24. 23Each phone rings in the sound its nurse choseNot yet tested
  25. 24Before Farida lets Joyce go, the site tells her what it will costNot yet tested
  26. 25On confirm she comes off every shift that has not started, and only thatNot yet tested
  27. 26Bringing her back restores her account, not her shiftsNot yet tested

2Test runs 3

DateWhat was testedResultRecord
17 SepOne nurse's task shown on the other nurse's Today cardThe task appeared on the Today card; the ringing screen was not tried.Record
16 SepWatching one nurse's "I'm on it" reach the other phones, 16 SepFor more than a minute after the Samsung nurse's tap, the iPhone's ringing screen still said nobody had taken the task, though the server had it quiet all along.Record
15 SepTimed alarms on the two nurses' phones and the Samsung, 15 SepThe chimes fired in the same second on both nurses' phones; on the Samsung the phone's own quiet-down feature muted the sound and the screen stayed asleep.Record

3Open findings 0

None.

4Depends on

Waits on:

Story 7

One story waits on this one:

Story 17

5Rulings that apply 32

D073 No task is ever assigned to a named nurse, and there is no backup-nurse designation.
D058 When care is due, every nurse on the shift is rung.
D296 A shift is simply the set of nurses on it, with no primary and no backup: a task belongs to everyone who is on shift at the moment it comes due.
D307 "I'm on it" is a snooze: it quiets every nurse on the shift for the importance level's snooze length, counts once against the number of snoozes allowed, and if it lapses without completion the task rings every nurse again carrying the name of the one who said she was on it.
D323 A nurse may quiet an escalated ring on her own phone with 'I'm on it' exactly as she quiets an unescalated one; her tap quiets her phone only and retracts nothing from the admins' phones, who see the item still open on their board until it is recorded.
D326 After the admins have been told, a nurse's "I'm on it" still spends one of her snoozes, and once they are spent her phone keeps ringing until the item is recorded.
D335 The moment a nurse's quiet becomes her own phone only is the moment the admins are told (the admin rung), not the earlier nurses-only escalated ring the code has today; until then her quiet works as it always did for the shift.
D308 Under the set-of-nurses model, when one nurse on a shift reports she cannot come, SHE leaves the set and the others stay on; the shift becomes a coverage gap for the admins only when nobody remains.
D342 When a task pages every nurse on a shift, each nurse's alert uses her own chosen alarm sound, and a shift cannot be deleted while any nurse who was on it has recorded activity against it.
D357 When an admin deactivates a nurse, the site first names her upcoming shifts and which of them would be left with no other nurse; on confirm she comes off every future shift, her past shifts stay as history, and the freed shifts show as open.
D354 Undo on the admin site restores exactly what was there before the removal - a nurse who had reported herself off that shift comes back as off, a live nurse comes back live.
D376 Undo of a deleted shift restores it as it was.
D383 Undo of a deleted shift restores everything the delete removed - the shift, who had left, AND the cleared can't-come report with its cleared-by and cleared-when - so the record reads as if the mistake never happened.
D368 The server accepts a nurse's "reported off" mark from the admin site when a deleted shift is restored, exactly as the undo sends it, without checking it against what the deleted shift had.
D377 When a person who is both admin and on the shift has received the nurse's alert and then the admin's for the same task, her ringing screen stays the NURSE's screen - 'Yours to complete', Complete, I'm on it - with one added line that the admins have been told.
D361 When the server cannot read the roster while building a phone's alarm plan, the per-task ownership answer is UNKNOWN (never a false 'not yours'); the phone keeps the last answer it had for that task and rechecks on the next plan.
D277 She is working that shift: her own roster shows it, she is told she is on, and her phone rings for it.Replaced by a later ruling
D221 The system refuses to put one nurse on two shifts that overlap in time, and the guarantee lives in the database rather than in a check in the app.
D207 When a nurse may not complete something, the app does not offer her the button.
D234 A task belongs to the nurse whose shift covered the moment it came due — it is hers if it buzzed her — and it stays hers until the escalation dies.
D253 The server tells the phone when a snooze or action lands on a task that is already completed or skipped, so the phone can tell her the truth instead of saying "Snoozed".
D261 Two phones signed in as the same nurse are both allowed and kept in sync: every phone she is signed in on receives the alerts and shows the same state, not only the last one to sign in.
D059 When nobody is on the shift roster at that time for a due task, every admin is alerted at the same moment, and when one of them responds the alert clears on every admin's phone.Partly replaced by D310
D310 A routine item due on a shift with nobody on the shift roster at that time pages nobody, and shows in the morning summary as not done.
D057 Escalation adds the admins.
D200 The roster's coverage bar and its gap, covered and overlap key stay, but the app no longer passes judgement on a gap: the picture informs and the admin decides.
D244 Snoozing an alarm for a task somebody has already completed tells her it is already done, instead of snoozing it.
D046 The server decides when care is due, when to alarm, when to escalate and when to stop.
D274 A person who is both the family admin and on the roster is alerted as a nurse first and then as the admin, and the app does not detect that they are the same person in order to suppress the second alert.
D219 A person who is both an admin and on the roster gets exactly one buzz at any moment, and which hat it wears depends on the stage.Partly replaced by D274 D377
D211 A person who is both an admin and on the roster gets ONE alert, not two.Replaced by a later ruling
D298 The change to who an alarm rings is written, reviewed and committed at night, then left unproven until a test on real phones with the owner awake.

6Evidence

Record folders: docs/qa/a-task-belongs-to-every-nurse-on-shift/Commit: 2903b579

6 The alarm ladder runs on the ruled numbersTesting In the second phone run the first three checks passed on the server at a one-minute test pace, but one whole chime was skipped, the snooze check was not run and the real ten-minute pace was not watched on a phone. Waits onStory 7

Of 8 criteria, 1 passes, 3 pass in part, and 4 are not yet tested · 2 test runs · 11 open findings

1Acceptance criteria 8

  1. 1Three chimes, ten minutes apartPass 5 Sep the one-minute test paceNot yet tested the real ten minutes
  2. 2Then the admins are told, at about thirty minutes — important and critical onlyPass 5 Sep the server sending itNot yet tested the admin's phone, and the real thirty minutes
  3. 3The admins joining takes nobody offPass 5 Sep
  4. 4Her chimes never slow, however long it goes onNot yet tested
  5. 5The numbers are read from the database, not from codePass 5 Sep the most urgent levelNot yet tested the next level down
  6. 6There is one home for each numberNot yet tested
  7. 7Her snooze re-arms in ten minutes and is one of her threeNot yet tested
  8. 8Missing numbers are loud at deploy time, never silent at three in the morningNot yet tested

