🛡️ Phase 4 Playbook — Quality & Hardening agent

> Duration: 3-7 days | Agents: 8 | Gate Keeper: Reality Checker (sole authority)

by msitarzewski·MIT license·★ 154,023 Stars on the repo·GitHub ↗

Files of 🛡️ Phase 4 Playbook — Quality & Hardening

msitarzewski/main1 file
phase-4-hardening.md
Show the full text333 lines

🛡️ Phase 4 Playbook — Quality & Hardening

Duration: 3-7 days | Agents: 8 | Gate Keeper: Reality Checker (sole authority)


Objective

The final quality gauntlet. The Reality Checker defaults to "NEEDS WORK" — you must prove production readiness with overwhelming evidence. This phase exists because first implementations typically need 2-3 revision cycles, and that's healthy.

Pre-Conditions

  • Phase 3 Quality Gate passed (all tasks QA'd)
  • Phase 3 Handoff Package received
  • All features implemented and individually verified

Critical Mindset

The Reality Checker's default verdict is NEEDS WORK.

This is not pessimism — it's realism. Production readiness requires:

  • Complete user journeys working end-to-end
  • Cross-device consistency (desktop, tablet, mobile)
  • Performance under load (not just happy path)
  • Security validation (not just "we added auth")
  • Specification compliance (every requirement, not most)

A B/B+ rating on first pass is normal and expected.

Agent Activation Sequence

Step 1: Evidence Collection (Day 1-2, All Parallel)
📸 Evidence Collector — Comprehensive Visual Evidence
Activate Evidence Collector for comprehensive system evidence on [PROJECT].

Deliverables required:
1. Full screenshot suite:
   - Desktop (1920x1080) — every page/view
   - Tablet (768x1024) — every page/view
   - Mobile (375x667) — every page/view
2. Interaction evidence:
   - Navigation flows (before/after clicks)
   - Form interactions (empty, filled, submitted, error states)
   - Modal/dialog interactions
   - Accordion/expandable content
3. Theme evidence:
   - Light mode — all pages
   - Dark mode — all pages
   - System preference detection
4. Error state evidence:
   - 404 pages
   - Form validation errors
   - Network error handling
   - Empty states

Format: Screenshot Evidence Package with test-results.json
Timeline: 2 days
🔌 API Tester — Full API Regression
Activate API Tester for complete API regression on [PROJECT].

Deliverables required:
1. Endpoint regression suite:
   - All endpoints tested (GET, POST, PUT, DELETE)
   - Authentication/authorization verification
   - Input validation testing
   - Error response verification
2. Integration testing:
   - Cross-service communication
   - Database operation verification
   - External API integration
3. Edge case testing:
   - Rate limiting behavior
   - Large payload handling
   - Concurrent request handling
   - Malformed input handling

Format: API Test Report with pass/fail per endpoint
Timeline: 2 days
⚡ Performance Benchmarker — Load Testing
Activate Performance Benchmarker for load testing on [PROJECT].

Deliverables required:
1. Load test at 10x expected traffic:
   - Response time distribution (P50, P95, P99)
   - Throughput under load
   - Error rate under load
   - Resource utilization (CPU, memory, network)
2. Core Web Vitals measurement:
   - LCP (Largest Contentful Paint) < 2.5s
   - FID (First Input Delay) < 100ms
   - CLS (Cumulative Layout Shift) < 0.1
3. Database performance:
   - Query execution times
   - Connection pool utilization
   - Index effectiveness
4. Stress test results:
   - Breaking point identification
   - Graceful degradation behavior
   - Recovery time after overload

Format: Performance Certification Report
Timeline: 2 days
Activate Legal Compliance Checker for final compliance audit on [PROJECT].

Deliverables required:
1. Privacy compliance verification:
   - Privacy policy accuracy
   - Consent management functionality
   - Data subject rights implementation
   - Cookie consent implementation
2. Security compliance:
   - Data encryption (at rest and in transit)
   - Authentication security
   - Input sanitization
   - OWASP Top 10 check
3. Regulatory compliance:
   - GDPR requirements (if applicable)
   - CCPA requirements (if applicable)
   - Industry-specific requirements
4. Accessibility compliance:
   - WCAG 2.1 AA verification
   - Screen reader compatibility
   - Keyboard navigation

Format: Compliance Certification Report
Timeline: 2 days
Step 2: Analysis (Day 3-4, Parallel, after Step 1)
📊 Test Results Analyzer — Quality Metrics Aggregation
Activate Test Results Analyzer for quality metrics aggregation on [PROJECT].

