Customer context
Only show products and conditions that are valid for the customer.
B2B search may vary by organization, contract, region, or user role. Rights control should be enforced before or during retrieval.
Assortment rights
Products outside of the permitted contract or account may not be visible through suggestions, results or API responses.
Price context
Search ranking may use availability and pricing information, but should not mix sensitive customer conditions between accounts.
User roles
Buyer, administrator and technical user may have different rights and preferences.
Store and account separation
Combine store context with customer context; neither of them should be implicitly reused from another session.
Caching
Cache keys must contain all relevant access context to prevent data breaches.
Test negative scenarios
Explicitly check that unauthorised products cannot be found via typos, filters, Ids or recommendations.