{
  "document_type": "VENDOR_REVIEW_DOCUMENTATION",
  "revision": "R1",
  "source_checked_on": "2026-10-04",
  "sources": {
    "VM": {
      "title": "Offering virtual machine (VM) products",
      "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm",
      "file": "google-vm-overview.txt",
      "scope": "Vendor entry, VM-specific requirements and lifecycle checklist. Linked specialist documents remain explicit dependencies.",
      "updated": "2026-09-30",
      "checked": "2026-10-04",
      "capture_sha256": "f4bf308c67846bee9886993647ee2c782450713598493dd74739d574256fa658"
    },
    "GS": {
      "title": "Set up your Google Cloud environment",
      "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/set-up-environment",
      "file": "google-getting-started.txt",
      "scope": "Workspace and product setup, product details, Google Cloud-specific Getting Started, next steps and draft feedback.",
      "updated": "2026-09-30",
      "checked": "2026-10-04",
      "capture_sha256": "d51859d9a0c9aa8a824059938716c664bb233d2b3aafb3306a8e03de531a9b82"
    },
    "IMAGE": {
      "title": "Building your virtual machine (VM) image",
      "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/build-vm-image",
      "file": "google-build-vm-image.txt",
      "scope": "Image preparation, license binding, conditional visibility and credentials, image checks and maintenance notes. Build commands are not operational instructions for frozen r232.",
      "updated": "2026-09-30",
      "checked": "2026-10-04",
      "capture_sha256": "0a9fe17187c4dae772ef7bd0c6446f23082b7cd2bee38856232c749e4c836573"
    },
    "TEST": {
      "title": "Testing your VM product",
      "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/test-product",
      "file": "google-test-product.txt",
      "scope": "Preview access, listing UI, deployment flows and variants, and documented post-deployment tests.",
      "updated": "2026-09-30",
      "checked": "2026-10-04",
      "capture_sha256": "a300a669b1efaa3b2016fba2a50ec54d5b6d678e6d1d5c31ca814d05aaa459db"
    },
    "SUBMIT": {
      "title": "Submit your product",
      "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/submitting",
      "file": "google-submitting.txt",
      "scope": "Submission prerequisites, component reviews, Google-owned VM checks, private final review, changes and public publication.",
      "updated": "2026-09-30",
      "checked": "2026-10-04",
      "capture_sha256": "71b707f3fb37f2d18d42a3b108696813e2a1080359d5ac7ec71be2f3112c3da1"
    }
  },
  "coverage_note": "All items in this declared mapping; not Google approval, product readiness or an exhaustive private review requirement set.",
  "items": [
    {
      "id": "VM-01",
      "source": "VM",
      "anchor": "before-you-begin",
      "locator": "sign up to become a vendor",
      "strength": "conditional",
      "stage": "prerequisites",
      "title": "Become an eligible Marketplace vendor",
      "applies": "A vendor new to Cloud Marketplace.",
      "owner": "Vendor onboarding owner.",
      "prerequisite": "Company onboarding details and authorized representative.",
      "action": "Follow vendor onboarding and retain the enrollment disposition.",
      "expected": "Vendor enrollment is established independently of product review or publication.",
      "evidence": "Enrollment confirmation and owner/date; keep private account details outside the public guide.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": [
        {
          "label": "Vendor onboarding",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/offer-products#initiate-onboarding"
        }
      ]
    },
    {
      "id": "VM-02",
      "source": "VM",
      "anchor": "before-you-begin",
      "locator": "For your first (and all subsequent) listings",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Complete onboarding validation for every listing",
      "applies": "Every VM Marketplace product.",
      "owner": "Vendor onboarding owner.",
      "prerequisite": "Exact listing identity and current onboarding form.",
      "action": "Complete the Cloud Marketplace Onboarding Validation Form for this listing, including subsequent listings.",
      "expected": "A submission record is bound to the exact listing; submission is not approval.",
      "evidence": "Form version, listing reference, submission date and Google response in the private handoff.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "VM-03",
      "source": "VM",
      "anchor": "before-you-begin",
      "locator": "complete the Cloud Marketplace Project Info Form",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Supply project information for Producer Portal access",
      "applies": "Every VM Marketplace product.",
      "owner": "Vendor onboarding owner.",
      "prerequisite": "Project identities and the form supplied by the Marketplace team.",
      "action": "Complete the Project Info Form; reconcile with SET-06 and SET-07 rather than creating duplicate submissions.",
      "expected": "The project-information submission and Portal enablement are separately recorded.",
      "evidence": "Form receipt and subsequent Partner Engineer enablement confirmation.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "VM-04",
      "source": "VM",
      "anchor": "product-specific_requirements",
      "locator": "comply with Cloud Marketplace open source policy",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Review and meet open source policy",
      "applies": "Every VM Marketplace product.",
      "owner": "Open source compliance owner.",
      "prerequisite": "Exact shipped artifact inventory and the linked current policy.",
      "action": "Have the owner review the linked recommendations, restrictions and policy against the shipped product. Record unresolved obligations explicitly.",
      "expected": "A release-specific compliance disposition is recorded with supporting notices and any required remediation.",
      "evidence": "Owner review, policy revision/date and approved distributable notices.",
      "note": "Dependency check pending. The linked open source policy has not been exhaustively mapped by this five-page review.",
      "refs": [
        {
          "label": "Open source compliance",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/open-source-compliance"
        }
      ]
    },
    {
      "id": "VM-05",
      "source": "VM",
      "anchor": "product-specific_requirements",
      "locator": "deploy software to, and run on, Compute Engine",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Run the delivered product on Compute Engine",
      "applies": "Every VM Marketplace product.",
      "owner": "Deployment package owner.",
      "prerequisite": "Exact VM product and supported deployment configuration.",
      "action": "Verify that the Marketplace delivery deploys its software to Compute Engine and runs there.",
      "expected": "The identified deployment is an operating Compute Engine VM product.",
      "evidence": "Deployment identity, product process/service observations and scoped test result.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "VM-06",
      "source": "VM",
      "anchor": "product-specific_requirements",
      "locator": "Cloud Marketplace-hosted image with the attached Compute Engine license",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Use the Marketplace image and attached license",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Candidate image, Marketplace delivery model and product license identity.",
      "action": "Verify the Marketplace-hosted image and attached Compute Engine license for the exact submitted candidate. Resolve the hosting route with the Partner Engineer.",
      "expected": "The delivered image and its valid license match the submitted product.",
      "evidence": "Image identity, Portal license reference and deployed-instance license evidence.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "VM-07",
      "source": "VM",
      "anchor": "product-specific_requirements",
      "locator": "tested end to end before you submitted it",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Complete end-to-end testing before submission",
      "applies": "Every VM Marketplace product.",
      "owner": "Deployment package owner.",
      "prerequisite": "Exact delivery candidate and a customer-reproducible procedure.",
      "action": "Complete the TEST mapping and retain the full customer path, including post-deployment setup, before claiming this requirement is met.",
      "expected": "The exact submitted candidate has successful end-to-end evidence without unresolved required steps.",
      "evidence": "Candidate identity, run record, expected/actual results and unresolved-step register.",
      "note": "Pending customer-delivery proof. r232 C7 customer administrator bootstrap remains blocked; local demonstrations do not close it.",
      "refs": [
        {
          "label": "VM testing",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/test-product"
        }
      ]
    },
    {
      "id": "VM-08",
      "source": "VM",
      "anchor": "product-specific_requirements",
      "locator": "any critical security issues related to the product",
      "strength": "conditional",
      "stage": "prerequisites",
      "title": "Resolve identified critical security issues",
      "applies": "If the vendor or Google identifies critical product security issues.",
      "owner": "Security response owner and release owner.",
      "prerequisite": "Confirmed issue, affected release, remediation owner and separate repair/release authority.",
      "action": "Track the issue to an authorized update and validation. Escalate any Frozen-release constraint to the owner; do not alter r232 through this guide.",
      "expected": "A verified remediation disposition is available for the affected product.",
      "evidence": "Issue reference, affected version, authorized remediation, validation and release disposition.",
      "note": "Conditional owner check pending. This mapping neither asserts a critical issue nor authorizes security repair.",
      "refs": []
    },
    {
      "id": "VM-09",
      "source": "VM",
      "anchor": "checklist",
      "locator": "Set up your Google Cloud environment",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Complete the environment and listing setup",
      "applies": "Every VM Marketplace product.",
      "owner": "Vendor onboarding owner.",
      "prerequisite": "Applicable SET rows and exact project/listing identities.",
      "action": "Reconcile the setup rows with the real project and Producer Portal records.",
      "expected": "Project setup and listing records have named owners and explicit dispositions.",
      "evidence": "Completed SET evidence references and pending items.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": [
        {
          "label": "Environment setup",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/set-up-environment"
        }
      ]
    },
    {
      "id": "VM-10",
      "source": "VM",
      "anchor": "checklist",
      "locator": "select a pricing model",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Select and submit the pricing model",
      "applies": "Every VM Marketplace product.",
      "owner": "Commercial pricing owner.",
      "prerequisite": "Approved commercial model and current pricing documentation.",
      "action": "Review the linked pricing options, select the model and record its Portal review result. The overview says review takes up to four business days and setup may continue in parallel.",
      "expected": "An exact selected pricing model and its review disposition are recorded.",
      "evidence": "Approved pricing specification and dated Portal review status.",
      "note": "Dependency check pending. Detailed pricing rules are outside the five-page mapping; the timing is guidance, not an approval guarantee.",
      "refs": [
        {
          "label": "Pricing models",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/select-pricing"
        }
      ]
    },
    {
      "id": "VM-11",
      "source": "VM",
      "anchor": "checklist",
      "locator": "Build your VM image",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Supply a reviewed VM image",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Reconcile the IMAGE requirements with the exact authorized release candidate and Partner Engineer feedback.",
      "expected": "The candidate image has a traceable build and validation disposition.",
      "evidence": "Image identity and the completed IMAGE evidence references.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": [
        {
          "label": "Build a VM image",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/build-vm-image"
        }
      ]
    },
    {
      "id": "VM-12",
      "source": "VM",
      "anchor": "checklist",
      "locator": "Create your deployment package",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Review the complete deployment package requirements",
      "applies": "Every VM Marketplace product.",
      "owner": "Deployment package owner.",
      "prerequisite": "Selected deployment method, image and current linked package documentation.",
      "action": "Review the linked package requirements for the selected deployment method and supply the package-specific checklist and evidence.",
      "expected": "The exact deployment package has its own complete requirements and review disposition.",
      "evidence": "Package identity, method-specific requirements review and Portal disposition.",
      "note": "Dependency check pending. This guide does not claim complete coverage of the linked deployment-package documentation.",
      "refs": [
        {
          "label": "Deployment package",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/create-deployment-package"
        }
      ]
    },
    {
      "id": "VM-13",
      "source": "VM",
      "anchor": "checklist",
      "locator": "Add a label to track your product's associated consumption",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Track associated Google Cloud consumption",
      "applies": "Every VM Marketplace product.",
      "owner": "Deployment package owner.",
      "prerequisite": "Current consumption-tracking instructions and authorized package configuration.",
      "action": "Have the package owner determine and validate the required consumption label against the linked instructions.",
      "expected": "Required consumption labeling is present and verifiable in the applicable deployment.",
      "evidence": "Label requirement reference, package mapping and deployed observation.",
      "note": "Dependency check pending. The deeper labeling specification is not fully mapped here; no cloud labeling operation was performed.",
      "refs": [
        {
          "label": "Associated consumption tracking",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/partner-consumption-tracking"
        }
      ]
    },
    {
      "id": "VM-14",
      "source": "VM",
      "anchor": "checklist",
      "locator": "Test your product end-to-end",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Reconcile the testing checklist",
      "applies": "Every VM Marketplace product.",
      "owner": "Deployment package owner.",
      "prerequisite": "Exact release and complete TEST rows.",
      "action": "Link all applicable TEST outcomes to the pre-submission end-to-end requirement in VM-07.",
      "expected": "Testing coverage and unresolved outcomes are visible before submission.",
      "evidence": "TEST workbook and exact candidate binding.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": [
        {
