A short reminder sheet that pairs with the full playbook. Use it in a meeting when you need the next move, not a long read. Tap “What this means” on any card if a heading is unclear.
Civil Service specificUniversal any sectorBoth
MAP-01
Quality maps
Both
Strategy: risk-based · pyramid · charters
Specify: BDD · NFR / WCAG
Feedback: CI gates · DORA · residual risk
RL-01
The role
Both
You own the risk narrative. The team owns quality.
Run daily:
Biggest ship risk?
Feedback still too slow?
What are we not testing, and why?
TS-01
Test strategy
Universal
Risks, approach mix, envs
Gates with teeth
Evidence for go/no-go
Update when risk moves
TS-02
Risk-based
Universal
Likelihood × impact with PO
Deep where harm is high
Publish conscious de-scopes
Never hide accepted risk at go/no-go
SL-01
Shift left
Universal
One sharp risk question in refinement
Three amigos for ambiguity
API/unit hooks before UI-only waits
EX-01
Exploratory
Universal
Timeboxed charters
Mission, oracles, debrief
Notes others can follow
Not an excuse for zero automation
AU-01
Pyramid & CI
Universal
Many unit/API, thin E2E
Flaky = defect with owner
Red means stop, not rerun
No secrets in tests
QL-01
WCAG & NFRs
Both
WCAG AA in Ready and Done
Perf and security smoke in CI
Known defects have release decisions
RV-01
Release evidence
Universal
Residual risk narrative
Go / conditions / no-go
UAT without the end ambush
CM-01
Tone & ask
Universal
Devs: actionable repro
SRO: residual risk + recommendation
Drop "QA signed off". State conditions.
GV-03
Troubleshooting: symptom to first move
Universal
!Bottleneck: pull AC and API tests earlier this Sprint
!Flaky suites: quarantine with owners; fix or delete
!Late UAT: mid-Increment checks; freeze AC before build
!Everything high risk: score with PO; publish de-scopes