⚖️ Start with governance (non-negotiable)
Get written authorization — explicit, scope-limited permission from asset owner(s). Include IP ranges, networks, allowed ports, allowed windows, and approved scanner source IP(s).
Document Rules of Engagement (RoE) — who to notify, emergency kill...