          "label": "Product testing",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/test-product"
        }
      ]
    },
    {
      "id": "VM-15",
      "source": "VM",
      "anchor": "checklist",
      "locator": "Submit your product to Cloud Marketplace",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Track every required product review",
      "applies": "Every VM Marketplace product.",
      "owner": "Producer Portal owner.",
      "prerequisite": "Product Details, Pricing and Deployment Package submissions.",
      "action": "Use the SUB mapping to track each submitted section, Google feedback and issue resolution.",
      "expected": "Each required review has its own explicit Google disposition.",
      "evidence": "Dated Portal statuses and feedback-resolution records.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": [
        {
          "label": "Submitting a VM product",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/submitting"
        }
      ]
    },
    {
      "id": "VM-16",
      "source": "VM",
      "anchor": "checklist",
      "locator": "After all reviews are approved",
      "strength": "google_process",
      "stage": "prerequisites",
      "title": "Separate approval from publication",
      "applies": "Every VM Marketplace product.",
      "owner": "Producer Portal owner.",
      "prerequisite": "All required review approvals and explicit publication authority.",
      "action": "Record approval of all reviews before any publication decision. The overview describes launch within minutes after approval, not a guaranteed deadline.",
      "expected": "Approval, publication action and public availability remain distinct recorded states.",
      "evidence": "Review approvals, publication authorization, action receipt and public listing observation.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "VM-17",
      "source": "VM",
      "anchor": "checklist",
      "locator": "Maintain and monitor your product after it has launched",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Assign post-launch maintenance and monitoring",
      "applies": "Every VM Marketplace product.",
      "owner": "Product operations and release owners.",
      "prerequisite": "Support/maintenance ownership and current linked monitoring guidance.",
      "action": "Review the linked monitoring guidance and record maintenance, monitoring and response responsibilities for the released product.",
      "expected": "Post-launch responsibilities and observable operating records are defined.",
      "evidence": "Maintenance plan, monitoring references, response owner and review cadence.",
      "note": "Dependency check pending. The linked monitoring documentation is not fully mapped by this review.",
      "refs": [
        {
          "label": "Monitoring guidance",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/monitor-analytics"
        }
      ]
    },
    {
      "id": "VM-18",
      "source": "VM",
      "anchor": "",
      "locator": "include the word \"Marketplace\" in your description",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Route onboarding questions to Partner Support Desk",
      "applies": "When onboarding questions require Google assistance.",
      "owner": "Vendor onboarding owner.",
      "prerequisite": "Exact unresolved question and non-secret product/project reference.",
      "action": "Submit an authorized Partner Support Desk request with Marketplace in the description and record the response.",
      "expected": "The request is routed with enough context for Google to answer.",
      "evidence": "Private support reference, question, owner and response.",
      "note": "No support message is sent by this documentation task.",
      "refs": [
        {
          "label": "Marketplace support",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/get-support"
        }
      ]
    },
    {
      "id": "SET-01",
      "source": "GS",
      "anchor": "create-workspace",
      "locator": "you create two Google Cloud projects",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Separate development and public-image projects",
      "applies": "Every VM Marketplace product.",
      "owner": "Vendor onboarding owner.",
      "prerequisite": "Approved project naming and ownership.",
      "action": "Verify the development/testing project uses PARTNER_NAME-dev and the final-image project uses PARTNER_NAME-public, or record Partner Engineer guidance for the actual arrangement.",
      "expected": "The two project purposes and exact identities are unambiguous.",
      "evidence": "Private project-purpose mapping and any Google-confirmed variance.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-02",
      "source": "GS",
      "anchor": "create-workspace",
      "locator": "Don't use this public project for anything other than hosting",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Keep the public project dedicated to images",
      "applies": "Every VM Marketplace product.",
      "owner": "Vendor onboarding owner.",
      "prerequisite": "Public-project identity and scoped inventory.",
      "action": "Verify the public project is used only for final Compute Engine image hosting.",
      "expected": "No unrelated use is included in the public-project inventory.",
      "evidence": "Dated scope review with private identifiers redacted from public material.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-03",
      "source": "GS",
      "anchor": "create-workspace",
      "locator": "grant the Editor (roles/editor) and Service Management Admin",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Verify the specified onboarding access",
      "applies": "Every VM Marketplace product.",
      "owner": "Authorized project IAM owner.",
      "prerequisite": "Current official principal/role pairs and explicit IAM authority outside this guide.",
      "action": "Have the IAM owner compare both projects with the official onboarding-principal Editor/Service Management Admin grants and producer-principal Config Editor grant. Record discrepancies without changing permissions here.",
      "expected": "The exact official principal/role/project relationships have an owner-verified disposition.",
      "evidence": "Access review reference and dated disposition; no credentials or complete IAM export in the public workbook.",
      "note": "Pending owner confirmation. This is a documentation check, not authority to grant or broaden access.",
      "refs": []
    },
    {
      "id": "SET-04",
      "source": "GS",
      "anchor": "create-workspace",
      "locator": "For each project, enable the Compute Engine API",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Verify Compute Engine API availability in both projects",
      "applies": "Every VM Marketplace product.",
      "owner": "Vendor onboarding owner.",
      "prerequisite": "Exact development and public project identities.",
      "action": "Record the Compute Engine API enablement disposition for each project.",
      "expected": "Both projects meet the documented API prerequisite.",
      "evidence": "Dated API state observations for both projects.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-05",
      "source": "GS",
      "anchor": "create-workspace",
      "locator": "In the public project only, set a security contact",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Assign the public-project security contact",
      "applies": "Every VM Marketplace product.",
      "owner": "Security contact owner.",
      "prerequisite": "Approved security contact and exact public-project identity.",
      "action": "Verify the public project has the required security notification contact.",
      "expected": "Security notifications have an assigned, current recipient.",
      "evidence": "Private contact configuration confirmation and review date.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-06",
      "source": "GS",
      "anchor": "create-workspace",
      "locator": "You only need to complete this form once",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Complete the Project Info Form once",
      "applies": "Every VM Marketplace product.",
      "owner": "Vendor onboarding owner.",
      "prerequisite": "Projects configured and high-level product details available.",
      "action": "Provide project/product details through the Project Info Form and link its existing receipt to VM-03; distinguish this one-time form from per-listing onboarding validation.",
      "expected": "One traceable project-information submission supports Portal onboarding.",
      "evidence": "Form receipt, scope and owner/date.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-07",
      "source": "GS",
      "anchor": "create-product",
      "locator": "Your Partner Engineer enables it for you",
      "strength": "google_process",
      "stage": "prerequisites",
      "title": "Confirm Producer Portal enablement",
      "applies": "Every VM Marketplace product.",
      "owner": "Partner Engineer and vendor onboarding owner.",
      "prerequisite": "Completed Project Info Form.",
      "action": "Obtain the Partner Engineer enablement disposition and verify authorized access to the intended product project.",
      "expected": "Portal access is established for the intended project.",
      "evidence": "Enablement confirmation and access observation without credentials.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-08",
      "source": "GS",
      "anchor": "create-product",
      "locator": "you submit the following information for review",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Prepare the three Portal review tracks",
      "applies": "Every VM Marketplace product.",
      "owner": "Producer Portal owner.",
      "prerequisite": "Exact product entry and named commercial/deployment owners.",
      "action": "Prepare Product Details, Pricing and Deployment Package as separately tracked review sections.",
      "expected": "All three tracks have identified inputs, owners and dispositions.",
      "evidence": "Three-track review register linked to the SUB rows.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-09",
      "source": "GS",
      "anchor": "create-product",
      "locator": "at any time and in any order",
      "strength": "google_process",
      "stage": "prerequisites",
      "title": "Plan independent review tracks early",
      "applies": "Every VM Marketplace product.",
      "owner": "Producer Portal owner.",
      "prerequisite": "The three review requirements and submission schedule.",
      "action": "Plan the reviews independently: the official page permits any order and says some reviews may take up to two weeks. Start reviewing requirements early.",
      "expected": "The schedule separates estimated review durations from actual approval dates.",
      "evidence": "Owner schedule and actual dated Portal statuses.",
      "note": "Official timing is an estimate, not a service-level guarantee or approval.",
      "refs": []
    },
    {
      "id": "SET-10",
      "source": "GS",
      "anchor": "create-product",
      "locator": "you only need to create a Cloud Marketplace entry",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Establish the product entry before other reviews",
      "applies": "Every VM Marketplace product.",
      "owner": "Producer Portal owner.",
      "prerequisite": "Producer Portal access and chosen public project.",
      "action": "Confirm the product entry exists in the intended public project; complete remaining details as the separately tracked reviews progress.",
      "expected": "A stable product entry anchors all review records.",
      "evidence": "Product entry reference, project binding and owner.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-11",
      "source": "GS",
      "anchor": "create-product",
      "locator": "If you don't see the link, or can't access the URL",
      "strength": "conditional",
      "stage": "prerequisites",
      "title": "Resolve Portal access through the documented route",
      "applies": "If the Producer Portal URL or link is unavailable.",
      "owner": "Producer Portal owner.",
      "prerequisite": "Intended project, authorized role review and exact access error.",
      "action": "Verify the selected project and required Editor role with the IAM owner. If access remains unavailable, use Partner Support Desk and include Marketplace in the description.",
      "expected": "The access issue has a supported resolution or explicit support disposition.",
      "evidence": "Error, project/role confirmation and private support reference.",
      "note": "No access expansion or support request is executed here.",
      "refs": [
        {
          "label": "Marketplace support",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/get-support"
        }
      ]
    },
    {
      "id": "SET-12",
      "source": "GS",
      "anchor": "create-product",
      "locator": "Select Virtual machine",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Confirm the VM product type",
      "applies": "Every VM Marketplace product.",
      "owner": "Producer Portal owner.",
      "prerequisite": "Approved product definition before entry creation.",
      "action": "Verify the product entry is of type Virtual machine. Record the intended product name and Product ID.",
      "expected": "The product type matches the VM review being prepared.",
      "evidence": "Product type/name/ID confirmation in the private handoff.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-13",
      "source": "GS",
      "anchor": "create-product",
      "locator": "The Product ID and product type cannot be changed",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Verify immutable product identity before creation",
      "applies": "Every VM Marketplace product.",
      "owner": "Producer Portal owner.",
      "prerequisite": "Approved product ID and type.",
      "action": "Confirm the ID and type before creation because both become immutable; confirm the product name before submission, when it can still be changed.",
      "expected": "The listing URL identity and product type are deliberately chosen and recorded.",
      "evidence": "Owner-confirmed identity decision and current product-entry record.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-14",
      "source": "GS",
      "anchor": "add_product_details",
      "locator": "Enter a name, tagline, image, and overview description",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Complete core listing information",
      "applies": "Every VM Marketplace product.",
      "owner": "Product listing owner.",
      "prerequisite": "Approved public product description and image assets.",
      "action": "In Product Details, complete name, tagline, image and overview description, then check that public claims match the delivered product.",
      "expected": "The listing contains accurate, reviewable public product information.",
      "evidence": "Submitted listing text/assets and owner review.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-15",
      "source": "GS",
      "anchor": "add_product_details",
      "locator": "You can select up to two Category IDs",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Select at most two listing categories",
      "applies": "Every VM Marketplace product.",
      "owner": "Product listing owner.",
      "prerequisite": "Applicable Portal category options.",
      "action": "Choose the relevant Category IDs within the documented limit of two.",
      "expected": "The categories are relevant and within the allowed count.",
      "evidence": "Selected category IDs and product relevance rationale.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-16",
