Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
petrkindlmann avatar

Test Data Management

  • 255 installs
  • 55 repo stars
  • Updated June 10, 2026
  • petrkindlmann/qa-skills

Test Data Management is a QA skill that defines factory, fixture, seeding, and anonymization patterns so automated tests can run on isolated deterministic data.

About

Test Data Management is a QA skill for factories, fixtures, synthetic data, database seeding, anonymization, and cleanup. It helps engineers escape flaky shared fixtures and unsafe production copies by giving each test isolated, deterministic data. Reach for it when setting up Fishery or FactoryBot, masking PII for staging, or designing parallel-safe teardown. It explicitly defers DB migration testing and environment provisioning to sibling skills.

  • Fishery, FactoryBot, and Factory Boy patterns with faker
  • GDPR-minded anonymization pipeline and compliance checklist
  • Idempotent seed scripts and per-test vs per-suite strategies
  • Cleanup via rollback, truncate, or API teardown for E2E

Test Data Management by the numbers

  • 255 all-time installs (skills.sh)
  • +51 installs in the week ending Aug 4, 2026 (Skillselion tracking)
  • Ranked #759 of 2,153 Testing & QA skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/petrkindlmann/qa-skills --skill test-data-management

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs255
repo stars55
Last updatedJune 10, 2026
Repositorypetrkindlmann/qa-skills

How do you create realistic test data that stays isolated, parallel-safe, and free of production PII?

Designs factories, fixtures, anonymization, seeds, and cleanup for isolated deterministic test data.

Who is it for?

QA and backend engineers designing factories, seeds, or anonymization for unit, integration, and E2E suites.

Skip if: Database schema migration validation or full test-environment provisioning without a data strategy focus.

When should I use this skill?

The user mentions test data, fixtures, factories, seed data, synthetic data, or data anonymization for tests.

What you get

A test data plan with factory/fixture choices, seed and cleanup strategy, and anonymization steps where needed.

Files

SKILL.mdMarkdownGitHub ↗

<objective> Create, maintain, and clean up test data that is deterministic, isolated, realistic, and safe. Good test data is the foundation of reliable tests -- without it, tests are either flaky (shared mutable state), unrealistic (hardcoded nonsense values), or dangerous (production PII in test environments). This skill delivers factories, fixtures, idempotent seeds, anonymization pipelines, and cleanup strategies that survive parallel execution. </objective>

---

Quick Route

SituationGo to
Need fresh entity data with per-test overridesFactory Patterns → references/factories.md
Mocking an API response or golden fileFixture Strategies → references/factories.md
Copying production data anywhere non-prodData Anonymization
Populating a test DB / reference data idempotentlyDatabase Seeding → references/seeding-and-synthetic.md
Cleaning up after tests / parallel isolationCleanup Strategies → references/seeding-and-synthetic.md
Generating edge cases and boundary valuesSynthetic Data → references/seeding-and-synthetic.md

---

Discovery Questions

Before designing a test data strategy, understand the current state. Check .agents/qa-project-context.md first -- if it exists, use it as the foundation and skip questions already answered there.

Current Data Practices

  • How is test data created today? (manually, scripts, copy of production, none)
  • Do tests share data or does each test create its own?
  • How is test data cleaned up? (truncate, rollback, manual, never)
  • Are there seed scripts? Are they idempotent?

Privacy and Compliance

  • Does the product handle PII? (names, emails, addresses, phone numbers, SSNs)
  • Are there GDPR, HIPAA, PCI-DSS, or other data protection requirements?
  • Is production data ever used in test environments?

Scale and Complexity

  • How large are the test datasets? (dozens of records, thousands, millions)
  • How complex are the data relationships? (simple CRUD, deep nested hierarchies, polymorphic)
  • Are there cross-service data dependencies? (microservices sharing data)

---

Core Principles

1. Each Test Owns Its Data

Tests that rely on pre-existing shared data are fragile. When Test A modifies shared data, Test B breaks. Every test should create exactly the data it needs, verify against that data, and clean up after itself. This enables parallel execution and eliminates ordering dependencies.

2. Factories Over Fixtures for Dynamic Data

Static fixtures (JSON/YAML files) are appropriate for reference data that does not change (country codes, currency lists). For entity data that tests create and manipulate (users, orders, products), use factory functions that generate fresh instances with sensible defaults and allow per-test overrides.

