{
  "url": "https://accounts.google.com",
  "auditedAt": "2026-07-27T19:14:23.318Z",
  "mode": "report",
  "status": "partial",
  "statusDetail": "Atomic coverage is structurally complete, but 2 checks were blocked by credential requirements and 4 active tests were not run or could not be triggered reliably.",
  "page": {
    "appType": "hybrid",
    "framework": "Google Accounts server-rendered Lite / client-enhanced Glif variants",
    "notes": "The generic evidence primitives received a lightweight server-rendered sign-in variant; Lighthouse received the fuller Glif variant. The audit covers the identifier entry, mobile reflow, raw no-JS view, and signup first step. Credentialed/password, account-management, recovery completion, and authenticated states are excluded."
  },
  "evidenceUsed": [
    "screenshot",
    "dom",
    "layout-metrics",
    "evaluate-probe",
    "trace",
    "har",
    "discoverability",
    "headers",
    "cookies",
    "trackers",
    "secrets",
    "images",
    "heap-summary",
    "lighthouse",
    "Modern Web Guidance 0.0.172"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "accessibility",
    "forms",
    "passkeys",
    "performance",
    "security",
    "privacy",
    "validate-input-after-interaction",
    "same-document-transitions",
    "identify-heavy-scripts",
    "optimize-preload-priority"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "Desktop sign-in initial state",
      "condition": "desktop",
      "findingIds": [
        "F07"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "Mobile sign-in at 360x800",
      "condition": "viewport: 360x800",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile-320.png",
      "caption": "Mobile sign-in at 320x640",
      "condition": "viewport: 320x640",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/dark.png",
      "caption": "Sign-in under requested dark scheme",
      "condition": "prefers-color-scheme: dark",
      "findingIds": [
        "F01"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/contrast.png",
      "caption": "Sign-in under increased contrast preference",
      "condition": "prefers-contrast: more",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/focus.png",
      "caption": "Focused first link, showing no visible focus treatment",
      "condition": "keyboard focus",
      "findingIds": [
        "F02"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/signup.png",
      "caption": "Create-account first step",
      "condition": "system dark scheme",
      "findingIds": [
        "F01"
      ]
    },
    {
      "type": "layout",
      "path": "evidence/layout-mobile.json",
      "caption": "Mobile layout metrics: no overflow, CLS 0",
      "condition": "viewport: 360x800",
      "findingIds": []
    },
    {
      "type": "dom",
      "path": "evidence/dom.json",
      "caption": "Rendered DOM and computed styles for sign-in",
      "condition": "default",
      "findingIds": [
        "F01",
        "F02",
        "F08"
      ]
    },
    {
      "type": "other",
      "path": "evidence/probe.json",
      "caption": "Metadata, links, controls, landmarks and feature probe",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/focus.json",
      "caption": "Programmatic focus-visible computed-style probe",
      "condition": "keyboard focus",
      "findingIds": [
        "F02"
      ]
    },
    {
      "type": "other",
      "path": "evidence/preferences.json",
      "caption": "Reduced-motion animation probe",
      "condition": "prefers-reduced-motion: reduce",
      "findingIds": []
    },
    {
      "type": "trace",
      "path": "evidence/perf",
      "caption": "Raw DevTools performance trace",
      "condition": "default",
      "findingIds": [
        "F03"
      ]
    },
    {
      "type": "trace-summary",
      "path": "evidence/perf-summary.json",
      "caption": "Trace summary with 0.843 s LCP and no long tasks",
      "condition": "default",
      "findingIds": [
        "F03"
      ]
    },
    {
      "type": "har",
      "path": "evidence/network",
      "caption": "HAR network capture",
      "condition": "default",
      "findingIds": [
        "F04"
      ]
    },
    {
      "type": "har-summary",
      "path": "evidence/network-summary.json",
      "caption": "Compact HAR summary",
      "condition": "default",
      "findingIds": [
        "F04"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Lighthouse report for full sign-in variant",
      "condition": "mobile throttling",
      "findingIds": [
        "F03",
        "F04",
        "F05",
        "F07",
        "F08"
      ]
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Security response headers",
      "condition": "default",
      "findingIds": [
        "F06"
      ]
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Cookie audit",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Third-party tracker inventory",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Client secret scan",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Image delivery and alt audit",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability",
