Per Oso Cloud docs: use Logs to confirm the request arrived and Explain to trace which facts and policy rules produced the decision.

Context: Problem: User bob can edit Document foo but should only have read access. Debug: 1) Reproduce by logging in as Bob and attempting the edit. 2) Open the Logs page in Oso Cloud and find the matching authorization request. If the log shows allowed true, the issue is in your authorization model, not your app code - Oso Cloud received and evaluated the query. 3) Click "Try this query" next to the unexpected result to open the Explain page, which re-runs the query and lists the facts that contributed plus the policy rules that matched. In the documented example, two facts granted edit access because the document belonged to a folder marked public - the root cause was data, not policy syntax.

## Matched source
Source: Source: https://www.osohq.com/docs/develop/troubleshooting/debugging
Original query: "A user got access they should not have in Oso Cloud - debug with Logs and Explain"
Key terms: access, cloud, debug, explain, have, logs, should, they, user
