ConductorQA

Sample report

Starter audit: Acme Invoicing (fictional)

This report shows the format you receive. Acme Invoicing is a fictional app, and the findings are written for this example. A real report also links a recording or screenshot for every finding.

Routes tested
14
P0 blockers
3
P1 major
3
P2 minor
5
Checks passed
31
Tested
Sept 22–23, 2026
Environment
Staging, build 2026.09.21-3, Stripe in test mode
Test accounts
Owner, Admin, and Viewer roles, plus a client with no account
Devices
iPhone 17 (iOS 26), Pixel 10 (Android 16), macOS and Windows desktops
Browsers
Safari, Chrome, and Firefox (current stable versions)
Reviewed by
A senior QA engineer who reproduced every finding by hand

Summary

Acme Invoicing is not ready to release. Three P0 bugs block it: one stops checkout on iPhones, one marks declined payments as paid, and one lets a Viewer delete a client and its billing history through the API. A password reset link that keeps working is the most serious P1. Signup, the core invoice flow, and most layouts work well. After you fix the six P0 and P1 findings, a re-test takes about half a day.

Fix order

  1. 1

    AC-02, AC-01, AC-03

    Two lose money on every affected payment, and one lets a Viewer delete billing history. Fix all three before the next release.

  2. 2

    AC-04

    A leaked reset link still works. Fix it this week.

  3. 3

    AC-05, AC-06

    Both are visible to clients or block a common task on Android.

  4. 4

    AC-07 to AC-11

    Low risk. Fix them in your normal backlog.

Scope and method

Routes tested

  • /signup
  • /login
  • /verify
  • /reset-password
  • /dashboard
  • /clients
  • /clients/:id
  • /invoices
  • /invoices/new
  • /invoices/:id
  • /invoices/:id/pay
  • /checkout
  • /payments
  • /settings

Tabs, sheets, and forms count as part of the route they open on. Emails were checked in Gmail and Outlook.

Severity levels

P0
Blocks release. Loses money or data, or stops a core flow.
P1
Fix before release, or within days. A real user hits it or it exposes data.
P2
Fix in the normal backlog. A workaround exists.
P3
Polish. None in this report.

Method: The QA team tested every route by hand on each device, with AI-assisted tooling to crawl routes and capture console and network logs. A senior engineer reproduced each finding by hand on a real device before it went in this report. Not tested: Load testing, penetration testing, native iOS and Android apps, and code changes. Accessibility checks cover contrast, alt text, and keyboard focus. AC-10 was found while testing focus. This audit is not a full WCAG review and did not include screen readers.

Findings

AC-01 /checkout · iPhone 17, Safari 26
P0

Checkout goes blank when you clear the promo code and tap Apply

Steps

  1. Open /checkout with the Pro plan in the cart.
  2. Type LAUNCH20 in Promo code, then delete it.
  3. Tap Apply.

What happens

The page goes blank. Console: TypeError: null is not an object (evaluating 'promo.trim').

Expected

The promo field clears and the order total returns to the full price.

Why it matters

Anyone who changes their mind about a code can't pay. Reloading empties the cart.

Suggested fix

Treat an empty field as no code: (promo ?? "").trim(). Disable Apply while the field is empty.

Reproduced:
5 of 5 attempts on iPhone 17. Not reproduced on desktop Safari or Chrome.
Evidence:
Screen recording (0:18), console log
AC-02 /invoices/:id/pay · Desktop, Chrome
P0

A declined card still marks the invoice as paid

Steps

  1. As the client, open the payment link for any unpaid invoice.
  2. Pay with the Stripe test card 4000 0000 0000 0002 (generic decline).
  3. Open the invoice list as the account owner.

What happens

The client sees “Your card was declined.” The owner's list shows the invoice as Paid. The Stripe test dashboard shows only payment_intent.created and payment_intent.payment_failed for this payment, so the status most likely changes on payment_intent.created.

Expected

The invoice stays Unpaid, and the owner sees the failed attempt.

Why it matters

Owners stop chasing invoices that were never paid. Revenue totals on the dashboard are wrong.

Suggested fix

Set Paid only on payment_intent.succeeded. Add a Failed status for payment_intent.payment_failed.

