Skip to content

Decide configurable campaign autonomy and approval boundaries #130

Description

@justsml

Question

What configurable autonomy modes should an OSS research campaign support, including a fully automated mode tested first, and how should planning, passive review, active probing, credential use, browser mutation, downloads, writes, shell commands, exploit validation, patching, and stop/resume behavior map to durable target authorization and exact-intent approvals? Decide what may be pre-authorized, what always requires a fresh decision, how denials and expired grants behave, how side effects are deduplicated across recovery, and what forensic evidence each autonomy transition must preserve.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions