Auditing Multi Tenant Isolation

Audit whether every data operation is scoped to the caller's tenant, so a request in one tenant cannot read or write another's data. Covers a query or object lookup with the object identifier but no tenant predicate, a tenant taken from client-controlled input at the operation rather than the authenticated session, scoping applied on the list path but dropped on the detail, update, delete, or export path, a cache or storage key with no tenant segment, and a background job, report, or privileged connection that runs across tenants or bypasses the mandatory scope. Frames isolation as a systemic invariant, not a single-object reference bug, which a separate skill covers. Use when reviewing data access in a system that serves multiple tenants. The tenant used at the operation is the source, the tenant-scoped data operation is the sink, and a sink scoped by anything but the authenticated tenant is the bug.

UnboundCompute c3c7c5c 9.8 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-multi-tenant-isolation commit c3c7c5cb6e

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-multi-tenant-isolation