2Test runs 2

DateWhat was testedResultRecord
5 SepAn independent check of the evidence1 pass, 3 pass in part, 4 not yet testedNot filed here yet
4 SepAn independent check of the evidence3 pass in part, 5 not yet testedNot filed here yet

3Open findings 11

  1. 1Serious: the nurse's phone says the family has been alerted at her second and third chime, before the family is told at the thirty-minute mark; the change to the phone belongs to stories 5 and 7. (found 5 Sep)Being judged
  2. 2Fairly serious: after the first chime the ringing screen stops offering the nurse a snooze, so the three snoozes the story stores can be reached at most once from the ring; not yet ruled. (found 5 Sep)Being judged
  3. 3The Pixel had Do Not Disturb on for the whole run, so whether a nurse would have heard anything is not proven. (found 5 Sep)Being judged
  4. 4The nurse whose phone rang was not on any shift, so the check about every nurse on shift has never been exercised. (found 5 Sep)Being judged
  5. 5A silent reminder shows on the lock screen eleven minutes before the due time; it is not in the story's list of things to expect. (found 5 Sep)Being judged
  6. 6Three saved pictures claim a screen they do not show, and two are byte for byte the same. (found 5 Sep)Being judged
  7. 7A saved screenshot of the admin's own phone that shows a real person's personal reminders was committed; it is gone from the story's own copy of the code but remains in an older saved copy, and what to do about that history has not been decided. (found 5 Sep)Being judged
  8. 8The ruling behind the alarm numbers assumed that the moment a task reads "escalated" and the moment the family is told are the same; on the running build they are not: a task reads "escalated" one chime gap after it is due, but the family is told only after the last chime, so for that stretch it reads escalated with the family not yet told, and the owner has not settled which one changes. (found 5 Sep)Being judged
  9. 9The story's setup does not say the admin's Samsung must have Do Not Disturb off, so it was on and the check of the admin's phone could not be made; the setup needs that line. (found 5 Sep)Being judged
  10. 10The admin website was set up but never opened during the checks, so what an admin sees while a task reads "escalated" and she has not yet been told has never been observed. (found 5 Sep)Being judged
  11. 11The story's own file still says it is filed at the planning step, although the check found it already built and tried twice on the phones. (found 5 Sep)Being judged

4Depends on

Waits on:

Story 7

Stories that wait on this one: none.

5Rulings that apply 6

D047 A due task chimes every 10 minutes, three times, and then the admins are told — roughly 30 minutes from due to an admin abroad knowing.
D057 Escalation adds the admins.
D292 The alarm numbers for each importance level live in the database from the start, not fixed in the code.
D322 When the alarm numbers for each importance level cannot be read from the database, the server refuses to start and reports itself unhealthy, so the fault is loud when the code is put on the test system, never silent at 3am.
D048 The full ladder: a nurse's snooze re-arms in 10 minutes and uses up one of her three; after the admins are told the nurses' phones keep chiming on the same 10 minutes; any admin may snooze and is rung again on the same 10.
D326 After the admins have been told, a nurse's "I'm on it" still spends one of her snoozes, and once they are spent her phone keeps ringing until the item is recorded.

6Evidence

Record folders: docs/qa/the-alarm-ladder-runs-on-the-ruled-numbers/, e2e-verdict.md, verdict-2.mdCommit: 65720df1

8 A routine item never reaches an adminBuilt Built; the newest read-through of the code by someone other than its builder, on 4 Sep, found no problem; no independent check of the evidence is on file. Waits onStory 7

Of 8 criteria, 8 are not yet tested · no test runs yet · no open findings

1Acceptance criteria 8

  1. 1A routine item chimes her gently, then goes quietNot yet tested
  2. 2…and never reaches an adminNot yet tested
  3. 3No email eitherNot yet tested
  4. 4Nobody can switch it onNot yet tested
  5. 5An escalation that reaches an admin plays one soundNot yet tested
  6. 6…and it is not the nurse's soundNot yet tested
  7. 7A critical escalation still wakes her — in the escalation soundNot yet tested
  8. 8The admin who is also a nurse hears two soundsNot yet tested

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on:

Story 7

Stories that wait on this one: none.

5Rulings that apply 20

D064 Alarm behaviour is configured per tier — routine, important, critical — from the admin dashboard, and never per care item.
D037 Three importance levels stay.
D049 A routine item never escalates to a person — that is fixed and cannot be configured on.
D309 After a routine item's last chime it goes quiet.
D310 A routine item due on a shift with nobody on the shift roster at that time pages nobody, and shows in the morning summary as not done.
D235 An escalation reaching an admin plays ONE uniform escalation sound — the same on every phone, distinct from the nurse's alarm sound, attention-getting without being irritating.
D311 The uniform escalation sound is one of the sounds already bundled and cleared, not a new asset, and it stays in the nurse's picker.
D312 A critical item escalating to an admin plays the uniform escalation sound delivered in the critical form that pierces a silenced phone.
D051 A critical item wakes an admin exactly as it wakes a nurse.
D052 Critical alarms break through Do Not Disturb on the nurse's phone.
D054 A critical chime breaks through silent mode even when the phone is offline.
D274 A person who is both the family admin and on the roster is alerted as a nurse first and then as the admin, and the app does not detect that they are the same person in order to suppress the second alert.
D220 The alarm's phone setting gets a new identity whenever its importance, sound, vibration or Do Not Disturb behaviour changes, so an old one can never be used and the nurse sees exactly one care-alarm entry in her phone's settings.
D259 The sound chosen for the critical alarm is cleared for distribution.
D295 Admins can snooze, and the number of snoozes allowed is capped per importance level.
D046 The server decides when care is due, when to alarm, when to escalate and when to stop.
D047 A due task chimes every 10 minutes, three times, and then the admins are told — roughly 30 minutes from due to an admin abroad knowing.
D048 The full ladder: a nurse's snooze re-arms in 10 minutes and uses up one of her three; after the admins are told the nurses' phones keep chiming on the same 10 minutes; any admin may snooze and is rung again on the same 10.
D057 Escalation adds the admins.
D059 When nobody is on the shift roster at that time for a due task, every admin is alerted at the same moment, and when one of them responds the alert clears on every admin's phone.Partly replaced by D310

