What Scope Controls
Use scope configuration to define:- primary domains and application URLs
- additional allowed domains or routes that are part of the same target
- in-scope systems agents should include
- out-of-scope systems agents should exclude
- important tenant, workspace, account, or environment values
- authentication context and credential role boundaries
Common Scope Patterns
| Pattern | Use When |
|---|---|
| Single application domain | The target lives under one domain such as https://app.example.com. |
| Marketing plus app domain | Login begins on one domain and redirects into another application domain. |
| Tenant-specific app | The application requires an org slug, tenant ID, workspace ID, or account selector. |
| Authenticated-only areas | Sensitive routes should only be tested after the agent is signed in with an approved test credential. |
| Excluded operational paths | Routes such as billing, destructive admin actions, production email sends, or customer-impacting workflows must be excluded or constrained with rules. |
Guardrail Types
MindFort agents use guardrails to keep testing inside approved boundaries:- Rate Limiting controls agent request pacing with Auto, Aggressive, Reduced, and Extreme Stealth modes.
- Scope stores Include and Exclude entries for domains, IPs, CIDRs, routes, or other testing boundaries.
- Rules store additional constraints for agent behavior.
- Custom Values store target-specific context agents should know while testing.
Configure Scope
- Open Target Inventory.
- Select the target.
- Open the Guardrails tab.
- Set Rate Limiting if the default automatic pacing is not appropriate.
- Add Include entries for systems that agents should test.
- Add Exclude entries for systems that agents must avoid.
- Add Rules for behavior constraints such as avoiding destructive actions.
- Add Custom Values for context such as
tenant_slug,workspace_id,organization_id, orenvironment. - Save changes before starting an assessment or task.
Examples
Tenant-Aware SaaS App
Multi-Domain Login Flow
Before Launch
Confirm:- the target is verified
- stored credentials are dedicated test accounts
- login instructions include every redirect and required intermediate step
- include and exclude entries are current
- behavior rules cover sensitive workflows
- WAF allowlisting is complete if your infrastructure filters automated traffic