Scope and intake
Turn a broad request into a bounded review plan with recorded ownership, constraints, and evidence goals.
This is the complete downloadable file. Open plain text ↗
---
name: intake
description: "Turn a broad request into a bounded review plan with recorded ownership, constraints, and evidence goals."
---
# Scope and intake
Turn a broad request into a bounded review plan with recorded ownership, constraints, and evidence goals.
Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.
## Bring to the review
- Written program scope and rules
- Approved test accounts or environments
- Known application entry points
## Review guide
### 1. Record the boundary
List approved hosts, applications, accounts, and data classes before opening a review. Mark excluded systems and actions beside them.
### 2. Model the actors
Describe the roles, tenants, and protected objects that the product is expected to keep separate.
### 3. Choose safe evidence
Define the smallest observation that can confirm or reject each security assumption using owned data.
## What to produce
- A scope record
- A role and object map
- A bounded evidence plan
## Common mistakes
- Treating a discovered hostname as authorization
- Mixing assumptions with observed facts
- Collecting more data than the review needs
## Reading and source context
### Resources
- [OWASP Threat Modeling: system assumptions and mitigation validation](https://vulns.co/research/resources/owasp-threat-modeling-assumptions-and-validation/)
- [OWASP Secure Code Review: baseline and change-focused review](https://vulns.co/research/resources/owasp-secure-code-review-methodology/)
## Provenance
Editorial guide by vulns.co / GK Data. Updated 2026-10-11.
Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3.
The guide is an editorial synthesis. Linked records preserve their own sources and review dates.
Reader: https://vulns.co/skills/intake/
The review
What to look for
Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.
Record the boundary
List approved hosts, applications, accounts, and data classes before opening a review. Mark excluded systems and actions beside them.
Model the actors
Describe the roles, tenants, and protected objects that the product is expected to keep separate.
Choose safe evidence
Define the smallest observation that can confirm or reject each security assumption using owned data.
What to produce
- A scope record
- A role and object map
- A bounded evidence plan
Common mistakes
- Treating a discovered hostname as authorization
- Mixing assumptions with observed facts
- Collecting more data than the review needs
Continue the study
Reading & source context
Editorial notes above connect these references. Open each record for its original source and review date.
From the field toolkit
Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.