Separate observation from interpretation
Record the request, response, code path, state transition, or permission outcome that was observed. Then state what it may mean. This separation makes uncertainty reviewable instead of hiding it inside confident prose.
Name the preconditions
Authentication level, role, tenant membership, network position, feature flags, timing, and user interaction can determine whether a weakness is exploitable. Missing preconditions turn edge cases into misleading headlines.
Show the violated boundary
Explain which subject acted on which object and why that action should have been denied. For injection and data-flow issues, identify how untrusted input reached the dangerous operation and what validation was bypassed.
Consolidate the root cause
Ten endpoints affected by one authorization helper may be one systemic finding with a broad blast radius—not ten independent defects. Conversely, similar symptoms with different controls may need separate ownership.
Make reproduction safe
Use the least harmful proof that establishes impact. Redact secrets, avoid retaining unnecessary personal data, and do not encourage copying destructive payloads into production.
Calibrate severity with context
Technical impact, required privileges, reachability, data sensitivity, detectability, and business process all matter. A score can support consistency; it cannot replace the organization’s risk decision.