Scope around risk and architecture
Identify sensitive workflows, trust boundaries, user roles, third-party integrations and data paths. A domain list alone rarely describes the system that needs testing.
Combine automation with judgement
Use tools for repeatable discovery, then validate findings manually. Test access control, workflow abuse, tenant isolation, business logic and chained conditions that scanners cannot understand reliably.
Report for remediation
Each finding should explain affected assets, evidence, realistic impact, reproduction boundaries and a repair approach. Separate confirmed conditions from observations and assumptions.
Retest the outcome
Verify the original condition and likely bypasses after remediation. A retest should record what changed and what residual risk remains.