      "source": "GS",
      "anchor": "add_product_details",
      "locator": "Complete the Documentation and Product metadata sections",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Complete documentation and product metadata",
      "applies": "Every VM Marketplace product.",
      "owner": "Product listing and documentation owners.",
      "prerequisite": "Current public guide URLs and exact product metadata.",
      "action": "Complete the Documentation and Product metadata sections and verify the listed documentation links.",
      "expected": "Reviewers can reach current documentation from the listing.",
      "evidence": "Submitted documentation URLs, metadata and link-check result.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-17",
      "source": "GS",
      "anchor": "add_product_details",
      "locator": "They must be directly relevant to your product",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Use directly relevant search keywords",
      "applies": "Every VM Marketplace product.",
      "owner": "Product listing owner.",
      "prerequisite": "Proposed Search keywords field.",
      "action": "Check each search keyword for direct relevance to the product.",
      "expected": "All submitted search keywords are directly relevant.",
      "evidence": "Keyword list and relevance review.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-18",
      "source": "GS",
      "anchor": "add_product_details",
      "locator": "must not include brand names or product names licensed by competitors",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Exclude competitor-licensed names from keywords",
      "applies": "Every VM Marketplace product.",
      "owner": "Product listing owner.",
      "prerequisite": "Proposed search keyword list.",
      "action": "Review the keywords against the prohibition on brand/product names licensed by competitors.",
      "expected": "The submitted keyword field avoids the prohibited names.",
      "evidence": "Owner-reviewed keyword list.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-19",
      "source": "GS",
      "anchor": "add_product_details",
      "locator": "might require additional approvals for some categories",
      "strength": "conditional",
      "stage": "prerequisites",
      "title": "Resolve additional or unavailable categories",
      "applies": "If a selected category needs extra approval or is not listed in Producer Portal.",
      "owner": "Producer Portal owner.",
      "prerequisite": "Category choice and Google category-specific instructions.",
      "action": "Record required extra approvals; request an unlisted category through the special category request form supplied by Google.",
      "expected": "Category-specific approvals or request outcomes are explicit.",
      "evidence": "Category request and approval disposition in private handoff.",
      "note": "Pending exact product and delivery evidence. This row records what to verify, not a completed check.",
      "refs": []
    },
    {
      "id": "SET-20",
      "source": "GS",
      "anchor": "add_product_details",
      "locator": "approximately 2-5 business days",
      "strength": "google_process",
      "stage": "prerequisites",
      "title": "Track actual Product Details review status",
      "applies": "Every VM Marketplace product.",
      "owner": "Producer Portal owner.",
      "prerequisite": "Product Details review submission.",
      "action": "Track the actual review response; the page estimates approximately 2–5 business days for Partner Engineering review and approval.",
      "expected": "Actual Google status and dates, rather than elapsed time, determine the recorded disposition.",
      "evidence": "Submission date and actual review response.",
      "note": "The estimate does not establish approval or a guaranteed turnaround.",
      "refs": []
    },
    {
      "id": "IMG-01",
      "source": "IMAGE",
      "anchor": "",
      "locator": "move it to your public project after your Google Partner Engineer has verified",
      "strength": "recommended",
      "stage": "prerequisites",
      "title": "Use development-first image review",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Record image development in the development project, Partner Engineer verification, and only then the separately authorized public-image progression.",
      "expected": "Development, Engineer verification and public-image progression are traceable distinct steps.",
      "evidence": "Image identities and dated Partner Engineer disposition.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-02",
      "source": "IMAGE",
      "anchor": "before_you_begin",
      "locator": "Download the Google Cloud SDK",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Identify the required Google Cloud tooling",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Approved isolated image-authoring environment.",
      "action": "Record the Google Cloud SDK/tooling availability and version for the authorized image workflow.",
      "expected": "The image workflow has the required tooling identified.",
      "evidence": "Tool/version observation and build-environment identity.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-03",
      "source": "IMAGE",
      "anchor": "create_the_base_product_vm",
      "locator": "Use one of Google's supported base public images",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Use a supported base image and declare architectures",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Verify the supported Google base public image, installed app packages/configuration, and each offered Arm or x86 image/machine-type pairing. Multiple architecture images may share one product.",
      "expected": "Every offered architecture has an identified supported base and compatible machine scope.",
      "evidence": "Base image and package inventory; architecture/machine matrix.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-04",
      "source": "IMAGE",
      "anchor": "create_the_base_product_vm",
      "locator": "If you intend to provide support to your customers",
      "strength": "conditional",
      "stage": "prerequisites",
      "title": "Review supported app-credential retrieval",
      "applies": "If customer support is provided under the image instructions.",
      "owner": "Customer support and deployment owners.",
      "prerequisite": "Approved credential lifecycle and supported customer access design.",
      "action": "Have the owners review the official instruction to install app-user-credential retrieval scripts and bind it to the supported design. Do not expose credential values in documentation evidence.",
      "expected": "A supported retrieval path or Partner Engineer-confirmed applicability disposition is recorded.",
      "evidence": "Approved procedure, applicability decision and redacted validation.",
      "note": "Pending exact delivery design/evidence. This guide does not authorize secret retrieval or resolve C7 bootstrap.",
      "refs": []
    },
    {
      "id": "IMG-05",
      "source": "IMAGE",
      "anchor": "create_a_licensed_vm_image",
      "locator": "Install and customize your software",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Identify the licensed-image preparation inputs",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Record the target project/zone, primary instance, software configuration and required startup scripts for an authorized image build. The source procedure includes a primary instance with cloud-platform scope; applicability and authority must be reviewed before any future execution.",
      "expected": "The exact authorized build inputs and startup behavior are reproducible.",
      "evidence": "Private build specification, scoped authority and startup-script validation.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-06",
      "source": "IMAGE",
      "anchor": "create_a_licensed_vm_image",
      "locator": "your app must be customized through a server script",
      "strength": "conditional",
      "stage": "prerequisites",
      "title": "Bind login setup to deployment metadata",
      "applies": "If the app has a dashboard, database or management console requiring login.",
      "owner": "Deployment package owner.",
      "prerequisite": "Approved supported login design and the exact deployment package.",
      "action": "Verify the required server script reads login credentials from instance metadata and configures the username/password during deployment; obtain Partner Engineer guidance where the product uses a different supported model.",
      "expected": "The applicable login-provisioning behavior is demonstrated for the customer delivery candidate.",
      "evidence": "Applicability decision, package/script binding and redacted fresh-deployment test.",
      "note": "Pending customer-delivery proof. Local admin access does not prove the supported r232 customer bootstrap path.",
      "refs": []
    },
    {
      "id": "IMG-07",
      "source": "IMAGE",
      "anchor": "create_a_licensed_vm_image",
      "locator": "you must clean the input disk",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Exclude build-user data and SSH keys from the image",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Review the input disk for build-user directories, SSH keys and temporary installation files before an authorized new image is made. Do not treat deletion of the Frozen disk as a cleanup option.",
      "expected": "The customer image does not inherit unwanted build-user data or credentials.",
      "evidence": "Redacted image-hygiene review and exact candidate identity.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-08",
      "source": "IMAGE",
      "anchor": "create_a_licensed_vm_image",
      "locator": "Delete the VM while preserving the disk",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Review the disk-preserving cleanup procedure",
      "applies": "For a separately authorized future image build following this official cleanup method.",
      "owner": "Release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Review the documented sequence: retain the source disk, use an isolated helper instance with the disk attached as data, clean the mounted disk, and retain the updated disk when the helper is removed. Require exact resource and cleanup authority before execution.",
      "expected": "An authorized procedure preserves the intended disk throughout cleanup and image creation.",
      "evidence": "Approved resource disposition and bounded build/cleanup receipt.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-09",
      "source": "IMAGE",
      "anchor": "create_a_licensed_vm_image",
      "locator": "Under VM license, note the name",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Bind the image to its Portal VM license",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Obtain the exact product VM license from the Deployment Package section and bind that license to the image-creation specification.",
      "expected": "The image specification uses the exact license assigned to the product.",
      "evidence": "Portal license reference, image specification and deployed license result.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-10",
      "source": "IMAGE",
      "anchor": "create_a_licensed_vm_image",
      "locator": "who-vmOS-image-architecture-date",
      "strength": "required",
      "stage": "prerequisites",
      "title": "Use architecture-aware, unique image names",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Check the image name follows the documented who-vmOS-image-architecture-date form with Arm or x86_64, and uses a new unique name for each update.",
      "expected": "Each release image can be distinguished by its immutable identity and supported architecture.",
      "evidence": "Image naming record and version/architecture mapping.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-11",
      "source": "IMAGE",
      "anchor": "create_a_licensed_vm_image",
      "locator": "roles/compute.storageAdmin",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Verify image-build project roles and disk identity",
      "applies": "Every VM Marketplace product.",
      "owner": "Authorized IAM and release owners.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Have the owners check the documented public-project Compute Storage Admin and development-project Compute Image User roles, plus source disk project/zone/name and product license. An image description is optional.",
      "expected": "The planned operation has exact resource inputs and an explicit role/authority disposition.",
      "evidence": "Private role review and image input manifest with optional description disposition.",
      "note": "Pending owner confirmation; this row does not grant IAM permissions, change image access or authorize a build.",
      "refs": []
    },
    {
      "id": "IMG-12",
      "source": "IMAGE",
      "anchor": "make_the_image_public",
      "locator": "For non-Terraform products that don't use Marketplace owned images",
      "strength": "conditional",
      "stage": "prerequisites",
      "title": "Apply public-image access only where required",
      "applies": "Non-Terraform products that do not use Marketplace-owned images. Terraform-only deployment or Marketplace-owned images are excluded by the source note.",
      "owner": "Deployment owner, IAM owner and Partner Engineer.",
      "prerequisite": "Confirmed deployment method, image ownership model and exact access authority.",
      "action": "Determine applicability first. Where applicable, have the authorized owner review the official public-image availability instruction without applying access changes through this guide.",
      "expected": "The conditional access requirement has a justified, Partner Engineer-confirmed disposition; actual access evidence is attached only if applicable.",
      "evidence": "Deployment/ownership classification, applicability rationale and private access-review evidence.",
      "note": "Applicability is pending; do not label this not applicable solely because an image is Frozen. No public-access grant is authorized.",
      "refs": []
    },
    {
      "id": "IMG-13",
      "source": "IMAGE",
      "anchor": "create_authorization_credentials",
      "locator": "single VM instance with basic firewall rules",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Review direct-package random password support",
      "applies": "A simple single-VM deployment with basic firewall rules that needs a generated password.",
      "owner": "Deployment package owner.",
      "prerequisite": "Selected deployment method and approved login requirements.",
      "action": "Review the documented direct deployment-package option for automatically including a secure randomized password. Link the decision to the login requirement and GS guidance.",
      "expected": "The chosen credential-provisioning option is documented and can be validated on the exact candidate.",
      "evidence": "Package-method decision and redacted generation/retrieval proof.",
      "note": "Conditional option, not proof that the current product uses or supports this path. Password values must remain private.",
      "refs": [
        {
          "label": "Deployment package",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/create-deployment-package"
        }
      ]
    },
    {
      "id": "IMG-14",
      "source": "IMAGE",
      "anchor": "create_authorization_credentials",
      "locator": "mpdev tool, which we recommend for most use cases",
      "strength": "recommended",
      "stage": "prerequisites",
