🛡️ Phase 4 Playbook — Quality & Hardening agent
> Duration: 3-7 days | Agents: 8 | Gate Keeper: Reality Checker (sole authority)
by msitarzewski·MIT license·★ 154,023 Stars on the repo·GitHub ↗
Files of 🛡️ Phase 4 Playbook — Quality & Hardening
msitarzewski/
Show the full text333 lines
🛡️ Phase 4 Playbook — Quality & Hardening
Duration: 3-7 days | Agents: 8 | Gate Keeper: Reality Checker (sole authority)
Objective
The final quality gauntlet. The Reality Checker defaults to "NEEDS WORK" — you must prove production readiness with overwhelming evidence. This phase exists because first implementations typically need 2-3 revision cycles, and that's healthy.
Pre-Conditions
- Phase 3 Quality Gate passed (all tasks QA'd)
- Phase 3 Handoff Package received
- All features implemented and individually verified
Critical Mindset
The Reality Checker's default verdict is NEEDS WORK.
This is not pessimism — it's realism. Production readiness requires:
- Complete user journeys working end-to-end
- Cross-device consistency (desktop, tablet, mobile)
- Performance under load (not just happy path)
- Security validation (not just "we added auth")
- Specification compliance (every requirement, not most)
A B/B+ rating on first pass is normal and expected.
Agent Activation Sequence
Step 1: Evidence Collection (Day 1-2, All Parallel)
📸 Evidence Collector — Comprehensive Visual Evidence
Activate Evidence Collector for comprehensive system evidence on [PROJECT].
Deliverables required:
1. Full screenshot suite:
- Desktop (1920x1080) — every page/view
- Tablet (768x1024) — every page/view
- Mobile (375x667) — every page/view
2. Interaction evidence:
- Navigation flows (before/after clicks)
- Form interactions (empty, filled, submitted, error states)
- Modal/dialog interactions
- Accordion/expandable content
3. Theme evidence:
- Light mode — all pages
- Dark mode — all pages
- System preference detection
4. Error state evidence:
- 404 pages
- Form validation errors
- Network error handling
- Empty states
Format: Screenshot Evidence Package with test-results.json
Timeline: 2 days
🔌 API Tester — Full API Regression
Activate API Tester for complete API regression on [PROJECT].
Deliverables required:
1. Endpoint regression suite:
- All endpoints tested (GET, POST, PUT, DELETE)
- Authentication/authorization verification
- Input validation testing
- Error response verification
2. Integration testing:
- Cross-service communication
- Database operation verification
- External API integration
3. Edge case testing:
- Rate limiting behavior
- Large payload handling
- Concurrent request handling
- Malformed input handling
Format: API Test Report with pass/fail per endpoint
Timeline: 2 days
⚡ Performance Benchmarker — Load Testing
Activate Performance Benchmarker for load testing on [PROJECT].
Deliverables required:
1. Load test at 10x expected traffic:
- Response time distribution (P50, P95, P99)
- Throughput under load
- Error rate under load
- Resource utilization (CPU, memory, network)
2. Core Web Vitals measurement:
- LCP (Largest Contentful Paint) < 2.5s
- FID (First Input Delay) < 100ms
- CLS (Cumulative Layout Shift) < 0.1
3. Database performance:
- Query execution times
- Connection pool utilization
- Index effectiveness
4. Stress test results:
- Breaking point identification
- Graceful degradation behavior
- Recovery time after overload
Format: Performance Certification Report
Timeline: 2 days
⚖️ Legal Compliance Checker — Final Compliance Audit
Activate Legal Compliance Checker for final compliance audit on [PROJECT].
Deliverables required:
1. Privacy compliance verification:
- Privacy policy accuracy
- Consent management functionality
- Data subject rights implementation
- Cookie consent implementation
2. Security compliance:
- Data encryption (at rest and in transit)
- Authentication security
- Input sanitization
- OWASP Top 10 check
3. Regulatory compliance:
- GDPR requirements (if applicable)
- CCPA requirements (if applicable)
- Industry-specific requirements
4. Accessibility compliance:
- WCAG 2.1 AA verification
- Screen reader compatibility
- Keyboard navigation
Format: Compliance Certification Report
Timeline: 2 days
Step 2: Analysis (Day 3-4, Parallel, after Step 1)
📊 Test Results Analyzer — Quality Metrics Aggregation
Activate Test Results Analyzer for quality metrics aggregation on [PROJECT].
