01
1. Describe the scenario
- Open /settings/scenarios and enter a title that names the behavior you intend to test.
- Add a description that states the expected evidence and its limit; do not place hostnames, credentials, or other secrets in these fields.
- Choose one available category: owasp-top10, auth-controls, cloud-misconfiguration, data-exfiltration, or ai-attacks. A category organizes the record; it does not prove coverage.
02
2. Save and verify the record
- Click Create and confirm that the title and category appear in the tenant's private list.
- The current form stores a standard staging template behind the record and supports listing or deletion. It does not expose template editing or MITRE-tactic selection.
- Do not treat the saved record as an executed test: the current /runs/new flow does not yet select these records. Only a completed run against an allowed target can produce evidence.