Safety boundaries
These controls exist in the product. They are not pentest claims and not restore claims.
Authorization gate
Work does not start outside the authorized project. Confirm target, identities, and exclusions in Workbench before a scan.
Authorization for one application does not include extra subdomains, identity providers, payment processors, CDN origins, or customer integrations unless those are written into the project.

Metadata IP blocking
Metadata and link-local targets are rejected. If a hostname resolves to a blocked address class, Workbench does not treat it as an authorized surface.
This is a safety control, not a network pentest feature.
Evidence drift
A signal when stored evidence no longer matches the current finding context. Re-open the HTTP Record or OAST callback before you change finding status.
Evidence drift is not backup or restore.
Production
Prefer staging. If production is explicitly authorized: keep scope narrow, exclude destructive workflows, watch the target, keep an operator in Workbench who can stop the scan.
Related
Need a workflow that is not documented here? Email contact@eresussec.com.