← All experiments

01 / Access Control Challenge

The right access.
For the right people.

You’re designing permissions for a fictional branch-based system. Let legitimate work happen. Keep everything else out.

Your mission

“Same branch” includes the user’s own records. Use the self-approval safeguard when scope alone is not enough.

Each role is tested for read, edit, and approve against an own record, a colleague’s record in the same branch, and a record in another branch: 27 checks in total.

POLICY EDITOR / v1Runs: 0
Agent

Works with their own records.

Manager

Oversees their branch.

Auditor

Reviews across branches.

Waiting for interactive controls. JavaScript is required to play.

Educational simulation. This is not a security audit or a production authorization system. Your choices stay in this page’s memory and reset when you reload or switch language.