Trust boundaries in code
Trace external data from input to consequential actions. Manually review authorisation, input handling and business logic. Confirm SAST findings against execution paths and explain them in the relevant file and component context.