Includes:
• agreed critical flows and acceptance criteria
• browser smoke and exploratory checks
• focused API checks for auth, validation, error handling, and duplicate requests
• severity-ranked report with reproduction steps and evidence
• one retest pass and release recommendation