--- name: intake description: "Turn a broad request into a bounded review plan with recorded ownership, constraints, and evidence goals." --- # Scope and intake Turn a broad request into a bounded review plan with recorded ownership, constraints, and evidence goals. Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question. ## Bring to the review - Written program scope and rules - Approved test accounts or environments - Known application entry points ## Review guide ### 1. Record the boundary List approved hosts, applications, accounts, and data classes before opening a review. Mark excluded systems and actions beside them. ### 2. Model the actors Describe the roles, tenants, and protected objects that the product is expected to keep separate. ### 3. Choose safe evidence Define the smallest observation that can confirm or reject each security assumption using owned data. ## What to produce - A scope record - A role and object map - A bounded evidence plan ## Common mistakes - Treating a discovered hostname as authorization - Mixing assumptions with observed facts - Collecting more data than the review needs ## Reading and source context ### Resources - [OWASP Threat Modeling: system assumptions and mitigation validation](https://vulns.co/research/resources/owasp-threat-modeling-assumptions-and-validation/) - [OWASP Secure Code Review: baseline and change-focused review](https://vulns.co/research/resources/owasp-secure-code-review-methodology/) ## Provenance Editorial guide by vulns.co / GK Data. Updated 2026-10-11. Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3. The guide is an editorial synthesis. Linked records preserve their own sources and review dates. Reader: https://vulns.co/skills/intake/