scopeflowEARLY BETA

MUSE REVIEW · EARLY BETA

Test Scopeflow

This beta is operated by VijeyaHasen. Contact hasenhamesh15@gmail.com for review questions or a security report. Use fictional project and client data.

Access

The app, documentation, and policies are publicly accessible. Create a Scopeflow account and sign in from the workspace to create test projects. Accounts are isolated by their verified Neon Auth user identifier. No shared password or pre-seeded customer account is provided.

Functional review

  1. Create a scope with deliverables, a fee, revision allowance, and exclusions.
  2. Open its review link in a signed-out browser. Reviewers do not need an account. The link is a bearer capability, so do not publish it.
  3. Request changes with a fictional reviewer name and a comment.
  4. Return to the creator workspace, refresh the decision, change the fee or deliverables, and save a new version.
  5. Open the new link and inspect its changes from the previous version. Approve it and confirm the history preserves both decisions.
  6. Back in the workspace, the approved project now shows its agreement ledger. Paste a fictional client request into “Is this in scope?”, draft a change order from it, set a fee change and record it.
  7. Open the same review link again. Confirm the change order is listed, approve it with a fictional name, and check the fee, deliverables and “Verified in your browser” record fingerprint update.
  8. Try submitting a decision through the old link. It must fail. Try submitting a second decision on the approved version. It must also fail.

API and Muse testing

Use the Muse & API page to create a 30-day token. Use it as an Authorization: Bearer header. The OpenAPI document defines the supported create, list, and revision calls. Ask Muse to build a custom integration using that document and enter the key through its secure credential flow. This integration has not yet been verified with a Muse account; this page does not claim Meta approval.

Security checks

Use two accounts that you control to check that one account cannot list or revise the other’s projects. Confirm absent or revoked credentials return 401 and inaccessible project IDs return 404. Check that negative fees, invalid dates, stale version numbers, and oversized payloads are rejected. Write operations allow up to 30 requests per minute per account; review decisions allow up to 10 attempts per minute per valid link. These limits are operational controls, not an invitation to load-test the hosting provider.

Known limits

Reviewers’ names are self-reported. Anyone with a review link can see its version and changed fields from the previous version. This beta does not send messages, verify signatures, process payments, offer team workspaces, or guarantee production availability. All scopes and their values are records only; saving or approving a scope does not charge anyone. The proposed paid plans are not active.

Test cleanup

Revoke your API token after testing. Contact the operator for deletion of test projects or an account-data export. Report a suspected vulnerability privately to the support email and avoid accessing real user data or disrupting the service.