Scope
The systems, identities, workflows and methods authorised for the assessment, with explicit exclusions and dependencies.
Rules of engagement
The operating conditions, permissions, escalation contacts and stop criteria that govern test execution.
Canary object
An intentionally synthetic record, account or transaction used to prove a result without relying on real sensitive data.
Segmentation
Controls that separate network or service access. A test examines defined paths and permissions rather than assuming a diagram reflects enforcement.
Workload identity
A machine or service principal used by applications, integrations or deployment systems. Its permissions and credential lifetime affect the reachable attack path.
Assisted scenario
A scenario that uses an approved supplied account or starting position. The assistance is recorded so the outcome is not confused with unaided access.
Evidence
The observations and records supporting a finding, with timestamps, context and integrity controls. Synthetic sample evidence must remain labelled as such.
Retest
A follow-up validation of specific remediation against agreed acceptance criteria. A planned procedure is not a completed result.
Residual risk
Exposure remaining after fixes, exclusions or interim controls, requiring an explicit owner and decision.
