# Rules of Engagement — assessment authorisation letter (template)

**Provael · template version 2026-08-04**

> **This is a template, not an executed authorisation, and not legal advice.** It is published so
> the security lead who has to sign it can read it before the scoping call. Nothing is tested until
> a completed version of this letter is signed by someone with authority to grant it.

---

## Why this letter exists

An adversarial evaluation is authorised activity or it is an incident. This letter is the artifact
that makes the difference legible to your SOC, your insurer and your auditor: it names what was
tested, by whom, in what window, and who could stop it.

**Scope reality that keeps this short:** Provael tests a policy **in simulation**. It ships no
hardware control path and no exploit tooling, so this letter authorises a simulated evaluation and
access to the environment needed to run one — not a network penetration test, and never physical
robot operation.

---

## 1. Parties

| | |
| --- | --- |
| Customer (authorising party) | |
| Authorising signatory (name, title) | |
| Assessor | Provael (named individual in the engagement contract) |
| Engagement reference | |

## 2. Authorisation

The Customer authorises the Assessor to perform an adversarial evaluation of the target described
in clause 3, within the window in clause 4, subject to the limits in clause 6.

The authorising signatory confirms they have authority to grant this authorisation for the systems
and data named, including where those systems are hosted by a third party.

## 3. Target of evaluation

| Item | Value |
| --- | --- |
| Policy / checkpoint under test | |
| Checkpoint location (customer-hosted, or hosted by whom) | |
| Simulation suite and task set | |
| Environment the evaluation runs in | |
| Accounts / credentials issued to the Assessor | |
| Data the Assessor will be given access to | |

**Weights and data handling.** The default is that the Assessor works **inside the Customer's
environment** or against a checkpoint the Customer hosts, and receives no copy of the weights.
Tick one:

- [ ] Assessor works in the Customer's environment. No weights or run data leave it.
- [ ] Customer will transfer a checkpoint to the Assessor. *(If ticked, complete the DPA and state
      the deletion date: ______________ )*

## 4. Window

| | |
| --- | --- |
| Start (date/time, timezone) | |
| End (date/time, timezone) | |
| Permitted hours | |

No testing occurs outside this window. An extension requires written agreement from the authorising
signatory.

## 5. Contacts and stop procedure

| Role | Name | Contact (24h) |
| --- | --- | --- |
| Customer technical contact | | |
| Customer authorising signatory | | |
| Assessor | | |

**Stop procedure.** Either Customer contact may halt all activity immediately by contacting the
Assessor on the channel above. The Assessor stops on request without requiring a reason, confirms
the stop in writing, and does not resume until the Customer confirms in writing.

## 6. Limits — what is explicitly NOT authorised

The following are out of scope and will not be attempted:

1. **Any operation of physical robot hardware.** Simulation only.
2. Denial-of-service or availability testing against production systems.
3. Social engineering of Customer personnel.
4. Network or infrastructure penetration testing beyond the access explicitly issued in clause 3.
5. Access to production customer data, PII or credentials not issued for this engagement.
6. Persistence, lateral movement, or use of any access beyond the window in clause 4.
7. Publication of any finding or Customer identity, except where a separate design-partner
   agreement grants it in writing.

## 7. Handling of findings

- Findings are delivered to the Customer contacts above and to nobody else.
- Evidence artifacts (measured attack-success rate with its confidence interval and benign control,
  SARIF findings, compliance crosswalk, signed attestation) are delivered to the Customer and are
  the Customer's to file, keep and share.
- The Assessor deletes assessment material within **30 days** of final delivery unless instructed
  otherwise in writing.
- Where a finding indicates a vulnerability in third-party software, disclosure to that third party
  is coordinated with the Customer first.

## 8. Interpretation of results

The Customer acknowledges that an evaluation performed under this letter produces **measured
evidence in simulation**, and that it is **not** a safety certification, a conformity assessment,
a legal opinion, or a statement that the policy is safe to deploy. Scope limits are reported
alongside every number.

---

**Signatures**

| | Customer authorising signatory | Assessor |
| --- | --- | --- |
| Name | | |
| Title | | |
| Date | | |
| Signature | | |

---

*Provael — evidence, not certification. Simulation only. This template is published at
https://www.provael.com/trust/ and is not legal advice; have your own counsel review it.*
