Roles and authority
- who may disclose information
- who confirms exceptions
- where authority is described ambiguously
- which roles carry an elevated burden of trust

Обновлено
01 / AUTHORIZED SOCIAL ENGINEERING ASSESSMENTBLACKFILE conducts controlled and written-authorised tests of how employees, contractors and internal procedures respond to attempts to obtain information, alter an action or bypass established procedure
We assess not "weak people" but the combination of context, authority, communication channel, quality of procedure and availability of a safe escalation path
The test does not begin until written authorisation, the composition of participants, prohibited actions and conditions for immediate stoppage have been agreed
A message may refer to urgency, a manager's authority, a routine process, a business context or a wish to help a client. Even an experienced specialist can make the wrong decision if the procedure is ambiguous, confirmation is difficult and a safe escalation path is not defined
This is why the result of a test should not be reduced to a percentage of "those who made a mistake". It is necessary to establish why the particular situation became possible and what change to the process will reduce the risk of recurrence
The purpose of the check is to strengthen the decision-making system, not to catch or publicly punish an employee.
How well the request fits an ordinary working situation.
Whether the employee is entitled to perform this action without approval.
Whether there is a way to independently confirm the request.
Whether a safe way to stop and clarify is known.
The number of external requests is growing, and employees are engaging with new advisers, counterparties and platforms.
Calendars, routes, documents, payments and personal contacts pass through a small circle of trusted staff.
A change of payment details, an urgent payment or a non-standard instruction can be initiated by a convincing message.
External teams take part in IT, finance, hiring, communications or administration and become part of the circle of trust.
It is necessary to check whether staff response is stable and whether the incident reporting channel works.
New employees, roles and countries create temporary gaps between formal policy and actual practice.

Опасные запросы выглядят правдоподобно. Процедура и эскалация решают больше, чем бдительность.
The same request may be safely declined in one department and lead to an error in another. The map does not rank people - it shows recurring conditions under which controls stop working
Payment and urgent instruction - the area of highest risk: a change of details proceeds without independent confirmation through a known channel
Red marks only a material process gap. Employee names are not shown in the interface. On the mobile version the matrix becomes a vertical index of roles with expandable scenarios
The authorised client, legal grounds, departments, countries and the period of the engagement are recorded
→Permitted channels, allowed actions, excluded categories and persons who must not be involved are defined
→Events triggering immediate termination of a specific scenario or of the entire check are established
→Scenarios model risk but do not require obtaining real passwords, financial credentials, or sensitive data.
→The course of the check is recorded, and access to the results is limited to the authorized team.
→Results are translated into changes to procedures, training, and escalation channels without publicly singling out employees.

Цель проверки - укрепить систему принятия решений, а не наказать сотрудника.
A brief description of the most material risk conditions, without unfounded ranking of individual employees.
Which combinations of authority, channels, and requests require additional control.
What was checked, under what conditions, and how the response developed.
Which procedures worked, where ambiguity arose, and where a safe verification path was absent.
Changes by urgency: immediate, short-term, and systemic.
Criteria for assessing whether risk has decreased after the changes.
It is checked whether a non-standard financial instruction requires independent confirmation through a channel known in advance.
It is assessed whether a reference to authority and urgency can substitute for the established approval procedure.
It is checked what information an employee discloses to a party who is familiar with the working context but has not passed the established identification.
from €3,000
The timeframe is determined by the scope of the check
Initial verification of resilience within a limited scope of roles and channels.
7 000-14 000 €
The timeframe is determined by the scope of the check
Full verification of the scope with a risk surface map and remediation priorities.
Individual quote
Phased execution according to an agreed schedule
Verification programme for an international structure with re-assessment after changes.
The exact scope, permissible scenarios, budget, and completion criteria are agreed in writing before the check begins.
BLACKFILE does not conduct unauthorized checks on third parties, does not help obtain other people's data or access, and does not publish personal results of employees. Specific scenarios undergo legal review with regard to the country and organization.
Systemic assessment of pressure factors and organizational weaknesses.
Open the practice area →SRV-02Work with information disclosure that has already occurred.
Open the practice area →SRV-03Verification of confirmable connections and environment within the scope of a lawful task.
Open the practice area →SRV-04Verification of biography, business history and risk factors for an agreed role.
Open the practice area →This is determined by the legal environment, internal policies and the agreed scenario. In any case, the check must be authorized in writing by an authorized party, have clear limitations and a proper follow-up review.
No. Scenarios are designed to test decision-making and procedure without obtaining actual credentials, banking details or sensitive information.
The purpose of the service is to assess the resilience of the system and improve processes. Personnel decisions fall within the client's competence and must comply with applicable labor law. The result of one scenario should not be interpreted outside its context.
No. Within the agreed scope, various communication processes, roles, confirmation of instructions and the escalation path may be assessed. Specific scenarios depend on the client's risks.
Only where appropriate authority, contractual grounds and written agreement on the scope of the check are in place.
The client receives a map of process risks, priority changes and criteria for a repeat check. The result must lead to an improvement of the system, not remain merely a report.
At the first stage, do not indicate employee names, e-mail addresses, phone numbers, passwords or other personal data.
Describe the processes giving rise to concern. BLACKFILE agrees the scope of authority, boundaries and stop conditions before any check begins.