      "title": "Review the mpdev credential option",
      "applies": "When choosing a deployment-package authoring method.",
      "owner": "Deployment package owner.",
      "prerequisite": "Deployment requirements and linked package documentation.",
      "action": "Consider the official mpdev recommendation for most use cases, including automatic inclusion of multiple secure randomized passwords. Record the selected method and current Partner Engineer guidance.",
      "expected": "The method choice and applicable credential behavior are explicit.",
      "evidence": "Method selection, Google guidance and redacted package validation.",
      "note": "The linked deployment-package documentation remains an owner dependency; no current mpdev integration is inferred.",
      "refs": [
        {
          "label": "Deployment package",
          "url": "https://docs.cloud.google.com/marketplace/docs/partners/vm/create-deployment-package"
        }
      ]
    },
    {
      "id": "IMG-15",
      "source": "IMAGE",
      "anchor": "create_authorization_credentials",
      "locator": "to obtain the values of any passwords that you created",
      "strength": "conditional",
      "stage": "prerequisites",
      "title": "Validate supported post-deployment password retrieval",
      "applies": "If passwords are created by the selected metadata-based deployment flow.",
      "owner": "Deployment package owner.",
      "prerequisite": "Approved password name/binding and authorized customer retrieval procedure.",
      "action": "Verify the documented within-VM metadata retrieval works for the approved customer path and document how the customer obtains credentials without publishing their values.",
      "expected": "The intended customer can obtain the appropriate generated credentials through the approved path.",
      "evidence": "Redacted retrieval result tied to a fresh deployment and documented customer procedure.",
      "note": "Pending exact delivery proof; no credential retrieval is executed by this documentation task.",
      "refs": []
    },
    {
      "id": "IMG-16",
      "source": "IMAGE",
      "anchor": "test_the_vm_image",
      "locator": "Create a VM instance with your newly created image",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Validate a fresh instance from the candidate image",
      "applies": "Every VM Marketplace product.",
      "owner": "Deployment package owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Within separately authorized testing, create a fresh instance from the exact candidate image and verify product functionality.",
      "expected": "Product functionality is observed on a newly deployed candidate, not inferred from a development machine.",
      "evidence": "Image/instance binding, functional test steps and actual results.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-17",
      "source": "IMAGE",
      "anchor": "test_the_vm_image",
      "locator": "verify that valid licenses are attached",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Inspect attached licenses on the test VM",
      "applies": "Every VM Marketplace product.",
      "owner": "Deployment package owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Use the authorized instance inspection path to verify valid attached licenses and compare them with the product license record.",
      "expected": "The actual deployed VM exposes the expected valid product license.",
      "evidence": "Redacted instance license observation and product/image identity binding.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-18",
      "source": "IMAGE",
      "anchor": "test_the_vm_image",
      "locator": "Verify that Python 2.6 or greater is installed",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Resolve the documented Python baseline",
      "applies": "Every VM Marketplace product.",
      "owner": "Partner Engineer and release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Record the official wording \"Python 2.6 or greater\" and obtain current applicability guidance for the selected OS/image. Preserve the observed version; do not install obsolete software to satisfy this wording.",
      "expected": "Current Google applicability guidance and the exact candidate observation are reconciled.",
      "evidence": "Dated Partner Engineer guidance and redacted version observation.",
      "note": "Official wording retained; applicability pending. Frozen r232 is not modified. Any future image change needs separate release authority.",
      "refs": []
    },
    {
      "id": "IMG-19",
      "source": "IMAGE",
      "anchor": "test_the_vm_image",
      "locator": "Verify that the following packages are installed",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Resolve the documented tooling and service checks",
      "applies": "Every VM Marketplace product.",
      "owner": "Partner Engineer and release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Record the source checks for gcloud, SSH client, sshd, curl and DHCP, then obtain current applicability guidance for the selected OS/image and record actual observations. Do not equate a process-name search with functional readiness.",
      "expected": "Every listed check has a current applicability decision and scoped evidence.",
      "evidence": "Five-item applicability/observation record and dated Partner Engineer guidance.",
      "note": "Official checks are retained as written requirements to reconcile; no package installation or Frozen-image modification is authorized.",
      "refs": []
    },
    {
      "id": "IMG-20",
      "source": "IMAGE",
      "anchor": "test_the_vm_image",
      "locator": "no other user directories installed on the instance except for your own",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Inspect residual users and credentials on the test image",
      "applies": "Every VM Marketplace product.",
      "owner": "Release owner.",
      "prerequisite": "Exact candidate image, project and release identities; authorized isolated build or test scope.",
      "action": "Check the deployed test instance for unintended user directories and residual credentials, preserving the source allowance for the test operator's own directory. Review findings without exposing secret contents.",
      "expected": "No unintended build-user directories or credentials are inherited by the customer image.",
      "evidence": "Redacted hygiene inspection tied to the candidate image.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "IMG-21",
      "source": "IMAGE",
      "anchor": "test_the_vm_image",
      "locator": "re-build and re-publish images once every month",
      "strength": "instruction",
      "stage": "prerequisites",
      "title": "Resolve the documented monthly image refresh",
      "applies": "Every VM Marketplace product.",
      "owner": "Partner Engineer and release owner.",
      "prerequisite": "Frozen release constraints, base-image update policy and separately authorized future release plan.",
      "action": "Record the official monthly rebuild/republication instruction when Google updates base public images. Obtain current applicability guidance and an owner-approved future release plan; never rebuild or republish Frozen r232 through this guide.",
      "expected": "The maintenance obligation, current Google guidance and future-release authority are reconciled explicitly.",
      "evidence": "Dated Google guidance, maintenance owner and separate future-release decision.",
      "note": "Official wording retained; maintenance applicability/plan pending. This instruction does not thaw Frozen r232.",
      "refs": []
    },
    {
      "id": "IMG-22",
      "source": "IMAGE",
      "anchor": "",
      "locator": "consider using the open source tool Imagebuilder",
      "strength": "recommended",
      "stage": "prerequisites",
      "title": "Consider the optional image-build automation tool",
      "applies": "If automating future authorized VM image builds.",
      "owner": "Release owner.",
      "prerequisite": "Approved future build scope and chosen toolchain.",
      "action": "Consider the Imagebuilder option cited by Google and record the chosen approach; adopting it is not a required product change.",
      "expected": "Automation choice is documented without implying use or validation of Imagebuilder.",
      "evidence": "Owner tool-choice disposition and, only if adopted, scoped validation.",
      "note": "Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.",
      "refs": []
    },
    {
      "id": "GS-01",
      "source": "GS",
      "anchor": "",
      "locator": "Every product must be accompanied by a Google Cloud-specific Getting Started document",
      "strength": "required",
      "stage": "getting-started",
      "title": "Maintain a Google Cloud Getting Started page",
      "applies": "Every VM product.",
      "prerequisite": "Identify the exact proposed VM delivery and the vendor documentation owner.",
      "action": "Check that a vendor-maintained website page gives detailed Google Cloud deployment and configuration steps for that delivery.",
      "expected": "A reachable, maintained Google Cloud-specific page identifies its applicable delivery and owner.",
      "evidence": "Public URL, page revision or capture date, delivery identity and owner.",
      "owner": "VibePackr documentation owner",
      "note": "A public deployment guide exists. Its availability does not prove end-to-end reproducibility for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#scope"
        }
      ]
    },
    {
      "id": "GS-02",
      "source": "GS",
      "anchor": "",
      "locator": "We suggest that you co-brand the page with the Google Cloud logo",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Consider permitted Google Cloud co-branding",
      "applies": "Every VM product.",
      "prerequisite": "An owner decides whether co-branding is appropriate and confirms permitted brand assets.",
      "action": "Record whether the Getting Started page will use the Google Cloud logo from Partner Network Hub; note that Hub access requires registration.",
      "expected": "The optional branding choice and asset source are recorded; absence is not classified as failure of a mandatory requirement.",
      "evidence": "Branding decision and asset reference, if used.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "GS-03",
      "source": "GS",
      "anchor": "",
      "locator": "starting with the product listing page on Cloud Marketplace",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Describe the complete customer journey",
      "applies": "Every VM product.",
      "prerequisite": "The listing entry, deployment package and post-deployment procedure are identified.",
      "action": "Read the guide from the Marketplace listing through deployment, configuration and post-deployment maintenance; map each transition to the next customer action.",
      "expected": "The customer can follow an ordered journey without an unexplained transition.",
      "evidence": "Reviewed page sections and a journey checklist identifying any missing transition.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#marketplace"
        }
      ]
    },
    {
      "id": "GS-04",
      "source": "GS",
      "anchor": "",
      "locator": "We recommend including screenshots throughout the document",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Support the journey with screenshots",
      "applies": "Every VM product.",
      "prerequisite": "Screenshots are tied to an identified delivery and contain no sensitive information.",
      "action": "Check that important deployment and operation steps have relevant screenshots alongside text; mark local demonstrations with their actual scope.",
      "expected": "Screenshots show the action and resulting state without implying an untested Marketplace result.",
      "evidence": "Captioned screenshot inventory with delivery identity and capture context.",
      "owner": "VibePackr documentation owner",
      "note": "Published walkthroughs include local evidence. Local R234 or repaired Admin candidate screenshots are not proof of the frozen r232 Marketplace customer path.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#operation-guides"
        }
      ]
    },
    {
      "id": "GS-05",
      "source": "GS",
      "anchor": "",
      "locator": "The recommended machine configuration, disk sizes, and zones.",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Explain machine configuration inputs",
      "applies": "Every VM product.",
      "prerequisite": "Delivery-specific defaults, recommendations and supported choices are supplied by the product owner.",
      "action": "Check that the guide identifies recommended machine type, CPU and memory and distinguishes a reference estimate from a minimum requirement.",
      "expected": "The customer can choose the input with its purpose and scope understood.",
      "evidence": "Page section, input/default inventory and product-owner confirmation for the exact delivery.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#prepare"
        }
      ]
    },
    {
      "id": "GS-06",
      "source": "GS",
      "anchor": "",
      "locator": "The recommended machine configuration, disk sizes, and zones.",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Explain disk sizing inputs",
      "applies": "Every VM product.",
      "prerequisite": "Delivery-specific defaults, recommendations and supported choices are supplied by the product owner.",
      "action": "Check that the guide identifies boot and additional disk sizes and their roles and distinguishes a reference estimate from a minimum requirement.",
      "expected": "The customer can choose the input with its purpose and scope understood.",
      "evidence": "Page section, input/default inventory and product-owner confirmation for the exact delivery.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#storage"
        }
      ]
    },
    {
      "id": "GS-07",
      "source": "GS",
      "anchor": "",
      "locator": "The recommended machine configuration, disk sizes, and zones.",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Explain location inputs",
      "applies": "Every VM product.",
      "prerequisite": "Delivery-specific defaults, recommendations and supported choices are supplied by the product owner.",
      "action": "Check that the guide identifies recommended deployment zones and relevant regional assumptions and distinguishes a reference estimate from a minimum requirement.",
      "expected": "The customer can choose the input with its purpose and scope understood.",
      "evidence": "Page section, input/default inventory and product-owner confirmation for the exact delivery.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#deploy"
        }
      ]
    },
    {
      "id": "GS-08",
      "source": "GS",
      "anchor": "",
      "locator": "If the customer has to open any ports (particularly 80 or 443).",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Explain required ports",
      "applies": "Every VM product.",
      "prerequisite": "The product owner supplies the exact delivery network requirements.",
      "action": "List whether the customer must open ports, particularly HTTP 80 or HTTPS 443; explain the required purpose and scope without assuming either port is necessary.",
      "expected": "The guide identifies required ports and distinguishes optional or unnecessary exposure.",
      "evidence": "Network requirements table and guide section tied to the delivery.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#deploy"
        }
      ]
    },
    {
      "id": "GS-09",
      "source": "GS",
