Project access is not object permission
Having access to a project, workspace, or tenant does not mean every nested action is allowed. Read on the folder is not delete on every child. Member of the org is not admin on every resource inside it. Authorize each request as subject + action + resource — including nested objects — instead of stopping at “they can see the parent.”
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.