Input: ALL Step 1 reports
Deliverables required:
1. Aggregate quality dashboard:
- Overall quality score
- Category breakdown (visual, functional, performance, security, compliance)
- Issue severity distribution
- Trend analysis (if multiple test cycles)
2. Issue prioritization:
- Critical issues (must fix before production)
- High issues (should fix before production)
- Medium issues (fix in next sprint)
- Low issues (backlog)
3. Risk assessment:
- Production readiness probability
- Remaining risk areas
- Recommended mitigations
Format: Quality Metrics Dashboard
Timeline: 1 day
🔄 Workflow Optimizer — Process Efficiency Review
Activate Workflow Optimizer for process efficiency review on [PROJECT].
Input: Phase 3 execution data + Step 1 findings
Deliverables required:
1. Process efficiency analysis:
- Dev↔QA loop efficiency (first-pass rate, average retries)
- Bottleneck identification
- Time-to-resolution for different issue types
2. Improvement recommendations:
- Process changes for Phase 6 operations
- Automation opportunities
- Quality improvement suggestions
Format: Optimization Recommendations Report
Timeline: 1 day
🏗️ Infrastructure Maintainer — Production Readiness Check
Activate Infrastructure Maintainer for production readiness on [PROJECT].
Deliverables required:
1. Production environment validation:
- All services healthy and responding
- Auto-scaling configured and tested
- Load balancer configuration verified
- SSL/TLS certificates valid
2. Monitoring validation:
- All critical metrics being collected
- Alert rules configured and tested
- Dashboard access verified
- Log aggregation working
3. Disaster recovery validation:
- Backup systems operational
- Recovery procedures documented and tested
- Failover mechanisms verified
4. Security validation:
- Firewall rules reviewed
- Access controls verified
- Secrets management confirmed
- Vulnerability scan clean
Format: Infrastructure Readiness Report
Timeline: 1 day
Step 3: Final Judgment (Day 5-7, Sequential)
🔍 Reality Checker — THE FINAL VERDICT
Activate Reality Checker for final integration testing on [PROJECT].
MANDATORY PROCESS — DO NOT SKIP:
Step 1: Reality Check Commands
- Verify what was actually built (ls, grep for claimed features)
- Cross-check claimed features against specification
- Run comprehensive screenshot capture
- Review all evidence from Step 1 and Step 2
Step 2: QA Cross-Validation
- Review Evidence Collector findings
- Cross-reference with API Tester results
- Verify Performance Benchmarker data
- Confirm Legal Compliance Checker findings
Step 3: End-to-End System Validation
- Test COMPLETE user journeys (not individual features)
- Verify responsive behavior across ALL devices
- Check interaction flows end-to-end
- Review actual performance data
Step 4: Specification Reality Check
- Quote EXACT text from original specification
- Compare with ACTUAL implementation evidence
- Document EVERY gap between spec and reality
- No assumptions — evidence only
VERDICT OPTIONS:
- READY: Overwhelming evidence of production readiness (rare first pass)
- NEEDS WORK: Specific issues identified with fix list (expected)
- NOT READY: Major architectural issues requiring Phase 1/2 revisit
Format: Reality-Based Integration Report
Default: NEEDS WORK unless proven otherwise
Quality Gate — THE FINAL GATE
| # | Criterion | Threshold | Evidence Required |
|---|---|---|---|
| 1 | User journeys complete | All critical paths working end-to-end | Reality Checker screenshots |
| 2 | Cross-device consistency | Desktop + Tablet + Mobile all working | Responsive screenshots |
| 3 | Performance certified | P95 < 200ms, LCP < 2.5s, uptime > 99.9% | Performance Benchmarker report |
| 4 | Security validated | Zero critical vulnerabilities | Security scan + compliance report |
| 5 | Compliance certified | All regulatory requirements met | Legal Compliance Checker report |
| 6 | Specification compliance | 100% of spec requirements implemented | Point-by-point verification |
| 7 | Infrastructure ready | Production environment validated | Infrastructure Maintainer report |
Gate Decision
Sole authority: Reality Checker
If READY (proceed to Phase 5):
## Phase 4 → Phase 5 Handoff Package
### For Launch Team:
- Reality Checker certification report
- Performance certification
- Compliance certification
- Infrastructure readiness report
- Known limitations (if any)
### For Growth Hacker:
- Product ready for users
- Feature list for marketing messaging
- Performance data for credibility
### For DevOps Automator:
- Production deployment approved
- Blue-green deployment plan
- Rollback procedures confirmed
If NEEDS WORK (return to Phase 3):
## Phase 4 → Phase 3 Return Package
### Fix List (from Reality Checker):
1. [Critical Issue 1]: [Description + evidence + fix instruction]
2. [Critical Issue 2]: [Description + evidence + fix instruction]
3. [High Issue 1]: [Description + evidence + fix instruction]
...
