Demonstration mode. Cedar Table Catering is a fictional business. All records are synthetic, all decisions are simulated, and nothing here carries client authority. This portal is not linked from the main site navigation.

Test evidence

Every result says how it was produced: automated runner, manual drill, or labeled sample fixture. A screenshot alone is never treated as proof.

Current evidence for build demo-build-1.0

Journey 1

Passed

Request a catering quote

Run RUN-MUW76YVQ-3J9Q

Journey 2

Passed

Correct mistakes and recover safely

Run RUN-MUW76YVQ-3J9Q

Journey 3

Passed

Follow an inquiry through its status

Run RUN-MUW76YVQ-3J9Q

Run history

RUN-MUW76YVQ-3J9QPassed10/6/2026, 4:48:00 AM

Target build demo-build-1.0 · manifest v1.0.0 · source: automated_inapp_runner

In-app integration runner (server-side assertions). Browser-layer checks (Chromium/Firefox/WebKit, keyboard, screen reader) are not covered by this runner — recorded as outstanding for the pilot.

  • j1-submit-validPassed

    Valid synthetic inquiry is stored and the confirmation is captured in the demo outbox

    Expected: One inquiry stored; one confirmation payload captured in the demo outbox; a unique reference returned.

    Observed: Inquiry CT-KVYRJ1 stored: true; outbox captured: true.

    Assertions: inquiry_created · outbox_captured · reference_returned

  • j1-single-inquiryPassed

    Exactly one inquiry and one outbox message exist for the submission

    Expected: inquiry count = 1; outbox count = 1

    Observed: inquiry count = 1; outbox count = 1

    Assertions: persistence_exact_once

  • j1-invalid-emailPassed

    Invalid email is rejected by the server with a field error and no side effects

    Expected: Rejected with an email field error; zero inquiries; zero outbox messages.

    Observed: rejected: true; inquiries created: 0.

    Assertions: server_validation · no_side_effects

  • j1-past-datePassed

    Past event date is rejected per the business-timezone rule

    Expected: Rejected with an event_date field error (business timezone America/Los_Angeles).

    Observed: rejected: true; event_date error present: true.

    Assertions: server_validation

  • j2-idempotent-retryPassed

    A retry with the same operation id creates no duplicate inquiry or confirmation

    Expected: Second submission returns the original reference; exactly 1 inquiry; exactly 1 outbox message.

    Observed: duplicate detected: true; inquiries: 1; outbox: 1.

    Assertions: idempotency · no_duplicate_side_effects

  • j2-guest-countPassed

    Unsupported guest count is rejected by the server

    Expected: Rejected with a guest_count field error (supported range 10–150).

    Observed: rejected: true; guest_count error present: true.

    Assertions: server_validation

  • j3-transition-validPassed

    Staff transitions follow the allowed path and history is preserved

    Expected: received → under review → quote prepared; history has 3 entries with actor and timestamp.

    Observed: step1 ok: true; step2 ok: true; history length: 3.

    Assertions: transition_allowed · history_preserved

  • j3-invalid-transitionPassed

    Skipping a status (received → quote prepared) is rejected

    Expected: Rejected with a clear invalid-transition error.

    Observed: rejected: true; error: Invalid transition: received to quote_prepared..

    Assertions: transition_validation

  • j3-cross-tenant-deniedPassed

    A different tenant's scope cannot read this tenant's inquiry (simulated isolation)

    Expected: A scoped lookup for another tenant is denied.

    Observed: denied: true (demo simulation — the Stage B pilot enforces this with server-side row-level rules).

    Assertions: scope_check_simulated

  • policy-stale-evidencePassed

    A passing run bound to a superseded build is treated as stale, not current

    Expected: A run whose target build differs from the active build is excluded from current evidence.

    Observed: Fixture run target demo-build-0.9 vs active demo-build-1.0 → treated as stale.

    Assertions: current_status_policy

RUN-MUW76QCZ-NLDSInconclusiveSeeded faults: broken_cta, rejected_submission, missing_confirmation, cross_tenant_access, stale_evidence10/6/2026, 4:47:49 AM

Target build demo-build-1.0 · manifest v1.0.0 · source: automated_inapp_runner

In-app integration runner (server-side assertions). Browser-layer checks (Chromium/Firefox/WebKit, keyboard, screen reader) are not covered by this runner — recorded as outstanding for the pilot.

  • j1-submit-validPassed

    Valid synthetic inquiry is stored and the confirmation is captured in the demo outbox

    Expected: One inquiry stored; one confirmation payload captured in the demo outbox; a unique reference returned.

