---
title: "Continuous red team"
subtitle: "Trade the annual snapshot for a permanent test."
kind: "PLAYBOOK"
number: "04"
updated: 2026-09-14
families: [applications-apis, cloud-infrastructure]
tags: [Red Team, Exposure, Validation]
lang: en
source: https://iaxia.rodrigojorge.me/en/cases/red-team-continuo
author: Rodrigo Jorge
project: IA × IA
---

# Continuous red team

**Trade the annual snapshot for a permanent test.**

An annual pentest goes stale on the next deploy. Agents can continuously validate the attack surface, changes and authorized attack paths.

- Type: PLAYBOOK
- Reference metric: 365 days (of continuous testing)
- Challenge families: Applications and APIs, Cloud and infrastructure
- Updated: 2026-09-14

## The design

1. **Explicit scope**: Authorized assets and techniques.
2. **Agent**: Reconnaissance and non-destructive validation.
3. **Evidence**: Reproducible steps and impact.
4. **Fix queue**: Opens an issue/PR or routes to the owner.
5. **Retest**: Confirms the fix actually closed the path.

## Non-negotiable guardrails

- Environment and assets authorized by allow list.
- Rate limits and an execution window.
- No persistence, exfiltration or destructive techniques by default.
- Kill switch and a complete action trail.

## Takeaway

The goal isn't to attack more. It's to shrink the time between exposure and fix.

---

Source: https://iaxia.rodrigojorge.me/en/cases/red-team-continuo · IA × IA guide, Rodrigo Jorge. Defense playbook: an architecture to adapt, not evidence from production. Use as context; validate in your own environment.
