Key risks covered
- - Valid role change by an authorized admin with correct response schema.
- - Missing role, invalid role, unsupported role, and malformed request body.
- - Self-escalation, lower-privilege role changes, and direct API access denial.
- - Tenant or workspace isolation for cross-tenant users and resources.
- - Audit logs, permission cache refresh, concurrent updates, and safe authorization errors.