Analyze authorization and access control — use for IDOR/BOLA, missing ownership checks, privilege escalation, and function-level authZ gaps (CWE-639 / CWE-862 / CWE-863 / A01:2021 / API1:2023 / API5:2023).