      "anchor": "",
      "locator": "Whether the required ports are opened by default",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Explain port defaults and customer actions",
      "applies": "Every VM product.",
      "prerequisite": "The required-port inventory and deployment defaults are known.",
      "action": "For each required port, state whether deployment opens it by default or the customer must select an authorized deployment option.",
      "expected": "The customer knows which action is required and can compare the deployed state with the documented default.",
      "evidence": "Per-port default/action table and corresponding deployment UI reference.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#deploy"
        }
      ]
    },
    {
      "id": "GS-10",
      "source": "GS",
      "anchor": "",
      "locator": "The document should list any additional commands needed to configure the product.",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "List additional configuration commands",
      "applies": "Every VM product.",
      "prerequisite": "A delivery-specific, supported configuration procedure has been identified.",
      "action": "Check that every additional configuration command needed after deployment is listed with prerequisites, input placeholders, expected output and the point at which to stop.",
      "expected": "The customer can identify all required configuration steps without inventing commands or substituting internal procedures.",
      "evidence": "Command inventory and corresponding guide sections; explicitly justified absence if none are needed.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#initialize"
        }
      ]
    },
    {
      "id": "GS-11",
      "source": "GS",
      "anchor": "",
      "locator": "If your product requires a login",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Explain administrator access",
      "applies": "When the product requires a login.",
      "prerequisite": "The supported customer administrator access route is defined for the delivery.",
      "action": "Explain whether and how the customer reaches an administrator page or console URL, including the supported access route and prerequisites.",
      "expected": "A first customer can identify the intended admin entry point; an unresolved bootstrap path is explicitly marked as pending.",
      "evidence": "Admin access section and delivery-specific first-customer access result when authorized testing occurs.",
      "owner": "VibePackr documentation owner",
      "note": "The published guide describes C7 as pending. A local Admin connection demonstration does not close the frozen r232 first-customer bootstrap gap.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#admin"
        }
      ]
    },
    {
      "id": "GS-12",
      "source": "GS",
      "anchor": "",
      "locator": "how login credentials can be obtained.",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Explain how login credentials are obtained",
      "applies": "When the product requires a login.",
      "prerequisite": "The product owner provides the supported first-customer credential provisioning route.",
      "action": "Document where and how the authorized customer obtains credentials and which party is responsible; do not publish secret values or substitute internal test credentials.",
      "expected": "The guide gives a usable, supported acquisition route or explicitly records the unresolved owner input.",
      "evidence": "Credential acquisition instructions and redacted first-customer verification record when available.",
      "owner": "VibePackr documentation owner",
      "note": "C7 remains a declared first-customer gap for frozen r232. This checklist does not approve a new credential or bootstrap design.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#admin"
        }
      ]
    },
    {
      "id": "GS-13",
      "source": "GS",
      "anchor": "",
      "locator": "the password must be auto-generated.",
      "strength": "conditional",
      "stage": "getting-started",
      "title": "Verify generated administrator passwords",
      "applies": "Only if a password is required to access an administrator page or console.",
      "prerequisite": "The product owner has confirmed that this password condition applies to the delivery.",
      "action": "Record how the delivery meets the auto-generated-password requirement and request redacted evidence from the approved credential flow. If no password is used, record the reason for that applicability decision.",
      "expected": "Any required administrator password is auto-generated; the applicability decision is supported.",
      "evidence": "Applicability rationale and redacted provisioning evidence, without the password itself.",
      "owner": "VibePackr documentation owner",
      "note": "Conditional Google requirement. It does not prescribe VibePackr password authentication or authorize a new authentication design.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#admin"
        }
      ]
    },
    {
      "id": "GS-14",
      "source": "GS",
      "anchor": "",
      "locator": "Can connect to the VM instance using SSH.",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Document SSH access",
      "applies": "Every VM product.",
      "prerequisite": "A supported customer SSH access route and prerequisites are identified.",
      "action": "Check that the Getting Started page explains how the customer reaches the VM through the supported SSH route and recognizes connection failure.",
      "expected": "The customer can follow a clear SSH access procedure for the exact delivery.",
      "evidence": "SSH guide section and separately recorded authorized connection result.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#access"
        }
      ]
    },
    {
      "id": "GS-15",
      "source": "GS",
      "anchor": "",
      "locator": "Can check the status or health of the app.",
      "strength": "recommended",
      "stage": "getting-started",
      "title": "Document application health checks",
      "applies": "Every VM product.",
      "prerequisite": "Supported readiness and health observations are identified for the delivery.",
      "action": "Check that the guide explains how to observe application status or health and distinguishes a running process from a ready, connected product.",
      "expected": "The customer can identify a healthy state, an incomplete state and the next supported action.",
      "evidence": "Health guide section, expected observations and authorized delivery-specific results.",
      "owner": "VibePackr documentation owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/docs/headless-operations-guide-en.html#headless-health"
        }
      ]
    },
    {
      "id": "GS-16",
      "source": "GS",
      "anchor": "",
      "locator": "email the URL of your draft to your assigned Partner Engineer for review and feedback.",
      "strength": "instruction",
      "stage": "getting-started",
      "title": "Submit the draft URL for Partner Engineer feedback",
      "applies": "Every VM product.",
      "prerequisite": "The Getting Started draft is reviewed and its assigned Partner Engineer is known.",
      "action": "Have the authorized review coordinator send the draft URL to the assigned Partner Engineer and track feedback against the same document revision. This checklist does not send a message.",
      "expected": "The assigned Partner Engineer receives the intended draft; feedback and its disposition can be traced.",
      "evidence": "Private correspondence reference, sent URL/revision, date and feedback log.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-01",
      "source": "TEST",
      "anchor": "",
      "locator": "preview and test the product.",
      "strength": "instruction",
      "stage": "preview",
      "title": "Plan a customer-view preview",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "Identify the product, image and deployment package versions under review.",
      "action": "Include a preview of the listing and deployment experience in the review plan, using the customer-facing flow.",
      "expected": "The planned preview identifies the exact delivery and what the customer will see.",
      "evidence": "Preview plan and exact product/image/package identity.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-02",
      "source": "TEST",
      "anchor": "",
      "locator": "the Cloud Storage object must be uploaded and validated in Producer Portal.",
      "strength": "required",
      "stage": "preview",
      "title": "Confirm the uploaded deployment object",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The authorized package owner supplies the intended Cloud Storage object identity.",
      "action": "Before scheduling deployment preview, request evidence that the correct Cloud Storage object was uploaded and selected in Producer Portal.",
      "expected": "The uploaded object identity matches the intended deployment package.",
      "evidence": "Private object identity, package digest/version and portal upload record.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-03",
      "source": "TEST",
      "anchor": "",
      "locator": "the Cloud Storage object must be uploaded and validated in Producer Portal.",
      "strength": "required",
      "stage": "preview",
      "title": "Confirm successful package validation",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The intended Cloud Storage object has an upload record.",
      "action": "Check the portal record for successful validation of that exact uploaded object before marking preview prerequisites satisfied.",
      "expected": "Producer Portal reports successful validation for the intended package revision.",
      "evidence": "Portal validation state, timestamp and matching object/package identity.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-04",
      "source": "TEST",
      "anchor": "",
      "locator": "verify that you've selected the correct project and have the Editor (roles/editor) role for the project.",
      "strength": "instruction",
      "stage": "preview",
      "title": "Confirm the preview project and authorized portal access",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The public project ID and authorized review operator are identified.",
      "action": "Document the Producer Portal entry for the public project. If access is unavailable, have the account owner verify the selected project and required Editor role before proceeding; this row does not grant access.",
      "expected": "The authorized operator can reach the correct product project in Producer Portal.",
      "evidence": "Redacted project selector/access confirmation and operator identity.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-05",
      "source": "TEST",
      "anchor": "",
      "locator": "On the Overview page, click Deployment package.",
      "strength": "instruction",
      "stage": "preview",
      "title": "Open the selected product deployment package",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "Portal access and the product identity are confirmed.",
      "action": "In the planned preview procedure, select the named product and open Deployment package from its Overview page.",
      "expected": "The package page belongs to the intended product and version.",
      "evidence": "Redacted product overview and package identity capture.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-06",
      "source": "TEST",
      "anchor": "",
      "locator": "Verify that your deployment package was read and validated successfully and click Deployment preview.",
      "strength": "instruction",
      "stage": "preview",
      "title": "Enter deployment preview after validation",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The exact package was read and validated successfully.",
      "action": "Include a gate that checks the successful read/validation state before the operator selects Deployment preview.",
      "expected": "The preview opens for the same successfully validated package.",
      "evidence": "Portal read/validation state and preview identity.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-07",
      "source": "TEST",
      "anchor": "",
      "locator": "Review the deployment details and click Deploy.",
      "strength": "instruction",
      "stage": "preview",
      "title": "Review preview settings before deployment",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "Preview prerequisites and a separately authorized test scope are recorded.",
      "action": "Plan to review the deployment details before the authorized operator selects Deploy; retain the selected settings and resulting deployment identity.",
      "expected": "The resulting preview uses the reviewed settings and has an observable deployment outcome.",
      "evidence": "Settings capture, deployment identity and outcome.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-08",
      "source": "TEST",
      "anchor": "",
      "locator": "verified that it behaves as you expect",
      "strength": "instruction",
      "stage": "preview",
      "title": "Verify behavior before leaving the preview",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "A preview deployment completed and its expected behavior is written down.",
      "action": "Plan a comparison of observed behavior with the stated expectations before exiting the preview; record discrepancies rather than assuming deployment success proves behavior.",
      "expected": "Observed results are linked to expected product behavior and all discrepancies are retained.",
      "evidence": "Behavior checklist, observations and discrepancy log for the preview deployment.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-09",
      "source": "TEST",
      "anchor": "",
      "locator": "Cloud Marketplace uses your original version of the VM image for your testing.",
      "strength": "google_process",
      "stage": "preview",
      "title": "Record the Marketplace-owned image distinction",
      "applies": "When Use Marketplace owned images is enabled.",
      "prerequisite": "The image ownership setting and original image identity are known.",
      "action": "Record that the vendor preview tests the original image while customers access a Google-owned copy; keep those identities distinct in the evidence.",
      "expected": "Preview proof is explicitly scoped to the original image; customer-copy equivalence is not silently assumed.",
      "evidence": "Ownership setting, original image identity and any separately supplied customer-copy correspondence.",
      "owner": "VibePackr test owner",
      "note": "The official test page explicitly distinguishes the two image paths. The exact setting for this review delivery remains owner input.",
      "refs": []
    },
    {
      "id": "TEST-10",
      "source": "TEST",
      "anchor": "",
      "locator": "To delete the preview deployment, open the Deployment Manager page and delete the deployment.",
      "strength": "instruction",
      "stage": "preview",
      "title": "Agree a current supported preview teardown procedure",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The test owner identifies preview resources and obtains the current Partner Engineer-supported teardown route.",
      "action": "Record cleanup ownership, retained evidence and the supported teardown procedure before testing. The source names the legacy Deployment Manager deletion route; confirm the current route with the Partner Engineer instead of treating that text as a live deletion instruction.",
