Question
What configurable autonomy modes should an OSS research campaign support, including a fully automated mode tested first, and how should planning, passive review, active probing, credential use, browser mutation, downloads, writes, shell commands, exploit validation, patching, and stop/resume behavior map to durable target authorization and exact-intent approvals? Decide what may be pre-authorized, what always requires a fresh decision, how denials and expired grants behave, how side effects are deduplicated across recovery, and what forensic evidence each autonomy transition must preserve.
Question
What configurable autonomy modes should an OSS research campaign support, including a fully automated mode tested first, and how should planning, passive review, active probing, credential use, browser mutation, downloads, writes, shell commands, exploit validation, patching, and stop/resume behavior map to durable target authorization and exact-intent approvals? Decide what may be pre-authorized, what always requires a fresh decision, how denials and expired grants behave, how side effects are deduplicated across recovery, and what forensic evidence each autonomy transition must preserve.