# Scope groups and reward tables

**Category:** [Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/bug-bounty)
**Updated:** 2026-10-04

## Why rewards live on the group

Each scope group carries its own reward table. That is deliberate: a public API and a channel for leaked credentials can be worth very different amounts and still belong to one program. A single table for the whole program cannot express that.
## Setting one up

- On **Scope & rewards**, add a group and give it a name a researcher will recognize — *Public API*, *Mobile apps*, *Corporate exposure*.
- Set the currency and, if you want one, a headline maximum.
- Fill the P1 to P4 ranges. Leave a level blank if you do not reward it — blank and zero are different statements, and a blank level simply is not published.
- Add targets: a name, a location such as a URL or a package, tags, and any known issues.

## Publish your known issues

The **Known issues** field on a target is published on purpose. It is how you stop paying five times for a bug you have already accepted and cannot yet fix, and it saves a researcher a weekend on something you know about.
## Out-of-scope groups

A group can be marked out of scope. It still appears on the page, labeled — telling somebody what not to test is more useful than leaving it unsaid.

---

## Related Articles

- [Getting started with Bug Bounty](https://help.totalctrl.app/en-US/articles/bugbounty-getting-started-1)
- [Response times and the disclosure window](https://help.totalctrl.app/en-US/articles/bugbounty-sla-1)
- [Who can work a program](https://help.totalctrl.app/en-US/articles/bugbounty-access-1)
- [Internal notes and talking to a reporter](https://help.totalctrl.app/en-US/articles/bugbounty-comments-1)
- [What is stored, and what is never sent](https://help.totalctrl.app/en-US/articles/bugbounty-data-handling-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)