Customer context

Only show products and conditions that are valid for the customer.

B2B search may vary by organization, contract, region, or user role. Rights control should be enforced before or during retrieval.

Assortment rights

Products outside of the permitted contract or account may not be visible through suggestions, results or API responses.

Price context

Search ranking may use availability and pricing information, but should not mix sensitive customer conditions between accounts.

User roles

Buyer, administrator and technical user may have different rights and preferences.

Store and account separation

Combine store context with customer context; neither of them should be implicitly reused from another session.

Caching

Cache keys must contain all relevant access context to prevent data breaches.

Test negative scenarios

Explicitly check that unauthorised products cannot be found via typos, filters, Ids or recommendations.