Home /Inside the deliverable

See what clarity looks like.

An illustrative report excerpt. This is a fictional example of the format, not a client result or an assessment of your software.

ILLUSTRATIVE EXAMPLE / NOT A CLIENT REPORT

Customer portal · launch review

Decision: resolve the identified access-control issue and verify the affected flows before launch.

Scope: example release v1.0, customer account and invoice journeys in a test environment. Infrastructure and payment processing are outside this example.

FINDING CSO-001High priority

Invoice access is not scoped to the customer.

Observation

A signed-in test user could request an invoice belonging to another test account by changing the invoice identifier.

Evidence

In the fictional reproduction, the response returned the other account’s invoice. The request was authenticated but the resource ownership check was absent.

Business impact

A customer could access invoice information belonging to another customer.

Recommended action

Enforce server-side ownership checks for invoice reads and downloads. Add tests covering permitted and denied access.

Verification

Repeat the original reproduction with two test accounts. Confirm cross-account requests are denied and authorised access continues to work.

A clear next step

Get this level of clarity for your software.

Tell us what you’re building and what’s coming next.
We’ll help you scope the right review.