Exhaustive checks of the statespace that enable us to give formal guarantees about runtime properties.