### Process:
- Issues enter Dev↔QA loop (Phase 3 mechanics)
- Each fix must pass Evidence Collector QA
- When all fixes complete → Return to Phase 4 Step 3
- Reality Checker re-evaluates with updated evidence
### Expected: 2-3 revision cycles is normal
If NOT READY (return to Phase 1/2):
## Phase 4 → Phase 1/2 Return Package
### Architectural Issues Identified:
1. [Fundamental Issue]: [Why it can't be fixed in Phase 3]
2. [Structural Problem]: [What needs to change at architecture level]
### Recommended Action:
- [ ] Revise system architecture (Phase 1)
- [ ] Rebuild foundation (Phase 2)
- [ ] Descope and redefine (Phase 1)
### Studio Producer Decision Required
Phase 4 is complete when the Reality Checker issues a READY verdict with overwhelming evidence. NEEDS WORK is the expected first-pass result — it means the system is working but needs polish.
| 1 | # 🛡️ Phase 4 Playbook — Quality & Hardening |
| 2 | |
| 3 | > **Duration**: 3-7 days | **Agents**: 8 | **Gate Keeper**: Reality Checker (sole authority) |
| 4 | |
| 5 | |
| 6 | |
| 7 | ## Objective |
| 8 | |
| 9 | The final quality gauntlet. The Reality Checker defaults to "NEEDS WORK" — you must prove production readiness with overwhelming evidence. This phase exists because first implementations typically need 2-3 revision cycles, and that's healthy. |
| 10 | |
| 11 | ## Pre-Conditions |
| 12 | |
| 13 | [ ] Phase 3 Quality Gate passed (all tasks QA'd) |
| 14 | [ ] Phase 3 Handoff Package received |
| 15 | [ ] All features implemented and individually verified |
| 16 | |
| 17 | ## Critical Mindset |
| 18 | |
| 19 | > **The Reality Checker's default verdict is NEEDS WORK.** |
| 20 | > |
| 21 | > This is not pessimism — it's realism. Production readiness requires: |
| 22 | > - Complete user journeys working end-to-end |
| 23 | > - Cross-device consistency (desktop, tablet, mobile) |
| 24 | > - Performance under load (not just happy path) |
| 25 | > - Security validation (not just "we added auth") |
| 26 | > - Specification compliance (every requirement, not most) |
| 27 | > |
| 28 | > A B/B+ rating on first pass is normal and expected. |
| 29 | |
| 30 | ## Agent Activation Sequence |
| 31 | |
| 32 | ### Step 1: Evidence Collection (Day 1-2, All Parallel) |
| 33 | |
| 34 | #### 📸 Evidence Collector — Comprehensive Visual Evidence |
| 35 | |
| 36 | Activate Evidence Collector for comprehensive system evidence on [PROJECT]. |
| 37 | |
| 38 | Deliverables required: |
| 39 | 1. Full screenshot suite: |
| 40 | - Desktop (1920x1080) — every page/view |
| 41 | - Tablet (768x1024) — every page/view |
| 42 | - Mobile (375x667) — every page/view |
| 43 | 2. Interaction evidence: |
| 44 | - Navigation flows (before/after clicks) |
| 45 | - Form interactions (empty, filled, submitted, error states) |
| 46 | - Modal/dialog interactions |
| 47 | - Accordion/expandable content |
| 48 | 3. Theme evidence: |
| 49 | - Light mode — all pages |
| 50 | - Dark mode — all pages |
| 51 | - System preference detection |
| 52 | 4. Error state evidence: |
| 53 | - 404 pages |
| 54 | - Form validation errors |
| 55 | - Network error handling |
| 56 | - Empty states |
| 57 | |
| 58 | Format: Screenshot Evidence Package with test-results.json |
| 59 | Timeline: 2 days |
| 60 | |
| 61 | |
| 62 | #### 🔌 API Tester — Full API Regression |
| 63 | |
| 64 | Activate API Tester for complete API regression on [PROJECT]. |
| 65 | |
| 66 | Deliverables required: |
| 67 | 1. Endpoint regression suite: |
| 68 | - All endpoints tested (GET, POST, PUT, DELETE) |
