# Getting started with Bug Bounty

**Updated:** 2026-10-04

## Publish a program in four steps

- Open **Bug Bounty** and choose **New program**. Give it a name and a short summary — the summary is the first line a researcher reads.
- Go to **Scope & rewards** and add at least one scope group, then the targets inside it. A program cannot be published without scope, because a program page with no scope invites reports you will only decline.
- Go to **Policy** and write your rules of engagement, what is out of scope, and your safe harbor terms. Set the response times you can actually keep.
- Back on **Overview**, set the status to **Open**. The public address is shown on that page.

## What a researcher sees

Your program page shows the summary, your safe harbor level, your response commitments, the policy, and every scope group with its reward table and targets. If the program is accepting reports there is a **Submit a report** button.

Reporters do not create an account. They enter an email address, we send a link, and that link lets them submit and follow their reports. Nobody who reports a bug becomes a user of your workspace.
## Working the reports

Every report lands in **Reports** for that program. Open one to set a state and a priority, add notes, and hand it to your issue tracker. The reporter is emailed when the state changes — that happens automatically, so a report cannot be quietly triaged while the person who sent it hears nothing.


---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)