Test with different users
Choose roles that exercise the operation's permission boundary: anonymous visitor, limited editor, and administrator. Use separate browser sessions or an explicit test context for each role.
Test the direct model or endpoint as well as the visible interface. Confirm that denied writes leave the data unchanged and do not reveal private fields in the error response.
Include unpublished resources and resources outside the user's content group where relevant. Record the role and resource used in the test so someone else can reproduce the result.