| 69 | - Authentication/authorization verification |
| 70 | - Input validation testing |
| 71 | - Error response verification |
| 72 | 2. Integration testing: |
| 73 | - Cross-service communication |
| 74 | - Database operation verification |
| 75 | - External API integration |
| 76 | 3. Edge case testing: |
| 77 | - Rate limiting behavior |
| 78 | - Large payload handling |
| 79 | - Concurrent request handling |
| 80 | - Malformed input handling |
| 81 | |
| 82 | Format: API Test Report with pass/fail per endpoint |
| 83 | Timeline: 2 days |
| 84 | |
| 85 | |
| 86 | #### ⚡ Performance Benchmarker — Load Testing |
| 87 | |
| 88 | Activate Performance Benchmarker for load testing on [PROJECT]. |
| 89 | |
| 90 | Deliverables required: |
| 91 | 1. Load test at 10x expected traffic: |
| 92 | - Response time distribution (P50, P95, P99) |
| 93 | - Throughput under load |
| 94 | - Error rate under load |
| 95 | - Resource utilization (CPU, memory, network) |
| 96 | 2. Core Web Vitals measurement: |
| 97 | - LCP (Largest Contentful Paint) < 2.5s |
| 98 | - FID (First Input Delay) < 100ms |
| 99 | - CLS (Cumulative Layout Shift) < 0.1 |
| 100 | 3. Database performance: |
| 101 | - Query execution times |
| 102 | - Connection pool utilization |
| 103 | - Index effectiveness |
| 104 | 4. Stress test results: |
| 105 | - Breaking point identification |
| 106 | - Graceful degradation behavior |
| 107 | - Recovery time after overload |
| 108 | |
| 109 | Format: Performance Certification Report |
| 110 | Timeline: 2 days |
| 111 | |
| 112 | |
| 113 | #### ⚖️ Legal Compliance Checker — Final Compliance Audit |
| 114 | |
| 115 | Activate Legal Compliance Checker for final compliance audit on [PROJECT]. |
| 116 | |
| 117 | Deliverables required: |
| 118 | 1. Privacy compliance verification: |
| 119 | - Privacy policy accuracy |
| 120 | - Consent management functionality |
| 121 | - Data subject rights implementation |
| 122 | - Cookie consent implementation |
| 123 | 2. Security compliance: |
| 124 | - Data encryption (at rest and in transit) |
| 125 | - Authentication security |
| 126 | - Input sanitization |
| 127 | - OWASP Top 10 check |
| 128 | 3. Regulatory compliance: |
| 129 | - GDPR requirements (if applicable) |
| 130 | - CCPA requirements (if applicable) |
| 131 | - Industry-specific requirements |
| 132 | 4. Accessibility compliance: |
| 133 | - WCAG 2.1 AA verification |
| 134 | - Screen reader compatibility |
| 135 | - Keyboard navigation |
| 136 | |
| 137 | Format: Compliance Certification Report |
| 138 | Timeline: 2 days |
| 139 | |
| 140 | |
| 141 | ### Step 2: Analysis (Day 3-4, Parallel, after Step 1) |
| 142 | |
| 143 | #### 📊 Test Results Analyzer — Quality Metrics Aggregation |
| 144 | |
| 145 | Activate Test Results Analyzer for quality metrics aggregation on [PROJECT]. |
| 146 | |
| 147 | Input: ALL Step 1 reports |
| 148 | Deliverables required: |
| 149 | 1. Aggregate quality dashboard: |
| 150 | - Overall quality score |
| 151 | - Category breakdown (visual, functional, performance, security, compliance) |
| 152 | - Issue severity distribution |
| 153 | - Trend analysis (if multiple test cycles) |
| 154 | 2. Issue prioritization: |
| 155 | - Critical issues (must fix before production) |
| 156 | - High issues (should fix before production) |
| 157 | - Medium issues (fix in next sprint) |
| 158 | - Low issues (backlog) |
| 159 | 3. Risk assessment: |
| 160 | - Production readiness probability |
| 161 | - Remaining risk areas |
| 162 | - Recommended mitigations |
