Files
arrr-erp-test-v2/data/generated-test-matrix.json
T
2026-06-22 12:52:00 +05:30

20743 lines
674 KiB
JSON

[
{
"sourceId": "GEN-001",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "All roles",
"scenario": "Valid login redirects to correct workspace",
"steps": "Login with System Admin, Firm Admin, Partner, Manager, Staff, Client and Consultant users.",
"expected": "Each role lands on its correct dashboard/workspace without error.",
"priority": "Critical",
"type": "Smoke",
"route": "/work",
"variantId": "GEN-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-001",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "All roles",
"scenario": "Valid login redirects to correct workspace",
"steps": "Login with System Admin, Firm Admin, Partner, Manager, Staff, Client and Consultant users.",
"expected": "Each role lands on its correct dashboard/workspace without error.",
"priority": "Critical",
"type": "Smoke",
"route": "/work",
"variantId": "GEN-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-001",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "All roles",
"scenario": "Valid login redirects to correct workspace",
"steps": "Login with System Admin, Firm Admin, Partner, Manager, Staff, Client and Consultant users.",
"expected": "Each role lands on its correct dashboard/workspace without error.",
"priority": "Critical",
"type": "Smoke",
"route": "/work",
"variantId": "GEN-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-001",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "All roles",
"scenario": "Valid login redirects to correct workspace",
"steps": "Login with System Admin, Firm Admin, Partner, Manager, Staff, Client and Consultant users.",
"expected": "Each role lands on its correct dashboard/workspace without error.",
"priority": "Critical",
"type": "Smoke",
"route": "/work",
"variantId": "GEN-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-001",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "All roles",
"scenario": "Valid login redirects to correct workspace",
"steps": "Login with System Admin, Firm Admin, Partner, Manager, Staff, Client and Consultant users.",
"expected": "Each role lands on its correct dashboard/workspace without error.",
"priority": "Critical",
"type": "Smoke",
"route": "/work",
"variantId": "GEN-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-002",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Manager / Branch Manager",
"scenario": "Manager direct landing",
"steps": "Login as Manager / Branch Manager.",
"expected": "User lands directly at /manager/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/manager/dashboard",
"variantId": "GEN-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-002",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Manager / Branch Manager",
"scenario": "Manager direct landing",
"steps": "Login as Manager / Branch Manager.",
"expected": "User lands directly at /manager/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/manager/dashboard",
"variantId": "GEN-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-002",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Manager / Branch Manager",
"scenario": "Manager direct landing",
"steps": "Login as Manager / Branch Manager.",
"expected": "User lands directly at /manager/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/manager/dashboard",
"variantId": "GEN-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-002",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Manager / Branch Manager",
"scenario": "Manager direct landing",
"steps": "Login as Manager / Branch Manager.",
"expected": "User lands directly at /manager/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/manager/dashboard",
"variantId": "GEN-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-002",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Manager / Branch Manager",
"scenario": "Manager direct landing",
"steps": "Login as Manager / Branch Manager.",
"expected": "User lands directly at /manager/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/manager/dashboard",
"variantId": "GEN-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-003",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Partner",
"scenario": "Partner direct landing",
"steps": "Login as Partner.",
"expected": "User lands at /partner/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/partner/dashboard",
"variantId": "GEN-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-003",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Partner",
"scenario": "Partner direct landing",
"steps": "Login as Partner.",
"expected": "User lands at /partner/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/partner/dashboard",
"variantId": "GEN-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-003",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Partner",
"scenario": "Partner direct landing",
"steps": "Login as Partner.",
"expected": "User lands at /partner/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/partner/dashboard",
"variantId": "GEN-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-003",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Partner",
"scenario": "Partner direct landing",
"steps": "Login as Partner.",
"expected": "User lands at /partner/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/partner/dashboard",
"variantId": "GEN-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-003",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Partner",
"scenario": "Partner direct landing",
"steps": "Login as Partner.",
"expected": "User lands at /partner/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/partner/dashboard",
"variantId": "GEN-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-004",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Client",
"scenario": "Client direct landing",
"steps": "Login as Client portal user.",
"expected": "User lands at /client/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/login",
"variantId": "GEN-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-004",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Client",
"scenario": "Client direct landing",
"steps": "Login as Client portal user.",
"expected": "User lands at /client/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/login",
"variantId": "GEN-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-004",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Client",
"scenario": "Client direct landing",
"steps": "Login as Client portal user.",
"expected": "User lands at /client/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/login",
"variantId": "GEN-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-004",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Client",
"scenario": "Client direct landing",
"steps": "Login as Client portal user.",
"expected": "User lands at /client/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/login",
"variantId": "GEN-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-004",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Client",
"scenario": "Client direct landing",
"steps": "Login as Client portal user.",
"expected": "User lands at /client/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/login",
"variantId": "GEN-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-005",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Consultant",
"scenario": "Consultant direct landing",
"steps": "Login as Consultant.",
"expected": "User lands at /consultant/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/consultants",
"variantId": "GEN-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-005",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Consultant",
"scenario": "Consultant direct landing",
"steps": "Login as Consultant.",
"expected": "User lands at /consultant/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/consultants",
"variantId": "GEN-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-005",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Consultant",
"scenario": "Consultant direct landing",
"steps": "Login as Consultant.",
"expected": "User lands at /consultant/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/consultants",
"variantId": "GEN-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-005",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Consultant",
"scenario": "Consultant direct landing",
"steps": "Login as Consultant.",
"expected": "User lands at /consultant/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/consultants",
"variantId": "GEN-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-005",
"sheet": "UAT_Common",
"module": "Login & Session",
"role": "Consultant",
"scenario": "Consultant direct landing",
"steps": "Login as Consultant.",
"expected": "User lands at /consultant/dashboard.",
"priority": "High",
"type": "Regression",
"route": "/consultants",
"variantId": "GEN-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-006",
"sheet": "UAT_Common",
"module": "Header/Layout",
"role": "All firm users",
"scenario": "Header firm/branch display",
"steps": "Open any page after login.",
"expected": "Header shows Firm Name and Branch Name, not raw tenant/branch IDs.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-006",
"sheet": "UAT_Common",
"module": "Header/Layout",
"role": "All firm users",
"scenario": "Header firm/branch display",
"steps": "Open any page after login.",
"expected": "Header shows Firm Name and Branch Name, not raw tenant/branch IDs.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-006",
"sheet": "UAT_Common",
"module": "Header/Layout",
"role": "All firm users",
"scenario": "Header firm/branch display",
"steps": "Open any page after login.",
"expected": "Header shows Firm Name and Branch Name, not raw tenant/branch IDs.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-006",
"sheet": "UAT_Common",
"module": "Header/Layout",
"role": "All firm users",
"scenario": "Header firm/branch display",
"steps": "Open any page after login.",
"expected": "Header shows Firm Name and Branch Name, not raw tenant/branch IDs.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-006",
"sheet": "UAT_Common",
"module": "Header/Layout",
"role": "All firm users",
"scenario": "Header firm/branch display",
"steps": "Open any page after login.",
"expected": "Header shows Firm Name and Branch Name, not raw tenant/branch IDs.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-007",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Staff",
"scenario": "Staff menu restriction",
"steps": "Login as normal staff and view sidebar.",
"expected": "Core Setup, Platform/Documents, full Documents agent menu and firm admin menus are hidden.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-007",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Staff",
"scenario": "Staff menu restriction",
"steps": "Login as normal staff and view sidebar.",
"expected": "Core Setup, Platform/Documents, full Documents agent menu and firm admin menus are hidden.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-007",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Staff",
"scenario": "Staff menu restriction",
"steps": "Login as normal staff and view sidebar.",
"expected": "Core Setup, Platform/Documents, full Documents agent menu and firm admin menus are hidden.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-007",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Staff",
"scenario": "Staff menu restriction",
"steps": "Login as normal staff and view sidebar.",
"expected": "Core Setup, Platform/Documents, full Documents agent menu and firm admin menus are hidden.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-007",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Staff",
"scenario": "Staff menu restriction",
"steps": "Login as normal staff and view sidebar.",
"expected": "Core Setup, Platform/Documents, full Documents agent menu and firm admin menus are hidden.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-008",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Firm Admin",
"scenario": "Menu order",
"steps": "Login as Firm Admin and verify sidebar order.",
"expected": "Order is My Workspace, Team Workspace, Billing, Team Administration, Firm Administration, Core Setup as applicable.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-008",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Firm Admin",
"scenario": "Menu order",
"steps": "Login as Firm Admin and verify sidebar order.",
"expected": "Order is My Workspace, Team Workspace, Billing, Team Administration, Firm Administration, Core Setup as applicable.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-008",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Firm Admin",
"scenario": "Menu order",
"steps": "Login as Firm Admin and verify sidebar order.",
"expected": "Order is My Workspace, Team Workspace, Billing, Team Administration, Firm Administration, Core Setup as applicable.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-008",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Firm Admin",
"scenario": "Menu order",
"steps": "Login as Firm Admin and verify sidebar order.",
"expected": "Order is My Workspace, Team Workspace, Billing, Team Administration, Firm Administration, Core Setup as applicable.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-008",
"sheet": "UAT_Common",
"module": "Sidebar",
"role": "Firm Admin",
"scenario": "Menu order",
"steps": "Login as Firm Admin and verify sidebar order.",
"expected": "Order is My Workspace, Team Workspace, Billing, Team Administration, Firm Administration, Core Setup as applicable.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-009",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert page access",
"steps": "Open /alerts.",
"expected": "User sees only their own alerts and can mark as read.",
"priority": "High",
"type": "UAT",
"route": "/alerts",
"variantId": "GEN-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-009",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert page access",
"steps": "Open /alerts.",
"expected": "User sees only their own alerts and can mark as read.",
"priority": "High",
"type": "UAT",
"route": "/alerts",
"variantId": "GEN-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-009",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert page access",
"steps": "Open /alerts.",
"expected": "User sees only their own alerts and can mark as read.",
"priority": "High",
"type": "UAT",
"route": "/alerts",
"variantId": "GEN-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-009",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert page access",
"steps": "Open /alerts.",
"expected": "User sees only their own alerts and can mark as read.",
"priority": "High",
"type": "UAT",
"route": "/alerts",
"variantId": "GEN-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-009",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert page access",
"steps": "Open /alerts.",
"expected": "User sees only their own alerts and can mark as read.",
"priority": "High",
"type": "UAT",
"route": "/alerts",
"variantId": "GEN-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-010",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Popup polling",
"steps": "Keep any page open while unread alert exists or create new alert.",
"expected": "Toast popup appears and unread count logic works without showing top header Alerts button.",
"priority": "Medium",
"type": "Regression",
"route": "/alerts",
"variantId": "GEN-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-010",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Popup polling",
"steps": "Keep any page open while unread alert exists or create new alert.",
"expected": "Toast popup appears and unread count logic works without showing top header Alerts button.",
"priority": "Medium",
"type": "Regression",
"route": "/alerts",
"variantId": "GEN-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-010",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Popup polling",
"steps": "Keep any page open while unread alert exists or create new alert.",
"expected": "Toast popup appears and unread count logic works without showing top header Alerts button.",
"priority": "Medium",
"type": "Regression",
"route": "/alerts",
"variantId": "GEN-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-010",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Popup polling",
"steps": "Keep any page open while unread alert exists or create new alert.",
"expected": "Toast popup appears and unread count logic works without showing top header Alerts button.",
"priority": "Medium",
"type": "Regression",
"route": "/alerts",
"variantId": "GEN-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-010",
"sheet": "UAT_Common",
"module": "Alerts",
"role": "All roles",
"scenario": "Popup polling",
"steps": "Keep any page open while unread alert exists or create new alert.",
"expected": "Toast popup appears and unread count logic works without showing top header Alerts button.",
"priority": "Medium",
"type": "Regression",
"route": "/alerts",
"variantId": "GEN-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-011",
"sheet": "UAT_Common",
"module": "CSRF",
"role": "All roles",
"scenario": "HTML POST CSRF",
"steps": "Submit key forms with missing/invalid CSRF token.",
"expected": "Request is rejected or redirected safely; no data change.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "GEN-011-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-011",
"sheet": "UAT_Common",
"module": "CSRF",
"role": "All roles",
"scenario": "HTML POST CSRF",
"steps": "Submit key forms with missing/invalid CSRF token.",
"expected": "Request is rejected or redirected safely; no data change.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "GEN-011-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-011",
"sheet": "UAT_Common",
"module": "CSRF",
"role": "All roles",
"scenario": "HTML POST CSRF",
"steps": "Submit key forms with missing/invalid CSRF token.",
"expected": "Request is rejected or redirected safely; no data change.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "GEN-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-011",
"sheet": "UAT_Common",
"module": "CSRF",
"role": "All roles",
"scenario": "HTML POST CSRF",
"steps": "Submit key forms with missing/invalid CSRF token.",
"expected": "Request is rejected or redirected safely; no data change.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "GEN-011-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-011",
"sheet": "UAT_Common",
"module": "CSRF",
"role": "All roles",
"scenario": "HTML POST CSRF",
"steps": "Submit key forms with missing/invalid CSRF token.",
"expected": "Request is rejected or redirected safely; no data change.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "GEN-011-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-012",
"sheet": "UAT_Common",
"module": "Unauthorized URL access",
"role": "All roles",
"scenario": "Direct URL access control",
"steps": "Paste URLs for another role directly.",
"expected": "User is denied or redirected; no restricted data shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "GEN-012-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-012",
"sheet": "UAT_Common",
"module": "Unauthorized URL access",
"role": "All roles",
"scenario": "Direct URL access control",
"steps": "Paste URLs for another role directly.",
"expected": "User is denied or redirected; no restricted data shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "GEN-012-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-012",
"sheet": "UAT_Common",
"module": "Unauthorized URL access",
"role": "All roles",
"scenario": "Direct URL access control",
"steps": "Paste URLs for another role directly.",
"expected": "User is denied or redirected; no restricted data shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "GEN-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-012",
"sheet": "UAT_Common",
"module": "Unauthorized URL access",
"role": "All roles",
"scenario": "Direct URL access control",
"steps": "Paste URLs for another role directly.",
"expected": "User is denied or redirected; no restricted data shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "GEN-012-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-012",
"sheet": "UAT_Common",
"module": "Unauthorized URL access",
"role": "All roles",
"scenario": "Direct URL access control",
"steps": "Paste URLs for another role directly.",
"expected": "User is denied or redirected; no restricted data shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "GEN-012-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-013",
"sheet": "UAT_Common",
"module": "Validation",
"role": "All roles",
"scenario": "Blank/invalid form submission",
"steps": "Submit blank or invalid forms on key pages.",
"expected": "Clear validation error shown; no server 500.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-013-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-013",
"sheet": "UAT_Common",
"module": "Validation",
"role": "All roles",
"scenario": "Blank/invalid form submission",
"steps": "Submit blank or invalid forms on key pages.",
"expected": "Clear validation error shown; no server 500.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-013-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-013",
"sheet": "UAT_Common",
"module": "Validation",
"role": "All roles",
"scenario": "Blank/invalid form submission",
"steps": "Submit blank or invalid forms on key pages.",
"expected": "Clear validation error shown; no server 500.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-013",
"sheet": "UAT_Common",
"module": "Validation",
"role": "All roles",
"scenario": "Blank/invalid form submission",
"steps": "Submit blank or invalid forms on key pages.",
"expected": "Clear validation error shown; no server 500.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-013-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-013",
"sheet": "UAT_Common",
"module": "Validation",
"role": "All roles",
"scenario": "Blank/invalid form submission",
"steps": "Submit blank or invalid forms on key pages.",
"expected": "Clear validation error shown; no server 500.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-013-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-014",
"sheet": "UAT_Common",
"module": "Audit / Logs",
"role": "All roles",
"scenario": "Permission denied events logged",
"steps": "Attempt blocked action and check audit log.",
"expected": "Event logged correctly without exposing secrets.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-014-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-014",
"sheet": "UAT_Common",
"module": "Audit / Logs",
"role": "All roles",
"scenario": "Permission denied events logged",
"steps": "Attempt blocked action and check audit log.",
"expected": "Event logged correctly without exposing secrets.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-014-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-014",
"sheet": "UAT_Common",
"module": "Audit / Logs",
"role": "All roles",
"scenario": "Permission denied events logged",
"steps": "Attempt blocked action and check audit log.",
"expected": "Event logged correctly without exposing secrets.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-014",
"sheet": "UAT_Common",
"module": "Audit / Logs",
"role": "All roles",
"scenario": "Permission denied events logged",
"steps": "Attempt blocked action and check audit log.",
"expected": "Event logged correctly without exposing secrets.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-014-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-014",
"sheet": "UAT_Common",
"module": "Audit / Logs",
"role": "All roles",
"scenario": "Permission denied events logged",
"steps": "Attempt blocked action and check audit log.",
"expected": "Event logged correctly without exposing secrets.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-014-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-015",
"sheet": "UAT_Common",
"module": "Search / Filter",
"role": "All roles",
"scenario": "List page search, filter, pagination",
"steps": "Use search/filter/pagination on client, employee, service list pages.",
"expected": "Works without data leakage across tenant/branch.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-015-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-015",
"sheet": "UAT_Common",
"module": "Search / Filter",
"role": "All roles",
"scenario": "List page search, filter, pagination",
"steps": "Use search/filter/pagination on client, employee, service list pages.",
"expected": "Works without data leakage across tenant/branch.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-015-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-015",
"sheet": "UAT_Common",
"module": "Search / Filter",
"role": "All roles",
"scenario": "List page search, filter, pagination",
"steps": "Use search/filter/pagination on client, employee, service list pages.",
"expected": "Works without data leakage across tenant/branch.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-015",
"sheet": "UAT_Common",
"module": "Search / Filter",
"role": "All roles",
"scenario": "List page search, filter, pagination",
"steps": "Use search/filter/pagination on client, employee, service list pages.",
"expected": "Works without data leakage across tenant/branch.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-015-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-015",
"sheet": "UAT_Common",
"module": "Search / Filter",
"role": "All roles",
"scenario": "List page search, filter, pagination",
"steps": "Use search/filter/pagination on client, employee, service list pages.",
"expected": "Works without data leakage across tenant/branch.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-015-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "GEN-016",
"sheet": "UAT_Common",
"module": "Imports",
"role": "All roles",
"scenario": "Upload invalid Excel/file on any import",
"steps": "Upload malformed or wrong-format file on any import screen.",
"expected": "Rejected with row-level errors; no partial commit.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-016-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "GEN-016",
"sheet": "UAT_Common",
"module": "Imports",
"role": "All roles",
"scenario": "Upload invalid Excel/file on any import",
"steps": "Upload malformed or wrong-format file on any import screen.",
"expected": "Rejected with row-level errors; no partial commit.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-016-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "GEN-016",
"sheet": "UAT_Common",
"module": "Imports",
"role": "All roles",
"scenario": "Upload invalid Excel/file on any import",
"steps": "Upload malformed or wrong-format file on any import screen.",
"expected": "Rejected with row-level errors; no partial commit.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-016-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "GEN-016",
"sheet": "UAT_Common",
"module": "Imports",
"role": "All roles",
"scenario": "Upload invalid Excel/file on any import",
"steps": "Upload malformed or wrong-format file on any import screen.",
"expected": "Rejected with row-level errors; no partial commit.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-016-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "GEN-016",
"sheet": "UAT_Common",
"module": "Imports",
"role": "All roles",
"scenario": "Upload invalid Excel/file on any import",
"steps": "Upload malformed or wrong-format file on any import screen.",
"expected": "Rejected with row-level errors; no partial commit.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "GEN-016-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-001",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Create firm-managed client",
"steps": "Create client from Firm Admin with PAN/GSTIN/contact/address/branch/partner.",
"expected": "Client is created under active firm/branch and appears in client list.",
"priority": "Critical",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-001",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Create firm-managed client",
"steps": "Create client from Firm Admin with PAN/GSTIN/contact/address/branch/partner.",
"expected": "Client is created under active firm/branch and appears in client list.",
"priority": "Critical",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-001",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Create firm-managed client",
"steps": "Create client from Firm Admin with PAN/GSTIN/contact/address/branch/partner.",
"expected": "Client is created under active firm/branch and appears in client list.",
"priority": "Critical",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-001",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Create firm-managed client",
"steps": "Create client from Firm Admin with PAN/GSTIN/contact/address/branch/partner.",
"expected": "Client is created under active firm/branch and appears in client list.",
"priority": "Critical",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-001",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Create firm-managed client",
"steps": "Create client from Firm Admin with PAN/GSTIN/contact/address/branch/partner.",
"expected": "Client is created under active firm/branch and appears in client list.",
"priority": "Critical",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-002",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Create partner client",
"steps": "Create client as Partner.",
"expected": "Client is linked to same firm and partner by default/available partner logic.",
"priority": "High",
"type": "UAT",
"route": "/partner/dashboard",
"variantId": "CL-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-002",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Create partner client",
"steps": "Create client as Partner.",
"expected": "Client is linked to same firm and partner by default/available partner logic.",
"priority": "High",
"type": "UAT",
"route": "/partner/dashboard",
"variantId": "CL-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-002",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Create partner client",
"steps": "Create client as Partner.",
"expected": "Client is linked to same firm and partner by default/available partner logic.",
"priority": "High",
"type": "UAT",
"route": "/partner/dashboard",
"variantId": "CL-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-002",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Create partner client",
"steps": "Create client as Partner.",
"expected": "Client is linked to same firm and partner by default/available partner logic.",
"priority": "High",
"type": "UAT",
"route": "/partner/dashboard",
"variantId": "CL-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-002",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Create partner client",
"steps": "Create client as Partner.",
"expected": "Client is linked to same firm and partner by default/available partner logic.",
"priority": "High",
"type": "UAT",
"route": "/partner/dashboard",
"variantId": "CL-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-003",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "System Admin",
"scenario": "Cross-tenant client view",
"steps": "Login as System Admin and view clients.",
"expected": "Can view all clients across tenants where designed, with clear firm context.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-003",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "System Admin",
"scenario": "Cross-tenant client view",
"steps": "Login as System Admin and view clients.",
"expected": "Can view all clients across tenants where designed, with clear firm context.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-003",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "System Admin",
"scenario": "Cross-tenant client view",
"steps": "Login as System Admin and view clients.",
"expected": "Can view all clients across tenants where designed, with clear firm context.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-003",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "System Admin",
"scenario": "Cross-tenant client view",
"steps": "Login as System Admin and view clients.",
"expected": "Can view all clients across tenants where designed, with clear firm context.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-003",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "System Admin",
"scenario": "Cross-tenant client view",
"steps": "Login as System Admin and view clients.",
"expected": "Can view all clients across tenants where designed, with clear firm context.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-004",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "No cross-tenant client leakage",
"steps": "Login as Firm Admin and view clients.",
"expected": "Only clients belonging to that firm are visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-004",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "No cross-tenant client leakage",
"steps": "Login as Firm Admin and view clients.",
"expected": "Only clients belonging to that firm are visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-004",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "No cross-tenant client leakage",
"steps": "Login as Firm Admin and view clients.",
"expected": "Only clients belonging to that firm are visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-004",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "No cross-tenant client leakage",
"steps": "Login as Firm Admin and view clients.",
"expected": "Only clients belonging to that firm are visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-004",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "No cross-tenant client leakage",
"steps": "Login as Firm Admin and view clients.",
"expected": "Only clients belonging to that firm are visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-005",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Partner scoping",
"steps": "Login as Partner and view clients.",
"expected": "Partner sees own assigned clients only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/partner/dashboard",
"variantId": "CL-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-005",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Partner scoping",
"steps": "Login as Partner and view clients.",
"expected": "Partner sees own assigned clients only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/partner/dashboard",
"variantId": "CL-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-005",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Partner scoping",
"steps": "Login as Partner and view clients.",
"expected": "Partner sees own assigned clients only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/partner/dashboard",
"variantId": "CL-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-005",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Partner scoping",
"steps": "Login as Partner and view clients.",
"expected": "Partner sees own assigned clients only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/partner/dashboard",
"variantId": "CL-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-005",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Partner",
"scenario": "Partner scoping",
"steps": "Login as Partner and view clients.",
"expected": "Partner sees own assigned clients only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/partner/dashboard",
"variantId": "CL-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-006",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Staff",
"scenario": "Staff client visibility",
"steps": "Login as staff and access client list/direct client URL.",
"expected": "Staff only sees clients linked through assigned work or is blocked as per permission.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-006",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Staff",
"scenario": "Staff client visibility",
"steps": "Login as staff and access client list/direct client URL.",
"expected": "Staff only sees clients linked through assigned work or is blocked as per permission.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-006",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Staff",
"scenario": "Staff client visibility",
"steps": "Login as staff and access client list/direct client URL.",
"expected": "Staff only sees clients linked through assigned work or is blocked as per permission.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-006",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Staff",
"scenario": "Staff client visibility",
"steps": "Login as staff and access client list/direct client URL.",
"expected": "Staff only sees clients linked through assigned work or is blocked as per permission.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-006",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Staff",
"scenario": "Staff client visibility",
"steps": "Login as staff and access client list/direct client URL.",
"expected": "Staff only sees clients linked through assigned work or is blocked as per permission.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-007",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Consultant",
"scenario": "Consultant client visibility",
"steps": "Login as Consultant and view clients.",
"expected": "Consultant sees only linked consultant clients.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CL-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-007",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Consultant",
"scenario": "Consultant client visibility",
"steps": "Login as Consultant and view clients.",
"expected": "Consultant sees only linked consultant clients.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CL-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-007",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Consultant",
"scenario": "Consultant client visibility",
"steps": "Login as Consultant and view clients.",
"expected": "Consultant sees only linked consultant clients.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CL-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-007",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Consultant",
"scenario": "Consultant client visibility",
"steps": "Login as Consultant and view clients.",
"expected": "Consultant sees only linked consultant clients.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CL-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-007",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Consultant",
"scenario": "Consultant client visibility",
"steps": "Login as Consultant and view clients.",
"expected": "Consultant sees only linked consultant clients.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CL-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-008",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Client user auto-creation",
"steps": "Create client with valid email.",
"expected": "Client portal user is mandatorily created/linked as per current business logic.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-008",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Client user auto-creation",
"steps": "Create client with valid email.",
"expected": "Client portal user is mandatorily created/linked as per current business logic.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-008",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Client user auto-creation",
"steps": "Create client with valid email.",
"expected": "Client portal user is mandatorily created/linked as per current business logic.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-008",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Client user auto-creation",
"steps": "Create client with valid email.",
"expected": "Client portal user is mandatorily created/linked as per current business logic.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-008",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Client user auto-creation",
"steps": "Create client with valid email.",
"expected": "Client portal user is mandatorily created/linked as per current business logic.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-009",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client portal login after creation",
"steps": "Login as auto-created client user or invite-created user.",
"expected": "Client can access /client/dashboard and sees only own compliance/documents/messages.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CL-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-009",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client portal login after creation",
"steps": "Login as auto-created client user or invite-created user.",
"expected": "Client can access /client/dashboard and sees only own compliance/documents/messages.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CL-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-009",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client portal login after creation",
"steps": "Login as auto-created client user or invite-created user.",
"expected": "Client can access /client/dashboard and sees only own compliance/documents/messages.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CL-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-009",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client portal login after creation",
"steps": "Login as auto-created client user or invite-created user.",
"expected": "Client can access /client/dashboard and sees only own compliance/documents/messages.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CL-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-009",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client portal login after creation",
"steps": "Login as auto-created client user or invite-created user.",
"expected": "Client can access /client/dashboard and sees only own compliance/documents/messages.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CL-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-010",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "PAN validation by entity type",
"steps": "Create client with various entity types and PAN formats.",
"expected": "PAN validation accepts/rejects correctly per entity.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-010",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "PAN validation by entity type",
"steps": "Create client with various entity types and PAN formats.",
"expected": "PAN validation accepts/rejects correctly per entity.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-010",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "PAN validation by entity type",
"steps": "Create client with various entity types and PAN formats.",
"expected": "PAN validation accepts/rejects correctly per entity.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-010",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "PAN validation by entity type",
"steps": "Create client with various entity types and PAN formats.",
"expected": "PAN validation accepts/rejects correctly per entity.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-010",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "PAN validation by entity type",
"steps": "Create client with various entity types and PAN formats.",
"expected": "PAN validation accepts/rejects correctly per entity.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-011",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "GSTIN validation state/PAN format",
"steps": "Enter GSTIN values.",
"expected": "GSTIN validated for state code and embedded PAN match.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-011-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-011",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "GSTIN validation state/PAN format",
"steps": "Enter GSTIN values.",
"expected": "GSTIN validated for state code and embedded PAN match.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-011-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-011",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "GSTIN validation state/PAN format",
"steps": "Enter GSTIN values.",
"expected": "GSTIN validated for state code and embedded PAN match.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-011",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "GSTIN validation state/PAN format",
"steps": "Enter GSTIN values.",
"expected": "GSTIN validated for state code and embedded PAN match.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-011-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-011",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "GSTIN validation state/PAN format",
"steps": "Enter GSTIN values.",
"expected": "GSTIN validated for state code and embedded PAN match.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-011-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-012",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Additional fields save",
"steps": "Fill CIN/LLPIN/TAN/MSME/IEC/alternate mobile/email/risk category/onboarding date.",
"expected": "All fields saved correctly and appear in detail view.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-012-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-012",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Additional fields save",
"steps": "Fill CIN/LLPIN/TAN/MSME/IEC/alternate mobile/email/risk category/onboarding date.",
"expected": "All fields saved correctly and appear in detail view.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-012-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-012",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Additional fields save",
"steps": "Fill CIN/LLPIN/TAN/MSME/IEC/alternate mobile/email/risk category/onboarding date.",
"expected": "All fields saved correctly and appear in detail view.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-012",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Additional fields save",
"steps": "Fill CIN/LLPIN/TAN/MSME/IEC/alternate mobile/email/risk category/onboarding date.",
"expected": "All fields saved correctly and appear in detail view.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-012-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-012",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Additional fields save",
"steps": "Fill CIN/LLPIN/TAN/MSME/IEC/alternate mobile/email/risk category/onboarding date.",
"expected": "All fields saved correctly and appear in detail view.",
"priority": "Medium",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-012-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-013",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Bulk import clients",
"steps": "Upload valid client import file.",
"expected": "Clients are imported with tenant/branch/partner scope and validation errors shown.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-013-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-013",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Bulk import clients",
"steps": "Upload valid client import file.",
"expected": "Clients are imported with tenant/branch/partner scope and validation errors shown.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-013-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-013",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Bulk import clients",
"steps": "Upload valid client import file.",
"expected": "Clients are imported with tenant/branch/partner scope and validation errors shown.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-013",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Bulk import clients",
"steps": "Upload valid client import file.",
"expected": "Clients are imported with tenant/branch/partner scope and validation errors shown.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-013-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-013",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Bulk import clients",
"steps": "Upload valid client import file.",
"expected": "Clients are imported with tenant/branch/partner scope and validation errors shown.",
"priority": "High",
"type": "UAT",
"route": "/employee/dashboard",
"variantId": "CL-013-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-014",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Duplicate client protection",
"steps": "Try duplicate PAN/GSTIN/client code within firm.",
"expected": "System prevents duplicate or shows clear validation message.",
"priority": "High",
"type": "Negative",
"route": "/employee/dashboard",
"variantId": "CL-014-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-014",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Duplicate client protection",
"steps": "Try duplicate PAN/GSTIN/client code within firm.",
"expected": "System prevents duplicate or shows clear validation message.",
"priority": "High",
"type": "Negative",
"route": "/employee/dashboard",
"variantId": "CL-014-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-014",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Duplicate client protection",
"steps": "Try duplicate PAN/GSTIN/client code within firm.",
"expected": "System prevents duplicate or shows clear validation message.",
"priority": "High",
"type": "Negative",
"route": "/employee/dashboard",
"variantId": "CL-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-014",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Duplicate client protection",
"steps": "Try duplicate PAN/GSTIN/client code within firm.",
"expected": "System prevents duplicate or shows clear validation message.",
"priority": "High",
"type": "Negative",
"route": "/employee/dashboard",
"variantId": "CL-014-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-014",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Firm Admin",
"scenario": "Duplicate client protection",
"steps": "Try duplicate PAN/GSTIN/client code within firm.",
"expected": "System prevents duplicate or shows clear validation message.",
