WT-07 · proof-gated configuration
Instruments and materials
Separate instrument master data from calibration, maintenance, and adapter-specific result imports.
Before using this page
- Use only a designated non-production tenant with synthetic records.
- Confirm the exact effective role and route before changing anything.
- Capture the pre-state and the supported reversal before the first mutation.
- If any route, field, transition, or downstream effect differs, stop and mark the action tenant-dependent.
Tenant-dependent · runtime pending
CFG-27
Instrument Locations
Who can do it: Separately authorized configuration administrator candidate.
Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.
Default navigation candidate: LIMS Setup → Instrument Locations. The exact route and permission must be read back from the frozen tenant runtime.
Source-grounded contract
Create/edit; activate/deactivate
Existing evidence: workflows.xml:217-218
Field and dependency status
On a small screen, scroll the table horizontally to view every column.
| Area | Current contract | Release condition |
|---|---|---|
| Required and optional fields | Not yet accepted as a tenant-effective field contract. | Record visible labels, required markers, validation, immutable fields, and approved synthetic examples. |
| Dependencies | Use only prerequisites established by source and runtime. | Prove both valid selection and safe behavior when the prerequisite is absent or inactive. |
| Existing-record impact | No blanket retroactive-effect claim. | Compare a pre-existing synthetic record with a newly created one after the change. |
Proof-gated walkthrough
- Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
- Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
- Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
- Persistence: read the value directly, restart the disposable runtime, and read it again.
- Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
- Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
- Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.
Step-to-proof matrix
On a small screen, scroll the table horizontally to view every column.
| Step | Required proof | Failure gate |
|---|---|---|
| Permission preflight | Effective roles, permission check, route status, and adjacent denial. | Unexpected access or redirect blocks publication. |
| Transaction | Exact request/action, success state, and object identifier using synthetic data. | Validation ambiguity, partial save, or unsupported field blocks publication. |
| Persistence | Direct readback before and after restart. | Toast-only evidence or changed post-state blocks publication. |
| Functional effect | Dependent synthetic selection, report, worksheet, QC, or label result where relevant. | No downstream proof means the effect remains unclaimed. |
| Reversal | Restored values/state and repeated readback. | No safe reversal changes disposition to Clearline-managed. |
Expected outcome and failures
The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.
Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.
Tenant-dependent · runtime pending
CFG-28
Instrument Types
Who can do it: Separately authorized configuration administrator candidate.
Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.
Default navigation candidate: LIMS Setup → Instrument Types. The exact route and permission must be read back from the frozen tenant runtime.
Source-grounded contract
Create/edit; activate/deactivate
Existing evidence: workflows.xml:220-221
Field and dependency status
On a small screen, scroll the table horizontally to view every column.
| Area | Current contract | Release condition |
|---|---|---|
| Required and optional fields | Not yet accepted as a tenant-effective field contract. | Record visible labels, required markers, validation, immutable fields, and approved synthetic examples. |
| Dependencies | Use only prerequisites established by source and runtime. | Prove both valid selection and safe behavior when the prerequisite is absent or inactive. |
| Existing-record impact | No blanket retroactive-effect claim. | Compare a pre-existing synthetic record with a newly created one after the change. |
Proof-gated walkthrough
- Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
- Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
- Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
- Persistence: read the value directly, restart the disposable runtime, and read it again.
- Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
- Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
- Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.
Step-to-proof matrix
On a small screen, scroll the table horizontally to view every column.
| Step | Required proof | Failure gate |
|---|---|---|
| Permission preflight | Effective roles, permission check, route status, and adjacent denial. | Unexpected access or redirect blocks publication. |
| Transaction | Exact request/action, success state, and object identifier using synthetic data. | Validation ambiguity, partial save, or unsupported field blocks publication. |
| Persistence | Direct readback before and after restart. | Toast-only evidence or changed post-state blocks publication. |
| Functional effect | Dependent synthetic selection, report, worksheet, QC, or label result where relevant. | No downstream proof means the effect remains unclaimed. |
| Reversal | Restored values/state and repeated readback. | No safe reversal changes disposition to Clearline-managed. |
Expected outcome and failures
The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.
Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.
Tenant-dependent · runtime pending
CFG-29
Instruments
Who can do it: Separately authorized configuration administrator candidate.
Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.
Default navigation candidate: LIMS Setup → Instruments. The exact route and permission must be read back from the frozen tenant runtime.
Source-grounded contract
Create/edit metadata; activate/deactivate; calibration/maintenance/import actions require separate proof
Existing evidence: bika_instruments.py:52-54; workflows.xml:214-215
Field and dependency status
On a small screen, scroll the table horizontally to view every column.
| Area | Current contract | Release condition |
|---|---|---|
| Required and optional fields | Not yet accepted as a tenant-effective field contract. | Record visible labels, required markers, validation, immutable fields, and approved synthetic examples. |
| Dependencies | Use only prerequisites established by source and runtime. | Prove both valid selection and safe behavior when the prerequisite is absent or inactive. |
| Existing-record impact | No blanket retroactive-effect claim. | Compare a pre-existing synthetic record with a newly created one after the change. |
Proof-gated walkthrough
- Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
- Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
- Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
- Persistence: read the value directly, restart the disposable runtime, and read it again.
- Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
- Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
- Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.
Step-to-proof matrix
On a small screen, scroll the table horizontally to view every column.
| Step | Required proof | Failure gate |
|---|---|---|
| Permission preflight | Effective roles, permission check, route status, and adjacent denial. | Unexpected access or redirect blocks publication. |
| Transaction | Exact request/action, success state, and object identifier using synthetic data. | Validation ambiguity, partial save, or unsupported field blocks publication. |
| Persistence | Direct readback before and after restart. | Toast-only evidence or changed post-state blocks publication. |
| Functional effect | Dependent synthetic selection, report, worksheet, QC, or label result where relevant. | No downstream proof means the effect remains unclaimed. |
| Reversal | Restored values/state and repeated readback. | No safe reversal changes disposition to Clearline-managed. |
Expected outcome and failures
The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.
Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.