- What it reproduces
- Mindmap creation, test-case generation, comprehensive JavaScript analysis and functional flow analysis. Those four are what a Security Brigade auditor moves through on an application, and the harness was written to run them rather than to run a check list.
- Where autonomy changes it
- A person works the highest-value part of a generated test set, because the engagement has an end date and they do not get to the rest. The platform has no end date, so the set is worked through. The same four practices then run the same way on the next target, at whatever cadence your releases ship.
- What comes out of the pair
- A test plan derived from what your application does, rather than a profile selected from what it appears to have been built with.