Session-based exploratory testing per the Bachs' SBTM: authoring charters (Explore X with Y to discover Z), running time-boxed sessions (60-90 min), logging session sheets with TBS metrics, and closing with the PROOF session debrief (Past, Results, Outlook, Obstacles, Feelings). Bundles the classic exploration heuristics as references: Whittaker's seven test tours (Feature, Money, Landmark, Intellectual, Bad-data, Configuration, Garbage collector's), Kelly's FCC CUTS VIDS recon tours, Bach's SFDPOT what-to-vary catalog, Bolton's HICCUPPS-F oracle heuristic, and Bach's CRUSSPIC STMPL quality criteria - plus a ready-to-fill charter-card template and a session-sheet review checklist. Use when planning, chartering, running, debriefing, or reviewing an exploratory testing session, or when picking a test tour, heuristic, or oracle mid-session. For scripted manual test cases, use manual-test-script-author instead.
86
91%
Does it follow best practices?
Impact
86%
1.01xAverage score across 10 eval scenarios
Passed
No findings from the security scan
We are turning on fingerprint and face unlock in the retail banking app next sprint. The app-sec team reviewed the design and came back with a list of eleven things they would like exercised by hand before we enable it for the 5% rollout cohort.
I have sixty minutes of one senior tester's time. That is the whole budget - he is on incident cover for the rest of the week and the rollout gate is Wednesday morning.
The risk that actually matters to the bank is someone else getting into an account: the enrolled biometric being accepted for the wrong customer, or a biometric staying valid after the customer's device or credentials should have invalidated it. Everything else on the list is real but is not what would put us in front of the regulator.
Rooted and jailbroken device handling is being covered by the vendor penetration test in two weeks, and we have no rooted handsets in the lab anyway. Do not plan for it.
Give me something the tester can pick up cold on Wednesday at 08:00 and a report I can attach to the rollout gate ticket by 09:30.
Produce a single file: docs/security/biometric-gate-check.md.
It must contain:
Budget: 60 minutes, one tester, single sitting, no second attempt before the gate. Out of scope: rooted and jailbroken devices, the vendor penetration test scope, and back-end key management.
Extract the following files before beginning.
=============== FILE: docs/biometric-unlock-brief.md ===============
Rollout: 5% cohort, Wednesday. Platforms: iOS 17+, Android 13+.