KAGEAI GUIDE
Scopes and Permissions
Define target boundaries, authorization evidence, rate limits, and out-of-scope actions before testing.
Last updated:
A useful scope identifies what may be tested, which techniques are allowed, and when testing must stop.
Scope checklist
- Exact domains, applications, repositories, accounts, or address ranges.
- Testing window, rate limits, and excluded production systems.
- Allowed accounts, credentials, and social-engineering rules.
- Emergency contact and stop conditions.
When the scope changes
Pause the task, obtain updated written authorization, and start again with the new boundaries. Do not treat a discovered dependency as automatically in scope.