VulnerabilityRequires setup1 check
Tenant Isolation Scanner
Use two authenticated test actors to verify tenant-scoped resources cannot be read across accounts.
How this scan works
- Genuinely needs two live test accounts on two different tenants, supplied by you
- Accepts {actorA, actorB} credentials — without them the scan returns requires_setup
- When supplied: authenticates as Actor A, records a resource ID, requests that same ID as Actor B, and flags any cross-tenant reads
