Documents

Testing Authorization

We run tests that touch a live system only on the basis of a written authorization. Without one we touch nothing, even if the client asks verbally.

Last updated: 21 August 2026

Why it is necessary

Sending a request to someone else’s system without its owner’s consent is a legal problem, not a matter of good manners. The authorization protects both parties: you from us doing something we did not agree on, and us from the allegation that we acted without a legal basis.

The authorization must be signed by a person who actually has the right to dispose of the system. If the system belongs to your client, we need your client’s consent, not yours.

What it must contain

ItemWhy
Who authorizesFirst name, surname, position and the basis for representing the system owner.
What it coversSpecific URLs, repositories, projects and databases. No wording such as “the entire infrastructure”.
Which environmentTest, staging or production. This changes everything, including when the tests are run.
Which testsAuthorization level from L0 to L4, as defined in the methodology.
Time windowFrom when to when. After that date the authorization expires and the tests will not run.
LimitsMaximum number of requests per minute, permitted test accounts, permitted methods.
What is prohibitedProhibited actions listed explicitly, for example modifying production data.
Emergency contactA person and a channel available during testing, for immediate contact.
StoppingHow to stop testing at any moment and without giving a reason. One message is enough.

How it works on our side

The authorization is not filed in a binder but recorded in the system. Every task has a minimum level assigned, and the queue rejects any task for which there is no active authorization covering that asset, that environment and that moment.

This is a technical block, not a warning in the interface.

How to get the template

We send a template tailored to your case together with the quote, after you submit a request through the form. If you need it earlier, write to arlets@yesfor.ai.