--- name: access-control description: "Review whether every protected operation binds the caller, tenant, resource, and action together at the decision point." --- # Access control and tenant boundaries Review whether every protected operation binds the caller, tenant, resource, and action together at the decision point. Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question. ## Bring to the review - Authorization policy or role matrix - Two approved tenant or role contexts - Owned example resources ## Review guide ### 1. Write the invariant State who may perform which action on which resource in which tenant; include inherited and combined views. ### 2. Trace enforcement Follow each server-side route, resolver, or service call to the authorization decision and note alternate interfaces. ### 3. Check stale authority Review exports, pagination, saved views, and cached references for a fresh permission decision before disclosure. ### 4. Preserve evidence Compare permitted and denied outcomes using only owned objects and record the expected policy result. ## What to produce - Authorization invariant table - Enforcement trace - Documented allow and deny evidence ## Common mistakes - Relying on UI visibility as authorization - Checking only one API path - Forgetting tenant context on background work ## Reading and source context ### Resources - [Authorization Cheat Sheet](https://vulns.co/research/resources/owasp-authorization-cheat-sheet/) - [NIST SP 800-162: attribute authority and policy traceability](https://vulns.co/research/resources/nist-sp-800-162-attribute-authority-modeling/) - [OpenFGA query consistency: authorization decisions need sufficiently fresh state](https://vulns.co/research/resources/openfga-authorization-query-freshness/) ### Diagrams - [Combined views preserve every source's access boundary](https://vulns.co/research/diagrams/combined-view-source-authorization/) - [Fallbacks must preserve the original caller's authority](https://vulns.co/research/diagrams/fallback-requester-authorization/) ### Reports - [GitHub comparison output lacked source-repository authorization](https://vulns.co/research/reports/github-cross-repository-comparison-authorization-2025/) - [Instagram embedding fallback changed the authorization context](https://vulns.co/research/reports/instagram-embedding-privileged-fallback-2023/) ## Provenance Editorial guide by vulns.co / GK Data. Updated 2026-10-11. Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3. The guide is an editorial synthesis. Linked records preserve their own sources and review dates. Reader: https://vulns.co/skills/access-control/