OWASP line
A01: IDOR, vertical/horizontal privilege escalation, RBAC/ABAC, deny-by-default
4 sections