i think that the story is loaded with about 80% superfluous context and 20% story.
op worked at us airforce base managing access control to global intel systems. he delegated authorisation check to jr. jr told op they checked out, however, jr had not adhered to latest security protocol that required cross checking request against request database, relying instead only on physical credentials. op granted access however asked that an officer watch the civilians’ access directly.
a week later it turns out the civilians were conducting pen testing for the systems and op had to debrief how they gained access.