Reproduced:
3 of 3 attempts, also with test card 4000 0000 0000 9995 (insufficient funds).
Evidence:
Screen recording (0:41), webhook payloads, network log
AC-03 /clients/:id · Desktop, Chrome
P0

Team members with the Viewer role can delete clients

Steps

  1. Invite a team member with the Viewer role, and sign in as that user.
  2. Open a client. The Delete button is hidden, as expected.
  3. Send DELETE /api/clients/:id with the Viewer's session, from the browser console.

What happens

The API returns 200 OK and deletes the client and every invoice attached to it.

Expected

The API returns 403 Forbidden and deletes nothing.

Why it matters

The lowest role can delete a client and its billing history with one request, and the interface has no way to restore it.

Suggested fix

Check the role in the API handler, not only in the interface.

Reproduced:
3 of 3 attempts, with two different Viewer accounts.
Evidence:
Network log, request and response
AC-04 /reset-password · All devices
P1

Password reset links still work after the password changes

Steps

  1. Request two reset emails for the same account.
  2. Use the first link to set a new password.
  3. Open the second link.

What happens

The second link opens the reset form and accepts a new password.

Expected

The second link shows that it has expired and offers to send a new one.

Why it matters

A reset link that leaks, for example in a forwarded email, still works after the user secures the account.

Suggested fix

Invalidate every outstanding reset token when the password changes.

Reproduced:
3 of 3 attempts.
Evidence:
Screen recording (0:35)
AC-05 /invoices/new · Desktop, Firefox
P1

The editor and the PDF calculate totals differently, so they differ by a cent

Steps

  1. Add three lines, each 1.5 hours at $45.25.
  2. Note the total in the editor.
  3. Export the invoice as a PDF and compare the totals.

What happens

The editor shows $203.64: it rounds each line to $67.88, then adds them. The PDF shows $203.63: it adds the unrounded lines ($203.625), then rounds.

Expected

The editor and the PDF show the same total, and the total equals the sum of the lines shown.

Why it matters

Clients see two different amounts for the same invoice and question the bill.

Suggested fix

Calculate totals in one shared function: round each line to cents, then add the rounded lines. Use it in the editor and in the PDF.

Reproduced:
Every time, on all browsers.
Evidence:
Screenshots of the editor and the PDF
AC-06 /invoices/:id, Send sheet · Pixel 10, Chrome
P1

The Send invoice button is under the keyboard on Android

Steps

  1. Open an invoice and tap Send.
  2. Tap the Message field.

What happens

The keyboard covers the Send button. The page can't scroll far enough to reach the button.

Expected

The sheet shrinks above the keyboard, and the Send button stays reachable.

Why it matters

Owners on Android can't send an invoice with a message.

Suggested fix

Add interactive-widget=resizes-content to the viewport meta tag, so the layout shrinks when the keyboard opens. Let the sheet content scroll.

Reproduced:
5 of 5 attempts on Pixel 10. iPhone 17 is not affected.
Evidence:
Screen recording (0:12)

P2 minor findings

A delivered report gives each of these the same steps, evidence, and fix as above. This sample lists them in short form.

  • P2 AC-07 Double-tapping Save creates two identical clients /clients, New client form
  • P2 AC-08 Dates show in US format for accounts set to the UK /invoices
  • P2 AC-09 Search returns no results for client names with an apostrophe /clients
  • P2 AC-10 Icon buttons in the sidebar have no accessible name All pages
  • P2 AC-11 The Terms link in the signup footer returns a 404 error /signup

What passed

31 checks found no problems. Each one lists what we tried, so you know what this release covers. A delivered report links the evidence for each check. “All” devices means iPhone 17, Pixel 10, and desktop Safari, Chrome, and Firefox.

