Reader scope
Reader scope exists to limit discovery and viewing by legitimate need. Within this permission architecture decision, sensitive records exposed through inheritance leaves reader scope downstream teams without a dependable starting point. Interpret overexposure findings as a reader scope signal of intake ownership, then connect the reader scope finding to a named correction owner and retained evidence.
- Locate which permission architecture policy governs reader scope
- Rehearse sensitive records exposed through inheritance beside the responsible reader scope role
- Record overexposure findings around the reader scope correction
