Staff permissions (§21, §44)  PASS An admin can manage provider credentials  PASS An admin can change settings  PASS An admin can work tickets  PASS A support user can work tickets  PASS A support user can see orders  PASS A support user CANNOT reach provider credentials  PASS A support user CANNOT change settings  PASS A support user CANNOT create staff accounts  PASS A content user can edit pages  PASS A content user CANNOT see orders  PASS A content user CANNOT open customer documents Support queue (§19)  PASS Staff see every message including internal notes  PASS The customer sees only the non-internal messages  PASS An internal note never reaches the customer-visible thread  PASS The queue surfaces higher-priority tickets first Expert requests (§4)  PASS An expert request is recorded  PASS Converting an expert request links it to a visible ticket  PASS The request status moves on Coupon management (§15)  PASS A coupon can be created  PASS Deactivating a coupon keeps its usage history intact  PASS The coupon is off, not deleted  PASS Total given away is reported accurately CMS (§22–24)  PASS A script tag is stripped from authored content  PASS An inline event handler is stripped  PASS A javascript: URL is neutralised  PASS Legitimate markup survives sanitising  PASS No script tag is ever stored in the database  PASS A noindex page is identifiable so the sitemap can exclude it  PASS A published, dated post is public  PASS A draft post is not public  PASS A future-dated post stays hidden until its date Email templates (§25)  PASS Email templates are seeded  PASS Every seeded template actually uses the variables it declares  PASS A hostile value substituted into a template is escaped Lawyer credentials (§20)  PASS An advocate can upload their enrolment certificate  PASS A credential document is encrypted at rest  PASS The owning advocate can read their own credential back  PASS Another advocate CANNOT read it  PASS A support user without lawyers.manage CANNOT read it  PASS An admin holding lawyers.manage can read it for verification  PASS Re-uploading replaces the previous copy rather than keeping both  PASS An unknown credential type is refused  PASS Credential uploads, reads and denials are all audited Analytics (§26)  PASS The daily rollup writes an aggregate row  PASS Funnel steps are counted correctly  PASS Each step is counted separately  PASS Re-running the rollup updates rather than duplicating the day  PASS Re-running the rollup does not double-count  PASS The page view table stores no raw IP address  PASS Visitors are identified by a salted hash instead ------------------------------------------------------------ 50 passed, 0 failed, 50 total