Perfai
    Perfai Security · Case Study

    "Read only" roles should never get full access

    A modern, venture-backed AI agent orchestration platform asked Perfai Security to test its multi-tenant API. Three autonomous agents ran the full role matrix. An entire control plane came back with no role-enforcement behind it.

    68
    Critical / High access-control findings
    4
    Privileged roles a low-tier user could impersonate
    122
    API endpoints tested, no UI workflows (API-first)
    <2 days
    To go from credentials to full findings report
    The Platform

    A workflow-orchestration engine where every tenant runs live automation

    The platform lets customers build AI agents and workflows that connect to their own systems through connectors, secrets, webhooks, and scheduled triggers. Every tenant stores credentials in the platform and pushes automation into a shared runtime. In that architecture, the API is not a side door. It is the product. A single missing role check does not leak one record, it hands over the machine that runs everyone's automation.

    The team had already been through a third-party penetration test and runs static scanners in CI. They engaged Perfai Security to answer a different question: can a role do something it was never granted permission to do?

    How the test worked

    From two test accounts to the full role matrix

    Perfai's three agents (Vision, Security, Fix) took two seeded accounts and derived the rest. Vision mapped the API surface. Security replayed every privileged action as each lower-privileged role and recorded which calls the server accepted that it should have rejected. No traffic was guessed, every finding is a request the platform answered for a role that should never have been allowed to make it.

    2
    accounts
    seed credentials
    4
    roles
    Dev · View · End · Op
    122
    endpoints
    full API surface
    12,994
    tests
    every role × action
    68
    Critical / High findings
    What we found

    One open door, four roles walking through it

    66 of the 68 findings were the same class of flaw: Broken Function Level Authorization. The server checked that you were logged in, then never checked whether your role was allowed to call the function. So the lowest tiers, a read-only Viewer, an End User, an Operator, could invoke the platform's most privileged operations. The remaining two were a cross-tenant Broken Object Level Authorization on a usage-records endpoint and a Broken Authentication flaw where an expired token was still accepted.

    The sharpest finding

    An End User, the lowest tier on the platform, could POST to deploy, publish, and test workflows. That is not read-only data leakage. A non-privileged tenant user could push live automation into the orchestration runtime that every customer shares.

    Low-privilege roles reach every control plane through a no-role-check API gateway
    Low-privilege roles → no role check → full control-plane access
    The findings, by plane

    Six surfaces, all reachable from the wrong role

    Secrets & credentials

    3 findings

    The crown jewels. A build-scope role could read stored secrets and API keys, and an End User could start an OAuth connection flow.

    read credential vaultread access keysstart connection auth
    DeveloperEnd User

    Workflow control plane

    17 findings

    Read and, critically, write. An End User could deploy, publish, and test workflows, and trigger schedulers, into the shared runtime.

    deploy automationpublish automationrun executionlist versionsread run historyfire scheduled trigger
    End UserViewer

    Integrations

    14 findings

    Connectors, webhooks, and environments, the wiring between the platform and a tenant's own systems, were listable and writable by roles with no integration scope.

    list connectorsread event hooksread environmentscreate environmentmanage triggers
    OperatorEnd UserViewerDeveloper

    Tenant & org config

    11 findings

    Organization records, per-org configuration, and the role catalog itself were readable across roles, including the definition of who can do what.

    list tenantsread tenantread tenant configread role catalog
    ViewerEnd UserOperatorDeveloper

    Billing & usage

    6 findings

    Plans, quotas, and usage were exposed across roles. The usage-records endpoint was also a cross-tenant BOLA, returning another tenant's data by object reference.

    read plansread quotasread usage records (BOLA)read AI usageread plan requests
    Developer

    Audit, alerts & observability

    17 findings

    Audit logs, alerts, events, and activity tracking were readable, and writable, by every role tested. A low-tier role could read or seed the record meant to catch them.

    read audit logread alertscreate alertsread eventsread activityread onboarding state
    DeveloperViewerOperatorEnd User

    Plus a Broken Authentication finding: the API continued to honor an expired token, removing the one time-bound control that could have limited a stolen session.

    Why traditional testing missed it

    The flaw lives where scanners and pentests don't look

    Static scanners

    SAST and dependency scanners read code and libraries. A missing role check is a logic gap, not a vulnerable pattern. There is nothing for a signature to match, so the test comes back clean while the door stays open.

    The earlier pentest

    A pentest samples. A human tries a few representative roles against a few representative endpoints inside a fixed window. 122 endpoints across 4 roles is 488 role-endpoint pairs before a single object is varied, far past what sampling reaches.

    Pentest · Sampled
    Perfai · Complete
    A pentest hits scattered cells. Perfai tests every role against every action, every run.
    Outcome

    A clean coverage map, in under two days

    Perfai handed the team 68 confirmed Critical / High findings, each tied to an exact role, method, and endpoint, plus a fix path for the underlying pattern. Because the flaws shared one root cause, a missing server-side authorization layer, the remediation was a single architectural change validated against the full matrix, not 68 separate patches. The platform now re-runs the same role matrix continuously, so a new endpoint or a new role surfaces the moment it ships, not at the next annual review.

    The takeaway for AI-native platforms

    When your product is an API that runs other people's automation, authentication is the easy half. Authorization, the question of what each role may actually invoke, is where the real exposure lives, and it is the half that sampling-based testing was never built to cover.

    Find the role checks your platform forgot.

    Perfai's autonomous agents run the full role matrix against your app — UI, API, and data — in days, not quarters.

    Book a Perfai test →