31 May 2014

Let's Test 2014

Let's Test 2014 is my weirdest conference experience so far. Put that in perspective with my other two being my first ever and my first ever as a speaker and you can imagine it was a special one. So what happened?

My mission
I came to Let's Test with a question: "What is my role" (both in my current job and how I would like it to be in the future) and the mission to gather as much understanding of this as possible.

I left with more than I could ever had imagine and still feel like I've just scratched the surface. I also left with something... else, something I haven't understood yet and with a magnitude I don't even know if I can grasp. If you feel confused, welcome to my world, I have some serious thinking to do.

Welcome!
Imagine this: You step out of your cab and immediately see two people running like their lives depended on it just to hug you. And we're not talking about a soldier coming back from a war zone, we're talking about a test conference! That's how it all started. I got a jumping hug from Meike Mertsch and a two minute hug from Helena Jeret-Mäe, can't ask for a better welcome!

Talking, testing challenge, some beer, dinner, another more large scale testing challenge, more talking... You wanna know one reason why Let's Test rocks? During the testing challenge in the evening some of the most well known names in the business was mixed up with newcomers and anyone in between. The result was beautiful and I can now say I know, from own experience, that for instance Rob Sabourin is a great test lead and Jon Bach is an excellent tester.

Ohh, by the way, what's not to love about someone immediately putting a testing challenge in your hands as soon as they've introduced themselves? That's Kristjan Uba, we'll come back to him but the short story from day one was he instantly made an impression.

Key lessons
  • Peers are invaluable! Peers are invaluable!
  • Twitter builds connections that can often be transferred into "real life" connections. So testers, get a Twitter account!
  • Seeing into the minds of some of the brightest and/or most well known testers in the industry was exciting.
Workshop day
The first day started with an interesting keynote by Tim Lister. It was basically his life story in the software business and lessons he had picked up along the way. It all came together as a beautiful experience report that provided just as much inspiration as it provided actual "content".

Key Lessons (Tim)
  • Be around people ahead of you.
  • Beautiful mindset from Harlan Mills: "If I get a compiler error I go: why did I get a compiler error". Illustrates the need to not just accept mistakes/problems but to learn as much as possible from them.
  • Life is short, stop waiting and just go out and make your own career!
  • Having fun and staying curios are key driving forces and should be treated as such.
  • Right and wrong is for kids, we're grown ups (see the full spectrum of possibilities).
Next up was Rob Sabourin's tutorial. That one just felt a bit too much of a lecture for my style (have quite a bit of useful notes from it though so not saying it was bad, just that I personally was looking for more interaction) so in the afternoon I moved (after getting an okey from the organizers) to Steve Smith's second workshop; "Managing your personal board of directors". I'm glad I did as this workshop turned out to be one of the highlights during the conference!

Key lessons (Rob)
  • Domain expert != Tester, we need to understand the skills involved in being a tester.
  • Decision tables are useful both to help you understand something as well as to spawn testing ideas. Can help you discover combinations of conditions and actions not thought of.
  • 30 years of experience as a tester does not mean 30 years of learning test
  • "Is this the problem?", repeat, repeat, repeat.
  • If a session just happens to not fit you, leave and go for something else!
Steve Smith's workshop had a simple setup: We started out identifying various "directors" influencing us (e.g. Chief Financials Officer advising you to save money/make more money). After that, one of us volunteered being the star (Kristjan Uba) and the rest of us played his board of directors. I ended up being "Chief Family Officer", a perfect fit I would say. Finally, after each of us had had the opportunity to ask a wide array of questions regarding our roles, we started a board of directors meeting. The meeting agenda was to solve three challenges/questions/dilemmas Kristjan was facing. It was fun (as in "laughing hysterically" fun) and, much thanks to an awesome job by the Mind Bender (Lars Sjödahl), the meeting really felt like something coming straight out of a head. I also wanna thank Kristjan for volunteering, he did a phenomenal job as "the star" in a rather exposed position.

Key Lessons (Steve)
  • How does your personal "board of directors" look? Which directors have the most power? Which are the loudest/most quiet?
  • Tim Lister talked about the value of peers, Steve Smith made something cool happen between peers and every moment of the conference proved the value of peers. So, like a wise man wrote just one chapter ago: Peers are invaluable!
  • Good experiential workshops are sooo powerful! (at least for me)
  • The more fun I have the better I seem to learn/remember.
Steve Smith's keynote
A 150 people experiential workshop as a keynote is just as awesome as it sounds. The mission was simple, almost to a degree of silly: You are 12 people, get as many of these to simultaneously stand, for 15 seconds, on a piece of paper placed on the floor. A judge will count your score and make sure you don't cheat. You get one point for each member and the ones that don't make it will become observers. These observers aren't allowed to interact with the rest in any way for the rest of the exercise. The exercise went on for three cycles and each time the paper was folded in half. Silly right?

Well, who is forced to become an observer? Who decides this? Who's ideas are considered? How much risk are you willing to accept and who decides that? What rules can be broken, what happens if you do, who will (try to) break them and who will support/reject this? How do people react when their ideas are rejected? How much will you think about your current context (members) and how much is generic solutions? Do points really matter and will anyone question this? Will you manage to be as creative as you usually are, under time pressure? What role will you take within the group? What happens when people with "key roles" become observers?

Silly changed to mind-boggling! I ended the second day taking a long walk with Helena Jeret-Mäe spending much of that talking about how I had taken more of a leadership role in my group (or at least I felt like that) and how I in this role had lost much of my usual strengths as creative rule challenger and went into "point tunnel vision". The beauty of experiencing this in the simple exercise was I could much more clearly see the outcome and what had lead to it as very little distracted me. Thank you Steve! Thank you Helena! Thank you team!

The final debrief also helped adding to the experience and hey, as part of the debrief I've now given a keynote at Let's Test.

Panda Panda!
I've never (I think) heard anyone say a single bad word about Pradeep Soundararajan. Instead everyone seems to treat him with huge respect, so it was interesting to finally attend one of his sessions. He did not disappoint! In the session he shared the story and vision behind his company Moolya. It was an hour of inspiration, passion, admiration and self-doubt if I really do the most valuable work I can for my current company. The basic message, as I interpreted it, was: "It's all about business value and we must understand the business problems to be useful". Just like Steve's keynote, this one left me with a ton of material that will require massive post-processing before I can fully understand it. Short version: Great session and Pradeep really lived up to his reputation! Panda Panda!

Carsten
I feel a bit guilty cause I needed the second day workshop basically to zone out and reflect on what Steve and Pradeep had helped me discover but not yet understand. The 2,5 hours of sleep I had the night before might have had an impact as well. But one image that stuck with me from Carsten's workhop was how much more clear a problem, and it's solutions, became when observing a group role play the problem compared to only have it on paper or, worse, in my head.

Martin Hynie and Christin Wiedemann
During CAST 2013 Martin said he wanted to speak at a conference and I told him I thought he would make a terrific presenter. He did! Well, both he and Christin did to be precise. I wasn't thrilled about the topic but went partly thanks to a rather weak lineup seen from what I was interested in: I did not regret my choice! For me this session was not so much about the presented content as it was a perfect demonstration of passion, creativity, curiosity and a willingness to explore/experiment, not to mention awesome stuff to use when I present myself (a slide deck made up by selfies, awesome!). Inspired to say the least!

Basic outline: Over a few beers the value of games as a means to train testers came up. No one could provide any real evidence for their claims that it did improve e.g. relevant cognitive skills. Due to this Martin and Christin not only went out to look at any existing data but they gathered a group of people to experiment with (including a "unicorn"; a 25-28 years old tester who had basically no experience of video games or board games), got in contact with a university and together with scientists they conducted cognitive experiments during which brain scans were made (Martin apparently has a big brain). All and all, scientists seemed to wanna keep doing these experiments and they now have at least some indications (even though the sample group was way too small) that testing games do improve relevant cognitive skills for testers. But don't care about the outcome, focus on what Martin and Christin did just because they couldn't find enough proof! Testers everywhere, take note and be inspired!

