Skip to main content

Product / Access

Find where observed permissions disagree with the rules.

Compare expected access with observations across roles, tenants, and actions to identify permission mismatches.

Illustrative workflow, not a live workspace result.
Role
Viewer
Expected
Cannot delete a project
API observation
Deletion allowed
Finding
Permission mismatch

Why use Access?

Hiding a button is not evidence that the underlying action is protected. Review the expected boundary alongside the behavior observed at each layer.

Make expected access explicit

Describe who should be able to perform each action.

Expose mismatches

Compare observed permissions with the expected contract, including cross-tenant cases.

Keep the evidence attached

Retain the observations needed to investigate a permission finding.

How Access fits your work

  1. 01

    Define expected access

    Supply roles, organizations, and allowed or denied actions.

  2. 02

    Supply observations

    Add the access results gathered by your tests.

  3. 03

    Investigate differences

    Review mismatches and rerun the relevant tests after a repair.

What to know before you start

Access analyzes supplied observations. Testing your application and collecting those observations remains a separate step.

Use your workspace or a compatible agent connected through MCP. Read the connection guide.

Explore the next step

Give your next software change a clear acceptance test.

Start with a project, the behavior you need, and the evidence that would show it works.