Authorising an assessment
The dated scope, exclusions and scan declaration that permit Verisight to collect.
Domain-based assessments (Full Security Snapshot and Adversary View) need an explicit authorisation before any collection starts. Paying for an assessment does not authorise it.
What an authorisation contains
| Part | Meaning |
|---|---|
| Authorisation reference | Your own reference, such as a change ticket or PO number, recorded with the assessment. |
| Starts / Expires | The window in which collection is allowed. Nothing runs outside it. |
| Domains | The verified domains in scope, chosen when you ordered. |
| Exclusions | Hosts inside those domains that must not be touched. Exclusions must sit inside the authorised domains. |
| Collection mode | Passive, unless you opt in to Adversary View's active testing. |
| Scan declaration | Your confirmation that you are entitled to authorise this assessment. |
Step by step
- Open the assessment in Assessments. A newly ordered assessment shows the authorisation card.
- Check the reference and the start/expiry dates.
- For Adversary View only: decide whether to tick Also run active testing. See Adversary View.
- Confirm the Domain ownership panel shows every domain as verified. Verify any that aren't.
- Read the scan declaration and tick it.
- Choose Authorise and start.
The scan declaration
Your acceptance is stored permanently as proof of consent, with your account, the date and time, your IP address and browser, the exact text you accepted, the domains and the DNS ownership evidence. If we update the declaration, you are asked to accept the new version next time.
Safety checks during collection
Even after you authorise, the scanner re-checks the authorisation and scope immediately before it sends any traffic. It never follows a redirect or DNS answer out of scope, to an excluded host, or to a private or internal address.
Authorisation expired before a retry?
If a failed assessment's authorisation has expired, you can re-authorise the same assessment and retry it. You are not charged again. The new authorisation replaces the old scope entirely.
Microsoft 365 and AWS assessments don't use this form: the connector consent is their authorisation. Cyber Essentials Readiness and Supply Chain Check need none, because they only evaluate what you provide.