Assess and strengthen controls at demonstrated trust boundaries. Use for security reviews, changes to authentication or authorization, sensitive data handling, destructive operations, or external inputs and integrations with material security risk.