# Scope groups and reward tables

**Updated:** 2026-10-04

## Why rewards live on the group

Each scope group carries its own reward table. That is deliberate: a public API and a channel for leaked credentials can be worth very different amounts and still belong to one program. A single table for the whole program cannot express that.
## Setting one up

- On **Scope & rewards**, add a group and give it a name a researcher will recognize — *Public API*, *Mobile apps*, *Corporate exposure*.
- Set the currency and, if you want one, a headline maximum.
- Fill the P1 to P4 ranges. Leave a level blank if you do not reward it — blank and zero are different statements, and a blank level simply is not published.
- Add targets: a name, a location such as a URL or a package, tags, and any known issues.

## Publish your known issues

The **Known issues** field on a target is published on purpose. It is how you stop paying five times for a bug you have already accepted and cannot yet fix, and it saves a researcher a weekend on something you know about.
## Out-of-scope groups

A group can be marked out of scope. It still appears on the page, labeled — telling somebody what not to test is more useful than leaving it unsaid.


---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)