"priority": "High",
"type": "Negative",
"route": "/employee/dashboard",
"variantId": "CL-014-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CL-015",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client profile update restriction",
"steps": "Client tries to edit restricted firm-controlled fields.",
"expected": "Only permitted profile/contact fields are editable; internal classification remains protected.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-015-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CL-015",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client profile update restriction",
"steps": "Client tries to edit restricted firm-controlled fields.",
"expected": "Only permitted profile/contact fields are editable; internal classification remains protected.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-015-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CL-015",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client profile update restriction",
"steps": "Client tries to edit restricted firm-controlled fields.",
"expected": "Only permitted profile/contact fields are editable; internal classification remains protected.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CL-015",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client profile update restriction",
"steps": "Client tries to edit restricted firm-controlled fields.",
"expected": "Only permitted profile/contact fields are editable; internal classification remains protected.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-015-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CL-015",
"sheet": "UAT_Clients",
"module": "Clients",
"role": "Client",
"scenario": "Client profile update restriction",
"steps": "Client tries to edit restricted firm-controlled fields.",
"expected": "Only permitted profile/contact fields are editable; internal classification remains protected.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "CL-015-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-001",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Create service catalogue",
"steps": "Create service category and catalogue service.",
"expected": "Catalogue service is created and visible system-wide.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-001",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Create service catalogue",
"steps": "Create service category and catalogue service.",
"expected": "Catalogue service is created and visible system-wide.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-001",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Create service catalogue",
"steps": "Create service category and catalogue service.",
"expected": "Catalogue service is created and visible system-wide.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-001",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Create service catalogue",
"steps": "Create service category and catalogue service.",
"expected": "Catalogue service is created and visible system-wide.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-001",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Create service catalogue",
"steps": "Create service category and catalogue service.",
"expected": "Catalogue service is created and visible system-wide.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-002",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Import service catalogue and default tasks",
"steps": "Use service import/bulk import if enabled.",
"expected": "Catalogue and default task templates are imported with validation.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-002",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Import service catalogue and default tasks",
"steps": "Use service import/bulk import if enabled.",
"expected": "Catalogue and default task templates are imported with validation.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-002",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Import service catalogue and default tasks",
"steps": "Use service import/bulk import if enabled.",
"expected": "Catalogue and default task templates are imported with validation.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-002",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Import service catalogue and default tasks",
"steps": "Use service import/bulk import if enabled.",
"expected": "Catalogue and default task templates are imported with validation.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-002",
"sheet": "UAT_Services",
"module": "Services",
"role": "System Admin",
"scenario": "Import service catalogue and default tasks",
"steps": "Use service import/bulk import if enabled.",
"expected": "Catalogue and default task templates are imported with validation.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-003",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "View service catalogue",
"steps": "Open /services/catalogue.",
"expected": "Firm Admin can view catalogue without 303 redirect/permission error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-003",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "View service catalogue",
"steps": "Open /services/catalogue.",
"expected": "Firm Admin can view catalogue without 303 redirect/permission error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-003",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "View service catalogue",
"steps": "Open /services/catalogue.",
"expected": "Firm Admin can view catalogue without 303 redirect/permission error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-003",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "View service catalogue",
"steps": "Open /services/catalogue.",
"expected": "Firm Admin can view catalogue without 303 redirect/permission error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-003",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "View service catalogue",
"steps": "Open /services/catalogue.",
"expected": "Firm Admin can view catalogue without 303 redirect/permission error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-004",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Select service for firm",
"steps": "From catalogue/list/detail click Select for Firm.",
"expected": "Service becomes enabled for firm and appears in Firm Services.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-004",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Select service for firm",
"steps": "From catalogue/list/detail click Select for Firm.",
"expected": "Service becomes enabled for firm and appears in Firm Services.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-004",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Select service for firm",
"steps": "From catalogue/list/detail click Select for Firm.",
"expected": "Service becomes enabled for firm and appears in Firm Services.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-004",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Select service for firm",
"steps": "From catalogue/list/detail click Select for Firm.",
"expected": "Service becomes enabled for firm and appears in Firm Services.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-004",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Select service for firm",
"steps": "From catalogue/list/detail click Select for Firm.",
"expected": "Service becomes enabled for firm and appears in Firm Services.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "SVC-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-005",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Disable service for firm",
"steps": "Disable previously selected firm service.",
"expected": "Service is inactive/disabled for firm but catalogue remains unchanged.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-005",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Disable service for firm",
"steps": "Disable previously selected firm service.",
"expected": "Service is inactive/disabled for firm but catalogue remains unchanged.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-005",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Disable service for firm",
"steps": "Disable previously selected firm service.",
"expected": "Service is inactive/disabled for firm but catalogue remains unchanged.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-005",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Disable service for firm",
"steps": "Disable previously selected firm service.",
"expected": "Service is inactive/disabled for firm but catalogue remains unchanged.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-005",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Disable service for firm",
"steps": "Disable previously selected firm service.",
"expected": "Service is inactive/disabled for firm but catalogue remains unchanged.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-006",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Customize firm tasks",
"steps": "Open /services/templates/{catalogue_id}.",
"expected": "Firm Admin can copy default tasks and add/edit firm-level templates.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-006",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Customize firm tasks",
"steps": "Open /services/templates/{catalogue_id}.",
"expected": "Firm Admin can copy default tasks and add/edit firm-level templates.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-006",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Customize firm tasks",
"steps": "Open /services/templates/{catalogue_id}.",
"expected": "Firm Admin can copy default tasks and add/edit firm-level templates.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-006",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Customize firm tasks",
"steps": "Open /services/templates/{catalogue_id}.",
"expected": "Firm Admin can copy default tasks and add/edit firm-level templates.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-006",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Customize firm tasks",
"steps": "Open /services/templates/{catalogue_id}.",
"expected": "Firm Admin can copy default tasks and add/edit firm-level templates.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-007",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner",
"scenario": "Partner task template access",
"steps": "Open firm task templates as Partner if permitted.",
"expected": "Partner can view/customise only permitted firm task templates.",
"priority": "Medium",
"type": "UAT",
"route": "/services",
"variantId": "SVC-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-007",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner",
"scenario": "Partner task template access",
"steps": "Open firm task templates as Partner if permitted.",
"expected": "Partner can view/customise only permitted firm task templates.",
"priority": "Medium",
"type": "UAT",
"route": "/services",
"variantId": "SVC-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-007",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner",
"scenario": "Partner task template access",
"steps": "Open firm task templates as Partner if permitted.",
"expected": "Partner can view/customise only permitted firm task templates.",
"priority": "Medium",
"type": "UAT",
"route": "/services",
"variantId": "SVC-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-007",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner",
"scenario": "Partner task template access",
"steps": "Open firm task templates as Partner if permitted.",
"expected": "Partner can view/customise only permitted firm task templates.",
"priority": "Medium",
"type": "UAT",
"route": "/services",
"variantId": "SVC-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-007",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner",
"scenario": "Partner task template access",
"steps": "Open firm task templates as Partner if permitted.",
"expected": "Partner can view/customise only permitted firm task templates.",
"priority": "Medium",
"type": "UAT",
"route": "/services",
"variantId": "SVC-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-008",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "System-only controls hidden",
"steps": "Check Create Catalogue Service/System Default Tasks.",
"expected": "These actions are hidden/blocked for Firm Admin; System Admin only.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-008",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "System-only controls hidden",
"steps": "Check Create Catalogue Service/System Default Tasks.",
"expected": "These actions are hidden/blocked for Firm Admin; System Admin only.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-008",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "System-only controls hidden",
"steps": "Check Create Catalogue Service/System Default Tasks.",
"expected": "These actions are hidden/blocked for Firm Admin; System Admin only.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-008",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "System-only controls hidden",
"steps": "Check Create Catalogue Service/System Default Tasks.",
"expected": "These actions are hidden/blocked for Firm Admin; System Admin only.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-008",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "System-only controls hidden",
"steps": "Check Create Catalogue Service/System Default Tasks.",
"expected": "These actions are hidden/blocked for Firm Admin; System Admin only.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-009",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Service categories view",
"steps": "Open /services/categories.",
"expected": "Firm Admin can view categories; creation/edit remains System Admin only.",
"priority": "Medium",
"type": "Regression",
"route": "/services",
"variantId": "SVC-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-009",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Service categories view",
"steps": "Open /services/categories.",
"expected": "Firm Admin can view categories; creation/edit remains System Admin only.",
"priority": "Medium",
"type": "Regression",
"route": "/services",
"variantId": "SVC-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-009",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Service categories view",
"steps": "Open /services/categories.",
"expected": "Firm Admin can view categories; creation/edit remains System Admin only.",
"priority": "Medium",
"type": "Regression",
"route": "/services",
"variantId": "SVC-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-009",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Service categories view",
"steps": "Open /services/categories.",
"expected": "Firm Admin can view categories; creation/edit remains System Admin only.",
"priority": "Medium",
"type": "Regression",
"route": "/services",
"variantId": "SVC-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-009",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Service categories view",
"steps": "Open /services/categories.",
"expected": "Firm Admin can view categories; creation/edit remains System Admin only.",
"priority": "Medium",
"type": "Regression",
"route": "/services",
"variantId": "SVC-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-010",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Client service assignment",
"steps": "Assign firm-enabled services to one or more clients.",
"expected": "Subscriptions are created with correct firm/branch/client scope.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-010",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Client service assignment",
"steps": "Assign firm-enabled services to one or more clients.",
"expected": "Subscriptions are created with correct firm/branch/client scope.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-010",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Client service assignment",
"steps": "Assign firm-enabled services to one or more clients.",
"expected": "Subscriptions are created with correct firm/branch/client scope.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-010",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Client service assignment",
"steps": "Assign firm-enabled services to one or more clients.",
"expected": "Subscriptions are created with correct firm/branch/client scope.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-010",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Client service assignment",
"steps": "Assign firm-enabled services to one or more clients.",
"expected": "Subscriptions are created with correct firm/branch/client scope.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-011",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Bulk service assignment",
"steps": "Import client-service assignment file.",
"expected": "Rows validate service enabled status, client scope and duplicates.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-011-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-011",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Bulk service assignment",
"steps": "Import client-service assignment file.",
"expected": "Rows validate service enabled status, client scope and duplicates.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-011-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-011",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Bulk service assignment",
"steps": "Import client-service assignment file.",
"expected": "Rows validate service enabled status, client scope and duplicates.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-011",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Bulk service assignment",
"steps": "Import client-service assignment file.",
"expected": "Rows validate service enabled status, client scope and duplicates.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-011-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-011",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Bulk service assignment",
"steps": "Import client-service assignment file.",
"expected": "Rows validate service enabled status, client scope and duplicates.",
"priority": "High",
"type": "UAT",
"route": "/services",
"variantId": "SVC-011-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-012",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Task template detail page",
"steps": "Open /services/templates/2 or valid id.",
"expected": "Page renders task template detail, not engagement detail; no 'row undefined' error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-012-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-012",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Task template detail page",
"steps": "Open /services/templates/2 or valid id.",
"expected": "Page renders task template detail, not engagement detail; no 'row undefined' error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-012-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-012",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Task template detail page",
"steps": "Open /services/templates/2 or valid id.",
"expected": "Page renders task template detail, not engagement detail; no 'row undefined' error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-012",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Task template detail page",
"steps": "Open /services/templates/2 or valid id.",
"expected": "Page renders task template detail, not engagement detail; no 'row undefined' error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-012-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-012",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Task template detail page",
"steps": "Open /services/templates/2 or valid id.",
"expected": "Page renders task template detail, not engagement detail; no 'row undefined' error.",
"priority": "Critical",
"type": "Regression",
"route": "/services",
"variantId": "SVC-012-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-013",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner/Staff",
"scenario": "Access as per permission",
"steps": "Access service management pages with different roles.",
"expected": "Each role sees only permitted actions; write actions blocked for read-only roles.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-013-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-013",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner/Staff",
"scenario": "Access as per permission",
"steps": "Access service management pages with different roles.",
"expected": "Each role sees only permitted actions; write actions blocked for read-only roles.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-013-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-013",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner/Staff",
"scenario": "Access as per permission",
"steps": "Access service management pages with different roles.",
"expected": "Each role sees only permitted actions; write actions blocked for read-only roles.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-013",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner/Staff",
"scenario": "Access as per permission",
"steps": "Access service management pages with different roles.",
"expected": "Each role sees only permitted actions; write actions blocked for read-only roles.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-013-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-013",
"sheet": "UAT_Services",
"module": "Services",
"role": "Partner/Staff",
"scenario": "Access as per permission",
"steps": "Access service management pages with different roles.",
"expected": "Each role sees only permitted actions; write actions blocked for read-only roles.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SVC-013-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SVC-014",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Duplicate subscription prevention",
"steps": "Assign same service to same client twice.",
"expected": "Prevented or handled safely with validation message.",
"priority": "High",
"type": "Negative",
"route": "/services",
"variantId": "SVC-014-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "SVC-014",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Duplicate subscription prevention",
"steps": "Assign same service to same client twice.",
"expected": "Prevented or handled safely with validation message.",
"priority": "High",
"type": "Negative",
"route": "/services",
"variantId": "SVC-014-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SVC-014",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Duplicate subscription prevention",
"steps": "Assign same service to same client twice.",
"expected": "Prevented or handled safely with validation message.",
"priority": "High",
"type": "Negative",
"route": "/services",
"variantId": "SVC-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SVC-014",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Duplicate subscription prevention",
"steps": "Assign same service to same client twice.",
"expected": "Prevented or handled safely with validation message.",
"priority": "High",
"type": "Negative",
"route": "/services",
"variantId": "SVC-014-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "SVC-014",
"sheet": "UAT_Services",
"module": "Services",
"role": "Firm Admin",
"scenario": "Duplicate subscription prevention",
"steps": "Assign same service to same client twice.",
"expected": "Prevented or handled safely with validation message.",
"priority": "High",
"type": "Negative",
"route": "/services",
"variantId": "SVC-014-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-001",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard shows workspace tabs and no duplicate unnecessary buttons.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WK-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-001",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard shows workspace tabs and no duplicate unnecessary buttons.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WK-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-001",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard shows workspace tabs and no duplicate unnecessary buttons.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WK-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-001",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard shows workspace tabs and no duplicate unnecessary buttons.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WK-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-001",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard shows workspace tabs and no duplicate unnecessary buttons.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WK-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-002",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Work board",
"steps": "Open /employee/work.",
"expected": "Assigned work appears in Pending/In Progress/Blocked/Completed grouping.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-002",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Work board",
"steps": "Open /employee/work.",
"expected": "Assigned work appears in Pending/In Progress/Blocked/Completed grouping.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-002",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Work board",
"steps": "Open /employee/work.",
"expected": "Assigned work appears in Pending/In Progress/Blocked/Completed grouping.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-002",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Work board",
"steps": "Open /employee/work.",
"expected": "Assigned work appears in Pending/In Progress/Blocked/Completed grouping.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-002",
"sheet": "UAT_Workspaces",
"module": "Staff Workspace",
"role": "Staff",
"scenario": "My Work board",
"steps": "Open /employee/work.",
"expected": "Assigned work appears in Pending/In Progress/Blocked/Completed grouping.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-003",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Staff",
"scenario": "Open work detail",
"steps": "Click work card to /work/engagements/{id}.",
"expected": "Staff sees own tasks, documents side panel and permitted communication.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-003",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Staff",
"scenario": "Open work detail",
"steps": "Click work card to /work/engagements/{id}.",
"expected": "Staff sees own tasks, documents side panel and permitted communication.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-003",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Staff",
"scenario": "Open work detail",
"steps": "Click work card to /work/engagements/{id}.",
"expected": "Staff sees own tasks, documents side panel and permitted communication.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-003",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Staff",
"scenario": "Open work detail",
"steps": "Click work card to /work/engagements/{id}.",
"expected": "Staff sees own tasks, documents side panel and permitted communication.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-003",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Staff",
"scenario": "Open work detail",
"steps": "Click work card to /work/engagements/{id}.",
"expected": "Staff sees own tasks, documents side panel and permitted communication.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-004",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Manager",
"scenario": "Manager open work detail",
"steps": "Click team work card.",
"expected": "Manager sees team assignment view and permitted status/priority updates.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-004",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Manager",
"scenario": "Manager open work detail",
"steps": "Click team work card.",
"expected": "Manager sees team assignment view and permitted status/priority updates.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-004",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Manager",
"scenario": "Manager open work detail",
"steps": "Click team work card.",
"expected": "Manager sees team assignment view and permitted status/priority updates.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-004",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Manager",
"scenario": "Manager open work detail",
"steps": "Click team work card.",
"expected": "Manager sees team assignment view and permitted status/priority updates.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-004",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Manager",
"scenario": "Manager open work detail",
"steps": "Click team work card.",
"expected": "Manager sees team assignment view and permitted status/priority updates.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-005",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Partner",
"scenario": "Partner open engagement detail",
"steps": "Click review board item.",
"expected": "Partner sees engagement wording, tasks, documents, review actions if implemented.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-005",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Partner",
"scenario": "Partner open engagement detail",
"steps": "Click review board item.",
"expected": "Partner sees engagement wording, tasks, documents, review actions if implemented.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-005",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Partner",
"scenario": "Partner open engagement detail",
"steps": "Click review board item.",
"expected": "Partner sees engagement wording, tasks, documents, review actions if implemented.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-005",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Partner",
"scenario": "Partner open engagement detail",
"steps": "Click review board item.",
"expected": "Partner sees engagement wording, tasks, documents, review actions if implemented.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-005",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Partner",
"scenario": "Partner open engagement detail",
"steps": "Click review board item.",
"expected": "Partner sees engagement wording, tasks, documents, review actions if implemented.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-006",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Client",
"scenario": "Client open compliance/service detail",
"steps": "Click compliance item.",
"expected": "Client sees service/compliance-safe data only, no internal notes.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-006",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Client",
"scenario": "Client open compliance/service detail",
"steps": "Click compliance item.",
"expected": "Client sees service/compliance-safe data only, no internal notes.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-006",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Client",
"scenario": "Client open compliance/service detail",
"steps": "Click compliance item.",
"expected": "Client sees service/compliance-safe data only, no internal notes.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-006",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Client",
"scenario": "Client open compliance/service detail",
"steps": "Click compliance item.",
"expected": "Client sees service/compliance-safe data only, no internal notes.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-006",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Client",
"scenario": "Client open compliance/service detail",
"steps": "Click compliance item.",
"expected": "Client sees service/compliance-safe data only, no internal notes.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-007",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Consultant",
"scenario": "Consultant open assignment detail",
"steps": "Click consultant assignment.",
"expected": "Consultant sees only referred/shared work and shared documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "WK-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-007",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Consultant",
"scenario": "Consultant open assignment detail",
"steps": "Click consultant assignment.",
"expected": "Consultant sees only referred/shared work and shared documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "WK-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-007",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Consultant",
"scenario": "Consultant open assignment detail",
"steps": "Click consultant assignment.",
"expected": "Consultant sees only referred/shared work and shared documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "WK-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-007",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Consultant",
"scenario": "Consultant open assignment detail",
"steps": "Click consultant assignment.",
"expected": "Consultant sees only referred/shared work and shared documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "WK-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-007",
"sheet": "UAT_Workspaces",
"module": "Unified Work Detail",
"role": "Consultant",
"scenario": "Consultant open assignment detail",
"steps": "Click consultant assignment.",
"expected": "Consultant sees only referred/shared work and shared documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "WK-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-008",
"sheet": "UAT_Workspaces",
"module": "Documents",
"role": "Staff/Manager/Partner",
"scenario": "Engagement documents side panel",
"steps": "Open unified detail with documents.",
"expected": "Relevant engagement documents appear; downloads respect permission and role visibility.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-008",
"sheet": "UAT_Workspaces",
"module": "Documents",
"role": "Staff/Manager/Partner",
"scenario": "Engagement documents side panel",
"steps": "Open unified detail with documents.",
"expected": "Relevant engagement documents appear; downloads respect permission and role visibility.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-008",
"sheet": "UAT_Workspaces",
"module": "Documents",
"role": "Staff/Manager/Partner",
"scenario": "Engagement documents side panel",
"steps": "Open unified detail with documents.",
"expected": "Relevant engagement documents appear; downloads respect permission and role visibility.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-008",
"sheet": "UAT_Workspaces",
"module": "Documents",
"role": "Staff/Manager/Partner",
"scenario": "Engagement documents side panel",
"steps": "Open unified detail with documents.",
"expected": "Relevant engagement documents appear; downloads respect permission and role visibility.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-008",
"sheet": "UAT_Workspaces",
"module": "Documents",
"role": "Staff/Manager/Partner",
"scenario": "Engagement documents side panel",
"steps": "Open unified detail with documents.",
"expected": "Relevant engagement documents appear; downloads respect permission and role visibility.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WK-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-009",
"sheet": "UAT_Workspaces",
"module": "Communication",
"role": "All roles",
"scenario": "Communication visibility",
"steps": "Add internal/client/consultant comments.",
"expected": "Internal notes hidden from client/consultant; client-visible notes visible to client only where allowed.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-009",
"sheet": "UAT_Workspaces",
"module": "Communication",
"role": "All roles",
"scenario": "Communication visibility",
"steps": "Add internal/client/consultant comments.",
"expected": "Internal notes hidden from client/consultant; client-visible notes visible to client only where allowed.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-009",
"sheet": "UAT_Workspaces",
"module": "Communication",
"role": "All roles",
"scenario": "Communication visibility",
"steps": "Add internal/client/consultant comments.",
"expected": "Internal notes hidden from client/consultant; client-visible notes visible to client only where allowed.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-009",
"sheet": "UAT_Workspaces",
"module": "Communication",
"role": "All roles",
"scenario": "Communication visibility",
"steps": "Add internal/client/consultant comments.",
"expected": "Internal notes hidden from client/consultant; client-visible notes visible to client only where allowed.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-009",
"sheet": "UAT_Workspaces",
"module": "Communication",
"role": "All roles",
"scenario": "Communication visibility",
"steps": "Add internal/client/consultant comments.",
"expected": "Internal notes hidden from client/consultant; client-visible notes visible to client only where allowed.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "WK-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WK-010",
"sheet": "UAT_Workspaces",
"module": "Task Status",
"role": "Staff",
"scenario": "Task status update",
"steps": "Move/update task status from detail page.",
"expected": "Status saves and appears correctly on staff/manager/partner boards.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "WK-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WK-010",
"sheet": "UAT_Workspaces",
"module": "Task Status",
"role": "Staff",
"scenario": "Task status update",
"steps": "Move/update task status from detail page.",
"expected": "Status saves and appears correctly on staff/manager/partner boards.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "WK-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WK-010",
"sheet": "UAT_Workspaces",
"module": "Task Status",
"role": "Staff",
"scenario": "Task status update",
"steps": "Move/update task status from detail page.",
"expected": "Status saves and appears correctly on staff/manager/partner boards.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "WK-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WK-010",
"sheet": "UAT_Workspaces",
"module": "Task Status",
"role": "Staff",
"scenario": "Task status update",
"steps": "Move/update task status from detail page.",
"expected": "Status saves and appears correctly on staff/manager/partner boards.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "WK-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WK-010",
"sheet": "UAT_Workspaces",
"module": "Task Status",
"role": "Staff",
"scenario": "Task status update",
"steps": "Move/update task status from detail page.",
"expected": "Status saves and appears correctly on staff/manager/partner boards.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "WK-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-001",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Manager dashboard",
"steps": "Open /manager/dashboard.",
"expected": "Shows total, unassigned, in progress, blocked, overdue, completed and team snapshot.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-001",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Manager dashboard",
"steps": "Open /manager/dashboard.",
"expected": "Shows total, unassigned, in progress, blocked, overdue, completed and team snapshot.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-001",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Manager dashboard",
"steps": "Open /manager/dashboard.",
"expected": "Shows total, unassigned, in progress, blocked, overdue, completed and team snapshot.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-001",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Manager dashboard",
"steps": "Open /manager/dashboard.",
"expected": "Shows total, unassigned, in progress, blocked, overdue, completed and team snapshot.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-001",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Manager dashboard",
"steps": "Open /manager/dashboard.",
"expected": "Shows total, unassigned, in progress, blocked, overdue, completed and team snapshot.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-002",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team Work Board",
"steps": "Open /manager/work.",
"expected": "Shows team task columns and manager actions.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-002",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team Work Board",
"steps": "Open /manager/work.",
"expected": "Shows team task columns and manager actions.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-002",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team Work Board",
"steps": "Open /manager/work.",
"expected": "Shows team task columns and manager actions.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-002",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team Work Board",
"steps": "Open /manager/work.",
"expected": "Shows team task columns and manager actions.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-002",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team Work Board",
"steps": "Open /manager/work.",
"expected": "Shows team task columns and manager actions.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-003",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Detailed Allocation",
"steps": "Open /employees/work.",
"expected": "Manager top tabs visible and active; allocation functions available.",
"priority": "Medium",
"type": "Regression",
"route": "/work",
"variantId": "MP-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-003",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Detailed Allocation",
"steps": "Open /employees/work.",
"expected": "Manager top tabs visible and active; allocation functions available.",
"priority": "Medium",
"type": "Regression",
"route": "/work",
"variantId": "MP-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-003",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Detailed Allocation",
"steps": "Open /employees/work.",
"expected": "Manager top tabs visible and active; allocation functions available.",
"priority": "Medium",
"type": "Regression",
"route": "/work",
"variantId": "MP-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-003",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Detailed Allocation",
"steps": "Open /employees/work.",
"expected": "Manager top tabs visible and active; allocation functions available.",
"priority": "Medium",
"type": "Regression",
"route": "/work",
"variantId": "MP-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-003",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Detailed Allocation",
"steps": "Open /employees/work.",
"expected": "Manager top tabs visible and active; allocation functions available.",
"priority": "Medium",
"type": "Regression",
"route": "/work",
"variantId": "MP-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-004",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Engagement Progress",
"steps": "Open /employees/progress.",
"expected": "Manager top tabs visible; progress renders without get_db or row errors.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "MP-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-004",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Engagement Progress",
"steps": "Open /employees/progress.",
"expected": "Manager top tabs visible; progress renders without get_db or row errors.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "MP-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-004",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Engagement Progress",
"steps": "Open /employees/progress.",
"expected": "Manager top tabs visible; progress renders without get_db or row errors.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "MP-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-004",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Engagement Progress",
"steps": "Open /employees/progress.",
"expected": "Manager top tabs visible; progress renders without get_db or row errors.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "MP-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-004",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Engagement Progress",
"steps": "Open /employees/progress.",
"expected": "Manager top tabs visible; progress renders without get_db or row errors.",
"priority": "High",
"type": "Regression",
"route": "/work",
"variantId": "MP-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-005",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team attendance",
"steps": "Open /employees/attendance.",
"expected": "Manager can view team attendance only for permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/attendance",
"variantId": "MP-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-005",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team attendance",
"steps": "Open /employees/attendance.",
"expected": "Manager can view team attendance only for permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/attendance",
"variantId": "MP-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-005",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team attendance",
"steps": "Open /employees/attendance.",
"expected": "Manager can view team attendance only for permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/attendance",
"variantId": "MP-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-005",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team attendance",
"steps": "Open /employees/attendance.",
"expected": "Manager can view team attendance only for permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/attendance",
"variantId": "MP-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-005",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team attendance",
"steps": "Open /employees/attendance.",
"expected": "Manager can view team attendance only for permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/attendance",
"variantId": "MP-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-006",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team leave",
"steps": "Open /employees/leave.",
"expected": "Manager can view/approve/act only within permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/leaves",
"variantId": "MP-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-006",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team leave",
"steps": "Open /employees/leave.",
"expected": "Manager can view/approve/act only within permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/leaves",
"variantId": "MP-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-006",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team leave",
"steps": "Open /employees/leave.",
"expected": "Manager can view/approve/act only within permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/leaves",
"variantId": "MP-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-006",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team leave",
"steps": "Open /employees/leave.",
"expected": "Manager can view/approve/act only within permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/leaves",
"variantId": "MP-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-006",
"sheet": "UAT_Manager_Partner",
"module": "Manager Workspace",
"role": "Manager",
"scenario": "Team leave",
"steps": "Open /employees/leave.",
"expected": "Manager can view/approve/act only within permitted branch/team.",
"priority": "High",
"type": "UAT",
"route": "/employee/leaves",
"variantId": "MP-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-007",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Partner dashboard",
"steps": "Open /partner/dashboard.",
"expected": "Partner dashboard summary loads.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-007",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Partner dashboard",
"steps": "Open /partner/dashboard.",
"expected": "Partner dashboard summary loads.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-007",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Partner dashboard",
"steps": "Open /partner/dashboard.",
"expected": "Partner dashboard summary loads.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-007",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Partner dashboard",
"steps": "Open /partner/dashboard.",
"expected": "Partner dashboard summary loads.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-007",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Partner dashboard",
"steps": "Open /partner/dashboard.",
"expected": "Partner dashboard summary loads.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-008",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review board",
"steps": "Open /partner/reviews.",
"expected": "Shows pending review, blocked and overdue engagement items.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-008",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review board",
"steps": "Open /partner/reviews.",
"expected": "Shows pending review, blocked and overdue engagement items.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-008",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review board",
"steps": "Open /partner/reviews.",
"expected": "Shows pending review, blocked and overdue engagement items.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-008",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review board",
"steps": "Open /partner/reviews.",
"expected": "Shows pending review, blocked and overdue engagement items.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-008",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review board",
"steps": "Open /partner/reviews.",
"expected": "Shows pending review, blocked and overdue engagement items.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-009",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "My Clients",
"steps": "Open /partner/clients.",
