Home / Templates / Authorization letter
Before anyone sends a packet at an asset, the permission to do so should exist in writing. This page explains the six things an authorization letter has to pin down, then gives you the full letter to copy and adapt — no signup, no email required.
PENETRATION TEST AUTHORIZATION LETTER
1. AUTHORIZING PARTY ("Client")
Organization: ______________________________
Authorized signer (name): ____________________________
Job title: ______________________________
Email: ______________________________ Phone: ______________
2. TESTING PARTY ("Tester")
Organization: ______________________________
Lead tester (name): ______________________________
Email: ______________________________ Phone: ______________
3. AUTHORIZATION
The Client authorizes the Tester to perform the security testing described
below. The Client confirms it owns, or is authorized to permit testing of,
every asset listed in scope.
4. SCOPE — IN SCOPE (assets the Tester may test)
Domains / hostnames: ______________________________
IP ranges: ______________________________
Applications / environments (e.g. staging only): ______
5. SCOPE — OUT OF SCOPE (explicitly not authorized)
______________________________________________
6. TESTING WINDOW
Start (date/time): ______________ End (date/time): ______________
Permitted hours: ______________ Time zone: ______________
7. SOURCE IPs
The test will originate from: ______________________________
8. PERMITTED TESTING
[ ] Network / infrastructure [ ] Web application [ ] API
[ ] Authentication testing [ ] Social engineering (separately agreed)
Intrusive testing (e.g. denial of service) is: NOT authorized / authorized
9. POINTS OF CONTACT
Client technical contact: _________ Phone: ______________
Tester technical contact: _________ Phone: ______________
10. EMERGENCY STOP
The Client may halt testing at any time by contacting the Tester's technical
contact above and stating "STOP". The Tester will acknowledge the stop
immediately and cease all active testing within ____ minutes.
11. DATA HANDLING
Findings and any data captured are confidential to the Client and will be
stored securely and destroyed on request.
12. SIGNATURES
Client (authorized signer): ____________________ Date: __________
Tester (lead): ____________________ Date: __________
This authorization is valid from the start of the testing window in
section 6 until the end date, unless withdrawn in writing earlier.Plain text on purpose, so you can paste it into your own document or contract workflow and adapt the wording to your jurisdiction.
Pair this letter with the rules of engagement template, which covers how the test is run rather than whether it is permitted.
The letter above is a document. PentSeal makes the same information a gate: it verifies target ownership, records the signed scope and window, and will not run a scan outside them. Walk the workflow in the browser, or talk to us about a pilot on a domain you own.