| 163 | |
| 164 | Format: Quality Metrics Dashboard |
| 165 | Timeline: 1 day |
| 166 | |
| 167 | |
| 168 | #### 🔄 Workflow Optimizer — Process Efficiency Review |
| 169 | |
| 170 | Activate Workflow Optimizer for process efficiency review on [PROJECT]. |
| 171 | |
| 172 | Input: Phase 3 execution data + Step 1 findings |
| 173 | Deliverables required: |
| 174 | 1. Process efficiency analysis: |
| 175 | - Dev↔QA loop efficiency (first-pass rate, average retries) |
| 176 | - Bottleneck identification |
| 177 | - Time-to-resolution for different issue types |
| 178 | 2. Improvement recommendations: |
| 179 | - Process changes for Phase 6 operations |
| 180 | - Automation opportunities |
| 181 | - Quality improvement suggestions |
| 182 | |
| 183 | Format: Optimization Recommendations Report |
| 184 | Timeline: 1 day |
| 185 | |
| 186 | |
| 187 | #### 🏗️ Infrastructure Maintainer — Production Readiness Check |
| 188 | |
| 189 | Activate Infrastructure Maintainer for production readiness on [PROJECT]. |
| 190 | |
| 191 | Deliverables required: |
| 192 | 1. Production environment validation: |
| 193 | - All services healthy and responding |
| 194 | - Auto-scaling configured and tested |
| 195 | - Load balancer configuration verified |
| 196 | - SSL/TLS certificates valid |
| 197 | 2. Monitoring validation: |
| 198 | - All critical metrics being collected |
| 199 | - Alert rules configured and tested |
| 200 | - Dashboard access verified |
| 201 | - Log aggregation working |
| 202 | 3. Disaster recovery validation: |
| 203 | - Backup systems operational |
| 204 | - Recovery procedures documented and tested |
| 205 | - Failover mechanisms verified |
| 206 | 4. Security validation: |
| 207 | - Firewall rules reviewed |
| 208 | - Access controls verified |
| 209 | - Secrets management confirmed |
| 210 | - Vulnerability scan clean |
| 211 | |
| 212 | Format: Infrastructure Readiness Report |
| 213 | Timeline: 1 day |
| 214 | |
| 215 | |
| 216 | ### Step 3: Final Judgment (Day 5-7, Sequential) |
| 217 | |
| 218 | #### 🔍 Reality Checker — THE FINAL VERDICT |
| 219 | |
| 220 | Activate Reality Checker for final integration testing on [PROJECT]. |
| 221 | |
| 222 | MANDATORY PROCESS — DO NOT SKIP: |
| 223 | |
| 224 | Step 1: Reality Check Commands |
| 225 | - Verify what was actually built (ls, grep for claimed features) |
| 226 | - Cross-check claimed features against specification |
| 227 | - Run comprehensive screenshot capture |
| 228 | - Review all evidence from Step 1 and Step 2 |
| 229 | |
| 230 | Step 2: QA Cross-Validation |
| 231 | - Review Evidence Collector findings |
| 232 | - Cross-reference with API Tester results |
| 233 | - Verify Performance Benchmarker data |
| 234 | - Confirm Legal Compliance Checker findings |
| 235 | |
| 236 | Step 3: End-to-End System Validation |
| 237 | - Test COMPLETE user journeys (not individual features) |
| 238 | - Verify responsive behavior across ALL devices |
| 239 | - Check interaction flows end-to-end |
| 240 | - Review actual performance data |
| 241 | |
| 242 | Step 4: Specification Reality Check |
| 243 | - Quote EXACT text from original specification |
| 244 | - Compare with ACTUAL implementation evidence |
| 245 | - Document EVERY gap between spec and reality |
| 246 | - No assumptions — evidence only |
| 247 | |
| 248 | VERDICT OPTIONS: |
| 249 | - READY: Overwhelming evidence of production readiness (rare first pass) |
| 250 | - NEEDS WORK: Specific issues identified with fix list (expected) |
