A successful AI red team engagement hinges on a meticulously defined scope and clear rules of engagement (RoE). This document serves as the foundational agreement between the red team and the system stakeholders. It prevents misunderstandings, protects both parties, and ensures the engagement delivers maximum value without causing unintended disruption. Use this template as a starting point, adapting it to the specific context of your target AI system and organizational policies.
AI Red Team Engagement & Scoping Document
This template provides a comprehensive structure for defining the parameters of an AI-focused red team assessment. Fill in each section with as much detail as possible before commencing any testing activities. All parties involved must formally approve this document.
| Engagement Plan: [Project Name/Code Name] | |
|---|---|
| Document Control |
|
| 1. Executive Summary |
Provide a high-level overview of the engagement. State the purpose, the primary target system, and the key business or security drivers for this assessment. This section should be understandable to non-technical stakeholders. Example: “This document outlines the scope and rules for a red team assessment of the ‘CustomerAssist’ GenAI chatbot. The primary objective is to identify and assess vulnerabilities related to prompt injection, data leakage, and harmful content generation before the model’s public launch. The engagement will run from [Start Date] to [End Date].” |
| 2. Project Objectives |
List the specific, measurable goals of the engagement. What questions are you trying to answer?
|
| 3. Scope Definition |
3.1 In-Scope Systems & ModelsList all explicit targets. Be precise with identifiers, endpoints, and versions.
3.2 Out-of-Scope Systems & ModelsExplicitly state what is NOT to be tested. This is as important as defining what is in scope.
3.3 In-Scope Attack VectorsDetail the types of attacks that are permitted.
3.4 Out-of-Scope Attack VectorsDetail forbidden tactics to prevent collateral damage.
|
| 4. Rules of Engagement (RoE) |
|
| 5. Approval & Sign-off |
By signing below, all parties acknowledge and agree to the terms outlined in this document. Red Team Lead: _________________________ [Name], [Date] System Owner: _________________________ [Name], [Date] Authorizing Manager/CISO: _________________________ [Name], [Date] |