Review agent · Identity & access

Access control & authorization

Checks that each sensitive action is authorized for the specific object, not just a logged-in user.

api/invoices.ts1const id = req.params.id;2const inv = await Invoice3 .findById(id);4res.json(inv);AuthZwhat this review answersObject ID taken from the request?Ownership or tenant check present?Protected fields mass-assignable?$ verdict REAL ISSUE$ fix scope the lookup to the tenant▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

Broken access control is number one in the OWASP Top 10 (A01), and broken object-level authorization (IDOR) tops the OWASP API Security Top 10. It is how one customer reads another customer's data.

Scanners struggle here because the bug is an absence — a missing ownership check. This agent reads the handler and asks whether the action is scoped to the current user or tenant, and calls out mass-assignment of protected fields.

What it checks

  • Object IDs from the request used without an ownership or tenant check
  • Missing role checks on privileged operations
  • Mass-assignment that lets clients set protected fields
  • Authorization bypass through user-controlled keys

When it marks a finding as a likely false positive

  • An explicit check scopes the action to the current user or tenant

The fix it suggests

  • A per-object authorization check on every sensitive route
  • Allow-listing writable fields
  • Centralizing tenant scoping in a shared layer

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Can static analysis find IDOR?

Partly. Scanners flag suspicious patterns; this agent reviews the surrounding handler to judge whether an ownership check is present, and says so in plain English.

Related agents

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Access control & authorization agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free