Lightning talks
I sent an email to Johan Jonasson before the conference asking if there would be any lightning talks, as I had one ready. The answer was: "Great idea, would you mind facilitating them?". I've never facilitated anything and knowing my track record when it comes to being patient and shutting up this couldn't turn into anything but a disaster. Well, it didn't, actually it went pretty good (I think) and it was a lot of fun. Also, in case you think facilitating seems trivial, it's not! I can't even imagine the difficulty level of facilitating e.g. a controversial talk with tons of arguing. I already had great respect for facilitators like Paul Holland, Ilari and Richard Robinson but holy cow, they rock!

So takeaways from the actual talks? Nah, I was way too focused (read nervous) to remember anything. But I did have a ton of fun and got some valuable experience!

Uncertainty workshop
Day three's workshops were crazy hard to choose between (I wanted to go to all of them). In the end I opted for Fiona Charles, much thanks to a quick chat I had with her the evening before. It was an interesting workshop and an interesting group to work in (a factory schooler made it even more interesting and sparked my first of two pretty tense debates during Let's Test). Uncertainty is one of those things I've learned to embrace and I actually do much of my best work when the plan is long gone and chaos is upon me (the flip side being I create chaos more often as I suck at following a plan). So my biggest takeaways were ways to communicate uncertainty not to mention I need to actually communicate it at some point. Some new tools but main takeaway was a started thought process.

The gem!
When looking at the program, one session stood out: Quality Leader - The changing role of a software tester. This aligned perfectly with my mission (figuring out my role). I had previously just quickly shook hands with Anna Royzman so I didn't know much about her but I was in for a treat. The actual session was great, not exceptional, but definitely great and it addressed many of my thoughts. What made the session awesome thought was Anna and a guy from Ukraine...

I think many from the session perceived Andrii as a clown. He did some pretty bold comments about testers' usefulness as well as not caring to use K-cards. After the session he stayed and a debate started between the three of us, a debate that addressed a ton of things related to my question. First of all, Andrii was a really smart man! He, just like me, was trying to figure out his role and we debated for almost 2 hours meaning I have nothing to report from Jon Bach's closing keynote. It started out as mostly a 2 on 1 with me and Anna against him. After a while it turned into more of a "free for all" where we slowly reached some kind of consensus.

I won't bore you with all the details but short version is: "Is (software) tester really a good name for the role many of us claim to have based on what goes into a pretty common view of what testing is within the software business context?". The outcome for me was something like "every person is a bit of everything, the title mostly reflects what we specialize in and/or do the most, this still might not make software tester the best title for many of us if we want to avoid confusion or limiting our ability to act but tester sure describes much of what we do even though tester and software tester are most often perceived as equal in our business". Well, I wish that discussion was recorded but I'll have to rely on my memory cause I was way to worked up to take any notes.

So thank you Andrii and Anna! You're a brave man Andrii and I very much respect that and you're a brilliant quality leader Anna!

Key Lessons (safety language somewhat off)
  • Be careful about speaking degrading about developers, many of us do from time to time (not excluding myself as somewhat seen below) and that's just not helping us.
  • We aren't set roles, we each create a unique, constantly changing role, based on our skills, ambition and current company need but often call them something generic for simplicity, don't be fooled by this though.
  • The landscape is shifting and more adopt ways of working where the "traditional tester" is harder to fit.
  • Don't tell people (like developers, product owners etc.) they test cause it'll freak them out!
  • Your job is not to think about quality, your job is to make everyone think about quality.
  • What will make users say "wow!" about your product? How can you test for that?
Barefoot
Day one I was approached by Ilari asking me why I wore shoes (just a regular day at Let's Test). I gave him a couple of reasons to which he gave valid counter arguments. All and all I promised to try walking barefoot day two, I did and it worked great. I often have sore feet in the evening of a conference day and well, barefoot solved that issue. Was actually comfortable outside as well (not counting some of the gravel) so I've not put on my shoes again since day 2 despite my girlfriend threatening to never walk close to me outside. That doesn't mean I will not put on a pair of shoes soon but you'll probably find me barefoot again during future conferences. Unexpected but very much appreciated experience.

Hugs and games
Someone said to me after Let's Test last year, the conference almost seems "unprofessional". What he was talking about was all the hugging, playing games, open sponsor bar etc. To me this is what takes Let's Test to the next level! Like Klas Hallberg so cleverly puts it: Having fun is not unprofessional but doing something in a boring way when the same thing can be achieved just as efficiently in a fun way, that is unprofessional (makes more sense in Swedish and Klas is probably not the first to say this but he's my source). And like I said before, I seem to learn better when I laugh and have fun which happens a lot during Let's Test.

People
Some, to me, new testers that left an impression:

Kristjan Uba - He's smart, dedicated and creative! After hearing Helena talk highly of him I had quite high expectations and he delivered! Immediately after shaking hands he handed me a testing challenge, he handled the star role in Steve's workshop beautifully and in almost any discussion he delivered snappy, insightful answers. Oh, by the way, as CFO I just wanna let you know Kristjan, you'll make a hell of a dad!

Graham Maxfield - This guy is smart and creative (good combo once again). He had all sorts of smart ideas during Steve Smith's keynote (that we foolishly rejected) and provided a lot of good feedback during other workshops and sessions we both attended.

Anna Royzman - After giving a great presentation she handled/facilitated her, my and Andrii's discussion perfectly and added many valuable points to it. This is a name I will look for in future conference programs and I look forward to speaking to her again!

... There are more people who deserves a mention but let's just say, a lot of you made an impression!

Summary
Greatest moment during this adventure? Getting back home hugging my kids. Boring answer but couldn't be more true. Second best moment; the two welcoming hugs and anything related to seeing my super peer Helena in person again for the first time since last Let's Test. Third best moment; when the lessons from Steve Smith's keynote just suddenly started to sink in.

Left to do? Massive post-processing! That "something" is still out of reach and there's more to many of the experiences I had throughout the conference that I just haven't figured out yet.

More substantial stuff to do? Put what I want my current and future role to look like on paper and try using decision tables on the business rules we have in the product I'm currently testing to find potential gaps/missed tests.

See you all soon (I hope) and thank you!

13 April 2014

SWET 7, peer conference on test coaching

SWET 7 (Swedish Workshop on Exploratory Testing, a software testing peer conference) has just come to an end and here is the promised summary and lessons learned from the event. The topic this time was "test coaching".

Don't worry Sweden

First of all, knowing that SWET 6 had few attendees, SWET 7 was almost cancelled and the group that finally signed up had far less experience than groups from previous iterations; you might be concerned about where context driven testing is heading in Sweden. Well, don't! There's a ridiculously talented group of up-and-coming testers. I feel fortunate to have met some of them already!

The venue

Villa Mälargården was a great venue. We had the conference center all for ourselves, it was well set up and the chef's passion (and skill) was a perfect fit, both for our palates as well as for a conference with passion being a common denominator. Thank you Michael Albrecht for doing all the arrangements, you did an awesome job!

Intro

Before the experience reports (which I will call sessions by the way) we went through practical information like how to use K-cards, what goals we had as well as making a check-in. Interesting this time was James emphasized stating possible distractions during the check-in. In at least two cases this definitely provided valuable information; Michael telling us about illness at home which he later had to, very abruptly, leave to attend, as well as Annie telling us about her migraine and how that could affect her which made me better understand her reaction when I tried to start a couple of discussions.

Before starting, James also showed and explained his view on coaching, a great way to ensure we all had a common ground to at least refer back to as well as for many of us to better understand what coaching can be.

Session 1, Michael Albrecht

Michael Albrecht started by speaking about a consulting job where several groups within a company needed coaching and training to change their testing process.

Takeaways
  • Set the goals with everyone involved (e.g. manager ordering and participants), follow up these goals with the same group.
  • There are many aspects of coaching to look at (and improve); e.g. facilitation, set up/preparations, actual questions/exercises, follow up, session quality evaluation etc. 
  • Coaching is not necessarily a one on one activity.
  • Propose a radical idea and ask why it wouldn't be a possible substitute what's currently implemented, to force people into thinking differently/see beyond what exists.

