Part 6
Tests and QA: proof against intention
6.1 The principle, in one line
A test proves what the code does. Your intention proves nothing. The whole discipline is replacing "I'm pretty sure it works" with "here's the proof it works."
6.2 The levels that actually exist
Build check: does it compile. If it doesn't build, it doesn't ship. Type-check: catches a class of errors before anything runs. Lint: style and quality rules. Unit test: one function in isolation. End-to-end test: a real user journey simulated in a browser. Smoke test: a quick check in real conditions right after deploy, like the endpoint answering or the checkout charging the right amount. Human QA: a person running a checklist for the complex journeys (payment, emails, scheduled jobs) before a release. You don't need all of them on day one. You need to know which ones a given change requires.
6.3 False reds, and why they cost as much as false greens
Everyone worries about a test that passes when it shouldn't, a false green (Law 5). The opposite is just as dangerous: a test that fails when nothing is wrong, a false red. A false red trains you to ignore the check. After the third time a gate cries wolf, you stop reading it, and now it protects nothing, even when it's right. A flaky check is not a minor annoyance. It's a check on its way to being disabled.
6.4 What human QA does that tests never will
Automated tests check what you thought to check. A human running the flow notices what you didn't think of: the wording that confuses, the state that feels wrong, the thing that technically works but no user would understand. On money paths especially (payments, refunds, anything with real financial effect), you validate in real test mode, with a real event, not by reading the code and reasoning that it should be fine. Reasoning is not proof.
6.5 How to prove that a guard actually guards
When you add a safety check, prove it guards the way you'd prove any invariant: feed it the bad input on purpose and confirm it blocks. A guard you've only ever seen pass is a guard you haven't tested. It's Law 5 again, aimed at your own safety code.
6.6 Test early, from the first slice
The most expensive testing mistake is testing late. If you build ten slices before you run the whole thing end to end, a break in slice one hides until slice ten, and now you're debugging through nine layers to find it. Run the real journey as early as the first thin version exists. A bug caught at slice one is a five-minute fix. The same bug caught at slice ten is an afternoon.