permissions.txt
My app has these kinds of user: <list them>
And these actions: <list them>

Design the permission model:
- A table of who can do what. Be explicit about every combination.
- Where the check happens — it must be server-side, on every route,
  including ones that only read.
- How a check is written so it's hard to forget. Suggest something
  structural rather than "remember to add it".

Then audit my existing routes: <paste them>. List every route that
checks authentication but not authorisation — that a logged-in user
could use to reach someone else's data.

Authentication is "who are you". Authorisation is "are you allowed". Nearly every real breach in a small app is the second one missing.