The penetration tester and client must define explicit scope boundaries including target IP ranges, domains, applications, physical sites, and business units that are included or excluded from testing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.