Who is allowed to do what
Get this wrong and it's a data breach, not a bug.
My app has these kinds of user: <list them> And these actions: <list them> Design the permission model: - A table of who can do what. Be explicit about every combination. - Where the check happens — it must be server-side, on every route, including ones that only read. - How a check is written so it's hard to forget. Suggest something structural rather than "remember to add it". Then audit my existing routes: <paste them>. List every route that checks authentication but not authorisation — that a logged-in user could use to reach someone else's data.
Authentication is "who are you". Authorisation is "are you allowed". Nearly every real breach in a small app is the second one missing.