      "caption": "Raw HTML versus rendered discoverability record",
      "condition": "JavaScript disabled/raw fetch",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "Discoverability browser view",
      "condition": "JavaScript enabled",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "Discoverability crawler view",
      "condition": "JavaScript disabled",
      "findingIds": []
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.json",
      "caption": "Baseline heap summary",
      "condition": "initial state",
      "findingIds": []
    },
    {
      "type": "heap",
      "path": "evidence/heap-post.json",
      "caption": "Heap after ten input interactions",
      "condition": "10 focus/input/clear/blur cycles",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/runtime.json",
      "caption": "Runtime memory, DOM, script and style probe",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/robots.json",
      "caption": "robots.txt and sitemap fetch results",
      "condition": "crawler",
      "findingIds": []
    },
    {
      "type": "dom",
      "path": "evidence/signup-dom.json",
      "caption": "Signup DOM and computed styles",
      "condition": "system dark scheme",
      "findingIds": []
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 52,
    "blocked": 2,
    "notRun": 4,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": false
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The dark-emulated screenshot is pixel-equivalent in appearance to the light capture, while the DOM reports color-scheme: normal and a white body background. The separate signup route does render dark, showing inconsistent preference support across the account journey.",
      "pathIds": [
        "sign-in"
      ],
      "artifacts": [
        "evidence/dark.png",
        "evidence/dom.json",
        "evidence/signup.png"
      ],
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The reduced-motion probe confirmed the emulated preference and found zero active animations.",
      "artifacts": [
        "evidence/preferences.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Lighthouse contrast passed and the prefers-contrast screenshot retained visible text, input boundaries, and controls.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/contrast.png"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "not-run",
      "confidence": "high",
      "method": "Planned active state/condition test",
      "evidence": "A successful identifier-to-authentication state transition was not executed because it requires valid credentials; no equivalent safe transition was available in the Lite response.",
      "reason": "A successful identifier-to-authentication state transition was not executed because it requires valid credentials; no equivalent safe transition was available in the Lite response."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "The audited identifier and signup forms contain no scroll-linked storytelling, parallax, carousel, or reveal motion.",
      "reason": "The audited identifier and signup forms contain no scroll-linked storytelling, parallax, carousel, or reveal motion."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "The audited forms expose no gesture-driven control or scroll-snap interaction.",
      "reason": "The audited forms expose no gesture-driven control or scroll-snap interaction."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "The short, single-task sign-in form has no persistent page chrome whose behavior needs to react to scroll position.",
      "reason": "The short, single-task sign-in form has no persistent page chrome whose behavior needs to react to scroll position."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "No tooltip, popover, context menu, or anchored overlay is present on the audited states.",
      "reason": "No tooltip, popover, context menu, or anchored overlay is present on the audited states."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Desktop/mobile screenshots show one H1, one outlined input, and one visually dominant Next action in reading order.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/mobile.png"
      ],
      "pathIds": [
        "sign-in",
        "sign-in-mobile"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Initial screenshots show the sign-in form immediately with no interstitial, consent wall, popup, or obscuring banner.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/mobile.png"
      ],
      "pathIds": [
        "sign-in",
        "sign-in-mobile"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "No transient overlay, dialog, disclosure, or rich custom picker is present on the audited states.",
      "reason": "No transient overlay, dialog, disclosure, or rich custom picker is present on the audited states."
