For my Applied Information Systems Security class, one of our project options is to audit a company's systems. Since my future father-in-law runs a lumber yard, I am taking that option. Here is a link to the project description. It is option number 3.

My question is, how can I find out what's legal? We have already signed a contract giving us permission to audit the system in just about any way we want, but what is going "too far"? Thanks!