Proof

Brand, technology and AI, with the working shown.

No. 01 Thresholds

The numbers that decide whether work ships

Four thresholds we check before anything goes live, for speed, for email, for AI agents and for accessibility, and where each one is written down.

Read
4 min
Stories
4
Get Proof by email
A long corridor of concrete doorways, one inside the next, in hard light and shadow.
Photograph: Haberdoedas / Unsplash

From the editor

Every programme we run has a handful of numbers that decide go or no-go. They are rarely the numbers in the deck. They are thresholds someone else has already published: a browser team, a mailbox provider, a standards body. They are easy to miss until a launch fails one.

This first issue collects four of them. For each, the number, where it is written down, and the check we run before we trust it. That is the shape every issue will take: one shift per story, the source linked, and anything we cannot confirm marked as such.

The Xterra Edze studio

Story 1 of 4, Technology: Two hundred milliseconds

Since 12 March 2024, Interaction to Next Paint (INP) has been a Core Web Vital, replacing First Input Delay. FID only measured the wait before the first interaction was handled. INP observes every click, tap and key press in a visit and reports one of the slowest, so a page that feels quick on arrival and sluggish afterwards can no longer hide it.

Interaction to Next Paint (INP)
≤ 200 ms
Largest Contentful Paint (LCP)
≤ 2.5 s
Cumulative Layout Shift (CLS)
≤ 0.1

“Good” thresholds, measured at the 75th percentile of page loads. Source: web.dev (Google), Web Vitals, as they stand since 12 March 2024, when INP replaced FID.

The usual culprits are long tasks on the main thread: a tag manager loading a dozen scripts, a consent banner that blocks input while it decides, a carousel that re-renders on every tap. Breaking work into smaller tasks, and deferring whatever the first interaction does not need, moves INP more than a faster server does.

What we check: field data, not only a lab score. A page can pass Lighthouse on a fast laptop and fail INP on the mid-range phones most of its visitors use. We read the 75th percentile from real-user data before a launch is signed off, and we treat a third-party script that pushes INP past 200 ms as a defect, not a trade-off.

Story 2 of 4, Martech: Below 0.3 per cent

Gmail’s guidelines for anyone sending more than 5,000 messages a day to Gmail accounts set three conditions. Authenticate the domain with SPF, DKIM and DMARC. Support one-click unsubscribe, with a visible unsubscribe link in the message body. And keep the spam rate reported in Postmaster Tools below 0.3 per cent, ideally below 0.1.

Messages a day to Gmail accounts: where the bulk-sender rules begin
5,000+
Spam rate reported in Postmaster Tools, at all times
< 0.3%
The rate Google recommends staying under
< 0.1%

Source: Email sender guidelines, Gmail Help; required of bulk senders since February 2024.

What we check: that every marketing message carries the List-Unsubscribe and List-Unsubscribe-Post headers described in RFC 8058, that an unsubscribe takes effect without a login, and that suppression runs before a send rather than after it. This newsletter works the same way: double opt-in, an unsubscribe link in every issue, and the one-click headers for the mail apps that support them.

Story 3 of 4, AI: A pass mark set before the test

The 2025 edition of the OWASP Top 10 for LLM Applications puts prompt injection first, as LLM01, and lists Excessive Agency as LLM06: an AI system given more functions, permissions or autonomy than its task needs. Neither is fixed by a better prompt. Both are tested for.

  • Write the evaluation set before building the agent, including attempts to slip instructions in through documents and tool results.
  • Agree the pass mark in advance, and what happens below it, so that a good demo cannot move it.
  • Give each tool the narrowest permission it needs, and put a person in front of anything that cannot be undone.

In practice that means a small, versioned set of test cases for each behaviour: answers the agent must give, actions it must refuse, data it must never reveal. The set runs on every change to the prompt, the model or the tools, and the results are kept with the release.

What we check: that the threshold was written down before anyone saw a result. A pass rate chosen after the fact is a description, not a test.

Story 4 of 4, Product: Twenty-four by twenty-four

WCAG 2.2, a W3C Recommendation since 5 October 2023, added nine success criteria. One of them, Target Size (Minimum) at level AA, asks for pointer targets of at least 24 by 24 CSS pixels, with exceptions such as enough space around a smaller target. The contrast minimum is unchanged: 4.5:1 for body text and 3:1 for large text.

The size of the target for pointer inputs is at least 24 by 24 CSS pixels, except when…

WCAG 2.2, success criterion 2.5.8

Two more of the new criteria are worth a look on any sign-up or checkout. Focus Not Obscured (Minimum) stops a sticky header or a cookie banner from hiding the field a keyboard user is on. Accessible Authentication (Minimum) means a log-in must not depend on remembering or transcribing something unless there is help, such as letting a password manager fill the field.

What we check: the smallest things on the page, such as close buttons, pagination and links packed into tables, on a phone, with a thumb. We design touch targets at 44 pixels, which clears the minimum with room to spare.

Worth reading. The sources behind this issue.

From the studio. Related work and writing.

Proof

Get the next issue. Free, monthly, easy to leave.

One issue a month in your inbox, after you confirm by email. Choose topics if you like, or none for every story.

Choose topics (optional)

We keep your address, any topics you choose, this page and when you agreed, with your IP address and browser as the record of that agreement. Privacy notice

Let’s build what happens next.

Tell us what you’re building. We’ll answer straight.

Book a discovery call

Three ways to start

  1. 01About 2 minutes

    A quick question

    You get A reply from a lead, not a sales queue

  2. 02About 8 minutesMost useful

    A project brief

    You get Options and a first scope after one call

  3. 03About 15 minutes

    A formal RFQ or RFP

    You get Receipt confirmed and a named bid lead

Every engagement starts with a written scope and a quote agreed before work begins. How each package is priced