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The first viewport is dominated by the task form and explanatory copy; only compact footer links sit outside the form.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/mobile.png"
      ],
      "pathIds": [
        "sign-in",
        "sign-in-mobile"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "At 360x800, layout metrics report scrollWidth=clientWidth=360 and 0 horizontal overflow; viewport metadata is present.",
      "artifacts": [
        "evidence/layout-mobile.json",
        "evidence/mobile.png"
      ],
      "pathIds": [
        "sign-in-mobile"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The form changes from a bordered centered desktop card to a full-width mobile composition without overflow or clipped controls.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/mobile.png",
        "evidence/layout-mobile.json"
      ],
      "pathIds": [
        "sign-in",
        "sign-in-mobile"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "issues",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The active focus probe found :focus-visible=true on the email input, links, and Next button, but every control computed outline-style:none and box-shadow:none. The focused-link screenshot shows no visible change, and the Lite sign-in DOM has no main landmark.",
      "pathIds": [
        "sign-in"
      ],
      "artifacts": [
        "evidence/focus.json",
        "evidence/focus.png",
        "evidence/dom.json"
      ],
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Both sign-in and signup states state their purpose in an H1 and present one visually dominant Next action.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/signup.png"
      ],
      "pathIds": [
        "sign-in",
        "signup"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted journey planning; stopped before protected state",
      "evidence": "A credentialed end-to-end sign-in requires a real Google account and must not be attempted with fabricated credentials.",
      "reason": "A credentialed end-to-end sign-in requires a real Google account and must not be attempted with fabricated credentials.",
      "pathIds": [
        "credentialed-flow"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "not-run",
      "confidence": "high",
      "method": "Planned active state/condition test",
      "evidence": "The synthetic untrusted click did not trigger the production validation flow, so error/success/retry states were not conclusively exercised.",
      "reason": "The synthetic untrusted click did not trigger the production validation flow, so error/success/retry states were not conclusively exercised."
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "issues",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Lighthouse measured LCP at 4.3 s and TTI at 6.1 s (performance 0.81). A separate unthrottled trace of the Lite response measured LCP at 0.843 s, so the regression is condition/variant-sensitive rather than universal.",
      "pathIds": [
        "sign-in"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/perf-summary.json",
        "evidence/perf"
      ],
      "findingIds": [
        "F03"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Layout observer and Lighthouse both measured CLS 0 with no recorded shifts.",
      "artifacts": [
        "evidence/layout-mobile.json",
        "evidence/lighthouse.json"
      ],
      "pathIds": [
        "sign-in-mobile",
        "sign-in"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The raw trace recorded no >50 ms tasks and 0 ms TBT; Lighthouse TBT remained 193 ms.",
      "artifacts": [
        "evidence/perf-summary.json",
        "evidence/lighthouse.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "issues",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The HAR shows three document redirects before the identifier page. Lighthouse reports a 686 ms longest network chain, including a 55 KB font, alongside the 4.3 s LCP.",
      "pathIds": [
        "sign-in"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/network",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F04"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "issues",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Lighthouse estimates 361 KiB of removable JavaScript and 165 KiB of removable CSS; two JavaScript bundles are 64–73% unused in the measured view.",
      "pathIds": [
        "sign-in"
      ],
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Lighthouse accessibility scored 1.0; label and button-name audits pass, and the Google image has alt text.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/images.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Lighthouse color-contrast audit passes and normal/high-contrast screenshots remain legible.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/contrast.png"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "issues",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The active focus probe found :focus-visible=true on the email input, links, and Next button, but every control computed outline-style:none and box-shadow:none. The focused-link screenshot shows no visible change, and the Lite sign-in DOM has no main landmark.",
