Reference

Behavioral QA (safe-active)

Observed flows, form/dialog/keyboard probes on Engineering plans.

On Engineering (and Security Pro when deeper checks run), the audit can probe how the site behaves — not only how pages look when fetched. It records evidence with confidence labels — observed or inferred — and never asks for login credentials.

ProbeWhat it doesNever does
Observed flowsSame-origin nav hops from homepage linksLogin / credentialed journeys
Auth wallsInfers login/signup barriers from URL + password fieldsSubmit credentials
Form validationEmpty required + invalid email/url/tel/number via HTML5XSS/SQLi payloads or off-origin submit
DialogOpen reversible dialog; Escape dismissDestructive confirm actions
KeyboardTab-order smoke (distinct focus targets)Full WCAG certification
CTAClick same-origin <a href> CTAs onlyClick submit buttons
CLI
qa-audit scan flows https://example.com --tier engineering --json
qa-audit scan keyboard https://example.com --tier engineering
# qa-audit.yml
scans:
  - flows
tier: engineering

This is assessment / smoke coverage — not a pentest. Checks that deliberately break forms or simulate network faults are not part of Launch or Team, and are not enabled by default.