Complete AI Training
Sign inGet my AI kit

Your job's AI kit

Get your AI kit

Tell us who you are and what you do. We show you your kit right away and email you the link: skills, prompts, AI agents, MCP servers and courses for your job.

500+ jobs ready, and we make a kit for any other job. No payment needed to look.

Share

AI agent for penetration testers

Engagement Scope Authorization Agent

A verified target list where every item is covered by signed authorization

Engagement Scope Authorization Agent: what goes in, what the agent does and what you get

What it does

Before any security testing, every target must be covered by a signed authorization, or the work is illegal, and client target lists are often messy. This agent reads the signed authorization and the client's target list, resolves each domain to its address and checks address ownership records. It compares each target with the signed scope. It flags targets not in scope, addresses that belong to a third party such as a cloud or shared hosting provider, and anything whose ownership it cannot confirm. Each unclear target is held, and the agent drafts a question to the client. Nothing held is passed to testing tools. It assembles the approved target list with the authorization record. You approve the final list. Edge case: a domain that now resolves to a different provider than when the authorization was signed is held for re-confirmation.

How it works

Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.

Start and resultWhat it doesA check on its own workWaits for your OKGoes back and retries
Yes, continueApprovedNo 1 STARTS WHEN Engagement authorized 2 USES A TOOL Read the signed authorization and the client targetlist 3 USES A TOOL Resolve domains to addresses 4 USES A TOOL Check address ownership records 5 DOES Compare each target with the signed scope 6 CHECKS THE RESULT Is every target in scope with ownership confirmed? If not: hold the target and draft a question to theclient. Back to step 3. 7 DOES Assemble the approved list with the authorizationrecord 8 YOU APPROVE Lead approves the final authorized target list 9 RESULT Authorized target list recorded
Read the steps as a list
  1. Engagement authorized
  2. Read the signed authorization and the client target list
  3. Resolve domains to addresses
  4. Check address ownership records
  5. Compare each target with the signed scope
  6. Is every target in scope with ownership confirmed?If not: hold the target and draft a question to the client. Back to step 3.
  7. Assemble the approved list with the authorization record
  8. Lead approves the final authorized target listThe agent waits here for your OK.
  9. Authorized target list recorded

How it decides

A target is cleared only when it is in the signed scope and ownership confirms it belongs to the client or an authorized provider.

  • Hold any target not in the signed scope
  • Hold third-party hosted addresses until the provider permits testing
  • Re-confirm targets whose hosting changed

Make it yours

Every agent is a starting point. You choose these settings for your own situation.

  • Authorized provider list
  • Re-confirmation schedule
  • Client question template
  • Output format for tools

What keeps you in control

It always asks you first

  • The final authorized target list
  • Questions sent to the client

Hard limits

  • No testing activity during validation beyond ownership lookups
  • Nothing proceeds without signed authorization

It stops when

  • Done: all targets cleared or excluded
  • Stop: no signed authorization is on file

Set it up

We guide you through the set-up, step by step

Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.

10 minto set it up in your AI
5 AIsChatGPT, Claude, Copilot, Gemini, Grok
  • One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
  • The agent then walks you through connecting your own data, one source at a time
  • A downloadable copy with the flow chart, the rules and the full guide
Get access to this agent

An example run

What happensFor an engagement with Granger Logistics starting May 6, the client listed 52 hosts. The agent found 4 addresses on a cloud provider needing separate permission and 3 subdomains outside the signed scope, so the check failed for 7. It held them and drafted a client question. Permission came through for 2. The lead tester approved a final list of 47 hosts.

More agents for penetration testers