Scope around risk and architecture

Identify sensitive workflows, trust boundaries, user roles, third-party integrations and data paths. A domain list alone rarely describes the system that needs testing.

Combine automation with judgement

Use tools for repeatable discovery, then validate findings manually. Test access control, workflow abuse, tenant isolation, business logic and chained conditions that scanners cannot understand reliably.

Report for remediation

Each finding should explain affected assets, evidence, realistic impact, reproduction boundaries and a repair approach. Separate confirmed conditions from observations and assumptions.

Retest the outcome

Verify the original condition and likely bypasses after remediation. A retest should record what changed and what residual risk remains.

Before testing startsThe asset owner, authorised targets, prohibited actions, testing window, escalation route and evidence handling rules must be written down.