Documentation
Griffin

AUTHORIZATION AND OWNERSHIP

Authorize and verify a target

Record written permission, prove technical control, evaluate preflight, and activate an eligible Griffin target.

Open the target workflow

  1. Open Applications and select Inventory.
  2. Find the registered target and select Review access.
  3. Confirm the exact normalized URL and scope version shown under Authorization and ownership.

Step 1: Record written authorization

  1. In Authorization basis, describe the current written permission that covers the exact origin and path, such as a signed statement of work.
  2. Optionally add a Supporting reference using a contract, ticket, or approval identifier that reviewers can locate. Do not paste secrets or the protected document itself.
  3. Select the required attestation confirming that current written authorization covers the exact origin and path for observational checks.
  4. Select Record 30-day authorization and confirm the new active record and expiry in authorization history.

Authorization example

Step 2: Verify technical ownership

  1. Choose DNS TXT or Well-known file as the Proof method.
  2. Select Generate one-shot challenge.
  3. Give the exact record name or file URL and displayed value to your own DNS or web operations team.
  4. Publish the proof before its 15-minute expiry. The challenge can be checked only once.
  5. Select Check published proof and confirm the ownership history reports verified.

Evaluate preflight and activate

  1. Select Evaluate scan preflight.
  2. Review whether the result is Allowed or Denied and resolve every reported requirement.
  3. When preflight is allowed, close the authorization panel and return to Inventory.
  4. Select Activate for the target. Griffin evaluates the safety requirements again before activation and before scanning.
  5. Confirm the target status is active before creating an on-demand or scheduled scan.

Keep access current

  • Renew creates a new authorization record; it does not rewrite history.
  • Revoke immediately blocks new requests and stops queued or running work at the next safety check.
  • Ownership proof is time-bounded and continuity is rechecked. A failed continuity check expires the proof.
  • Changing or restoring target scope requires fresh written authorization and ownership proof.
Was this page helpful?