Use this page when a term in the Tahr interface is unfamiliar.
#Application
An application is a target Tahr can assess, including its URLs, access details, repository settings, and testing context.
#Assessment
An assessment is one execution of a Tahr testing workflow against an application. It may be started manually, scheduled, triggered from CI/CD, or run in a routine.
#Authenticated testing
Authenticated testing uses test users to exercise functionality unavailable to anonymous visitors.
#Finding
A finding is a security issue or observation produced by an assessment, with severity, evidence, affected areas, status, and review controls.
#Authorization finding
An authorization finding concerns access-control behavior, such as a user viewing or changing data they should not access.
#Attack path
An attack path connects observations into a larger exploitation chain and explains how smaller issues can combine into greater risk.
#Routine
A routine is an ordered set of assessment steps used to repeat a standard workflow.
#Portfolio
A portfolio groups applications by product, team, business unit, or environment.
#Verified domain
A verified domain proves that an organization controls a hostname and helps prevent accidental testing of assets it does not own.
#Reserved IP
A reserved IP is a dedicated IP useful when a target requires IP allowlisting.
#Assistant
Assistant is a planned organization-scoped chat for reviewing findings and assessment information. It is coming soon and is not currently available.
#Threat Modeling
Threat Modeling is an assessment and workspace for threats, attack paths, assets, assumptions, evidence, and recommended mitigations.
#Tahr context
Testing instructions is the application-level base field. A finding, authorization finding, or authorization matrix comment can be marked with Add this comment to testing instructions for future assessments. The saved comment has a Tahr context badge and remains attached to its finding or authorization review item. Tahr merges marked comments into effective instructions for future assessments without rewriting the application's Testing instructions field.
#Application Document
An application document is an uploaded file that adds context to supported workflows, especially Threat Modeling.
#Assessment Credit
An assessment credit is a unit used when Tahr starts an assessment type that shows a credit requirement.
#Source Code Diff Review
Source Code Diff Review examines repository changes since a selected source analysis commit.
#Routine Template
A routine template is a provided starting workflow that teams can copy when its assessment types are available.