"expected": "Partner sees own client portfolio only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "MP-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-009",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "My Clients",
"steps": "Open /partner/clients.",
"expected": "Partner sees own client portfolio only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "MP-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-009",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "My Clients",
"steps": "Open /partner/clients.",
"expected": "Partner sees own client portfolio only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "MP-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-009",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "My Clients",
"steps": "Open /partner/clients.",
"expected": "Partner sees own client portfolio only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "MP-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-009",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "My Clients",
"steps": "Open /partner/clients.",
"expected": "Partner sees own client portfolio only unless higher permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/work",
"variantId": "MP-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "MP-010",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review actions",
"steps": "Approve/send rework/request clarification from engagement detail.",
"expected": "Review note is saved to task communication and status updates correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "MP-010",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review actions",
"steps": "Approve/send rework/request clarification from engagement detail.",
"expected": "Review note is saved to task communication and status updates correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "MP-010",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review actions",
"steps": "Approve/send rework/request clarification from engagement detail.",
"expected": "Review note is saved to task communication and status updates correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "MP-010",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review actions",
"steps": "Approve/send rework/request clarification from engagement detail.",
"expected": "Review note is saved to task communication and status updates correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "MP-010",
"sheet": "UAT_Manager_Partner",
"module": "Partner Workspace",
"role": "Partner",
"scenario": "Review actions",
"steps": "Approve/send rework/request clarification from engagement detail.",
"expected": "Review note is saved to task communication and status updates correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "MP-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-001",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Create consultant",
"steps": "Create consultant master/profile.",
"expected": "Consultant user/profile is created/linked and visible in Consultant List.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-001",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Create consultant",
"steps": "Create consultant master/profile.",
"expected": "Consultant user/profile is created/linked and visible in Consultant List.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-001",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Create consultant",
"steps": "Create consultant master/profile.",
"expected": "Consultant user/profile is created/linked and visible in Consultant List.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-001",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Create consultant",
"steps": "Create consultant master/profile.",
"expected": "Consultant user/profile is created/linked and visible in Consultant List.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-001",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Create consultant",
"steps": "Create consultant master/profile.",
"expected": "Consultant user/profile is created/linked and visible in Consultant List.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-002",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Consultant dashboard",
"steps": "Login as consultant.",
"expected": "Consultant lands at /consultant/dashboard with portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-002",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Consultant dashboard",
"steps": "Login as consultant.",
"expected": "Consultant lands at /consultant/dashboard with portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-002",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Consultant dashboard",
"steps": "Login as consultant.",
"expected": "Consultant lands at /consultant/dashboard with portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-002",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Consultant dashboard",
"steps": "Login as consultant.",
"expected": "Consultant lands at /consultant/dashboard with portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-002",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Consultant dashboard",
"steps": "Login as consultant.",
"expected": "Consultant lands at /consultant/dashboard with portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-003",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "My Work Board",
"steps": "Open /consultant/work.",
"expected": "Only referred/assigned consultant-visible tasks appear.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-003",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "My Work Board",
"steps": "Open /consultant/work.",
"expected": "Only referred/assigned consultant-visible tasks appear.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-003",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "My Work Board",
"steps": "Open /consultant/work.",
"expected": "Only referred/assigned consultant-visible tasks appear.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-003",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "My Work Board",
"steps": "Open /consultant/work.",
"expected": "Only referred/assigned consultant-visible tasks appear.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-003",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "My Work Board",
"steps": "Open /consultant/work.",
"expected": "Only referred/assigned consultant-visible tasks appear.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-004",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Assignment detail",
"steps": "Open /consultant/assignments/{task_id} or unified detail link.",
"expected": "Consultant can view assignment and submit reply/update without internal data exposure.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-004",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Assignment detail",
"steps": "Open /consultant/assignments/{task_id} or unified detail link.",
"expected": "Consultant can view assignment and submit reply/update without internal data exposure.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-004",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Assignment detail",
"steps": "Open /consultant/assignments/{task_id} or unified detail link.",
"expected": "Consultant can view assignment and submit reply/update without internal data exposure.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-004",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Assignment detail",
"steps": "Open /consultant/assignments/{task_id} or unified detail link.",
"expected": "Consultant can view assignment and submit reply/update without internal data exposure.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-004",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Assignment detail",
"steps": "Open /consultant/assignments/{task_id} or unified detail link.",
"expected": "Consultant can view assignment and submit reply/update without internal data exposure.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-005",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Shared documents",
"steps": "Open /consultant/documents.",
"expected": "Only shared/allowed documents are listed.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-005",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Shared documents",
"steps": "Open /consultant/documents.",
"expected": "Only shared/allowed documents are listed.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-005",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Shared documents",
"steps": "Open /consultant/documents.",
"expected": "Only shared/allowed documents are listed.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-005",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Shared documents",
"steps": "Open /consultant/documents.",
"expected": "Only shared/allowed documents are listed.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-005",
"sheet": "UAT_Consultants_Leads",
"module": "Consultant Portal",
"role": "Consultant",
"scenario": "Shared documents",
"steps": "Open /consultant/documents.",
"expected": "Only shared/allowed documents are listed.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-006",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Service request/lead creation",
"steps": "Consultant creates service request/lead for a client needing audit/filing from firm.",
"expected": "Lead/request is captured and visible to firm in Consultant Service Requests.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-006",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Service request/lead creation",
"steps": "Consultant creates service request/lead for a client needing audit/filing from firm.",
"expected": "Lead/request is captured and visible to firm in Consultant Service Requests.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-006",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Service request/lead creation",
"steps": "Consultant creates service request/lead for a client needing audit/filing from firm.",
"expected": "Lead/request is captured and visible to firm in Consultant Service Requests.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-006",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Service request/lead creation",
"steps": "Consultant creates service request/lead for a client needing audit/filing from firm.",
"expected": "Lead/request is captured and visible to firm in Consultant Service Requests.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-006",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Service request/lead creation",
"steps": "Consultant creates service request/lead for a client needing audit/filing from firm.",
"expected": "Lead/request is captured and visible to firm in Consultant Service Requests.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-007",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin/Partner",
"scenario": "Lead conversion",
"steps": "Firm reviews consultant-generated service request and converts/links it to client/service/engagement.",
"expected": "Conversion request status updates and no duplicate client is created unless intentionally approved.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-007",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin/Partner",
"scenario": "Lead conversion",
"steps": "Firm reviews consultant-generated service request and converts/links it to client/service/engagement.",
"expected": "Conversion request status updates and no duplicate client is created unless intentionally approved.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-007",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin/Partner",
"scenario": "Lead conversion",
"steps": "Firm reviews consultant-generated service request and converts/links it to client/service/engagement.",
"expected": "Conversion request status updates and no duplicate client is created unless intentionally approved.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-007",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin/Partner",
"scenario": "Lead conversion",
"steps": "Firm reviews consultant-generated service request and converts/links it to client/service/engagement.",
"expected": "Conversion request status updates and no duplicate client is created unless intentionally approved.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-007",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin/Partner",
"scenario": "Lead conversion",
"steps": "Firm reviews consultant-generated service request and converts/links it to client/service/engagement.",
"expected": "Conversion request status updates and no duplicate client is created unless intentionally approved.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-008",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Bookkeeping client to audit firm referral",
"steps": "Consultant managing bookkeeping refers same client to audit firm for audit.",
"expected": "Firm receives referral; consultant cannot access audit engagement unless shared.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-008",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Bookkeeping client to audit firm referral",
"steps": "Consultant managing bookkeeping refers same client to audit firm for audit.",
"expected": "Firm receives referral; consultant cannot access audit engagement unless shared.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-008",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Bookkeeping client to audit firm referral",
"steps": "Consultant managing bookkeeping refers same client to audit firm for audit.",
"expected": "Firm receives referral; consultant cannot access audit engagement unless shared.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-008",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Bookkeeping client to audit firm referral",
"steps": "Consultant managing bookkeeping refers same client to audit firm for audit.",
"expected": "Firm receives referral; consultant cannot access audit engagement unless shared.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-008",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Bookkeeping client to audit firm referral",
"steps": "Consultant managing bookkeeping refers same client to audit firm for audit.",
"expected": "Firm receives referral; consultant cannot access audit engagement unless shared.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-009",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Consultant menu entries",
"steps": "Open Firm Administration \u2192 Consultants.",
"expected": "Consultant List, Add Consultant, Service Requests, Conversions are available if permissions allow.",
"priority": "Medium",
"type": "Regression",
"route": "/consultants",
"variantId": "CON-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-009",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Consultant menu entries",
"steps": "Open Firm Administration \u2192 Consultants.",
"expected": "Consultant List, Add Consultant, Service Requests, Conversions are available if permissions allow.",
"priority": "Medium",
"type": "Regression",
"route": "/consultants",
"variantId": "CON-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-009",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Consultant menu entries",
"steps": "Open Firm Administration \u2192 Consultants.",
"expected": "Consultant List, Add Consultant, Service Requests, Conversions are available if permissions allow.",
"priority": "Medium",
"type": "Regression",
"route": "/consultants",
"variantId": "CON-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-009",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Consultant menu entries",
"steps": "Open Firm Administration \u2192 Consultants.",
"expected": "Consultant List, Add Consultant, Service Requests, Conversions are available if permissions allow.",
"priority": "Medium",
"type": "Regression",
"route": "/consultants",
"variantId": "CON-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-009",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Consultant menu entries",
"steps": "Open Firm Administration \u2192 Consultants.",
"expected": "Consultant List, Add Consultant, Service Requests, Conversions are available if permissions allow.",
"priority": "Medium",
"type": "Regression",
"route": "/consultants",
"variantId": "CON-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-010",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Negative",
"scenario": "Cross-client consultant leakage",
"steps": "Consultant attempts direct URL to another consultant/client assignment.",
"expected": "Access blocked or returns not found.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-010",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Negative",
"scenario": "Cross-client consultant leakage",
"steps": "Consultant attempts direct URL to another consultant/client assignment.",
"expected": "Access blocked or returns not found.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-010",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Negative",
"scenario": "Cross-client consultant leakage",
"steps": "Consultant attempts direct URL to another consultant/client assignment.",
"expected": "Access blocked or returns not found.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-010",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Negative",
"scenario": "Cross-client consultant leakage",
"steps": "Consultant attempts direct URL to another consultant/client assignment.",
"expected": "Access blocked or returns not found.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-010",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Negative",
"scenario": "Cross-client consultant leakage",
"steps": "Consultant attempts direct URL to another consultant/client assignment.",
"expected": "Access blocked or returns not found.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-011",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Consultant cannot edit plan/limits",
"steps": "Attempt to edit firm plan or conversion limits as Consultant.",
"expected": "Blocked; only Firm Admin can manage these.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-011-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-011",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Consultant cannot edit plan/limits",
"steps": "Attempt to edit firm plan or conversion limits as Consultant.",
"expected": "Blocked; only Firm Admin can manage these.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-011-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-011",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Consultant cannot edit plan/limits",
"steps": "Attempt to edit firm plan or conversion limits as Consultant.",
"expected": "Blocked; only Firm Admin can manage these.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-011",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Consultant cannot edit plan/limits",
"steps": "Attempt to edit firm plan or conversion limits as Consultant.",
"expected": "Blocked; only Firm Admin can manage these.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-011-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-011",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Consultant",
"scenario": "Consultant cannot edit plan/limits",
"steps": "Attempt to edit firm plan or conversion limits as Consultant.",
"expected": "Blocked; only Firm Admin can manage these.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-011-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-012",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Duplicate consultant email/mobile",
"steps": "Try creating consultant with duplicate email/mobile.",
"expected": "Validation warning or prevention shown.",
"priority": "Medium",
"type": "Negative",
"route": "/consultants",
"variantId": "CON-012-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-012",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Duplicate consultant email/mobile",
"steps": "Try creating consultant with duplicate email/mobile.",
"expected": "Validation warning or prevention shown.",
"priority": "Medium",
"type": "Negative",
"route": "/consultants",
"variantId": "CON-012-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-012",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Duplicate consultant email/mobile",
"steps": "Try creating consultant with duplicate email/mobile.",
"expected": "Validation warning or prevention shown.",
"priority": "Medium",
"type": "Negative",
"route": "/consultants",
"variantId": "CON-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-012",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Duplicate consultant email/mobile",
"steps": "Try creating consultant with duplicate email/mobile.",
"expected": "Validation warning or prevention shown.",
"priority": "Medium",
"type": "Negative",
"route": "/consultants",
"variantId": "CON-012-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-012",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Duplicate consultant email/mobile",
"steps": "Try creating consultant with duplicate email/mobile.",
"expected": "Validation warning or prevention shown.",
"priority": "Medium",
"type": "Negative",
"route": "/consultants",
"variantId": "CON-012-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-013",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Staff/Client",
"scenario": "Staff or client direct access to consultant admin URL",
"steps": "Login as Staff or Client and open /consultants admin URLs.",
"expected": "Blocked; unauthorized access redirected.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-013-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-013",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Staff/Client",
"scenario": "Staff or client direct access to consultant admin URL",
"steps": "Login as Staff or Client and open /consultants admin URLs.",
"expected": "Blocked; unauthorized access redirected.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-013-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-013",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Staff/Client",
"scenario": "Staff or client direct access to consultant admin URL",
"steps": "Login as Staff or Client and open /consultants admin URLs.",
"expected": "Blocked; unauthorized access redirected.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-013",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Staff/Client",
"scenario": "Staff or client direct access to consultant admin URL",
"steps": "Login as Staff or Client and open /consultants admin URLs.",
"expected": "Blocked; unauthorized access redirected.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-013-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-013",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Staff/Client",
"scenario": "Staff or client direct access to consultant admin URL",
"steps": "Login as Staff or Client and open /consultants admin URLs.",
"expected": "Blocked; unauthorized access redirected.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "CON-013-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-014",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject service request with notes",
"steps": "Review service request and approve or reject with reason.",
"expected": "Status and reason saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-014-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-014",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject service request with notes",
"steps": "Review service request and approve or reject with reason.",
"expected": "Status and reason saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-014-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-014",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject service request with notes",
"steps": "Review service request and approve or reject with reason.",
"expected": "Status and reason saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-014",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject service request with notes",
"steps": "Review service request and approve or reject with reason.",
"expected": "Status and reason saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-014-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-014",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject service request with notes",
"steps": "Review service request and approve or reject with reason.",
"expected": "Status and reason saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-014-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CON-015",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject conversion request",
"steps": "Firm approves or rejects conversion.",
"expected": "Firm client created/linked or rejected without duplicates.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-015-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CON-015",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject conversion request",
"steps": "Firm approves or rejects conversion.",
"expected": "Firm client created/linked or rejected without duplicates.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-015-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CON-015",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject conversion request",
"steps": "Firm approves or rejects conversion.",
"expected": "Firm client created/linked or rejected without duplicates.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CON-015",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject conversion request",
"steps": "Firm approves or rejects conversion.",
"expected": "Firm client created/linked or rejected without duplicates.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-015-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CON-015",
"sheet": "UAT_Consultants_Leads",
"module": "Consultants",
"role": "Firm Admin",
"scenario": "Approve/reject conversion request",
"steps": "Firm approves or rejects conversion.",
"expected": "Firm client created/linked or rejected without duplicates.",
"priority": "High",
"type": "UAT",
"route": "/consultants",
"variantId": "CON-015-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CP-001",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Client dashboard",
"steps": "Open /client/dashboard.",
"expected": "Overview shows compliance summary and portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CP-001",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Client dashboard",
"steps": "Open /client/dashboard.",
"expected": "Overview shows compliance summary and portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CP-001",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Client dashboard",
"steps": "Open /client/dashboard.",
"expected": "Overview shows compliance summary and portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CP-001",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Client dashboard",
"steps": "Open /client/dashboard.",
"expected": "Overview shows compliance summary and portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CP-001",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Client dashboard",
"steps": "Open /client/dashboard.",
"expected": "Overview shows compliance summary and portal tabs.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CP-002",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "My Compliance",
"steps": "Open /client/compliance.",
"expected": "Shows Pending from Client / With Firm / Clarification Required / Filed Completed style statuses.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CP-002",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "My Compliance",
"steps": "Open /client/compliance.",
"expected": "Shows Pending from Client / With Firm / Clarification Required / Filed Completed style statuses.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CP-002",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "My Compliance",
"steps": "Open /client/compliance.",
"expected": "Shows Pending from Client / With Firm / Clarification Required / Filed Completed style statuses.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CP-002",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "My Compliance",
"steps": "Open /client/compliance.",
"expected": "Shows Pending from Client / With Firm / Clarification Required / Filed Completed style statuses.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CP-002",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "My Compliance",
"steps": "Open /client/compliance.",
"expected": "Shows Pending from Client / With Firm / Clarification Required / Filed Completed style statuses.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CP-003",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Service detail",
"steps": "Open /client/engagements/{id} or unified detail.",
"expected": "Client sees service status, required actions, shared docs and messages only.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CP-003",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Service detail",
"steps": "Open /client/engagements/{id} or unified detail.",
"expected": "Client sees service status, required actions, shared docs and messages only.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CP-003",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Service detail",
"steps": "Open /client/engagements/{id} or unified detail.",
"expected": "Client sees service status, required actions, shared docs and messages only.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CP-003",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Service detail",
"steps": "Open /client/engagements/{id} or unified detail.",
"expected": "Client sees service status, required actions, shared docs and messages only.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CP-003",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Service detail",
"steps": "Open /client/engagements/{id} or unified detail.",
"expected": "Client sees service status, required actions, shared docs and messages only.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CP-004",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Document upload/download",
"steps": "Open /client/documents.",
"expected": "Client can view/upload/download allowed documents; internal documents hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CP-004",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Document upload/download",
"steps": "Open /client/documents.",
"expected": "Client can view/upload/download allowed documents; internal documents hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CP-004",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Document upload/download",
"steps": "Open /client/documents.",
"expected": "Client can view/upload/download allowed documents; internal documents hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CP-004",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Document upload/download",
"steps": "Open /client/documents.",
"expected": "Client can view/upload/download allowed documents; internal documents hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CP-004",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Document upload/download",
"steps": "Open /client/documents.",
"expected": "Client can view/upload/download allowed documents; internal documents hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CP-005",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Messages",
"steps": "Open /client/messages and reply to clarification.",
"expected": "Reply is saved and visible to firm users with proper visibility.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CP-005",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Messages",
"steps": "Open /client/messages and reply to clarification.",
"expected": "Reply is saved and visible to firm users with proper visibility.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CP-005",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Messages",
"steps": "Open /client/messages and reply to clarification.",
"expected": "Reply is saved and visible to firm users with proper visibility.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CP-005",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Messages",
"steps": "Open /client/messages and reply to clarification.",
"expected": "Reply is saved and visible to firm users with proper visibility.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CP-005",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Messages",
"steps": "Open /client/messages and reply to clarification.",
"expected": "Reply is saved and visible to firm users with proper visibility.",
"priority": "High",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CP-006",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Profile",
"steps": "Open /client/profile.",
"expected": "Profile loads with client tabs and permitted fields only.",
"priority": "Medium",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CP-006",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Profile",
"steps": "Open /client/profile.",
"expected": "Profile loads with client tabs and permitted fields only.",
"priority": "Medium",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CP-006",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Profile",
"steps": "Open /client/profile.",
"expected": "Profile loads with client tabs and permitted fields only.",
"priority": "Medium",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CP-006",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Profile",
"steps": "Open /client/profile.",
"expected": "Profile loads with client tabs and permitted fields only.",
"priority": "Medium",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CP-006",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Profile",
"steps": "Open /client/profile.",
"expected": "Profile loads with client tabs and permitted fields only.",
"priority": "Medium",
"type": "UAT",
"route": "/client/dashboard",
"variantId": "CP-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "CP-007",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Alerts",
"steps": "Open /alerts from client portal.",
"expected": "Only client alerts shown.",
"priority": "High",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "CP-007",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Alerts",
"steps": "Open /alerts from client portal.",
"expected": "Only client alerts shown.",
"priority": "High",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "CP-007",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Alerts",
"steps": "Open /alerts from client portal.",
"expected": "Only client alerts shown.",
"priority": "High",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "CP-007",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Alerts",
"steps": "Open /alerts from client portal.",
"expected": "Only client alerts shown.",
"priority": "High",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "CP-007",
"sheet": "UAT_Client_Portal",
"module": "Client Portal",
"role": "Client",
"scenario": "Alerts",
"steps": "Open /alerts from client portal.",
"expected": "Only client alerts shown.",
"priority": "High",
"type": "VAPT",
"route": "/client/dashboard",
"variantId": "CP-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-001",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin/Manager",
"scenario": "Create employee",
"steps": "Create staff/manager/partner-linked employee.",
"expected": "Employee profile and user relationship is created as per business logic.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-001",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin/Manager",
"scenario": "Create employee",
"steps": "Create staff/manager/partner-linked employee.",
"expected": "Employee profile and user relationship is created as per business logic.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-001",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin/Manager",
"scenario": "Create employee",
"steps": "Create staff/manager/partner-linked employee.",
"expected": "Employee profile and user relationship is created as per business logic.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-001",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin/Manager",
"scenario": "Create employee",
"steps": "Create staff/manager/partner-linked employee.",
"expected": "Employee profile and user relationship is created as per business logic.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-001",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin/Manager",
"scenario": "Create employee",
"steps": "Create staff/manager/partner-linked employee.",
"expected": "Employee profile and user relationship is created as per business logic.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-002",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Create employee with linked user",
"steps": "Create employee and link to existing user.",
"expected": "User linked correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-002",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Create employee with linked user",
"steps": "Create employee and link to existing user.",
"expected": "User linked correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-002",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Create employee with linked user",
"steps": "Create employee and link to existing user.",
"expected": "User linked correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-002",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Create employee with linked user",
"steps": "Create employee and link to existing user.",
"expected": "User linked correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-002",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Create employee with linked user",
"steps": "Create employee and link to existing user.",
"expected": "User linked correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-003",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Filter linked/unlinked employees",
"steps": "Use filter on employee list.",
"expected": "Shows correct filtered set.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-003",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Filter linked/unlinked employees",
"steps": "Use filter on employee list.",
"expected": "Shows correct filtered set.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-003",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Filter linked/unlinked employees",
"steps": "Use filter on employee list.",
"expected": "Shows correct filtered set.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-003",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Filter linked/unlinked employees",
"steps": "Use filter on employee list.",
"expected": "Shows correct filtered set.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-003",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Filter linked/unlinked employees",
"steps": "Use filter on employee list.",
"expected": "Shows correct filtered set.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-004",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Change employee status",
"steps": "Change status to active/inactive/relieved.",
"expected": "Status updated and access adjusted accordingly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-004",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Change employee status",
"steps": "Change status to active/inactive/relieved.",
"expected": "Status updated and access adjusted accordingly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-004",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Change employee status",
"steps": "Change status to active/inactive/relieved.",
"expected": "Status updated and access adjusted accordingly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-004",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Change employee status",
"steps": "Change status to active/inactive/relieved.",
"expected": "Status updated and access adjusted accordingly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-004",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Change employee status",
"steps": "Change status to active/inactive/relieved.",
"expected": "Status updated and access adjusted accordingly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-005",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My profile",
"steps": "Open /employee/profile.",
"expected": "Profile opens with My Workspace top menu and no page compression.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-005",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My profile",
"steps": "Open /employee/profile.",
"expected": "Profile opens with My Workspace top menu and no page compression.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-005",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My profile",
"steps": "Open /employee/profile.",
"expected": "Profile opens with My Workspace top menu and no page compression.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-005",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My profile",
"steps": "Open /employee/profile.",
"expected": "Profile opens with My Workspace top menu and no page compression.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-005",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My profile",
"steps": "Open /employee/profile.",
"expected": "Profile opens with My Workspace top menu and no page compression.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-006",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard loads with workspace tabs.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-006",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard loads with workspace tabs.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-006",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard loads with workspace tabs.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-006",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard loads with workspace tabs.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-006",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My Workspace dashboard",
"steps": "Open /employee/dashboard.",
"expected": "Dashboard loads with workspace tabs.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-007",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My attendance",
"steps": "Open /employee/attendance and punch in/out.",
"expected": "Location permission prompt/geolocation flow works if configured; timestamps show correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-007",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My attendance",
"steps": "Open /employee/attendance and punch in/out.",
"expected": "Location permission prompt/geolocation flow works if configured; timestamps show correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-007",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My attendance",
"steps": "Open /employee/attendance and punch in/out.",
"expected": "Location permission prompt/geolocation flow works if configured; timestamps show correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-007",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My attendance",
"steps": "Open /employee/attendance and punch in/out.",
"expected": "Location permission prompt/geolocation flow works if configured; timestamps show correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-007",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My attendance",
"steps": "Open /employee/attendance and punch in/out.",
"expected": "Location permission prompt/geolocation flow works if configured; timestamps show correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-008",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My leave",
"steps": "Open /employee/leave.",
"expected": "Workspace tabs visible; no unnecessary buttons.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-008",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My leave",
"steps": "Open /employee/leave.",
"expected": "Workspace tabs visible; no unnecessary buttons.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-008",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My leave",
"steps": "Open /employee/leave.",
"expected": "Workspace tabs visible; no unnecessary buttons.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-008",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My leave",
"steps": "Open /employee/leave.",
"expected": "Workspace tabs visible; no unnecessary buttons.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-008",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "My leave",
"steps": "Open /employee/leave.",
"expected": "Workspace tabs visible; no unnecessary buttons.",
"priority": "Medium",
"type": "Regression",
"route": "/employees",
"variantId": "EMP-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-009",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Manager",
"scenario": "Employee master scoping",
"steps": "Open /employees as Manager/Branch Manager.",
"expected": "Manager sees employees only for permitted tenant/branch.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-009",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Manager",
"scenario": "Employee master scoping",
"steps": "Open /employees as Manager/Branch Manager.",
"expected": "Manager sees employees only for permitted tenant/branch.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-009",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Manager",
"scenario": "Employee master scoping",
"steps": "Open /employees as Manager/Branch Manager.",
"expected": "Manager sees employees only for permitted tenant/branch.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-009",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Manager",
"scenario": "Employee master scoping",
"steps": "Open /employees as Manager/Branch Manager.",
"expected": "Manager sees employees only for permitted tenant/branch.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-009",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Manager",
"scenario": "Employee master scoping",
"steps": "Open /employees as Manager/Branch Manager.",
"expected": "Manager sees employees only for permitted tenant/branch.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-010",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Leave types/balances",
"steps": "Open leave setup/balances.",
"expected": "Setup pages work and are visible under Team Administration as permitted.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-010",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Leave types/balances",
"steps": "Open leave setup/balances.",
"expected": "Setup pages work and are visible under Team Administration as permitted.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-010",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Leave types/balances",
"steps": "Open leave setup/balances.",
"expected": "Setup pages work and are visible under Team Administration as permitted.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-010",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Leave types/balances",
"steps": "Open leave setup/balances.",
"expected": "Setup pages work and are visible under Team Administration as permitted.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-010",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Leave types/balances",
"steps": "Open leave setup/balances.",
"expected": "Setup pages work and are visible under Team Administration as permitted.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-011",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Employee documents",
"steps": "Open employee documents and document types.",
"expected": "Employee HR documents are separate from engagement documents and permission-controlled.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-011-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-011",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Employee documents",
"steps": "Open employee documents and document types.",
"expected": "Employee HR documents are separate from engagement documents and permission-controlled.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-011-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-011",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Employee documents",
"steps": "Open employee documents and document types.",
"expected": "Employee HR documents are separate from engagement documents and permission-controlled.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-011",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Employee documents",
"steps": "Open employee documents and document types.",
"expected": "Employee HR documents are separate from engagement documents and permission-controlled.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-011-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-011",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Employee documents",
"steps": "Open employee documents and document types.",
"expected": "Employee HR documents are separate from engagement documents and permission-controlled.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-011-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-012",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Onboarding/offboarding",
"steps": "Open employee lifecycle pages.",
"expected": "Onboarding/offboarding flows render and permissions apply.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-012-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-012",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Onboarding/offboarding",
"steps": "Open employee lifecycle pages.",
"expected": "Onboarding/offboarding flows render and permissions apply.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-012-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-012",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Onboarding/offboarding",
"steps": "Open employee lifecycle pages.",