6Evidence

Record folders: docs/qa/a-routine-item-never-reaches-an-admin/Commit: 3288ba79

9 An admin snoozes or skips only what has escalatedBuilt Built; the newest read-through of the code by someone other than its builder, on 8 Sep, found no problem, and code changed after it has not been read through again; no independent check of the evidence is on file. Setting up a test on the phones ran into blockers. Waits onnothing

Of 13 criteria, 13 are not yet tested · no test runs yet · no open findings

1Acceptance criteria 13

  1. 1The alert reaches her with her two answers on itNot yet tested
  2. 2Snooze quiets every phone now — hers, the other admins', and the nurses'Not yet tested
  3. 3…and ten minutes later everyone is rung againNot yet tested
  4. 4Her snoozes are counted, and the alert says where she standsNot yet tested
  5. 5After the last attempt the alarms stop, and every admin is emailed onceNot yet tested
  6. 6What has not reached her is not hers to skip, and no screen here offers her anything on itNot yet tested
  7. 7She skips what has escalated — including a critical item — and the record says it was hersNot yet tested
  8. 8When one admin answers, the other admins' phones clear on their ownNot yet tested
  9. 9The nurse's own answers are what story 5 made them, and nothing here moved themNot yet tested
  10. 10Her old "I'm on it" is gone — Snooze is her one quiet answer, and it countsNot yet tested
  11. 11Her alert offers her no CompleteNot yet tested
  12. 12While one admin's snooze is live, the other may still skipNot yet tested
  13. 13The board's escalated queue holds what is open and escalated, and counts itNot yet tested

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 27

D275 Until the application stabilises, every ESCALATED item is snoozable and skippable by an admin.
D048 The full ladder: a nurse's snooze re-arms in 10 minutes and uses up one of her three; after the admins are told the nurses' phones keep chiming on the same 10 minutes; any admin may snooze and is rung again on the same 10.
D060 A nurse may snooze a task only if she is on the roster and her shift covers the task's due time.
D290 An admin's snooze silences the nurse's chime instead of only slowing it: a person may silence what the software may not.
D295 Admins can snooze, and the number of snoozes allowed is capped per importance level.
D059 When nobody is on the shift roster at that time for a due task, every admin is alerted at the same moment, and when one of them responds the alert clears on every admin's phone.Partly replaced by D310
D088 Skip belongs to the nurse, at the bedside, in the moment.Partly replaced by D275
D340 (1) an admin may skip an escalated item while another admin's snooze is live — a snoozed item is still escalated and a skip is a record, not a ring; (2) once the ladder has given up on an item, Skip survives and Snooze is gone — there is nothing left to quiet.
D379 The give-up email's 'on shift at the time' line names everyone the roster carried at that instant, including a deactivated nurse whose shift was never swapped, marked 'not rung - deactivated'.
D387 The alert leaves a deactivated nurse out, while the give-up email, the record of what went wrong, names the roster with her marked; both rulings stand, each in its own place.
D388 In the give-up email, when the roster could not be read at the moment the email is built, the on-shift line reads 'On-shift at the time: could not be read.' - never 'no one on the shift roster at that time'.
D389 In the give-up email, a nurse who was on the roster but not rung because her phone had no alert address is named and marked "not rung - no phone registered".
D394 The give-up email protects every name and task it prints, so a name with an angle bracket in it shows exactly as typed (today it is built by plain text substitution with no such protection).
D371 On the admin site, when two nurses are named together both names are written in full, and three or more show the first two and "and 1 more".
D064 Alarm behaviour is configured per tier — routine, important, critical — from the admin dashboard, and never per care item.
D292 The alarm numbers for each importance level live in the database from the start, not fixed in the code.
D166 The care author marks each care item skippable or not, and a skip always carries the item's mark as it stood at the moment it was skipped, so judgement calls and incidents stay distinguishable in the record forever.
D036 A critical item cannot be skipped.
D209 An item marked as one that must not be skipped offers the nurse no Skip control at all.
D137 An action that cannot succeed is never shown as available, and the screen says what is blocking it, never a save that fails after she commits.
D041 The app speaks inline when it is only telling her something, and interrupts only when she is choosing, or when what happens next is not what she would assume.
D201 A task the alarm ladder has given up on stays in the nurse's history, greyed out and not actionable.
D253 The server tells the phone when a snooze or action lands on a task that is already completed or skipped, so the phone can tell her the truth instead of saying "Snoozed".
D307 "I'm on it" is a snooze: it quiets every nurse on the shift for the importance level's snooze length, counts once against the number of snoozes allowed, and if it lapses without completion the task rings every nurse again carrying the name of the one who said she was on it.
D207 When a nurse may not complete something, the app does not offer her the button.
D262 When the admin step of the escalation first finds an active admin unreachable, she gets one email for that event, not none and not a stream of them.
D046 The server decides when care is due, when to alarm, when to escalate and when to stop.

6Evidence

Record folders: docs/qa/an-admin-snoozes-or-skips-only-what-has-escalated/Commit: 6d28fb48

12 The admin corrects a wrong recordTesting The last web check found that the care-entries page could name one day and show another, that an entry could show old wording right after a save, and that a reported row does not name the admin who reported it; of 15 criteria, 2 pass, 3 pass in part, 6 fail, and 4 are not yet tested. Waits onnothing

Of 15 criteria, 2 pass, 3 pass in part, 6 fail, and 4 are not yet tested · 3 test runs · 14 open findings

1Acceptance criteria 15

  1. 1She finds Tuesday's entry without a search boxFail 17 Sep
  2. 2A wrong reading becomes right, and she is told which one the doctor's charts useFail 17 Sep
  3. 3A wrong time or note on a task is fixed the same wayFail 17 Sep
  4. 4"This entry should not stand" voids it, and the task stays closedPass 17 Sep
  5. 5After a void, the screen points at what she probably needs nextNot yet tested
  6. 6Care that happened but was never written down is recorded as someone's wordFail 17 Sep
  7. 7The wrong person is named: the care stays done, the name changesPass 17 Sep
  8. 8A wrong correction is fixed by another on top, and the earlier turns stay readableFail 17 Sep
  9. 9The door offers only what the server will take, and says why when it will notNot yet tested
  10. 10The same door from today's boardNot yet tested
  11. 11Nothing is lost when a save fails, and nothing is composed offlinePass 17 Sep the checks triedNot yet tested a double-tap on Save
  12. 12Someone else corrected it while she was writingPass 17 Sep the conflict stateNot yet tested its resolution
  13. 13She could not have edited the original if she triedNot yet tested
  14. 14The doctor's charts read the corrected recordPass 17 Sep the part checkedNot yet tested the rest
  15. 15A nurse's note — a care note, or the words of her shift close — is corrected the same wayFail 17 Sep

