Control
Access
Compare expected access with observations across roles, tenants, and actions to identify permission mismatches.
Last updated August 22, 2026
Find where observed permissions disagree with the rules.
Use cases
Make expected access explicit
Describe who should be able to perform each action.
Expose mismatches
Compare observed permissions with the expected contract, including cross-tenant cases.
Keep the evidence attached
Retain the observations needed to investigate a permission finding.
How it works
- 1
Define expected access
Supply roles, organizations, and allowed or denied actions.
- 2
Supply observations
Add the access results gathered by your tests.
- 3
Investigate differences
Review mismatches and rerun the relevant tests after a repair.
Quickstart
Open Access in the console, provide the required inputs, and start an organization scoped run.
Inputs
- roles and tenants
- identity fixtures
- UI, API, and data probes
- approved authorization contract
Outputs
- permission matrix
- cross-tenant exploit evidence
- privilege drift
- release gate verdict
MCP
Call Access from a compatible agent with the preferred public tool name.
The previous internal service identifier remains accepted for compatibility, but new integrations should use this product name.