01 / Access Control Challenge
The right access.
For the right people.
You’re designing permissions for a fictional branch-based system. Let legitimate work happen. Keep everything else out.
Your mission
- Agent:read and edit their own records. Never approve.
- Manager:read all records in their branch. Approve other people’s records in that branch, but never their own. Never edit.
- Auditor:read records across all branches. Never edit or approve.
“Same branch” includes the user’s own records. Use the self-approval safeguard when scope alone is not enough.
Each role is tested for read, edit, and approve against an own record, a colleague’s record in the same branch, and a record in another branch: 27 checks in total.
Waiting for interactive controls. JavaScript is required to play.
Educational simulation. This is not a security audit or a production authorization system. Your choices stay in this page’s memory and reset when you reload or switch language.