guide Updated 2026-10-06

Manage Your Scope

Organize platforms, programs, and assets so the rest of the vault has a place to live.

The shape of the work

Everything in the vault hangs off the scope hierarchy: platform → program → asset. You rarely revisit it once it is set up, but a sloppy hierarchy makes every later step worse.

Create the platform

A platform is where the work comes from: a bug bounty platform, a VDP, a private client. Capture the essentials — name, description, and the program's currency — and move on. Platforms are containers, not analysis.

Create the program

A program is one organization's scope. Set the **program type** (bug bounty, VDP, or pentest), its status, and the practical details — rewards range, program URL, and the asset types it covers. This is where the rules of engagement live.

Create assets for the concrete things

An asset is one thing you test: a host, an API, an app, a repository. Choose the **asset type** (Web, API, Mobile iOS/Android, Desktop, Cloud Infrastructure, Network/VPN, Smart Contract, Hardware/IoT, Source Code Repository, and more) and set a **priority** if it deserves one. Name assets the way you think about them — the engine works with whatever is concrete.

Model the hierarchy

Real targets have structure: subdomains belong to a domain, an API belongs to an app. Nest assets under a parent instead of flattening everything into the program — a capability recorded on a child sharpens what the engine knows about the parent without duplicating records.

Use wildcards as containers

A **Wildcard** is a special asset type for grouping: its name must be a pattern like `*.example.com`, and it is a container rather than a tracked target. Concrete URLs live under it as Web assets. This keeps broad scopes organized without pretending the wildcard is something you test directly.

Getting a list in

If you already maintain a target list, import it rather than retyping: a CSV import brings assets in, and you can map components to them afterward. Import first, then map the ones worth pursuing.

Habits that pay off

  • Concrete names. api.example.com beats "the API". The engine ranks precision, and it starts with what you called things.
  • Priorities are triage. Nothing stops you from mapping everything, but priority focuses which assets get attention first.
  • Tags and favorites on platforms and programs keep large scopes navigable as they grow.
  • One workspace per context — client boundaries are worth preserving, and cloning makes the setup cheap (see Clone a Workspace).

What's next

With the scope in place, the real work starts: map an asset.