Penetration Testing Guide
How to Prepare for a Penetration Test

A practical guide for SaaS teams preparing scope, test environments, user access, documentation, timelines, and communication before a penetration test begins.

Overview

What Preparation Actually Means

Preparation is not paperwork. It is making sure the right application areas, user roles, environments, and business workflows are ready before testing starts.

Clear scope

Know which product areas, APIs, portals, roles, and workflows are included before testing begins.

Working access

Prepare realistic test accounts and remove avoidable login, allowlist, and permission blockers.

Useful output

Good preparation leads to stronger findings, clearer evidence, and actionable remediation.

Visual Scope

Turn the Product Into a Testable Surface

A penetration test becomes more valuable when the tester can see how users, roles, APIs, and business-critical actions connect.

01

Scope

Application, API, portal, or workflow.

02

Access

Accounts, roles, tenants, and authentication paths.

03

Context

Important business workflows and sensitive actions.

04

Testing

Manual validation of reachable risk and exploitability.

Preparation Flow

From Request to Testing

This is the simple path most teams follow before a focused penetration test starts.

01

Initial Discussion

Share product area, objective, and security concern.

02

Scope Review

Confirm targets, environments, exclusions, and roles.

03

Access Setup

Prepare accounts, tenants, allowlists, and documentation.

04

Testing Begins

Manual testing starts against the agreed scope.

What to Prepare

What Your Team Should Have Ready

You do not need perfect documentation. You need enough context for the engagement to begin cleanly.

Scope definition

  • Application, API, portal, or workflow
  • In-scope and excluded areas
  • High-risk workflows

Testing environment

  • Production or staging decision
  • Stable representative build
  • Features deployed and reachable

Access and accounts

  • Accounts for relevant roles
  • Tenant or organization setup
  • Allowlisting and restrictions

Documentation

  • Entry points and URLs
  • API collections if available
  • Recent changes or sensitive areas

Communication

  • Main point of contact
  • Access issue owner
  • Urgent finding path

Role coverage

Authorization testing is stronger when admin, manager, member, viewer, guest, or tenant-specific accounts are available.

Typical Engagement Timeline

What Happens After You Contact THF

Day 1

Kickoff

Confirm scope, environment, and point of contact.

Days 2–5

Testing

Validate access, test workflows, and confirm findings.

Day 6–7

Reporting

Prepare evidence, impact, and remediation guidance.

After fixes

Retesting

Validate fixes and document final status.

Readiness Snapshot

Preparation Readiness Matrix

Scope definedReady
Environment readyNeeds Attention
Test accounts readyReady
Documentation sharedNeeds Attention
Point of contact assignedReady
Output

What You Receive After Testing

The value of a penetration test is the combination of validated findings, clear evidence, business impact, remediation guidance, and retesting support.

Validated findings

Confirmed issues, not scanner noise.

Technical evidence

Requests, responses, screenshots, and reproduction context.

Remediation guidance

Practical next steps your team can act on.

FAQ

Common Questions

Answers for teams preparing for SaaS, API, GraphQL, and access-control-focused penetration testing.

Should we test production or staging?+
It depends on risk, stability, and engagement goals. Staging can be safer, while production may be more representative when carefully scoped.
Do we need to provide test accounts?+
Usually yes. Test accounts improve speed and coverage, especially when roles, authorization, or tenant boundaries are in scope.
Can APIs and web app flows be covered together?+
Yes. SaaS workflows often span web UI, REST APIs, GraphQL, background actions, and admin portals.
How long does preparation usually take?+
Usually not long if scope, access, environment, and a point of contact are clear.
What if our team is non-technical?+
That is fine. A good testing partner should guide the process and explain risk clearly.
Next Step

Need a Penetration Test Built Around Your Product?

The Hidden Finds helps SaaS teams scope focused manual testing across web applications, APIs, GraphQL, access control, business logic, and multi-tenant risk.