Documents
Testing Authorization
We run tests that touch a live system only on the basis of a written authorization. Without one we touch nothing, even if the client asks verbally.
Last updated: 21 August 2026
Why it is necessary
Sending a request to someone else’s system without its owner’s consent is a legal problem, not a matter of good manners. The authorization protects both parties: you from us doing something we did not agree on, and us from the allegation that we acted without a legal basis.
The authorization must be signed by a person who actually has the right to dispose of the system. If the system belongs to your client, we need your client’s consent, not yours.
What it must contain
| Item | Why |
|---|---|
| Who authorizes | First name, surname, position and the basis for representing the system owner. |
| What it covers | Specific URLs, repositories, projects and databases. No wording such as “the entire infrastructure”. |
| Which environment | Test, staging or production. This changes everything, including when the tests are run. |
| Which tests | Authorization level from L0 to L4, as defined in the methodology. |
| Time window | From when to when. After that date the authorization expires and the tests will not run. |
| Limits | Maximum number of requests per minute, permitted test accounts, permitted methods. |
| What is prohibited | Prohibited actions listed explicitly, for example modifying production data. |
| Emergency contact | A person and a channel available during testing, for immediate contact. |
| Stopping | How to stop testing at any moment and without giving a reason. One message is enough. |
How it works on our side
The authorization is not filed in a binder but recorded in the system. Every task has a minimum level assigned, and the queue rejects any task for which there is no active authorization covering that asset, that environment and that moment.
This is a technical block, not a warning in the interface.
How to get the template
We send a template tailored to your case together with the quote, after you submit a request through the form. If you need it earlier, write to arlets@yesfor.ai.