# Public Demo Risk-Based Assurance Protocol and Execution Summary

> **LIMITED DEMONSTRATION ASSURANCE / UNAPPROVED / NOT A PRODUCTION VALIDATION REPORT**

- Record ID: `QMS-PD-ATP-001`
- Revision: `2026-08-11.4`
- Execution date: `2026-08-11`
- Intended-use reference: `QMS-PD-IUS-001`
- Baseline classification: Final app source commit deployed as Sites version 21; not approved for regulated production use
- Overall conclusion: Limited public synthetic-demo behavior verified; human, customer, regulated-release, and specialist gates remain open

## 1. Purpose and evidence status

This record defines and summarizes proportionate checks for the final recorded public synthetic demo release. It distinguishes evidence generated from the final app source and bounded live release from evidence that requires qualified human review, regulated release control, production-like customer environments, or customer approval.

The protocol was not approved before execution, no independent regulated-validation reviewer witnessed execution, and raw browser traces/screenshots were not placed under a controlled validation-record retention process. Results are therefore diagnostic supplier evidence only. They must not be represented as a formal regulated protocol execution, production-release authorization, or customer validation conclusion.

## 2. Baseline and environment

- Final app source commit: `02d2f87ecccfd7c7b0770b0b95df5ff69377242b`
- Final deployed release: Sites version `21`
- Canonical release URL: `https://qms-studio-medical-demo.gentle-lotus-1481.chatgpt.site/`
- Custom-domain live target: `https://qms.bio-consultant.com/`
- Source state at commit capture: Clean working tree at the final app commit; evidence revision `.4` changes validation-kit files only, which are outside the scoped app-source fingerprint
- Scoped source fingerprint: SHA-256 `4d8ca26c48468c689edf3c225a48085e275a6905af5ecc55ba73361e1278a24d` across 68 validation/demo/runtime source, font, and configuration files, as defined in `validation-status.json`; the selection was expanded to include `app/coverage` and `public/fonts`
- Package version: `0.1.0`
- Lock-file SHA-256: `254a1f5f0055b81523bf1627799b8d4c23bdfa977c993b71724bbaf329119165`
- Execution host: Windows PowerShell; Node.js `v24.14.1`; npm `11.11.0`
- Render surface: Codex in-app Chromium browser; exact browser build not captured
- Current local prerequisite attempt: `npm test` could not start because the workspace lacked the installed `eslint` binary; `npm ci --prefer-offline --no-audit --no-fund` then timed out after 124 seconds. No current-release lint/build result is claimed.
- Historical local evidence: The predecessor release passed lint/build and local production asset smoke; those results were not reexecuted for the typography-only release and are leveraged only for unchanged behavior.
- Final Sites-v21 live check: The custom target passed 30/30 checks at `2026-08-12T01:25:22.377Z`; no current-release canonical-target result was supplied
- Final custom-domain browser QA: desktop 1280 x 720 px and mobile 390 x 844 px; Inter and Source Serif loaded; no horizontal overflow; the mobile assistant launcher measured 56 x 56 px; and the header parent cue was hidden on mobile
- Evidence revision `.4` publication state: Local post-deployment record only; this evidence update did not commit, publish, deploy, or live-recheck the revised archive

The scoped fingerprint was recomputed from the clean working tree at the exact final commit. The current live and browser results target the deployed typography release, while earlier functional checks are cumulative predecessor evidence for unchanged behavior. See `validation-status.json` for key-file hashes, selection details, and release identity. The source identity, primary-target live pass, and targeted browser pass support technical deployment gate `GATE-001`; they do not supply regulated release authorization.

