Threat modeling starts with a map of components and data flows, then asks what can go wrong at each trust boundary. Identify attacker-controlled inputs and valuable assets first.
The demo follows input through an API to storage and highlights the risky boundary. A diagram is useful only when its findings become controls and verification tasks.
When to use
Use it before new features, external integrations, or changes to access boundaries.