Sign-in and accounts

  • TC-01

    Signup with email and with Google

    /signup · All

    New email, existing email, Google account with and without a name

    Pass
  • TC-02

    Email verification link

    /verify · All

    Valid link, reused link, link older than 24 hours

    Pass
  • TC-03

    Wrong password shows a clear error

    /login · All

    Wrong password, unknown email, five attempts in a row

    Pass
  • TC-04

    Session expires after 30 days

    All signed-in routes · Desktop Chrome

    Session cookie set to expire, then a page reload

    Pass
  • TC-05

    Logout clears the session on every tab

    Account menu · Desktop Chrome, Firefox

    Three open tabs, logout in one, actions in the others

    Pass
  • TC-06

    Magic link login

    /login · iPhone 17, desktop Chrome

    Link opened on the same device and on a second device

    Pass

Invoices

  • TC-07

    Create, edit, and duplicate an invoice

    /invoices/new · All

    One line, 40 lines, edit after sending, duplicate a paid invoice

    Pass
  • TC-08

    Tax calculation for one and two tax rates

    /invoices/new · Desktop Chrome

    0%, 20%, and 5% + 9.975% compound rates

    Pass
  • TC-09

    PDF export on desktop and phone

    /invoices/:id · All

    Short and multi-page invoices, logo and no logo

    Pass
  • TC-10

    Recurring invoice schedule

    /invoices, Recurring tab · Desktop Chrome

    Weekly, monthly on the 31st, and yearly schedules

    Pass
  • TC-11

    Overdue reminder email

    Email · Gmail, Outlook

    Invoice one day overdue, then paid before the second reminder

    Pass
  • TC-12

    Currency switch between USD, EUR, and GBP

    /settings, Billing tab · Desktop Chrome

    Switch with open invoices, check symbols and decimal separators

    Pass

Payments in test mode

  • TC-13

    Successful card payment

    /invoices/:id/pay · All

    Stripe test card 4242 4242 4242 4242

    Pass
  • TC-14

    3D Secure challenge

    /invoices/:id/pay · iPhone 17, desktop Chrome

    Test card 4000 0027 6000 3184, approve and cancel the challenge

    Pass
  • TC-15

    Refund from the dashboard

    /payments · Desktop Chrome

    Full and partial refunds, invoice status after each

    Pass
  • TC-16

    Receipt email to the client

    Email · Gmail, Outlook

    Paid, refunded, and partially refunded invoices

    Pass
  • TC-17

    Plan upgrade and downgrade

    /settings, Plan tab · Desktop Chrome

    Upgrade mid-cycle, downgrade with more clients than the plan allows

    Pass

Layouts

  • TC-18

    No horizontal scroll at 320 px

    All 14 routes · Chrome device mode, iPhone 17

    Every route at 320, 375, and 430 px wide

    Pass
  • TC-19

    Navigation menu on phones

    All routes · iPhone 17, Pixel 10

    Open, close, rotate the phone, use the back button

    Pass
  • TC-20

    Tables scroll on phones

    /invoices, /clients · iPhone 17, Pixel 10

    100 invoices, long client names

    Pass
  • TC-21

    Dark mode

    All routes · macOS Safari, iPhone 17

    System dark mode on and off with the app open

    Pass

Errors and links

  • TC-22

    No console errors

    13 routes, all except /checkout · All

    Console open through every flow on each route. The error on /checkout is AC-01.

    Pass
  • TC-23

    No failed requests on page load

    All 14 routes · Desktop Chrome

    Network log on a cold load of each route

    Pass
  • TC-24

    Custom 404 page

    Unknown URLs · All

    Unknown path, deleted invoice ID, malformed ID

    Pass
  • TC-25

    Main navigation and sidebar links

    All routes · Desktop Chrome

    Every link followed. The broken footer link on /signup is AC-11.

    Pass

Forms and accessibility

  • TC-26

    Required field errors on every form

    9 forms · All

    Submit empty, then fix one field at a time

    Pass
  • TC-27

    Very long client names

    /clients, New client form · All

    255 characters, no spaces, on lists and PDFs

    Pass
  • TC-28

    Emoji and non-Latin characters

    /clients, New client form · All

    Emoji, Arabic, Chinese, and Hindi names on lists and PDFs

    Pass
  • TC-29

    Keyboard focus order

    /signup, /checkout · Desktop Chrome, Safari

    Tab and Shift+Tab through every field and button

    Pass
  • TC-30

    Text contrast on all buttons

    All routes · Desktop Chrome

    Contrast checked in light and dark mode

    Pass
  • TC-31

    Alt text on uploaded logos

    /settings, Brand tab · Desktop Chrome

    Logo shown with the business name as alt text

    Pass