Adversarial testing is only acceptable when its boundaries are explicit and enforced. Scope is a control surface, not paperwork.
Authorization
- Recorded authorization for each asset class in scope
- Named approvers for sensitive operations
- Documented exclusions with a stated reason
Technical boundaries
- Allowlists for hosts, domains, tenants and identities
- Approval gates before higher-impact actions
- Exploitation limits that prove reach without causing damage
- Audit logs covering every action performed
Operational readiness
Decide in advance how detection and response teams should treat authorized activity, and whether you intentionally want it unannounced to measure detection coverage.
Tags
- scope
- authorization
- governance
- trust