Test more than the happy path before handing a flow over.
Does one valid request produce one intended result?
Does the process stop and explain what is missing?
Does repeating the same request avoid duplicate actions?
Can an unapproved request trigger a consequential action? It should not.
Is a failure visible, recoverable and assigned to an owner?
Can a user access only the information and actions they are permitted to use?
Record: case ID, input, expected behaviour, observation, pass/fail, reviewer and date. This checklist is not a security certification.
Version 1.0. Personal and internal team use. Examples are fictional. Not a certification or outcome guarantee.