Agree the boundary before the tool
A project brief should make it possible to tell the difference between an authorised test and an unsafe action. Confirm the owner, target, time window, allowed methods, and what is explicitly out of scope.
\nDo not infer permission from curiosity, a hostname, or a credential that happens to work. Written scope protects you, the organisation, and the people whose data may be involved.
\n- Record the authorisation and the person who can change it.
- Use test data and least-privilege access where possible.
- Stop and escalate when the observed situation differs from the brief.
Handle findings with care
Keep notes limited to what the project needs and follow the organisation's handling instructions. Report a concern through the agreed route instead of sharing it broadly or turning it into a public example.
\nThe DIVD.Works safety page is a concise baseline. The project owner and school may add stricter requirements.
\n- Do not access, use, or share systems and information without permission.
- Report concerns, incidents, or unsafe behaviour promptly.
- Ask your supervisor when the brief, evidence, or next step is unclear.