Review results and troubleshoot
After you launch a campaign, Respan opens a live workspace and builds the report in the same view.
Follow campaign progress
There is no cancel, pause, resume, edit, or delete workflow. Retrying creates a new campaign.

The progress rail has five stages:
Use Target profile to review what reconnaissance inferred, Current attempt to see the active objective and response, and the event log to understand how the campaign reached a result. Live grades and findings are provisional until report generation finishes.
Read the report

Start with:
- Overall grade: A through F when a score is available;
?when no probes completed - Confirmed findings: failures supported by campaign evidence
- Score: a 0–100 blend of confirmed-finding severity and resistance, when available
- Resistance rate: the share of completed probes that the target refused, when available
- Probe progress: sent, completed, errored, and planned probes
- Duration and estimated cost: run time and the engine’s model-activity estimate, when available
- Severity and category results: where to prioritize review and where coverage was limited
Campaign state and report state answer different questions. A campaign can be Succeeded while its report is not complete:
Always inspect completed and errored probe counts before treating the grade as representative of the planned scope.
An A does not prove that an agent is secure against every attack. It means no severe vulnerability was confirmed within that campaign’s tested scope and budget.
Understand a finding
Open a confirmed finding and review:
- The decisive prompt and target response
- The evidence used to confirm the failure
- The security category and attack technique
- Severity
- OWASP or MITRE ATLAS mappings, when present
Prioritize critical and high-severity evidence, then reproduce the issue in a controlled environment. After changing the agent or its safeguards, launch a new campaign to test the updated target.
Red Team campaigns are adaptive, so two runs can use different probes or produce different results. Use the finding details and event log for the run you are reviewing.
Coverage and limits
Black-box campaigns cover risks that Respan can test through the connected conversation interface. Tool-dependent tests run only when reconnaissance detects the required capability. For example, a test that needs customer lookup cannot run when the target exposes no such tool.
Some categories require access that a black-box endpoint does not provide, such as retrieval, embedding, training-data, or response-side controls. Additional access required means the category was not fully testable; it is not a pass or a failure.
Your organization’s current campaign allowance and reset date appear in the campaign creation screen. Avoid using a fixed quota from a copied report because allowances can vary by plan.
Troubleshoot a run
If a campaign fails, fix the displayed error before launching its replacement. A succeeded campaign with missing probes should be reviewed as partial coverage, not silently treated as complete.
Handle report data safely
Reports can contain attack prompts, target responses, reconstructed instructions, secrets, personal data, and details about connected tools. Restrict access to the report and any copies you create.
Use non-production targets where possible, keep credentials narrowly scoped, and grant an adapter only the network and tool access required for the assessment.