2Test runs 3

DateWhat was testedResultRecord
17 SepAn independent check of the evidence2 pass, 3 pass in part, 6 fail, 4 not yet testedRecord
16 SepAn independent check of the evidence1 pass, 6 fail, 8 not yet testedRecord
16 SepA test run on the websiteTried; judged in the independent check of 16 Sep. The story did not pass this check.Record

3Open findings 14

  1. 1An entry for a task that was skipped prints the database's lowercase word "skipped", where the day's list says "Skipped". (found 17 Sep)Being judged
  2. 2The line a tidy-up script writes on an old test item ("sanitised by …") is shown to the admin under the entry as if a nurse had written it as a care note; the note proposes a story for it. (found 17 Sep)
  3. 3At the largest text size with bold text, the attention banner at the top of the admin site loses its sentence and shows only a warning sign, "Review" and a close mark; the note says it is not this story's screen and proposes a story for it. (found 17 Sep)
  4. 4When saving a correction fails, the block that says so offers Retry and a close mark but no Back, so she cannot go back and edit, although the design names a Back. (found 17 Sep)Being judged
  5. 5While the admin is offline, the "Fix what was recorded" button looks normal, with the warning block beneath it, where the design says the button is disabled. (found 17 Sep)Being judged
  6. 6The care-entries page's care day and an entry's care day can disagree, so the date field can default a day out, the refusal for a change across days cannot fire, and a time correction can silently move the record to another day. (found 17 Sep)Being judged
  7. 7An entry can show a state it does not yet know: the old row and old history right after a save, and "no history" on a fresh load. (found 17 Sep)Being judged
  8. 8A voided note's entry loses its why, its author and its whole history. (found 17 Sep)Being judged
  9. 9The line that offers an entry's earlier versions appears even when the entry has no corrections. (found 17 Sep)Being judged
  10. 10The line saying the doctor's figures are built from the corrected value is missing on every number reading. (found 17 Sep)Being judged
  11. 11A reported row does not say which admin reported it; that needs a new field on the server. (found 17 Sep)Being judged
  12. 12The day picker does not mark a day that has a correction, although its key is shown. (found 17 Sep)Being judged
  13. 13When a day truly has no entries, the page lacks its two taps to the nearest day that has entries. (found 17 Sep)Being judged
  14. 14The last web check's own records are flawed: 13 of the 53 lines in its results list are unreadable, its files were left on one computer and never filed with the rest of the code, and every screenshot shows only the part of the page that fits on screen. (found 17 Sep)Being judged

4Depends on

Waits on: nothing.

Two stories wait on this one:

Story 10Story 11

5Rulings that apply 21

D241 Mark incomplete comes off the nurse's phone now, without waiting for its replacement.
D268 The pilot's admin correction screen covers both halves of the care record, not one: a care task wrongly marked complete or skipped, AND a wrongly-entered observation (a blood pressure typed as 120 instead of 210).
D231 Care cannot be provided in the past; only the record can be made straight.
D096 An admin may record care as reported by someone else, naming who said so.
D270 An admin can correct who gave the care.
D267 When an admin corrects a wrongly-recorded care entry or observation, the statistics a doctor later reads — analytics, trends, whatever the doctor is shown — are built from the CORRECTED value, not the original.
D336 (1) a voided entry is left out of every statistic and chart, and a reported entry counts as given at the time reported — the corrected record is what the doctor sees; (2) the time on a reported entry may be left unknown, the giver may not.
D337 Voiding removes the ENTRY, not the task.
D350 The admin reaches the Record (story 12, correcting a wrong entry) BOTH ways - a Record item in the site's left menu for browsing the days, and the drawer on the Live board for the task in front of her.
D374 The admin owns the patient's care and the buck stops there, so the admin has every opportunity to correct the record - including the shift close.
D402 The 'was something else given instead?' pop-up that opens from a voided entry never lists a voided entry - a voided entry has no door, so it is not offered.
D381 A shift close's words may be corrected OR voided by an admin, the same two acts as every other written entry - one screen, one rule; a void leaves her words struck through with the admin's note, still readable, never deleted.
D412 In the admin's list of a day's records, the second line under each entry shows the record's state when it has one - voided, corrected - and falls back to the time the record was written down when it has none.
D210 When an admin closes a task during an escalation, the record carries two facts, not one: who administered the care, and that an admin entered it, with when and on whose word.
D207 When a nurse may not complete something, the app does not offer her the button.
D272 On the admin's reassign screen, a nurse's green "Available" tag and her place in the list come from the same question the server asks when it refuses: does her time overlap the shift being reassigned.
D202 An admin cannot reopen a task the ladder has given up on.
D401 A story is ready to show the owner only when its full test on the test system is recorded, every check has an unqualified pass or is retired by a ruling, its walk-through by made-up users is recorded, and every hard prerequisite is done and shown.
D170 The product is called "Zarah at Home".
D256 Error copy never promises what the system will do next.
D437 After an admin corrects or voids a nurse's shift-close words, her own phone shows her original words untouched with a one-line marker ("An admin corrected this" or "An admin voided this"), and nothing of the admin's note.

