This is a trite response to an actual concern: Placing scope limits on bug bounties is meaningless and dangerous. Hackers will not respect your scope. The scope of a bug bounty program should always be "Anything that affects our, or our users, data or security". There's plenty of non-entities that get reported: Failures of XSS protections on data that is actually public, vulnerabilities on vendors sites that don't im…
I think the best of both worlds would be very wide scopes with targeted limitations. Don't log into user accounts or company accounts at other services, but here's a few sample user accounts that are fair game and if it's an external service, here's a rep to vet whether credentials you gathered are correct or not.