Product / Access
Find where observed permissions disagree with the rules.
Compare expected access with observations across roles, tenants, and actions to identify permission mismatches.
Illustrative workflow, not a live workspace result.- Role
- Viewer
- Expected
- Cannot delete a project
- API observation
- Deletion allowed
- Finding
- Permission mismatch
Why use Access?
Hiding a button is not evidence that the underlying action is protected. Review the expected boundary alongside the behavior observed at each layer.
Make expected access explicit
Describe who should be able to perform each action.
Expose mismatches
Compare observed permissions with the expected contract, including cross-tenant cases.
Keep the evidence attached
Retain the observations needed to investigate a permission finding.
How Access fits your work
- 01
Define expected access
Supply roles, organizations, and allowed or denied actions.
- 02
Supply observations
Add the access results gathered by your tests.
- 03
Investigate differences
Review mismatches and rerun the relevant tests after a repair.
What to know before you start
Access analyzes supplied observations. Testing your application and collecting those observations remains a separate step.
Use your workspace or a compatible agent connected through MCP. Read the connection guide.