6Evidence

Record folders: docs/qa/the-admin-corrects-a-wrong-record/, e2e-judge-web.mdCommit: 66ae943d

10 The morning summary arrives at 08:00Testing In the last judged send (24 Sep), the email arrived on time and every fact it checked against the record held up, matching the drawn design for the states this send showed; two checks could not be judged because the night held no quiet case and no refused-mail case to test, and the test setup and the design wording are not yet ruled. Waits onStory 12

Of 19 criteria, 10 pass, and 9 are not yet tested · 2 test runs · 6 open findings

1Acceptance criteria 19

  1. 1It arrives at eight, on the patient's clock, every morning, to every adminPass 24 Sep
  2. 2…and it wakes nobodyPass 23 Sep
  3. 3Once, whatever happens to the serverNot yet tested
  4. 4A routine item nobody recorded is in it as not donePass 23 Sep
  5. 5Everything not done that night is listed, whoever was onPass 24 Sep
  6. 6A skip says why, and whoPass 23 Sep
  7. 7A late dose is one the app had started chasing — and the line tells given late from written up latePass 23 Sep
  8. 8A quiet night still arrives, and says soNot yet tested
  9. 9The morning view is on the admin siteNot yet tested
  10. 10Earlier mornings are there tooNot yet tested
  11. 11Then, and nowNot yet tested
  12. 12Each line opens the record behind itNot yet tested
  13. 13Whether it went is never a secretNot yet tested
  14. 14Nurses never receive it and cannot open itNot yet tested
  15. 15The places for what later stories add already existPass 23 Sep
  16. 16Before the first morningNot yet tested
  17. 17A paused item is on its own line, never under not donePass 24 Sep
  18. 18A close written after the summary went out is in the next morning's — once; the summary never waitsPass 23 Sep
  19. 19The email looks the way it was drawnPass 24 Sep

2Test runs 2

DateWhat was testedResultRecord
24 SepAn independent check of the evidence4 pass, 2 not yet testedRecord
23 SepAn independent check of the evidence9 pass, 1 fail, 9 not yet testedNot filed here yet

3Open findings 6

  1. 1A made-up test address that cannot receive mail was still switched on as a recipient of the morning email on the test system when the check was made, against the owner's ruling that only two named real addresses receive it there; the next test send would mail it again. (found 23 Sep)Being judged
  2. 2The late-doses hint in the morning email says a dose given a few minutes after its time is not listed, directly above a line listing one as 4 minutes late; the test system's shorter test timing causes this, and with the real timings it would read true. (found 23 Sep)Being judged
  3. 3The test system's record of changes shows the test admin account making changes after the record says it had been deactivated, with no entry for reactivating it, so it may have been done directly in the database; the note did not investigate this and puts it outside the story. (found 23 Sep)Being judged
  4. 4The email's design brief and the rule that wording stays unchanged disagree about two footer and hint facts the styled email added; which rule wins has not been settled. (found 24 Sep)Being judged
  5. 5No mail sent to the test system has yet been refused before acceptance, so the check that a bounced or refused address is reported nowhere on the app still cannot be tried; whether the app should instead learn about a bounce after acceptance is not yet ruled. (found 24 Sep)Being judged
  6. 6Every item loaded onto the test system for the pilot's demo is paused with no end date until install day, so every test night has a paused item and the truly-quiet-night check cannot be tried on this test system as it stands. (found 24 Sep)Being judged

4Depends on

Waits on:

Story 12

One story waits on this one:

Story 11

5Rulings that apply 27

D106 The morning summary arrives at 08:00 Kampala for everyone, wherever an admin is — silently if it is the middle of their night.
D105 An escalation reaches the admins the moment it happens; everything else (skips, no-shows, an unclosed shift, a late dose) collects into one morning summary.
D011 The old half-built admin escalation screen is deleted rather than shipped, and everything it was for is rebuilt from scratch.
D037 Three importance levels stay.
D359 The 08:00 morning summary carries the shift-closing words that exist at 08:00; a close written afterwards appears in the next morning's summary.
D367 A shift that was never closed is named in the morning summary every morning until it is closed, for as long as the 30-day unclosed window keeps it open - never once-and-dropped.
D380 The 08:00 morning summary email is sent to the family in its styled version, as the design specialist drew it, not as the bare plain-text placeholder.
D309 After a routine item's last chime it goes quiet.
D320 In the morning summary a 'late dose' is a medication item recorded as given after its tier's first escalation moment; a dose given inside the chime window is on time and not listed. 'Dose' means medication items only.
D321 The 08:00 summary is an email to every admin plus the same content as a morning view on the admin site; no phone alert.
D338 For a dose recorded without a separate time of care, the time the nurse recorded it counts as the time of care for the morning summary's late-dose test.
D102 Every screen shows the patient's timezone only — admin dashboard and nurse alike.
D356 Wherever a notification or message names the patient's clock it says the city in plain words - 'Due 13:45 Kampala time' - never an abbreviation (EAT) or an offset (GMT+3).
D273 A nurse's edit window on her own entry ends at the end of the care day, 06:00 in the patient's timezone, when no shift of hers covers the entry's own due instant — confirming the assumption the code already makes elsewhere rather than minting a new clock.
D076 The care day runs 06:00 to 06:00 on the patient's clock.
D064 Alarm behaviour is configured per tier — routine, important, critical — from the admin dashboard, and never per care item.
D095 Every entry carries both when the care happened and when it was recorded, and the record distinguishes delayed care from delayed logging.
D336 (1) a voided entry is left out of every statistic and chart, and a reported entry counts as given at the time reported — the corrected record is what the doctor sees; (2) the time on a reported entry may be left unknown, the giver may not.
D337 Voiding removes the ENTRY, not the task.
D267 When an admin corrects a wrongly-recorded care entry or observation, the statistics a doctor later reads — analytics, trends, whatever the doctor is shown — are built from the CORRECTED value, not the original.
D097 An entry recorded as reported closes the task — the alarm stops and the morning view stops showing it outstanding.
D099 An admin phoning a nurse to handle an escalation is not recorded anywhere, and the resulting blind spot is accepted.
D137 An action that cannot succeed is never shown as available, and the screen says what is blocking it, never a save that fails after she commits.
D063 The escalation ladder is phone alerts and email only.
D225 The patient's timezone is read once when the server starts and held.
D237 An admin may pause their own alarms and interruptions indefinitely, ending only when they turn them back on.
D049 A routine item never escalates to a person — that is fixed and cannot be configured on.

