- What you set
- The application, API or host this scan is against. One scan is one application or target, so a monorepo that ships two deployable services is two targets rather than one.
- What it decides
- Which coverage class the run is, and therefore what it actually does. A web application, a mobile app, an API, a thick client and a source tree are each worked as their own class.
- What it never decides
- Scope. The authorised scope is agreed in writing before a run, and nothing in a workflow file widens it.