guide Updated 2026-10-06

Manage Your Scope

Platforms, programs, and assets — the exact forms, in order.

Everything in the vault hangs off one hierarchy: platform → program → asset. Set it up once, properly, and every later step inherits the structure.

1. Create a platform

A platform is where the work comes from: a bug bounty platform, a VDP, a private client.

  1. Open Platforms in the sidebar.
  2. Click Add Platform.
  3. Fill in the drawer:
FieldRequiredNotes
NameYese.g. HackerOne, Private clients
DescriptionNoShort description
TagsNoComma-separated, e.g. bug bounty, private
CurrencyNoe.g. USD — shown alongside rewards
WebsiteNoe.g. example.com
Logo URLNoOptional branding
  1. Click Create Platform.

Platforms in the list can be favorited — the star on each row (Favorite platform / Unfavorite platform) keeps active sources at hand.

2. Create a program

A program is one organization's scope — where the rules of engagement live.

  1. Open the platform (or go to Programs and click Add Program).
  2. Fill in the drawer:
FieldRequiredNotes
NameYesThe organization's program name
PlatformNoPre-filled when launched from inside a platform
Program TypeNoBug Bounty, VDP, or Pentest
StatusNoActive, Paused, or Ended — defaults to Active
Launch DateNoWhen the program started
Program URLNoLink to the official brief
Rewards RangeNoFree text, e.g. $100 - $10,000
Logo URLNoOptional branding
  1. Click Create Program.

The program's page carries its own guidelines editor — paste the scope, excluded assets, and program rules there; save from that page. It is the one place to re-read the rules without leaving the vault.

3. Create assets

Assets are the concrete things you test. There's a global Assets page, and asset lists inside programs.

  1. Click Add Asset.
  2. Fill in the drawer:
FieldRequiredNotes
NameYese.g. api.example.com; the placeholder follows the chosen type
Asset TypeYesPick from the type list (Web, API, Mobile iOS/Android, Desktop, Cloud Infrastructure, Network/VPN, Smart Contract, Hardware/IoT, Source Code Repository, and more)
PriorityNoDefaults to None; also Low, Medium, High, Critical
TagsNoComma-separated, e.g. prod, internal, mobile
URLNoA direct link to the target
  1. Click Create Asset.

Wildcards are containers, not targets

Choose the Wildcard type when you want to organize a broad scope. Two rules apply:

  • The name must contain * — e.g. *.example.com or target.*.staging.com. Otherwise the drawer refuses it: "Wildcard names must contain *."
  • Concrete URLs live under the wildcard as Web assets — a URL whose parent wildcard does not exist is rejected.

A wildcard groups; it is never the thing you map.

Bring in a list you already have

If you maintain targets elsewhere, skip the retyping:

  1. Open the Assets page and click Import.
  2. The Import Assets modal parses your list; review and select the rows to bring in.
  3. Click Import N assets — progress streams as they land, and the import can be cancelled mid-run.

Import first, then map the ones worth pursuing.

Habits that pay off

  • Concrete names. api.example.com beats "the API" — precision starts with what you called things.
  • Priorities are triage. Map everything if you like; priority decides what gets attention first.
  • Nest what belongs together. Subdomains under their domain, an API under its app — a capability on a child sharpens what the engine knows about the parent.
  • One workspace per context — client boundaries are worth preserving, and cloning makes the setup cheap.

What's next

With the scope in place, the real work starts: map an asset.