People responsible for informed decisions
- Security and assurance practitioners
- Engineering and delivery teams
- Release and service owners
- Security consultants and reviewers
Work through repository, SBOM, DNS, header, vulnerability, finding, exception, and release-readiness decisions.
Individual developers can begin in a free, non-production Developer workspace. Team assignments, teaching, and governance features depend on plan and role.
The Lab combines method, guided practice, evidence, assessment, reflection, and an applicable output.
Define the asset, purpose, exposure, dependencies, owners, criticality, and release boundary.
Review repository, dependency, SBOM, DNS, header, and vulnerability observations in context.
Separate signal from conclusion and define severity, evidence, ownership, remediation, or exception needs.
Bring residual risk, open findings, exceptions, compensating controls, and decision authority together.
Each stage strengthens the evidence and preserves the distinction between learning and operational authority.
Review security evidence, finding, severity, treatment, exception, and release-decision principles.
Evaluate approved evidence for the selected security context.
Test interpretation, prioritization, traceability, proportionality, and decision quality.
Record uncertainty, evidence limitations, and conditions that would change the recommendation.
Prepare a security assurance record for authorized review.
A security assurance record containing context, reviewed evidence, findings, treatment, exceptions, residual risk, and a release recommendation.
Feedback and reflection support retry and mastery; they do not replace destination review or approval.
A completed Lab demonstrates learning evidence. It does not grant production authority, certify compliance, accept risk, or bypass human decisions.
The Lab is not a penetration test or authorization to test third-party systems.
Secrets, credentials, exploit material, and unsuitable production evidence must not be entered.
Release and risk acceptance remain with authorized owners.
My Batoi manages authentication and workspace selection before you enter the workspace-scoped Learn capability.