6Evidence

Record folders: docs/qa/the-morning-summary-arrives-at-eight/, judge-2026-09-24-email.md, judge-2026-09-23.mdCommit: d7f88a73

11 The nurse closes her shift, and is nagged, never blocked, if she forgetsTesting On the last phone check the reopen screen's two labels were the wrong way round and the care-notes card showed the nurse's name three times; the last website check noted two more web checks booked for a test window the next day. Waits onStory 10Story 12

Of 21 criteria, 5 pass, 3 pass in part, 5 fail, and 8 are not yet tested · 15 test runs · 13 open findings

1Acceptance criteria 21

  1. 1The way in is where she already is, from half an hour before the endPass 17 Sep the part checkedNot yet tested the rest
  2. 2Every honest answer costs one tapNot yet tested
  3. 3Her words, or Nothing to report — and the record keeps no scorePass 17 Sep the words field, the option buttons and SaveFail the option buttons' labels
  4. 4She closes, and the screen says what is now truePass 17 Sep
  5. 5Thirty minutes on, her phone reminds her — on its own sound, never through silentFail 17 Sep
  6. 6Every fifteen minutes, againNot yet tested
  7. 7At about forty-five minutes the admin is told quietly, and the shift sits in her queueFail 15 Sep
  8. 8At two hours her phone goes quiet; the admin's row does notPass 15 Sep the part checkedNot yet tested the rest
  9. 9On the close screen, nothing ringsNot yet tested
  10. 10Nothing stops her going homeNot yet tested
  11. 11The morning summary says so — in two different sentences for two different factsNot yet tested
  12. 12She closes it the next morning, and the record keeps both timesPass 17 Sep
  13. 13A typo is hers to fix until 06:00, or for an hour, whichever is laterPass 17 Sep
  14. 14Her words reach whoever comes next, and the admins, and nobody needs a fourth placeFail 17 Sep
  15. 15On a shift with two nurses, each closes her ownPass 15 Sep the webNot yet tested the phone
  16. 16She closes a little early, then records one more task — nothing is lostNot yet tested
  17. 17A nurse who is gone is not reminded; the admins still hearNot yet tested
  18. 18Offline, the close is refused before she writes, and her words surviveNot yet tested
  19. 19Once the morning summary has said so, nobody writes that close — not her, not an adminPass 17 Sep
  20. 20The admin writes on the shift in her own name — never as the nurse's closePass 15 Sep the behaviourFail one wording defect
  21. 21A corrected close is the admin's words, in the admin's name, with hers beneath; a voided close is her words struck through — nothing is ever deletedPass 17 Sep

2Test runs 15

DateWhat was testedResultRecord
17 SepAn independent check of the evidenceThe three checks tried again all pass and no product defect was found, but the website half is still not done: seven checks are still open and not accounted for.Record
17 SepAn independent check of the evidence5 pass, 1 pass in part, 1 fail, 11 not yet testedRecord
17 SepA test run on the websiteTried; judged in the independent check of 17 Sep. The three checks tried again all pass and no product defect was found, but the website half is still not done: seven checks are still open and not accounted for.Record
17 SepA test run on the phonesTried; judged in the independent check of 17 Sep.Record
17 SepAn independent check of the evidenceNot done, but no product defect is open on the website: the wrong-day failure is fixed, and what is left is checks not yet tested.Record
17 SepA test run on the websiteTried; judged in the independent check of 17 Sep. Not done, but no product defect is open on the website: the wrong-day failure is fixed, and what is left is checks not yet tested.Record
17 SepAn independent check of the evidenceNot done: the two defects found in the check before are fixed, but one new blocking failure appeared — the Record opens on the wrong day, silently.Record
17 SepA test run on the websiteTried; judged in the independent check of 17 Sep. Not done: the two defects found in the check before are fixed, but one new blocking failure appeared — the Record opens on the wrong day, silently.Record
17 SepAn independent check of the evidence2 pass, 4 pass in part, 1 fail, 4 not yet testedRecord
17 SepA test run on the phonesTried; judged in the independent check of 17 Sep.Record
17 SepAn independent check of the evidenceThe story did not pass this check.Record
17 SepA test run on the websiteTried; judged in the independent check of 17 Sep. The story did not pass this check.Record
16 SepAn independent check of the evidenceThe web pass still does not pass.Record
15 SepAn independent check of the evidence1 pass, 3 pass in part, 1 fail, 16 not yet testedRecord
15 SepA test run on the websiteTried; judged in the independent check of 15 Sep. The web pass does not pass.Record

3Open findings 13

  1. 1The last phone check's saved pictures include three identical pairs, two of them named for screens that were never taken. (found 17 Sep)Being judged
  2. 2No saved picture of the Samsung's Settings screen, where the app's version is shown at the bottom, was taken in the last phone check. (found 17 Sep)Being judged
  3. 3Nothing was saved of what the system recorded while the last phone check ran, so the check that no unexplained error message reached a person could not be run. (found 17 Sep)Being judged
  4. 4The reminder does not reach a registered phone (carried from the round before; the note has it second-hand). (found 17 Sep)Being judged
  5. 5The iPhone app's error record shows 46 fatal stops from July onward across four users and two recent builds (the phone's own watchdog ended the app); no ruling of the owner's covers it, it is not this story's, and the note proposes a story for it. (found 17 Sep)
  6. 6On Today, a cancelled task still reads "Yours to complete" beside its CANCELLED badge, which tells the nurse two opposite things about the same row. (found 17 Sep)Being judged
  7. 7The admin website asks for the signed-in admin's profile several times on every page load, which the error tracker flags on every screen; it costs a person nothing visible, and the note proposes a story for it. (found 17 Sep)
  8. 8A saved picture that should show a signed-out visitor being turned away is a blank dark image, so that check rests on the tester's word. (found 17 Sep)Being judged
  9. 9Two saved pictures cut off the sentence they were taken to show, below the edge of the screen; the saved text of the page carries it. (found 17 Sep)Being judged
  10. 10A saved sign-in session was left in the tester's folder of saved pictures; it had already expired and the folder is not committed, but the step that creates it should remove it. (found 17 Sep)Being judged
  11. 11On a phone, the cards for things needing attention squeeze a care task's name until it breaks in the middle of a word. (found 17 Sep)
  12. 12Two web checks were booked for a test window the day after the check; no test run dated after 17 Sep is on file. (found 17 Sep)Being judged
  13. 13Seven checks on the shift's page (a shift that does not exist, its loading, its failed load, the way back to the roster, a phone-width screen, a nurse's account and a signed-out browser) are neither tested nor accepted as deferred. (found 17 Sep)Being judged

4Depends on

Waits on:

Story 10Story 12

Stories that wait on this one: none.

