The decision
Permission testing should verify what a user can read, change, export, and approve. It also needs to confirm what is denied. Testing only the administrator's happy path leaves important boundaries unexamined.
In practice
A client should not access another organization's invoice by changing a URL or opening a shared link. An employee who can view a record may still lack permission to approve it. Review actions and data scope separately.
- Build a role-and-action matrix using actual business responsibilities.
- Test representative accounts, direct URLs, file downloads, and changes in membership.
- Include server-side checks; hiding a button alone does not establish an access boundary.
When to take the next step
Review access before adding roles, organizations, or exports. Choose test accounts that represent the actual boundaries rather than relying on one unrestricted administrator.
Questions clients ask
Is a role list enough?
No. Connect each role to permitted actions and the specific records it may access.
When should permissions be retested?
Whenever roles, workflows, exports, organization boundaries, or identity behavior change.

