Review authentication and authorization flows for gaps — missing route guards, broken object-level access control, token lifecycle flaws, privilege escalation paths — by tracing enforcement in the actual code. Use when endpoints or resources are added/changed, roles or permissions are introduced, login/session/token code is touched, or someone asks "is this properly protected". Produces a verified access-control findings report per endpoint and resource. Defensive review only.