- The Agent handles sensitive data, regulated workflows, or privileged actions
- The Agent uses tools, MCP servers, delegated Agents, or external data stores
- A Trust Score or custom Harness finding needs deeper investigation
- A release needs security, safety, or risk-owner review before deployment
- You want to validate whether previous fixes reduced exploitable behavior
Red Team is enabled per deployment. Where it is not enabled, the Adaptive tab appears but stays disabled, and selecting it reports
Red Team is not enabled for this deployment. Contact your Vijil account team to have it turned on.Before You Start
For best results, make sure the selected Agent is Active and has as much context as you can safely provide. Attaching Policies and Personas improves both the attack seeds the campaign generates and the accuracy of its judgments.Launch a Campaign
1
Create an Evaluation
Navigate to Tests in the Console sidebar, then click Create Evaluation.
2
Choose an Agent
Select the registered Agent you want to test. Only Agents with status Active can be tested.
3
Select the Adaptive tab
In the Test Configuration panel, choose the Adaptive tab, which runs Red Team. The other two tabs, Baseline and Bespoke, run standard Trust Score Evaluations.
4
Configure the campaign
Set the sliders under General Settings, press the icon in the top right corner for Advanced settings if you need finer control, then attach Personas and Policies OPTIONAL.
5
Start the campaign
Click Run Evaluation.
For how the wave loop works, see Engagements.
General Settings
Four sliders control the shape and cost of the run. An Estimated time panel updates as you move them, and Reset to defaults restores the starting values.
Setting Min waves above Max waves is rejected with
Min waves cannot exceed max waves.
Advanced Settings
Four further settings control how hard each attacker works before it gives up. To reach them, press the icon in the top right corner of the General Settings section header. The settings open in a dialog with its own Estimated time panel and Reset to defaults control. Click Save to apply your changes, or Cancel to discard them. Use these only when you understand the cost and runtime impact of the campaign.Personas and Policies
Below the settings, the Personas and Policies sections each provide a searchable list of what your team has created.
If Policies are missing, Red Team still runs, but judgments rely more heavily on general safety and security expectations rather than your rules.
Monitor a Campaign
Red Team campaigns take longer than a standard Evaluation because each wave may run several attackers and an analysis step. Open the run from Evaluation Results to follow it live, and use Cancel run to stop it early. See Understand Red Team Results for what the run page shows.Runtime and Cost
Red Team campaigns generate more traffic than a standard Harness because each wave may launch several attackers and each attacker can run multi-turn conversations. Start with conservative wave, seed, and parallel attacker settings. Increase them only after you have confirmed your Agent’s rate limits and the campaign cost profile. The Estimated time panel is the fastest way to see what a change to the sliders will cost you in wall-clock time.Best Practices
Run Red Team for deeper security review: Run a campaign after baseline Evaluation, before major releases, and after changes to tools, prompts, policies, or access controls. Give Red Team enough context: Policies and Personas improve seed quality and judgment accuracy. Start small: Run a short campaign with low wave and seed budgets first to confirm your Agent holds up under adversarial traffic, then widen them.Next Steps
Understand Results
Read waves, judgments, and the final report
How Engagements Work
The wave loop behind a campaign
Personas
Define who is attacking your Agent
Policies
Give the judge rules to test against