"expected": "Onboarding/offboarding flows render and permissions apply.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-012",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Onboarding/offboarding",
"steps": "Open employee lifecycle pages.",
"expected": "Onboarding/offboarding flows render and permissions apply.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-012-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-012",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Firm Admin",
"scenario": "Onboarding/offboarding",
"steps": "Open employee lifecycle pages.",
"expected": "Onboarding/offboarding flows render and permissions apply.",
"priority": "Medium",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-012-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-013",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin/Allowed role",
"scenario": "Payroll pages",
"steps": "Open salary structures, runs, payslips.",
"expected": "Visible only to payroll-permitted users and CRUD/actions work.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-013-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-013",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin/Allowed role",
"scenario": "Payroll pages",
"steps": "Open salary structures, runs, payslips.",
"expected": "Visible only to payroll-permitted users and CRUD/actions work.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-013-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-013",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin/Allowed role",
"scenario": "Payroll pages",
"steps": "Open salary structures, runs, payslips.",
"expected": "Visible only to payroll-permitted users and CRUD/actions work.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-013",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin/Allowed role",
"scenario": "Payroll pages",
"steps": "Open salary structures, runs, payslips.",
"expected": "Visible only to payroll-permitted users and CRUD/actions work.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-013-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-013",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin/Allowed role",
"scenario": "Payroll pages",
"steps": "Open salary structures, runs, payslips.",
"expected": "Visible only to payroll-permitted users and CRUD/actions work.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-013-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-014",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Forbidden HR pages",
"steps": "Staff tries /employees or payroll admin URLs.",
"expected": "Blocked/redirected without data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-014-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-014",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Forbidden HR pages",
"steps": "Staff tries /employees or payroll admin URLs.",
"expected": "Blocked/redirected without data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-014-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-014",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Forbidden HR pages",
"steps": "Staff tries /employees or payroll admin URLs.",
"expected": "Blocked/redirected without data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-014",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Forbidden HR pages",
"steps": "Staff tries /employees or payroll admin URLs.",
"expected": "Blocked/redirected without data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-014-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-014",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Forbidden HR pages",
"steps": "Staff tries /employees or payroll admin URLs.",
"expected": "Blocked/redirected without data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-014-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-015",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Firm Admin",
"scenario": "Branch timezone saved",
"steps": "Set branch timezone to Asia/Kolkata.",
"expected": "Saved correctly and punch times reflect branch local time.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-015-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-015",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Firm Admin",
"scenario": "Branch timezone saved",
"steps": "Set branch timezone to Asia/Kolkata.",
"expected": "Saved correctly and punch times reflect branch local time.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-015-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-015",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Firm Admin",
"scenario": "Branch timezone saved",
"steps": "Set branch timezone to Asia/Kolkata.",
"expected": "Saved correctly and punch times reflect branch local time.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-015",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Firm Admin",
"scenario": "Branch timezone saved",
"steps": "Set branch timezone to Asia/Kolkata.",
"expected": "Saved correctly and punch times reflect branch local time.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-015-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-015",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Firm Admin",
"scenario": "Branch timezone saved",
"steps": "Set branch timezone to Asia/Kolkata.",
"expected": "Saved correctly and punch times reflect branch local time.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-015-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-016",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch within geofence",
"steps": "Employee punches within 100m geofence.",
"expected": "Auto-approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-016-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-016",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch within geofence",
"steps": "Employee punches within 100m geofence.",
"expected": "Auto-approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-016-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-016",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch within geofence",
"steps": "Employee punches within 100m geofence.",
"expected": "Auto-approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-016-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-016",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch within geofence",
"steps": "Employee punches within 100m geofence.",
"expected": "Auto-approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-016-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-016",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch within geofence",
"steps": "Employee punches within 100m geofence.",
"expected": "Auto-approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-016-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-017",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch outside geofence",
"steps": "Employee punches outside 100m / geolocation denied.",
"expected": "Marked pending approval / OD.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-017-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-017",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch outside geofence",
"steps": "Employee punches outside 100m / geolocation denied.",
"expected": "Marked pending approval / OD.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-017-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-017",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch outside geofence",
"steps": "Employee punches outside 100m / geolocation denied.",
"expected": "Marked pending approval / OD.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-017-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-017",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch outside geofence",
"steps": "Employee punches outside 100m / geolocation denied.",
"expected": "Marked pending approval / OD.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-017-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-017",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Staff",
"scenario": "Punch outside geofence",
"steps": "Employee punches outside 100m / geolocation denied.",
"expected": "Marked pending approval / OD.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-017-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-018",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Late/half-day/weekly-off rules",
"steps": "Configure rules and create attendance records.",
"expected": "Rules applied correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-018-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-018",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Late/half-day/weekly-off rules",
"steps": "Configure rules and create attendance records.",
"expected": "Rules applied correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-018-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-018",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Late/half-day/weekly-off rules",
"steps": "Configure rules and create attendance records.",
"expected": "Rules applied correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-018-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-018",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Late/half-day/weekly-off rules",
"steps": "Configure rules and create attendance records.",
"expected": "Rules applied correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-018-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-018",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Late/half-day/weekly-off rules",
"steps": "Configure rules and create attendance records.",
"expected": "Rules applied correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-018-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-019",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Approve OD",
"steps": "Branch Manager/Partner/Admin approves OD request.",
"expected": "Status approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-019-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-019",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Approve OD",
"steps": "Branch Manager/Partner/Admin approves OD request.",
"expected": "Status approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-019-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-019",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Approve OD",
"steps": "Branch Manager/Partner/Admin approves OD request.",
"expected": "Status approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-019-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-019",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Approve OD",
"steps": "Branch Manager/Partner/Admin approves OD request.",
"expected": "Status approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-019-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-019",
"sheet": "UAT_Employees",
"module": "Attendance",
"role": "Manager/Admin",
"scenario": "Approve OD",
"steps": "Branch Manager/Partner/Admin approves OD request.",
"expected": "Status approved.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-019-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-020",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Staff",
"scenario": "Apply leave and balance validation",
"steps": "Employee applies leave; balance checked.",
"expected": "Request created; balance validated; error if insufficient.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-020-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-020",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Staff",
"scenario": "Apply leave and balance validation",
"steps": "Employee applies leave; balance checked.",
"expected": "Request created; balance validated; error if insufficient.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-020-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-020",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Staff",
"scenario": "Apply leave and balance validation",
"steps": "Employee applies leave; balance checked.",
"expected": "Request created; balance validated; error if insufficient.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-020-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-020",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Staff",
"scenario": "Apply leave and balance validation",
"steps": "Employee applies leave; balance checked.",
"expected": "Request created; balance validated; error if insufficient.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-020-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-020",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Staff",
"scenario": "Apply leave and balance validation",
"steps": "Employee applies leave; balance checked.",
"expected": "Request created; balance validated; error if insufficient.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-020-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-021",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Manager/Admin",
"scenario": "Approve/reject leave",
"steps": "Approve or reject leave request.",
"expected": "Balance updated only on approval.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-021-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-021",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Manager/Admin",
"scenario": "Approve/reject leave",
"steps": "Approve or reject leave request.",
"expected": "Balance updated only on approval.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-021-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-021",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Manager/Admin",
"scenario": "Approve/reject leave",
"steps": "Approve or reject leave request.",
"expected": "Balance updated only on approval.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-021-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-021",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Manager/Admin",
"scenario": "Approve/reject leave",
"steps": "Approve or reject leave request.",
"expected": "Balance updated only on approval.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-021-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-021",
"sheet": "UAT_Employees",
"module": "Leave",
"role": "Manager/Admin",
"scenario": "Approve/reject leave",
"steps": "Approve or reject leave request.",
"expected": "Balance updated only on approval.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-021-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-022",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Add salary structure",
"steps": "Create salary structure for employee.",
"expected": "Saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-022-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-022",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Add salary structure",
"steps": "Create salary structure for employee.",
"expected": "Saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-022-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-022",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Add salary structure",
"steps": "Create salary structure for employee.",
"expected": "Saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-022-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-022",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Add salary structure",
"steps": "Create salary structure for employee.",
"expected": "Saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-022-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-022",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Add salary structure",
"steps": "Create salary structure for employee.",
"expected": "Saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-022-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-023",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Generate payroll run and payslips",
"steps": "Run payroll for a period.",
"expected": "Payslips generated correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-023-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-023",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Generate payroll run and payslips",
"steps": "Run payroll for a period.",
"expected": "Payslips generated correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-023-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-023",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Generate payroll run and payslips",
"steps": "Run payroll for a period.",
"expected": "Payslips generated correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-023-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-023",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Generate payroll run and payslips",
"steps": "Run payroll for a period.",
"expected": "Payslips generated correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-023-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-023",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Generate payroll run and payslips",
"steps": "Run payroll for a period.",
"expected": "Payslips generated correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-023-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-024",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Approve and mark paid",
"steps": "Approve payroll run and mark as paid.",
"expected": "Status updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-024-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-024",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Approve and mark paid",
"steps": "Approve payroll run and mark as paid.",
"expected": "Status updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-024-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-024",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Approve and mark paid",
"steps": "Approve payroll run and mark as paid.",
"expected": "Status updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-024-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-024",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Approve and mark paid",
"steps": "Approve payroll run and mark as paid.",
"expected": "Status updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-024-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-024",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Firm Admin",
"scenario": "Approve and mark paid",
"steps": "Approve payroll run and mark as paid.",
"expected": "Status updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-024-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-025",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Staff",
"scenario": "Employee views own payslip only",
"steps": "Staff opens payslip page.",
"expected": "Only own payslips visible; other employee payslips blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-025-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-025",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Staff",
"scenario": "Employee views own payslip only",
"steps": "Staff opens payslip page.",
"expected": "Only own payslips visible; other employee payslips blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-025-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-025",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Staff",
"scenario": "Employee views own payslip only",
"steps": "Staff opens payslip page.",
"expected": "Only own payslips visible; other employee payslips blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-025-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-025",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Staff",
"scenario": "Employee views own payslip only",
"steps": "Staff opens payslip page.",
"expected": "Only own payslips visible; other employee payslips blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-025-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-025",
"sheet": "UAT_Employees",
"module": "Payroll",
"role": "Staff",
"scenario": "Employee views own payslip only",
"steps": "Staff opens payslip page.",
"expected": "Only own payslips visible; other employee payslips blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-025-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-026",
"sheet": "UAT_Employees",
"module": "HR Imports",
"role": "Firm Admin",
"scenario": "Download and upload employee/leave/payroll templates",
"steps": "Download import template; upload with valid and invalid data.",
"expected": "Preview, errors and commit work correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-026-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-026",
"sheet": "UAT_Employees",
"module": "HR Imports",
"role": "Firm Admin",
"scenario": "Download and upload employee/leave/payroll templates",
"steps": "Download import template; upload with valid and invalid data.",
"expected": "Preview, errors and commit work correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-026-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-026",
"sheet": "UAT_Employees",
"module": "HR Imports",
"role": "Firm Admin",
"scenario": "Download and upload employee/leave/payroll templates",
"steps": "Download import template; upload with valid and invalid data.",
"expected": "Preview, errors and commit work correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-026-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-026",
"sheet": "UAT_Employees",
"module": "HR Imports",
"role": "Firm Admin",
"scenario": "Download and upload employee/leave/payroll templates",
"steps": "Download import template; upload with valid and invalid data.",
"expected": "Preview, errors and commit work correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-026-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-026",
"sheet": "UAT_Employees",
"module": "HR Imports",
"role": "Firm Admin",
"scenario": "Download and upload employee/leave/payroll templates",
"steps": "Download import template; upload with valid and invalid data.",
"expected": "Preview, errors and commit work correctly.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "EMP-026-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "EMP-027",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Employee cannot access another employee document",
"steps": "Staff tries direct URL to another employee HR document.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-027-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "EMP-027",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Employee cannot access another employee document",
"steps": "Staff tries direct URL to another employee HR document.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-027-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "EMP-027",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Employee cannot access another employee document",
"steps": "Staff tries direct URL to another employee HR document.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-027-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "EMP-027",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Employee cannot access another employee document",
"steps": "Staff tries direct URL to another employee HR document.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-027-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "EMP-027",
"sheet": "UAT_Employees",
"module": "Employees",
"role": "Staff",
"scenario": "Employee cannot access another employee document",
"steps": "Staff tries direct URL to another employee HR document.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "EMP-027-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-001",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "My Work board opens",
"steps": "Open /employee/work.",
"expected": "Assigned tasks appear grouped in Pending/In Progress/Blocked/Completed columns.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-001",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "My Work board opens",
"steps": "Open /employee/work.",
"expected": "Assigned tasks appear grouped in Pending/In Progress/Blocked/Completed columns.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-001",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "My Work board opens",
"steps": "Open /employee/work.",
"expected": "Assigned tasks appear grouped in Pending/In Progress/Blocked/Completed columns.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-001",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "My Work board opens",
"steps": "Open /employee/work.",
"expected": "Assigned tasks appear grouped in Pending/In Progress/Blocked/Completed columns.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-001",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "My Work board opens",
"steps": "Open /employee/work.",
"expected": "Assigned tasks appear grouped in Pending/In Progress/Blocked/Completed columns.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-002",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Grouped priority \u2192 client \u2192 engagement",
"steps": "View My Work board task grouping.",
"expected": "Correct priority \u2192 client \u2192 engagement grouping applied.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-002",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Grouped priority \u2192 client \u2192 engagement",
"steps": "View My Work board task grouping.",
"expected": "Correct priority \u2192 client \u2192 engagement grouping applied.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-002",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Grouped priority \u2192 client \u2192 engagement",
"steps": "View My Work board task grouping.",
"expected": "Correct priority \u2192 client \u2192 engagement grouping applied.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-002",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Grouped priority \u2192 client \u2192 engagement",
"steps": "View My Work board task grouping.",
"expected": "Correct priority \u2192 client \u2192 engagement grouping applied.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-002",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Grouped priority \u2192 client \u2192 engagement",
"steps": "View My Work board task grouping.",
"expected": "Correct priority \u2192 client \u2192 engagement grouping applied.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-003",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Expand/collapse sections",
"steps": "Use expand/collapse on work board.",
"expected": "Works without page error.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-003",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Expand/collapse sections",
"steps": "Use expand/collapse on work board.",
"expected": "Works without page error.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-003",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Expand/collapse sections",
"steps": "Use expand/collapse on work board.",
"expected": "Works without page error.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-003",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Expand/collapse sections",
"steps": "Use expand/collapse on work board.",
"expected": "Works without page error.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-003",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Expand/collapse sections",
"steps": "Use expand/collapse on work board.",
"expected": "Works without page error.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-004",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Search task/client/engagement",
"steps": "Use search on work board.",
"expected": "Results filtered correctly.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-004",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Search task/client/engagement",
"steps": "Use search on work board.",
"expected": "Results filtered correctly.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-004",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Search task/client/engagement",
"steps": "Use search on work board.",
"expected": "Results filtered correctly.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-004",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Search task/client/engagement",
"steps": "Use search on work board.",
"expected": "Results filtered correctly.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-004",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Search task/client/engagement",
"steps": "Use search on work board.",
"expected": "Results filtered correctly.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-005",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee updates own task status",
"steps": "Change task status on My Work.",
"expected": "Status updated and reflected on manager/partner boards.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-005",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee updates own task status",
"steps": "Change task status on My Work.",
"expected": "Status updated and reflected on manager/partner boards.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-005",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee updates own task status",
"steps": "Change task status on My Work.",
"expected": "Status updated and reflected on manager/partner boards.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-005",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee updates own task status",
"steps": "Change task status on My Work.",
"expected": "Status updated and reflected on manager/partner boards.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-005",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee updates own task status",
"steps": "Change task status on My Work.",
"expected": "Status updated and reflected on manager/partner boards.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-006",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee cannot update others' tasks",
"steps": "Staff tries to change another employee's task status.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "WRK-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-006",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee cannot update others' tasks",
"steps": "Staff tries to change another employee's task status.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "WRK-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-006",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee cannot update others' tasks",
"steps": "Staff tries to change another employee's task status.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "WRK-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-006",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee cannot update others' tasks",
"steps": "Staff tries to change another employee's task status.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "WRK-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-006",
"sheet": "UAT_Work",
"module": "Engagement Work",
"role": "Staff",
"scenario": "Employee cannot update others' tasks",
"steps": "Staff tries to change another employee's task status.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "WRK-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-007",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager opens Work Allocation",
"steps": "Open /employees/work.",
"expected": "Team tasks visible; allocation actions available.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-007",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager opens Work Allocation",
"steps": "Open /employees/work.",
"expected": "Team tasks visible; allocation actions available.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-007",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager opens Work Allocation",
"steps": "Open /employees/work.",
"expected": "Team tasks visible; allocation actions available.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-007",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager opens Work Allocation",
"steps": "Open /employees/work.",
"expected": "Team tasks visible; allocation actions available.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-007",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager opens Work Allocation",
"steps": "Open /employees/work.",
"expected": "Team tasks visible; allocation actions available.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-008",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager assigns task to employee",
"steps": "Assign/reassign task from allocation view.",
"expected": "Assignee updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-008",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager assigns task to employee",
"steps": "Assign/reassign task from allocation view.",
"expected": "Assignee updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-008",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager assigns task to employee",
"steps": "Assign/reassign task from allocation view.",
"expected": "Assignee updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-008",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager assigns task to employee",
"steps": "Assign/reassign task from allocation view.",
"expected": "Assignee updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-008",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager assigns task to employee",
"steps": "Assign/reassign task from allocation view.",
"expected": "Assignee updated.",
"priority": "High",
"type": "UAT",
"route": "/employees",
"variantId": "WRK-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-009",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager changes priority/status/due date",
"steps": "Update task priority, status and due date.",
"expected": "Fields updated correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-009",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager changes priority/status/due date",
"steps": "Update task priority, status and due date.",
"expected": "Fields updated correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-009",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager changes priority/status/due date",
"steps": "Update task priority, status and due date.",
"expected": "Fields updated correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-009",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager changes priority/status/due date",
"steps": "Update task priority, status and due date.",
"expected": "Fields updated correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-009",
"sheet": "UAT_Work",
"module": "Allocation",
"role": "Manager",
"scenario": "Manager changes priority/status/due date",
"steps": "Update task priority, status and due date.",
"expected": "Fields updated correctly.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-010",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress dashboard opens",
"steps": "Open /employees/progress.",
"expected": "Client/engagement progress visible without errors.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-010",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress dashboard opens",
"steps": "Open /employees/progress.",
"expected": "Client/engagement progress visible without errors.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-010",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress dashboard opens",
"steps": "Open /employees/progress.",
"expected": "Client/engagement progress visible without errors.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-010",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress dashboard opens",
"steps": "Open /employees/progress.",
"expected": "Client/engagement progress visible without errors.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-010",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress dashboard opens",
"steps": "Open /employees/progress.",
"expected": "Client/engagement progress visible without errors.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-011",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress percentage calculation",
"steps": "Check progress percentages.",
"expected": "Completed \u00f7 total tasks calculation correct.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-011-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-011",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress percentage calculation",
"steps": "Check progress percentages.",
"expected": "Completed \u00f7 total tasks calculation correct.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-011-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-011",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress percentage calculation",
"steps": "Check progress percentages.",
"expected": "Completed \u00f7 total tasks calculation correct.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-011",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress percentage calculation",
"steps": "Check progress percentages.",
"expected": "Completed \u00f7 total tasks calculation correct.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-011-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-011",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Progress percentage calculation",
"steps": "Check progress percentages.",
"expected": "Completed \u00f7 total tasks calculation correct.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-011-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-012",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Overdue/due today filters",
"steps": "Apply overdue and due-today filters.",
"expected": "Correct results returned.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-012-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-012",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Overdue/due today filters",
"steps": "Apply overdue and due-today filters.",
"expected": "Correct results returned.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-012-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-012",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Overdue/due today filters",
"steps": "Apply overdue and due-today filters.",
"expected": "Correct results returned.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-012",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Overdue/due today filters",
"steps": "Apply overdue and due-today filters.",
"expected": "Correct results returned.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-012-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-012",
"sheet": "UAT_Work",
"module": "Progress",
"role": "Manager",
"scenario": "Overdue/due today filters",
"steps": "Apply overdue and due-today filters.",
"expected": "Correct results returned.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-012-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-013",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Task communication timeline opens",
"steps": "Open communication tab on work detail.",
"expected": "Timeline visible with correct notes and timestamps.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-013-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-013",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Task communication timeline opens",
"steps": "Open communication tab on work detail.",
"expected": "Timeline visible with correct notes and timestamps.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-013-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-013",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Task communication timeline opens",
"steps": "Open communication tab on work detail.",
"expected": "Timeline visible with correct notes and timestamps.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-013",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Task communication timeline opens",
"steps": "Open communication tab on work detail.",
"expected": "Timeline visible with correct notes and timestamps.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-013-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-013",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Task communication timeline opens",
"steps": "Open communication tab on work detail.",
"expected": "Timeline visible with correct notes and timestamps.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-013-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-014",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Add internal note/client clarification/partner note",
"steps": "Add different comment types.",
"expected": "Note saved with correct type/visibility; wrong-role notes hidden.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-014-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-014",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Add internal note/client clarification/partner note",
"steps": "Add different comment types.",
"expected": "Note saved with correct type/visibility; wrong-role notes hidden.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-014-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-014",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Add internal note/client clarification/partner note",
"steps": "Add different comment types.",
"expected": "Note saved with correct type/visibility; wrong-role notes hidden.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-014",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Add internal note/client clarification/partner note",
"steps": "Add different comment types.",
"expected": "Note saved with correct type/visibility; wrong-role notes hidden.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-014-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-014",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Add internal note/client clarification/partner note",
"steps": "Add different comment types.",
"expected": "Note saved with correct type/visibility; wrong-role notes hidden.",
"priority": "High",
"type": "UAT",
"route": "/work",
"variantId": "WRK-014-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "WRK-015",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Comment count/latest preview",
"steps": "View comment count on work list/board.",
"expected": "Shows correctly and updates after adding comment.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-015-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "WRK-015",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Comment count/latest preview",
"steps": "View comment count on work list/board.",
"expected": "Shows correctly and updates after adding comment.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-015-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "WRK-015",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Comment count/latest preview",
"steps": "View comment count on work list/board.",
"expected": "Shows correctly and updates after adding comment.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "WRK-015",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Comment count/latest preview",
"steps": "View comment count on work list/board.",
"expected": "Shows correctly and updates after adding comment.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-015-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "WRK-015",
"sheet": "UAT_Work",
"module": "Communication",
"role": "All roles",
"scenario": "Comment count/latest preview",
"steps": "View comment count on work list/board.",
"expected": "Shows correctly and updates after adding comment.",
"priority": "Medium",
"type": "UAT",
"route": "/work",
"variantId": "WRK-015-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOC-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Firm Admin",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes and generate/download branch agent.",
"expected": "Firm Admin can generate/download only for their permitted firm/branch.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOC-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Firm Admin",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes and generate/download branch agent.",
"expected": "Firm Admin can generate/download only for their permitted firm/branch.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOC-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Firm Admin",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes and generate/download branch agent.",
"expected": "Firm Admin can generate/download only for their permitted firm/branch.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOC-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Firm Admin",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes and generate/download branch agent.",
"expected": "Firm Admin can generate/download only for their permitted firm/branch.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOC-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Firm Admin",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes and generate/download branch agent.",
"expected": "Firm Admin can generate/download only for their permitted firm/branch.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOC-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Partner",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes as Partner.",
"expected": "Partner can access only permitted branch agent flow if business rule allows.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOC-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Partner",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes as Partner.",
"expected": "Partner can access only permitted branch agent flow if business rule allows.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOC-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Partner",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes as Partner.",
"expected": "Partner can access only permitted branch agent flow if business rule allows.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOC-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Partner",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes as Partner.",
"expected": "Partner can access only permitted branch agent flow if business rule allows.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOC-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Storage Agent",
"role": "Partner",
"scenario": "Generate branch local storage agent",
"steps": "Open /documents/storage-nodes as Partner.",
"expected": "Partner can access only permitted branch agent flow if business rule allows.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOC-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Staff",
"scenario": "Full documents menu hidden",
"steps": "Login as staff.",
"expected": "Global documents menu/download agents are hidden; docs accessible only from My Docs/work detail.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOC-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Staff",
"scenario": "Full documents menu hidden",
"steps": "Login as staff.",
"expected": "Global documents menu/download agents are hidden; docs accessible only from My Docs/work detail.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOC-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Staff",
"scenario": "Full documents menu hidden",
"steps": "Login as staff.",
"expected": "Global documents menu/download agents are hidden; docs accessible only from My Docs/work detail.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOC-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Staff",
"scenario": "Full documents menu hidden",
"steps": "Login as staff.",
"expected": "Global documents menu/download agents are hidden; docs accessible only from My Docs/work detail.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOC-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Staff",
"scenario": "Full documents menu hidden",
"steps": "Login as staff.",
"expected": "Global documents menu/download agents are hidden; docs accessible only from My Docs/work detail.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "DOC-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOC-004",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Client",
"scenario": "Permanent documents",
"steps": "Open client document list.",
"expected": "Client sees/downloads only their own allowed permanent and engagement documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/billing",
"variantId": "DOC-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOC-004",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Client",
"scenario": "Permanent documents",
"steps": "Open client document list.",
"expected": "Client sees/downloads only their own allowed permanent and engagement documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/billing",
"variantId": "DOC-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOC-004",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Client",
"scenario": "Permanent documents",
"steps": "Open client document list.",
"expected": "Client sees/downloads only their own allowed permanent and engagement documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/billing",
"variantId": "DOC-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOC-004",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Client",
"scenario": "Permanent documents",
"steps": "Open client document list.",
"expected": "Client sees/downloads only their own allowed permanent and engagement documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/billing",
"variantId": "DOC-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOC-004",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Documents",
"role": "Client",
"scenario": "Permanent documents",
"steps": "Open client document list.",
"expected": "Client sees/downloads only their own allowed permanent and engagement documents.",
"priority": "Critical",
"type": "VAPT",
"route": "/billing",
"variantId": "DOC-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "BILL-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Invoice list",
"steps": "Open /billing.",
"expected": "Invoices list loads within firm scope.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "BILL-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Invoice list",
