Rules of engagement exist to make testing safe, lawful and useful. Write them down before the first packet.
What belongs in the document
Scope. Named systems, address ranges, domains and accounts — and explicitly what is out of scope. Third-party hosted systems need the provider's authorisation too; your contract with a SaaS vendor rarely grants you permission to test their platform.
Authorisation. Signed by somebody who actually owns the systems. This is the clause that distinguishes testing from an offence under computer misuse law in most jurisdictions.
Timing. Windows for noisy activity, change freezes to respect, and whether the blue team is told. "Nobody told operations" is the most common cause of an unnecessary incident.
Technique limits. Denial of service, social engineering, physical access, testing in production, and what happens on finding live customer data. Say what is permitted rather than listing what is not.
Data handling. What may be captured, where it is stored, how long it is kept and how it is destroyed. A tester's evidence archive is a concentrated copy of your worst exposures.
Contacts and escalation. Who to call on discovering a critical issue or evidence of a prior compromise, and the number that works at 3am.
Stop conditions
Agree in advance what halts the engagement: a production outage, discovery of an active intruder, or anything suggesting the test has strayed outside scope. A test that quietly continues past a stop condition becomes somebody else's incident.