      "pathIds": [
        "sign-in"
      ],
      "artifacts": [
        "evidence/focus.json",
        "evidence/focus.png",
        "evidence/dom.json"
      ],
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Desktop and 320/360 px screenshots show unclipped text, readable line lengths, and clear hierarchy.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/mobile.png",
        "evidence/mobile-320.png"
      ],
      "pathIds": [
        "sign-in",
        "sign-in-mobile"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Viewport scaling is not disabled, mobile reflow has no horizontal overflow, and the page contains no audio/video requiring alternatives.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/layout-mobile.json",
        "evidence/lighthouse.json"
      ],
      "pathIds": [
        "sign-in",
        "sign-in-mobile"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Lighthouse reports no browser console errors.",
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "DOM/Lighthouse confirm HTML doctype, UTF-8 charset, viewport metadata, and correctly dimensioned image with matching 2x display size.",
      "artifacts": [
        "evidence/dom.json",
        "evidence/lighthouse.json",
        "evidence/images.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Lighthouse best-practices scored 1.0; no permission prompts appeared and the bfcache exclusions are security-related no-store/WebAuthn constraints.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "issues",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The DOM probe and Lighthouse both found a descriptive title but no meta[name=description].",
      "pathIds": [
        "sign-in"
      ],
      "artifacts": [
        "evidence/dom.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F08"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Lighthouse confirms crawlable anchors, a valid robots.txt, indexing allowed, and viewport metadata; link labels are descriptive.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/robots.json",
        "evidence/probe.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The entry and final sign-in documents returned successful/expected redirect statuses, robots.txt allows the page, and no accidental noindex policy was found. A canonical is not appropriate for session-specific authentication continuation URLs.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/robots.json",
        "evidence/probe.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "The authentication form is not a public article, product, event, organization profile, or other shareable rich entity.",
      "reason": "The authentication form is not a public article, product, event, organization profile, or other shareable rich entity."
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "HTTPS, HSTS, nosniff, X-Frame-Options:DENY, CSP nonces/Trusted Types, and a Secure HttpOnly __Host- cookie were directly observed.",
      "artifacts": [
        "evidence/headers.json",
        "evidence/cookies.json",
        "evidence/secrets.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Tracker probe found no known tracker domains; HAR recorded only two low-byte third-party requests and secrets scan found no exposed credentials.",
      "artifacts": [
        "evidence/trackers.json",
        "evidence/network-summary.json",
        "evidence/secrets.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "No on-load permission activity was observed; Lighthouse identifies WebAuthentication API use, corroborating phishing-resistant authentication support.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/lighthouse.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The headers probe found no Referrer-Policy header and a CSP policy containing unsafe-eval. Strong compensating controls are present, including HSTS, X-Frame-Options:DENY, nosniff, nonces, and require-trusted-types-for script.",
      "pathIds": [
        "sign-in"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F06"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Discoverability raw fetch is HTTP 200, not a JS shell, retains title/H1, and exposes 76% of rendered content without JavaScript.",
      "artifacts": [
        "evidence/discoverability",
        "evidence/discoverability-crawler.png",
        "evidence/discoverability-rendered.png"
      ],
      "pathIds": [
        "no-js"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "No overlays can be clipped, no console/runtime errors were observed, and the simple server-rendered state remained stable.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/desktop.png"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "Authentication is intrinsically online and should not be installable or claim offline completion.",
      "reason": "Authentication is intrinsically online and should not be installable or claim offline completion."