"steps": "Open /billing.",
"expected": "Invoices list loads within firm scope.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "BILL-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Invoice list",
"steps": "Open /billing.",
"expected": "Invoices list loads within firm scope.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "BILL-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Invoice list",
"steps": "Open /billing.",
"expected": "Invoices list loads within firm scope.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "BILL-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Invoice list",
"steps": "Open /billing.",
"expected": "Invoices list loads within firm scope.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "BILL-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Partner",
"scenario": "Partner billing rights",
"steps": "Partner generates invoice/bill for own client/engagement if permitted.",
"expected": "Partner cannot bill other partner's clients unless permission exists.",
"priority": "High",
"type": "VAPT",
"route": "/billing",
"variantId": "BILL-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "BILL-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Partner",
"scenario": "Partner billing rights",
"steps": "Partner generates invoice/bill for own client/engagement if permitted.",
"expected": "Partner cannot bill other partner's clients unless permission exists.",
"priority": "High",
"type": "VAPT",
"route": "/billing",
"variantId": "BILL-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "BILL-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Partner",
"scenario": "Partner billing rights",
"steps": "Partner generates invoice/bill for own client/engagement if permitted.",
"expected": "Partner cannot bill other partner's clients unless permission exists.",
"priority": "High",
"type": "VAPT",
"route": "/billing",
"variantId": "BILL-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "BILL-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Partner",
"scenario": "Partner billing rights",
"steps": "Partner generates invoice/bill for own client/engagement if permitted.",
"expected": "Partner cannot bill other partner's clients unless permission exists.",
"priority": "High",
"type": "VAPT",
"route": "/billing",
"variantId": "BILL-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "BILL-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Partner",
"scenario": "Partner billing rights",
"steps": "Partner generates invoice/bill for own client/engagement if permitted.",
"expected": "Partner cannot bill other partner's clients unless permission exists.",
"priority": "High",
"type": "VAPT",
"route": "/billing",
"variantId": "BILL-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "BILL-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Fee structure import",
"steps": "Download fee template and import fee structure.",
"expected": "Import validates client/service mapping and creates fee structures.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "BILL-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Fee structure import",
"steps": "Download fee template and import fee structure.",
"expected": "Import validates client/service mapping and creates fee structures.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "BILL-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Fee structure import",
"steps": "Download fee template and import fee structure.",
"expected": "Import validates client/service mapping and creates fee structures.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "BILL-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Fee structure import",
"steps": "Download fee template and import fee structure.",
"expected": "Import validates client/service mapping and creates fee structures.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "BILL-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Billing",
"role": "Firm Admin",
"scenario": "Fee structure import",
"steps": "Download fee template and import fee structure.",
"expected": "Import validates client/service mapping and creates fee structures.",
"priority": "High",
"type": "UAT",
"route": "/billing",
"variantId": "BILL-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "ALRT-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Due today alert",
"steps": "Create task due today and run/await scheduler.",
"expected": "Assigned staff receives alert.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "ALRT-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Due today alert",
"steps": "Create task due today and run/await scheduler.",
"expected": "Assigned staff receives alert.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "ALRT-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Due today alert",
"steps": "Create task due today and run/await scheduler.",
"expected": "Assigned staff receives alert.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "ALRT-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Due today alert",
"steps": "Create task due today and run/await scheduler.",
"expected": "Assigned staff receives alert.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "ALRT-001",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Due today alert",
"steps": "Create task due today and run/await scheduler.",
"expected": "Assigned staff receives alert.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "ALRT-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Overdue escalation",
"steps": "Create overdue task by 1/3 days.",
"expected": "Alert escalates to manager/partner according to rules.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "ALRT-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Overdue escalation",
"steps": "Create overdue task by 1/3 days.",
"expected": "Alert escalates to manager/partner according to rules.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "ALRT-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Overdue escalation",
"steps": "Create overdue task by 1/3 days.",
"expected": "Alert escalates to manager/partner according to rules.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "ALRT-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Overdue escalation",
"steps": "Create overdue task by 1/3 days.",
"expected": "Alert escalates to manager/partner according to rules.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "ALRT-002",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Automation",
"role": "Scheduler",
"scenario": "Overdue escalation",
"steps": "Create overdue task by 1/3 days.",
"expected": "Alert escalates to manager/partner according to rules.",
"priority": "Medium",
"type": "UAT",
"route": "/billing",
"variantId": "ALRT-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "ALRT-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Popup",
"role": "All roles",
"scenario": "Toast polling",
"steps": "Keep page open after alert creation.",
"expected": "Popup appears within polling interval; no visible header alert button required.",
"priority": "Medium",
"type": "Regression",
"route": "/billing",
"variantId": "ALRT-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "ALRT-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Popup",
"role": "All roles",
"scenario": "Toast polling",
"steps": "Keep page open after alert creation.",
"expected": "Popup appears within polling interval; no visible header alert button required.",
"priority": "Medium",
"type": "Regression",
"route": "/billing",
"variantId": "ALRT-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "ALRT-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Popup",
"role": "All roles",
"scenario": "Toast polling",
"steps": "Keep page open after alert creation.",
"expected": "Popup appears within polling interval; no visible header alert button required.",
"priority": "Medium",
"type": "Regression",
"route": "/billing",
"variantId": "ALRT-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "ALRT-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Popup",
"role": "All roles",
"scenario": "Toast polling",
"steps": "Keep page open after alert creation.",
"expected": "Popup appears within polling interval; no visible header alert button required.",
"priority": "Medium",
"type": "Regression",
"route": "/billing",
"variantId": "ALRT-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "ALRT-003",
"sheet": "UAT_Docs_Billing_Alerts",
"module": "Alerts Popup",
"role": "All roles",
"scenario": "Toast polling",
"steps": "Keep page open after alert creation.",
"expected": "Popup appears within polling interval; no visible header alert button required.",
"priority": "Medium",
"type": "Regression",
"route": "/billing",
"variantId": "ALRT-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-001",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create document requirement in service task template",
"steps": "Open Service Catalogue > Task Template > Add Document Requirement.",
"expected": "Requirement is saved and displayed under the selected task template.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-001",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create document requirement in service task template",
"steps": "Open Service Catalogue > Task Template > Add Document Requirement.",
"expected": "Requirement is saved and displayed under the selected task template.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-001",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create document requirement in service task template",
"steps": "Open Service Catalogue > Task Template > Add Document Requirement.",
"expected": "Requirement is saved and displayed under the selected task template.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-001",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create document requirement in service task template",
"steps": "Open Service Catalogue > Task Template > Add Document Requirement.",
"expected": "Requirement is saved and displayed under the selected task template.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-001",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create document requirement in service task template",
"steps": "Open Service Catalogue > Task Template > Add Document Requirement.",
"expected": "Requirement is saved and displayed under the selected task template.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-002",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as mandatory",
"steps": "Create/edit requirement and enable Mandatory.",
"expected": "Mandatory flag is saved and visible.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-002",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as mandatory",
"steps": "Create/edit requirement and enable Mandatory.",
"expected": "Mandatory flag is saved and visible.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-002",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as mandatory",
"steps": "Create/edit requirement and enable Mandatory.",
"expected": "Mandatory flag is saved and visible.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-002",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as mandatory",
"steps": "Create/edit requirement and enable Mandatory.",
"expected": "Mandatory flag is saved and visible.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-002",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as mandatory",
"steps": "Create/edit requirement and enable Mandatory.",
"expected": "Mandatory flag is saved and visible.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-003",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as optional",
"steps": "Create/edit requirement and disable Mandatory.",
"expected": "Optional flag is saved and visible.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-003",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as optional",
"steps": "Create/edit requirement and disable Mandatory.",
"expected": "Optional flag is saved and visible.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-003",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as optional",
"steps": "Create/edit requirement and disable Mandatory.",
"expected": "Optional flag is saved and visible.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-003",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as optional",
"steps": "Create/edit requirement and disable Mandatory.",
"expected": "Optional flag is saved and visible.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-003",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Mark required document as optional",
"steps": "Create/edit requirement and disable Mandatory.",
"expected": "Optional flag is saved and visible.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-004",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Upload template attachment at task template level",
"steps": "Upload DOCX/PDF/XLSX template against service task template.",
"expected": "Template file is uploaded, listed, and downloadable.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-004",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Upload template attachment at task template level",
"steps": "Upload DOCX/PDF/XLSX template against service task template.",
"expected": "Template file is uploaded, listed, and downloadable.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-004",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Upload template attachment at task template level",
"steps": "Upload DOCX/PDF/XLSX template against service task template.",
"expected": "Template file is uploaded, listed, and downloadable.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-004",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Upload template attachment at task template level",
"steps": "Upload DOCX/PDF/XLSX template against service task template.",
"expected": "Template file is uploaded, listed, and downloadable.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-004",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Upload template attachment at task template level",
"steps": "Upload DOCX/PDF/XLSX template against service task template.",
"expected": "Template file is uploaded, listed, and downloadable.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-005",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Edit document requirement",
"steps": "Change document name/type/mandatory flag/allowed file types.",
"expected": "Updated values are saved without affecting unrelated tasks.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-005",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Edit document requirement",
"steps": "Change document name/type/mandatory flag/allowed file types.",
"expected": "Updated values are saved without affecting unrelated tasks.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-005",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Edit document requirement",
"steps": "Change document name/type/mandatory flag/allowed file types.",
"expected": "Updated values are saved without affecting unrelated tasks.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-005",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Edit document requirement",
"steps": "Change document name/type/mandatory flag/allowed file types.",
"expected": "Updated values are saved without affecting unrelated tasks.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-005",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Edit document requirement",
"steps": "Change document name/type/mandatory flag/allowed file types.",
"expected": "Updated values are saved without affecting unrelated tasks.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-006",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Delete/deactivate document requirement",
"steps": "Delete/deactivate a test requirement.",
"expected": "Requirement is removed/deactivated without deleting existing uploaded engagement documents.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-006",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Delete/deactivate document requirement",
"steps": "Delete/deactivate a test requirement.",
"expected": "Requirement is removed/deactivated without deleting existing uploaded engagement documents.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-006",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Delete/deactivate document requirement",
"steps": "Delete/deactivate a test requirement.",
"expected": "Requirement is removed/deactivated without deleting existing uploaded engagement documents.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-006",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Delete/deactivate document requirement",
"steps": "Delete/deactivate a test requirement.",
"expected": "Requirement is removed/deactivated without deleting existing uploaded engagement documents.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-006",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Delete/deactivate document requirement",
"steps": "Delete/deactivate a test requirement.",
"expected": "Requirement is removed/deactivated without deleting existing uploaded engagement documents.",
"priority": "High",
"type": "Regression",
"route": "/documents",
"variantId": "TD-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-007",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create engagement from service with requirements",
"steps": "Create engagement using service containing task document requirements.",
"expected": "Engagement tasks are created and document requirements are available at task level.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-007",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create engagement from service with requirements",
"steps": "Create engagement using service containing task document requirements.",
"expected": "Engagement tasks are created and document requirements are available at task level.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-007",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create engagement from service with requirements",
"steps": "Create engagement using service containing task document requirements.",
"expected": "Engagement tasks are created and document requirements are available at task level.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-007",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create engagement from service with requirements",
"steps": "Create engagement using service containing task document requirements.",
"expected": "Engagement tasks are created and document requirements are available at task level.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-007",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Firm Admin / Partner",
"scenario": "Create engagement from service with requirements",
"steps": "Create engagement using service containing task document requirements.",
"expected": "Engagement tasks are created and document requirements are available at task level.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-008",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload engagement task document",
"steps": "Open engagement task document page and upload valid file.",
"expected": "File is uploaded and linked to correct engagement task.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-008",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload engagement task document",
"steps": "Open engagement task document page and upload valid file.",
"expected": "File is uploaded and linked to correct engagement task.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-008",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload engagement task document",
"steps": "Open engagement task document page and upload valid file.",
"expected": "File is uploaded and linked to correct engagement task.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-008",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload engagement task document",
"steps": "Open engagement task document page and upload valid file.",
"expected": "File is uploaded and linked to correct engagement task.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-008",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload engagement task document",
"steps": "Open engagement task document page and upload valid file.",
"expected": "File is uploaded and linked to correct engagement task.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-009",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload multiple versions/documents",
"steps": "Upload another file for same requirement/task.",
"expected": "System records latest upload and preserves version history.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-009",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload multiple versions/documents",
"steps": "Upload another file for same requirement/task.",
"expected": "System records latest upload and preserves version history.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-009",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload multiple versions/documents",
"steps": "Upload another file for same requirement/task.",
"expected": "System records latest upload and preserves version history.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-009",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload multiple versions/documents",
"steps": "Upload another file for same requirement/task.",
"expected": "System records latest upload and preserves version history.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-009",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Upload multiple versions/documents",
"steps": "Upload another file for same requirement/task.",
"expected": "System records latest upload and preserves version history.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-010",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Download uploaded task document",
"steps": "Click download/view for uploaded task document.",
"expected": "Correct file is downloaded; no wrong client/task file is served.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-010",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Download uploaded task document",
"steps": "Click download/view for uploaded task document.",
"expected": "Correct file is downloaded; no wrong client/task file is served.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-010",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Download uploaded task document",
"steps": "Click download/view for uploaded task document.",
"expected": "Correct file is downloaded; no wrong client/task file is served.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-010",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Download uploaded task document",
"steps": "Click download/view for uploaded task document.",
"expected": "Correct file is downloaded; no wrong client/task file is served.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-010",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Download uploaded task document",
"steps": "Click download/view for uploaded task document.",
"expected": "Correct file is downloaded; no wrong client/task file is served.",
"priority": "Critical",
"type": "UAT",
"route": "/services",
"variantId": "TD-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-011",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff",
"scenario": "Staff task document upload permission",
"steps": "Login as Staff and upload document for assigned/permitted task.",
"expected": "Upload allowed only where permission and assignment/tenant scope permit.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-011-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-011",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff",
"scenario": "Staff task document upload permission",
"steps": "Login as Staff and upload document for assigned/permitted task.",
"expected": "Upload allowed only where permission and assignment/tenant scope permit.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-011-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-011",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff",
"scenario": "Staff task document upload permission",
"steps": "Login as Staff and upload document for assigned/permitted task.",
"expected": "Upload allowed only where permission and assignment/tenant scope permit.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-011",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff",
"scenario": "Staff task document upload permission",
"steps": "Login as Staff and upload document for assigned/permitted task.",
"expected": "Upload allowed only where permission and assignment/tenant scope permit.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-011-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-011",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff",
"scenario": "Staff task document upload permission",
"steps": "Login as Staff and upload document for assigned/permitted task.",
"expected": "Upload allowed only where permission and assignment/tenant scope permit.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-011-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-012",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager",
"scenario": "Manager task document access",
"steps": "Login as Manager and view/upload/download task documents.",
"expected": "Manager can access only permitted branch/tenant task documents.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-012-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-012",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager",
"scenario": "Manager task document access",
"steps": "Login as Manager and view/upload/download task documents.",
"expected": "Manager can access only permitted branch/tenant task documents.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-012-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-012",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager",
"scenario": "Manager task document access",
"steps": "Login as Manager and view/upload/download task documents.",
"expected": "Manager can access only permitted branch/tenant task documents.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-012",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager",
"scenario": "Manager task document access",
"steps": "Login as Manager and view/upload/download task documents.",
"expected": "Manager can access only permitted branch/tenant task documents.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-012-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-012",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager",
"scenario": "Manager task document access",
"steps": "Login as Manager and view/upload/download task documents.",
"expected": "Manager can access only permitted branch/tenant task documents.",
"priority": "Critical",
"type": "Permission",
"route": "/services",
"variantId": "TD-012-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-013",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Client",
"scenario": "Client upload restriction/permission",
"steps": "Login as Client and attempt upload if client upload is enabled/disabled.",
"expected": "Client upload follows configured permission; unauthorized action is blocked.",
"priority": "High",
"type": "Permission",
"route": "/documents",
"variantId": "TD-013-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-013",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Client",
"scenario": "Client upload restriction/permission",
"steps": "Login as Client and attempt upload if client upload is enabled/disabled.",
"expected": "Client upload follows configured permission; unauthorized action is blocked.",
"priority": "High",
"type": "Permission",
"route": "/documents",
"variantId": "TD-013-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-013",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Client",
"scenario": "Client upload restriction/permission",
"steps": "Login as Client and attempt upload if client upload is enabled/disabled.",
"expected": "Client upload follows configured permission; unauthorized action is blocked.",
"priority": "High",
"type": "Permission",
"route": "/documents",
"variantId": "TD-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-013",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Client",
"scenario": "Client upload restriction/permission",
"steps": "Login as Client and attempt upload if client upload is enabled/disabled.",
"expected": "Client upload follows configured permission; unauthorized action is blocked.",
"priority": "High",
"type": "Permission",
"route": "/documents",
"variantId": "TD-013-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-013",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Client",
"scenario": "Client upload restriction/permission",
"steps": "Login as Client and attempt upload if client upload is enabled/disabled.",
"expected": "Client upload follows configured permission; unauthorized action is blocked.",
"priority": "High",
"type": "Permission",
"route": "/documents",
"variantId": "TD-013-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-014",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Mandatory document missing indicator",
"steps": "Open task where mandatory document is not uploaded.",
"expected": "Missing mandatory document is clearly shown/warned.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-014-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-014",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Mandatory document missing indicator",
"steps": "Open task where mandatory document is not uploaded.",
"expected": "Missing mandatory document is clearly shown/warned.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-014-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-014",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Mandatory document missing indicator",
"steps": "Open task where mandatory document is not uploaded.",
"expected": "Missing mandatory document is clearly shown/warned.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-014",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Mandatory document missing indicator",
"steps": "Open task where mandatory document is not uploaded.",
"expected": "Missing mandatory document is clearly shown/warned.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-014-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-014",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Staff / Manager",
"scenario": "Mandatory document missing indicator",
"steps": "Open task where mandatory document is not uploaded.",
"expected": "Missing mandatory document is clearly shown/warned.",
"priority": "High",
"type": "UAT",
"route": "/documents",
"variantId": "TD-014-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-015",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Invalid file type upload",
"steps": "Try uploading unsupported extension such as .exe/.bat or invalid renamed file.",
"expected": "Upload is blocked or rejected as per validation.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-015-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-015",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Invalid file type upload",
"steps": "Try uploading unsupported extension such as .exe/.bat or invalid renamed file.",
"expected": "Upload is blocked or rejected as per validation.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-015-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-015",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Invalid file type upload",
"steps": "Try uploading unsupported extension such as .exe/.bat or invalid renamed file.",
"expected": "Upload is blocked or rejected as per validation.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-015",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Invalid file type upload",
"steps": "Try uploading unsupported extension such as .exe/.bat or invalid renamed file.",
"expected": "Upload is blocked or rejected as per validation.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-015-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-015",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Invalid file type upload",
"steps": "Try uploading unsupported extension such as .exe/.bat or invalid renamed file.",
"expected": "Upload is blocked or rejected as per validation.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-015-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-016",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Large file upload validation",
"steps": "Try uploading file beyond permitted size.",
"expected": "System blocks or handles gracefully without crash.",
"priority": "High",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-016-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-016",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Large file upload validation",
"steps": "Try uploading file beyond permitted size.",
"expected": "System blocks or handles gracefully without crash.",
"priority": "High",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-016-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-016",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Large file upload validation",
"steps": "Try uploading file beyond permitted size.",
"expected": "System blocks or handles gracefully without crash.",
"priority": "High",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-016-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-016",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Large file upload validation",
"steps": "Try uploading file beyond permitted size.",
"expected": "System blocks or handles gracefully without crash.",
"priority": "High",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-016-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-016",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "All upload roles",
"scenario": "Large file upload validation",
"steps": "Try uploading file beyond permitted size.",
"expected": "System blocks or handles gracefully without crash.",
"priority": "High",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-016-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-017",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Delete task document",
"steps": "Delete a test uploaded document if delete feature is enabled.",
"expected": "Delete is permission controlled and audit/history is preserved where applicable.",
"priority": "High",
"type": "Permission",
"route": "/services",
"variantId": "TD-017-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-017",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Delete task document",
"steps": "Delete a test uploaded document if delete feature is enabled.",
"expected": "Delete is permission controlled and audit/history is preserved where applicable.",
"priority": "High",
"type": "Permission",
"route": "/services",
"variantId": "TD-017-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-017",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Delete task document",
"steps": "Delete a test uploaded document if delete feature is enabled.",
"expected": "Delete is permission controlled and audit/history is preserved where applicable.",
"priority": "High",
"type": "Permission",
"route": "/services",
"variantId": "TD-017-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-017",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Delete task document",
"steps": "Delete a test uploaded document if delete feature is enabled.",
"expected": "Delete is permission controlled and audit/history is preserved where applicable.",
"priority": "High",
"type": "Permission",
"route": "/services",
"variantId": "TD-017-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-017",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Authorized roles",
"scenario": "Delete task document",
"steps": "Delete a test uploaded document if delete feature is enabled.",
"expected": "Delete is permission controlled and audit/history is preserved where applicable.",
"priority": "High",
"type": "Permission",
"route": "/services",
"variantId": "TD-017-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-018",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Storage path generation",
"steps": "Upload task document and verify stored path.",
"expected": "Path follows FY/client/service/period/engagement/task document structure as designed.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-018-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-018",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Storage path generation",
"steps": "Upload task document and verify stored path.",
"expected": "Path follows FY/client/service/period/engagement/task document structure as designed.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-018-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-018",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Storage path generation",
"steps": "Upload task document and verify stored path.",
"expected": "Path follows FY/client/service/period/engagement/task document structure as designed.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-018-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-018",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Storage path generation",
"steps": "Upload task document and verify stored path.",
"expected": "Path follows FY/client/service/period/engagement/task document structure as designed.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-018-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-018",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Storage path generation",
"steps": "Upload task document and verify stored path.",
"expected": "Path follows FY/client/service/period/engagement/task document structure as designed.",
"priority": "Critical",
"type": "UAT",
"route": "/documents",
"variantId": "TD-018-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-019",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Tenant isolation",
"steps": "Attempt to view/download task document from another tenant by URL/id manipulation.",
"expected": "Access is blocked; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-019-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-019",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Tenant isolation",
"steps": "Attempt to view/download task document from another tenant by URL/id manipulation.",
"expected": "Access is blocked; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-019-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-019",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Tenant isolation",
"steps": "Attempt to view/download task document from another tenant by URL/id manipulation.",
"expected": "Access is blocked; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-019-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-019",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Tenant isolation",
"steps": "Attempt to view/download task document from another tenant by URL/id manipulation.",
"expected": "Access is blocked; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-019-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-019",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "System Admin / Firm Admin",
"scenario": "Tenant isolation",
"steps": "Attempt to view/download task document from another tenant by URL/id manipulation.",
"expected": "Access is blocked; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-019-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "TD-020",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager / Staff",
"scenario": "Branch isolation",
"steps": "Attempt to view/download task document from another branch.",
"expected": "Access is blocked unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-020-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "TD-020",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager / Staff",
"scenario": "Branch isolation",
"steps": "Attempt to view/download task document from another branch.",
"expected": "Access is blocked unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-020-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "TD-020",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager / Staff",
"scenario": "Branch isolation",
"steps": "Attempt to view/download task document from another branch.",
"expected": "Access is blocked unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-020-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "TD-020",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager / Staff",
"scenario": "Branch isolation",
"steps": "Attempt to view/download task document from another branch.",
"expected": "Access is blocked unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-020-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "TD-020",
"sheet": "UAT_Task_Documents",
"module": "Task Level Documents",
"role": "Manager / Staff",
"scenario": "Branch isolation",
"steps": "Attempt to view/download task document from another branch.",
"expected": "Access is blocked unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "TD-020-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-001",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create GST notice case",
"steps": "Open Notices & Cases > New and create GST notice.",
"expected": "Case is created with client, department, reference number and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-001",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create GST notice case",
"steps": "Open Notices & Cases > New and create GST notice.",
"expected": "Case is created with client, department, reference number and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-001",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create GST notice case",
"steps": "Open Notices & Cases > New and create GST notice.",
"expected": "Case is created with client, department, reference number and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-001",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create GST notice case",
"steps": "Open Notices & Cases > New and create GST notice.",
"expected": "Case is created with client, department, reference number and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-001",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create GST notice case",
"steps": "Open Notices & Cases > New and create GST notice.",
"expected": "Case is created with client, department, reference number and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-002",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create Income Tax notice case",
"steps": "Create Income Tax notice/assessment case.",
"expected": "Case is created and listed correctly.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-002",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create Income Tax notice case",
"steps": "Create Income Tax notice/assessment case.",
"expected": "Case is created and listed correctly.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-002",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create Income Tax notice case",
"steps": "Create Income Tax notice/assessment case.",
"expected": "Case is created and listed correctly.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-002",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create Income Tax notice case",
"steps": "Create Income Tax notice/assessment case.",
"expected": "Case is created and listed correctly.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-002",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create Income Tax notice case",
"steps": "Create Income Tax notice/assessment case.",
"expected": "Case is created and listed correctly.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-003",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create ROC case",
"steps": "Create ROC/MCA case.",
"expected": "Case is created and department/category is saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-003",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create ROC case",
"steps": "Create ROC/MCA case.",
"expected": "Case is created and department/category is saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-003",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create ROC case",
"steps": "Create ROC/MCA case.",
"expected": "Case is created and department/category is saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-003",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create ROC case",
"steps": "Create ROC/MCA case.",
"expected": "Case is created and department/category is saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-003",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create ROC case",
"steps": "Create ROC/MCA case.",
"expected": "Case is created and department/category is saved correctly.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-004",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner",
"scenario": "Create appeal case",
"steps": "Create Appeal case linked to client/FY/AY where applicable.",
"expected": "Appeal case is created with correct status and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-004",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner",
"scenario": "Create appeal case",
"steps": "Create Appeal case linked to client/FY/AY where applicable.",
"expected": "Appeal case is created with correct status and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-004",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner",
"scenario": "Create appeal case",
"steps": "Create Appeal case linked to client/FY/AY where applicable.",
"expected": "Appeal case is created with correct status and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-004",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner",
"scenario": "Create appeal case",
"steps": "Create Appeal case linked to client/FY/AY where applicable.",
"expected": "Appeal case is created with correct status and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-004",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner",
"scenario": "Create appeal case",
"steps": "Create Appeal case linked to client/FY/AY where applicable.",
"expected": "Appeal case is created with correct status and due date.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-005",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create rectification/refund/registration case",
"steps": "Create non-notice case type.",
"expected": "Case type is saved and appears in list/detail pages.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-005",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create rectification/refund/registration case",
"steps": "Create non-notice case type.",
"expected": "Case type is saved and appears in list/detail pages.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-005",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create rectification/refund/registration case",
"steps": "Create non-notice case type.",
"expected": "Case type is saved and appears in list/detail pages.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-005",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create rectification/refund/registration case",
"steps": "Create non-notice case type.",
"expected": "Case type is saved and appears in list/detail pages.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-005",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Create rectification/refund/registration case",
"steps": "Create non-notice case type.",
"expected": "Case type is saved and appears in list/detail pages.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-006",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Assign case to user",
"steps": "Select assigned user in case form.",
"expected": "Assignment is saved and visible in case detail/list.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-006",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Assign case to user",
"steps": "Select assigned user in case form.",
"expected": "Assignment is saved and visible in case detail/list.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-006",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Assign case to user",
"steps": "Select assigned user in case form.",
"expected": "Assignment is saved and visible in case detail/list.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-006",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Assign case to user",
"steps": "Select assigned user in case form.",
"expected": "Assignment is saved and visible in case detail/list.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-006",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / Partner / Manager",
"scenario": "Assign case to user",
"steps": "Select assigned user in case form.",
"expected": "Assignment is saved and visible in case detail/list.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-007",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Due date tracking",
"steps": "Create case with due date and check list/detail display.",
"expected": "Due date is visible; overdue/upcoming indicator works if implemented.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-007",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Due date tracking",
"steps": "Create case with due date and check list/detail display.",
"expected": "Due date is visible; overdue/upcoming indicator works if implemented.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-007",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Due date tracking",
"steps": "Create case with due date and check list/detail display.",
"expected": "Due date is visible; overdue/upcoming indicator works if implemented.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-007",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Due date tracking",
"steps": "Create case with due date and check list/detail display.",
