Blackbourne Worldwide BlackbourneWorldwide

Home / Authorization Policy

Authorization Policy

Last updated 1 January 2026

This page sets out what we require before any testing begins. It exists for two reasons: the work is lawful only when it is authorised, and an engagement that starts without clear authorisation puts both the client and us at risk.

Written authorisation

Before testing starts we require a signed authorisation that includes:

  • The authorising party — name, title and the basis on which they can authorise testing of the systems in scope.
  • Targets in scope — hosts, applications, networks, cloud environments, personnel populations and physical locations, stated specifically.
  • Explicit exclusions — anything that must not be touched, including production systems, third-party services and personal devices.
  • Testing window — the dates and hours in which testing may occur.
  • Stop conditions — the events that end testing immediately.
  • Emergency contact — a named person reachable during testing, including out of hours.
  • Data handling — collection limits, storage location, retention period and deletion.
  • Notification requirements — who is told what, and when, during the engagement.

Third-party systems

Systems owned or operated by someone else are not in scope by default. That includes cloud providers, SaaS platforms, managed service providers, suppliers, and client customers. Where testing would touch a third party, the client must obtain that party's permission and provide it to us in writing, or the system is excluded.

Social engineering and consent

Social engineering campaigns involve contacting people. Before a campaign runs, the client confirms that:

  • It is entitled to authorise testing of the population concerned, and has notified employees that such testing may take place, in line with its own policies and any applicable employment or works-council requirements.
  • The campaign will not target individuals outside the agreed population — including contractors, family members or third parties — without specific authorisation.
  • Aggregate reporting by role and department is acceptable; individual results will not be used to discipline staff.
  • Any personal data collected during the campaign is handled under the agreed data handling terms.

What we will not do

We decline any engagement that would require us to:

  • Test systems without the authorisation of the party that owns or operates them.
  • Target individuals outside an agreed population, or conduct surveillance of individuals for personal purposes.
  • Cause damage, disruption or data loss beyond what the scope permits and the client accepts.
  • Produce work intended to harm a person or organisation, or to facilitate an offence.
  • Conceal findings from the client, or report selectively to make a result look better.

Personnel

Personnel working on engagements are bound by confidentiality agreements, work to the agreed scope, and are identifiable to the client on request. Testing activity is logged so that any client question about an action can be answered.

If authorisation is unclear

Testing pauses. We would rather delay an engagement than run it on an assumption about who had the right to approve it.

Contact

Questions about authorisation or scope: legal@blackbourneco.com, or through the contact page.