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "not-run",
      "confidence": "high",
      "method": "Planned active state/condition test",
      "evidence": "Offline and HTTP-failure injection was not run against this live authentication endpoint to avoid disrupting or misrepresenting security-sensitive behavior.",
      "reason": "Offline and HTTP-failure injection was not run against this live authentication endpoint to avoid disrupting or misrepresenting security-sensitive behavior."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The DOM declares lang=en-US and dir=ltr, and both sign-in and signup expose a language selector.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/desktop.png",
        "evidence/signup.png"
      ],
      "pathIds": [
        "sign-in",
        "signup"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "The audited states display no dates, numbers, currency, duration, or calendar data to localize.",
      "reason": "The audited states display no dates, numbers, currency, duration, or calendar data to localize."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "The audited states expose no time or recurring-event concepts.",
      "reason": "The audited states expose no time or recurring-event concepts."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Initial sign-in/signup screenshots show no preselected consent, upsell, continuity trap, disguised ad, or confirmshaming; recovery and account creation are plainly labelled.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/signup.png"
      ],
      "pathIds": [
        "sign-in",
        "signup"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "not-run",
      "confidence": "high",
      "method": "Planned active state/condition test",
      "evidence": "The production validation state could not be triggered reliably with the generic untrusted interaction probe, so timing and accessible announcement were not judged.",
      "reason": "The production validation state could not be triggered reliably with the generic untrusted interaction probe, so timing and accessible announcement were not judged."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The identifier field exposes autocomplete=username and visible Email or phone labelling.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/dom.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted journey planning; stopped before protected state",
      "evidence": "Credentialed sign-in, reauthentication, account management, and cancellation/reversal states require an authorized test account.",
      "reason": "Credentialed sign-in, reauthentication, account management, and cancellation/reversal states require an authorized test account.",
      "pathIds": [
        "credentialed-flow"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The only image is a dimensioned 3.7 KB 2x logo, displayed at exactly half its natural dimensions; no oversized assets were found.",
      "artifacts": [
        "evidence/images.json",
        "evidence/network-summary.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "issues",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "Lighthouse estimates 361 KiB unused JavaScript and 165 KiB unused CSS on a screen whose core UI is one text field and one primary button.",
      "pathIds": [
        "sign-in"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/desktop.png"
      ],
      "findingIds": [
        "F07"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "pass",
      "confidence": "high",
      "method": "Direct artifact review and objective probe",
      "evidence": "The Lite HAR transfers 156.6 KB with 5.2 KB third-party bytes and no audio/video/autoplay media.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/probe.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "Exposing sign-in or account-creation actions as general agent tools would be inappropriate for this sensitive authentication surface; no declared agent-facing intent exists.",
      "reason": "Exposing sign-in or account-creation actions as general agent tools would be inappropriate for this sensitive authentication surface; no declared agent-facing intent exists."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and applicability judgement from rendered DOM and page purpose",
      "evidence": "The deterministic sign-in form has no summarization or language-model task that would benefit from on-device inference.",
      "reason": "The deterministic sign-in form has no summarization or language-model task that would benefit from on-device inference."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct artifact review and objective probe",
      "evidence": "After ten focus/input/clear/blur cycles, heap self-size changed from 7,936,758 to 7,941,728 bytes (+4,970 bytes, 0.06%), with no unbounded-growth signal.",
      "artifacts": [
        "evidence/heap-baseline.json",
        "evidence/heap-post.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct artifact review and objective probe",
      "evidence": "The Lite page heap is about 7.94 MB with 178 live DOM elements and 4.77 MB JS heap used, proportionate to the form.",
      "artifacts": [
        "evidence/heap-baseline.json",
        "evidence/runtime.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "medium",
      "method": "Direct artifact review and objective probe",
      "evidence": "The before/after summaries show only +13 native nodes after ten cycles and no Detached* constructor among the reported top constructors.",
      "artifacts": [
        "evidence/heap-baseline.json",
        "evidence/heap-post.json"
      ],
      "pathIds": [
        "sign-in"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "incomplete",
      "reason": "One or more atomic checks were blocked or not run; see checkOutcomes."
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "incomplete",
      "reason": "One or more atomic checks were blocked or not run; see checkOutcomes."
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F03",
        "F04",
        "F05"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F08"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F06"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "incomplete",
      "reason": "One or more atomic checks were blocked or not run; see checkOutcomes."
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "incomplete",
      "reason": "One or more atomic checks were blocked or not run; see checkOutcomes."
