Where relevant to the agreed journey, I also review API responses, authentication and owner-access boundaries, data relationships, and failure/retry behavior using authorized read-only evidence or staging tests with synthetic data. Findings distinguish verified behavior from untested areas. We select the relevant checks within the one-journey scope and confirm inputs, access, price and timing before starting.