A modern, venture-backed AI agent orchestration platform asked Perfai Security to test its multi-tenant API. Three autonomous agents ran the full role matrix. An entire control plane came back with no role-enforcement behind it.
A workflow-orchestration engine where every tenant runs live automation
The platform lets customers build AI agents and workflows that connect to their own systems through connectors, secrets, webhooks, and scheduled triggers. Every tenant stores credentials in the platform and pushes automation into a shared runtime. In that architecture, the API is not a side door. It is the product. A single missing role check does not leak one record, it hands over the machine that runs everyone's automation.
The team had already been through a third-party penetration test and runs static scanners in CI. They engaged Perfai Security to answer a different question: can a role do something it was never granted permission to do?
From two test accounts to the full role matrix
Perfai's three agents (Vision, Security, Fix) took two seeded accounts and derived the rest. Vision mapped the API surface. Security replayed every privileged action as each lower-privileged role and recorded which calls the server accepted that it should have rejected. No traffic was guessed, every finding is a request the platform answered for a role that should never have been allowed to make it.
One open door, four roles walking through it
66 of the 68 findings were the same class of flaw: Broken Function Level Authorization. The server checked that you were logged in, then never checked whether your role was allowed to call the function. So the lowest tiers, a read-only Viewer, an End User, an Operator, could invoke the platform's most privileged operations. The remaining two were a cross-tenant Broken Object Level Authorization on a usage-records endpoint and a Broken Authentication flaw where an expired token was still accepted.
An End User, the lowest tier on the platform, could POST to deploy, publish, and test workflows. That is not read-only data leakage. A non-privileged tenant user could push live automation into the orchestration runtime that every customer shares.

Six surfaces, all reachable from the wrong role
Secrets & credentials
3 findingsThe crown jewels. A build-scope role could read stored secrets and API keys, and an End User could start an OAuth connection flow.
Workflow control plane
17 findingsRead and, critically, write. An End User could deploy, publish, and test workflows, and trigger schedulers, into the shared runtime.
Integrations
14 findingsConnectors, webhooks, and environments, the wiring between the platform and a tenant's own systems, were listable and writable by roles with no integration scope.
Tenant & org config
11 findingsOrganization records, per-org configuration, and the role catalog itself were readable across roles, including the definition of who can do what.
Billing & usage
6 findingsPlans, quotas, and usage were exposed across roles. The usage-records endpoint was also a cross-tenant BOLA, returning another tenant's data by object reference.
Audit, alerts & observability
17 findingsAudit logs, alerts, events, and activity tracking were readable, and writable, by every role tested. A low-tier role could read or seed the record meant to catch them.
Plus a Broken Authentication finding: the API continued to honor an expired token, removing the one time-bound control that could have limited a stolen session.
The flaw lives where scanners and pentests don't look
Static scanners
SAST and dependency scanners read code and libraries. A missing role check is a logic gap, not a vulnerable pattern. There is nothing for a signature to match, so the test comes back clean while the door stays open.
The earlier pentest
A pentest samples. A human tries a few representative roles against a few representative endpoints inside a fixed window. 122 endpoints across 4 roles is 488 role-endpoint pairs before a single object is varied, far past what sampling reaches.
A clean coverage map, in under two days
Perfai handed the team 68 confirmed Critical / High findings, each tied to an exact role, method, and endpoint, plus a fix path for the underlying pattern. Because the flaws shared one root cause, a missing server-side authorization layer, the remediation was a single architectural change validated against the full matrix, not 68 separate patches. The platform now re-runs the same role matrix continuously, so a new endpoint or a new role surfaces the moment it ships, not at the next annual review.
When your product is an API that runs other people's automation, authentication is the easy half. Authorization, the question of what each role may actually invoke, is where the real exposure lives, and it is the half that sampling-based testing was never built to cover.
Find the role checks your platform forgot.
Perfai's autonomous agents run the full role matrix against your app — UI, API, and data — in days, not quarters.
Book a Perfai test →