02 / Approach
The interesting part
is the second request.
One account retrieves a document. So far, everything looks ordinary. Repeat the request as someone else, and you have a more useful question: does the system check who owns it?
Same document. Different account.
Illustrative modelThe request
GET /documents/field-notes
- Document owner
- account / 01
- First request
- account / 01
- Second request
- account / 02
The comparison
The document's owner
A different account
Ownership boundary crossed
The second account receives the same document. Signing in was enough; ownership was never checked.
Read the check
function mayRead(account, document) {
return account.signedIn;
}This example runs entirely in your browser. It uses fictional accounts and sends no requests to another system.
A successful response becomes useful evidence when it is tied to the condition that should have prevented it. The comparison makes that condition visible.
Real investigations have more moving parts. The principle carries across: vary an assumption, repeat the observation, and make the reasoning inspectable. That's the work we're trying to automate.
Have a system or a research question you'd like us to look at?