| 251 | - NOT READY: Major architectural issues requiring Phase 1/2 revisit |
| 252 | |
| 253 | Format: Reality-Based Integration Report |
| 254 | Default: NEEDS WORK unless proven otherwise |
| 255 | |
| 256 | |
| 257 | ## Quality Gate — THE FINAL GATE |
| 258 | |
| 259 | | # | Criterion | Threshold | Evidence Required | |
| 260 | |---|-----------|-----------|-------------------| |
| 261 | | 1 | User journeys complete | All critical paths working end-to-end | Reality Checker screenshots | |
| 262 | | 2 | Cross-device consistency | Desktop + Tablet + Mobile all working | Responsive screenshots | |
| 263 | | 3 | Performance certified | P95 < 200ms, LCP < 2.5s, uptime > 99.9% | Performance Benchmarker report | |
| 264 | | 4 | Security validated | Zero critical vulnerabilities | Security scan + compliance report | |
| 265 | | 5 | Compliance certified | All regulatory requirements met | Legal Compliance Checker report | |
| 266 | | 6 | Specification compliance | 100% of spec requirements implemented | Point-by-point verification | |
| 267 | | 7 | Infrastructure ready | Production environment validated | Infrastructure Maintainer report | |
| 268 | |
| 269 | ## Gate Decision |
| 270 | |
| 271 | **Sole authority**: Reality Checker |
| 272 | |
| 273 | ### If READY (proceed to Phase 5): |
| 274 | |
| 275 | ## Phase 4 → Phase 5 Handoff Package |
| 276 | |
| 277 | ### For Launch Team: |
| 278 | - Reality Checker certification report |
| 279 | - Performance certification |
| 280 | - Compliance certification |
| 281 | - Infrastructure readiness report |
| 282 | - Known limitations (if any) |
| 283 | |
| 284 | ### For Growth Hacker: |
| 285 | - Product ready for users |
| 286 | - Feature list for marketing messaging |
| 287 | - Performance data for credibility |
| 288 | |
| 289 | ### For DevOps Automator: |
| 290 | - Production deployment approved |
| 291 | - Blue-green deployment plan |
| 292 | - Rollback procedures confirmed |
| 293 | |
| 294 | |
| 295 | ### If NEEDS WORK (return to Phase 3): |
| 296 | |
| 297 | ## Phase 4 → Phase 3 Return Package |
| 298 | |
| 299 | ### Fix List (from Reality Checker): |
| 300 | 1. [Critical Issue 1]: [Description + evidence + fix instruction] |
| 301 | 2. [Critical Issue 2]: [Description + evidence + fix instruction] |
| 302 | 3. [High Issue 1]: [Description + evidence + fix instruction] |
| 303 | ... |
| 304 | |
| 305 | ### Process: |
| 306 | - Issues enter Dev↔QA loop (Phase 3 mechanics) |
| 307 | - Each fix must pass Evidence Collector QA |
| 308 | - When all fixes complete → Return to Phase 4 Step 3 |
| 309 | - Reality Checker re-evaluates with updated evidence |
| 310 | |
| 311 | ### Expected: 2-3 revision cycles is normal |
| 312 | |
| 313 | |
| 314 | ### If NOT READY (return to Phase 1/2): |
| 315 | |
| 316 | ## Phase 4 → Phase 1/2 Return Package |
| 317 | |
| 318 | ### Architectural Issues Identified: |
| 319 | 1. [Fundamental Issue]: [Why it can't be fixed in Phase 3] |
| 320 | 2. [Structural Problem]: [What needs to change at architecture level] |
| 321 | |
| 322 | ### Recommended Action: |
| 323 | - [ ] Revise system architecture (Phase 1) |
| 324 | - [ ] Rebuild foundation (Phase 2) |
| 325 | - [ ] Descope and redefine (Phase 1) |
| 326 | |
| 327 | ### Studio Producer Decision Required |
| 328 | |
| 329 | |
| 330 | |
| 331 | |
| 332 | *Phase 4 is complete when the Reality Checker issues a READY verdict with overwhelming evidence. NEEDS WORK is the expected first-pass result — it means the system is working but needs polish.* |
| 333 |