- What the worksheet settles before day one
- The apex domains you are certain about and the entities you are not. The authorisation scope in writing — what may be tested, from which source addresses, in which windows, and what is out of bounds, whether that is production at month end, anything a partner owns, or anything in a jurisdiction your legal team has not cleared. And the definition of “found”: does a parked domain count as an asset, does a credential from a six-year-old dump count as an exposure, does a look-alike domain that resolves nowhere count. All of it written while nobody yet knows which way the numbers will fall.
- What it records while the trial runs
- Assets discovered that your inventory did not hold, and which of the properties you held back were found without being named. Findings actioned, findings rejected, and the reason recorded against each. Median triage time in week one against week two. The findings you disputed, what evidence the vendor produced, who arbitrated and how it ended. The worksheet asks for disagreements to be logged rather than quietly resolved, because by the end of the fortnight that log tells you more than the findings do.
- What it decides at the end
- Whether the platform met the pass criteria you wrote down before it started, criterion by criterion, with the gaps named rather than averaged away. A trial scored after the readout is scored on the readout, and every vendor in this category is good at readouts. The sheet is designed so the decision is made against a page you filled in a fortnight earlier — including the honest entry where a criterion turned out to be the wrong thing to have measured.