Scoping and authorisation
We define targets, in-scope user roles, environments, and testing windows — and document what is explicitly out of scope. Written authorisation is agreed before any testing activity begins, along with an emergency contact and escalation path for critical findings.