Session 2, Erik Brickarp

I want to discuss this a little further with Helena Jeret-Mäe, whom I share this experience with, before posting. But it revolved around Transpection Tuesdays, how, and why, we've integrated more and more coaching into them, the format we use and lessons learned.

Session 3, Liza Ivinskaia

Liza spoke about her first test coaching experience and lessons learned from this.

Takeaways
  • Survey's can be used as a quick way of reaching out to a lot of people for some simpler coaching and/or as valuable input to coaching/coaching decisions (e.g. who to focus on).
  • Spend time with the people you are about to coach to make sure you understand their context
  • Make sure you focus not just on what's wrong but also point out what people are doing right
  • Presenter technique: Draw a big mind map (e.g. on a whiteboard) to help audience "navigate" your presentation. To enhance, create or highlight the connections as you present.
  • "Don't look at it as a problem, look at it as a challenge"
  • Everyone has coaching experience. You've most likely helped a friend/sibling/child/partner in a challenging situation or tried to help someone understand something in school for instance. Some of that is likely coaching.

Lightning talks

Annie Rydholm
Talked about her coaching sessions with Carsten Feilberg and how these have helped her.
  • Find out the missing "because" by asking "why"
David Högberg
Talked about his failed attempt to teach a student taking notes and lessons from that.
  • Taking notes is a vital skill we need to practice
  • We all take notes differently, teaching someone "their style" is hard
  • Take notes throughout the day and at the end of the day, collect them in a mind map
Björn Kinell
Talked about a mistake when coaching, where he had been too impatient to let the coachee figure out an answer for himself.
  • It's easy to get impatient and just give someone your answers. Coaching requires patience.
Amanda Johansson
Talked about how she basically made herself obsolete in a team.
  • Making yourself obsolete in a team is an interesting goal to get you to coach and help people take their responsibility in building quality in as well as finding bugs.
Meike Mertsch
Talked about her coaching session with James Bach and how what she learned unexpectedly became valuable much later.
  • You never know when and what experiences/knowledge will come in handy
  • Explaining exactly what you do provides insight for yourself

Lesson: "Innocent girls"

I heard at least three times, by different testers and in different settings, "I was surprised this innocent girl was so tough". I think that is an indication we should stop assuming innocent girl (or well, any girl) equals weak/fragile. My own experience in life is boys might be better at hiding/faking but we're not tougher.

Lesson: Admitting being human

I heard David Högberg in several open seasons, as well as in between sessions say things like "did you admit?", "it's okey to be human", "admitting can build trust" etc. He definitely hammered in a valuable takeaway from SWET: There is nothing wrong with being human, in fact it often helps strengthen relationships and build trust!

The mentor

I want to give a special thanks to James Bach. I had tremendous respect for the man who help me find my way into testing, already before SWET 7. But after seeing him work with all these rather fresh participants (including myself) he has raised my admiration even more. He inspired, he encouraged, he supported, he taught, he lead by example all and all, he did everything to make sure we all got the best out of every single participant, rookie or veteran (or at least that's my view). That on its own was a great and valuable experience for me in community greeting and group mentoring. Thank you James!

Summary

If you look closer you likely know/have experienced much more coaching than you think.

... and there are plenty of up-and-coming testers to keep an eye on!

Participants

These are the people who taught me the lessons shared in this post; all being curious, brave and smart testers, worth listening to.

Amanda Johansson
Annie Rydholm
Björn Kinell
David Högberg
Liza Ivinskaia
Mikael Ulander

Thank you!

28 March 2014

What happens if...

Intro

The quality categorization below derives from the work of James Bach / the Test Eye.

What happens if...

... we don't care about security

Internet is playing grounds for brilliant people who like to figure out how to get passed applications' moats or bring them down. Leaked credit card numbers, leaked personal or other sensitive information, leaked passwords, malware on the customers' computers, defaced company websites and services unavailable, all due to security shortcomings in software happens daily. This can lead to lawsuits, loss of customers, the company losing a lot of money or, worst case, bankruptcy.

Even if your application is not using network communication, no one will care the day someone hacks/steals a computer with (or even worse, due to) your app and get their hands on sensitive information. Also few (read no) customers will care if it was a third party product that failed or not. The "we didn't build it so we don't have to test it" mentality is simply not productive.

... we don't care about charisma

The amount of applications is huge and that has changed how we pick our preferred ones. Now you can install an application, look at it, dislike its design (not professional, fresh, modern, elegant, beautiful, simple, safe... looking enough) and quickly move on to the next, without even "using it". I repeat, you can lose customers simply because your product doesn't look like the product it is!

"It's just an [pick your type of application], no one will care about how it looks" is rarely true anymore. Also remember charisma is not just "cool design features", it can mean anything from simple/elegant to looking robust/secure (we do judge an application by its cover).

... we don't care about usability

Just because someone initially choose your application doesn't mean they'll stick with it. One annoying extra step or interrupt in their work flow might be enough to trigger an "uninstall and move on". Even if customers are tolerant and the competition isn't that fierce, too bad usability can render key features useless (thus wasted money developing).

Also, usability problems might add a lot of costs for customer support as they'll have to spend time explaining things to the customers that the product should make obvious.

One big enemy to usability in my experience is programmer shortcuts. "Well the framework doesn't really support dropdowns so we had to go with five links instead". Beware of just accepting this, usually technology isn't the limiting factor even though it might feel like that when in the middle of things (my experience as a tester and a programmer).

... we don't care about robustness

A crash or loss of service, even for a brief moment, can be enough to get your application uninstalled. Also, downtime can be extremely costly for customers and, worst case, a customer may not just stop using the product but also demand compensation. No matter what, common/long down times and other robustness problems can quickly hurt the company's/product's reputation. Remember, time is money.

One mistake often done is many testers just open the application, do their tests and close it down/reset. Customers on the other hand often work for hours or even weeks without closing stuff down, can your application handle that? Are you sure?

... we don't care about performance

We are an inpatient, stressed society, if the loading of a webpage/application/service is not quick enough we'll simply not wait to see if the result is pleasing or not. Slow apps are quickly gone.

Once again some experience: If a function is really slow and can't be tweaked to go faster (e.g. a complex algorithm), maybe it shouldn't be in the product at all even though it seems valuable. Or the algorithm should be simplified or changed to become some kind of background job. All this to avoid frustrated users (if a function is in the product it's expected to work and work well!).

... we don't care about compatibility

I happen to like my browser. If you don't support that browser (support means, work better than the competitors, not "well, it does but...") I won't even consider you an option... And by the way, the world is going mobile and Windows is no longer "the only" operating system on the market.

So what happens if you "support Windows, iOS and Linux" but only Windows is actually tested and in reality your product hasn't even started on Linux since three versions back? Well, a customer could demand money back, which adds administrative costs, or compensation for lost money installing/upgrading. A company buying your product might ditch you on all platforms due to distrust or you might be headlining a lot more blogs than you wished for (or rather, not for the reasons you wished for). Simply put, it would be considered lying and lying is rarely appreciated. Also shortening the list of compatible systems due to uncertainty (due to lakc of testing) is of course a deal breaker for potential customers on those systems.

... we don't care about IT-ability

Every install/reinstall and update/upgrade (or lack thereof) is a potential source of frustration and incentive to uninstall. Make sure you avoid any unnecessary friction or even a great application may find itself deleted.

Also in bigger companies there's likely someone maintaining/supporting your product internally. Those guys tend to have quite a bit of saying when it comes to selecting applications, so you don't want your application/brand/company to be on their black list. "It seems like a great product but out IT department says it's impossible to have in our software infrastructure".

Make time

We all have limited resources and have to prioritize. What I'm trying to explain above is not "we need to double the amount of testers" but rather "we need to prioritize testing and make sure the right people focus on the right stuff".

Of course a big part of this is arguing for the importance of quality, not just for the functions themselves. I hope the list above can aid you in this.

Programmers

Many things are better tested by programmers (knowledge about what has been implemented and ability to manipulate code for targeted, temporary testability) and no matter what, a simple bug caught by a programmer and solved immediately is a lot less time consuming than if a tester finds it, has to report it, may be stopped until it's fixed/application rebuilt, the programmer has to stop and context switching likely happens for both parties. Don't underestimate the saved cost of programmers that test their own code well and (almost) always hands over high quality stuff!

