The sweep that could only find what it guarded
A check walked every screen looking for unprotected Save buttons, using the protection own selector. By construction it could not find one outside it.
Every Save button in our back office disables itself the moment it is pressed and comes back when the server has answered. It is one of the five feedback rules we build to, and it stops the second tap that creates a second order or a second supplier. The guard is one piece of code that watches for buttons matching a short list of patterns: a primary button, or one carrying a particular attribute.
A few weeks ago we wrote a sweep to prove the guard reached everywhere. It opened all one hundred and seven office screens in a browser, found the Save buttons on each, and pressed them to see whether they went grey. It reported sixteen that did not, we fixed them, and the sweep was recorded as having walked every route.
The probe used the guard's own eyes
It had walked every route. But the way it found a Save button on each one was to ask for elements matching the guard's own patterns. A button that did not match those patterns was invisible to the sweep in exactly the way it was invisible to the guard, so the one kind of button the sweep existed to find was the one kind it could not see. Two stragglers turned up afterwards by somebody clicking around, which is the signature of a census with a hole shaped like its own definition.
We walked the screens again, this time listing every visible button on each page regardless of what it looked like. One thousand nine hundred and eleven of them, of which the guard could see a hundred and eight.
Eighteen hundred is not a finding
The honest work was the reduction. Seven hundred and twenty-one of those buttons were seven controls counted once per screen: the sidebar toggle, the venue switcher and its code, the attention bar and its dismiss, the top bar icon and the avatar, each present on a hundred and three screens. That is the shell, not the screens. Most of the rest were small row actions, or buttons that open a dialog whose own footer has had its own guard for a while. That left a few hundred distinct controls, of which thirty-two carried a label that read like a write, and of those, six followed a naming convention this codebase genuinely uses for Save buttons.
And there was the finding, small and real. The dialog footer guard and the page-level guard disagreed about that convention. One of them matched a button whose id ends in the word save; the other did not. Twenty-four page-level buttons end that way, and eighteen of them were protected only because they happened to be primary buttons too. The fix was one pattern added to one list. The lesson is older: a check that looks for trouble using the definition of safety will report a clean sheet every time, and the clean sheet is the symptom.