NullSquare
conceptbeginnerReviewed May 18, 2026

Agent and user responsibilities

What the agent does for you and what your team must configure.

What the agent does

  • Turns your assessment goal into a plan you can review.
  • Discovers reachable hosts, services, endpoints, technologies, and authentication surfaces.
  • Tests inside the configured rules of engagement.
  • Preserves evidence for findings and reports.
  • Uses prior assets, findings, notes, credentials, and repository mappings when available.

What your team does

  • Creates scopes that reflect authorized environments.
  • Adds public domains, hosts, or internal CIDR targets.
  • Deploys private runners when the target is internal or private.
  • Adds business context, credentials, repositories, and asset profiles after discovery.
  • Reviews plans, triages findings, accepts risk where appropriate, and starts retests.

Boundary

The agent does not replace authorization

Only add targets your organization owns or has explicit permission to test. The platform enforces scope boundaries, but your team owns the authorization decision.

Related articles