# Rules of engagement: [engagement name]

Agreed between [client] and Breakfirst on [date]. Both sides keep a signed copy. Anything not written here is out of scope until it is added in writing.

This is the Breakfirst rules-of-engagement template, released for anyone to use. It is a working agreement, not a contract; your contract sits above it. Replace everything in square brackets.

## 1. People

| Role | Name | Contact | Hours |
| --- | --- | --- | --- |
| Client owner | | | |
| Client on-call during test windows | | | |
| Breakfirst lead | | | |
| Breakfirst second | | | |

If something breaks in production during a test window, Breakfirst calls the client on-call first, before anything else.

## 2. Scope

**In scope**

- [System, URL, environment, version or commit]
- [System, URL, environment, version or commit]

**Out of scope**

- [Third-party services, other business units, physical access, social engineering, anything not listed above]

**Environments.** Testing runs against [staging / dedicated test environment]. If production is in scope, the allowed actions are listed in section 4 and nothing else is permitted there.

## 3. Windows

| From | To | Timezone | Systems | Notes |
| --- | --- | --- | --- | --- |

Testing outside these windows needs written agreement the same day.

## 4. What is allowed and what is not

**Allowed**

- Manual testing and tooling against in-scope systems, within the windows.
- Creating, changing and deleting data in test accounts created for this engagement.
- Reading the minimum data needed to prove a finding; redacted in the report.

**Not allowed**

- Reading, changing, exporting or deleting data belonging to real customers.
- Denial-of-service or volumetric testing, except against [environment] within [window].
- Social engineering of staff or customers, physical access, or testing of out-of-scope systems.
- Pivoting from an in-scope system into one that is not listed.

## 5. Accounts and access

- The client issues named accounts to each Breakfirst tester, so every action appears in logs under a name.
- Credentials are shared through [password manager / encrypted channel], never by email or chat.
- The client revokes all accounts when the retest is signed off.

## 6. Data handling

- Evidence is kept in an encrypted engagement folder, accessible only to the people in section 1.
- Personal data captured as evidence is the minimum needed, redacted in the report, and never copied in bulk.
- The engagement folder is deleted [thirty days] after the retest is signed off unless the client asks for a longer retention in writing.

## 7. Communication

- Critical findings: a call to the client owner the same day, followed by a written note.
- High findings: a written note within one working day.
- Everything else: the report.
- Weekly status in [channel] during testing.

## 8. Reporting and retest

- Report delivered [N] working days after testing ends, in the format in the report template.
- Walkthrough call within [N] days of delivery.
- One retest of every finding included, within [thirty] days of delivery.

## 9. Signatures

| For [client] | For Breakfirst |
| --- | --- |
| Name, role, date | Name, role, date |

---

Template by Breakfirst (breakfirst.dev). Use it, change it, keep the rules written down before the clock starts.