3. Anonymize Production Data Before Use

Production databases contain the most realistic data, but they also contain real user information. Never copy production data to test environments without anonymization. Replace PII with synthetic equivalents while preserving data distributions and relationships.

4. Deterministic Data Enables Reproducible Tests

Tests should produce the same results regardless of when or where they run. Avoid Math.random(), Date.now(), or auto-increment IDs in assertions. Use seeded random generators (faker.seed(n)), fixed timestamps, factory sequences, and -- when an ID must be a UUID you assert on -- a seeded faker.string.uuid() so it stays stable across runs.

5. Minimize Data, Maximize Signal

Create only the data each test needs. A test for user search does not need a complete user profile with billing address, payment method, and order history. Over-specified test data obscures the intent of the test and increases maintenance burden.

---

Factory Patterns

Factories are functions that produce test data with sensible defaults, allowing individual tests to override only what matters for their scenario. Fishery (2.4.0) is the default for TypeScript, FactoryBot (6.6.0) for Ruby, factory-boy (3.3.3) for Python; all pair with faker (v10.4.0) for realistic field values.

See references/factories.md for the full Fishery (with associations and deterministic UUIDs), FactoryBot (User + Product out_of_stock/discounted traits), Factory Boy (class Params + Trait), and Playwright fixture implementations. The shape every factory follows:

  • Defaults + overridesFactory.define produces sensible defaults; tests pass overrides for the one field they care about (userFactory.build({ role: 'admin' })).
  • Sequences for unique fieldssequence (Fishery), sequence(:email) (FactoryBot), factory.Sequence (Factory Boy) — never hardcode IDs or emails.
  • Traits for variants — name common states (:admin, :inactive, out_of_stock, discounted) instead of spawning a fixture file per combination.
  • Associations — one factory builds another (an order builds its user), keeping referential structure without manual wiring.

When to Use Factories vs Fixtures

ScenarioFactoriesStatic Fixtures
Entity data that tests create/modifyYesNo
Reference data (countries, currencies, configs)NoYes
Data with many variations per testYesNo -- file explosion
Data with complex relationshipsYes -- associationsNo -- hard to maintain
API response mocksNoYes -- JSON fixtures
Snapshot/golden file comparisonsNoYes

Decision rule: If the data has a lifecycle (created, modified, deleted during tests), use a factory. If the data is read-only reference material, use a fixture file.

---

Fixture Strategies

Three fixture shapes, all in references/factories.md:

  • Static fixtures (JSON/YAML) — best for API response mocks (page.route + route.fulfill), config data, and golden file comparisons.
  • Dynamic fixtures (Playwright)test.extend creates data via API before the test and deletes it after await use(...). The standard per-test setup/teardown.
  • Fixture composition — combine factory-built data (userFactory.build(), orderFactory.buildList(3)) inside a single test.extend that seeds and cleans up in one step.

---

Data Anonymization

When production data is needed for realistic testing, anonymize it before use.

PII Masking Rules

Data TypeAnonymization MethodExample
EmailFaker email with original domain patternjane.doe@acme.com -> user-7291@test.example.com
Full nameFaker nameJane Doe -> Alice Johnson
Phone numberFaker phone, preserve format+1-555-123-4567 -> +1-555-987-6543
AddressFaker address, preserve country/region123 Main St, NYC -> 456 Oak Ave, NYC
SSN/National IDTest pattern123-45-6789 -> 000-00-0001
Credit cardTest card numbers4111-... -> 4242-4242-4242-4242
Date of birthShift by fixed offset1990-03-15 -> 1987-07-22

The anonymization pipeline -- seeded Faker for determinism, an in-memory lookup table, parent-records-first ordering, and a wrapping transaction -- is in references/seeding-and-synthetic.md (Anonymization with Faker.js, Referential Integrity During Anonymization). Anonymizing a user's email must also update that email everywhere it is referenced (orders, comments, audit logs); process parents first, children second, using the same lookup, all inside one transaction.

