# Application action verification matrix Updated: 2026-08-10 This is the rolling action-level evidence index. `PASS (automated/runtime)` is not a browser or production claim. | Area | Action | Automated/API result | Browser | Production | Evidence | |---|---|---|---|---|---| | Origin | reject unknown/malformed production host | PASS | BLOCKED | NOT RUN | `sec-001-canonical-origin.md` | | Ingress | production host-port and forwarded-proxy contract | PASS (config) | N/A | NOT RUN | `sec-002-ingress-compose.md` | | Microsoft | tenant/issuer validation | PASS | BLOCKED | NOT RUN | `sec-003-microsoft-tenant.md` | | Microsoft | canonical link/relink/unlink isolation | PASS | BLOCKED | NOT RUN | `sec-004-microsoft-identity.md` | | Sessions | logout/reset/recovery revocation | PASS | BLOCKED | NOT RUN | `sec-005a-session-revocation.md` | | Email | register/verify/pending-change ownership | PASS | BLOCKED | NOT RUN | `sec-005b-email-ownership.md` | | Career/API | SQLite variants/runs/usage/history/workspace | PASS | BLOCKED | NOT RUN | `core-001-sqlite-provider-parity.md` | | Application workspace | timeline/interview board/generated brief routes and owner isolation | PASS | BLOCKED | NOT RUN | `core-002-route-uniqueness.md` | | Attachments | upload/list/download | PASS | BLOCKED | NOT RUN | `sec-008-attachment-consistency.md` | | Attachments | metadata rename/purpose/AI flag | PASS | BLOCKED | NOT RUN | `sec-008-attachment-consistency.md` | | Attachments | delete/restart recovery/two-user denial | PASS | BLOCKED | NOT RUN | `sec-008-attachment-consistency.md` | | Workers | two-owner rules, export, reminders and enrichment | PASS (real SQLite; fake email/AI) | BLOCKED pending notification UI | NOT RUN; switches off | `bg-001-tenant-workers.md` | | Durable operations | idempotent create/claim/lease/retry/cancel/complete | PASS (real SQLite) | NOT APPLICABLE until API/UI slice | NOT RUN | `ops-001a-durable-operations.md` | | Notifications | atomic terminal record, owner list/read/dismiss | PASS (real SQLite; forced rollback) | NOT APPLICABLE until API/UI slice | NOT RUN | `ops-001b-notifications.md` | | Operations UI | owner list/detail/cancel/retry and persistent notification surface | PASS (two-user HTTP + components) | BLOCKED | NOT RUN | `ops-001c-operation-ui.md` | | Entitlements | Free direct request to every explicit AI action | PASS (policy/route inventory) | BLOCKED | NOT RUN | `pol-001-free-pro-entitlements.md` | | Entitlements | stale Pro claim after downgrade | PASS (live-role policy test) | BLOCKED | NOT RUN | `pol-001-free-pro-entitlements.md` | | Entitlements | queued CV and enrichment worker recheck | PASS (fake AI; real SQLite worker scopes) | N/A | NOT RUN; workers off | `pol-001-free-pro-entitlements.md` | | Entitlements | Free core job create/detail and deterministic match data | PASS (automated) | BLOCKED | NOT RUN | `pol-001-free-pro-entitlements.md` | | Entitlements | Free locked AI Workspace/Career/CV Builder/job-assistance states | PASS (components) | BLOCKED | NOT RUN | `pol-001-free-pro-entitlements.md` | | Entitlements | Pro/Admin AI admission | PASS (automated policy) | BLOCKED | NOT RUN | `pol-001-free-pro-entitlements.md` | | AI evaluation | synthetic task/category/privacy/constraint fixture coverage | PASS (19 cases; validator) | N/A | N/A | `prod-002-ai-evaluation.md` | | AI privacy | disable AI for a current Pro user | PASS (live database policy + worker tests) | BLOCKED | NOT RUN | `pol-002-ai-privacy.md` | | AI privacy | external `/cv/*` without administrator gate or user consent | PASS — forced local in backend/sidecar tests | BLOCKED | NOT RUN | `pol-002-ai-privacy.md` | | AI privacy | approved external route with synthetic payload | PASS (mocked transport only) | BLOCKED | NOT RUN | `pol-002-ai-privacy.md` | | Durable AI | Pro admission, idempotent status URL and bounded capacity | PASS (real SQLite + synthetic subject IDs) | BLOCKED until real producer | NOT RUN; worker off | `ai-001-durable-ai-queue.md` | | Durable AI | priority/task-filtered atomic claim and owner-scoped success | PASS (fake handler, real operation/notification