Product owners

My product owner does an awesome testing job! What he does is simply making sure what he gets is what he asked for and since he wrote the requirement/specification/user story that lead to the code he knows what he actually meant rather than what can be interpreted from the text (meaning is often lost/changed when thoughts are translated to written language). His job saves me (tester) a lot of time figuring out if he actually means what I interpret he means.

Domain experts

In my current company, much of the technical complexity of our main product is in the handling of security cameras. In this area I'm glad we have a great domain expert who both tests and technically supports my testing when needed. This once again saves me time to focus specifically on e.g. security in this area, which I have more knowledge about.

Combined effort

I (let's hope so at least) have a broader knowledge about testing and potential ways to put the system in risk of failing. However, programmers, product owners, domain experts, graphical designers/interaction designers etc. know their own domains much better. Teaming up when testing is rarely a bad idea as it's a way for both parties to learn from each other and better utilize the strengths of each person (e.g. the domain expert shows various ways to feed data into the system while the tester suggests various kinds of data to try).

Not everything can be tested in isolation

Testing "what has just been developed" is not enough (which some Scrum fans seems to find provoking). Often when testing we simply need to zoom out, for several reasons:
  • E.g. Consistency, flow (as a usability aspect) and data flow (as in how data is transferred through the product) requires you too look at the whole, or a big part of the, product.
  • We learn new things all the time which also concerns old functionality and a difference between programming and testing is testers don't need to make expensive refactoring to apply new knowledge on what already exists.
  • We test how new functionality integrates with old, and sometimes those new changes also affect how old functionality integrates with other old functionality.
  • Security, performance, robustness etc. is not always efficient to test for a specific function, instead you need regular sessions to test it for all functionality in a sprint, from the last month or, once again, the whole product.
  • You don't always know what existing parts new functionality impacts and programmers are not always aware of what might, even on a code level, affect existing functionality (and if they are it's not necessarily communicated). Thus we need to simply "look over the whole thing" or look at a more general area every once in a while.
  • ... and when looking at old functionality we inevitably find issues we've missed before due to new tests, new knowledge, changed context etc.
What sums this up I think is: A lot of what's needed to test is not efficient/possible to test isolated. It sure sucks to correct one year old bugs as a programmer, but you need to understand: Testing is not programming nor is it "extended unit tests". To a tester, modules interact and form something together, they aren't isolated blocks with api:s... Oh, and by the way testers and programmers, never expect two sides to have interpreted an api-spec the same way.

A way to solve this in e.g. Scrum is to add stories aimed towards a kind of testing rather than a functionality to test e.g. "Security survey" or "User tests/usability" and if needed, compensate this with less testing of each specific function developed (which requires more testing work, as well as better communicated testing work, by programmers and others). Another solution is to add "system test" periods before release where the product as a whole is tested with not too much regard to what has just been developed.

Let's make this a requirement

Some of this can sure be requirements and/or added to a specification, and I'm not saying it doesn't help, because I think having people aware of e.g. the quality characteristics, writing the requirements/specifications is great. But a specification will never include everything simply because even if you have all your experts doing their best, a product changes from the spec, reality is never as problem free as planning and the context (users, market windows, staff etc.) will change in one way or another as the project progress.

So, yes, I think considering quality characteristics when writing specification/requirements is great but, no, it will sure not cover everything.

Customers never ask for these things!

True, in many cases they don't explicitly ask for things like security and usability. But it's not because they don't care, it's because they simply assume it will be there and if you do deliver and don't get any feedback about bad quality, do all your customers come back? Do they recommend you to friends and business colleagues, creating new business opportunities?

And sure, if you care less about security you might save some money and still never end up in trouble. But if that chance taking doesn't go as planned it might, as already said, put you out of business. So make sure you understand the risks really well before taking such a chance.

Summary

Customers will not stick to your products (except in rare cases, and you're not one of them) and your reputation will not be impressive if your products have low quality. And what great quality means can never be fully predicted or documented so let's not kid ourselves and say checking based on the specification is enough.

Make time by explaining consequences (thus getting the right attention), educate the people around you and making sure everyone do their share of the testing job!

Good luck!

20 March 2014

Lessons from testing my own code

The last 5 months I've spent almost every free minute developing a website for my kids' preschool. This blog post is devoted to observations done when testing my own code while creating it. Notice many of these are highly subjective and biased but if nothing else, I hope they can raise some interesting questions.



Observation 1: Finish developing (mentally) before testing
I found it hard to do good testing when I was in the middle of developing something. My brain seemed to be more focused on how to solve the next problem rather than critically question what existed.

On the other hand, when a function was done (both function and done is ambiguous, the key though is the feeling of being able to move on) I found it much easier to change my focus to "how can I improve this?" or "what are the problems with my solution?". I often setup a few tasks, completed those and then sat down and committed to make what already existed (including older stuff) awesome, before moving on planning the next tasks.

Lesson: Finish up mentally, before doing non-superficial testing.

Observation 2: Some testing was easier to do than other
Testing I do rather statically (e.g. following checklists, like OWASP checklist, or strict procedures) worked better than more creative or "subjective" testing (no right answer, more about judgment/opinion) compared to when I work with other people's products. In the latter case I often found it much harder to see the alternatives on how to solve problems and of course what I created was intuitive, right? .)

Two things I found useful when doing less static testing was scenarios and roles. When examining the product trying to observe it from the perspective of a certain user or had a certain task to perform I could better defocus and question the decisions I had already done... a bit like I was no longer responsible for the code "I'm the news editor now, not the developer".

Lesson: Scenarios and roles, I think, helped me fight "my solution is perfect" bias.

Lessons: I sometimes find checklists thought limiting when testing others' products but it did help to observe my own more critically/objectively.

Observation 3: Only testing new functionality was not as efficient
I discovered my "examine old functionality" sessions seemed to reveal more bugs, both in number and severity, compared to sessions focused on new and specific functionality. A few reasons for this, I think, is:
  1. I learned new things about the product/environment that inspired new tests and applying these to existing functionality often revealed bugs I had previously missed.
  2. I got some more distance to the functions making it easier to look at them as if I were a regular user, not the creator.
  3. I found my affection for the specific functionality (wanting my product to work) lowered over time. At some point it was like "I don't want this to work perfectly just to show to myself that I've gotten better as a programmer".
  4. Naturally I found it much easier to observe inconsistencies and problems with flows when looking at the product as a whole, not at a single function.
  5. I found it much more motivating to "play around" with the whole product and following my own energy seemed to make me a better tester than if I tried to "force myself" to test a specific part.
Lesson: Instead of spending all my time testing new functionality, spending a short session on new functionality and then add longer (or several shorter) general sessions every once in a while was a more effective way for me to spend my testing time.

Notice, I've observed a similar pattern at my job. Although, when being a tester in that context I also have to consider the fact that new functionality will be delivered to customers so I can't "save testing for later" as much and as a programmer I do prefer to work with code I've recently written. Still, scheduling time to just generally go over the whole product has often proved to be a valuable practice for me even when there's a lot of new functionality to look into!

Observation 4: Testing my own code really helped me think about testability
I think any company would benefit from pairing a programmer with a tester, not so much for the tester to get quick feedback on bugs or help with how some functionality is meant to work, but for the programmer to see what parts are hard to observe or control (read: test). Turning it around, as a tester it has been interesting to play with what's actually possible to achieve. Also, when I have the code in front of me I noticed I do a lot of things I would never had done on a "regular testing project", like disable functionality to enable better/quicker testing of back end stuff and making printouts I would normally "have to live without".

Testability, and especially ways to achieve/improve it, has been one of the most interesting lessons learned during this project, both from the perspective of me being a programmer and of me being a tester!

Lesson: Testers benefits from observing programmers/program as it helps understand what's possible and programmers benefit from observing testers/test as it helps understanding what makes a product testable (not to mention what strange ways users can "misuse" their creation .)

