Good guidelines answer the questions researchers ask before they start:
Each asset has a type (URL, domain, wildcard, API, Android, iOS, source code, hardware), whether it is in scope, and the maximum severity you accept on it. Add notes for test environments or credentials. Researchers can only file reports against in-scope assets.
Bug bounties publish the most they pay per severity (critical ≥ high ≥ medium ≥ low). The actual bounty is decided per report once it is accepted, and can later be increased (never reduced).
Programs are reviewed by the RootBounty team before going live. Once live, you can keep editing content, scope and rewards; changes are published immediately and recorded in the audit log. Staff can pause or close a program if it breaks the platform rules.