state) | N/A | NOT RUN | `ai-001-durable-ai-queue.md` | | Durable AI | retryable failure, downgrade recheck, lease/cancel/restart recovery | PASS (automated) | BLOCKED until real producer | NOT RUN | `ai-001-durable-ai-queue.md` | | AI routing | local primary success and no parallel external call | PASS (fake transports) | N/A | NOT RUN | `ai-002-provider-routing.md` | | AI routing | consent/admin/task/config/prompt-cap fallback denial | PASS (backend + sidecar policy tests) | BLOCKED | NOT RUN | `ai-002-provider-routing.md` | | AI routing | schema/local-outage/circuit fallback and external failure | PASS (fake transports) | BLOCKED | NOT RUN | `ai-002-provider-routing.md` | | AI routing | actual provider/model/route persistence on success/failure | PASS (real SQLite operation/history state; fake provider) | BLOCKED until real producer | NOT RUN | `ai-002-provider-routing.md` | | Strategy Snapshot | Pro enqueue returns 202; active/double-click request is idempotent | PASS (real SQLite; fake model) | BLOCKED | NOT RUN; worker off | `ai-003-strategy-snapshot-queue.md` | | Strategy Snapshot | queued/running/retry/failure/cancel/completion UI and cached result refresh | PASS (component tests) | BLOCKED | NOT RUN | `ai-003-strategy-snapshot-queue.md` | | Strategy Snapshot | owner-scoped rehydration/result/operation and no partial malformed output | PASS (real SQLite; fake model) | BLOCKED | NOT RUN | `ai-003-strategy-snapshot-queue.md` | | CV processing | upload 202, active duplicate reuse, owner-scoped execution and review gate | PASS (real SQLite; synthetic CV/fake provider) | BLOCKED | NOT RUN; worker off | `ai-004-cv-processing-queue.md` | | CV processing | retry provenance, durable refresh state and cancel/retry controls | PASS (backend + component tests) | BLOCKED | NOT RUN | `ai-004-cv-processing-queue.md` | | Authentication UI | unified username/password and provider alternatives; invalid/cancel/return behavior | PASS (components; mocked providers) | PARTIAL — local dark-theme form at 375/768/1440 | NOT RUN | `ux-001-unified-authentication.md` | | Theme state | Light/Dark/System precedence, login/logout scope, refresh/navigation and two-tab synchronization | PASS (state/provider/bootstrap tests) | PASS/PARTIAL — anonymous local browser at 375/768/1440 | NOT RUN | `ux-002-deterministic-theme-state.md` | | Job match terms | bilingual/noisy/short/technology-heavy/filler extraction and honest labels | PASS (seven fixtures + component tests) | NOT RUN | NOT RUN | `qa-001-job-term-quality.md` | | Career Workspace | first/returning/incomplete/loading/import processing/review/failure and recent CV actions | PASS (components; approval gate regression) | NOT RUN | NOT RUN | `career-001-career-workspace.md` | | CV Builder | edit/collapse/add/delete/reorder/hide, save states/latest-data retry, navigation warning and preview failure/retry | PASS (components) | NOT RUN | NOT RUN | `career-002-cv-builder.md` | | Job email hub | linked/review view switching, Gmail decision component reuse and legacy route redirect | PASS (components; mocked provider data) | NOT RUN | NOT RUN | `mail-001-job-email-hub.md` | | Job email hub | provider status, owner-scoped search/detail and saved-copy fallback | PASS (fake providers + components) | NOT RUN | NOT RUN | `mail-001-job-email-hub.md` | | Job email send | explicit confirmation, owner isolation, idempotency, failure/uncertainty and restart recovery | PASS (real SQLite + fake providers) | NOT RUN | NOT RUN | `mail-001-job-email-hub.md` | | Job email send | content-free encrypted/daily export and hard-job-delete cascade | PASS (real SQLite) | N/A | NOT RUN | `mail-001-job-email-hub.md` | | Follow-up draft | generate/edit/copy and open canonical Job email; legacy direct SMTP returns 410 | PASS (backend + components) | NOT RUN | NOT RUN | `mail-001-job-email-hub.md` | Remaining product actions are `NOT STARTED` in the master plan and will be added as their work packages enter verification. The in-app browser is available for local UI checks; configured/real-provider and production access are not documented/configured.