Access and authorization
Does the code enforce the intended permission model consistently, including for administrative or support tooling that touches account records? Are permission checks placed close to the data access itself, rather than only at the interface layer?