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F07"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "Exposing sign-in or account-creation actions as general agent tools would be inappropriate for this sensitive authentication surface; no declared agent-facing intent exists. The deterministic sign-in form has no summarization or language-model task that would benefit from on-device inference."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "pass"
    }
  ],
  "paths": [
    {
      "id": "sign-in",
      "description": "Public identifier-entry page: desktop initial state, semantics, focus, metadata, security, network, performance and memory.",
      "url": "https://accounts.google.com",
      "conditions": [
        "desktop",
        "keyboard-only",
        "prefers-color-scheme: dark",
        "prefers-contrast: more",
        "prefers-reduced-motion: reduce"
      ],
      "result": "issues"
    },
    {
      "id": "sign-in-mobile",
      "description": "Identifier-entry mobile template at 360x800 and 320x640, representing narrow-screen reflow.",
      "url": "https://accounts.google.com",
      "conditions": [
        "viewport 360x800",
        "viewport 320x640"
      ],
      "result": "issues"
    },
    {
      "id": "signup",
      "description": "Create-account first step, representing the linked signup form archetype.",
      "url": "https://accounts.google.com/signup",
      "conditions": [
        "system dark scheme"
      ],
      "result": "pass"
    },
    {
      "id": "no-js",
      "description": "Raw no-JavaScript/crawler view of the public identifier page.",
      "url": "https://accounts.google.com",
      "conditions": [
        "JavaScript disabled/raw HTML"
      ],
      "result": "pass"
    },
    {
      "id": "credentialed-flow",
      "description": "Credentialed sign-in through password/passkey and account-management states. Not executed without an authorized test account.",
      "url": "https://accounts.google.com",
      "conditions": [
        "credentialed"
      ],
      "result": "skipped"
    }
  ],
  "findings": [
    {
      "id": "F01",
      "pathId": "sign-in",
      "url": "https://accounts.google.com",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "The sign-in surface ignores the user’s dark color-scheme preference.",
      "evidence": "The dark-emulated screenshot is pixel-equivalent in appearance to the light capture, while the DOM reports color-scheme: normal and a white body background. The separate signup route does render dark, showing inconsistent preference support across the account journey.",
      "artifacts": [
        "evidence/dark.png",
        "evidence/dom.json",
        "evidence/signup.png"
      ],
      "suggestedFix": "Apply the same root-level light/dark color tokens used by the signup flow to sign-in; declare <meta name=\"color-scheme\" content=\"light dark\"> and color-scheme: light dark on :root.",
      "effort": "small"
    },
    {
      "id": "F02",
      "pathId": "sign-in",
      "url": "https://accounts.google.com",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Keyboard focus is not visibly distinguished on the sign-in controls.",
      "evidence": "The active focus probe found :focus-visible=true on the email input, links, and Next button, but every control computed outline-style:none and box-shadow:none. The focused-link screenshot shows no visible change, and the Lite sign-in DOM has no main landmark.",
      "artifacts": [
        "evidence/focus.json",
        "evidence/focus.png",
        "evidence/dom.json"
      ],
      "suggestedFix": "Add a high-contrast :focus-visible outline or equivalent ring to every interactive control and place the primary sign-in content in a <main> landmark.",
      "effort": "small"
    },
    {
      "id": "F03",
      "pathId": "sign-in",
      "url": "https://accounts.google.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "good-core-web-vitals",
      "guidanceId": "performance",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "medium",
      "summary": "The full sign-in implementation misses the good LCP threshold under Lighthouse throttling.",
      "evidence": "Lighthouse measured LCP at 4.3 s and TTI at 6.1 s (performance 0.81). A separate unthrottled trace of the Lite response measured LCP at 0.843 s, so the regression is condition/variant-sensitive rather than universal.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/perf-summary.json",
        "evidence/perf"
      ],
      "suggestedFix": "Profile the full Glif sign-in variant’s LCP dependency chain, prioritize its LCP text/font resources, and defer work that is not needed for the identifier step.",
      "effort": "medium"
    },
    {
      "id": "F04",
      "pathId": "sign-in",
      "url": "https://accounts.google.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-resource-delivery",
      "guidanceId": "optimize-preload-priority",
      "guidanceCategory": "performance",
      "severity": "low",
