Runnable artifactSynthetic data · no production actions

Browser runs withproof and brakes.

A compact control surface for deterministic Playwright checks, evidence capture, failure isolation, prompt-injection containment, and approval-gated agent actions.

This page simulates the control plane. It does not connect to live OTP, CRM, Claude, Sentry, Slack, or customer systems.
Run configuration
Choose a bounded scenario, then execute it.
Target: prooffirst.dev/web-qaAllowlisted
Run PF-0042
Last run reference snapshot ET · 1,842 ms
healthy
5/5
completed steps passed
3
synthetic regions
0
real customer records
Landing page
CTA and price assertions passed
passed
Registration form
Required fields are usable
passed
Synthetic OTP
Test-mode challenge accepted
passed
Slot API
Valid inventory returned in 312 ms
passed
CRM handoff
Synthetic lead excluded from reporting
passed
Regional probesPrivate values masked
Toronto
ca-central · 182 ms
London
eu-west · 247 ms
Mumbai
ap-south · 314 ms

Safety architecture

Treat evidence, authority, and side effects differently.

The same design supports a five-minute synthetic monitor and a supervised browser agent: deterministic steps, typed failures, least-privilege access, evidence capture, and explicit stops before consequential actions.

Domain allowlist

Navigation is limited to approved origins and exact redirect rules.

Synthetic identity

OTP and lead tests use client-owned test mode—never real customer data.

Injection boundary

Instructions found in page content cannot rewrite the trusted run plan.

Approval gates

Submissions, messages, purchases, and credential use pause for a person.

Verification record

3/3

Playwright paths

4/4

policy tests

The Playwright suite exercises both Web QA builds and the interactive agent console. The policy tests cover allowlisting, injection rejection, approval gating, and synthetic data.

Open artifacts

Inspect the implementation.

Honest boundary: this is independent portfolio work against an owned test route—not client work, a production SLA, or a live third-party integration.