Review context
Release, environment, scope, reviewer and date: to be completed. For each check record Pass / Fail / Not applicable, a reason and a link to evidence. This is a planning aid, not a certification.
Behaviour and resilience
Check agreed acceptance criteria, input validation, permission boundaries, retries, duplicate requests, failure messages, backups and rollback. Confirm that incomplete work cannot be mistaken for success.
Security and data
Review dependency findings, approved data flows, secrets handling, least privilege, logging and retention. Track unresolved findings with an owner and explicit release decision.
Usability and accessibility
Check keyboard operation, focus visibility, readable labels, error recovery, zoom and narrow screens. Include manual checks with assistive technology relevant to the service.
Performance and operations
Measure representative user journeys, document test conditions, verify monitoring and alerts, and agree support ownership. Set budgets appropriate to the project before assessing them.
Release recommendation
Summarise evidence, unresolved risks and acceptance conditions. Name the person accountable for the go/no-go decision and record the decision date.