      "confidence": "medium",
      "summary": "Redirect and font/script dependency chains delay the full sign-in render.",
      "evidence": "The HAR shows three document redirects before the identifier page. Lighthouse reports a 686 ms longest network chain, including a 55 KB font, alongside the 4.3 s LCP.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/network",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Collapse avoidable entry redirects and ensure only the critical font/style resources are prioritized for the identifier view.",
      "effort": "medium"
    },
    {
      "id": "F05",
      "pathId": "sign-in",
      "url": "https://accounts.google.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "identify-heavy-scripts",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "The identifier step ships substantial code not used during initial render.",
      "evidence": "Lighthouse estimates 361 KiB of removable JavaScript and 165 KiB of removable CSS; two JavaScript bundles are 64–73% unused in the measured view.",
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Split the account UI by step and load password, recovery, account-picker, and ancillary modules only when those states are reached; tree-shake unused CSS.",
      "effort": "large"
    },
    {
      "id": "F06",
      "pathId": "sign-in",
      "url": "https://accounts.google.com",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "severity": "medium",
      "confidence": "high",
      "summary": "The authentication response has gaps in explicit browser-enforced policy.",
      "evidence": "The headers probe found no Referrer-Policy header and a CSP policy containing unsafe-eval. Strong compensating controls are present, including HSTS, X-Frame-Options:DENY, nosniff, nonces, and require-trusted-types-for script.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "suggestedFix": "Set an explicit restrictive Referrer-Policy and remove unsafe-eval from the remaining allow-list policy after a report-only compatibility rollout; preserve Trusted Types and nonce enforcement.",
      "effort": "medium"
    },
    {
      "id": "F07",
      "pathId": "sign-in",
      "url": "https://accounts.google.com",
      "principleId": "be-sustainable",
      "principleCheckId": "no-wasteful-work",
      "guidanceId": "identify-heavy-scripts",
      "guidanceCategory": "performance",
      "severity": "low",
      "confidence": "high",
      "summary": "Unused client code adds avoidable transfer, parse, and memory cost to a simple identifier form.",
      "evidence": "Lighthouse estimates 361 KiB unused JavaScript and 165 KiB unused CSS on a screen whose core UI is one text field and one primary button.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/desktop.png"
      ],
      "suggestedFix": "Use route/step-level code and style splitting so only identifier-step behavior is loaded before the user advances.",
      "effort": "large"
    },
    {
      "id": "F08",
      "pathId": "sign-in",
      "url": "https://accounts.google.com",
      "principleId": "be-discoverable",
      "principleCheckId": "title-and-description",
      "severity": "low",
      "confidence": "high",
      "summary": "The public sign-in entry has no meta description.",
      "evidence": "The DOM probe and Lighthouse both found a descriptive title but no meta[name=description].",
      "artifacts": [
        "evidence/dom.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Add a concise description of the Google Account sign-in purpose while avoiding session-specific or sensitive content.",
      "effort": "trivial"
    }
  ],
  "taskList": [
    {
      "id": "T01",
      "title": "Restore a visible keyboard focus indicator and primary main landmark",
      "priority": 1,
      "findingIds": [
        "F02"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T02",
      "title": "Split identifier-step JavaScript and CSS to remove unused payload",
      "priority": 2,
      "findingIds": [
        "F05",
        "F07"
      ],
      "guidanceId": "identify-heavy-scripts",
      "status": "open"
    },
    {
      "id": "T03",
      "title": "Improve full-variant LCP and shorten its critical dependency chain",
      "priority": 3,
      "findingIds": [
        "F03",
        "F04"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T04",
      "title": "Make sign-in honor the same dark preference as signup",
      "priority": 4,
      "findingIds": [
        "F01"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T05",
      "title": "Tighten explicit Referrer-Policy and remaining CSP eval allowance",
      "priority": 5,
      "findingIds": [
        "F06"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T06",
      "title": "Add a concise sign-in meta description",
      "priority": 6,
      "findingIds": [
        "F08"
      ],
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 5,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-27T19-14-23-318Z"
}
