How a global medical technology company replaced manual permission testing with a maintainable automation framework its own team can run.
About our client
Our client is a global medical technology company. This engagement focused on its clinical-grade, web-based surgical planning platform, where accuracy, regulatory compliance and reliability are non-negotiable.
The challenge
- Manual-only regression testing of role-based permissions as features and access rules evolved.
- Consistent coverage needed across Chrome, Edge and Safari, in two regions with different interface variations.
- Compliance obligations under FDA and TGA frameworks.
- A requirement for an Australian-based delivery team.
- Limited in-house automation experience, so the solution had to build internal capability.
Our approach
- A short discovery phase to confirm where automation would reduce the most risk.
- A Python and Playwright framework covering user access across all eight roles, with resilient selectors.
- Cross-browser, multi-region coverage accounting for regional interface differences.
- A design integrated with the client's test management tooling for compliance traceability.
- Pair-programming between our Senior Automation Lead and the client's team throughout the build.
- Framework documentation, a maintenance guide and a recommended roadmap for further phases.
The outcome
- The client moved from manual-only testing to a maintainable automation framework covering one of its highest-risk areas.
- Its internal team gained hands-on automation capability rather than inheriting a black box.
- The framework flexes with frequent feature-flag changes, reducing brittle automation.
- Traceability considered from the outset supports ongoing FDA and TGA compliance.
- A prioritised roadmap for extending automation across more testing types and product lines.
Related
Still testing permissions by hand? Talk to us about a Test Automation Maturity Assessment.