Authorization & Safety
Authorization & Safety
SiegePoint never tests without written authorization. Two documents govern every engagement:
- Authorization-to-Test Letter — the signed permission that makes the testing lawful.
- Rules of Engagement (RoE) — scope, targets, windows, escalation contacts, and hard stop lines.
The guardrail layer
A guardrail layer keeps authorized testing from becoming an actual incident: destructive actions require an explicit, named approval; social-engineering "actions" (rung S3) run only inside an agreed, reversible blast radius; and the Authorization Ceiling is a hard stop the tester will not cross. Voice-based testing defaults to dry-run and is limited to consented, allowlisted numbers.
The template authorization letter and SOW/MSA clauses provided in an engagement are starting points. Your attorney and insurer should review them before signature.