Skip to main content
Trust · Approvals

Three actions stop and wait for you

Autonomy is the product claim, and a claim like that is only worth anything with a boundary attached. These three are the boundary. They are identical on every coverage class and in all three delivery models, including the one with nobody in it after scope sign-off.

The gates

What waits, and what runs

The second row is the one that distinguishes this platform from the category. Persistence is performed by B-52 itself, inside authorised scope, rather than by a human operator — and that is exactly why it sits behind a written gate rather than behind a preference.

The three approval gates and what runs without asking
ActionWhat it coversWhat happens
Destructive or state-changing actions in production Anything that alters or removes what is on a live system, rather than demonstrating that it could be altered. Stops and waits, in writing.
Persistence and movement past the entry host Implants, footholds, and movement beyond the first host reached. Persistence is performed by the platform itself within authorised scope, which is why the boundary around it is written down. Stops and waits, in writing.
Live credentials or real customer data Anything that would use a real account’s credentials or read a real person’s records, once a path to them has been proved. Stops and waits, in writing.
Everything else inside the authorised scope Terminal Discovery, planning, scanning, exploitation, chaining and reporting — the work the scope you signed authorises. Runs without asking.
Key
  • Requires your written approval before B-52 proceeds
  • Authorised by the scope you signed off
  • TerminalNo state follows this one

What an approval covers

The five questions a security team asks about this

Usually in this order, and usually before the commercial conversation rather than after it.

The questionThe answer
Does an approval cover one action or many? A boundary, for one engagement. Approving movement inside a named segment authorises it inside that segment for that engagement; B-52 does not return for a second signature on each host it reaches. Reaching past the boundary is a new decision.
Can a gate be released mid-run? Yes, in writing, and on some classes that is the normal shape — an internal network engagement settles its movement boundary at scoping precisely so that it is not being decided while a run is going.
What happens if nobody responds? The run does what it was authorised to do and reports. A gate that was never released is a gate that was never released, and the work either side of it still happened.
Does the fully autonomous model have fewer gates? No. The three are the same in all three delivery models. What the fully autonomous model removes is the human between scope sign-off and the report, not the boundary around what the run may do.
Who signs the scope? You do, before the engagement. In the fully autonomous model that sign-off is the last human action of the engagement, which is what makes it the document everything else is measured against.

Does an approval cover one action or many?

The answer
A boundary, for one engagement. Approving movement inside a named segment authorises it inside that segment for that engagement; B-52 does not return for a second signature on each host it reaches. Reaching past the boundary is a new decision.

Can a gate be released mid-run?

The answer
Yes, in writing, and on some classes that is the normal shape — an internal network engagement settles its movement boundary at scoping precisely so that it is not being decided while a run is going.

What happens if nobody responds?

The answer
The run does what it was authorised to do and reports. A gate that was never released is a gate that was never released, and the work either side of it still happened.

Does the fully autonomous model have fewer gates?

The answer
No. The three are the same in all three delivery models. What the fully autonomous model removes is the human between scope sign-off and the report, not the boundary around what the run may do.

Who signs the scope?

The answer
You do, before the engagement. In the fully autonomous model that sign-off is the last human action of the engagement, which is what makes it the document everything else is measured against.

The record

What a written approval leaves behind

An approval that has to be in writing produces a document, and that document is what a reviewer reads afterwards: what was asked for, what was permitted, and when. The half of it people underestimate is the refusals. A gate that was raised and never released is as informative as one that was — it says the run reached a point where it would have gone further and did not, which is a fact about the engagement that a findings list does not contain.

Alongside it sits the scope itself: the targets, the classes, the roles, and for the classes that need one, the movement boundary. In the fully autonomous model that document is the last human action of the engagement, which is why every page on this site treats it as the thing the run is measured against rather than as paperwork preceding it.

Scope sign-off, then nothing

That is the claim, and the three gates above are what keeps it from being a slogan. The autonomy boundary page sets out where the human sits in each delivery model.