Input: ALL Step 1 reports
Deliverables required:
1. Aggregate quality dashboard:
   - Overall quality score
   - Category breakdown (visual, functional, performance, security, compliance)
   - Issue severity distribution
   - Trend analysis (if multiple test cycles)
2. Issue prioritization:
   - Critical issues (must fix before production)
   - High issues (should fix before production)
   - Medium issues (fix in next sprint)
   - Low issues (backlog)
3. Risk assessment:
   - Production readiness probability
   - Remaining risk areas
   - Recommended mitigations

Format: Quality Metrics Dashboard
Timeline: 1 day
🔄 Workflow Optimizer — Process Efficiency Review
Activate Workflow Optimizer for process efficiency review on [PROJECT].

Input: Phase 3 execution data + Step 1 findings
Deliverables required:
1. Process efficiency analysis:
   - Dev↔QA loop efficiency (first-pass rate, average retries)
   - Bottleneck identification
   - Time-to-resolution for different issue types
2. Improvement recommendations:
   - Process changes for Phase 6 operations
   - Automation opportunities
   - Quality improvement suggestions

Format: Optimization Recommendations Report
Timeline: 1 day
🏗️ Infrastructure Maintainer — Production Readiness Check
Activate Infrastructure Maintainer for production readiness on [PROJECT].

Deliverables required:
1. Production environment validation:
   - All services healthy and responding
   - Auto-scaling configured and tested
   - Load balancer configuration verified
   - SSL/TLS certificates valid
2. Monitoring validation:
   - All critical metrics being collected
   - Alert rules configured and tested
   - Dashboard access verified
   - Log aggregation working
3. Disaster recovery validation:
   - Backup systems operational
   - Recovery procedures documented and tested
   - Failover mechanisms verified
4. Security validation:
   - Firewall rules reviewed
   - Access controls verified
   - Secrets management confirmed
   - Vulnerability scan clean

Format: Infrastructure Readiness Report
Timeline: 1 day
Step 3: Final Judgment (Day 5-7, Sequential)
🔍 Reality Checker — THE FINAL VERDICT
Activate Reality Checker for final integration testing on [PROJECT].

MANDATORY PROCESS — DO NOT SKIP:

Step 1: Reality Check Commands
- Verify what was actually built (ls, grep for claimed features)
- Cross-check claimed features against specification
- Run comprehensive screenshot capture
- Review all evidence from Step 1 and Step 2

Step 2: QA Cross-Validation
- Review Evidence Collector findings
- Cross-reference with API Tester results
- Verify Performance Benchmarker data
- Confirm Legal Compliance Checker findings

Step 3: End-to-End System Validation
- Test COMPLETE user journeys (not individual features)
- Verify responsive behavior across ALL devices
- Check interaction flows end-to-end
- Review actual performance data

Step 4: Specification Reality Check
- Quote EXACT text from original specification
- Compare with ACTUAL implementation evidence
- Document EVERY gap between spec and reality
- No assumptions — evidence only

VERDICT OPTIONS:
- READY: Overwhelming evidence of production readiness (rare first pass)
- NEEDS WORK: Specific issues identified with fix list (expected)
- NOT READY: Major architectural issues requiring Phase 1/2 revisit

Format: Reality-Based Integration Report
Default: NEEDS WORK unless proven otherwise

Quality Gate — THE FINAL GATE

# Criterion Threshold Evidence Required
1 User journeys complete All critical paths working end-to-end Reality Checker screenshots
2 Cross-device consistency Desktop + Tablet + Mobile all working Responsive screenshots
3 Performance certified P95 < 200ms, LCP < 2.5s, uptime > 99.9% Performance Benchmarker report
4 Security validated Zero critical vulnerabilities Security scan + compliance report
5 Compliance certified All regulatory requirements met Legal Compliance Checker report
6 Specification compliance 100% of spec requirements implemented Point-by-point verification
7 Infrastructure ready Production environment validated Infrastructure Maintainer report

Gate Decision

Sole authority: Reality Checker

If READY (proceed to Phase 5):
## Phase 4 → Phase 5 Handoff Package

### For Launch Team:
- Reality Checker certification report
- Performance certification
- Compliance certification
- Infrastructure readiness report
- Known limitations (if any)

### For Growth Hacker:
- Product ready for users
- Feature list for marketing messaging
- Performance data for credibility

### For DevOps Automator:
- Production deployment approved
- Blue-green deployment plan
- Rollback procedures confirmed
If NEEDS WORK (return to Phase 3):
## Phase 4 → Phase 3 Return Package

### Fix List (from Reality Checker):
1. [Critical Issue 1]: [Description + evidence + fix instruction]
2. [Critical Issue 2]: [Description + evidence + fix instruction]
3. [High Issue 1]: [Description + evidence + fix instruction]
...

