Reference
Observed flows, form/dialog/keyboard probes on Engineering plans.
On Engineering (and Security Pro when deeper checks run), the audit can probe how the site behaves — not only how pages look when fetched. It records evidence with confidence labels — observed or inferred — and never asks for login credentials.
| Probe | What it does | Never does |
|---|---|---|
| Observed flows | Same-origin nav hops from homepage links | Login / credentialed journeys |
| Auth walls | Infers login/signup barriers from URL + password fields | Submit credentials |
| Form validation | Empty required + invalid email/url/tel/number via HTML5 | XSS/SQLi payloads or off-origin submit |
| Dialog | Open reversible dialog; Escape dismiss | Destructive confirm actions |
| Keyboard | Tab-order smoke (distinct focus targets) | Full WCAG certification |
| CTA | Click same-origin <a href> CTAs only | Click submit buttons |
qa-audit scan flows https://example.com --tier engineering --json
qa-audit scan keyboard https://example.com --tier engineering
# qa-audit.yml
scans:
- flows
tier: engineeringThis is assessment / smoke coverage — not a pentest. Checks that deliberately break forms or simulate network faults are not part of Launch or Team, and are not enabled by default.