Operating ProcedureExecution layer

Pre-Engagement Security Scoping (Onboarding)

A checklist with 7 steps: Inventory every asset the client expects the agency to touch before signing the retainer.

By InnovaAI ResearchPublished

What are the steps?

checklist

Pre-Engagement Security Scoping (Onboarding)

  1. 01

    Inventory every asset the client expects the agency to touch before signing the retainer

    List ad accounts, CRM instances, repositories, cloud buckets, and any AI agent pipelines. Anything unnamed at scoping becomes an unbounded liability later.

  2. 02

    Classify each asset by data sensitivity and regulatory exposure

    Separate public marketing assets from systems holding PII, payment data, or health records. A regulated-industry client using Tresorit-style encrypted storage has different obligations than a B2C brand running open web forms.

  3. 03

    Map which third-party tools already hold client credentials

    Document every integration with API access, including AI coding assistants and automation platforms. Exposed keys in client-facing apps have produced four-figure unauthorized usage bills in documented cases.

  4. 04

    Define the security scope boundary in writing, including what the agency does not cover

    State plainly that the agency monitors, scans, and remediates within named systems only. Absolute security guarantees are uninsurable; scope language is the substitute.

  5. 05

    Assign a named owner for security incidents on the account

    One person, reachable, with a documented escalation path. Shared ownership means no ownership when a breach window opens at 2am.

  6. 06

    Price the security work as a line item, not a bundled courtesy

    Proactive threat modeling and periodic scanning are recurring deliverables. Bundling them into general retainer hours hides the cost and invites scope creep.

  7. 07

    Confirm the client's own incident response contact and notification obligations

    If the client has regulatory breach-notification duties, the agency needs their legal contact before work starts, not after an incident.