5Rulings that apply 42

D147 The unclosed-shift nag starts 30 minutes after the shift ends, repeats on her phone every 15 minutes, tells the admin at about 45 minutes, stops on her phone at 2 hours while the item stays open in the admins' list, and pauses while she is on the close screen.
D056 The nag about an unclosed shift has its own sound and never uses the sound reserved for critical alarms.
D085 Closing a shift is a nag, never a block.
D148 On the shift-close screen, “done” and every not-done reason are the same one tap at the same visual weight; only “Other” may cost more, because it needs typed words.
D273 A nurse's edit window on her own entry ends at the end of the care day, 06:00 in the patient's timezone, when no shift of hers covers the entry's own due instant — confirming the assumption the code already makes elsewhere rather than minting a new clock.
D010 Handover between nurses is retired as a concept — no passing a task to a named person, no accept or decline.
D313 The shift-close screen lists the nurse's still-open items, each closed with one tap, followed by an optional few lines in her own words, where "Nothing to report" is a real one-tap answer.
D314 A shift close is a record of its own, one row per shift per nurse, carrying who closed it, when, which shift, and her words.
D315 The close is offered on the nurse's Today screen from about thirty minutes before her shift ends, and stays offered until she closes.Partly replaced by D373
D316 A shift's close belongs to the care day the shift STARTED on (a Monday 19:00 to Tuesday 08:00 shift is Monday's).
D359 The 08:00 morning summary carries the shift-closing words that exist at 08:00; a close written afterwards appears in the next morning's summary.
D317 The close screen shows her what is still open while she can still act on it, and the close record keeps no count of what she left open.
D318 A nurse let go while holding an unclosed shift gets no reminder but the admins still hear that the shift went unclosed.
D319 The admin's alert at about 45 minutes for an unclosed shift is a quiet notification plus a row in her list, and the shift also appears in the morning summary.Partly replaced by D375
D372 The rule that error copy never promises what the system will do next reaches only error copy and the escalation's actions; a reminder may say it is the last of its series.Partly replaced by D433
D373 A first shift close can be written only until the morning summary reports that shift as unclosed; then the offer leaves her card, the card says the shift was not closed, and nobody - not an admin - writes a close for it.
D374 The admin owns the patient's care and the buck stops there, so the admin has every opportunity to correct the record - including the shift close.
D375 'not available' is removed from the not-done reasons.
D367 A shift that was never closed is named in the morning summary every morning until it is closed, for as long as the 30-day unclosed window keeps it open - never once-and-dropped.
D351 The admin's list of shifts nobody closed (story 11) reaches back 30 days for now.
D384 The admin's own line on an unclosed shift counts as dealing with it - once written, the row leaves the admin queue; the shift still reads not closed in the record and in the morning summary's 30-day list.
D382 The admin's own line on a nurse's shift is never shown to the nurse, on her phone or anywhere she reads; it lives in the admins' list, the record and the admins' morning summary.
D381 A shift close's words may be corrected OR voided by an admin, the same two acts as every other written entry - one screen, one rule; a void leaves her words struck through with the admin's note, still readable, never deleted.
D436 A nurse's own unrecorded routine task closes to her at the end of her shift plus an extra 30 minutes: after that it is a greyed row with a line saying so, recordable by nobody on the phone, and the screens that only read show it as unrecorded.
D437 After an admin corrects or voids a nurse's shift-close words, her own phone shows her original words untouched with a one-line marker ("An admin corrected this" or "An admin voided this"), and nothing of the admin's note.
D406 A nurse may record or skip an unrecorded routine task at any point while she is still on the shift that owned it, however many hours past due it is.
D036 A critical item cannot be skipped.
D209 An item marked as one that must not be skipped offers the nurse no Skip control at all.
D166 The care author marks each care item skippable or not, and a skip always carries the item's mark as it stood at the moment it was skipped, so judgement calls and incidents stay distinguishable in the record forever.
D201 A task the alarm ladder has given up on stays in the nurse's history, greyed out and not actionable.
D137 An action that cannot succeed is never shown as available, and the screen says what is blocking it, never a save that fails after she commits.
D207 When a nurse may not complete something, the app does not offer her the button.
D100 When the phone cannot reach the server, the app says plainly that recording is paused and asks the nurse to note the time and enter it when she is back online.Partly replaced by D555
D149 The record shows who was on the shift roster at that time for a task and who actually acted on it as two separate facts.
D052 Critical alarms break through Do Not Disturb on the nurse's phone.
D046 The server decides when care is due, when to alarm, when to escalate and when to stop.
D197 Letting someone go is one complete action: her access ends, her phone stops registering, any unused invitation she holds dies, and she stops being named as someone to ring.
D308 Under the set-of-nurses model, when one nurse on a shift reports she cannot come, SHE leaves the set and the others stay on; the shift becomes a coverage gap for the admins only when nobody remains.
D296 A shift is simply the set of nurses on it, with no primary and no backup: a task belongs to everyone who is on shift at the moment it comes due.
D403 A nurse may record or skip a task before its due minute, within her own shift - real care does not wait for the minute.
D228 One person holds both roles as a single account whose role is admin, who can additionally be placed on the roster like any nurse.
D297 One person is one account holding both roles; the earlier two-account arrangement is retired.

6Evidence

Record folders: docs/qa/the-nurse-closes-her-shift-and-is-nagged-never-blocked/, e2e-judge-phone-2.md, e2e-judge-phone-3.md, e2e-judge-web-2.md, e2e-judge-web-3.md, e2e-judge-web-4.md, e2e-judge-web-5.md, e2e-judge-web.mdCommit: 172373a0

13 The admin closes a task during escalation honestly: nurse gave, admin wrote; “closed as missed” is the only other close; a reported entry clears the outstanding list; the proof-photo rule is not bypassed from the boardNot started No work yet. Waits onnothing

No checks listed · no test runs yet · no open findings

1Acceptance criteria 0

None. No work yet.

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: noneCommit: none

14 The admin site never shows the browser's clockNot started No work yet. Waits onnothing

No checks listed · no test runs yet · no open findings

1Acceptance criteria 0

None. No work yet.

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: noneCommit: none

17 The nurse skips a task at the bedsideBuilding Code written but not yet added to the app; the newest read-through of the code by someone other than its builder, on 22 Sep, found problems, and code changed after it has not been read through again; no independent check of the evidence is on file. Waits onStory 5Needs a repair first: the phone still uses the 4-hour clock for routine tasks

Of 10 criteria, 10 are not yet tested · no test runs yet · no open findings

1Acceptance criteria 10

  1. 1Skip is there, beside Complete, on every task she may act onNot yet tested
  2. 2A must-not-skip or critical item offers her no Skip at allNot yet tested
  3. 3One pop-up, four equal reasons, only other costs wordsNot yet tested
  4. 4One tap records it, in her name, and the row says so — not a tickNot yet tested
  5. 5The skip is hers on the same terms as a completion — before, during, and in the extra time; never afterNot yet tested
  6. 6Skipping a ringing task stops the ringNot yet tested
  7. 7If a colleague got there first, she is told the truthNot yet tested
  8. 8With no signal, she is told it did not save — and nothing is sent laterNot yet tested
  9. 9The website says who skipped it and why, in a sentenceNot yet tested
  10. 10A closed routine task no shift still covers reads the ruling's words — on the Record onlyNot yet tested

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on:

Story 5Needs a repair first: the phone still uses the 4-hour clock for routine tasks

Stories that wait on this one: none.