Observation 5: Programmers do a lot of testing better than testers
I found knowledge and control over the code invaluable, especially when testing "functional correctness":
  • I can manipulate code as I test
    e.g. remove client side form validation to quicker test server side validation
  • I know about technical solutions affecting testing
    e.g. due to a technical limitation we need to handle two seemingly identical requests differently
  • I know about the full implemented feature set, including "bonus functionality"
    e.g. no one requested drag and drop but it came with the framework, still it has to work
  • I know about the code quality/problems
    e.g. the user form handler is very messy, give it some extra testing attention
Communication can help much of this but it's hard as a programmer to know what a tester needs, it's hard as a tester to know what you need when you don't know what's available and it's hard to be fully aware of what you actually take into consideration when testing no matter if you're a programmer or a tester.

As the programmer you're of course likely to agree with your solution and test for the things you've already built protection against, simply because those are the problems/scenarios you're familiar with/have identified. Thus a second, third and forth opinion is important but don't underestimate the awesome bulk of unique knowledge the programmer possesses!

Lesson: Programmers testing their own code is extremely important, much of the testing they do will not be done by a tester and/or as efficiently.

Lesson: Pairing the programmer with a tester/test coach is probably awesome (in fact, I think it is).

Observation 6: Mixing up customer value and technical practicality
"That checkbox is not vertically aligned but I know it's really messy to fix so it's not important".

This kind of mind traps I found hard to fight against, even though I'm normally a tester.

The only real protection against it, that I found, was to force myself to solve any problem I found. In the beginning it was time consuming and demotivating (slowed the progress quite a bit) but soon I noticed it greatly improved my "base quality" as many of the problems were reoccurring until I dig in and learned how to solve them.

Lesson: Extremely low tolerance to faults really helps you improve! Of course I've had to let a few problems slide but I've always given them significant time, weighing the options/workarounds and tried to find consensus that a problem is impossible/not worth solving within the professional community. The stuff inconvenient to solve, technically, often provided me the big programmer "a-ha moments" when solved.

Summary
Forcing programmers to test their own code more will not make testers obsolete as well as adding more testers won't solve the problem where programmers aren't given enough time to test their code. Both are important and both add unique elements to testing!

I think programmers can severely affect their ability to test by how they behave/plan. For me, testing intensively while in development and trying to make "objective judgments", didn't work very well. Checklists and waiting with non-superficial testing until "mentally done", seemed to greatly improve my ability to test my own code.

So can programmers test their own code?
Yes, and they should but not alone for best result, that's my experience!

Agree?

15 February 2014

The ideal testing project

To get to the good stuff quickly without much explanation of why and how this list exists, jump to the "How to use the list" chapter.

What?
This "exercise" is rather simple:
Describe an ideal testing project

So first off, there's a lot of ambiguity in that statement. Ideal? To who? In what context? Testing project? Means what? What are the boundaries? Valid in what context?

Exactly what this means is not so important, and I'll explain why in the next chapter. But to give you a good enough idea to understand this post: "Using the experience you have, list the actions/rituals/behaviors etc. you think would make for the best possible testing". That still leaves you with a ton of ambiguity but hopefully you agree that's not the bigger issue here when I explain...

Why?
I often find when I try to look at my current context and how to improve it, I limit my thinking. By trying to list "ideal attributes" I can look at each of them and say: "do we do this today, to what extent, is it ideal in our context and how would the ideal scenario look in my specific context". Those questions, for me, tend to break that mental limitation and it's, once again for me, especially useful to see those, individually insignificant changes, that together really make for a huge improvement.

How?
Feel free to skip to the next chapter if you don't care about how this list was created.

I've tried this "exercise" three times. First time was in a workshop at Securitas Direct/Verisure on testability. One question was: "how can we improve our testability" and my brilliant colleague Niklas Grönberg, suggested we, instead of thinking about what we had, should think about how we wish things were. It generated several great ideas and everyone, no matter of current context, could add to the list.

Soon after I suggested trying the same thing on a Transpection Tuesday with Helena Jeret Mäe but focus on the project in general. We spent roughly three hours adding to the list and while doing it sharing ideas on how this could be achieved in our respective contexts.

Finally I tried the idea as a group exercise at EAST. In this case 8-10 people shouted out ideas that were discussed/further described and then added to lists on a whiteboard. When we were done everyone got a few minutes to look at the lists (we filled two whiteboards) and in an open forum we shared our key takeaways. I'll add a few notes from that at the end.

To support/guide the thinking a bit I added a few categories both when running it as an exercise on EAST and with Helena. This also (I think) helped explain what I was looking for. You will see a similar setup in this post.

How to use the list?
This is not attributes of an ideal project, it's attributes that to someone seemed ideal in some, to that person, relevant context. Thus you can't just take an item from the list and say: "well how do we achieve this". Instead I suggest you look at an idea and ask yourself, as described before:
  • Is this relevant to my context?
  • Why/why not?
  • Do we do this today?
  • To what extent?
  • How would this ideally work in my unique context?
Important: I do not agree with all the items below. But I wanted to add everything I picked up as it was mentioned by some skilled tester as ideal in a context (s)he could relate to and thus potentially helpful to someone reading this.

Also notice some of the items are in conflict with each other. Once again something might be valid in one context or aspect of a context while something else is true in a different context.

General
  • Clear boundaries/limitations throughout the whole project
    Time, resources etc. also knowledge about why it's limited and why the limit is set to what it is
  • Clear and well communicated goals and milestones
    Iteratively challenged throughout the whole project
  • Knowledge about users and buyers
    In bigger companies the buyer and user can be two very different groups
  • Access (throughout the whole project) to users and buyers
  • Knowledge about stakeholder
  • Knowledge about market (e.g. competitors and market windows)
  • Manageable amount of changes and quickly informed about these
  • No hidden agendas
  • A product you...
    ... like to work with
    ... find meaningful
    ... believe in
    ... want
  • Balanced work flow
  • Time to experiment
    Including product, working methods, techniques and tools
  • Being included and listened to
    E.g. invited to meetings
  • See the product being used
    And see that it matters to the customer
  • Low level of (boring) repetition
  • Some "hype factor"
  • Test ideas generated from day one
  • The agreed level of quality and customer focus is not lowered throughout the project
  • Everyone strives to achieve better results when agreed upon
    Includes everything from quality/scope to efficiency/cost/time
  • One focus at a time (no multitasking)
  • Testing being a respected and prioritized activity that everyone cares about
Start of project and general
  • Involved when it's a problem to solve not a solution to implement
  • Well communicated why (why it's a problem, why it's important)
    This includes being presented the real why, not the "official" why.
  • Kick off to meet, bond and discuss
  • Being listened to regarding testing issues and general risks we see
  • Everyone genuinely agrees upon what to build and why
    Also includes for instance salespeople and maintenance/support
Team
  • Motivated
  • Mixed group of expertise/experience
  • Skilled to do the job
  • A willingness to get better, both individually and as a team
  • Problems and concerns are shared
  • Having fun together!
  • Everyone is listened to
  • Respect for each other
  • Working well together
  • Domain knowledge
  • Clear, effective communication
Implementation discussions
  • Quality characteristics are discussed and clearly prioritized.
    This is an iterative process
    Stakeholders, customers, testers, programmers should be involved
    Most important is to state what is not that prioritized
  • All solutions should have a known "why"
  • Testable paper mocks or similar
  • Customer feedback on these mocks, communicated to the testers
  • Testability and relevant quality characteristics issues should be discussed as part of each solution
  • Always 3 options to consider (<- much debate to "at least", "roughly" or "exactly" three)
  • Key areas and lower prioritized areas are discussed and agreed upon
Test planning and strategy
  • Risks collected from testers, customers, stakeholders etc. discussed and prioritized
  • Discussions on how to test with programmers involved
  • Test process revisited and tweaked to fit current context
    E.g. what documentation, for who and why. When/how to involve programmers etc.
  • Testers, programmers, customers and stakeholders read, understand and commit to the strategy
  • Strategy is continuously revisited throughout the whole project
Testing / Developing
  • Feedback on errors (email, popup), rather than scanning a log
    (could be achieved with a tool scanning a log of course)
  • Being able to start a flow at any relevant position
    (e.g. in the middle of a setup wizard)
  • Being able to extract any relevant information from the product
  • Early first delivery and frequent deliveries throughout the whole project
  • Attention on bugs, not just new functionality
  • Programmers being aware of and taking relevant quality characteristics into account when developing
  • High quality code delivered
    Helped by code reviews, static code analysis, TDD/BDD, quick manual sanity tests, (automated) smoketests, skilled programmers taking pride in delivering great quality code etc.
  • Testers pairing up with programmers, customers, stakeholders when testing
  • No distance between programmers and testers (and stakeholders)
  • No delays from code written to code up and running in the test environment
  • All target systems/platforms/versions used by customers available to testers
  • Regularly time to test with and speak to customers
  • Why should be well explained and motivated for every demanded administrational action
    E.g. documentation and reporting
  • Iterative reflection on processes and tools that everyone is engage in, genuinely want to engage in and given time to act upon.
  • Progress is celebrated!
  • Everyone is having fun!
  • Testers are not the only ones testing
    Stakeholders, programmers and customers test the product as well, both while pairing with testers and alone.
  • Mistakes being embraced
    Admitting mistakes should never lead to shame, everyone naturally want to share mistakes done rather than keep them a secret.
  • Lots of questions asked and people taking time to answer questions
  • Amazing tools that support the desired process, not dictating it
  • Short optimized feedback loops
    Includes communication
  • Testers focusing on testing not checking
  • No stupid measurements and KPIs
  • Stakeholders accept relevant information, no extra translation necessary
    Much of this is probably better explained as both parties striving to understand each other and to learn speaking each other's language.
  • Team! Not individuals
  • Continuously challenging goals and milestones as more is learned about the product
  • Stakeholders clearly explaining why they chose to ignore certain risks communicated by testers
Finishing up
  • Customers blown away
  • World peace and end of world hunger
  • Time to reflect
    ... and result of reflection being used as input for the next project
  • Clear finish
  • Getting the time to feel proud
  • Being shown appreciation from managers, customers and stakeholders
  • Lessons learned shared between various projects (if projects are run in parallel with different testers)
Some reflections from the wrap up during EAST
As I said before we ended the exercise during EAST with sharing lessons and ideas to bring back to our respective contexts. One observation was most of them related to communication like ideas to improve communication or information someone should ask for. Another was very different kinds of lessons were described but everyone seemed to identify something relevant to their context that they might not had thought about before, or now thought about in a different way, which to me indicates that the list can be valuable to most testers.

