GraphQL operation boundaries
Map which queries and mutations each test role may execute, including object-level authorization and persisted-operation handling. Keep introspection and volume within the program's rules.
Level: advanced
Tools: Burp Suite, GraphQL IDE, schema documentation
Pipeline
For each documented operation, run the smallest valid query as two controlled roles and compare data fields, object ownership checks, and mutation effects on owned test data.