      "expected": "The preview has an approved, current cleanup plan and its completion can be recorded without changing retained product artifacts.",
      "evidence": "Partner Engineer clarification, resource inventory, authorized cleanup procedure and later cleanup result.",
      "owner": "VibePackr test owner",
      "note": "Legacy reference retained for traceability only. No deployment or deletion is executed by this guide.",
      "refs": []
    },
    {
      "id": "TEST-11",
      "source": "TEST",
      "anchor": "",
      "locator": "We recommend you test each of your products' end-to-end flows",
      "strength": "recommended",
      "stage": "preview",
      "title": "Plan every product end-to-end flow",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The product owner lists supported customer flows and their expected outcomes.",
      "action": "Prepare a test matrix for each end-to-end flow, connecting listing entry, deployment, configuration, use and completion to an exact delivery.",
      "expected": "No supported flow is silently omitted; exclusions have an owner and rationale.",
      "evidence": "Flow inventory, delivery-bound test matrix and exclusions with rationale.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/#plan"
        }
      ]
    },
    {
      "id": "TEST-12",
      "source": "TEST",
      "anchor": "",
      "locator": "as soon as your Partner Engineer informs you that your product is ready for end-to-end testing.",
      "strength": "instruction",
      "stage": "preview",
      "title": "Obtain Partner Engineer readiness for the prescribed tests",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The assigned Partner Engineer and product delivery are identified.",
      "action": "Record the Partner Engineer notification that the product is ready for the prescribed end-to-end testing before scheduling that test phase.",
      "expected": "The test phase is tied to the Partner Engineer readiness notification.",
      "evidence": "Private notification reference, date, product identity and permitted test scope.",
      "owner": "VibePackr review coordinator / Google Partner Engineer",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-13",
      "source": "TEST",
      "anchor": "",
      "locator": "verify that all testers have access to the product.",
      "strength": "instruction",
      "stage": "preview",
      "title": "Verify access for every tester",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The intended tester roster is approved.",
      "action": "Have the account owner confirm product access for every named tester before test execution; record unavailable access as pending.",
      "expected": "Each listed tester can access the product under the intended account.",
      "evidence": "Tester roster and redacted access confirmations; no credentials.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-14",
      "source": "TEST",
      "anchor": "",
      "locator": "If the product image(s) is not in your public project",
      "strength": "conditional",
      "stage": "preview",
      "title": "Verify development-project viewer access when needed",
      "applies": "When product images are outside the public project.",
      "prerequisite": "Image project placement and the intended tester roster are confirmed.",
      "action": "Have the authorized project owner verify the documented viewer access for each tester in the development project containing the images. Record the access finding; do not create a grant from this checklist.",
      "expected": "Every intended tester has the required access to the image-bearing development project, or the condition is justified as inapplicable.",
      "evidence": "Image-project identity, applicability rationale and redacted access confirmation.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-15",
      "source": "TEST",
      "anchor": "",
      "locator": "The testers need to be users of Cloud console, and must be added to the project.",
      "strength": "required",
      "stage": "preview",
      "title": "Verify tester console and project membership",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The authorized project owner has the tester roster.",
      "action": "Request confirmation that each tester is a Cloud console user and has been added to the applicable project before testing.",
      "expected": "The roster has no unconfirmed console user or project membership entry.",
      "evidence": "Redacted roster-to-project membership confirmation.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-16",
      "source": "TEST",
      "anchor": "",
      "locator": "Ensure that the product card is visible in the search results",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Check Marketplace search visibility",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The Partner Engineer-supported test visibility and tester access are confirmed.",
      "action": "Plan to open Explore Marketplace, search for the product and record whether the intended product card appears.",
      "expected": "The correct product card appears in the tester search results.",
      "evidence": "Search term, tester visibility context, date and result capture.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-17",
      "source": "TEST",
      "anchor": "",
      "locator": "the information on the card is displayed correctly.",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Check product card content",
      "applies": "Each proposed VM product delivery.",
      "prerequisite": "The approved listing content and intended product identity are available.",
      "action": "Compare the product card information with the intended listing content and record incorrect or clipped fields.",
      "expected": "The card displays the intended product information correctly.",
      "evidence": "Card capture and field-by-field comparison to approved listing content.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-18",
      "source": "TEST",
      "anchor": "",
      "locator": "If you have more than one product",
      "strength": "conditional",
      "stage": "listing-ui",
      "title": "Distinguish multiple product listings",
      "applies": "When the vendor has more than one product.",
      "prerequisite": "The relevant product listing inventory is known.",
      "action": "Compare each product card and ensure its content can be distinguished from the vendor's other products.",
      "expected": "Customers can tell the listed products apart; applicability is documented.",
      "evidence": "Product comparison captures or a documented single-product rationale.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-19",
      "source": "TEST",
      "anchor": "",
      "locator": "The header is displayed with your name, category, estimated costs and Launch button.",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Check the product details header",
      "applies": "Each proposed VM product listing.",
      "prerequisite": "The intended listing and estimate are available.",
      "action": "From the product card, open the product details page and check the name, category, estimated costs and Launch button in the header.",
      "expected": "All four header elements are present and match the intended listing.",
      "evidence": "Header capture, listing revision and expected name/category/cost values.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-20",
      "source": "TEST",
      "anchor": "",
      "locator": "a Learn more link that points to a specific product or service page on your website.",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Check description and Learn more destination",
      "applies": "Each proposed VM product listing.",
      "prerequisite": "The intended product description and specific vendor product page are known.",
      "action": "Compare the displayed description and follow Learn more to verify that it reaches the specific product or service page.",
      "expected": "The intended description is shown and Learn more resolves to the relevant product page.",
      "evidence": "Description capture, link URL and observed destination.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-21",
      "source": "TEST",
      "anchor": "",
      "locator": "The tech stack is displayed, with the product type, version, last updated timestamp, and category ID and components, if applicable.",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Check the technology stack fields",
      "applies": "Each proposed VM product listing.",
      "prerequisite": "The exact release metadata and applicable components are supplied.",
      "action": "Check product type, version, last updated timestamp, category ID and any applicable components in the displayed technology stack.",
      "expected": "The fields are present, applicable and consistent with the delivery identity.",
      "evidence": "Technology-stack capture and comparison to delivery metadata; reasons for inapplicable components.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-22",
      "source": "TEST",
      "anchor": "",
      "locator": "The Pricing section has the price breakdown, as well as working links to pricing and free trial.",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Check price breakdown and pricing links",
      "applies": "Each proposed VM product listing.",
      "prerequisite": "The approved pricing model and any trial offer are identified.",
      "action": "Check the price breakdown and follow the pricing and free-trial links. If no trial is offered, retain the approved applicability decision rather than inventing an offer.",
      "expected": "Pricing information is visible and applicable links work; trial treatment matches the approved offer.",
      "evidence": "Pricing capture, resolved links and trial applicability rationale.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-23",
      "source": "TEST",
      "anchor": "",
      "locator": "The pricing details are correct, and the Show more arrow expands properly.",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Check pricing accuracy and expansion",
      "applies": "Each proposed VM product listing.",
      "prerequisite": "The approved price schedule and estimation assumptions are available.",
      "action": "Compare displayed pricing details with the approved schedule and expand Show more to check hidden details.",
      "expected": "Pricing values are accurate and Show more exposes the expected details.",
      "evidence": "Before/after expansion captures and price comparison.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-24",
      "source": "TEST",
      "anchor": "",
      "locator": "clearly specifies whether the support is bundled into the pricing.",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Clarify whether support is included in price",
      "applies": "Each proposed VM product listing.",
      "prerequisite": "The approved support and commercial terms are available.",
      "action": "Check that Maintenance & support explicitly states whether support is included in the listed price.",
      "expected": "A customer can determine whether the listed price includes support.",
      "evidence": "Maintenance & support capture and approved inclusion statement.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-25",
      "source": "TEST",
      "anchor": "",
      "locator": "A description of available support channels and their hours of service.",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Describe support channels and hours",
      "applies": "Each proposed VM product listing.",
      "prerequisite": "The approved support offer identifies channels and operating hours.",
      "action": "Check that Maintenance & support describes each available channel and its hours of service without implying an unapproved service level.",
      "expected": "Support channels and service hours are explicit and match the approved offer.",
      "evidence": "Support section capture and approved channel/hour reference.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-26",
      "source": "TEST",
      "anchor": "",
      "locator": "A link to your support site.",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Check the support-site link",
      "applies": "Each proposed VM product listing.",
      "prerequisite": "The intended customer support entry point is known.",
      "action": "Follow the link in Maintenance & support and verify that it reaches the intended customer support site.",
      "expected": "The support link works and the customer can identify the support entry point.",
      "evidence": "Listed support URL and observed destination.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-27",
      "source": "TEST",
      "anchor": "",
      "locator": "The Terms of service section includes a link to your End User License Agreement (EULA).",
      "strength": "instruction",
      "stage": "listing-ui",
      "title": "Check the EULA link",
      "applies": "Each proposed VM product listing.",
      "prerequisite": "The legal owner supplies the applicable EULA and its approval state.",
      "action": "Check that Terms of service links to the correct EULA and record its version and approval state; do not treat a public draft as an effective agreement.",
      "expected": "The listing points to the intended EULA and unresolved legal approval is visible.",
      "evidence": "EULA link, version, observed destination and owner-provided approval reference.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-28",
      "source": "TEST",
      "anchor": "",
      "locator": "Click Launch and fill in all of the applicable input fields to deploy the product.",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Complete the launch inputs",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "The approved test scope, deployment prerequisites and intended input values are recorded.",
      "action": "Plan to open the product details page, select Launch and complete every applicable input; retain chosen values without secrets.",
      "expected": "The deployment form accepts the applicable values and omitted fields have a documented reason.",
      "evidence": "Redacted completed-input inventory and form validation observations.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#deploy"
        }
      ]
    },
    {
      "id": "TEST-29",
      "source": "TEST",
      "anchor": "",
      "locator": "The product has the same default machine type and disk size as are specified in the pricing table",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Match deployment defaults to the pricing table",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "The current listing pricing table and unchanged launch defaults are captured.",
      "action": "Compare the default machine type and disk size in the launch form with those used in the product-details pricing table.",
      "expected": "Both default values match the pricing-table configuration.",
      "evidence": "Side-by-side pricing table and launch defaults with listing/package revisions.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-30",
      "source": "TEST",
      "anchor": "",
      "locator": "Links work correctly.",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Check links in the deployment flow",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "The relevant launch/deployment screens and intended destinations are identified.",
      "action": "Follow each customer-facing link in the deployment flow and record its destination and any failure.",
      "expected": "Each link reaches its intended accessible destination.",
      "evidence": "Link inventory with source screen, URL, destination and result.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-31",