Feel free to share your own additions as comments below, I will gladly add them to the list!

And to all of you who've added to this list already thank you! This is not my work, it's our work! Actually I even tried to shut up during EAST! (which went... okey I guess, at least compared to how it usually ends up)

Thank you for reading!

15 January 2014

So when will you be done?

Project manager: How's it going?
Tester: Right now we see a lot of problems in the export functionality but import seems a lot more stable than last week
Project manager: Okey, so when will you be done?

The next time you get this question, answer:

I can be done tomorrow, or next week, or in September if you want, when I'm done (testing) is irrelevant, what's relevant is how confident you want to be with the product when it's released.

When are we "done"?
We don't really decide when we're done, that's up to the people delivering something for us to test (developers, designers, people responsible for builds etc.) and the people deciding when a product is ready for the market (let's call that person(s) a project manager in this post). How is that?

First of all we don't create quality, developers etc. do, we only make a quality assessment. That means we don't control when the "desired level of quality" is reached, that's once again up to developers etc.

Second of all we don't decide the "desired level of quality" itself, that's up to people with better knowledge of the market, internal business situation etc., the person(s) I call the project managers in this post.

And finally we don't know about the actual level of quality in a product, we only try to make an, as good as possible, assessment. This poses another problem as we have to try and communicate the level of quality we think the product is at and communicate this in a way so that the person actually deciding if the quality is good enough (once again, the project manager) can take an as good decision as possible. This is typically where risk comes in: "If we release now, here are the risks I see, it's your call if we can live with those or not" and the last part, if we can live with those or not, that could be translated to "if I'm done or not".

Problem, QA
Now there are a couple of problems.

First, why doesn't testers then decide if we should release or not? After all, we have the most detailed view of the system? Well, we call that quality assurance (QA) and there's several reason why I highly dislike that concept: One is we don't know the business well enough! There might be a market window we can't miss or that will be very costly to miss, we might need more money now to make crucial investments and so on. Long story short: Quality, no matter if we like it or not, is far from the only thing deciding when a product is ready to release. And also, I strongly believe QA could, or rather would, hamper our ability to stay critical and "test minded" as we would be biased to fulfill other goals (like the wish/pressure to release).

Problem, estimates
Second I know someone is saying: "But as a project manager I can't just have a huge question mark in my time plan, I need an estimate of when we think we can release!". Sure, in my team test is currently not estimated (we do have some days between code freeze and release but they are set, and same for every sprint), instead I just report if I see problems a long the way that I think jeopardize our ability to release when planned (risk). That's one way to do it.

At my previous work we did specific estimates for testing, nothing wrong in that, but it doesn't change anything. Once again, that's for someone to be able to make a plan. In the middle of everything though, the time is suddenly irrelevant and we can only hope our assessment of how long it will take developers etc. to reach a perceived level of quality where the project manager feels confident to release, is anywhere near reality.

... Oh, and test cases, or rather pass-fail/pass-total ratios, don't change any of this, it's only a way to pretend you have control over something you don't control.

Summary
Never ask a tester when (s)he will be done, ask about current risks and what consequences (s)he thinks come with those risks.

As a tester, don't provide a "time left", it's not up to you when you're done. But do help the person asking to figure out an estimate for themselves to when the product/feature might be ready by presenting known problems, how deep areas are covered and other relevant information.

Credit
This comes from a Transpection Tuesday with Helena Jeret-Mäe.

Clarification
I received a comment and want to add a clarification: At my current work, this is not a problem and has never been (at least I haven't come in contact with it)... but it has been earlier in my career.

17 November 2013

Rules can't stop me!


I love this picture! I think it brilliantly illustrates an important creative skill testers need: the ability to see beyond and challenge existing rules.

... And it got me thinking; what other ways can I think of that would/could fool a genie. Here's a quick list, I would love to hear your creative solutions as well:


  • Wish for the ability to grant wishes
  • Wish for every lamp you touch to contain a genie
  • Wish that the genie will keep forgetting that it has already granted you a wish
  • Wish that the genie stopped having/followed rules (seems dangerous though!)
  • Wish that no wish you make counts towards the limit
  • Wish there would pop out a different genie every time you rubbed the lamp
  • Find out a way to express all your wishes as one wish
  • Wish there was a much higher limit than 3
  • Wish that 3 changed meaning to unlimited (consequences once again)
  • Wish "I want to change into a new but identical person" as your third and final wish
  • Wish the genie inscrutiating pain whenever he decides to decline you a wish.
  • Wish... now it's your turn!

16 October 2013

How many holes are in this shirt?


Saw this picture on Facebook and couldn't resist to add to the long stream of comments saying 6, 7, 8, .. holes:

First: Definition of a hole? You have separations between threads in the fabric for instance, do they count?

Second: Even with a definition it's impossible to say only based on that picture since you can't see holes on the back of the shirt, covered by the part of the front that is not ripped open. For instance, you can see right through so there must be holes on the back but is there two different holes or one big hole?

For the spirit of the question: At minimum zero, assuming the yellow parts are only clever design and the whole back is gone so that holes for arm, neck etc. are not really holes anymore... hard to call it shirt in that case tough.

... so what's the minimum requirement for it to be called a shirt?

You could of course continue and question things like if that's a shirt or a drawing, that a two dimensional object in general would work poorly as a shirt if you don't live in Flat Land and so on.

I wanted to share this just as an example of how many assumptions we make when giving a simple answer even to a simple question. I leave it to you to make something out of it but a start could be to look critically at simple, especially "universal", answers you get or give. What's required for them to be true and are you sure that reflects reality?

