Security Scope Agreement (Onboarding)
A template with 7 steps: Inventory every system that touches client data before drafting any security language.
By InnovaAI Research
What are the steps?
Security Scope Agreement (Onboarding)
- 01
Inventory every system that touches client data before drafting any security language
List repositories, cloud accounts, endpoint fleets, and third-party APIs by name and owner. A scanner such as Sentrint can produce a repository-level baseline, but the inventory must also cover the browser and firewall policy layer that tools like Bor manage on Linux fleets.
- 02
Classify each asset by breach consequence, not by technical category
Separate assets that would trigger regulatory notification from those that would only cause rework. This determines which controls get named in the agreement and which stay internal.
- 03
Write the scope clause around controls delivered, never around outcomes guaranteed
State the specific scans, monitoring windows, and response times the agency will run. Absolute security promises create liability that no retainer covers, and attack surfaces change faster than any contract cycle.
- 04
Define the client-side obligations that the controls depend on
Patch cadence, credential rotation, and access revocation sit with the client in most engagements. Name them explicitly so a missed patch is not read as an agency failure.
- 05
Set the incident response clock and the notification path in writing
Agree on detection-to-notification time, who calls whom, and what the agency will and will not say publicly. Ambiguity here is where most post-incident disputes start.
- 06
Price the security work as a line item, not as a bundled favor
Proactive threat modeling and response readiness consume senior hours. A named line item protects margin and gives the client a reason to renew the security scope separately from campaign work.
- 07
Have both parties sign a scope-change trigger list
New AI agents in production, new data sources, or new jurisdictions should automatically reopen the agreement. Runtime governance layers such as Vaultak exist precisely because agent behavior drifts after launch.