Need tenant-specific help? Prepare a safe support request.Do not submit sample, client, patient, credential, report, or other regulated data

WT-04 · proof-gated configuration

Sample collection setup

Proof-gated configuration contracts for matrices, sample types, containers, preservation, conditions, deviations, points, templates, and storage.

Before using this page

  • Use only a designated non-production tenant with synthetic records.
  • Confirm the exact effective role and route before changing anything.
  • Capture the pre-state and the supported reversal before the first mutation.
  • If any route, field, transition, or downstream effect differs, stop and mark the action tenant-dependent.

Tenant-dependent · runtime pending

CFG-09

Sample Matrices

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Sample Matrices. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: workflows.xml:250-251

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.

Evidence boundary: docs 9fb44eacc4a1; source ba6799a57d63; security f32ac72b910b; runtime transaction not yet accepted.

Tenant-dependent · runtime pending

CFG-10

Sample Types

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Sample Types. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: rolemap.xml:291-296; workflows.xml:259-260

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.

Evidence boundary: docs 9fb44eacc4a1; source ba6799a57d63; security f32ac72b910b; runtime transaction not yet accepted.

Tenant-dependent · runtime pending

CFG-11

Container Types

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Container Types. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: workflows.xml:202-203

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.

Evidence boundary: docs 9fb44eacc4a1; source ba6799a57d63; security f32ac72b910b; runtime transaction not yet accepted.

Tenant-dependent · runtime pending

CFG-12

Sample Containers

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Sample Containers. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: workflows.xml:199-203

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.

Evidence boundary: docs 9fb44eacc4a1; source ba6799a57d63; security f32ac72b910b; runtime transaction not yet accepted.

Tenant-dependent · runtime pending

CFG-13

Sample Preservations

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Sample Preservations. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: workflows.xml:256-257

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.

Evidence boundary: docs 9fb44eacc4a1; source ba6799a57d63; security f32ac72b910b; runtime transaction not yet accepted.

Tenant-dependent · runtime pending

CFG-14

Sample Conditions

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Sample Conditions. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: workflows.xml:247-248

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.

Evidence boundary: docs 9fb44eacc4a1; source ba6799a57d63; security f32ac72b910b; runtime transaction not yet accepted.

Tenant-dependent · runtime pending

CFG-15

Sampling Deviations

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Sampling Deviations. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: rolemap.xml:297-302; workflows.xml:262-263

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.

Evidence boundary: docs 9fb44eacc4a1; source ba6799a57d63; security f32ac72b910b; runtime transaction not yet accepted.

Tenant-dependent · runtime pending

CFG-16

Sample Points

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Sample Points. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: workflows.xml:253-254

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.

Evidence boundary: docs 9fb44eacc4a1; source ba6799a57d63; security f32ac72b910b; runtime transaction not yet accepted.

Tenant-dependent · runtime pending

CFG-17

Sample Templates

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Sample Templates. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: rolemap.xml:380-386; workflows.xml:187-188

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.

Evidence boundary: docs 9fb44eacc4a1; source ba6799a57d63; security f32ac72b910b; runtime transaction not yet accepted.

Tenant-dependent · runtime pending

CFG-18

Storage Locations

Who can do it: Separately authorized configuration administrator candidate.

Who cannot: Ordinary operational users and delegated LIMS User Admin. Upstream availability does not grant tenant authority.

Default navigation candidate: LIMS Setup → Storage Locations. The exact route and permission must be read back from the frozen tenant runtime.

Source-grounded contract

Create/edit; activate/deactivate

Existing evidence: rolemap.xml:303-308; workflows.xml:265-266

Field and dependency status

On a small screen, scroll the table horizontally to view every column.

AreaCurrent contractRelease condition
Required and optional fieldsNot yet accepted as a tenant-effective field contract.Record visible labels, required markers, validation, immutable fields, and approved synthetic examples.
DependenciesUse only prerequisites established by source and runtime.Prove both valid selection and safe behavior when the prerequisite is absent or inactive.
Existing-record impactNo blanket retroactive-effect claim.Compare a pre-existing synthetic record with a newly created one after the change.

Proof-gated walkthrough

  1. Permission preflight: authenticate as the claimed owner and as a delegated LIMS User Admin; record allow and deny behavior.
  2. Route and field capture: record the exact route, labels, defaults, required fields, and validation without using real lab data.
  3. Smallest transaction: create or edit one uniquely named synthetic record only when the expected reversal is known.
  4. Persistence: read the value directly, restart the disposable runtime, and read it again.
  5. Downstream check: exercise the smallest dependent synthetic workflow; do not infer effects from a success notice.
  6. Reversal: restore the prior value or use the source-supported deactivate/reactivate transition. If neither exists, record Support/CTM ownership rather than invent deletion.
  7. Negative proof: repeat the route/action as an unauthorized persona and verify no partial mutation.

Step-to-proof matrix

On a small screen, scroll the table horizontally to view every column.

StepRequired proofFailure gate
Permission preflightEffective roles, permission check, route status, and adjacent denial.Unexpected access or redirect blocks publication.
TransactionExact request/action, success state, and object identifier using synthetic data.Validation ambiguity, partial save, or unsupported field blocks publication.
PersistenceDirect readback before and after restart.Toast-only evidence or changed post-state blocks publication.
Functional effectDependent synthetic selection, report, worksheet, QC, or label result where relevant.No downstream proof means the effect remains unclaimed.
ReversalRestored values/state and repeated readback.No safe reversal changes disposition to Clearline-managed.

Expected outcome and failures

The action remains non-executable in public documentation until every proof row passes. A missing route, different label, denied permission, validation mismatch, unsupported transition, or failed reversal is an expected stop condition—not a prompt to improvise.

Escalation evidence: sanitized tenant/build identity, role/account type, route, exact validation text, synthetic object identifier, pre/post state, and attempted reversal. Never include credentials, regulated data, customer records, results, reports, or production exports.