### Process:
- Issues enter Dev↔QA loop (Phase 3 mechanics)
- Each fix must pass Evidence Collector QA
- When all fixes complete → Return to Phase 4 Step 3
- Reality Checker re-evaluates with updated evidence

### Expected: 2-3 revision cycles is normal
If NOT READY (return to Phase 1/2):
## Phase 4 → Phase 1/2 Return Package

### Architectural Issues Identified:
1. [Fundamental Issue]: [Why it can't be fixed in Phase 3]
2. [Structural Problem]: [What needs to change at architecture level]

### Recommended Action:
- [ ] Revise system architecture (Phase 1)
- [ ] Rebuild foundation (Phase 2)
- [ ] Descope and redefine (Phase 1)

### Studio Producer Decision Required

Phase 4 is complete when the Reality Checker issues a READY verdict with overwhelming evidence. NEEDS WORK is the expected first-pass result — it means the system is working but needs polish.

1# 🛡️ Phase 4 Playbook — Quality & Hardening
2 
3> **Duration**: 3-7 days | **Agents**: 8 | **Gate Keeper**: Reality Checker (sole authority)
4 
5---
6 
7## Objective
8 
9The final quality gauntlet. The Reality Checker defaults to "NEEDS WORK" — you must prove production readiness with overwhelming evidence. This phase exists because first implementations typically need 2-3 revision cycles, and that's healthy.
10 
11## Pre-Conditions
12 
13- [ ] Phase 3 Quality Gate passed (all tasks QA'd)
14- [ ] Phase 3 Handoff Package received
15- [ ] All features implemented and individually verified
16 
17## Critical Mindset
18 
19> **The Reality Checker's default verdict is NEEDS WORK.**
20>
21> This is not pessimism — it's realism. Production readiness requires:
22> - Complete user journeys working end-to-end
23> - Cross-device consistency (desktop, tablet, mobile)
24> - Performance under load (not just happy path)
25> - Security validation (not just "we added auth")
26> - Specification compliance (every requirement, not most)
27>
28> A B/B+ rating on first pass is normal and expected.
29 
30## Agent Activation Sequence
31 
32### Step 1: Evidence Collection (Day 1-2, All Parallel)
33 
34#### 📸 Evidence Collector — Comprehensive Visual Evidence
35```
36Activate Evidence Collector for comprehensive system evidence on [PROJECT].
37 
38Deliverables required:
391. Full screenshot suite:
40 - Desktop (1920x1080) — every page/view
41 - Tablet (768x1024) — every page/view
42 - Mobile (375x667) — every page/view
432. Interaction evidence:
44 - Navigation flows (before/after clicks)
45 - Form interactions (empty, filled, submitted, error states)
46 - Modal/dialog interactions
47 - Accordion/expandable content
483. Theme evidence:
49 - Light mode — all pages
50 - Dark mode — all pages
51 - System preference detection
524. Error state evidence:
53 - 404 pages
54 - Form validation errors
55 - Network error handling
56 - Empty states
57 
58Format: Screenshot Evidence Package with test-results.json
59Timeline: 2 days
60```
61 
62#### 🔌 API Tester — Full API Regression
63```
64Activate API Tester for complete API regression on [PROJECT].
65 
66Deliverables required:
671. Endpoint regression suite:
68 - All endpoints tested (GET, POST, PUT, DELETE)
69 - Authentication/authorization verification
70 - Input validation testing
71 - Error response verification
722. Integration testing:
73 - Cross-service communication
74 - Database operation verification
75 - External API integration
763. Edge case testing:
77 - Rate limiting behavior
78 - Large payload handling
79 - Concurrent request handling
80 - Malformed input handling
81 
82Format: API Test Report with pass/fail per endpoint
83Timeline: 2 days
84```
85 
86#### ⚡ Performance Benchmarker — Load Testing
87```
88Activate Performance Benchmarker for load testing on [PROJECT].
89 
90Deliverables required:
911. Load test at 10x expected traffic:
92 - Response time distribution (P50, P95, P99)
93 - Throughput under load
94 - Error rate under load
95 - Resource utilization (CPU, memory, network)
962. Core Web Vitals measurement:
97 - LCP (Largest Contentful Paint) < 2.5s
98 - FID (First Input Delay) < 100ms
