Access control and tenant boundaries
Review whether every protected operation binds the caller, tenant, resource, and action together at the decision point.
This is the complete downloadable file. Open plain text ↗
---
name: access-control
description: "Review whether every protected operation binds the caller, tenant, resource, and action together at the decision point."
---
# Access control and tenant boundaries
Review whether every protected operation binds the caller, tenant, resource, and action together at the decision point.
Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.
## Bring to the review
- Authorization policy or role matrix
- Two approved tenant or role contexts
- Owned example resources
## Review guide
### 1. Write the invariant
State who may perform which action on which resource in which tenant; include inherited and combined views.
### 2. Trace enforcement
Follow each server-side route, resolver, or service call to the authorization decision and note alternate interfaces.
### 3. Check stale authority
Review exports, pagination, saved views, and cached references for a fresh permission decision before disclosure.
### 4. Preserve evidence
Compare permitted and denied outcomes using only owned objects and record the expected policy result.
## What to produce
- Authorization invariant table
- Enforcement trace
- Documented allow and deny evidence
## Common mistakes
- Relying on UI visibility as authorization
- Checking only one API path
- Forgetting tenant context on background work
## Reading and source context
### Resources
- [Authorization Cheat Sheet](https://vulns.co/research/resources/owasp-authorization-cheat-sheet/)
- [NIST SP 800-162: attribute authority and policy traceability](https://vulns.co/research/resources/nist-sp-800-162-attribute-authority-modeling/)
- [OpenFGA query consistency: authorization decisions need sufficiently fresh state](https://vulns.co/research/resources/openfga-authorization-query-freshness/)
### Diagrams
- [Combined views preserve every source's access boundary](https://vulns.co/research/diagrams/combined-view-source-authorization/)
- [Fallbacks must preserve the original caller's authority](https://vulns.co/research/diagrams/fallback-requester-authorization/)
### Reports
- [GitHub comparison output lacked source-repository authorization](https://vulns.co/research/reports/github-cross-repository-comparison-authorization-2025/)
- [Instagram embedding fallback changed the authorization context](https://vulns.co/research/reports/instagram-embedding-privileged-fallback-2023/)
## Provenance
Editorial guide by vulns.co / GK Data. Updated 2026-10-11.
Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3.
The guide is an editorial synthesis. Linked records preserve their own sources and review dates.
Reader: https://vulns.co/skills/access-control/
The review
What to look for
Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.
Write the invariant
State who may perform which action on which resource in which tenant; include inherited and combined views.
Trace enforcement
Follow each server-side route, resolver, or service call to the authorization decision and note alternate interfaces.
Check stale authority
Review exports, pagination, saved views, and cached references for a fresh permission decision before disclosure.
Preserve evidence
Compare permitted and denied outcomes using only owned objects and record the expected policy result.
What to produce
- Authorization invariant table
- Enforcement trace
- Documented allow and deny evidence
Common mistakes
- Relying on UI visibility as authorization
- Checking only one API path
- Forgetting tenant context on background work
Continue the study
Reading & source context
Editorial notes above connect these references. Open each record for its original source and review date.
Visual models
Connected disclosures
From the field toolkit
Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.