Follow every request carrying value or personal information, from user entry points through services, caches, queues, and persistence layers. Note where identities are asserted, where messages cross privilege boundaries, and where conversion or signing happens. Readers, compare our checklist with your systems and comment on missed hops, unusual protocols, or side channels discovered during pentests or incident reviews. The goal is practicality, not perfection, so every shared map helps someone else avoid a costly oversight.
Classify secrets, keys, monetary balances, transaction drafts, and customer identifiers using categories tied to action, not vanity labels. If compromise of a class demands rotation, refunds, or regulatory reporting, mark it clearly. Share examples of categories that simplified decisions under pressure, especially during late-night rollbacks or coordinated disclosures. Practical classification reduces meeting time, clarifies responsibilities, and accelerates audits. Comment with lightweight templates your teams actually used and kept, rather than theoretical frameworks that gathered dust.