## 3. Risk-based scope

| Risk ID | Foreseeable failure | Potential effect | Assurance response | Residual position |
| --- | --- | --- | --- | --- |
| `R-PD-001` | Demo or package is mistaken for validated production software | Unsupported regulated reliance | Verify visible use boundaries; publish intended-use and machine status | Human claim review and customer approval remain required |
| `R-PD-002` | Real regulated or confidential data is entered | Privacy, confidentiality, or record-control harm | State synthetic-only boundary; exclude live assistant and lead endpoints | Technical prevention and privacy/security assessment not established |
| `R-PD-003` | Build or principal views are broken | Misleading evaluation or inaccessible package | Build, lint, route, DOM, console, and interaction smoke checks | No dedicated regression suite or CI evidence |
| `R-PD-004` | Simulated approval/signature is treated as a real control | False evidence of identity, intent, retention, or Part 11/eIDAS controls | Negative/positive UI guard check and reload-reset check; explicit simulation statement | Backend identity, atomicity, audit, time, and retention untested |
| `R-PD-005` | Package inventory or checksums are stale | Users receive incomplete or unverifiable artifacts | Parse artifacts, recompute SHA-256 values, inspect archive inventory, and check HTTP availability | No document-control approval or signed distribution record |
| `R-PD-006` | Production server cannot deliver generated assets | Blank or unstyled public release | Historical local production-start plus current live smoke tests | Sites v21 passed the primary live target; current local and canonical-target reruns were not recorded |
| `R-PD-007` | Live assistant behavior is conflated with synthetic workflow assurance | External data transfer or unsupported AI claims | Exclude assistant, storage, chat, lead, provider, and model behavior | Separate AI/privacy/security verification required |
| `R-PD-008` | UI fails for mobile, assistive technology, or supported browsers | Evaluation or future regulated workflow is unusable | Limited 1280/390 px rendered smoke | Cross-browser, automated accessibility, and qualified manual accessibility testing not executed |
| `R-PD-009` | A small demo trace is represented as full PRD coverage | False release-readiness claim | Publish a bounded traceability matrix with explicit gaps | Full PRD implementation and verification remain unestablished |

## 4. Executed checks and results

| Test ID | Method and acceptance criterion | Result | Objective observation | Limitation |
| --- | --- | --- | --- | --- |
| `PDV-001` | Capture the exact release source/configuration/font baseline at a clean commit | **PASS** | The expanded 68-file fingerprint equaled `4d8ca2...a24d`; final app commit is `02d2f87...742b` | No regulated release tag or quality authorization |
| `PDV-002` | Run repository `npm test`; command must execute lint and build successfully | **BLOCKED / NO CURRENT RESULT** | The command could not find `eslint`; a lockfile dependency-restoration attempt timed out after 124 seconds | Predecessor pass is historical only; current controlled CI/lint/build evidence remains absent |
| `PDV-003` | Run production build; exit code must be 0 and routes must include `/demo` and `/validation` | **NOT REEXECUTED** | Predecessor build passed; current deployed release instead received the bounded live check | Build pass for the exact typography commit was not generated locally in this execution |
| `PDV-004` | Start the built app locally; `/validation` and every referenced JS/CSS asset must return 200 | **NOT REEXECUTED** | Predecessor local production validation passed; Sites-v21 custom live smoke passed 30/30 | Local production equivalence for the exact typography commit was not rechecked |
| `PDV-005` | Render `/validation`; title, meaningful DOM, three statuses, customer boundary, package links, no overlay, and no relevant console warning/error must be present | **PASS** | Development check passed; candidate browser QA confirmed package links and clean rendered state | Does not approve the wording as a regulated claim or customer conclusion |
| `PDV-006` | Render every source-defined demo view; each must show meaningful content, an expected H1, no overlay, and no console warning/error | **PASS** | 10/10 views rendered: home, complaints, complaint, CAPA, regulatory, change, training, approval, audit, evidence | Smoke coverage only; no exhaustive state, boundary, or error testing |
| `PDV-007` | Navigate to complaint register and search a known synthetic ID; visible result count must update | **PASS** | Search for `CMP-2026-0142` displayed `Showing 1 of 5 synthetic complaints.` | Does not test persistence, pagination, export, authorization, or data accuracy |
| `PDV-008` | Exercise simulated signature guard; commit must be disabled before name/intent, enabled after both, show committed state, and reset on reload | **PASS** | Negative and positive UI states behaved as expected; committed demo state did not persist after reload | Not evidence of real authentication, signature, server commit, immutable audit, or legal reliance |
| `PDV-009` | Verify built production-server delivery after runtime-script correction | **PASS** | Final candidate `/validation` and 9/9 referenced local JS/CSS assets returned 200 | Supersedes the failed pre-integration start attempt; future changes require rerun |
| `PDV-010` | Validate JSON/CSV/Markdown artifacts, manifest inventory/checksums, archive inventory, and validation-kit availability | **PASS** | Focused local integrity reconciled revision `.4`; the live validator confirmed the existing package paths within its 30 checks | Revision `.4` was not committed or deployed by this execution; no signed manifest or quality-system distribution approval |
| `PDV-011` | Verify targeted responsive typography behavior at desktop and mobile sizes | **PASS LIMITED** | Custom-domain QA passed at 1280 x 720 and 390 x 844 px; Inter and Source Serif loaded; no horizontal overflow; mobile launcher was 56 x 56 px; mobile header parent cue was hidden | Not cross-browser, keyboard, screen-reader, zoom, reflow, font-rendering consistency, or WCAG conformance evidence |
| `PDV-012` | Run the bounded live validator on the Sites-v21 primary custom-domain target | **PASS** | At `2026-08-12T01:25:22.377Z`, `https://qms.bio-consultant.com` passed 30/30; source release identified as commit `02d2f87...742b` | Canonical target was not recorded for v21; HTTP/content smoke is not backend, security, privacy, or data-integrity testing |
| `PDV-013` | Confirm the typography change's intended visible outcomes | **PASS LIMITED** | Both named font families loaded at both recorded viewports; no overflow; the mobile-specific launcher and parent-cue states matched expectations | Visual/DOM smoke only; no full visual-regression baseline or accessibility approval |

