Official technical audit, concurrency test results, and compliance specification for ChoiceGuard in Google Workspace.
This technical docket documents the architectural boundaries, security audit results, and functional concurrency test cases verified for ChoiceGuard before publication to the Google Workspace Marketplace.
ChoiceGuard dynamically limits options and caps seating or inventory capacity across Google Forms directly within your workspace. As responses arrive, exhausted choices are eliminated in real time.
Built with Apps Script's native LockService, ChoiceGuard eliminates race conditions and double-bookings during simultaneous sign-ups — solving the known failure mode of legacy tools.
Zero external cloud relays, zero middleman databases, zero analytics telemetry. Execution runs 100% inside the user's authenticated Google tenant perimeter.
2 active managed forms 100% free forever with unlimited responses. ChoiceGuard Pro is a one-time $29.00 lifetime unlock. Zero recurring monthly or annual SaaS subscriptions.
ChoiceGuard is an in-tenant Google Forms choice limiter executing entirely within Google's V8 Apps Script engine under the user's authenticated Google perimeter. It does not utilize external cloud servers, third-party databases, or middleman analytics relays.
| Attribute | Specification | Verification Standard |
|---|---|---|
| Host Application | Google Forms (Editor Add-on) | Google Workspace Add-ons API v1 |
| Runtime Execution | Google Apps Script (V8 Engine) | In-Tenant Google Server Infrastructure |
| Data Residency | 100% In-Account (Document & User Properties) | Zero Outbound Network Transit (FERPA Compliant) |
| OAuth Scopes | forms.currentonly, script.container.ui, script.scriptapp |
Strict Least-Privilege (Non-Sensitive) |
| CASA Review Status | Tier 2 Audit Exempt | Google Cloud Application Security Assessment Standard |
| Monetization & Licensing | 2 Active Forms Free (Unlimited Submissions) · $29 Lifetime Pro | Deterministic In-Script Property Gate |
The following test suite was executed against the production deployment artifact in a live Google Forms container:
| Test ID | Assertion & Objective | Method / Mechanism | Audit Result |
|---|---|---|---|
| QA-01 | Least-Privilege Scope Boundary: Manifest requests strictly non-sensitive scopes. Cannot read user Drive, emails, or unrelated forms. | AST Manifest Inspection (appsscript.json) |
PASS |
| QA-02 | Zero External Telemetry: Code contains zero HTTP calls (UrlFetchApp) to remote tracking endpoints or external databases. |
Static Code Call-Graph Audit | PASS |
| QA-03 | Concurrency Mutex Protection: Prevents race conditions and double-bookings during simultaneous sign-ups. | LockService.getScriptLock() 15-second mutex queue |
PASS |
| QA-04 | Dynamic Choice Elimination: Exhausted choice is cleanly removed from live form options upon reaching configured cap. | Real-time form option mutation | PASS |
| QA-05 | Zero-Choice Edge Case: Gracefully handles all options exhausted without throwing Forms API runtime exceptions. | Boundary submission condition | PASS |
| QA-06 | One-Click State Restoration: Original choices and limits restored cleanly without corrupting form questions. | restoreOriginalChoices() RPC execution |
PASS |
| QA-07 | Free Tier Integrity: Enforces 2 active managed forms while guaranteeing 100% unlimited submissions per form. Zero mid-event cutoffs. | UserProperties form registration quota | PASS |
To eliminate the infamous Choice Eliminator race condition where concurrent submissions double-book the last remaining slot, ChoiceGuard wraps all submission mutations in a deterministic script lock:
// ChoiceGuard Concurrency Mutex Engine (Code.gs)
var lock = LockService.getScriptLock();
var hasLock = lock.tryLock(15000); // 15-second serialized queue
if (!hasLock) {
console.error("Lock timeout: concurrent submission load exceeded threshold");
return;
}
try {
var form = (e && e.source) ? e.source : FormApp.openById(formId);
processChoiceElimination_(form, e.response);
} finally {
lock.releaseLock();
}Deployment Identification: Script ID 1PHFsHT5E0sovI3M7MALFv6mlWf28JCUbzRU3tlenCHfxmSK6N1xbLBt7, Version 2 (v1.1.0). All 7 gates passed and verified by 864zeros LLC engineering board on 2026-10-09.