Skip to main content

KAGEAI GUIDE

Scopes and Permissions

Define target boundaries, authorization evidence, rate limits, and out-of-scope actions before testing.

Last updated:

A useful scope identifies what may be tested, which techniques are allowed, and when testing must stop.

Scope checklist

  • Exact domains, applications, repositories, accounts, or address ranges.
  • Testing window, rate limits, and excluded production systems.
  • Allowed accounts, credentials, and social-engineering rules.
  • Emergency contact and stop conditions.

When the scope changes

Pause the task, obtain updated written authorization, and start again with the new boundaries. Do not treat a discovered dependency as automatically in scope.