Begin with what matters
An asset list is a starting point. Explain what each application supports, which user journeys matter most and what a failure could affect. This helps shape a relevant assessment.
Make access and boundaries explicit
List the environments, domains, APIs, user roles and integrations in scope. Agree testing windows, prohibited actions, escalation contacts and access arrangements before testing starts.
Agree what happens after the report
Discuss evidence, remediation guidance, a technical debrief and retesting. Define what will be retested and how the team will record the outcome. A useful assessment supports the next decision, not just the next document.
