Scoping in one call
We size the test on the application as it really is, not on a page count. The scoping call covers the number of distinct user roles, the count of dynamic pages and API endpoints behind the UI, whether there is a payment or file-upload path, and which environment we test in. From that we fix the number of testing days and the reporting date before any work starts.
- Typical effort: 5 to 8 testing days for a single application with two or three roles; larger multi-tenant platforms are phased by module.
- Access we need: one account per role, a staging or production URL, and any IP allow-listing for our testing egress.
- Rules of engagement: agreed testing window, emergency contact on both sides, and an explicit list of anything out of bounds such as denial-of-service or third-party integrations.