Rules of Engagement document creation — scope definition, prohibited/permitted actions, testing windows, escalation contacts, incident procedures.
The RoE is the legally binding foundation of every red team engagement. All other documents build on it.
Ask these questions in two rounds (batch related questions to minimize back-and-forth):
Round 1 — Identity & Scope:
external / internal / hybrid / assumed-breach / physicalRound 2 — Boundaries & Escalation: 6. Additional prohibited actions beyond defaults 7. Special permitted actions (phishing, password spraying, etc.) 8. Escalation contacts (minimum 2: client + red team lead) — name, role, channel 9. Authorization reference (contract #, signed letter)
Use the RoE schema from decepticon.core.schemas. Write to the engagement directory.
See references/roe-example.json for a complete example and ../references/schema-quick-reference.md for all required fields and valid values.
Run through the checklist in references/validation-checklist.md before presenting to user.
Write roe.json to the engagement directory, then present a human-readable summary to the user for confirmation.