Access control (authorization) answers whether a caller is allowed to perform an action on data. Failures are common and high impact. Organize testing and documentation by where the check fails:
| Subtopic | Question |
|---|---|
| Endpoint level | Is this route or function restricted to the right roles or tenants? |
| Object level | May this user access this specific record (IDs, slugs, nested resources)? |
| Property level | Can the user change fields they should not (mass assignment, partial updates)? |
| Trust boundary | Does the app believe headers, client certificates, or upstream identity without sound binding? |