Ownership Authorization

Use to design ownership, organization/tenant-scope, and object-level authorization — the caller may touch only their own or their tenant's resources. Scope derives from the session, never from client-supplied IDs; requires cross-user and cross-tenant negative tests.

ahtishamshahzad Updated

File contents

ahtishamshahzad/agent_dev_flow/tree/main/.ai/skills/backend/ownership-authorization commit 7ad7f5f0d5

Frequently asked questions

npx skillmds@latest add ahtishamshahzad/ownership-authorization