--- name: engagement-intake-and-planning description: Ingest authorized engagement scope, validate targets and windows, and compile reviewable immutable action plans. --- # Engagement intake and execution planning 1. **Intake and RoE Verification**: - Collect and validate assessment targets, exclusions, operator ownership, assessment window, allowed effects, budget, and credential references. - Refuse any request lacking explicit operator identity, valid future assessment window, or unambiguous target specifications. 2. **Scope Boundary Enforcement**: - Reject wildcards (`*`, universal ranges), malformed network representations, and collisions where a target is simultaneously included and excluded. - Restrict active live requests to bounded subnets (/24 or narrower). 3. **Execution Mode Distinction**: - Explicitly distinguish between: - `planning`: Purely offline hypothesis modeling and test plan assembly. - `import`: Static parsing and ingestion of external logs, scans, and manifests. - `laboratory`: Synthetic or containerized simulation in an isolated environment. - `live`: Active network verification against production or staging infrastructure. - For `live` mode, mandate explicit budgets, non-empty emergency contacts, and active windows; refuse incomplete live requests. 4. **Action Plan Compilation**: - Produce an immutable `ActionPlan` (`cops.action-plan/v1`) with: - Declared platform prerequisites (OS, container boundaries, required CLI tools). - Bounded operations with an exact, independently measured caller-supplied tool version, expected evidence receipts, anticipated side effects, and cleanup obligations. - Execution budget limits and credential references. - Canonical SHA-256 `plan_digest`. - Do not infer or discover executable versions at runtime. Reject a missing or blank version for the scenario operation tool. 5. **CLI Invocation**: ```bash python3 -m cops engagement create --name "Scope Review" --owner "operator" --targets "10.0.0.5" --start "2026-10-05T00:00:00Z" --until "2026-10-05T23:59:59Z" python3 -m cops engagement validate python3 -m cops engagement plan --engagement --scenario COPS-E03.01-S01 --target 10.0.0.5 --tool-version python3=3.11.9 ``` Repeat `--tool-version TOOL=VERSION` when supplying more than one independently measured value. The CLI rejects malformed or blank entries and conflicting repeated values for the same tool. API callers must pass the required `tool_versions` mapping explicitly.