99 - CLS (Cumulative Layout Shift) < 0.1
1003. Database performance:
101 - Query execution times
102 - Connection pool utilization
103 - Index effectiveness
1044. Stress test results:
105 - Breaking point identification
106 - Graceful degradation behavior
107 - Recovery time after overload
108 
109Format: Performance Certification Report
110Timeline: 2 days
111```
112 
113#### ⚖️ Legal Compliance Checker — Final Compliance Audit
114```
115Activate Legal Compliance Checker for final compliance audit on [PROJECT].
116 
117Deliverables required:
1181. Privacy compliance verification:
119 - Privacy policy accuracy
120 - Consent management functionality
121 - Data subject rights implementation
122 - Cookie consent implementation
1232. Security compliance:
124 - Data encryption (at rest and in transit)
125 - Authentication security
126 - Input sanitization
127 - OWASP Top 10 check
1283. Regulatory compliance:
129 - GDPR requirements (if applicable)
130 - CCPA requirements (if applicable)
131 - Industry-specific requirements
1324. Accessibility compliance:
133 - WCAG 2.1 AA verification
134 - Screen reader compatibility
135 - Keyboard navigation
136 
137Format: Compliance Certification Report
138Timeline: 2 days
139```
140 
141### Step 2: Analysis (Day 3-4, Parallel, after Step 1)
142 
143#### 📊 Test Results Analyzer — Quality Metrics Aggregation
144```
145Activate Test Results Analyzer for quality metrics aggregation on [PROJECT].
146 
147Input: ALL Step 1 reports
148Deliverables required:
1491. Aggregate quality dashboard:
150 - Overall quality score
151 - Category breakdown (visual, functional, performance, security, compliance)
152 - Issue severity distribution
153 - Trend analysis (if multiple test cycles)
1542. Issue prioritization:
155 - Critical issues (must fix before production)
156 - High issues (should fix before production)
157 - Medium issues (fix in next sprint)
158 - Low issues (backlog)
1593. Risk assessment:
160 - Production readiness probability
161 - Remaining risk areas
162 - Recommended mitigations
163 
164Format: Quality Metrics Dashboard
165Timeline: 1 day
166```
167 
168#### 🔄 Workflow Optimizer — Process Efficiency Review
169```
170Activate Workflow Optimizer for process efficiency review on [PROJECT].
171 
172Input: Phase 3 execution data + Step 1 findings
173Deliverables required:
1741. Process efficiency analysis:
175 - Dev↔QA loop efficiency (first-pass rate, average retries)
176 - Bottleneck identification
177 - Time-to-resolution for different issue types
1782. Improvement recommendations:
179 - Process changes for Phase 6 operations
180 - Automation opportunities
181 - Quality improvement suggestions
182 
183Format: Optimization Recommendations Report
184Timeline: 1 day
185```
186 
187#### 🏗️ Infrastructure Maintainer — Production Readiness Check
188```
189Activate Infrastructure Maintainer for production readiness on [PROJECT].
190 
191Deliverables required:
1921. Production environment validation:
193 - All services healthy and responding
194 - Auto-scaling configured and tested
195 - Load balancer configuration verified
196 - SSL/TLS certificates valid
1972. Monitoring validation:
198 - All critical metrics being collected
199 - Alert rules configured and tested
200 - Dashboard access verified
201 - Log aggregation working
2023. Disaster recovery validation:
203 - Backup systems operational
204 - Recovery procedures documented and tested
205 - Failover mechanisms verified
2064. Security validation:
207 - Firewall rules reviewed
208 - Access controls verified
209 - Secrets management confirmed
210 - Vulnerability scan clean
211 
212Format: Infrastructure Readiness Report
213Timeline: 1 day
214```
215 
216### Step 3: Final Judgment (Day 5-7, Sequential)
217 
218#### 🔍 Reality Checker — THE FINAL VERDICT
219```
220Activate Reality Checker for final integration testing on [PROJECT].
221 
222MANDATORY PROCESS — DO NOT SKIP:
223 
224Step 1: Reality Check Commands
225- Verify what was actually built (ls, grep for claimed features)
