Informative Appendix (non-normative)
This appendix provides an illustrative template for documenting operator qualification, training, competency assessment, remediation, mentoring, and succession evidence for autonomous penetration testing platforms. It helps operators, customers, and reviewers inspect whether personnel assignments align with the competency governance described in APTS-HO-018. It does not create or modify APTS requirements.
APTS-HO-018 defines expectations for operator qualification, autonomy-level assignment, training curriculum, incident-response preparation, ongoing assessment, remediation, mentoring, and succession planning. A dedicated competency record helps organizations show how those expectations are tracked for each operator without relying on informal personnel notes.
This appendix shows:
Use an operator competency record when the platform needs to document:
An operator competency record should:
Use stable identifiers so the record can be correlated with personnel systems, approval logs, and the engagement audit trail.
Recommended fields:
competency_record_idoperator_idoperator_rolerecord_versionstatuscreated_atlast_updated_atrecord_ownerSuggested status values:
activerestrictedsuspended_pending_remediationinactiveDocument what the operator is currently authorized to do and where that authority is defined.
Recommended fields:
authorized_autonomy_levelsmaximum_autonomy_levelauthorized_action_classesapproval_authority_rolesauthority_delegation_matrix_refshift_handoff_eligibleemergency_authority_rolesrestrictionsCapture qualifications that support the assignment without turning the template into a general HR file.
Recommended fields:
professional_qualificationsplatform_specific_qualificationsexperience_summarycertification_expiration_datesqualification_evidence_refsRecord required training modules and the evidence that they were completed.
Recommended fields:
module_idmodule_namerequired_for_levelscompletion_statuscompleted_atevidence_refinstructor_or_evaluatorSuggested module families:
Document the exercises that demonstrate the operator can respond to autonomous testing failures and emergency situations.
Recommended fields:
exercise_idscenarioskills_testedresultobserved_response_timeevidence_reffollow_up_requiredExample exercise scenarios:
Record assessment outcomes, restrictions, and conditions for restoring authority.
Recommended fields:
assessment_idassessment_typeassessment_dateassessor_roleresultgaps_identifiedrequired_remediationtemporary_restrictionsreassessment_due_atauthority_restored_atSuggested result values:
passedpassed_with_conditionsfailed_restrictedfailed_suspendedDocument operational continuity support without silently granting approval authority outside the Authority Delegation Matrix.
Recommended fields:
mentor_rolementoring_plan_refbackup_operator_rolesuccession_plan_refreadiness_statushandoff_practice_refscompetency_record_id: ocr-2026-0042
operator_id: operator-17
operator_role: senior-autonomous-testing-operator
record_version: "1.0"
status: active
created_at: "2026-05-01T10:00:00Z"
last_updated_at: "2026-05-15T16:30:00Z"
record_owner: security-operations-training-lead
authorization_scope:
authorized_autonomy_levels:
- L1 Assisted
- L2 Supervised
- L3 Semi-Autonomous
maximum_autonomy_level: L3 Semi-Autonomous
authorized_action_classes:
- exploitation-approval-cvss-7-to-8-9
- scope-uncertainty-escalation-review
- emergency-pause
- shift-handoff-primary
approval_authority_roles:
- ho-role-senior-operator
authority_delegation_matrix_ref: adm-2026-001#ho-role-senior-operator
shift_handoff_eligible: true
emergency_authority_roles:
- emergency-pause-operator
- secondary-kill-switch-operator
restrictions: []
qualification_evidence:
professional_qualifications:
- OSCP
- 6 years offensive security experience
platform_specific_qualifications:
- cloak-autonomous-platform-operator-l3
experience_summary: Led supervised and semi-autonomous web application assessments
certification_expiration_dates:
OSCP: "2028-04-30"
cloak-autonomous-platform-operator-l3: "2027-05-15"
qualification_evidence_refs:
- personnel-training-system#cert-8821
- personnel-training-system#platform-cert-4462
training_curriculum:
- module_id: apt-roe-101
module_name: Scope interpretation and Rules of Engagement handling
required_for_levels:
- L1 Assisted
- L2 Supervised
- L3 Semi-Autonomous
completion_status: completed
completed_at: "2026-05-02T14:00:00Z"
evidence_ref: lms#completion-771
instructor_or_evaluator: training-lead
- module_id: apt-ir-301
module_name: Incident escalation and evidence preservation
required_for_levels:
- L3 Semi-Autonomous
- L4 Autonomous
completion_status: completed
completed_at: "2026-05-08T18:00:00Z"
evidence_ref: lms#completion-779
instructor_or_evaluator: incident-response-lead
incident_response_readiness:
- exercise_id: drill-2026-015
scenario: emergency pause and state preservation during suspected scope drift
skills_tested:
- pause-activation
- escalation-routing
- state-preservation
- evidence-handoff
result: passed
observed_response_time: PT2M10S
evidence_ref: incident-drill-record-2026-015
follow_up_required: none
competency_assessments:
- assessment_id: assess-2026-044
assessment_type: annual-practical-assessment
assessment_date: "2026-05-15"
assessor_role: autonomous-testing-program-lead
result: passed
gaps_identified: []
required_remediation: []
temporary_restrictions: []
reassessment_due_at: "2027-05-15"
authority_restored_at: null
mentoring_and_succession:
mentor_role: principal-autonomous-testing-operator
mentoring_plan_ref: mentoring-plan-2026-operator-17
backup_operator_role: senior-autonomous-testing-operator-backup
succession_plan_ref: succession-plan-ho-2026
readiness_status: ready-for-primary-shift-duty
handoff_practice_refs:
- shift-handoff-record-2026-033
{
"competency_record_id": "ocr-2026-0042",
"operator_id": "operator-17",
"operator_role": "senior-autonomous-testing-operator",
"record_version": "1.0",
"status": "active",
"authorization_scope": {
"authorized_autonomy_levels": ["L1 Assisted", "L2 Supervised", "L3 Semi-Autonomous"],
"maximum_autonomy_level": "L3 Semi-Autonomous",
"authorized_action_classes": ["exploitation-approval-cvss-7-to-8-9", "scope-uncertainty-escalation-review", "emergency-pause", "shift-handoff-primary"],
"authority_delegation_matrix_ref": "adm-2026-001#ho-role-senior-operator",
"shift_handoff_eligible": true,
"restrictions": []
},
"qualification_evidence": {
"professional_qualifications": ["OSCP", "6 years offensive security experience"],
"platform_specific_qualifications": ["cloak-autonomous-platform-operator-l3"],
"qualification_evidence_refs": ["personnel-training-system#cert-8821", "personnel-training-system#platform-cert-4462"]
},
"training_curriculum": [
{
"module_id": "apt-roe-101",
"module_name": "Scope interpretation and Rules of Engagement handling",
"completion_status": "completed",
"completed_at": "2026-05-02T14:00:00Z",
"evidence_ref": "lms#completion-771"
}
],
"competency_assessments": [
{
"assessment_id": "assess-2026-044",
"assessment_type": "annual-practical-assessment",
"assessment_date": "2026-05-15",
"result": "passed",
"reassessment_due_at": "2027-05-15"
}
]
}
When inspecting an operator competency record, ask:
This template complements, but does not replace:
This template can help collect evidence for: