AI-content platform
Object-level authorization
Account and authorization boundaries
Identified cross-account authorization failures affecting private and collaborative resources, then reported the proven impact through the platform’s security channel.
- Method
- Two controlled identities, synthetic records, owner-versus-non-owner comparisons, and exact negative controls.
- Boundary
- Testing stopped after the minimum cross-account impact was reproduced. No external accounts or third-party records were used.