Manage Your Scope
Platforms, programs, and assets — the exact forms, in order.
Everything in the vault hangs off one hierarchy: platform → program → asset. Set it up once, properly, and every later step inherits the structure.
1. Create a platform
A platform is where the work comes from: a bug bounty platform, a VDP, a private client.
- Open Platforms in the sidebar.
- Click Add Platform.
- Fill in the drawer:
| Field | Required | Notes |
|---|---|---|
| Name | Yes | e.g. HackerOne, Private clients |
| Description | No | Short description |
| Tags | No | Comma-separated, e.g. bug bounty, private |
| Currency | No | e.g. USD — shown alongside rewards |
| Website | No | e.g. example.com |
| Logo URL | No | Optional branding |
- Click Create Platform.
Platforms in the list can be favorited — the star on each row (Favorite platform / Unfavorite platform) keeps active sources at hand.
2. Create a program
A program is one organization's scope — where the rules of engagement live.
- Open the platform (or go to Programs and click Add Program).
- Fill in the drawer:
| Field | Required | Notes |
|---|---|---|
| Name | Yes | The organization's program name |
| Platform | No | Pre-filled when launched from inside a platform |
| Program Type | No | Bug Bounty, VDP, or Pentest |
| Status | No | Active, Paused, or Ended — defaults to Active |
| Launch Date | No | When the program started |
| Program URL | No | Link to the official brief |
| Rewards Range | No | Free text, e.g. $100 - $10,000 |
| Logo URL | No | Optional branding |
- Click Create Program.
The program's page carries its own guidelines editor — paste the scope, excluded assets, and program rules there; save from that page. It is the one place to re-read the rules without leaving the vault.
3. Create assets
Assets are the concrete things you test. There's a global Assets page, and asset lists inside programs.
- Click Add Asset.
- Fill in the drawer:
| Field | Required | Notes |
|---|---|---|
| Name | Yes | e.g. api.example.com; the placeholder follows the chosen type |
| Asset Type | Yes | Pick from the type list (Web, API, Mobile iOS/Android, Desktop, Cloud Infrastructure, Network/VPN, Smart Contract, Hardware/IoT, Source Code Repository, and more) |
| Priority | No | Defaults to None; also Low, Medium, High, Critical |
| Tags | No | Comma-separated, e.g. prod, internal, mobile |
| URL | No | A direct link to the target |
- Click Create Asset.
Wildcards are containers, not targets
Choose the Wildcard type when you want to organize a broad scope. Two rules apply:
- The name must contain
*— e.g.*.example.comortarget.*.staging.com. Otherwise the drawer refuses it: "Wildcard names must contain*." - Concrete URLs live under the wildcard as Web assets — a URL whose parent wildcard does not exist is rejected.
A wildcard groups; it is never the thing you map.
Bring in a list you already have
If you maintain targets elsewhere, skip the retyping:
- Open the Assets page and click Import.
- The Import Assets modal parses your list; review and select the rows to bring in.
- Click Import N assets — progress streams as they land, and the import can be cancelled mid-run.
Import first, then map the ones worth pursuing.
Habits that pay off
- Concrete names.
api.example.combeats "the API" — precision starts with what you called things. - Priorities are triage. Map everything if you like; priority decides what gets attention first.
- Nest what belongs together. Subdomains under their domain, an API under its app — a capability on a child sharpens what the engine knows about the parent.
- One workspace per context — client boundaries are worth preserving, and cloning makes the setup cheap.
What's next
With the scope in place, the real work starts: map an asset.