GDPR Compliance Checklist

  • [ ] No real PII exists in any non-production environment
  • [ ] Anonymization is irreversible (no lookup table mapping back to originals is stored)
  • [ ] Anonymization preserves data distributions (age ranges, geographic spread) for realistic testing
  • [ ] Anonymized data cannot be re-identified through combination of quasi-identifiers
  • [ ] Data retention policies apply to test environments (auto-delete after N days)
  • [ ] The anonymization pipeline runs automatically, not manually (eliminates human error)

---

Database Seeding

Idempotent Seed Scripts

Seed scripts must be safe to run multiple times without duplicating data. Use upsert -- INSERT ... ON CONFLICT (natural_key) DO UPDATE SET ... -- keyed on a stable natural key, not the primary key. A DELETE-then-INSERT "reset" is not idempotent: it breaks foreign keys and reassigns serial IDs. See references/seeding-and-synthetic.md (Idempotent Seed Scripts) for the full INSERT ... ON CONFLICT (code) DO UPDATE countries/currencies example and the reasoning.

Database Branching (DB-as-a-Service)

If your prod DB lives on Neon, Supabase, or PlanetScale, branching can give a PR its own database instead of seeding from scratch -- but the providers differ on whether the branch carries data:

  • Neon Branching — copy-on-write Postgres branches in seconds, with data; ideal for ephemeral preview envs. The strongest "PR gets a real DB copy" story.
  • Supabase Branchingsupabase branches create pr-123 clones schema and (optionally, from a backup) data; preview env points at the branch URL.
  • PlanetScale Branching — MySQL branches are schema-only by default (no data), so you still seed the branch. Note: PlanetScale removed its free Hobby tier (April 2024); MySQL now starts at ~$39/mo, Postgres ~$5/mo.

Pair with the Preview Environments pattern in test-environments.

Avoid: Snaplet (hosted) — shut down 31 Aug 2024; the team joined Supabase. @snaplet/seed
lives on as supabase-community/seed (community-maintained, last meaningful release v0.98.0,
July 2024, no feature work since). For new projects, prefer the DB-branching providers above
plus factory-generated seeds.

Per-Test vs Per-Suite Data

StrategyWhen to UseProsCons
Per-test setup/teardownTests that modify dataFull isolation, parallel-safeSlower, more setup code
Per-suite seedRead-only reference dataFast, simpleCannot be modified by tests
Per-worker seedPlaywright parallel workersBalances speed and isolationRequires worker-scoped fixtures
Global seedEnvironment bootstrapRuns once, sets up baselineMust be idempotent, shared state risk

For the worker-scoped fixture (test.extend with { scope: 'worker' }) that powers per-worker seeding, see references/factories.md (Worker-Scoped Seeding).

Cleanup Strategies

StrategyWhen to useSpeed
Transaction rollbackUnit/integration tests with direct DB accessFastest
Truncation (TRUNCATE ... CASCADE)Resetting tables between suitesMedium
API-based cleanupE2E tests with no direct DB accessSlowest

Transaction rollback cannot clean up E2E tests -- the app opens its own DB connections, so a test-side transaction can't undo the app's writes; use API-based cleanup (delete in reverse creation order) there. All three implementations are in references/seeding-and-synthetic.md (Cleanup Strategies).

---

Synthetic Data Generation

Factories should make it easy to generate edge cases and boundary values without hand-writing them per test. The reusable arrays and helpers -- edgeCaseStrings (empty, whitespace, very long, XSS, SQL injection, null/control chars, RTL override), edgeCaseDates, and boundaryValues(min, max) driving a test.each -- are in references/seeding-and-synthetic.md (Synthetic Data Generation).

---

Anti-Patterns

Shared Mutable Test Data

Multiple tests reading and writing the same database rows. Test A creates a user, Test B modifies it, Test C asserts on the original state and fails. Fix by having each test create its own data through factories.

Production Data Without Anonymization

Copying the production database to staging for "realistic testing." This violates GDPR, risks data breaches in less-secured environments, and creates compliance liability. Always anonymize before use, or generate synthetic data that matches production distributions.

Non-Deterministic Data

Using Math.random() or Date.now() in test data creation without seeding. Tests pass on Monday and fail on Tuesday because the random name generated happens to exceed a field length limit. Use seeded Faker instances and fixed timestamps.

No Cleanup Strategy

Tests that create data and never clean it up. The test database grows until it affects performance, or stale data causes false positives in other tests. Every data creation must have a corresponding cleanup.

