{
  "slug": "access-control",
  "name": "Access control and tenant boundaries",
  "category": "Identity",
  "summary": "Review whether every protected operation binds the caller, tenant, resource, and action together at the decision point.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Authorization policy or role matrix",
    "Two approved tenant or role contexts",
    "Owned example resources"
  ],
  "review": [
    {
      "title": "Write the invariant",
      "body": "State who may perform which action on which resource in which tenant; include inherited and combined views."
    },
    {
      "title": "Trace enforcement",
      "body": "Follow each server-side route, resolver, or service call to the authorization decision and note alternate interfaces."
    },
    {
      "title": "Check stale authority",
      "body": "Review exports, pagination, saved views, and cached references for a fresh permission decision before disclosure."
    },
    {
      "title": "Preserve evidence",
      "body": "Compare permitted and denied outcomes using only owned objects and record the expected policy result."
    }
  ],
  "outputs": [
    "Authorization invariant table",
    "Enforcement trace",
    "Documented allow and deny evidence"
  ],
  "pitfalls": [
    "Relying on UI visibility as authorization",
    "Checking only one API path",
    "Forgetting tenant context on background work"
  ],
  "references": {
    "resources": [
      {
        "id": "owasp-authorization-cheat-sheet",
        "title": "Authorization Cheat Sheet",
        "url": "https://vulns.co/research/resources/owasp-authorization-cheat-sheet/"
      },
      {
        "id": "nist-sp-800-162-attribute-authority-modeling",
        "title": "NIST SP 800-162: attribute authority and policy traceability",
        "url": "https://vulns.co/research/resources/nist-sp-800-162-attribute-authority-modeling/"
      },
      {
        "id": "openfga-authorization-query-freshness",
        "title": "OpenFGA query consistency: authorization decisions need sufficiently fresh state",
        "url": "https://vulns.co/research/resources/openfga-authorization-query-freshness/"
      }
    ],
    "diagrams": [
      {
        "id": "combined-view-source-authorization",
        "title": "Combined views preserve every source's access boundary",
        "url": "https://vulns.co/research/diagrams/combined-view-source-authorization/"
      },
      {
        "id": "fallback-requester-authorization",
        "title": "Fallbacks must preserve the original caller's authority",
        "url": "https://vulns.co/research/diagrams/fallback-requester-authorization/"
      }
    ],
    "reports": [
      {
        "id": "github-cross-repository-comparison-authorization-2025",
        "title": "GitHub comparison output lacked source-repository authorization",
        "url": "https://vulns.co/research/reports/github-cross-repository-comparison-authorization-2025/"
      },
      {
        "id": "instagram-embedding-privileged-fallback-2023",
        "title": "Instagram embedding fallback changed the authorization context",
        "url": "https://vulns.co/research/reports/instagram-embedding-privileged-fallback-2023/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/access-control/",
  "markdown_url": "https://vulns.co/skills/access-control/SKILL.md"
}
