Request choreography
One request.
Every boundary.
Travel with a request. A valid token should never be a passport to someone else’s data.
Interactive path view
The scenario and controls work without 3D.Change the conditions. Change the outcome.
The experiment
Break it.
Then make it hold.
An external user requests another tenant’s invoice using a guessed object ID. Explore object-level authorisation, not just authentication.
How this simulation works
Each run follows one deterministic path. An enabled control stops this particular scenario at its boundary. Results are educational, not a security assessment or a guarantee against other attacks.
Set the defences
0 of 3 enabledFor this private API, reject requests outside the allowed network.
Check that the authenticated subject can access this invoice.
Bind the database lookup to the authenticated tenant.
Run once without controls. Then activate a defence and compare what happens.
Keep exploring
Return to the service universe