      "source": "TEST",
      "anchor": "",
      "locator": "HTTP and HTTPS ports are checked/unchecked accurately.",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Check HTTP and HTTPS deployment choices",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "Documented network requirements and deployment defaults are available.",
      "action": "Compare HTTP and HTTPS checked/unchecked states in the deployment form with the documented requirements and defaults.",
      "expected": "Both choices reflect the intended network configuration; neither is assumed necessary by this checklist.",
      "evidence": "Form capture and per-port comparison to documented requirements.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-32",
      "source": "TEST",
      "anchor": "",
      "locator": "Deploy the product on a default machine type, and verify that the product is deployed successfully.",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Verify deployment on the default machine type",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "The test operator has a separately approved deployment scope and documented default settings.",
      "action": "Include one default-machine deployment in the test plan and record its actual completion or failure before further checks.",
      "expected": "The intended product deploys successfully using the documented default machine type.",
      "evidence": "Deployment identity, selected machine/disk settings, image/package identity and observed result.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-33",
      "source": "TEST",
      "anchor": "",
      "locator": "You can SSH into the virtual machine instance.",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Verify SSH connectivity to the deployed VM",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "The default deployment completed and supported SSH access is authorized.",
      "action": "Plan an SSH connection through the documented customer route and record the exact VM reached.",
      "expected": "The authorized tester can open an SSH session to the intended deployed VM.",
      "evidence": "Redacted connection result bound to deployment identity and access route.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#access"
        }
      ]
    },
    {
      "id": "TEST-34",
      "source": "TEST",
      "anchor": "",
      "locator": "Test the license key in an SSH session:",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Verify license metadata in the SSH session",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "The authorized tester has an SSH session to the intended VM and the expected license reference.",
      "action": "Plan the official read-only license metadata check at the instance licenses endpoint, using the Metadata-Flavor: Google header, and compare the returned license reference with the expected delivery license.",
      "expected": "The response identifies the intended license association; an empty or mismatched result is retained as a finding.",
      "evidence": "Redacted command/result record, VM identity and expected license reference.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-35",
      "source": "TEST",
      "anchor": "",
      "locator": "Application info is loaded.",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Verify loaded application information",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "The default deployment completed and its expected application information is identified.",
      "action": "Check the post-deployment application information shown to the customer and compare it with the intended product and deployment.",
      "expected": "Application information loads and identifies the correct deployed product.",
      "evidence": "Application-information capture and deployment identity.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-36",
      "source": "TEST",
      "anchor": "",
      "locator": "If the application has admin URL, log into the Admin console with the username/password.",
      "strength": "conditional",
      "stage": "deployment",
      "title": "Verify the applicable administrator login",
      "applies": "When the application exposes an administrator URL.",
      "prerequisite": "The exact delivery has a supported first-customer access and credential route.",
      "action": "Record the administrator URL and approved authentication route; plan the login test using that route. The source describes username/password; if the product uses another mechanism, obtain Partner Engineer applicability confirmation instead of inventing passwords.",
      "expected": "An authorized first customer can reach and use the intended Admin console, or the unresolved route/applicability remains explicit.",
      "evidence": "Redacted login result, access procedure and any Partner Engineer applicability decision.",
      "owner": "VibePackr test owner",
      "note": "Frozen r232 first-customer bootstrap remains blocked at C7. Local repaired Admin candidate evidence is a separate scope and is not substituted for this result.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#admin"
        }
      ]
    },
    {
      "id": "TEST-37",
      "source": "TEST",
      "anchor": "",
      "locator": "Check that the specified ports are opened.",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Verify specified ports after deployment",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "The declared port inventory and separately authorized network observation scope are available.",
      "action": "Plan a comparison of observed port exposure with the documented specified ports after deployment, retaining the network context.",
      "expected": "Specified ports are open in the expected scope, with unexpected results recorded.",
      "evidence": "Port observation record, source/destination context and comparison to the declared configuration.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-38",
      "source": "TEST",
      "anchor": "",
      "locator": "Repeat above steps for different instance sizes (especially large and small) and regions.",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Repeat the deployment checks across instance sizes",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "The product owner and Partner Engineer establish supported small and large instance test choices.",
      "action": "Include different instance sizes, especially small and large, in the matrix and repeat the applicable deployment checks for each.",
      "expected": "Each selected size has its own deployment and post-deployment result; untested sizes are visible.",
      "evidence": "Size matrix with configuration, delivery identity, per-check results and exclusions.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-39",
      "source": "TEST",
      "anchor": "",
      "locator": "Repeat above steps for different instance sizes (especially large and small) and regions.",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Repeat the deployment checks across regions",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "Supported regions and the authorized test matrix are agreed.",
      "action": "Include multiple agreed regions and repeat the applicable deployment checks in each; record the exact region and zone.",
      "expected": "Each selected region has a traceable result; a single-region result is not presented as all-region proof.",
      "evidence": "Region/zone matrix with delivery identity, configuration, per-check results and exclusions.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-40",
      "source": "TEST",
      "anchor": "",
      "locator": "Repeat the above steps with cloned instances (cloned hard drives).",
      "strength": "instruction",
      "stage": "deployment",
      "title": "Repeat checks on cloned instances",
      "applies": "Each proposed VM deployment package.",
      "prerequisite": "A supported cloning route, test scope and cleanup disposition are agreed.",
      "action": "Add cloned instances or cloned hard drives to the plan and repeat the applicable deployment-flow checks against their recorded lineage.",
      "expected": "The cloned-instance path has its own results; original-instance proof is not reused as clone proof.",
      "evidence": "Original-to-clone identity mapping, per-check results and cleanup disposition.",
      "owner": "VibePackr test owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "TEST-41",
      "source": "TEST",
      "anchor": "",
      "locator": "then you must also test these steps",
      "strength": "conditional",
      "stage": "deployment",
      "title": "Test every documented post-deployment step",
      "applies": "When the Getting Started guide specifies post-deployment next steps.",
      "prerequisite": "The delivery-bound Getting Started revision and post-deployment step inventory are identified.",
      "action": "Map every documented post-deployment step to an authorized test and record its actual result, including required AI, storage, administrator and health steps when present.",
      "expected": "All applicable next steps are tested so successful deployment completion is supported; untested steps remain pending.",
      "evidence": "Guide-step-to-result crosswalk with exact delivery and document revision, outputs and unresolved findings.",
      "owner": "VibePackr test owner",
      "note": "The public guide identifies pending customer AI, storage and administrator boundaries. Recorded local demonstrations do not establish completion of those steps on the review delivery.",
      "refs": [
        {
          "label": "Related VibePackr guidance",
          "url": "https://www.vibepackr.com/guides/poc/deployment.html#ready"
        }
      ]
    },
    {
      "id": "SUB-01",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "reviewed and met all the requirements for listing your product.",
      "strength": "instruction",
      "stage": "submission",
      "title": "Reconcile listing prerequisites",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The current official listing-requirements inventory and exact product are identified.",
      "action": "Review the listing prerequisite mapping and request evidence for each applicable requirement; unresolved rows remain pending before submission.",
      "expected": "The listing prerequisite set has itemized evidence and an accountable disposition for every applicable requirement.",
      "evidence": "Completed prerequisite crosswalk, supporting private evidence references and unresolved items.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-02",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "reviewed and met all the requirements for packaging your product.",
      "strength": "instruction",
      "stage": "submission",
      "title": "Reconcile packaging prerequisites",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The current official packaging-requirements inventory and exact image/package are identified.",
      "action": "Review the packaging prerequisite mapping against the exact image and deployment package; do not use documentation existence as package compliance evidence.",
      "expected": "Every applicable packaging requirement has a delivery-bound result or explicit unresolved disposition.",
      "evidence": "Packaging crosswalk, exact image/package identities and private verification references.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-03",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Configure payments so that you can be paid for your product's usage.",
      "strength": "instruction",
      "stage": "submission",
      "title": "Confirm payment setup",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The authorized commercial owner and payments configuration scope are identified.",
      "action": "Request the commercial owner's confirmation that the required payment setup is complete for the product and legal entity. Keep financial and account data in private records.",
      "expected": "The submission has an owner-confirmed payment setup record, with unresolved items visible.",
      "evidence": "Private setup completion reference, legal-entity/product association and commercial owner confirmation.",
      "owner": "VibePackr commercial owner",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-04",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Test your product end-to-end.",
      "strength": "instruction",
      "stage": "submission",
      "title": "Reconcile end-to-end results before submission",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The exact delivery, authorized test matrix and recorded results are available.",
      "action": "Review every applicable preview, listing, deployment and post-deployment row before submission. Keep unsuccessful, not-run and inapplicable cases distinct.",
      "expected": "The end-to-end submission record reflects actual results, not a documentation completion score.",
      "evidence": "Delivery-bound test matrix, unresolved findings and owner decisions for exclusions.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-05",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Product details",
      "strength": "required",
      "stage": "submission",
      "title": "Obtain the Product Details component review",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The intended Product Details revision and its prerequisite records are identified.",
      "action": "Include Product Details in the component-review checklist and retain the corresponding Producer Portal result before publication.",
      "expected": "The exact component revision has a traceable review state; submission and approval are recorded separately.",
      "evidence": "Portal component name, revision, state, date and any required changes.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-06",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Pricing",
      "strength": "required",
      "stage": "submission",
      "title": "Obtain the Pricing component review",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The intended Pricing revision and its prerequisite records are identified.",
      "action": "Include Pricing in the component-review checklist and retain the corresponding Producer Portal result before publication.",
      "expected": "The exact component revision has a traceable review state; submission and approval are recorded separately.",
      "evidence": "Portal component name, revision, state, date and any required changes.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-07",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Deployment package",
      "strength": "required",
      "stage": "submission",
      "title": "Obtain the Deployment Package component review",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The intended Deployment Package revision and its prerequisite records are identified.",
      "action": "Include Deployment Package in the component-review checklist and retain the corresponding Producer Portal result before publication.",
      "expected": "The exact component revision has a traceable review state; submission and approval are recorded separately.",
      "evidence": "Portal component name, revision, state, date and any required changes.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-08",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "You can submit the following reviews in any order",
      "strength": "google_process",
      "stage": "submission",
      "title": "Track component reviews independently",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The Product Details, Pricing and Deployment Package review rows are present.",
