Make the expectation explicit
Identify the infrastructure access layer and the application account separately. Confirm how the runner is permitted to reach the target without placing credentials in test descriptions or public URLs.
Put it into practice
Validate the supported environment configuration during onboarding. Do not assume that OTP support, application login, and HTTP Basic authentication are interchangeable capabilities.
Choose one journey, define the expected result, and inspect the evidence from a completed run. Expand the suite after the first test is useful.