Fixture File Explosion

Creating a separate JSON fixture file for every test variation. Instead of user-admin.json, user-inactive.json, user-admin-inactive.json, use a factory with traits. Fixtures should be reserved for static reference data and API response mocks.

Over-Specified Test Data

Creating a complete user object with 30 fields when the test only cares about role. This obscures intent and makes tests brittle. Factories with sensible defaults solve this: override only what the test cares about.

Hard-Coded IDs

Using userId: '1' in tests. This couples tests to database state and breaks when running in parallel (ID collision) or against a database with existing data. Use factory sequences or seeded UUIDs (see Core Principle 4).

---

Verification

Prove the data layer is deterministic, isolated, and PII-free, smallest check first:

1. Seeds are idempotent — run the seed twice back-to-back and diff the row counts: psql -c "SELECT count(*) FROM countries" && <seed> && psql -c "SELECT count(*) FROM countries" returns the same number both times and exits 0. A growing count means a missing ON CONFLICT. 2. No shared mutable state — run the suite under parallelism and randomized order: npx playwright test --workers=4 (or pytest -n auto -p randomly) stays green. A failure that only appears here is an ordering or shared-data dependency. 3. Determinism holds — run the same data-generating test twice; with faker.seed(n) set, generated names/IDs/UUIDs match across runs. If they drift, an unseeded Faker call or Date.now()/crypto.randomUUID() leaked in. 4. No real PIIgrep -rE '@(gmail|outlook|yahoo)\.com|[0-9]{3}-[0-9]{2}-[0-9]{4}' tests/ fixtures/ returns nothing (real-looking emails and SSNs). Anything it finds is an anonymization gap. 5. Cleanup returns to baseline — snapshot row counts before the suite, run it, snapshot again: the test DB is back to baseline with no orphaned records.

---

Done When

  • Every entity type the suite creates has a factory or fixture (no inline ad-hoc object literals in tests for shared entities -- grep the test dir for hand-built fixtures and confirm none remain).
  • Test data is isolated per test -- the suite passes with parallelism on (--workers=N / pytest -n auto) and under randomized order (--shuffle / -p randomly), proving no shared mutable state or ordering dependency.
  • Seed scripts are idempotent -- running the seed twice in a row produces the same row count and exits 0; the CI job runs them with no manual intervention.
  • No real PII used in test fixtures -- all sensitive data anonymized or synthetic (grep for production domains / real-looking SSNs returns nothing).
  • Data cleanup verified -- row counts in the test DB return to baseline after the suite (no orphaned records accumulate across runs).

---

Reference Files (in references/)

  • factories.md — Full Fishery (associations, deterministic UUIDs), FactoryBot (User + Product traits), Factory Boy (Params/Trait), static/dynamic/composed Playwright fixtures, and the worker-scoped seeding fixture.
  • seeding-and-synthetic.md — Idempotent ON CONFLICT seed script, Faker.js anonymization + referential-integrity pipeline, cleanup strategies (rollback / truncate / API), and synthetic edge-case + boundary-value generators.

Related Skills

  • unit-testing -- Unit tests are the primary consumer of factory-generated data; this skill provides the data layer.
  • api-testing -- API tests use both factories (for request bodies) and fixtures (for mocked responses).
  • playwright-automation -- E2E tests need test data seeded via API or fixtures before browser interaction.
  • test-reliability -- Deterministic test data eliminates a major source of test flakiness.
  • test-environments -- Owns environment provisioning and database-branching strategy (Neon, Supabase, PlanetScale) for preview envs; this skill owns the data that fills them.
  • database-testing -- Migration testing, data-integrity assertions, and Testcontainers for the database layer specifically -- go there to test the DB, come here to populate it.
  • ci-cd-integration -- Database seeding and cleanup must be integrated into CI pipeline stages.

Related skills

FAQ

Factories or static fixtures?

Use factories for entity data with lifecycle changes; use static JSON/YAML for read-only reference or API mocks.

Can production data be copied to test?

Only after irreversible anonymization that preserves distributions without storing re-identification maps.

How should E2E tests clean up?

Prefer API-based deletion in reverse creation order because app DB connections break transaction rollback.

Testing & QAtestingintegrations

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.