13 October 2013

Arguing for Exploratory Testing, part 2, Reuse

Intro
You can read a bit more about this series in the first post:
Arguing for Exploratory Testing, part 1, Traceability

The topic for our second Transpection Tuesday on "Arguing for Exploratory Testing" was Reuse.

We finished with two open questions:
Can we ensure we actually repeat the exact same test a second time?
How do you actually achieve reuse in exploratory testing (when it is desired)?

Reasons to reuse tests
First we tried to state reasons someone would want to reuse test cases:
  • Save time during test design
  • Functionality is changed and we want to rerun the full/part of the test scope
  • We want to verify a (bug) fix
Preconceptions
Looking at reasons quickly led us to some preconceptions which became the topic for a big portion of the session:
  • Effort = Value
  • Equal execution = Equal value
  • Our scope is (almost) complete
  • Reuse = free testing
  • A monkey can run a test case
Preconception: Effort = ValueSince we've invested so much time (as well as money and prestige) in writing test cases they must be worth more than a single execution.
  • Even if presented with clear evidence we may reject it to defend out judgement
  • We may overestimate what a test case is useful for (we want to get the most out of our work)
  • It's my work, criticize it and you criticize me not the work! (common and unfortunate misconception)
It takes a lot of self-esteem to say: "Yeah I screwed up, could you help me?", especially in an environment where mistakes are not accepted. Notice many of the "so how can we make the most of this mistake" still communicates "so you made a mistake, now you'll have to suffer for it by telling us why you are a failure". It takes a lot of work to change this.

Preconception: Equal execution = Equal value
Let's say we execute the exact same steps in a scripted and an exploratory way, wouldn't that be two identical tests? We believe not.
  1. Your goal differs. With test cases your goal is to finish as many test cases as possible (progress). That's how you measure "how much testing you were able to perform". In exploratory testing you are judged based on the information you provide thus you should be more incline to spend a few extra minutes observing/following something up even when it's not "part of your test".
  2. Your focus differs. When you have a script you have to focus on following that script. In exploratory testing your goal is typically to find new leads to base the next test on. That means in one case your focus is on the product and in the other on an artifact. Think about the Invisible Gorilla experiment.
  3. Scripts easier bias you not to observe. In a script you typically have verification steps e.g. "verify X=5". We believe this could bias you to not be as observant during the other steps: "this is just setup so nothing should happen that concerns me".
Preconception: Our scope is (almost) complete
We know a feature's boundaries (specifications, requirements) so when we set the scope for testing we can, and usually will, cover almost the entire feature.
  • We can't know the boundaries of a feature:
    • We will impact and use other components not "part of the feature" e.g. other code in the application, the operating system, surrounding applications, third party plugins, hardware, hardware states etc.
    • We interpret planning documents differently, adding parts, discover things we couldn't had anticipated, correct mistakes or interpret something differently than intended by the author and/or interpreted by the tester.
  • We can (almost) always tweak a test a little bit (e.g. change input data or timing). But testing all combinations (we recognize) is way too expensive. Also there are usually so many ways an application can be misused (intentionally or unintentionally) that even with a ton of creativity we can't figure out them all (ask any security expert .)
So our scope is basically a few small dots on a big canvas rather than a well colored map. But those dots are (hopefully) carefully selected to protect us from the greatest risks we can anticipate. Still, they are only dots.
As testers we easily support the preconception of full coverage by answering questions like "do we cover this feature now?", "is all testing done?" etc. with a simple "yes" or "almost". The more accurate answer would be "we cover the most important risks we identified limited by our current knowledge, time available and other constraints", but that answer is not very manager friendly which leads us to...

There is a general lack of knowledge and understanding of testing in most organizations. And we decided to stop there since that was a way too big question to tackle at the point we got there. But it's an important questions so please take a moment and think about it for yourself: How can you improve understanding and interest for test in your organization?

A final note. Since we only cover a small part, reusing a test scope will not help us catch the bugs we missed the first time. How big of a problem that is differs but repeat a few times and it may scale up in a nasty way.

Preconception: Reuse = free testing
We've already written the test case so wherever it's applicable (which should be self-explanatory) we can just paste it into out test scope and voí la! Free coverage!

The big issue here is the "self-explanatory" part. Problem is what fitted well in one feature might not do it in another even similar one. Even without needed tweaks we still have to figure out what the test case actually does, so that we know what we have covered with it and what we still need to cover in other ways.

This process is expensive, really expensive, so sure we save time not having to figure out the test and how to practically run it all over again but consider the time it takes to find the test case, analyse what it covers, analyse what it doesn't cover, analyse how it interacts with existing test cases, analyse if something has changed that impacts the test case compared to last time and so forth.

Preconception: A monkey can run a test case
  • We all interpret things differently. Click can mean single click, double click, right click (already assuming the first two were left clicks), tab and use enter, middle button click, etc. Even a well written, simple test case can lead to different interpretations.
  • One thing we're looking for is unexpected behavior and it's in the nature of "unexpected" to be something we can't plan for. Thus to get much use of a test case we need to handle the system well enough to investigate and identify when a behavior is unexpected or undesired.
  • We do a ton more observations than we consciously think of. These observations takes practice, focus and skill. For example, when you boot your computer you would react to a lot more things than you would add in a "boot test". Examples: screen is blinking, smoke is coming out, lights in the room flickers, you hear strange mechanical sounds, all these should catch you attention but are unlikely written down.

    More skill and/or focus can lead to more valuable observations: The login screen looks different, memory calculations are wrong, it's slower than usual/expected, BIOS version is incorrect, the operating system's starting mode is wrong etc.
  • When we don't fully understand something we tend to write it down less detailed (sucks to look stupid by writing down something incorrect and we're too lazy to investigate every detail we don't understand, it's easier to investigate as we get there).
  • When we write a test case based on specifications, requirements and other "guesses" of how the end system will work even a flawless instruction will sometimes not correspond to how the system is actually working (including when working as desired). This of course requires the person executing to be able to correct the test case thus understand both the intention with the test case and how the system works.
  • If we don't understand the system we may lose a lot of time setting up fully or partly irrelevant variables to the values stated in the instructions. The immediate comment is, if we have stated irrelevant variables in the test case we've failed. Consider then that the variable might be irrelevant to the test but mandatory to the system (e.g. you have to set a valid time server). Leave that out and the person executing once again needs to understand the system.
When is reuse actually beneficial?
  • We have rewritten something from the ground up but want it to externally still work the same. Reuse could save time.
  • We have some critical paths through the system that can't break.
  • We need to quickly regression test a feature without having to dig in too deep in the feature itself.
But remember that the one executing still should understand the test and the system to ensure tweaks (using different input values, triggering different fault cases etc.) can be made and important observations are more likely to be made.

How can we achieve reuse in Exploratory Testing
Not covered much by this particular session but a few thoughts:
  • Charters
  • Debrief notes
  • Test ideas
  • Test plans
Try creating a report specifically used as a "feature summary" including valuable operational instructions, general test ideas, impacts, lessons, problems, tools, important details, testability etc. We did kind of this at my former company where we let the test plan continuously turn into an end report as we added lessons from our testing. This would not only help when retesting a similar feature but also as educational material or test plan input for instance. Important though is to stay concise, noise is a huge enemy! The number of readers of a document is inversely proportional to the number of pages in the document, you know .)

A few notes on test case storage
First off I love this post on having a big inventory of test cases by Kristoffer Nordström.

It's easy to think something you've already created is free, but there's no such thing. Having a large inventory to test cases costs in many different ways:
  • Storage
  • Noise (it's one more thing testers have to keep track of)
  • Another tool/part of tool for testers to stay updated with / learn / understand
  • For a test case to be fully reusable later it should be kept up to date. How many refactors all their old test cases as functionality is changed?
  • ... if you do, that sounds really expensive.
Summary
Reuse has it's place but be careful!

Remember reuse means inheriting blind spots, has a cost and still requires the person "reusing" to know just as much about the feature, system and testing in general as if (s)he wasn't reusing old checks.

Take care, and I hope these Transpection Tuesday notes (even though somewhat messy) were helpful!

... and of course, thank you Helena!

