Targets, rules, budgets, approvals, and stop conditions are executable constraints.
Proof / AOTP
AI can accelerate testing.
Authority stays human.
Privacy. AI acceleration. Human control. AOTP explores how local agentic planning can increase useful offensive-security work without transferring campaign authority, evidence state, or final judgment to the model.
Why it exists
Agentic testing needs stronger controls than ordinary automation.
An agent can plan, adapt, choose tools, and continue. That capability only becomes useful for professional security work when campaign authority, approvals, stop conditions, evidence quality, and human review are part of the execution architecture.
The model assists planning while deterministic state governs what may actually execute.
Replay, provenance, controls, and human review reject unsupported candidates.
Confidential by design
Client and campaign context should not become the price of AI assistance.
AOTP is designed around local model assistance so sensitive security context can stay close to the workstation and the engagement rather than defaulting to an external model path.
Scope, evidence, targets, and sensitive working state remain under engagement control.
Model assistance can operate close to the work.
Operator judgment governs execution and findings.
Proof remains deterministic, reviewable, and replayable.
What this proves
Use AI aggressively without treating it casually.
AOTP demonstrates a practical architecture for increasing testing capability while protecting client material, maintaining explicit campaign authority, and preserving the evidence needed for professional conclusions.
Model assistance without unmanaged external exposure as the default.
Challenge promising paths after execution and separate signal from proof.
Material findings and report language remain accountable.
Campaign state continues through remediation verification and closure.
Why a client should care
AI should increase security-testing capability without weakening confidentiality, authority, or proof.
That discipline carries directly into how AI-assisted testing is used during real engagements.
Campaign context stays controlled.
AI expands useful testing capacity.
Authority and judgment remain human.