High-level check of any change that adds or alters something the outside world can reach — a page, route, API endpoint, form, upload, login or role change, or new stored personal data — for who can reach it, what they can do, and what abuse would cost. Run BEFORE building any new surface and again BEFORE opening a PR that adds one. Stays high level; pair it with lower-level security tooling. Written for feature owners who are not engineers.