      "action": "Plan component reviews in the order appropriate for their readiness, while tracking each state separately. Do not treat one completed review as completion of the other components.",
      "expected": "The review tracker permits independent ordering and identifies which component reviews remain open.",
      "evidence": "Component review tracker with independent states, revisions and next actions.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-09",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "verifying that your image deploys and uninstalls successfully",
      "strength": "google_process",
      "stage": "submission",
      "title": "Track Google installation verification",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The exact submitted image and Google review record are identified.",
      "action": "Reserve a field for Google's image deployment verification result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.",
      "expected": "Google's image deployment verification outcome and any requested changes are traceable to the submitted image.",
      "evidence": "Google review outcome or correspondence reference, image identity and finding disposition.",
      "owner": "Google Cloud Marketplace review team",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-10",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "verifying that your image deploys and uninstalls successfully",
      "strength": "google_process",
      "stage": "submission",
      "title": "Track Google uninstallation verification",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The exact submitted image and Google review record are identified.",
      "action": "Reserve a field for Google's image uninstallation verification result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.",
      "expected": "Google's image uninstallation verification outcome and any requested changes are traceable to the submitted image.",
      "evidence": "Google review outcome or correspondence reference, image identity and finding disposition.",
      "owner": "Google Cloud Marketplace review team",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-11",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "running unit tests",
      "strength": "google_process",
      "stage": "submission",
      "title": "Track Google unit testing",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The exact submitted image and Google review record are identified.",
      "action": "Reserve a field for Google's unit testing result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.",
      "expected": "Google's unit testing outcome and any requested changes are traceable to the submitted image.",
      "evidence": "Google review outcome or correspondence reference, image identity and finding disposition.",
      "owner": "Google Cloud Marketplace review team",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-12",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "scanning your VM image for vulnerabilities",
      "strength": "google_process",
      "stage": "submission",
      "title": "Track Google vulnerability scanning",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The exact submitted image and Google review record are identified.",
      "action": "Reserve a field for Google's VM image vulnerability scanning result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.",
      "expected": "Google's VM image vulnerability scanning outcome and any requested changes are traceable to the submitted image.",
      "evidence": "Google review outcome or correspondence reference, image identity and finding disposition.",
      "owner": "Google Cloud Marketplace review team",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-13",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "after you upload it",
      "strength": "google_process",
      "stage": "submission",
      "title": "Track automatic validation after package upload",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The exact uploaded package revision is identified.",
      "action": "Record the portal result of the automatic deployment-package validation triggered by upload. Keep uploading and successful validation as separate states.",
      "expected": "The upload has a corresponding automatic validation result for the same package.",
      "evidence": "Upload record, package identity and automatic validation state.",
      "owner": "Google Cloud Marketplace validation service",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-14",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "each time that you make a subsequent update to the package.",
      "strength": "google_process",
      "stage": "submission",
      "title": "Track validation for every package update",
      "applies": "Whenever the deployment package is updated.",
      "prerequisite": "The prior and updated package revisions are identified.",
      "action": "Record the automatic validation result for each subsequent package update; do not carry a prior revision's success into the updated revision.",
      "expected": "Every updated revision has its own validation result.",
      "evidence": "Revision history, update identity and per-revision validation states.",
      "owner": "Google Cloud Marketplace validation service",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-15",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "it marks this review as complete in Producer Portal.",
      "strength": "google_process",
      "stage": "submission",
      "title": "Confirm portal completion after package validation",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "Successful validation of the current package is evidenced.",
      "action": "Check the Deployment Package review state that Producer Portal marks complete after successful validation; retain its exact revision.",
      "expected": "The portal completion state corresponds to successful validation of the intended current package.",
      "evidence": "Portal completion capture and matching validation/package identity.",
      "owner": "Google Cloud Marketplace validation service",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-16",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "thoroughly test your product after validation is complete",
      "strength": "recommended",
      "stage": "submission",
      "title": "Test after package validation and before publication submission",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "The current package validation is complete and its identity is fixed.",
      "action": "Schedule thorough product tests after validation and before submitting for publication, and bind the results to that validated revision.",
      "expected": "The post-validation test results apply to the package being submitted for publication.",
      "evidence": "Validated package identity, dated test matrix and recorded results before publication submission.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-17",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "After Google has approved your product's component reviews",
      "strength": "required",
      "stage": "submission",
      "title": "Gate private publication on component approvals",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "All component-review states and exact revisions are available.",
      "action": "Check that Google has approved the product component reviews before the coordinator plans private publication for final testing and review.",
      "expected": "Private publication is gated by the required component approvals, with unresolved reviews visible.",
      "evidence": "Component approval references, revision binding and private-publication readiness decision.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-18",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Click Publish. This notifies Google that your product is ready for final review before publication.",
      "strength": "instruction",
      "stage": "submission",
      "title": "Plan private Publish for Google final review",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "Google component approvals and separately authorized submission action are recorded.",
      "action": "In the authorized submission procedure, open the product Overview in Producer Portal and select Publish to notify Google for final testing and review. Record this as private publication, not public launch.",
      "expected": "Google is notified for final review and the product is privately published for that stage.",
      "evidence": "Private Publish confirmation, date, delivery identity and Google final-review reference.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-19",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Navigate to the page you'd like to make changes to.",
      "strength": "conditional",
      "stage": "submission",
      "title": "Identify the review affected by a requested change",
      "applies": "When a product mistake is found or Google requests a change after submission.",
      "prerequisite": "The requested change, relevant page and submitted revision are identified.",
      "action": "Record the correction request and identify the exact product page and component review affected before planning the change.",
      "expected": "Each requested change has an identified target and affected review.",
      "evidence": "Change request, page/component mapping and prior submitted revision.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-20",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Click Acknowledge to acknowledge that you must re-submit the corresponding review",
      "strength": "conditional",
      "stage": "submission",
      "title": "Acknowledge the resubmission consequence",
      "applies": "When changing a product page after submission.",
      "prerequisite": "The affected review and authorized change scope are identified.",
      "action": "Include the Acknowledge step in the change procedure so the owner explicitly accepts that the corresponding review must be resubmitted.",
      "expected": "The change record shows acknowledgment of the required resubmission.",
      "evidence": "Acknowledgment record and affected review identity.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-21",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Make any intended changes to your product.",
      "strength": "conditional",
      "stage": "submission",
      "title": "Record the intended post-submission changes",
      "applies": "When an authorized post-submission correction is needed.",
      "prerequisite": "The exact requested change and corresponding review are identified and acknowledged.",
      "action": "Have the responsible owner apply only the intended correction through the approved change procedure; preserve before/after revision identities in the review record.",
      "expected": "The changed revision corresponds to the intended correction and its scope is reviewable.",
      "evidence": "Change summary, before/after identities and owner authorization reference.",
      "owner": "VibePackr review coordinator",
      "note": "This is a review-process checklist. It does not authorize changes to the frozen Golden or product artifacts.",
      "refs": []
    },
    {
      "id": "SUB-22",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Re-submit the affected review for approval.",
      "strength": "conditional",
      "stage": "submission",
      "title": "Resubmit the affected component review",
      "applies": "After an acknowledged post-submission change.",
      "prerequisite": "The changed revision and affected review are recorded.",
      "action": "Include resubmission of the affected review in the authorized submission plan and retain the new approval result separately from the previous revision.",
      "expected": "The updated revision has a resubmission record and its own review disposition.",
      "evidence": "Resubmission reference, changed revision, review outcome and remaining feedback.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-23",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "After all reviews have been approved",
      "strength": "required",
      "stage": "submission",
      "title": "Gate public launch on all review approvals",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "Component and final-review results for the exact intended delivery are available.",
      "action": "Verify all review approvals before planning public launch; private publication and document completion do not satisfy this gate.",
      "expected": "The public-launch checklist has complete review approval references for the intended delivery.",
      "evidence": "All-review approval matrix, final-review outcome and delivery identity.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-24",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Click Enable public display.",
      "strength": "instruction",
      "stage": "submission",
      "title": "Plan Enable public display",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "All reviews are approved and the product owner authorizes public launch separately.",
      "action": "In the authorized launch procedure, open the product Overview in Producer Portal and select Enable public display.",
      "expected": "The portal presents the next public-launch confirmation for the approved product.",
      "evidence": "Portal action record tied to the approved delivery and launch authorization.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-25",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "If you don't see this button, verify that you've published your product privately.",
      "strength": "conditional",
      "stage": "submission",
      "title": "Resolve a missing Enable public display control",
      "applies": "When Enable public display is not visible.",
      "prerequisite": "The product Overview and current publication state are known.",
      "action": "Check the private-publication record first and route any remaining portal-state mismatch to the review coordinator or Partner Engineer; do not infer public readiness from a missing control.",
      "expected": "The missing-control finding is tied to the actual private-publication state and an explicit next action.",
      "evidence": "Portal state capture, private Publish record and any clarification.",
      "owner": "VibePackr review coordinator",
      "note": "Not yet evidenced for the exact Marketplace review delivery.",
      "refs": []
    },
    {
      "id": "SUB-26",
      "source": "SUBMIT",
      "anchor": "",
      "locator": "Click Make public.",
      "strength": "instruction",
      "stage": "submission",
      "title": "Record the final Make public action",
      "applies": "Every proposed VM product submission.",
      "prerequisite": "All reviews are approved, private review is complete and the exact public launch is authorized.",
      "action": "Include Make public as the final authorized portal action after Enable public display; verify and record the resulting public listing instead of assuming the action alone proves availability.",
      "expected": "The approved product is publicly visible and the actual publication state is recorded.",
      "evidence": "Make public confirmation, public listing URL, observed visibility, timestamp and delivery identity.",
      "owner": "VibePackr review coordinator",
      "note": "Public website documentation is available. This is not evidence that the Marketplace product has been approved or made public.",
      "refs": []
    }
  ]
}