## 5. Anomalies and deviations

| ID | Description | Impact | Disposition |
| --- | --- | --- | --- |
| `ANOM-PD-001` | Initial `npm test` script was not Windows-portable | Default command failed on the initial working copy | Closed for final release: scripts were made portable and final `npm test` passed |
| `ANOM-PD-002` | Initial built server returned 404 for generated JS/CSS assets | Pre-integration production-start surface was unstyled | Closed historically: production-start wrapper was added and later local/live asset checks passed |
| `ANOM-PD-003` | No dedicated risk-based automated functional suite or controlled CI execution package was found | Regression depth remains inadequate for regulated production claims | Open; implement and retain approved automated/manual evidence |
| `ANOM-PD-004` | Browser QA covers two widths but not a supported browser/assistive-technology matrix | Accessibility and broad compatibility remain unestablished | Open; execute approved browser, keyboard, screen-reader, zoom, reflow, and WCAG plan |
| `ANOM-PD-005` | Global Bio-Consultant assistant uses browser storage and external chat/lead endpoints | Site is not wholly nonpersistent or synthetic-only at the platform boundary | Excluded from this conclusion; requires separate AI, privacy, security, consent, and integration assurance |
| `ANOM-PD-006` | Custom domain briefly served a stale/mixed cache state during a predecessor rollout | Users could receive prior HTML while new package files propagated | Closed historically after repeat checks passed; no cache anomaly was reported for Sites v21 |
| `ANOM-PD-007` | Current local `npm test` prerequisite was unavailable and dependency restoration timed out | Exact-commit lint/build evidence was not generated in this execution | Open technical evidence gap; rely only on the bounded live/browser results and obtain controlled CI evidence before any regulated-release conclusion |

No anomaly was closed or risk-accepted by an authorized human in this record.

## 6. Traceability reconciliation

`public-demo-traceability.csv` links the bounded intended use, selected PRD requirements, demo risks, controls, and tests. It intentionally does not claim traceability to every PRD requirement. Requirements concerning regulated production releases, security pipelines, customer deployments, regulated records, electronic signatures, and accessibility remain partial, not executed, or human-gated.

## 7. Conclusion

The final app source commit and Sites-v21 deployment have limited evidence that:

- the exact committed source is captured by the expanded scoped fingerprint, while the current local lint/build rerun remains an explicit evidence gap;
- the validation route and ten principal synthetic demo views render without observed framework overlays or relevant console warnings/errors in the recorded checks;
- the package anchor, complaint search, and simulated signature UI guard behave as described; and
- the local production start path serves referenced assets; and
- the primary custom-domain target passes the bounded 30-check live validator; and
- the exact typography release loads Inter and Source Serif and meets the recorded 1280 x 720 / 390 x 844 px responsive observations.

This is sufficient only for the public-demo intended use in `QMS-PD-IUS-001`, subject to the stated exclusions. It does not establish a validation-ready regulated release or approved production deployment. No dedicated risk-based functional regression suite exists, and qualified accessibility, security, privacy, AI, backend, data-integrity, recovery, performance, customer-configuration, and regulated release evidence is absent.

## 8. Required approvals and residual gates

Technical primary-target deployment gate `GATE-001` is passed for commit `02d2f87ecccfd7c7b0770b0b95df5ff69377242b` on Sites version 21. The following remain open and cannot be generated or signed by this automated execution:

1. Product and quality approval of intended use, claims, risk classification, protocol, results, anomalies, residual risk, and release disposition.
2. Controlled regulated-release identity, build provenance, retained CI evidence, SBOM/dependency review, release notes, known-anomaly approval, rollback, and deployment authorization. Candidate commit and Sites version identification do not supply quality approval.
3. Qualified security, privacy, AI, regulatory/legal, and accessibility review and testing.
4. Customer-defined intended use, applicable obligations, configuration, environment, integrations, procedures, risk acceptance, protocol approval, execution, deviation closure, training, production-release decision, and ongoing change control.

## 9. Approval record

No approval is recorded. Empty names or signature fields are deliberately omitted so this diagnostic record cannot be mistaken for an executed approval page.