    Observed: Inquiry CT-QYRVSX stored: true; outbox captured: true.

    Assertions: inquiry_created · outbox_captured · reference_returned

  • j1-single-inquiryPassed

    Exactly one inquiry and one outbox message exist for the submission

    Expected: inquiry count = 1; outbox count = 1

    Observed: inquiry count = 1; outbox count = 1

    Assertions: persistence_exact_once

  • j1-invalid-emailPassed

    Invalid email is rejected by the server with a field error and no side effects

    Expected: Rejected with an email field error; zero inquiries; zero outbox messages.

    Observed: rejected: true; inquiries created: 0.

    Assertions: server_validation · no_side_effects

  • j1-past-datePassed

    Past event date is rejected per the business-timezone rule

    Expected: Rejected with an event_date field error (business timezone America/Los_Angeles).

    Observed: rejected: true; event_date error present: true.

    Assertions: server_validation

  • j2-idempotent-retryPassed

    A retry with the same operation id creates no duplicate inquiry or confirmation

    Expected: Second submission returns the original reference; exactly 1 inquiry; exactly 1 outbox message.

    Observed: duplicate detected: true; inquiries: 1; outbox: 1.

    Assertions: idempotency · no_duplicate_side_effects

  • j2-guest-countPassed

    Unsupported guest count is rejected by the server

    Expected: Rejected with a guest_count field error (supported range 10–150).

    Observed: rejected: true; guest_count error present: true.

    Assertions: server_validation

  • j3-transition-validPassed

    Staff transitions follow the allowed path and history is preserved

    Expected: received → under review → quote prepared; history has 3 entries with actor and timestamp.

    Observed: step1 ok: true; step2 ok: true; history length: 3.

    Assertions: transition_allowed · history_preserved

  • j3-invalid-transitionPassed

    Skipping a status (received → quote prepared) is rejected

    Expected: Rejected with a clear invalid-transition error.

    Observed: rejected: true; error: Invalid transition: received to quote_prepared..

    Assertions: transition_validation

  • j3-cross-tenant-deniedPassed

    A different tenant's scope cannot read this tenant's inquiry (simulated isolation)

    Expected: A scoped lookup for another tenant is denied.

    Observed: denied: true (demo simulation — the Stage B pilot enforces this with server-side row-level rules).

    Assertions: scope_check_simulated

  • policy-stale-evidencePassed

    A passing run bound to a superseded build is treated as stale, not current

    Expected: A run whose target build differs from the active build is excluded from current evidence.

    Observed: Fixture run target demo-build-0.9 vs active demo-build-1.0 → treated as stale.

    Assertions: current_status_policy

  • fault-broken-ctaFailed

    Broken request-quote call to action

    Expected: The demo preview exposes a working "Request a quote" action.

    Observed: Fixture flag active: the demo preview renders the request-quote action as unavailable. Detected via the fault fixture (flag-based, not a browser observation).

    Assertions: fixture_flag_detected

  • fault-rejected-submissionFailed

    Valid submissions are unexpectedly rejected

    Expected: A valid inquiry is accepted and stored.

    Observed: A valid submission was rejected before commit — failure observed and preserved in this run.

    Assertions: valid_input_rejected

  • fault-missing-confirmationFailed

    Inquiry is stored without its confirmation capture

    Expected: Storing the inquiry also captures the confirmation payload in the demo outbox.

    Observed: Inquiry CT-T1G9B2 stored but no outbox message exists — failure observed.

    Assertions: confirmation_missing_detected

  • fault-cross-tenant-accessFailed

    Without an isolation control, another tenant record is reachable

    Expected: The demo never returns another tenant inquiry to an unauthorized scope.

    Observed: An unscoped lookup returned the other-tenant sample record — demonstrating exactly what the Stage B pilot must enforce with row-level rules.

    Assertions: isolation_simulated

  • fault-stale-evidencePassed

    Expired evidence under the current-status policy is excluded from readiness

    Expected: Stale evidence is labeled stale and excluded from current readiness.

    Observed: The seeded sample run targets a superseded build; the evidence view and release policy treat it as stale (see policy-stale-evidence).

    Assertions: current_status_policy

RUN-MUW76GGM-BNXQPassed10/6/2026, 4:47:36 AM

Target build demo-build-1.0 · manifest v1.0.0 · source: automated_inapp_runner

In-app integration runner (server-side assertions). Browser-layer checks (Chromium/Firefox/WebKit, keyboard, screen reader) are not covered by this runner — recorded as outstanding for the pilot.