03 October 2013

Arguing for Exploratory Testing, part 1, Traceability

Background
The topic for my and Helena Jeret Mäe's last Transpection Tuesday was Arguing for Exploratory Testing. What we basically wanted to achieve was to get better at explaining the pros (and cons) about exploratory testing, in a concise way, as well as identify common preconceptions about scripted versus exploratory testing.

Input
We had defined 15 subtopics such as time estimations, credibility and making sure the important testing is done. The first item on this list was traceability which turned out to be enough material to fill the whole 2 hour session.

What is Traceability
First question was: What do we mean with traceability?

Our answer: Being able to track what has been tested, how, when and by who.

Why do we want Traceability
The next question was why we want traceability. We quickly formed a list but reading it now makes me realize we mixed together traceability and claimed benefits of having a trunk of test cases. But anyway:
  • External demands
  • Ensure work has been performed
  • Base for further testing
  • Support handovers
  • Create a map
  • Reuse
General thoughts
One thing we got back to over and over again was: The best way (often related to level of detail) to achieve good enough traceability is highly context dependent! For example having a simple mind map with short comments is good enough for one company while another requires every session to be recorded with the recordings being stored and indexed together with session notes, debrief summaries and saved logs. It all depends!

Another reoccurring theme was: "But do we really achieve that kind of traceability with test cases". I will not bring up those discussions much in this post but expect another one on "false assumptions about scripted and exploratory testing" soon.

Terms

Charter
Charter is basically an area to test, a way to break down a big testing mission. Notice though that as you test new charters might come up so it's by no means a definite plan. Read more >>

Test idea
Typically a one liner describing one or more tests you want to do. Read more >>

Session
A timeboxed, uninterrupted test sitting, typically 60-120 minutes. Read more >>

Debrief
Refers to an activity happening after a session where the tester explains what has been done to, for example, a test manager. This also includes clarifying questions, feedback and other kinds of dialog to help both parties learn from the session. Read more >>

Recording

We mainly refer to screen recording (video, either using a screen recording tool or an external video camera) but could as well mean record audio, save logs/traces or other ways to save what has been done. A good resource >>

External demands
This refers to regulated businesses (watch the excellent presentation What is good evidence by Griffin Jones), evidence in a potential lawsuit or customers demanding test data.

Possible solutions:
  • Record the sessions, preferably with configuration (device, version, settings etc.) explained if that matters. Adding commentary might improve the value as well (communicating purpose, observations etc.). This is also typically a scenario where logs/traces can be a required addition to a video recording. Once again, watch What is good evidence.
  • Store session notes
  • Store session summaries
  • Store charters
  • Store debrief summaries
  • Store test ideas (assuming they has been covered by your testing)
Creating support to find old information (index) seems key as well. For this charters, time stamps and/or categories might be useful to tag your save material with.

Ensure work has been performed
First question raised was: Is this really something we want to encourage? And our general answer is no; with the motivation that people in our experience tend to do things to look good rather than do what is needed/valuable when closely monitored. But being able to know that the testers actually do their job is closely connected to credibility and transparency so still a valid question.

Possible solutions:
  • Debriefs
  • Recordings
  • Notes
  • Bugs reported (a really bad metric for this but can indicates something!)
Debriefs seemed to most often be the preferred approach. During a good debrief the person being debriefed asks followup questions that will require the person debriefing to explain the testing done. A byproduct in this process would be to ensure that the tester actually did a good job / any job at all. But once again; if your focus is on monitoring, the people monitored (testers as well as non-testers) is likely to waste time proving job has been done rather than actually work!

Base for further testing
Let's say we've finished the prepared scope or are suddenly given an extra week to test something. If we can't go back and use already executed tests as inspiration, how do we know where to continue?

Possible solutions:
  • Having a bulk of charters as inspiration
  • Make comments about testing you've left out in your finished charters/sessions
  • Review session notes
We also brought up if there's a value of actually looking at what has been done. Often we found that the time it takes to analyse the work already done might not be worth it (information being too detailed making it hard to overview and learn from quickly). Simply exploring using knowledge we might not had had the first time or by having a different tester from when we first tested, is often more than enough to add value. After all, the time we analyse is time we cannot test (which might or might not be well invested).

Support handovers
One tester leaves (quits, parental leave, other tasks etc.) and another has to take over, how can we manage such a change when not having a set scope of test cases? First of all the new tester do have to spend some time getting familiar with the feature in exploratory testing but this is also true for using test cases since we, for instance, can't predict what problems we will run into thus can't prepare instructions for those!

But we can make it easier:
  • Charters (with status)
  • Debrief
  • Documented test ideas with already investigated ideas being marked
  • Session notes or session summaries
  • Mind maps or other test planning with already tested parts commented
  • Documenting lessons learned (like operational instructions)
Debrief in this case refers to a general debrief of what has been done, what we know is left, problems seen, lessons learned, where information is stored, who to talk to etc. by the tester leaving. Of course if the switch happens very suddenly (e.g. sickness) performing this is not possible and in that case it's important testers are professional enough to document what has been done (mind maps, short plans, visualizations, debrief/session summaries, charters). This is once again true for both exploratory and scripted testing.

Create a map
A bulk of test cases combined with statuses can somewhat be used to draw a map of what has been covered and what is left to test. How can we visualize this without test cases?

Possible solutions:
  • Charters
  • A mind map describing what has been tested
  • A picture/model of our product with comments about testing/coverage
  • Other visualizations like diagrams
  • The Low Tech Dashboard
A few important notes:
  1. You sure have a map with test cases but is it actually anyway near accurate? Say we have two equally complex functions. One takes 1 argument, one takes 10. We likely will have at least 10 times as many test cases to cover the second function. So if we execute all the test cases for the second function, have we really covered over 90% (with "covered" only considering these 2 functions)?
  2. Even if equally sized, that map would not cover what we didn't anticipate from the beginning so you still need to add an up to date judgement/evaluation (e.g. "wow that network protocol sure was more complex when we expected during the planning, we need more testing of it!").
  3. Scale is really important. Do we want to see Tartu, Estonia, Europe, the world or the Milky Way galaxy? We might need different visualizations to create all the maps we need (once again, think about value, how much time can we spare to keep these updated).
Reuse
Later a similar feature or a feature impacting the one we just tested is developed and we want to reuse the work previously done. How can we do this without test cases?

First of all, reuse is one of the places where test cases are powerful. However you have the minesweeper problem: If you walk the same lane in a mine field over and over, as new mines are constantly added, it's likely that the number of mines beside your narrow track start to build up while few will happen to end up in your path. Meaning, running the same tests over and over is less likely catch new bugs as creating new tests are so value quickly diminishes (more tests executed is not equal to more valuable ground covered).

What we often would suggest is to use knowledge acquired the first time as foundation for new testing to speed it up. Think about the new risks introduced and what needs to be tested based on that (like with new functionality) rather than how old test cases might fit into your testing.

Possible solutions:
  • Reuse of charters
  • Reuse of test ideas
  • Look at old session notes / summaries
  • Use old recordings (the simpler the form of the recordings the better for this, watching several hours of screen recording is probably waste)
  • Start a wiki page/document/similar for each feature and add lessons learned, where to find info, problems etc. as you test.
Summary
There are many ways of achieving traceability (and similar potential benefits of test case trunks) in exploratory testing, Session Based Test Management principles seems to be the most straight forward way but keeping track of test ideas or using other approaches works as well. All have their own contexts where they seem to work best (e.g. SBTM might add too much overhead for a simple project).

All and all, if someone claims "You lose traceability with exploratory testing", ask what that person means more precisely (e.g. present testing data to customer) and explain the alternatives. Notice this is only based on our two hour discussion and there are a whole lot more to add so think for yourself as well! Also question whether you actually achieve the kind of traceability requested using a scripted approach and to what cost. Finally question if the requested traceability is actually worth its cost no matter if exploratory or scripted testing is used. Doing unnecessary work is wasteful no matter what approach you use.

Finally: There are still contexts where a highly scripted approach is likely the best option but the closer you get to a pure scripted approach the fewer and more extreme the contexts become.

Thank you for reading!

And thank you Helena, see you next week!