"expected": "Due date is visible; overdue/upcoming indicator works if implemented.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-007",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Due date tracking",
"steps": "Create case with due date and check list/detail display.",
"expected": "Due date is visible; overdue/upcoming indicator works if implemented.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-008",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add timeline event",
"steps": "Add event such as Notice Received / Reply Filed / Appeal Filed.",
"expected": "Event appears in case timeline with date/user/remarks.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-008",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add timeline event",
"steps": "Add event such as Notice Received / Reply Filed / Appeal Filed.",
"expected": "Event appears in case timeline with date/user/remarks.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-008",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add timeline event",
"steps": "Add event such as Notice Received / Reply Filed / Appeal Filed.",
"expected": "Event appears in case timeline with date/user/remarks.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-008",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add timeline event",
"steps": "Add event such as Notice Received / Reply Filed / Appeal Filed.",
"expected": "Event appears in case timeline with date/user/remarks.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-008",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add timeline event",
"steps": "Add event such as Notice Received / Reply Filed / Appeal Filed.",
"expected": "Event appears in case timeline with date/user/remarks.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-009",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add hearing",
"steps": "Add hearing date, authority, mode and remarks.",
"expected": "Hearing record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-009",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add hearing",
"steps": "Add hearing date, authority, mode and remarks.",
"expected": "Hearing record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-009",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add hearing",
"steps": "Add hearing date, authority, mode and remarks.",
"expected": "Hearing record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-009",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add hearing",
"steps": "Add hearing date, authority, mode and remarks.",
"expected": "Hearing record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-009",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add hearing",
"steps": "Add hearing date, authority, mode and remarks.",
"expected": "Hearing record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-010",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add order",
"steps": "Add order details/status/date/outcome.",
"expected": "Order record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-010",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add order",
"steps": "Add order details/status/date/outcome.",
"expected": "Order record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-010",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add order",
"steps": "Add order details/status/date/outcome.",
"expected": "Order record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-010",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add order",
"steps": "Add order details/status/date/outcome.",
"expected": "Order record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-010",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Add order",
"steps": "Add order details/status/date/outcome.",
"expected": "Order record is saved and displayed.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-011",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Upload case document",
"steps": "Upload notice/reply/order/appeal PDF/DOCX.",
"expected": "Document is uploaded and linked to correct case/event if applicable.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-011-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-011",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Upload case document",
"steps": "Upload notice/reply/order/appeal PDF/DOCX.",
"expected": "Document is uploaded and linked to correct case/event if applicable.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-011-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-011",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Upload case document",
"steps": "Upload notice/reply/order/appeal PDF/DOCX.",
"expected": "Document is uploaded and linked to correct case/event if applicable.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-011",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Upload case document",
"steps": "Upload notice/reply/order/appeal PDF/DOCX.",
"expected": "Document is uploaded and linked to correct case/event if applicable.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-011-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-011",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Upload case document",
"steps": "Upload notice/reply/order/appeal PDF/DOCX.",
"expected": "Document is uploaded and linked to correct case/event if applicable.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-011-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-012",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Download case document",
"steps": "Download uploaded case document.",
"expected": "Correct document downloads; unauthorized access blocked.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-012-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-012",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Download case document",
"steps": "Download uploaded case document.",
"expected": "Correct document downloads; unauthorized access blocked.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-012-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-012",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Download case document",
"steps": "Download uploaded case document.",
"expected": "Correct document downloads; unauthorized access blocked.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-012",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Download case document",
"steps": "Download uploaded case document.",
"expected": "Correct document downloads; unauthorized access blocked.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-012-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-012",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Download case document",
"steps": "Download uploaded case document.",
"expected": "Correct document downloads; unauthorized access blocked.",
"priority": "Critical",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-012-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-013",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Change case status",
"steps": "Move case through Open/In Progress/Replied/Appealed/Closed etc.",
"expected": "Status updates correctly without losing timeline/documents.",
"priority": "Critical",
"type": "Regression",
"route": "/notice-cases",
"variantId": "NC-013-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-013",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Change case status",
"steps": "Move case through Open/In Progress/Replied/Appealed/Closed etc.",
"expected": "Status updates correctly without losing timeline/documents.",
"priority": "Critical",
"type": "Regression",
"route": "/notice-cases",
"variantId": "NC-013-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-013",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Change case status",
"steps": "Move case through Open/In Progress/Replied/Appealed/Closed etc.",
"expected": "Status updates correctly without losing timeline/documents.",
"priority": "Critical",
"type": "Regression",
"route": "/notice-cases",
"variantId": "NC-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-013",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Change case status",
"steps": "Move case through Open/In Progress/Replied/Appealed/Closed etc.",
"expected": "Status updates correctly without losing timeline/documents.",
"priority": "Critical",
"type": "Regression",
"route": "/notice-cases",
"variantId": "NC-013-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-013",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Assigned user / Manager",
"scenario": "Change case status",
"steps": "Move case through Open/In Progress/Replied/Appealed/Closed etc.",
"expected": "Status updates correctly without losing timeline/documents.",
"priority": "Critical",
"type": "Regression",
"route": "/notice-cases",
"variantId": "NC-013-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-014",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Overdue case visibility",
"steps": "Create/verify case with past due date and open list/dashboard.",
"expected": "Overdue status is visible/highlighted if configured.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-014-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-014",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Overdue case visibility",
"steps": "Create/verify case with past due date and open list/dashboard.",
"expected": "Overdue status is visible/highlighted if configured.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-014-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-014",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Overdue case visibility",
"steps": "Create/verify case with past due date and open list/dashboard.",
"expected": "Overdue status is visible/highlighted if configured.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-014",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Overdue case visibility",
"steps": "Create/verify case with past due date and open list/dashboard.",
"expected": "Overdue status is visible/highlighted if configured.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-014-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-014",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Overdue case visibility",
"steps": "Create/verify case with past due date and open list/dashboard.",
"expected": "Overdue status is visible/highlighted if configured.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-014-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-015",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Client-wise case listing",
"steps": "Filter/search cases by client.",
"expected": "Only selected client's cases are shown.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-015-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-015",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Client-wise case listing",
"steps": "Filter/search cases by client.",
"expected": "Only selected client's cases are shown.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-015-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-015",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Client-wise case listing",
"steps": "Filter/search cases by client.",
"expected": "Only selected client's cases are shown.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-015",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Client-wise case listing",
"steps": "Filter/search cases by client.",
"expected": "Only selected client's cases are shown.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-015-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-015",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Client-wise case listing",
"steps": "Filter/search cases by client.",
"expected": "Only selected client's cases are shown.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-015-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-016",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Department-wise listing",
"steps": "Filter by GST/Income Tax/ROC/PF/ESI/Other.",
"expected": "Filtered results are correct.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-016-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-016",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Department-wise listing",
"steps": "Filter by GST/Income Tax/ROC/PF/ESI/Other.",
"expected": "Filtered results are correct.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-016-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-016",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Department-wise listing",
"steps": "Filter by GST/Income Tax/ROC/PF/ESI/Other.",
"expected": "Filtered results are correct.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-016-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-016",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Department-wise listing",
"steps": "Filter by GST/Income Tax/ROC/PF/ESI/Other.",
"expected": "Filtered results are correct.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-016-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-016",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Department-wise listing",
"steps": "Filter by GST/Income Tax/ROC/PF/ESI/Other.",
"expected": "Filtered results are correct.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-016-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-017",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Search by reference number",
"steps": "Search using notice/reference/order number.",
"expected": "Correct case is found.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-017-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-017",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Search by reference number",
"steps": "Search using notice/reference/order number.",
"expected": "Correct case is found.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-017-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-017",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Search by reference number",
"steps": "Search using notice/reference/order number.",
"expected": "Correct case is found.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-017-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-017",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Search by reference number",
"steps": "Search using notice/reference/order number.",
"expected": "Correct case is found.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-017-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-017",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "Search by reference number",
"steps": "Search using notice/reference/order number.",
"expected": "Correct case is found.",
"priority": "High",
"type": "UAT",
"route": "/notice-cases",
"variantId": "NC-017-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-018",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Manager / Staff",
"scenario": "Branch visibility",
"steps": "Access cases from different branch.",
"expected": "Access is restricted as per branch permissions.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-018-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-018",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Manager / Staff",
"scenario": "Branch visibility",
"steps": "Access cases from different branch.",
"expected": "Access is restricted as per branch permissions.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-018-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-018",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Manager / Staff",
"scenario": "Branch visibility",
"steps": "Access cases from different branch.",
"expected": "Access is restricted as per branch permissions.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-018-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-018",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Manager / Staff",
"scenario": "Branch visibility",
"steps": "Access cases from different branch.",
"expected": "Access is restricted as per branch permissions.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-018-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-018",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Manager / Staff",
"scenario": "Branch visibility",
"steps": "Access cases from different branch.",
"expected": "Access is restricted as per branch permissions.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-018-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-019",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / System Admin",
"scenario": "Tenant visibility",
"steps": "Access cases from different tenant by URL/id manipulation.",
"expected": "Access is blocked unless explicit cross-tenant permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-019-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-019",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / System Admin",
"scenario": "Tenant visibility",
"steps": "Access cases from different tenant by URL/id manipulation.",
"expected": "Access is blocked unless explicit cross-tenant permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-019-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-019",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / System Admin",
"scenario": "Tenant visibility",
"steps": "Access cases from different tenant by URL/id manipulation.",
"expected": "Access is blocked unless explicit cross-tenant permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-019-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-019",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / System Admin",
"scenario": "Tenant visibility",
"steps": "Access cases from different tenant by URL/id manipulation.",
"expected": "Access is blocked unless explicit cross-tenant permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-019-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-019",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Firm Admin / System Admin",
"scenario": "Tenant visibility",
"steps": "Access cases from different tenant by URL/id manipulation.",
"expected": "Access is blocked unless explicit cross-tenant permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "NC-019-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "NC-020",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Delete/close case control",
"steps": "Attempt delete/close case with different roles.",
"expected": "Only authorized roles can delete/close; data integrity is maintained.",
"priority": "Critical",
"type": "Permission",
"route": "/notice-cases",
"variantId": "NC-020-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "NC-020",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Delete/close case control",
"steps": "Attempt delete/close case with different roles.",
"expected": "Only authorized roles can delete/close; data integrity is maintained.",
"priority": "Critical",
"type": "Permission",
"route": "/notice-cases",
"variantId": "NC-020-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "NC-020",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Delete/close case control",
"steps": "Attempt delete/close case with different roles.",
"expected": "Only authorized roles can delete/close; data integrity is maintained.",
"priority": "Critical",
"type": "Permission",
"route": "/notice-cases",
"variantId": "NC-020-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "NC-020",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Delete/close case control",
"steps": "Attempt delete/close case with different roles.",
"expected": "Only authorized roles can delete/close; data integrity is maintained.",
"priority": "Critical",
"type": "Permission",
"route": "/notice-cases",
"variantId": "NC-020-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "NC-020",
"sheet": "UAT_Notice_Cases",
"module": "Notice & Case Management",
"role": "Authorized roles",
"scenario": "Delete/close case control",
"steps": "Attempt delete/close case with different roles.",
"expected": "Only authorized roles can delete/close; data integrity is maintained.",
"priority": "Critical",
"type": "Permission",
"route": "/notice-cases",
"variantId": "NC-020-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-001",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "System Admin",
"scenario": "System Admin sees Domain Configuration",
"steps": "Login as System Admin; verify Platform menu opens and Domain Configuration section appears with all 6 child links.",
"expected": "System Admin only",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-001-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-001",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "System Admin",
"scenario": "System Admin sees Domain Configuration",
"steps": "Login as System Admin; verify Platform menu opens and Domain Configuration section appears with all 6 child links.",
"expected": "System Admin only",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-001-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-001",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "System Admin",
"scenario": "System Admin sees Domain Configuration",
"steps": "Login as System Admin; verify Platform menu opens and Domain Configuration section appears with all 6 child links.",
"expected": "System Admin only",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-001",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "System Admin",
"scenario": "System Admin sees Domain Configuration",
"steps": "Login as System Admin; verify Platform menu opens and Domain Configuration section appears with all 6 child links.",
"expected": "System Admin only",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-001-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-001",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "System Admin",
"scenario": "System Admin sees Domain Configuration",
"steps": "Login as System Admin; verify Platform menu opens and Domain Configuration section appears with all 6 child links.",
"expected": "System Admin only",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-001-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-002",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Firm Admin",
"scenario": "Firm Admin cannot see Domain Configuration",
"steps": "Login as Firm Admin; verify Platform \u2192 Domain Configuration is hidden.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-002-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-002",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Firm Admin",
"scenario": "Firm Admin cannot see Domain Configuration",
"steps": "Login as Firm Admin; verify Platform \u2192 Domain Configuration is hidden.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-002-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-002",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Firm Admin",
"scenario": "Firm Admin cannot see Domain Configuration",
"steps": "Login as Firm Admin; verify Platform \u2192 Domain Configuration is hidden.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-002",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Firm Admin",
"scenario": "Firm Admin cannot see Domain Configuration",
"steps": "Login as Firm Admin; verify Platform \u2192 Domain Configuration is hidden.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-002-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-002",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Firm Admin",
"scenario": "Firm Admin cannot see Domain Configuration",
"steps": "Login as Firm Admin; verify Platform \u2192 Domain Configuration is hidden.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-002-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-003",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Partner/Manager/Staff",
"scenario": "Partner/Manager/Staff cannot see Domain Configuration",
"steps": "Login as Partner, Manager and Staff; verify no domain management menu is visible.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-003-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-003",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Partner/Manager/Staff",
"scenario": "Partner/Manager/Staff cannot see Domain Configuration",
"steps": "Login as Partner, Manager and Staff; verify no domain management menu is visible.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-003-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-003",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Partner/Manager/Staff",
"scenario": "Partner/Manager/Staff cannot see Domain Configuration",
"steps": "Login as Partner, Manager and Staff; verify no domain management menu is visible.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-003",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Partner/Manager/Staff",
"scenario": "Partner/Manager/Staff cannot see Domain Configuration",
"steps": "Login as Partner, Manager and Staff; verify no domain management menu is visible.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-003-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-003",
"sheet": "UAT_Domains",
"module": "Sidebar/Menu",
"role": "Partner/Manager/Staff",
"scenario": "Partner/Manager/Staff cannot see Domain Configuration",
"steps": "Login as Partner, Manager and Staff; verify no domain management menu is visible.",
"expected": "Hidden",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-003-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-004",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Domain Mappings page opens",
"steps": "Open /domains as System Admin; page should load without 404/500.",
"expected": "System Admin",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-004-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-004",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Domain Mappings page opens",
"steps": "Open /domains as System Admin; page should load without 404/500.",
"expected": "System Admin",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-004-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-004",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Domain Mappings page opens",
"steps": "Open /domains as System Admin; page should load without 404/500.",
"expected": "System Admin",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-004",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Domain Mappings page opens",
"steps": "Open /domains as System Admin; page should load without 404/500.",
"expected": "System Admin",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-004-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-004",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Domain Mappings page opens",
"steps": "Open /domains as System Admin; page should load without 404/500.",
"expected": "System Admin",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-004-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-005",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Tenant Subdomains page opens",
"steps": "Open /domains/tenant-subdomains.",
"expected": "Page loads and shows tenant subdomain records/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-005-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-005",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Tenant Subdomains page opens",
"steps": "Open /domains/tenant-subdomains.",
"expected": "Page loads and shows tenant subdomain records/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-005-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-005",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Tenant Subdomains page opens",
"steps": "Open /domains/tenant-subdomains.",
"expected": "Page loads and shows tenant subdomain records/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-005",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Tenant Subdomains page opens",
"steps": "Open /domains/tenant-subdomains.",
"expected": "Page loads and shows tenant subdomain records/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-005-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-005",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Tenant Subdomains page opens",
"steps": "Open /domains/tenant-subdomains.",
"expected": "Page loads and shows tenant subdomain records/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-005-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-006",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Firm Domains page opens",
"steps": "Open /domains/firm-domain.",
"expected": "Page loads and firm-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-006-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-006",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Firm Domains page opens",
"steps": "Open /domains/firm-domain.",
"expected": "Page loads and firm-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-006-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-006",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Firm Domains page opens",
"steps": "Open /domains/firm-domain.",
"expected": "Page loads and firm-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-006",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Firm Domains page opens",
"steps": "Open /domains/firm-domain.",
"expected": "Page loads and firm-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-006-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-006",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Firm Domains page opens",
"steps": "Open /domains/firm-domain.",
"expected": "Page loads and firm-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-006-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-007",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Consultant Domains page opens",
"steps": "Open /domains/consultant-domains.",
"expected": "Page loads and consultant-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-007-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-007",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Consultant Domains page opens",
"steps": "Open /domains/consultant-domains.",
"expected": "Page loads and consultant-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-007-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-007",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Consultant Domains page opens",
"steps": "Open /domains/consultant-domains.",
"expected": "Page loads and consultant-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-007",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Consultant Domains page opens",
"steps": "Open /domains/consultant-domains.",
"expected": "Page loads and consultant-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-007-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-007",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "Consultant Domains page opens",
"steps": "Open /domains/consultant-domains.",
"expected": "Page loads and consultant-domain mapping UI visible.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-007-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-008",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "DNS Verification page opens",
"steps": "Open /domains/verification.",
"expected": "Page loads and shows DNS verification controls/status.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-008-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-008",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "DNS Verification page opens",
"steps": "Open /domains/verification.",
"expected": "Page loads and shows DNS verification controls/status.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-008-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-008",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "DNS Verification page opens",
"steps": "Open /domains/verification.",
"expected": "Page loads and shows DNS verification controls/status.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-008",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "DNS Verification page opens",
"steps": "Open /domains/verification.",
"expected": "Page loads and shows DNS verification controls/status.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-008-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-008",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "DNS Verification page opens",
"steps": "Open /domains/verification.",
"expected": "Page loads and shows DNS verification controls/status.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-008-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-009",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "SSL Status page opens",
"steps": "Open /domains/ssl.",
"expected": "Page loads and shows SSL status/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-009-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-009",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "SSL Status page opens",
"steps": "Open /domains/ssl.",
"expected": "Page loads and shows SSL status/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-009-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-009",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "SSL Status page opens",
"steps": "Open /domains/ssl.",
"expected": "Page loads and shows SSL status/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-009",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "SSL Status page opens",
"steps": "Open /domains/ssl.",
"expected": "Page loads and shows SSL status/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-009-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-009",
"sheet": "UAT_Domains",
"module": "Routes",
"role": "System Admin",
"scenario": "SSL Status page opens",
"steps": "Open /domains/ssl.",
"expected": "Page loads and shows SSL status/actions.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-009-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-010",
"sheet": "UAT_Domains",
"module": "Active State",
"role": "System Admin",
"scenario": "Correct menu item remains highlighted",
"steps": "Open each /domains path; verify correct child item highlighted.",
"expected": "Platform menu expanded; correct child highlighted.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-010-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-010",
"sheet": "UAT_Domains",
"module": "Active State",
"role": "System Admin",
"scenario": "Correct menu item remains highlighted",
"steps": "Open each /domains path; verify correct child item highlighted.",
"expected": "Platform menu expanded; correct child highlighted.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-010-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-010",
"sheet": "UAT_Domains",
"module": "Active State",
"role": "System Admin",
"scenario": "Correct menu item remains highlighted",
"steps": "Open each /domains path; verify correct child item highlighted.",
"expected": "Platform menu expanded; correct child highlighted.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-010",
"sheet": "UAT_Domains",
"module": "Active State",
"role": "System Admin",
"scenario": "Correct menu item remains highlighted",
"steps": "Open each /domains path; verify correct child item highlighted.",
"expected": "Platform menu expanded; correct child highlighted.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-010-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-010",
"sheet": "UAT_Domains",
"module": "Active State",
"role": "System Admin",
"scenario": "Correct menu item remains highlighted",
"steps": "Open each /domains path; verify correct child item highlighted.",
"expected": "Platform menu expanded; correct child highlighted.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-010-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-011",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Firm Administration menus unchanged",
"steps": "Verify Services, Clients, Consultants, Email Settings, Branding, Local Storage links still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-011-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-011",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Firm Administration menus unchanged",
"steps": "Verify Services, Clients, Consultants, Email Settings, Branding, Local Storage links still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-011-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-011",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Firm Administration menus unchanged",
"steps": "Verify Services, Clients, Consultants, Email Settings, Branding, Local Storage links still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-011",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Firm Administration menus unchanged",
"steps": "Verify Services, Clients, Consultants, Email Settings, Branding, Local Storage links still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-011-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-011",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Firm Administration menus unchanged",
"steps": "Verify Services, Clients, Consultants, Email Settings, Branding, Local Storage links still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-011-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-012",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Workspace menus unchanged",
"steps": "Verify My Workspace, Partner Workspace, Team Workspace and Team Administration menus still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-012-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-012",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Workspace menus unchanged",
"steps": "Verify My Workspace, Partner Workspace, Team Workspace and Team Administration menus still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-012-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-012",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Workspace menus unchanged",
"steps": "Verify My Workspace, Partner Workspace, Team Workspace and Team Administration menus still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-012",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Workspace menus unchanged",
"steps": "Verify My Workspace, Partner Workspace, Team Workspace and Team Administration menus still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-012-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-012",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Workspace menus unchanged",
"steps": "Verify My Workspace, Partner Workspace, Team Workspace and Team Administration menus still appear.",
"expected": "Existing menus intact.",
"priority": "Critical",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-012-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-013",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Core Setup menu unchanged",
"steps": "Verify System Settings, Audit Firms, Branches and Audit Logs remain accessible.",
"expected": "Existing menus intact.",
"priority": "High",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-013-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-013",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Core Setup menu unchanged",
"steps": "Verify System Settings, Audit Firms, Branches and Audit Logs remain accessible.",
"expected": "Existing menus intact.",
"priority": "High",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-013-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-013",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Core Setup menu unchanged",
"steps": "Verify System Settings, Audit Firms, Branches and Audit Logs remain accessible.",
"expected": "Existing menus intact.",
"priority": "High",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-013",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Core Setup menu unchanged",
"steps": "Verify System Settings, Audit Firms, Branches and Audit Logs remain accessible.",
"expected": "Existing menus intact.",
"priority": "High",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-013-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-013",
"sheet": "UAT_Domains",
"module": "No Regression",
"role": "Existing roles",
"scenario": "Existing Core Setup menu unchanged",
"steps": "Verify System Settings, Audit Firms, Branches and Audit Logs remain accessible.",
"expected": "Existing menus intact.",
"priority": "High",
"type": "Regression",
"route": "/domains",
"variantId": "DOM-UAT-013-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-014",
"sheet": "UAT_Domains",
"module": "Template Safety",
"role": "All logged-in users",
"scenario": "layout.html renders after replacement",
"steps": "Restart Uvicorn and open dashboard; verify no Jinja UndefinedError or syntax error.",
"expected": "No Jinja error.",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-014-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-014",
"sheet": "UAT_Domains",
"module": "Template Safety",
"role": "All logged-in users",
"scenario": "layout.html renders after replacement",
"steps": "Restart Uvicorn and open dashboard; verify no Jinja UndefinedError or syntax error.",
"expected": "No Jinja error.",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-014-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-014",
"sheet": "UAT_Domains",
"module": "Template Safety",
"role": "All logged-in users",
"scenario": "layout.html renders after replacement",
"steps": "Restart Uvicorn and open dashboard; verify no Jinja UndefinedError or syntax error.",
"expected": "No Jinja error.",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-014",
"sheet": "UAT_Domains",
"module": "Template Safety",
"role": "All logged-in users",
"scenario": "layout.html renders after replacement",
"steps": "Restart Uvicorn and open dashboard; verify no Jinja UndefinedError or syntax error.",
"expected": "No Jinja error.",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-014-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-014",
"sheet": "UAT_Domains",
"module": "Template Safety",
"role": "All logged-in users",
"scenario": "layout.html renders after replacement",
"steps": "Restart Uvicorn and open dashboard; verify no Jinja UndefinedError or syntax error.",
"expected": "No Jinja error.",
"priority": "Critical",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-014-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-015",
"sheet": "UAT_Domains",
"module": "Access Control",
"role": "Non-System Admin",
"scenario": "Direct URL access blocked for non-System Admin",
"steps": "Login as Firm Admin/Partner and open each /domains URL directly.",
"expected": "403/redirect; not data exposure.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-015-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-015",
"sheet": "UAT_Domains",
"module": "Access Control",
"role": "Non-System Admin",
"scenario": "Direct URL access blocked for non-System Admin",
"steps": "Login as Firm Admin/Partner and open each /domains URL directly.",
"expected": "403/redirect; not data exposure.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-015-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-015",
"sheet": "UAT_Domains",
"module": "Access Control",
"role": "Non-System Admin",
"scenario": "Direct URL access blocked for non-System Admin",
"steps": "Login as Firm Admin/Partner and open each /domains URL directly.",
"expected": "403/redirect; not data exposure.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-015",
"sheet": "UAT_Domains",
"module": "Access Control",
"role": "Non-System Admin",
"scenario": "Direct URL access blocked for non-System Admin",
"steps": "Login as Firm Admin/Partner and open each /domains URL directly.",
"expected": "403/redirect; not data exposure.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-015-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-015",
"sheet": "UAT_Domains",
"module": "Access Control",
"role": "Non-System Admin",
"scenario": "Direct URL access blocked for non-System Admin",
"steps": "Login as Firm Admin/Partner and open each /domains URL directly.",
"expected": "403/redirect; not data exposure.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-015-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-016",
"sheet": "UAT_Domains",
"module": "Tenant Safety",
"role": "Firm Admin/Partner",
"scenario": "Domain records not editable from firm context",
"steps": "Verify Firm Admin/Partner cannot create/edit/delete platform domain mappings.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-016-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-016",
"sheet": "UAT_Domains",
"module": "Tenant Safety",
"role": "Firm Admin/Partner",
"scenario": "Domain records not editable from firm context",
"steps": "Verify Firm Admin/Partner cannot create/edit/delete platform domain mappings.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-016-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-016",
"sheet": "UAT_Domains",
"module": "Tenant Safety",
"role": "Firm Admin/Partner",
"scenario": "Domain records not editable from firm context",
"steps": "Verify Firm Admin/Partner cannot create/edit/delete platform domain mappings.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-016-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-016",
"sheet": "UAT_Domains",
"module": "Tenant Safety",
"role": "Firm Admin/Partner",
"scenario": "Domain records not editable from firm context",
"steps": "Verify Firm Admin/Partner cannot create/edit/delete platform domain mappings.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-016-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-016",
"sheet": "UAT_Domains",
"module": "Tenant Safety",
"role": "Firm Admin/Partner",
"scenario": "Domain records not editable from firm context",
"steps": "Verify Firm Admin/Partner cannot create/edit/delete platform domain mappings.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-UAT-016-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-017",
"sheet": "UAT_Domains",
"module": "Data Integrity",
"role": "System Admin",
"scenario": "Saving domain mapping does not affect tenant/branch context",
"steps": "Create/update a mapping; verify normal pages still work.",
"expected": "Tenant/branch context unaffected.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-017-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-017",
"sheet": "UAT_Domains",
"module": "Data Integrity",
"role": "System Admin",
"scenario": "Saving domain mapping does not affect tenant/branch context",
"steps": "Create/update a mapping; verify normal pages still work.",
"expected": "Tenant/branch context unaffected.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-017-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-017",
"sheet": "UAT_Domains",
"module": "Data Integrity",
"role": "System Admin",
"scenario": "Saving domain mapping does not affect tenant/branch context",
"steps": "Create/update a mapping; verify normal pages still work.",
"expected": "Tenant/branch context unaffected.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-017-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-017",
"sheet": "UAT_Domains",
"module": "Data Integrity",
"role": "System Admin",
"scenario": "Saving domain mapping does not affect tenant/branch context",
"steps": "Create/update a mapping; verify normal pages still work.",
"expected": "Tenant/branch context unaffected.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-017-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-017",
"sheet": "UAT_Domains",
"module": "Data Integrity",
"role": "System Admin",
"scenario": "Saving domain mapping does not affect tenant/branch context",
"steps": "Create/update a mapping; verify normal pages still work.",
"expected": "Tenant/branch context unaffected.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-017-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-018",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Duplicate domain/subdomain validation",
"steps": "Attempt to add duplicate domain/subdomain.",
"expected": "Rejected or shows safe validation message.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-018-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-018",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Duplicate domain/subdomain validation",
"steps": "Attempt to add duplicate domain/subdomain.",
"expected": "Rejected or shows safe validation message.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-018-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-018",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Duplicate domain/subdomain validation",
"steps": "Attempt to add duplicate domain/subdomain.",
"expected": "Rejected or shows safe validation message.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-018-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-018",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Duplicate domain/subdomain validation",
"steps": "Attempt to add duplicate domain/subdomain.",
"expected": "Rejected or shows safe validation message.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-018-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-018",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Duplicate domain/subdomain validation",
"steps": "Attempt to add duplicate domain/subdomain.",
"expected": "Rejected or shows safe validation message.",
"priority": "High",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-018-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-019",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Invalid domain format validation",
"steps": "Try invalid domain values.",
"expected": "Rejected without server error.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-019-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-019",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Invalid domain format validation",
"steps": "Try invalid domain values.",
"expected": "Rejected without server error.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-019-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-019",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Invalid domain format validation",
"steps": "Try invalid domain values.",
