Define the action, evidence gate and authority owner before anyone tests it.
Build the scope locally. Mapper drafts can be handed into this page through browser session storage. Generating the brief does not transmit data or authorize testing; any online handoff, when explicitly available, requires a separate consent and submit action.
Review every imported field. Owner decision, object-binding evidence, Rules-of-Engagement permissions, company/contact, access approval, data boundary and testing authorization remain intentionally unset.
API keys · passwords · tokens · private keys · wallet seeds · production credentials · customer secrets. Describe boundaries, evidence classes and access paths instead.
Start with Entry. Expand only when the owner decision needs Primary depth.
ENTRY · reduced first-step fields · Primary evidence/RoE fields deferred until deeper scope review
Choosing a depth and generating the brief are browser-local. No data is transmitted, work booked or testing authorized unless a separately enabled online handoff is explicitly consented to and submitted.