Separating customers in the interface does not prove isolation. A route, a client-controlled header or a collection can expose another organization’s records.
02
The engineering decision
Exercise real HTTP requests against a local server with synthetic identities and records. Check forbidden access alongside legitimate access.
03
What was observed
Three vulnerable configurations fail. The scoped secure configuration passes. Denying every request does not demonstrate correct isolation: it produces INCONCLUSIVE.
04
Where the evidence ends
Read-only detail and collection routes on synthetic local targets. This is not a full audit of authorization, RLS, writes, roles or production.
60-SECOND WALKTHROUGH / TENANT-FENCE
A tenant ID is not an access boundary.
Choose a scenario
Inspect the recorded evidence
Compare correction and lost controls
Explorer of previously executed reports, using synthetic data. Switching scenarios does not run Python, scan your system or send HTTP requests.
The full report remains available below.
Inspect original JSON evidence
Executed on 19 September 2026. A PASS applies only to that configured experiment.
If multiple organizations share your platform, isolation should be demonstrable through user journeys and contracts.
A proposed review could include
An identity and trust-boundary map, an agreed access matrix, prioritized findings and regression criteria for the team.
This is a synthetic engineering case, not a client outcome. Implementation, intrusive production tests and compliance certification are outside the standard diagnostic scope.
FROM EXPERIMENT TO DECISION
Find out which boundary to review first.
The technical and strategic diagnostic turns a scoped question into a system map, prioritized findings and an actionable roadmap. Scope and access are agreed before any work.