"expected": "Rejected without server error.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-019-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-019",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Invalid domain format validation",
"steps": "Try invalid domain values.",
"expected": "Rejected without server error.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-019-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-019",
"sheet": "UAT_Domains",
"module": "Validation",
"role": "System Admin",
"scenario": "Invalid domain format validation",
"steps": "Try invalid domain values.",
"expected": "Rejected without server error.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-019-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-020",
"sheet": "UAT_Domains",
"module": "SSL Flow",
"role": "System Admin",
"scenario": "SSL status action safe when certificate absent",
"steps": "Open SSL page for domain without certificate.",
"expected": "Safe pending/not configured status, not crash.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-020-POS-01",
"variantName": "Positive primary workflow",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-020",
"sheet": "UAT_Domains",
"module": "SSL Flow",
"role": "System Admin",
"scenario": "SSL status action safe when certificate absent",
"steps": "Open SSL page for domain without certificate.",
"expected": "Safe pending/not configured status, not crash.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-020-NEG-01",
"variantName": "Negative blank/invalid validation",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-020",
"sheet": "UAT_Domains",
"module": "SSL Flow",
"role": "System Admin",
"scenario": "SSL status action safe when certificate absent",
"steps": "Open SSL page for domain without certificate.",
"expected": "Safe pending/not configured status, not crash.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-020-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-020",
"sheet": "UAT_Domains",
"module": "SSL Flow",
"role": "System Admin",
"scenario": "SSL status action safe when certificate absent",
"steps": "Open SSL page for domain without certificate.",
"expected": "Safe pending/not configured status, not crash.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-020-VAL-01",
"variantName": "Input validation and safe form submit",
"variantType": "validation",
"automation": "automated"
},
{
"sourceId": "DOM-UAT-020",
"sheet": "UAT_Domains",
"module": "SSL Flow",
"role": "System Admin",
"scenario": "SSL status action safe when certificate absent",
"steps": "Open SSL page for domain without certificate.",
"expected": "Safe pending/not configured status, not crash.",
"priority": "Medium",
"type": "UAT",
"route": "/domains",
"variantId": "DOM-UAT-020-BOUND-01",
"variantName": "Boundary length and edge input check",
"variantType": "boundary",
"automation": "automated"
},
{
"sourceId": "SEC-001",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Invalid password lockout",
"steps": "Attempt multiple wrong logins.",
"expected": "Account lockout/rate limit behavior works and does not reveal sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-001-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-001",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Invalid password lockout",
"steps": "Attempt multiple wrong logins.",
"expected": "Account lockout/rate limit behavior works and does not reveal sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-001-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-001",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Invalid password lockout",
"steps": "Attempt multiple wrong logins.",
"expected": "Account lockout/rate limit behavior works and does not reveal sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-001",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Invalid password lockout",
"steps": "Attempt multiple wrong logins.",
"expected": "Account lockout/rate limit behavior works and does not reveal sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-001-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-001",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Invalid password lockout",
"steps": "Attempt multiple wrong logins.",
"expected": "Account lockout/rate limit behavior works and does not reveal sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-001-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-002",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Session fixation/logout",
"steps": "Login/logout/back-button/session reuse tests.",
"expected": "Logged-out sessions cannot access protected pages.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-002-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-002",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Session fixation/logout",
"steps": "Login/logout/back-button/session reuse tests.",
"expected": "Logged-out sessions cannot access protected pages.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-002-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-002",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Session fixation/logout",
"steps": "Login/logout/back-button/session reuse tests.",
"expected": "Logged-out sessions cannot access protected pages.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-002",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Session fixation/logout",
"steps": "Login/logout/back-button/session reuse tests.",
"expected": "Logged-out sessions cannot access protected pages.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-002-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-002",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Session fixation/logout",
"steps": "Login/logout/back-button/session reuse tests.",
"expected": "Logged-out sessions cannot access protected pages.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-002-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-003",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Cross-tenant direct URL",
"steps": "Change client/service/employee ids in URL to another tenant.",
"expected": "403/404/redirect; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-003-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-003",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Cross-tenant direct URL",
"steps": "Change client/service/employee ids in URL to another tenant.",
"expected": "403/404/redirect; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-003-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-003",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Cross-tenant direct URL",
"steps": "Change client/service/employee ids in URL to another tenant.",
"expected": "403/404/redirect; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-003",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Cross-tenant direct URL",
"steps": "Change client/service/employee ids in URL to another tenant.",
"expected": "403/404/redirect; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-003-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-003",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Cross-tenant direct URL",
"steps": "Change client/service/employee ids in URL to another tenant.",
"expected": "403/404/redirect; no data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-003-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-004",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Branch Manager",
"scenario": "Cross-branch direct URL",
"steps": "Access records from another branch.",
"expected": "Blocked unless explicitly permitted.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-004-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-004",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Branch Manager",
"scenario": "Cross-branch direct URL",
"steps": "Access records from another branch.",
"expected": "Blocked unless explicitly permitted.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-004-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-004",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Branch Manager",
"scenario": "Cross-branch direct URL",
"steps": "Access records from another branch.",
"expected": "Blocked unless explicitly permitted.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-004",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Branch Manager",
"scenario": "Cross-branch direct URL",
"steps": "Access records from another branch.",
"expected": "Blocked unless explicitly permitted.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-004-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-004",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Branch Manager",
"scenario": "Cross-branch direct URL",
"steps": "Access records from another branch.",
"expected": "Blocked unless explicitly permitted.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-004-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-005",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client",
"scenario": "Internal note leakage",
"steps": "Client views work detail/messages.",
"expected": "Internal/partner/manager notes are hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-005-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-005",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client",
"scenario": "Internal note leakage",
"steps": "Client views work detail/messages.",
"expected": "Internal/partner/manager notes are hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-005-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-005",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client",
"scenario": "Internal note leakage",
"steps": "Client views work detail/messages.",
"expected": "Internal/partner/manager notes are hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-005",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client",
"scenario": "Internal note leakage",
"steps": "Client views work detail/messages.",
"expected": "Internal/partner/manager notes are hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-005-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-005",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client",
"scenario": "Internal note leakage",
"steps": "Client views work detail/messages.",
"expected": "Internal/partner/manager notes are hidden.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-005-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-006",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Consultant",
"scenario": "Internal engagement leakage",
"steps": "Consultant views work detail/shared docs.",
"expected": "Only referred/shared data visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/engagements",
"variantId": "SEC-006-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-006",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Consultant",
"scenario": "Internal engagement leakage",
"steps": "Consultant views work detail/shared docs.",
"expected": "Only referred/shared data visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/engagements",
"variantId": "SEC-006-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-006",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Consultant",
"scenario": "Internal engagement leakage",
"steps": "Consultant views work detail/shared docs.",
"expected": "Only referred/shared data visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/engagements",
"variantId": "SEC-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-006",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Consultant",
"scenario": "Internal engagement leakage",
"steps": "Consultant views work detail/shared docs.",
"expected": "Only referred/shared data visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/engagements",
"variantId": "SEC-006-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-006",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Consultant",
"scenario": "Internal engagement leakage",
"steps": "Consultant views work detail/shared docs.",
"expected": "Only referred/shared data visible.",
"priority": "Critical",
"type": "VAPT",
"route": "/engagements",
"variantId": "SEC-006-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-007",
"sheet": "VAPT_Security",
"module": "CSRF",
"role": "All forms",
"scenario": "CSRF token missing on POST",
"steps": "Submit forms without CSRF.",
"expected": "Request blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-007-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-007",
"sheet": "VAPT_Security",
"module": "CSRF",
"role": "All forms",
"scenario": "CSRF token missing on POST",
"steps": "Submit forms without CSRF.",
"expected": "Request blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-007-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-007",
"sheet": "VAPT_Security",
"module": "CSRF",
"role": "All forms",
"scenario": "CSRF token missing on POST",
"steps": "Submit forms without CSRF.",
"expected": "Request blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-007",
"sheet": "VAPT_Security",
"module": "CSRF",
"role": "All forms",
"scenario": "CSRF token missing on POST",
"steps": "Submit forms without CSRF.",
"expected": "Request blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-007-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-007",
"sheet": "VAPT_Security",
"module": "CSRF",
"role": "All forms",
"scenario": "CSRF token missing on POST",
"steps": "Submit forms without CSRF.",
"expected": "Request blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-007-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-008",
"sheet": "VAPT_Security",
"module": "XSS",
"role": "All input forms",
"scenario": "Stored XSS attempt",
"steps": "Enter <script> or HTML in notes/client/consultant fields.",
"expected": "Output escaped; script not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-008-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-008",
"sheet": "VAPT_Security",
"module": "XSS",
"role": "All input forms",
"scenario": "Stored XSS attempt",
"steps": "Enter <script> or HTML in notes/client/consultant fields.",
"expected": "Output escaped; script not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-008-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-008",
"sheet": "VAPT_Security",
"module": "XSS",
"role": "All input forms",
"scenario": "Stored XSS attempt",
"steps": "Enter <script> or HTML in notes/client/consultant fields.",
"expected": "Output escaped; script not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-008",
"sheet": "VAPT_Security",
"module": "XSS",
"role": "All input forms",
"scenario": "Stored XSS attempt",
"steps": "Enter <script> or HTML in notes/client/consultant fields.",
"expected": "Output escaped; script not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-008-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-008",
"sheet": "VAPT_Security",
"module": "XSS",
"role": "All input forms",
"scenario": "Stored XSS attempt",
"steps": "Enter <script> or HTML in notes/client/consultant fields.",
"expected": "Output escaped; script not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-008-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-009",
"sheet": "VAPT_Security",
"module": "File Upload",
"role": "Documents",
"scenario": "Malicious upload",
"steps": "Upload exe/html/js disguised files.",
"expected": "Rejected or safely stored; download headers safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-009-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-009",
"sheet": "VAPT_Security",
"module": "File Upload",
"role": "Documents",
"scenario": "Malicious upload",
"steps": "Upload exe/html/js disguised files.",
"expected": "Rejected or safely stored; download headers safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-009-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-009",
"sheet": "VAPT_Security",
"module": "File Upload",
"role": "Documents",
"scenario": "Malicious upload",
"steps": "Upload exe/html/js disguised files.",
"expected": "Rejected or safely stored; download headers safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-009",
"sheet": "VAPT_Security",
"module": "File Upload",
"role": "Documents",
"scenario": "Malicious upload",
"steps": "Upload exe/html/js disguised files.",
"expected": "Rejected or safely stored; download headers safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-009-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-009",
"sheet": "VAPT_Security",
"module": "File Upload",
"role": "Documents",
"scenario": "Malicious upload",
"steps": "Upload exe/html/js disguised files.",
"expected": "Rejected or safely stored; download headers safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-009-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-010",
"sheet": "VAPT_Security",
"module": "File Download",
"role": "Documents",
"scenario": "Path traversal",
"steps": "Try filename/path traversal or direct file URL manipulation.",
"expected": "Blocked; only DB-authorized file ids downloadable.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-010-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-010",
"sheet": "VAPT_Security",
"module": "File Download",
"role": "Documents",
"scenario": "Path traversal",
"steps": "Try filename/path traversal or direct file URL manipulation.",
"expected": "Blocked; only DB-authorized file ids downloadable.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-010-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-010",
"sheet": "VAPT_Security",
"module": "File Download",
"role": "Documents",
"scenario": "Path traversal",
"steps": "Try filename/path traversal or direct file URL manipulation.",
"expected": "Blocked; only DB-authorized file ids downloadable.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-010",
"sheet": "VAPT_Security",
"module": "File Download",
"role": "Documents",
"scenario": "Path traversal",
"steps": "Try filename/path traversal or direct file URL manipulation.",
"expected": "Blocked; only DB-authorized file ids downloadable.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-010-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-010",
"sheet": "VAPT_Security",
"module": "File Download",
"role": "Documents",
"scenario": "Path traversal",
"steps": "Try filename/path traversal or direct file URL manipulation.",
"expected": "Blocked; only DB-authorized file ids downloadable.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-010-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-011",
"sheet": "VAPT_Security",
"module": "Service Catalogue",
"role": "Firm Admin",
"scenario": "System-only mutation",
"steps": "Firm Admin attempts create/edit catalogue/default task URLs.",
"expected": "Blocked; Firm Admin can only firm selection/customisation.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-011-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-011",
"sheet": "VAPT_Security",
"module": "Service Catalogue",
"role": "Firm Admin",
"scenario": "System-only mutation",
"steps": "Firm Admin attempts create/edit catalogue/default task URLs.",
"expected": "Blocked; Firm Admin can only firm selection/customisation.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-011-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-011",
"sheet": "VAPT_Security",
"module": "Service Catalogue",
"role": "Firm Admin",
"scenario": "System-only mutation",
"steps": "Firm Admin attempts create/edit catalogue/default task URLs.",
"expected": "Blocked; Firm Admin can only firm selection/customisation.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-011",
"sheet": "VAPT_Security",
"module": "Service Catalogue",
"role": "Firm Admin",
"scenario": "System-only mutation",
"steps": "Firm Admin attempts create/edit catalogue/default task URLs.",
"expected": "Blocked; Firm Admin can only firm selection/customisation.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-011-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-011",
"sheet": "VAPT_Security",
"module": "Service Catalogue",
"role": "Firm Admin",
"scenario": "System-only mutation",
"steps": "Firm Admin attempts create/edit catalogue/default task URLs.",
"expected": "Blocked; Firm Admin can only firm selection/customisation.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-011-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-012",
"sheet": "VAPT_Security",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert ownership",
"steps": "User changes alert id in mark-read URL.",
"expected": "Cannot read/modify another user's alert.",
"priority": "High",
"type": "VAPT",
"route": "/alerts",
"variantId": "SEC-012-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-012",
"sheet": "VAPT_Security",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert ownership",
"steps": "User changes alert id in mark-read URL.",
"expected": "Cannot read/modify another user's alert.",
"priority": "High",
"type": "VAPT",
"route": "/alerts",
"variantId": "SEC-012-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-012",
"sheet": "VAPT_Security",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert ownership",
"steps": "User changes alert id in mark-read URL.",
"expected": "Cannot read/modify another user's alert.",
"priority": "High",
"type": "VAPT",
"route": "/alerts",
"variantId": "SEC-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-012",
"sheet": "VAPT_Security",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert ownership",
"steps": "User changes alert id in mark-read URL.",
"expected": "Cannot read/modify another user's alert.",
"priority": "High",
"type": "VAPT",
"route": "/alerts",
"variantId": "SEC-012-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-012",
"sheet": "VAPT_Security",
"module": "Alerts",
"role": "All roles",
"scenario": "Alert ownership",
"steps": "User changes alert id in mark-read URL.",
"expected": "Cannot read/modify another user's alert.",
"priority": "High",
"type": "VAPT",
"route": "/alerts",
"variantId": "SEC-012-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-013",
"sheet": "VAPT_Security",
"module": "Invite Flow",
"role": "Invited user",
"scenario": "Invite token reuse/expiry",
"steps": "Use expired or already-used invite token.",
"expected": "Rejected with safe message.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-013-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-013",
"sheet": "VAPT_Security",
"module": "Invite Flow",
"role": "Invited user",
"scenario": "Invite token reuse/expiry",
"steps": "Use expired or already-used invite token.",
"expected": "Rejected with safe message.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-013-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-013",
"sheet": "VAPT_Security",
"module": "Invite Flow",
"role": "Invited user",
"scenario": "Invite token reuse/expiry",
"steps": "Use expired or already-used invite token.",
"expected": "Rejected with safe message.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-013",
"sheet": "VAPT_Security",
"module": "Invite Flow",
"role": "Invited user",
"scenario": "Invite token reuse/expiry",
"steps": "Use expired or already-used invite token.",
"expected": "Rejected with safe message.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-013-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-013",
"sheet": "VAPT_Security",
"module": "Invite Flow",
"role": "Invited user",
"scenario": "Invite token reuse/expiry",
"steps": "Use expired or already-used invite token.",
"expected": "Rejected with safe message.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-013-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-014",
"sheet": "VAPT_Security",
"module": "API/HTML consistency",
"role": "All roles",
"scenario": "Backend permission after menu hidden",
"steps": "Directly call hidden menu URLs.",
"expected": "Backend still enforces permission; hiding menu is not sole security.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-014-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-014",
"sheet": "VAPT_Security",
"module": "API/HTML consistency",
"role": "All roles",
"scenario": "Backend permission after menu hidden",
"steps": "Directly call hidden menu URLs.",
"expected": "Backend still enforces permission; hiding menu is not sole security.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-014-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-014",
"sheet": "VAPT_Security",
"module": "API/HTML consistency",
"role": "All roles",
"scenario": "Backend permission after menu hidden",
"steps": "Directly call hidden menu URLs.",
"expected": "Backend still enforces permission; hiding menu is not sole security.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-014",
"sheet": "VAPT_Security",
"module": "API/HTML consistency",
"role": "All roles",
"scenario": "Backend permission after menu hidden",
"steps": "Directly call hidden menu URLs.",
"expected": "Backend still enforces permission; hiding menu is not sole security.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-014-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-014",
"sheet": "VAPT_Security",
"module": "API/HTML consistency",
"role": "All roles",
"scenario": "Backend permission after menu hidden",
"steps": "Directly call hidden menu URLs.",
"expected": "Backend still enforces permission; hiding menu is not sole security.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-014-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-015",
"sheet": "VAPT_Security",
"module": "Rate Limits",
"role": "Login/OTP",
"scenario": "Brute force controls",
"steps": "Repeat login/OTP attempts quickly.",
"expected": "Rate limit/lockout works; logs capture event.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-015-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-015",
"sheet": "VAPT_Security",
"module": "Rate Limits",
"role": "Login/OTP",
"scenario": "Brute force controls",
"steps": "Repeat login/OTP attempts quickly.",
"expected": "Rate limit/lockout works; logs capture event.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-015-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-015",
"sheet": "VAPT_Security",
"module": "Rate Limits",
"role": "Login/OTP",
"scenario": "Brute force controls",
"steps": "Repeat login/OTP attempts quickly.",
"expected": "Rate limit/lockout works; logs capture event.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-015",
"sheet": "VAPT_Security",
"module": "Rate Limits",
"role": "Login/OTP",
"scenario": "Brute force controls",
"steps": "Repeat login/OTP attempts quickly.",
"expected": "Rate limit/lockout works; logs capture event.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-015-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-015",
"sheet": "VAPT_Security",
"module": "Rate Limits",
"role": "Login/OTP",
"scenario": "Brute force controls",
"steps": "Repeat login/OTP attempts quickly.",
"expected": "Rate limit/lockout works; logs capture event.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-015-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-016",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Disabled/inactive user login",
"steps": "Login as deactivated or inactive user.",
"expected": "Blocked; clear error without sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-016-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-016",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Disabled/inactive user login",
"steps": "Login as deactivated or inactive user.",
"expected": "Blocked; clear error without sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-016-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-016",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Disabled/inactive user login",
"steps": "Login as deactivated or inactive user.",
"expected": "Blocked; clear error without sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-016-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-016",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Disabled/inactive user login",
"steps": "Login as deactivated or inactive user.",
"expected": "Blocked; clear error without sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-016-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-016",
"sheet": "VAPT_Security",
"module": "Authentication",
"role": "All roles",
"scenario": "Disabled/inactive user login",
"steps": "Login as deactivated or inactive user.",
"expected": "Blocked; clear error without sensitive info.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-016-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-017",
"sheet": "VAPT_Security",
"module": "Session",
"role": "All roles",
"scenario": "Cookie HttpOnly/Secure/SameSite flags",
"steps": "Inspect session cookie in browser dev tools.",
"expected": "HttpOnly, Secure (production), SameSite=Lax flags set.",
"priority": "High",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-017-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-017",
"sheet": "VAPT_Security",
"module": "Session",
"role": "All roles",
"scenario": "Cookie HttpOnly/Secure/SameSite flags",
"steps": "Inspect session cookie in browser dev tools.",
"expected": "HttpOnly, Secure (production), SameSite=Lax flags set.",
"priority": "High",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-017-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-017",
"sheet": "VAPT_Security",
"module": "Session",
"role": "All roles",
"scenario": "Cookie HttpOnly/Secure/SameSite flags",
"steps": "Inspect session cookie in browser dev tools.",
"expected": "HttpOnly, Secure (production), SameSite=Lax flags set.",
"priority": "High",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-017-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-017",
"sheet": "VAPT_Security",
"module": "Session",
"role": "All roles",
"scenario": "Cookie HttpOnly/Secure/SameSite flags",
"steps": "Inspect session cookie in browser dev tools.",
"expected": "HttpOnly, Secure (production), SameSite=Lax flags set.",
"priority": "High",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-017-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-017",
"sheet": "VAPT_Security",
"module": "Session",
"role": "All roles",
"scenario": "Cookie HttpOnly/Secure/SameSite flags",
"steps": "Inspect session cookie in browser dev tools.",
"expected": "HttpOnly, Secure (production), SameSite=Lax flags set.",
"priority": "High",
"type": "VAPT",
"route": "/login",
"variantId": "SEC-017-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-018",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Staff",
"scenario": "Staff opens /employees",
"steps": "Login as staff and attempt /employees URL.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-018-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-018",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Staff",
"scenario": "Staff opens /employees",
"steps": "Login as staff and attempt /employees URL.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-018-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-018",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Staff",
"scenario": "Staff opens /employees",
"steps": "Login as staff and attempt /employees URL.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-018-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-018",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Staff",
"scenario": "Staff opens /employees",
"steps": "Login as staff and attempt /employees URL.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-018-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-018",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Staff",
"scenario": "Staff opens /employees",
"steps": "Login as staff and attempt /employees URL.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-018-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-019",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client/Consultant",
"scenario": "Client/consultant opens internal HR/work URLs",
"steps": "Login as Client or Consultant and attempt internal URLs.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "SEC-019-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-019",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client/Consultant",
"scenario": "Client/consultant opens internal HR/work URLs",
"steps": "Login as Client or Consultant and attempt internal URLs.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "SEC-019-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-019",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client/Consultant",
"scenario": "Client/consultant opens internal HR/work URLs",
"steps": "Login as Client or Consultant and attempt internal URLs.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "SEC-019-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-019",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client/Consultant",
"scenario": "Client/consultant opens internal HR/work URLs",
"steps": "Login as Client or Consultant and attempt internal URLs.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "SEC-019-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-019",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "Client/Consultant",
"scenario": "Client/consultant opens internal HR/work URLs",
"steps": "Login as Client or Consultant and attempt internal URLs.",
"expected": "Blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/consultants",
"variantId": "SEC-019-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-020",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "All roles",
"scenario": "Non-admin imports HR/services Excel",
"steps": "Non-admin role attempts import confirm action.",
"expected": "Blocked.",
"priority": "High",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-020-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-020",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "All roles",
"scenario": "Non-admin imports HR/services Excel",
"steps": "Non-admin role attempts import confirm action.",
"expected": "Blocked.",
"priority": "High",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-020-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-020",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "All roles",
"scenario": "Non-admin imports HR/services Excel",
"steps": "Non-admin role attempts import confirm action.",
"expected": "Blocked.",
"priority": "High",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-020-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-020",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "All roles",
"scenario": "Non-admin imports HR/services Excel",
"steps": "Non-admin role attempts import confirm action.",
"expected": "Blocked.",
"priority": "High",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-020-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-020",
"sheet": "VAPT_Security",
"module": "Authorization",
"role": "All roles",
"scenario": "Non-admin imports HR/services Excel",
"steps": "Non-admin role attempts import confirm action.",
"expected": "Blocked.",
"priority": "High",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-020-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-021",
"sheet": "VAPT_Security",
"module": "Injection",
"role": "All roles",
"scenario": "SQL injection in search/id params",
"steps": "Use SQL payloads such as ' OR 1=1 -- in search/id fields.",
"expected": "No SQL error or data leak; ORM protects correctly.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-021-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-021",
"sheet": "VAPT_Security",
"module": "Injection",
"role": "All roles",
"scenario": "SQL injection in search/id params",
"steps": "Use SQL payloads such as ' OR 1=1 -- in search/id fields.",
"expected": "No SQL error or data leak; ORM protects correctly.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-021-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-021",
"sheet": "VAPT_Security",
"module": "Injection",
"role": "All roles",
"scenario": "SQL injection in search/id params",
"steps": "Use SQL payloads such as ' OR 1=1 -- in search/id fields.",
"expected": "No SQL error or data leak; ORM protects correctly.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-021-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-021",
"sheet": "VAPT_Security",
"module": "Injection",
"role": "All roles",
"scenario": "SQL injection in search/id params",
"steps": "Use SQL payloads such as ' OR 1=1 -- in search/id fields.",
"expected": "No SQL error or data leak; ORM protects correctly.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-021-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-021",
"sheet": "VAPT_Security",
"module": "Injection",
"role": "All roles",
"scenario": "SQL injection in search/id params",
"steps": "Use SQL payloads such as ' OR 1=1 -- in search/id fields.",
"expected": "No SQL error or data leak; ORM protects correctly.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-021-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-022",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Employee approves own leave/OD",
"steps": "Employee attempts to approve own leave/OD request.",
"expected": "Blocked; self-approval not allowed.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-022-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-022",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Employee approves own leave/OD",
"steps": "Employee attempts to approve own leave/OD request.",
"expected": "Blocked; self-approval not allowed.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-022-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-022",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Employee approves own leave/OD",
"steps": "Employee attempts to approve own leave/OD request.",
"expected": "Blocked; self-approval not allowed.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-022-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-022",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Employee approves own leave/OD",
"steps": "Employee attempts to approve own leave/OD request.",
"expected": "Blocked; self-approval not allowed.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-022-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-022",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Employee approves own leave/OD",
"steps": "Employee attempts to approve own leave/OD request.",
"expected": "Blocked; self-approval not allowed.",
"priority": "High",
"type": "VAPT",
"route": "/employees",
"variantId": "SEC-022-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-023",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Payroll role",
"scenario": "Payroll marked paid without approval",
"steps": "Attempt to mark payroll as paid without approval step.",
"expected": "Blocked if approval required.",
"priority": "High",
"type": "VAPT",
"route": "/employee/payroll",
"variantId": "SEC-023-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-023",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Payroll role",
"scenario": "Payroll marked paid without approval",
"steps": "Attempt to mark payroll as paid without approval step.",
"expected": "Blocked if approval required.",
"priority": "High",
"type": "VAPT",
"route": "/employee/payroll",
"variantId": "SEC-023-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-023",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Payroll role",
"scenario": "Payroll marked paid without approval",
"steps": "Attempt to mark payroll as paid without approval step.",
"expected": "Blocked if approval required.",
"priority": "High",
"type": "VAPT",
"route": "/employee/payroll",
"variantId": "SEC-023-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-023",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Payroll role",
"scenario": "Payroll marked paid without approval",
"steps": "Attempt to mark payroll as paid without approval step.",
"expected": "Blocked if approval required.",
"priority": "High",
"type": "VAPT",
"route": "/employee/payroll",
"variantId": "SEC-023-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-023",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Payroll role",
"scenario": "Payroll marked paid without approval",
"steps": "Attempt to mark payroll as paid without approval step.",
"expected": "Blocked if approval required.",
"priority": "High",
"type": "VAPT",
"route": "/employee/payroll",
"variantId": "SEC-023-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-024",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Staff changes hidden tenant/branch ids in form",
"steps": "Submit form with modified hidden tenant/branch field values.",
"expected": "Server ignores/validates against session scope.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-024-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-024",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Staff changes hidden tenant/branch ids in form",
"steps": "Submit form with modified hidden tenant/branch field values.",
"expected": "Server ignores/validates against session scope.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-024-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-024",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Staff changes hidden tenant/branch ids in form",
"steps": "Submit form with modified hidden tenant/branch field values.",
"expected": "Server ignores/validates against session scope.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-024-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-024",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Staff changes hidden tenant/branch ids in form",
"steps": "Submit form with modified hidden tenant/branch field values.",
"expected": "Server ignores/validates against session scope.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-024-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-024",
"sheet": "VAPT_Security",
"module": "Business Logic",
"role": "Staff",
"scenario": "Staff changes hidden tenant/branch ids in form",
"steps": "Submit form with modified hidden tenant/branch field values.",
"expected": "Server ignores/validates against session scope.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-024-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-025",
"sheet": "VAPT_Security",
"module": "Error Handling",
"role": "All roles",
"scenario": "Invalid URL/DB error response",
"steps": "Hit invalid URLs and trigger DB errors in production mode.",
"expected": "No stack trace or SQL details leaked.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-025-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-025",
"sheet": "VAPT_Security",
"module": "Error Handling",
"role": "All roles",
"scenario": "Invalid URL/DB error response",
"steps": "Hit invalid URLs and trigger DB errors in production mode.",
"expected": "No stack trace or SQL details leaked.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-025-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-025",
"sheet": "VAPT_Security",
"module": "Error Handling",
"role": "All roles",
"scenario": "Invalid URL/DB error response",
"steps": "Hit invalid URLs and trigger DB errors in production mode.",
"expected": "No stack trace or SQL details leaked.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-025-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-025",
"sheet": "VAPT_Security",
"module": "Error Handling",
"role": "All roles",
"scenario": "Invalid URL/DB error response",
"steps": "Hit invalid URLs and trigger DB errors in production mode.",
"expected": "No stack trace or SQL details leaked.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-025-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-025",
"sheet": "VAPT_Security",
"module": "Error Handling",
"role": "All roles",
"scenario": "Invalid URL/DB error response",
"steps": "Hit invalid URLs and trigger DB errors in production mode.",
"expected": "No stack trace or SQL details leaked.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-025-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-026",
"sheet": "VAPT_Security",
"module": "Security Headers",
"role": "All roles",
"scenario": "CSP/X-Frame/X-Content-Type/Referrer/HSTS headers",
"steps": "Check response headers on any page.",
"expected": "Headers present and correctly configured per environment.",
"priority": "Medium",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-026-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-026",
"sheet": "VAPT_Security",
"module": "Security Headers",
"role": "All roles",
"scenario": "CSP/X-Frame/X-Content-Type/Referrer/HSTS headers",
"steps": "Check response headers on any page.",
"expected": "Headers present and correctly configured per environment.",
"priority": "Medium",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-026-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-026",
"sheet": "VAPT_Security",
"module": "Security Headers",
"role": "All roles",
"scenario": "CSP/X-Frame/X-Content-Type/Referrer/HSTS headers",
"steps": "Check response headers on any page.",
"expected": "Headers present and correctly configured per environment.",
"priority": "Medium",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-026-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-026",
"sheet": "VAPT_Security",
"module": "Security Headers",
"role": "All roles",
"scenario": "CSP/X-Frame/X-Content-Type/Referrer/HSTS headers",
"steps": "Check response headers on any page.",
"expected": "Headers present and correctly configured per environment.",
"priority": "Medium",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-026-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-026",
"sheet": "VAPT_Security",
"module": "Security Headers",
"role": "All roles",
"scenario": "CSP/X-Frame/X-Content-Type/Referrer/HSTS headers",
"steps": "Check response headers on any page.",
"expected": "Headers present and correctly configured per environment.",
"priority": "Medium",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-026-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-027",
"sheet": "VAPT_Security",
"module": "Configuration",
"role": "System Admin",
"scenario": "Secret key/.env/debug mode/upload dirs",
"steps": "Verify production deployment configuration.",
"expected": "DEBUG=False, COOKIE_SECURE=True, SECRET_KEY changed from default, no .env committed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-027-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-027",
"sheet": "VAPT_Security",
"module": "Configuration",
"role": "System Admin",
"scenario": "Secret key/.env/debug mode/upload dirs",
"steps": "Verify production deployment configuration.",
"expected": "DEBUG=False, COOKIE_SECURE=True, SECRET_KEY changed from default, no .env committed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-027-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-027",
"sheet": "VAPT_Security",
"module": "Configuration",
"role": "System Admin",
"scenario": "Secret key/.env/debug mode/upload dirs",
"steps": "Verify production deployment configuration.",
"expected": "DEBUG=False, COOKIE_SECURE=True, SECRET_KEY changed from default, no .env committed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-027-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-027",
"sheet": "VAPT_Security",
"module": "Configuration",
"role": "System Admin",
"scenario": "Secret key/.env/debug mode/upload dirs",
"steps": "Verify production deployment configuration.",
"expected": "DEBUG=False, COOKIE_SECURE=True, SECRET_KEY changed from default, no .env committed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-027-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-027",
"sheet": "VAPT_Security",
"module": "Configuration",
"role": "System Admin",
"scenario": "Secret key/.env/debug mode/upload dirs",
"steps": "Verify production deployment configuration.",
"expected": "DEBUG=False, COOKIE_SECURE=True, SECRET_KEY changed from default, no .env committed.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-027-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-101",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct access to another tenant's notice",
"steps": "Manually change notice/case id in URL to another tenant's case.",
"expected": "403/404/redirect; no case data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-101-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "manual",
"manualReason": "Marked manual in source checklist."
},
{
"sourceId": "SEC-101",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct access to another tenant's notice",
"steps": "Manually change notice/case id in URL to another tenant's case.",
"expected": "403/404/redirect; no case data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-101-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "manual",
"manualReason": "Marked manual in source checklist."
},
{
"sourceId": "SEC-101",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct access to another tenant's notice",
"steps": "Manually change notice/case id in URL to another tenant's case.",
"expected": "403/404/redirect; no case data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-101-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "manual",
"manualReason": "Marked manual in source checklist."
},
{
"sourceId": "SEC-101",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct access to another tenant's notice",
"steps": "Manually change notice/case id in URL to another tenant's case.",
"expected": "403/404/redirect; no case data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-101-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "manual",
"manualReason": "Marked manual in source checklist."
},
{
"sourceId": "SEC-101",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct access to another tenant's notice",
"steps": "Manually change notice/case id in URL to another tenant's case.",
"expected": "403/404/redirect; no case data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-101-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "manual",
"manualReason": "Marked manual in source checklist."
