UM-SA-001 · Revision 4.0One customer can read another customer’s invoices
In this fictional product, a signed-in customer could read another customer’s invoices by changing a number in an invoice link. The data export and the AI search had the same gap. Separately, code and permissions could reach production without the sign-off the team believed was in place.
10Findings
7High
3Medium
Issued before any fixes. One round of retesting is included.
Do first
- Make every invoice, export and search request check which customer is asking. (ARC-01, APP-01, AI-01)
- Let only the protected release workflow, its own roles and the images it built reach production. (CLD-01 to CLD-03)
- Keep the assistant’s send action off until a person signs off each send. (AI-02)
For your engineers
| Area | High | Medium | Main change |
|---|---|---|---|
| SaaS architecture | 1 | 1 | Tie each export job to the account that asked for it, and keep webhooks to public addresses. |
| Application and API | 2 | 1 | Check the account, the user’s role and current membership on every request. |
| Cloud and CI/CD | 2 | 1 | Limit production to the protected workflow, the runtime roles it needs and the images it built. |
| AI and agents | 2 | 0 | Filter search by account, and require a person’s sign-off before any external action. |
What happens next
- We make four fixes at a fixed price: identity, cloud monitoring, backups and edge.
- Your developers make the code changes, from our pattern.
- We retest every fix, ours and your developers’. One round is included.
Fictional sample. The company, systems and data are invented; no real client was assessed.

