Skip to main content

Scope / Account Isolation Tests

IDTest CaseTypePriorityExpected ResultEvidence RequiredStatus
TC-TEN-001School Manager A attempts to access School B dataNegativeCriticalAccess deniedScreenshot or API 403 responseNot Run
TC-TEN-002Supplier A attempts to access Supplier B ordersNegativeCriticalAccess deniedScreenshot or API 403 responseNot Run
TC-TEN-003Operator A attempts to access unassigned store/cafeteriaNegativeCriticalAccess deniedScreenshot or API 403 responseNot Run
TC-TEN-004Parent A attempts to access another parent studentNegativeCriticalAccess deniedScreenshot or API 403 responseNot Run
TC-TEN-005User modifies request scope manuallyNegativeCriticalBackend rejects unauthorized scopeAPI request/response evidenceNot Run