Scope is a technical control
Written authorization is not paperwork added after the technical work. It defines the assets, identities, methods, test window, data rules, rate limits, and emergency contacts that make the activity safe and lawful.
For self-study, use loopback services, local containers, disposable accounts, synthetic identities, and intentionally vulnerable applications. Never convert a hostname found in a tutorial into a real target.
- In scope: exact local services, test accounts, and permitted actions.
- Out of scope: production, third-party tenants, real people, and shared networks.
- Stop conditions: unexpected outbound traffic, real data, instability, or unclear ownership.
- Recovery: snapshots, reset scripts, logs, and an easy way to destroy the environment.