},
{
"sourceId": "SEC-102",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Branch-restricted user",
"scenario": "Direct access to another branch's notice",
"steps": "Change id to case belonging to another branch.",
"expected": "Access denied unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-102-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-102",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Branch-restricted user",
"scenario": "Direct access to another branch's notice",
"steps": "Change id to case belonging to another branch.",
"expected": "Access denied unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-102-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-102",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Branch-restricted user",
"scenario": "Direct access to another branch's notice",
"steps": "Change id to case belonging to another branch.",
"expected": "Access denied unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-102-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-102",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Branch-restricted user",
"scenario": "Direct access to another branch's notice",
"steps": "Change id to case belonging to another branch.",
"expected": "Access denied unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-102-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-102",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Branch-restricted user",
"scenario": "Direct access to another branch's notice",
"steps": "Change id to case belonging to another branch.",
"expected": "Access denied unless cross-branch permission exists.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-102-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-103",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "Direct download of task document by URL manipulation",
"steps": "Modify document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-103-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-103",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "Direct download of task document by URL manipulation",
"steps": "Modify document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-103-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-103",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "Direct download of task document by URL manipulation",
"steps": "Modify document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-103-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-103",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "Direct download of task document by URL manipulation",
"steps": "Modify document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-103-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-103",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "Direct download of task document by URL manipulation",
"steps": "Modify document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/services",
"variantId": "SEC-103-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-104",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct download of case document by URL manipulation",
"steps": "Modify case document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-104-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-104",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct download of case document by URL manipulation",
"steps": "Modify case document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-104-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-104",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct download of case document by URL manipulation",
"steps": "Modify case document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-104-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-104",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct download of case document by URL manipulation",
"steps": "Modify case document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-104-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-104",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Direct download of case document by URL manipulation",
"steps": "Modify case document id/download URL.",
"expected": "Download is blocked; no file leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-104-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-105",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload executable file renamed as PDF",
"steps": "Rename .exe/.bat to .pdf and upload.",
"expected": "Upload is rejected or safely quarantined; no execution risk.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-105-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-105",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload executable file renamed as PDF",
"steps": "Rename .exe/.bat to .pdf and upload.",
"expected": "Upload is rejected or safely quarantined; no execution risk.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-105-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-105",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload executable file renamed as PDF",
"steps": "Rename .exe/.bat to .pdf and upload.",
"expected": "Upload is rejected or safely quarantined; no execution risk.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-105-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-105",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload executable file renamed as PDF",
"steps": "Rename .exe/.bat to .pdf and upload.",
"expected": "Upload is rejected or safely quarantined; no execution risk.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-105-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-105",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload executable file renamed as PDF",
"steps": "Rename .exe/.bat to .pdf and upload.",
"expected": "Upload is rejected or safely quarantined; no execution risk.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-105-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-106",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload oversized file",
"steps": "Upload file beyond configured limit.",
"expected": "Upload is blocked or handled gracefully.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-106-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-106",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload oversized file",
"steps": "Upload file beyond configured limit.",
"expected": "Upload is blocked or handled gracefully.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-106-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-106",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload oversized file",
"steps": "Upload file beyond configured limit.",
"expected": "Upload is blocked or handled gracefully.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-106-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-106",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload oversized file",
"steps": "Upload file beyond configured limit.",
"expected": "Upload is blocked or handled gracefully.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-106-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-106",
"sheet": "VAPT_Security",
"module": "File Upload Security",
"role": "All upload roles",
"scenario": "Upload oversized file",
"steps": "Upload file beyond configured limit.",
"expected": "Upload is blocked or handled gracefully.",
"priority": "High",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-106-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-107",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Unauthorized user creates case",
"steps": "Login as user without case create permission and access /notice-cases/new.",
"expected": "Action is blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-107-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-107",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Unauthorized user creates case",
"steps": "Login as user without case create permission and access /notice-cases/new.",
"expected": "Action is blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-107-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-107",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Unauthorized user creates case",
"steps": "Login as user without case create permission and access /notice-cases/new.",
"expected": "Action is blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-107-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-107",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Unauthorized user creates case",
"steps": "Login as user without case create permission and access /notice-cases/new.",
"expected": "Action is blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-107-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-107",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "Unauthorized user creates case",
"steps": "Login as user without case create permission and access /notice-cases/new.",
"expected": "Action is blocked.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-107-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-108",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Staff",
"scenario": "Staff accesses management-only case",
"steps": "Login as staff and access restricted management case.",
"expected": "Action is blocked or limited to permitted records.",
"priority": "High",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-108-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-108",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Staff",
"scenario": "Staff accesses management-only case",
"steps": "Login as staff and access restricted management case.",
"expected": "Action is blocked or limited to permitted records.",
"priority": "High",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-108-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-108",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Staff",
"scenario": "Staff accesses management-only case",
"steps": "Login as staff and access restricted management case.",
"expected": "Action is blocked or limited to permitted records.",
"priority": "High",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-108-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-108",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Staff",
"scenario": "Staff accesses management-only case",
"steps": "Login as staff and access restricted management case.",
"expected": "Action is blocked or limited to permitted records.",
"priority": "High",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-108-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-108",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Staff",
"scenario": "Staff accesses management-only case",
"steps": "Login as staff and access restricted management case.",
"expected": "Action is blocked or limited to permitted records.",
"priority": "High",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-108-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-109",
"sheet": "VAPT_Security",
"module": "Search / Filtering",
"role": "Branch/Tenant user",
"scenario": "Cross-tenant search leakage",
"steps": "Search using client/reference keywords from another tenant.",
"expected": "No cross-tenant results shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-109-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-109",
"sheet": "VAPT_Security",
"module": "Search / Filtering",
"role": "Branch/Tenant user",
"scenario": "Cross-tenant search leakage",
"steps": "Search using client/reference keywords from another tenant.",
"expected": "No cross-tenant results shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-109-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-109",
"sheet": "VAPT_Security",
"module": "Search / Filtering",
"role": "Branch/Tenant user",
"scenario": "Cross-tenant search leakage",
"steps": "Search using client/reference keywords from another tenant.",
"expected": "No cross-tenant results shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-109-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-109",
"sheet": "VAPT_Security",
"module": "Search / Filtering",
"role": "Branch/Tenant user",
"scenario": "Cross-tenant search leakage",
"steps": "Search using client/reference keywords from another tenant.",
"expected": "No cross-tenant results shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-109-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-109",
"sheet": "VAPT_Security",
"module": "Search / Filtering",
"role": "Branch/Tenant user",
"scenario": "Cross-tenant search leakage",
"steps": "Search using client/reference keywords from another tenant.",
"expected": "No cross-tenant results shown.",
"priority": "Critical",
"type": "VAPT",
"route": "/employee/dashboard",
"variantId": "SEC-109-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-110",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "IDOR on notice-case IDs",
"steps": "Enumerate notice-case ids in URLs/API calls.",
"expected": "Unauthorized records are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-110-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-110",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "IDOR on notice-case IDs",
"steps": "Enumerate notice-case ids in URLs/API calls.",
"expected": "Unauthorized records are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-110-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-110",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "IDOR on notice-case IDs",
"steps": "Enumerate notice-case ids in URLs/API calls.",
"expected": "Unauthorized records are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-110-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-110",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "IDOR on notice-case IDs",
"steps": "Enumerate notice-case ids in URLs/API calls.",
"expected": "Unauthorized records are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-110-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-110",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "Unauthorized user",
"scenario": "IDOR on notice-case IDs",
"steps": "Enumerate notice-case ids in URLs/API calls.",
"expected": "Unauthorized records are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-110-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-111",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "IDOR on task-document IDs",
"steps": "Enumerate task document ids in URLs/API calls.",
"expected": "Unauthorized records/files are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-111-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-111",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "IDOR on task-document IDs",
"steps": "Enumerate task document ids in URLs/API calls.",
"expected": "Unauthorized records/files are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-111-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-111",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "IDOR on task-document IDs",
"steps": "Enumerate task document ids in URLs/API calls.",
"expected": "Unauthorized records/files are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-111-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-111",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "IDOR on task-document IDs",
"steps": "Enumerate task document ids in URLs/API calls.",
"expected": "Unauthorized records/files are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-111-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-111",
"sheet": "VAPT_Security",
"module": "Task Level Documents",
"role": "Unauthorized user",
"scenario": "IDOR on task-document IDs",
"steps": "Enumerate task document ids in URLs/API calls.",
"expected": "Unauthorized records/files are not returned.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-111-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-112",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in case remarks",
"steps": "Enter <script> payload in case remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-112-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-112",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in case remarks",
"steps": "Enter <script> payload in case remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-112-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-112",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in case remarks",
"steps": "Enter <script> payload in case remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-112-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-112",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in case remarks",
"steps": "Enter <script> payload in case remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-112-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-112",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in case remarks",
"steps": "Enter <script> payload in case remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-112-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-113",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in hearing remarks",
"steps": "Enter script payload in hearing remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-113-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-113",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in hearing remarks",
"steps": "Enter script payload in hearing remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-113-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-113",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in hearing remarks",
"steps": "Enter script payload in hearing remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-113-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-113",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in hearing remarks",
"steps": "Enter script payload in hearing remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-113-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-113",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All roles",
"scenario": "Stored XSS in hearing remarks",
"steps": "Enter script payload in hearing remarks.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-113-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-114",
"sheet": "VAPT_Security",
"module": "Documents",
"role": "All upload roles",
"scenario": "Stored XSS in document description",
"steps": "Enter script payload in document description/title.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-114-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-114",
"sheet": "VAPT_Security",
"module": "Documents",
"role": "All upload roles",
"scenario": "Stored XSS in document description",
"steps": "Enter script payload in document description/title.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-114-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-114",
"sheet": "VAPT_Security",
"module": "Documents",
"role": "All upload roles",
"scenario": "Stored XSS in document description",
"steps": "Enter script payload in document description/title.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-114-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-114",
"sheet": "VAPT_Security",
"module": "Documents",
"role": "All upload roles",
"scenario": "Stored XSS in document description",
"steps": "Enter script payload in document description/title.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-114-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-114",
"sheet": "VAPT_Security",
"module": "Documents",
"role": "All upload roles",
"scenario": "Stored XSS in document description",
"steps": "Enter script payload in document description/title.",
"expected": "Script is escaped/sanitized and not executed.",
"priority": "Critical",
"type": "VAPT",
"route": "/documents",
"variantId": "SEC-114-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "SEC-115",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "SQL injection in case search",
"steps": "Search using SQL payloads such as ' OR 1=1 --.",
"expected": "No SQL error; results remain scoped and safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-115-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "SEC-115",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "SQL injection in case search",
"steps": "Search using SQL payloads such as ' OR 1=1 --.",
"expected": "No SQL error; results remain scoped and safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-115-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "SEC-115",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "SQL injection in case search",
"steps": "Search using SQL payloads such as ' OR 1=1 --.",
"expected": "No SQL error; results remain scoped and safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-115-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "SEC-115",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "SQL injection in case search",
"steps": "Search using SQL payloads such as ' OR 1=1 --.",
"expected": "No SQL error; results remain scoped and safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-115-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "SEC-115",
"sheet": "VAPT_Security",
"module": "Notice & Case Management",
"role": "All permitted roles",
"scenario": "SQL injection in case search",
"steps": "Search using SQL payloads such as ' OR 1=1 --.",
"expected": "No SQL error; results remain scoped and safe.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "SEC-115-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-001",
"sheet": "VAPT_Domains",
"module": "Authentication",
"role": "Unauthenticated user",
"scenario": "Unauthenticated user cannot access domain pages",
"steps": "Logout and open every /domains URL.",
"expected": "Redirect/login or 401/403, not page content.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-001-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-001",
"sheet": "VAPT_Domains",
"module": "Authentication",
"role": "Unauthenticated user",
"scenario": "Unauthenticated user cannot access domain pages",
"steps": "Logout and open every /domains URL.",
"expected": "Redirect/login or 401/403, not page content.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-001-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-001",
"sheet": "VAPT_Domains",
"module": "Authentication",
"role": "Unauthenticated user",
"scenario": "Unauthenticated user cannot access domain pages",
"steps": "Logout and open every /domains URL.",
"expected": "Redirect/login or 401/403, not page content.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-001-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-001",
"sheet": "VAPT_Domains",
"module": "Authentication",
"role": "Unauthenticated user",
"scenario": "Unauthenticated user cannot access domain pages",
"steps": "Logout and open every /domains URL.",
"expected": "Redirect/login or 401/403, not page content.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-001-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-001",
"sheet": "VAPT_Domains",
"module": "Authentication",
"role": "Unauthenticated user",
"scenario": "Unauthenticated user cannot access domain pages",
"steps": "Logout and open every /domains URL.",
"expected": "Redirect/login or 401/403, not page content.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-001-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-002",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Firm Admin direct URL access is blocked",
"steps": "Login as Firm Admin and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-002-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-002",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Firm Admin direct URL access is blocked",
"steps": "Login as Firm Admin and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-002-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-002",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Firm Admin direct URL access is blocked",
"steps": "Login as Firm Admin and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-002-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-002",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Firm Admin direct URL access is blocked",
"steps": "Login as Firm Admin and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-002-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-002",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Firm Admin",
"scenario": "Firm Admin direct URL access is blocked",
"steps": "Login as Firm Admin and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-002-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-003",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Partner/Staff",
"scenario": "Partner/Staff direct URL access is blocked",
"steps": "Login as Partner/Staff and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-003-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-003",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Partner/Staff",
"scenario": "Partner/Staff direct URL access is blocked",
"steps": "Login as Partner/Staff and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-003-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-003",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Partner/Staff",
"scenario": "Partner/Staff direct URL access is blocked",
"steps": "Login as Partner/Staff and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-003-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-003",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Partner/Staff",
"scenario": "Partner/Staff direct URL access is blocked",
"steps": "Login as Partner/Staff and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-003-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-003",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Partner/Staff",
"scenario": "Partner/Staff direct URL access is blocked",
"steps": "Login as Partner/Staff and open every /domains URL.",
"expected": "403/redirect.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-003-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-004",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Non-System Admin",
"scenario": "POST/PUT/DELETE actions require System Admin",
"steps": "Attempt create/update/delete request as non-System Admin.",
"expected": "403/CSRF rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-004-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-004",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Non-System Admin",
"scenario": "POST/PUT/DELETE actions require System Admin",
"steps": "Attempt create/update/delete request as non-System Admin.",
"expected": "403/CSRF rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-004-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-004",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Non-System Admin",
"scenario": "POST/PUT/DELETE actions require System Admin",
"steps": "Attempt create/update/delete request as non-System Admin.",
"expected": "403/CSRF rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-004-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-004",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Non-System Admin",
"scenario": "POST/PUT/DELETE actions require System Admin",
"steps": "Attempt create/update/delete request as non-System Admin.",
"expected": "403/CSRF rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-004-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-004",
"sheet": "VAPT_Domains",
"module": "Authorization",
"role": "Non-System Admin",
"scenario": "POST/PUT/DELETE actions require System Admin",
"steps": "Attempt create/update/delete request as non-System Admin.",
"expected": "403/CSRF rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-004-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-005",
"sheet": "VAPT_Domains",
"module": "CSRF",
"role": "All forms",
"scenario": "Domain configuration forms require CSRF token",
"steps": "Submit without/invalid CSRF token.",
"expected": "Rejection and no DB write.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-005-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-005",
"sheet": "VAPT_Domains",
"module": "CSRF",
"role": "All forms",
"scenario": "Domain configuration forms require CSRF token",
"steps": "Submit without/invalid CSRF token.",
"expected": "Rejection and no DB write.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-005-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-005",
"sheet": "VAPT_Domains",
"module": "CSRF",
"role": "All forms",
"scenario": "Domain configuration forms require CSRF token",
"steps": "Submit without/invalid CSRF token.",
"expected": "Rejection and no DB write.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-005-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-005",
"sheet": "VAPT_Domains",
"module": "CSRF",
"role": "All forms",
"scenario": "Domain configuration forms require CSRF token",
"steps": "Submit without/invalid CSRF token.",
"expected": "Rejection and no DB write.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-005-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-005",
"sheet": "VAPT_Domains",
"module": "CSRF",
"role": "All forms",
"scenario": "Domain configuration forms require CSRF token",
"steps": "Submit without/invalid CSRF token.",
"expected": "Rejection and no DB write.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-005-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-006",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects script tags and HTML injection",
"steps": "Enter <script> payload in domain/name fields.",
"expected": "Escaped display/no execution.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-006-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-006",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects script tags and HTML injection",
"steps": "Enter <script> payload in domain/name fields.",
"expected": "Escaped display/no execution.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-006-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-006",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects script tags and HTML injection",
"steps": "Enter <script> payload in domain/name fields.",
"expected": "Escaped display/no execution.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-006-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-006",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects script tags and HTML injection",
"steps": "Enter <script> payload in domain/name fields.",
"expected": "Escaped display/no execution.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-006-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-006",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects script tags and HTML injection",
"steps": "Enter <script> payload in domain/name fields.",
"expected": "Escaped display/no execution.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-006-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-007",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects path/URL injection",
"steps": "Try values like https://evil.com/path, ../admin, or domain with spaces.",
"expected": "Validation failure.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-007-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-007",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects path/URL injection",
"steps": "Try values like https://evil.com/path, ../admin, or domain with spaces.",
"expected": "Validation failure.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-007-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-007",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects path/URL injection",
"steps": "Try values like https://evil.com/path, ../admin, or domain with spaces.",
"expected": "Validation failure.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-007-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-007",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects path/URL injection",
"steps": "Try values like https://evil.com/path, ../admin, or domain with spaces.",
"expected": "Validation failure.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-007-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-007",
"sheet": "VAPT_Domains",
"module": "Input Validation",
"role": "All roles",
"scenario": "Domain field rejects path/URL injection",
"steps": "Try values like https://evil.com/path, ../admin, or domain with spaces.",
"expected": "Validation failure.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-007-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-008",
"sheet": "VAPT_Domains",
"module": "Tenant Isolation",
"role": "System Admin",
"scenario": "Domain mapping cannot be used to view another tenant data",
"steps": "Map test domain to Tenant A, then attempt access to Tenant B records.",
"expected": "Tenant isolation maintained.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-008-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-008",
"sheet": "VAPT_Domains",
"module": "Tenant Isolation",
"role": "System Admin",
"scenario": "Domain mapping cannot be used to view another tenant data",
"steps": "Map test domain to Tenant A, then attempt access to Tenant B records.",
"expected": "Tenant isolation maintained.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-008-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-008",
"sheet": "VAPT_Domains",
"module": "Tenant Isolation",
"role": "System Admin",
"scenario": "Domain mapping cannot be used to view another tenant data",
"steps": "Map test domain to Tenant A, then attempt access to Tenant B records.",
"expected": "Tenant isolation maintained.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-008-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-008",
"sheet": "VAPT_Domains",
"module": "Tenant Isolation",
"role": "System Admin",
"scenario": "Domain mapping cannot be used to view another tenant data",
"steps": "Map test domain to Tenant A, then attempt access to Tenant B records.",
"expected": "Tenant isolation maintained.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-008-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-008",
"sheet": "VAPT_Domains",
"module": "Tenant Isolation",
"role": "System Admin",
"scenario": "Domain mapping cannot be used to view another tenant data",
"steps": "Map test domain to Tenant A, then attempt access to Tenant B records.",
"expected": "Tenant isolation maintained.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-008-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-009",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Unknown Host header does not resolve to tenant data",
"steps": "Send request with unknown Host.",
"expected": "Default/login/error, not tenant data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-009-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-009",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Unknown Host header does not resolve to tenant data",
"steps": "Send request with unknown Host.",
"expected": "Default/login/error, not tenant data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-009-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-009",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Unknown Host header does not resolve to tenant data",
"steps": "Send request with unknown Host.",
"expected": "Default/login/error, not tenant data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-009-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-009",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Unknown Host header does not resolve to tenant data",
"steps": "Send request with unknown Host.",
"expected": "Default/login/error, not tenant data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-009-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-009",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Unknown Host header does not resolve to tenant data",
"steps": "Send request with unknown Host.",
"expected": "Default/login/error, not tenant data leakage.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-009-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-010",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Malformed Host header is safely handled",
"steps": "Use malformed/long Host header.",
"expected": "Safe rejection/no crash.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-010-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-010",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Malformed Host header is safely handled",
"steps": "Use malformed/long Host header.",
"expected": "Safe rejection/no crash.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-010-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-010",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Malformed Host header is safely handled",
"steps": "Use malformed/long Host header.",
"expected": "Safe rejection/no crash.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-010-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-010",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Malformed Host header is safely handled",
"steps": "Use malformed/long Host header.",
"expected": "Safe rejection/no crash.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-010-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-010",
"sheet": "VAPT_Domains",
"module": "Host Header",
"role": "All roles",
"scenario": "Malformed Host header is safely handled",
"steps": "Use malformed/long Host header.",
"expected": "Safe rejection/no crash.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-010-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-011",
"sheet": "VAPT_Domains",
"module": "DNS Verification",
"role": "System Admin",
"scenario": "Verification token cannot be guessed or reused across tenant",
"steps": "Try using one tenant verification token for another.",
"expected": "Rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-011-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-011",
"sheet": "VAPT_Domains",
"module": "DNS Verification",
"role": "System Admin",
"scenario": "Verification token cannot be guessed or reused across tenant",
"steps": "Try using one tenant verification token for another.",
"expected": "Rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-011-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-011",
"sheet": "VAPT_Domains",
"module": "DNS Verification",
"role": "System Admin",
"scenario": "Verification token cannot be guessed or reused across tenant",
"steps": "Try using one tenant verification token for another.",
"expected": "Rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-011-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-011",
"sheet": "VAPT_Domains",
"module": "DNS Verification",
"role": "System Admin",
"scenario": "Verification token cannot be guessed or reused across tenant",
"steps": "Try using one tenant verification token for another.",
"expected": "Rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-011-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-011",
"sheet": "VAPT_Domains",
"module": "DNS Verification",
"role": "System Admin",
"scenario": "Verification token cannot be guessed or reused across tenant",
"steps": "Try using one tenant verification token for another.",
"expected": "Rejection.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-011-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-012",
"sheet": "VAPT_Domains",
"module": "SSL Automation",
"role": "System Admin",
"scenario": "SSL action cannot be triggered by unauthorized role",
"steps": "Attempt SSL issue/renew action as non-System Admin.",
"expected": "Block.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-012-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-012",
"sheet": "VAPT_Domains",
"module": "SSL Automation",
"role": "System Admin",
"scenario": "SSL action cannot be triggered by unauthorized role",
"steps": "Attempt SSL issue/renew action as non-System Admin.",
"expected": "Block.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-012-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-012",
"sheet": "VAPT_Domains",
"module": "SSL Automation",
"role": "System Admin",
"scenario": "SSL action cannot be triggered by unauthorized role",
"steps": "Attempt SSL issue/renew action as non-System Admin.",
"expected": "Block.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-012-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-012",
"sheet": "VAPT_Domains",
"module": "SSL Automation",
"role": "System Admin",
"scenario": "SSL action cannot be triggered by unauthorized role",
"steps": "Attempt SSL issue/renew action as non-System Admin.",
"expected": "Block.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-012-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-012",
"sheet": "VAPT_Domains",
"module": "SSL Automation",
"role": "System Admin",
"scenario": "SSL action cannot be triggered by unauthorized role",
"steps": "Attempt SSL issue/renew action as non-System Admin.",
"expected": "Block.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-012-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-013",
"sheet": "VAPT_Domains",
"module": "Audit Log",
"role": "System Admin",
"scenario": "Domain create/update/delete is audit logged",
"steps": "Perform domain mapping change; verify actor, timestamp, tenant/domain and action are logged.",
"expected": "Audit log entry created correctly.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-013-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-013",
"sheet": "VAPT_Domains",
"module": "Audit Log",
"role": "System Admin",
"scenario": "Domain create/update/delete is audit logged",
"steps": "Perform domain mapping change; verify actor, timestamp, tenant/domain and action are logged.",
"expected": "Audit log entry created correctly.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-013-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-013",
"sheet": "VAPT_Domains",
"module": "Audit Log",
"role": "System Admin",
"scenario": "Domain create/update/delete is audit logged",
"steps": "Perform domain mapping change; verify actor, timestamp, tenant/domain and action are logged.",
"expected": "Audit log entry created correctly.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-013-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-013",
"sheet": "VAPT_Domains",
"module": "Audit Log",
"role": "System Admin",
"scenario": "Domain create/update/delete is audit logged",
"steps": "Perform domain mapping change; verify actor, timestamp, tenant/domain and action are logged.",
"expected": "Audit log entry created correctly.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-013-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-013",
"sheet": "VAPT_Domains",
"module": "Audit Log",
"role": "System Admin",
"scenario": "Domain create/update/delete is audit logged",
"steps": "Perform domain mapping change; verify actor, timestamp, tenant/domain and action are logged.",
"expected": "Audit log entry created correctly.",
"priority": "High",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-013-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-014",
"sheet": "VAPT_Domains",
"module": "Rate/Abuse",
"role": "System Admin",
"scenario": "Verification endpoint resists repeated brute attempts",
"steps": "Send repeated verification attempts.",
"expected": "Throttling or safe handling without server degradation.",
"priority": "Medium",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-014-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-014",
"sheet": "VAPT_Domains",
"module": "Rate/Abuse",
"role": "System Admin",
"scenario": "Verification endpoint resists repeated brute attempts",
"steps": "Send repeated verification attempts.",
"expected": "Throttling or safe handling without server degradation.",
"priority": "Medium",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-014-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-014",
"sheet": "VAPT_Domains",
"module": "Rate/Abuse",
"role": "System Admin",
"scenario": "Verification endpoint resists repeated brute attempts",
"steps": "Send repeated verification attempts.",
"expected": "Throttling or safe handling without server degradation.",
"priority": "Medium",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-014-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-014",
"sheet": "VAPT_Domains",
"module": "Rate/Abuse",
"role": "System Admin",
"scenario": "Verification endpoint resists repeated brute attempts",
"steps": "Send repeated verification attempts.",
"expected": "Throttling or safe handling without server degradation.",
"priority": "Medium",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-014-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-014",
"sheet": "VAPT_Domains",
"module": "Rate/Abuse",
"role": "System Admin",
"scenario": "Verification endpoint resists repeated brute attempts",
"steps": "Send repeated verification attempts.",
"expected": "Throttling or safe handling without server degradation.",
"priority": "Medium",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-014-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-015",
"sheet": "VAPT_Domains",
"module": "Regression",
"role": "All roles",
"scenario": "Existing auth/session flow still works after menu patch",
"steps": "Login, OTP, logout, password change and normal dashboard rendering continue to work.",
"expected": "All flows intact.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-015-SEC-01",
"variantName": "Security assertion",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-015",
"sheet": "VAPT_Domains",
"module": "Regression",
"role": "All roles",
"scenario": "Existing auth/session flow still works after menu patch",
"steps": "Login, OTP, logout, password change and normal dashboard rendering continue to work.",
"expected": "All flows intact.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-015-NEG-01",
"variantName": "Malformed/invalid request",
"variantType": "negative",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-015",
"sheet": "VAPT_Domains",
"module": "Regression",
"role": "All roles",
"scenario": "Existing auth/session flow still works after menu patch",
"steps": "Login, OTP, logout, password change and normal dashboard rendering continue to work.",
"expected": "All flows intact.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-015-RBAC-01",
"variantName": "Unauthorized role access check",
"variantType": "rbac",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-015",
"sheet": "VAPT_Domains",
"module": "Regression",
"role": "All roles",
"scenario": "Existing auth/session flow still works after menu patch",
"steps": "Login, OTP, logout, password change and normal dashboard rendering continue to work.",
"expected": "All flows intact.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-015-IDOR-01",
"variantName": "Direct object reference/tampering check",
"variantType": "idor",
"automation": "automated"
},
{
"sourceId": "DOM-VAPT-015",
"sheet": "VAPT_Domains",
"module": "Regression",
"role": "All roles",
"scenario": "Existing auth/session flow still works after menu patch",
"steps": "Login, OTP, logout, password change and normal dashboard rendering continue to work.",
"expected": "All flows intact.",
"priority": "Critical",
"type": "VAPT",
"route": "/domains",
"variantId": "DOM-VAPT-015-HDR-01",
"variantName": "Header/session safety check",
"variantType": "headers",
"automation": "automated"
},
{
"sourceId": "V204-SEC-001",
"sheet": "V204_Additional_Checks",
"module": "Security Hardening",
"role": "System Admin",
"scenario": "Forgot-password API does not expose reset token",
"steps": "POST forgot-password endpoint for a real seeded user and inspect response body.",
"expected": "Response must not contain reset_token/password_reset_token or long token values.",
"priority": "Critical",
"type": "VAPT",
"route": "/auth/forgot-password",
"variantId": "V204-SEC-001-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-SEC-002",
"sheet": "V204_Additional_Checks",
"module": "Security Hardening",
"role": "All roles",
"scenario": "Invalid reset token is rejected safely",
"steps": "Submit random reset token to reset-password API.",
"expected": "Request is rejected without 500 error and without changing password.",
"priority": "High",
"type": "VAPT",
"route": "/auth/reset-password",
"variantId": "V204-SEC-002-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-SEC-003",
"sheet": "V204_Additional_Checks",
"module": "Security Hardening",
"role": "All roles",
"scenario": "API login brute-force attempts do not crash",
"steps": "Submit repeated wrong API token/login requests.",
"expected": "All responses are safe 4xx/429 and no server error occurs.",
"priority": "Critical",
"type": "VAPT",
"route": "/auth/token",
"variantId": "V204-SEC-003-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-CTX-001",
"sheet": "V204_Additional_Checks",
"module": "Tenant/Branch Context",
"role": "Staff",
"scenario": "Public X-Tenant-Code/X-Branch-Code/X-Year-Code headers ignored",
"steps": "Login with spoofed tenant/branch/year headers but without secret.",
"expected": "ERP must not switch context or leak another tenant/branch/year.",
"priority": "Critical",
"type": "VAPT",
"route": "/system-settings",
"variantId": "V204-CTX-001-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-CTX-002",
"sheet": "V204_Additional_Checks",
"module": "Tenant/Branch Context",
"role": "Staff",
"scenario": "Wrong context secret is ignored",
"steps": "Login with spoofed context headers and wrong X-AuditFirm-Context-Secret.",
"expected": "ERP must ignore context headers and must not leak Tenant B.",
"priority": "Critical",
"type": "VAPT",
"route": "/billing",
"variantId": "V204-CTX-002-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-CTX-003",
"sheet": "V204_Additional_Checks",
"module": "Tenant/Branch Context",
"role": "System Admin",
"scenario": "Trusted context headers require configured secret",
"steps": "When TRUST_CONTEXT_HEADERS=true, send headers with configured secret.",
"expected": "Trusted internal context works only with matching secret.",
"priority": "Medium",
"type": "VAPT",
"route": "/system-settings",
"variantId": "V204-CTX-003-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-FY-001",
"sheet": "V204_Additional_Checks",
"module": "Financial Year",
"role": "System Admin",
"scenario": "FY selector/session context visible after login",
"steps": "Login and open system settings/dashboard.",
"expected": "Active FY selector or active FY text is visible.",
"priority": "Critical",
"type": "UAT",
"route": "/system-settings",
"variantId": "V204-FY-001-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "V204-FY-002",
"sheet": "V204_Additional_Checks",
"module": "Financial Year",
"role": "System Admin",
"scenario": "Active FY switch does not break transactional screens",
"steps": "Switch active FY and open engagements, documents, notices, billing and payments.",
"expected": "All screens load without 500 and use selected FY context.",
"priority": "Critical",
"type": "UAT",
"route": "/services/engagements",
"variantId": "V204-FY-002-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "positive",
"automation": "automated"
},
{
"sourceId": "V204-LOCK-001",
"sheet": "V204_Additional_Checks",
"module": "Year Lock",
"role": "System Admin",
"scenario": "Locked FY write attempt blocked",
"steps": "Set LOCKED_FY, switch to locked FY and try notice/case creation.",
"expected": "Create/edit/write operation is blocked safely.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases/new",
"variantId": "V204-LOCK-001-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-BACKUP-001",
"sheet": "V204_Additional_Checks",
"module": "Year Backup",
"role": "Anonymous",
"scenario": "Backup screens/files not anonymously accessible",
"steps": "Open backup URLs and likely backup file paths without login.",
"expected": "All requests redirect/block/404 and no backup file is exposed.",
"priority": "Critical",
"type": "VAPT",
"route": "/system-settings/financial-years/1/backup",
"variantId": "V204-BACKUP-001-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-BACKUP-002",
"sheet": "V204_Additional_Checks",
"module": "Year Backup",
"role": "Staff",
"scenario": "Low-privilege user cannot access backup export",
"steps": "Login as Staff and open backup/export URLs.",
"expected": "Staff is denied and no backup ZIP is downloadable.",
"priority": "Critical",
"type": "VAPT",
"route": "/system-settings/financial-years/1/backup",
"variantId": "V204-BACKUP-002-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-UPLOAD-001",
"sheet": "V204_Additional_Checks",
"module": "Upload Security",
"role": "System Admin",
"scenario": "Executable upload blocked in notice/case documents",
"steps": "Upload not-a-pdf.exe to seeded notice/case document flow.",
"expected": "Upload is rejected due to type/extension validation.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "V204-UPLOAD-001-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-UPLOAD-002",
"sheet": "V204_Additional_Checks",
"module": "Upload Security",
"role": "System Admin",
"scenario": "Oversized upload blocked safely",
"steps": "Upload large-file.bin to seeded notice/case document flow.",
"expected": "Upload is rejected due to size/type validation and no memory/server error occurs.",
"priority": "Critical",
"type": "VAPT",
"route": "/notice-cases",
"variantId": "V204-UPLOAD-002-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-STORAGE-001",
"sheet": "V204_Additional_Checks",
"module": "Storage Agent Security",
"role": "Anonymous",
"scenario": "Storage agent endpoints require node authentication",
"steps": "Call storage-agent pending jobs endpoints without node headers.",
"expected": "Endpoints reject unauthenticated caller without 500.",
"priority": "High",
"type": "VAPT",
"route": "/documents/storage-agent/jobs/pending",
"variantId": "V204-STORAGE-001-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-HEADERS-001",
"sheet": "V204_Additional_Checks",
"module": "Session/Cookie Security",
"role": "System Admin",
"scenario": "Security headers and cookie flags remain valid",
"steps": "Open login, login as System Admin and inspect headers/cookies.",
"expected": "Security headers exist and session cookie is HttpOnly/SameSite; Secure when production flag enabled.",
"priority": "Critical",
"type": "VAPT",
"route": "/login",
"variantId": "V204-HEADERS-001-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
},
{
"sourceId": "V204-CSP-001",
"sheet": "V204_Additional_Checks",
"module": "XSS/CSP",
"role": "Anonymous",
"scenario": "Strict CSP has no unsafe-inline when enforced",
"steps": "Enable EXPECT_STRICT_CSP after removing inline JS/CSS and inspect CSP.",
"expected": "CSP exists and does not contain unsafe-inline.",
"priority": "Medium",
"type": "VAPT",
"route": "/login",
"variantId": "V204-CSP-001-AUTO-01",
"variantName": "Targeted v2.0.4 automated check",
"variantType": "security",
"automation": "automated"
}
]