Skip to main content

ADR 0007: Privacy-First Testing Strategy


Context​

Correctness alone is insufficient. Regressions that auto-send, spoof “Local LLM,” or exfiltrate résumé text are product-breaking. Tests must encode user guarantees, not vanity throughput.

Alternatives considered:

OptionProsCons
Layered tests with privacy must-pass suiteProtects promisesSlightly more fixtures/discipline
UI-only E2ELooks realSlow; misses package fences
Metric-driven “apply volume” benchmarksGrowth theaterViolates leverage-over-volume

Decision​

Adopt a layered testing strategy with an explicit privacy & sovereignty must-pass set.

Layers: unit → contract → integration → privacy/boundary → UI a11y → plugin capability denial.

Must-pass guarantees include:

  1. No résumé egress without send path
  2. Approval gates honored
  3. Agent pause leaves queue intact and cannot send
  4. Honest send outcomes (unknown ≠ success)
  5. Local badge truthfulness
  6. Capabilities fail closed
  7. No inactivity-shame scheduler jobs

Tooling posture (implementation may pin versions later): unit/contract in TypeScript packages; host integration tests; UI smoke for badge/focus/live regions. Test names describe user guarantees calmly.


Consequences​

Positive​

  • Architecture laws stay enforceable as code lands.
  • Plugins/extensions get deny-by-default proof.
  • Aligns engineering culture with brand calm.

Negative / tradeoffs​

  • Boundary tests need careful network mocking.
  • Full Tauri E2E may be sparse early — prioritize package-level proofs.

Follow-ups​

  • Keep synthetic fixtures in examples/ only — never real user data in git.
  • CI gates must-pass suite on mainline once code exists.