Home / Templates / Rules of engagement
The authorization letter says whether testing is allowed. The rules of engagement document says how it will be run — what is permitted, how the team communicates, how the test stops, and how evidence is handled. Here is what each clause needs to cover, and the full template to copy.
RULES OF ENGAGEMENT (ROE)
Engagement: ______________________________
Tester: ______________________________
Client: ______________________________
Authorization letter reference: ______________________
1. OBJECTIVE
Scope of work: ______________________________
In-scope assets, window and source IPs: see the signed authorization letter.
2. PERMITTED TESTING CATEGORIES
Authorized by default:
[ ] Network / infrastructure scanning
[ ] Web application testing
[ ] API testing
[ ] Authentication / authorization testing
Require separate written approval:
[ ] Intrusive testing (e.g. denial of service) [ ] Social engineering
Explicitly prohibited:
______________________________________________
3. RATE LIMITS AND RESTRICTIONS
Maximum automated request rate: ______________
Prohibited actions (e.g. data modification, destructive payloads): ________
Production data may be: read / modified only with prior approval
4. COMMUNICATION
Status updates every ________ via ______________________
Primary channel: ______________________
Client primary contact: __________ Backup: __________
Tester primary contact: __________ Backup: __________
5. ESCALATION
If a critical finding or real incident is discovered:
Notify ______________________ within ________ minutes.
Testing will: continue / pause until cleared.
6. EMERGENCY STOP
The Client may halt testing at any time by stating "STOP" to the Tester's
primary contact. The Tester will acknowledge immediately and cease all active
testing within ________ minutes. No new testing resumes without written
clearance from the Client.
7. EVIDENCE AND DATA HANDLING
Evidence captured: ______________________
Stored where / accessible to whom: ______________________
Retention period: ______________ Destruction method: ______________
Confidential material encountered by chance will be: reported / not retained
8. REPORTING
Draft delivered by: ______________ Final by: ______________
Format: ______________________
9. RETEST
Retest included: yes / no Window: ______________
Eligible findings: confirmed high and critical, unless otherwise agreed.
10. APPROVAL
Client signer: ____________________ Date: __________
Tester lead: ____________________ Date: __________Plain text on purpose, so you can paste it into your own document workflow and adapt it to your engagement.
Use this ROE alongside the penetration test authorization letter, which records the permission this document assumes.
The ROE above is a document the tester is trusted to follow. PentSeal makes the same scope and window a hard gate on execution: it verifies target ownership, records the signed scope and testing window, and will not run a scan outside them. Walk the workflow in the browser, or talk to us about a pilot on a domain you own.