The surface as it stands today, not as the documentation describes it
- What runs
- B-52 establishes what is actually reachable: hosts, applications, endpoints, and the roles that can get to each of them. On an application this is also where the client-side code is read, which is how routes nothing on the interface links to end up in scope for testing.
- Before it moves on
- The authorised scope is the boundary. B-52 tests what you signed off and nothing outside it, however interesting the thing outside it looks.