#130 · Multi-user testing is now available for Web Apps
We’re thrilled to announce the availability of multi-user testing for Web Apps, enabling you to run symmetric and asymmetric permission testing to ensure your multi-tenant environments are properly isolated and secure.
These new capabilities extend our previous update, including the ability to configure tenant isolation rules with natural language and implement custom detection rules for precision targeting of vulnerabilities. Together, these features provide a more tailored and effective solution for securing your system.
Why is Multi-User Testing Important?¶
For multi-tenant SaaS applications, ensuring proper tenant isolation and access control is essential. Vulnerabilities like Broken Access Control (BAC) or Cross-User Data Breaches can arise when tenants or users with the same or different permissions inadvertently access unauthorized data. Our new multi-user testing capabilities are designed to help you detect these vulnerabilities before they become security risks.
What’s New?¶
We’ve introduced two powerful multi-user testing approaches to Web Apps that ensure both symmetric and asymmetric permission scenarios are tested and validated for tenant isolation:
1. Symmetric Permission Tenant Isolation Testing¶
With symmetric permission testing, you can validate that users with identical roles or permission levels across tenants cannot access each other’s data. This approach is critical for applications where users across different tenants have the same privileges but should still be properly isolated.
When This Applies:
- Multi-Tenant SaaS Applications: Ensure that, for example, Company A’s sales reps can’t access Company B’s customer data, even though both have identical "Sales Rep" permissions.
- Financial Services Platforms: Prevent standard account holders from accessing each other’s transaction histories.
- Educational Platforms: Ensure students in different courses cannot view each other’s grades, submissions, or personal information.
How It Works:¶
A single scan profile is configured with a primary user for exploration and secondary users as exploitation targets. Escape tests for Broken Access Control, Tenant Isolation, and Cross-User Data Breaches by attempting to replay the primary user’s requests using secondary users’ credentials. Since permission levels are symmetric, this approach ensures violations are automatically detected in both directions.
2. Asymmetric Permission Bidirectional Testing¶
Asymmetric permission testing is designed for scenarios where users have different privilege levels, such as admins, standard users, or privileged roles in different domains. This type of testing validates that unauthorized access is prevented in both directions between users of different permission levels.
When This Applies:
- Enterprise Applications with RBAC: Ensure that standard users cannot access admin endpoints, while admins cannot access standard user data.
- Healthcare Systems: Ensure that physicians cannot access admin records, while admins cannot view sensitive clinical data.
- Financial Platforms: Verify that portfolio managers can’t access compliance officer audit trails and vice versa.
How It Works:¶
This testing requires two separate scan profiles to test both directions of authorization:
- Scan Profile A: Primary user is configured for exploration, secondary user as the target.
- Scan Profile B: Secondary user becomes the primary user, with the first user as the target.
This bidirectional approach captures vulnerabilities from both perspectives, ensuring all potential weaknesses are identified.
Integration with Natural Language Processing (NLP) Queries and Custom Detection Rules¶
We’ve made it simpler than ever to configure tenant isolation rules with Escape’s agentic system. Now, whether you are configuring symmetric or asymmetric permission tests, you can define tenant isolation rules using natural language as mentioned in the previous note—without needing to write complex code.
For complex scenarios where user-specific variations (e.g., timestamps, metadata, or localized data) need to remain tenant-isolated, custom detection rules allow you to precisely target authorization boundaries. This ensures that even complex, nuanced data—such as user-specific metadata—remains securely isolated across tenants.
More Information¶
For a detailed guide on configuring multi-user testing, tenant isolation with natural language rule generation, and custom detection rules, visit our full documentation:
This update gives you greater control, flexibility, and the ability to proactively enforce tenant isolation and authorization boundaries across your web applications and APIs.
And as always, stay secure! :)