What do I need to give the testers?
Give testers the app URL (staging if it mirrors production), two test accounts for every role, a short description of what each role should and should not do, code access if the scope includes review, the list of third-party services and AI features, a technical contact, and written authorization to test. Having these ready on day one saves paid tester days.
The preparation list
About data
Use realistic fake data in staging. If testing production, testers may see real personal information; the contract should cover confidentiality and deletion, since under PIPEDA they act as your service provider.
What not to do
Do not fix things during the test without telling the testers, and do not whitelist their IPs past protections you want tested unless agreed.
Writing the role description
The most useful document you can give testers is half a page describing each role. For each one: what it can see, what it can create, what it can change, what it can delete, and anything it must never do. For example: "Member: sees projects in their own organization; creates tasks; edits only tasks they created; cannot invite users or see billing."
Testers turn each line into attacks: can a member edit someone else's task, see billing, invite users, reach another organization's projects? Without the description, they have to infer the rules from the interface, which takes longer and misses rules the interface does not show. Writing it often reveals rules you never told your AI tool, which is where many findings come from.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
- Should I test staging or production?
- Black box test or code review?
- Security testing a vibe coded app
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Should I give them admin access?
Give them an admin test account if admin functions are in scope. They need it to test whether normal users can reach admin functions.
Do they need my hosting or Supabase dashboard access?
Usually not. A configuration review may ask for read-only access, agreed in the scope.