whitehat-security/engagements/README.md

12 lines
493 B
Markdown
Raw Normal View History

# Engagement records
Copy `template.json` to a dated, target-specific record and have both the
operator and target owner approve it before a live run. The runner validates
the record at execution time and fails closed when it is incomplete, expired,
outside its window, too permissive, or mismatched to the requested technique
or route.
An engagement record contains authorization metadata only. Never put a token,
password, database URL, secret path value, or real tenant identifier here.