A login page is not the application
An unauthenticated scan may reach public routes while missing the workflows available to signed-in users. Coverage also changes with role, object ownership and the state of a session.
A user who can read their own record is not necessarily allowed to read someone else's. Testing that distinction needs appropriate test identities and objects, not just a successful HTTP response.
Make the identity explicit
Pentest-AI supports authentication inputs and named authentication profiles. Inspect the options in your installed version:
ptai start --help
ptai auth profile --help
Use dedicated test accounts and only permissions included in the engagement scope. Keep passwords and tokens out of public logs and command examples. Do not assume that a logged-in response proves the intended role was tested.
Check the control
For an access-control finding, the useful evidence is the difference between an allowed action and a disallowed one under comparable conditions. A redirect, a generic success page or stale session state can otherwise obscure the result.
Review what was actually requested and returned. Unsupported checks can remain candidates for a human to investigate.