226- Cross-check claimed features against specification
227- Run comprehensive screenshot capture
228- Review all evidence from Step 1 and Step 2
229 
230Step 2: QA Cross-Validation
231- Review Evidence Collector findings
232- Cross-reference with API Tester results
233- Verify Performance Benchmarker data
234- Confirm Legal Compliance Checker findings
235 
236Step 3: End-to-End System Validation
237- Test COMPLETE user journeys (not individual features)
238- Verify responsive behavior across ALL devices
239- Check interaction flows end-to-end
240- Review actual performance data
241 
242Step 4: Specification Reality Check
243- Quote EXACT text from original specification
244- Compare with ACTUAL implementation evidence
245- Document EVERY gap between spec and reality
246- No assumptions — evidence only
247 
248VERDICT OPTIONS:
249- READY: Overwhelming evidence of production readiness (rare first pass)
250- NEEDS WORK: Specific issues identified with fix list (expected)
251- NOT READY: Major architectural issues requiring Phase 1/2 revisit
252 
253Format: Reality-Based Integration Report
254Default: NEEDS WORK unless proven otherwise
255```
256 
257## Quality Gate — THE FINAL GATE
258 
259| # | Criterion | Threshold | Evidence Required |
260|---|-----------|-----------|-------------------|
261| 1 | User journeys complete | All critical paths working end-to-end | Reality Checker screenshots |
262| 2 | Cross-device consistency | Desktop + Tablet + Mobile all working | Responsive screenshots |
263| 3 | Performance certified | P95 < 200ms, LCP < 2.5s, uptime > 99.9% | Performance Benchmarker report |
264| 4 | Security validated | Zero critical vulnerabilities | Security scan + compliance report |
265| 5 | Compliance certified | All regulatory requirements met | Legal Compliance Checker report |
266| 6 | Specification compliance | 100% of spec requirements implemented | Point-by-point verification |
267| 7 | Infrastructure ready | Production environment validated | Infrastructure Maintainer report |
268 
269## Gate Decision
270 
271**Sole authority**: Reality Checker
272 
273### If READY (proceed to Phase 5):
274```markdown
275## Phase 4 → Phase 5 Handoff Package
276 
277### For Launch Team:
278- Reality Checker certification report
279- Performance certification
280- Compliance certification
281- Infrastructure readiness report
282- Known limitations (if any)
283 
284### For Growth Hacker:
285- Product ready for users
286- Feature list for marketing messaging
287- Performance data for credibility
288 
289### For DevOps Automator:
290- Production deployment approved
291- Blue-green deployment plan
292- Rollback procedures confirmed
293```
294 
295### If NEEDS WORK (return to Phase 3):
296```markdown
297## Phase 4 → Phase 3 Return Package
298 
299### Fix List (from Reality Checker):
3001. [Critical Issue 1]: [Description + evidence + fix instruction]
3012. [Critical Issue 2]: [Description + evidence + fix instruction]
3023. [High Issue 1]: [Description + evidence + fix instruction]
303...
304 
305### Process:
306- Issues enter Dev↔QA loop (Phase 3 mechanics)
307- Each fix must pass Evidence Collector QA
308- When all fixes complete → Return to Phase 4 Step 3
309- Reality Checker re-evaluates with updated evidence
310 
311### Expected: 2-3 revision cycles is normal
312```
313 
314### If NOT READY (return to Phase 1/2):
315```markdown
316## Phase 4 → Phase 1/2 Return Package
317 
318### Architectural Issues Identified:
3191. [Fundamental Issue]: [Why it can't be fixed in Phase 3]
3202. [Structural Problem]: [What needs to change at architecture level]
321 
322### Recommended Action:
323- [ ] Revise system architecture (Phase 1)
324- [ ] Rebuild foundation (Phase 2)
325- [ ] Descope and redefine (Phase 1)
326 
327### Studio Producer Decision Required
328```
329 
330---
331 
332*Phase 4 is complete when the Reality Checker issues a READY verdict with overwhelming evidence. NEEDS WORK is the expected first-pass result — it means the system is working but needs polish.*
333 

Discussion

Alternatives