  • j1-submit-validPassed

    Valid synthetic inquiry is stored and the confirmation is captured in the demo outbox

    Expected: One inquiry stored; one confirmation payload captured in the demo outbox; a unique reference returned.

    Observed: Inquiry CT-2YFM7I stored: true; outbox captured: true.

    Assertions: inquiry_created · outbox_captured · reference_returned

  • j1-single-inquiryPassed

    Exactly one inquiry and one outbox message exist for the submission

    Expected: inquiry count = 1; outbox count = 1

    Observed: inquiry count = 1; outbox count = 1

    Assertions: persistence_exact_once

  • j1-invalid-emailPassed

    Invalid email is rejected by the server with a field error and no side effects

    Expected: Rejected with an email field error; zero inquiries; zero outbox messages.

    Observed: rejected: true; inquiries created: 0.

    Assertions: server_validation · no_side_effects

  • j1-past-datePassed

    Past event date is rejected per the business-timezone rule

    Expected: Rejected with an event_date field error (business timezone America/Los_Angeles).

    Observed: rejected: true; event_date error present: true.

    Assertions: server_validation

  • j2-idempotent-retryPassed

    A retry with the same operation id creates no duplicate inquiry or confirmation

    Expected: Second submission returns the original reference; exactly 1 inquiry; exactly 1 outbox message.

    Observed: duplicate detected: true; inquiries: 1; outbox: 1.

    Assertions: idempotency · no_duplicate_side_effects

  • j2-guest-countPassed

    Unsupported guest count is rejected by the server

    Expected: Rejected with a guest_count field error (supported range 10–150).

    Observed: rejected: true; guest_count error present: true.

    Assertions: server_validation

  • j3-transition-validPassed

    Staff transitions follow the allowed path and history is preserved

    Expected: received → under review → quote prepared; history has 3 entries with actor and timestamp.

    Observed: step1 ok: true; step2 ok: true; history length: 3.

    Assertions: transition_allowed · history_preserved

  • j3-invalid-transitionPassed

    Skipping a status (received → quote prepared) is rejected

    Expected: Rejected with a clear invalid-transition error.

    Observed: rejected: true; error: Invalid transition: received to quote_prepared..

    Assertions: transition_validation

  • j3-cross-tenant-deniedPassed

    A different tenant's scope cannot read this tenant's inquiry (simulated isolation)

    Expected: A scoped lookup for another tenant is denied.

    Observed: denied: true (demo simulation — the Stage B pilot enforces this with server-side row-level rules).

    Assertions: scope_check_simulated

  • policy-stale-evidencePassed

    A passing run bound to a superseded build is treated as stale, not current

    Expected: A run whose target build differs from the active build is excluded from current evidence.

    Observed: Fixture run target demo-build-0.9 vs active demo-build-1.0 → treated as stale.

    Assertions: current_status_policy

RUN-SAMPLE-001PassedSample fixture10/6/2026, 4:47:27 AM

Target build demo-build-0.9 · manifest v1.0.0 · source: sample_fixture

Sample fixture — clearly labeled; never counts as current evidence. Demonstrates the stale-evidence policy.

  • j1-submit-validPassed

    Sample fixture result (not a fresh run)

    Expected: Seeded sample used to demonstrate stale-evidence handling.

    Observed: This is a labeled fixture bound to superseded build demo-build-0.9 — it must never count as current evidence.

    Assertions: sample_fixture

Criterion-to-test coverage map

CriterionCheckMode
c1Accessible form opens at desktop and mobile sizesBrowser harness (Playwright) — outstanding for pilot
c2Valid data creates exactly one inquiry with a referenceAutomated
c3Confirmation payload captured with matching referenceAutomated
c4Confirmation copy states “not a confirmed booking”Manual copy check — outstanding
c5Invalid email / guest count / past date rejected, values preservedAutomated
c6Retry with the same operation id cannot duplicateAutomated
c7Unknown outcome offers honest recoveryManual demo drill (lost-response checkbox)
c8Customer retrieves own inquiry statusManual demo drill (status view)
c9Allowed transitions only; history preservedAutomated
c10Another tenant's scope is denied (simulated)Automated (demo simulation)
c11Superseded-build evidence is stale, never currentAutomated
c12Only synthetic data is collectedBy design

The in-app runner performs server-side assertions only. Chromium/Firefox/WebKit browser runs, keyboard-only and screen-reader smoke tests are outstanding for the pilot's browser harness.

AYCD Proof — Stage A demonstration. Client authentication, tenant isolation and durable approvals arrive at the approved pilot gate.