Skip to main content
RealHumanTests

Authorization and consent

Authorization and consent come before any test

We only test systems a customer owns or has written authorization to test. Every tester works under a consent and confidentiality contract, and recording is consented on every side of the conversation.

The owner

Written authorization from the system owner

Before a single session runs, the business that owns the AI signs a written authorization. If your AI runs on a vendor platform, you authorize testing of your own deployment; if a vendor's terms require their notice or approval, that is settled during scoping.

The authorization spells out:

  • The exact system being tested, and the channels testers may use to reach it
  • The testing window, so your team knows when test sessions will arrive
  • The scenarios and personas agreed during scoping
  • How test bookings, orders, leads or tickets are marked or cancelled, so nothing reaches real operations by surprise
  • Recording of sessions, and who receives the transcripts and recordings
  • Anything testers must not do, such as completing a real purchase

The testers

Contracted, consented and confidential

Every tester signs a contract before joining a panel. It covers consent to being recorded during sessions, confidentiality for everything they see and hear, and the conduct rules for testing: stay in persona, stay inside the agreed scenarios, and never use real personal or payment details.

Testers only see what an ordinary customer would see, plus the scenario brief we write for them.

Recording

All-party recording consent

Some places require every party to a call or conversation to consent before it is recorded. We cover both sides in writing: the business consents through its authorization, and each tester consents through their contract. No real customer of yours is ever part of a test session, so no one is recorded who has not agreed to it.

If a session is handed to one of your human staff, the authorization sets out how that is handled, for example by agreeing in advance that testers end the session at handoff, or that your team is told when the testing window is open.

Boundaries

What is always out of bounds

No authorization or request unlocks any of these.

  • Testing a system without written authorization from its owner, including a competitor's system
  • Security or penetration testing, attempts to access data, or anything aimed at the infrastructure behind the AI
  • Real purchases, real charges or real cancellations that were not agreed in writing
  • Using a real person's identity or real customer data in a test
  • Harassing or deceiving real staff: when a session reaches a human agent, testers follow the handoff instructions agreed in the authorization

The Benchmark

How the public Benchmark handles consent

The public Benchmark only scores products whose owner authorizes testing, or publicly available consumer-facing experiences used exactly as an ordinary customer would use them. It never places real orders, costs a business money, or tests anything an ordinary customer could not reach. The full rules are in the Benchmark methodology.

This page explains how we work. It is not legal advice about recording or consent law where you operate.

See your AI the way your customers do

Tell us what your AI does and what worries you. We build a panel of real people around it and hand you every transcript, a score per criterion and a plain verdict. We never sell the fix.