Red Team Scoping Tool
Before testing starts, an engagement scope has to settle which layers you may test and who owns each finding. The operating model decides both. Under AI-SaaS, the platform and model layers belong to the provider, and testing them without authorization is out of scope. This tool reads the SRF layer model and operating-model matrix, resolves testable, authorization-required, and out-of-scope layers, pre-assigns finding ownership, and produces a signable scoping record. It supplies the accountability overlay only. Methodology comes from the OWASP GenAI Red Teaming Guide and attack taxonomy from NIST AI 100-2.
Runs in your browser. No data leaves your device. Engagement details, authorization references, and scope notes stay local and are never sent anywhere.
This scoping record applies the CoSAI AI Shared Responsibility Framework's accountability overlay to an engagement: which layers your operating model puts in scope, and who owns each finding. It does not define attack techniques, test methodology, or severity; consult the OWASP GenAI Red Teaming Guide and NIST AI 100-2 for those. Governance artifact, not legal advice; verify testing authorization against your contracts before probing any provider-owned layer. This tool is one step in the AI security lifecycle: findings it pre-assigns route onward through the finding routing reference to the incident response playbooks.