Step 1Scope from the line
What changed, what's exposed, what the threat model flagged.
ATALAIAWe test what changed: the redeem flow, the partner webhook, the admin panel.
DEV LEADThe staging copy is ready. Same build as prod, fake points.
Leaves the roomScope: redeem flow, partner webhook, admin
Step 2Test like an attacker
Manual, in staging, with your team on a channel.
ATALAIA 2Changing the offer ID on /redeem returns another user's voucher.
ATALAIAThat's an IDOR. It goes in the channel now, not in a PDF next month.
DEV LEADSeen. Who owns /redeem? Assigning it.
Leaves the roomTesting staging, team on a channel
Step 3File, don't publish
Tickets with steps and fixes, as they are found.
ATALAIATicket filed: steps, a request you can replay, and a suggested fix.
DEV LEADFix merged. Can you check it?
Leaves the room5 findings filed as tickets
Step 4Retest and hand over
Fixes verified; detections passed to the SOC.
ATALAIA 2Retest is green. The same request now returns a 403.
SOCCan we alert when one user asks for many other users' offers?
ATALAIAThat's the detection. The rule and its test are in the hand-over.
Leaves the roomRetest green, 2 detections to the SOC
- ATALAIA
- ATALAIA 2
- DEV LEAD
- SOC