5Rulings that apply 32

D490 The bedside Skip for nurses is built before install day: a Skip control on the nurse's task card (hidden on must-not-skip items), a skip pop-up with four reasons, the server accepting a nurse's skip on her own shift, the skip queued offline like a completion, and the website showing who skipped and why.Partly replaced by D494
D493 The shift-end closure of a nurse's unrecorded routine task is built inside story 17, in the same server rule the nurse's skip touches; important and critical tasks are untouched.
D494 A skip with no signal behaves exactly like a plain completion with no signal: the app tells her it did not save and she tries again when she has signal.
D495 A skip record does NOT store a snapshot of whether the task was skippable at that moment — deferred to a later story.
D509 A closed routine task that no shift still covers (story 17's question G) reads exactly "Not done — the shift ended" on both the day list row's third line and the Record entry's line — no nurse's name, no reason given.
D088 Skip belongs to the nurse, at the bedside, in the moment.Partly replaced by D275
D209 An item marked as one that must not be skipped offers the nurse no Skip control at all.
D036 A critical item cannot be skipped.
D375 'not available' is removed from the not-done reasons.
D403 A nurse may record or skip a task before its due minute, within her own shift - real care does not wait for the minute.
D406 A nurse may record or skip an unrecorded routine task at any point while she is still on the shift that owned it, however many hours past due it is.
D234 A task belongs to the nurse whose shift covered the moment it came due — it is hers if it buzzed her — and it stays hers until the escalation dies.
D436 A nurse's own unrecorded routine task closes to her at the end of her shift plus an extra 30 minutes: after that it is a greyed row with a line saying so, recordable by nobody on the phone, and the screens that only read show it as unrecorded.
D201 A task the alarm ladder has given up on stays in the nurse's history, greyed out and not actionable.
D207 When a nurse may not complete something, the app does not offer her the button.
D137 An action that cannot succeed is never shown as available, and the screen says what is blocking it, never a save that fails after she commits.
D068 Recording a task silences its alarm on every on-shift nurse's phone, not only the recorder's.
D253 The server tells the phone when a snooze or action lands on a task that is already completed or skipped, so the phone can tell her the truth instead of saying "Snoozed".
D244 Snoozing an alarm for a task somebody has already completed tells her it is already done, instead of snoozing it.
D196 The app does not guard against a double dose, and a nurse cannot record care she did not personally give.
D100 When the phone cannot reach the server, the app says plainly that recording is paused and asks the nurse to note the time and enter it when she is back online.Partly replaced by D555
D256 Error copy never promises what the system will do next.
D241 Mark incomplete comes off the nurse's phone now, without waiting for its replacement.
D248 Undo is removed entirely.
D296 A shift is simply the set of nurses on it, with no primary and no backup: a task belongs to everyone who is on shift at the moment it comes due.
D073 No task is ever assigned to a named nurse, and there is no backup-nurse designation.
D138 Rules and specifications are written in roles — the patient, the nurse, the admin, the care author, the specialist — not in people's names.
D401 A story is ready to show the owner only when its full test on the test system is recorded, every check has an unqualified pass or is retired by a ruling, its walk-through by made-up users is recorded, and every hard prerequisite is done and shown.
D447 The owner's test-phone window is a fixed daily hour, 14:00–15:00 Eastern time, extendable to a second hour when asked by 09:00 that day.Partly replaced by D480 D483
D432 Agents never sign in, on any story: every end-to-end sign-in uses real Google and Apple accounts and the owner performs it himself.Replaced by a later ruling
D448 The six password-only test nurse accounts on the test system are deactivated, never deleted, and the test data points at the real Google and Apple nurse accounts.Partly replaced by D531
D408 The testing roles never sign in themselves (no typed password, no account picker, no consent screen, no one-time code); another role prepares the signed-in state for them.Partly replaced by D432 D485

6Evidence

Record folders: noneCommit: ae3e8b15

18 Before recording a medicine or critical item she is shown what she is about to put on the record in her name; other items skip the confirm stepNot started No work yet. Waits onnothing

No checks listed · no test runs yet · no open findings

1Acceptance criteria 0

None. No work yet.

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: noneCommit: none

19 A proof photo never traps her and never goes silently missing: denied camera sends her to settings, a failed upload does not hold the task, the record says the photo never arrivedNot started No work yet. Waits onnothing

No checks listed · no test runs yet · no open findings

1Acceptance criteria 0

None. No work yet.

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: noneCommit: none

20 Offline, the app says recording is paused and asks her to note the time; there is no queue; a hung save cannot be missedNot started No work yet. Waits onnothing

No checks listed · no test runs yet · no open findings

1Acceptance criteria 0

None. No work yet.

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: noneCommit: none

21 The Complete button is absent wherever she may not complete, on every screenNot started No work yet. Waits onnothing

No checks listed · no test runs yet · no open findings

1Acceptance criteria 0

None. No work yet.

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: noneCommit: none

22 When the roster check cannot run she records anyway; her entry says verification was not done; the admin sees that on the entry; the state is visible outside the logs and clears itselfNot started No work yet. Waits onnothing

No checks listed · no test runs yet · no open findings

1Acceptance criteria 0

None. No work yet.

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: noneCommit: none

26 An item runs only between its datesNot started No work yet. Waits onnothing

No checks listed · no test runs yet · no open findings

1Acceptance criteria 0

None. No work yet.

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: noneCommit: none

30 Every screen keeps the four product-wide promises: where the record cannot say, the screen says so; the app speaks inline unless she is choosing; nothing is offered that cannot succeed, and what blocks it is said; error copy says what happened and never promises what happens nextNot started No work yet. Waits onnothing

No checks listed · no test runs yet · no open findings

1Acceptance criteria 0

None. No work yet.

2Test runs 0

None yet.

3Open findings 0

None.

4Depends on

Waits on: nothing.

Stories that wait on this one: none.

5Rulings that apply 0

None.

6Evidence

Record folders: noneCommit: none