No caller identity, unless the instruction demands one.
Solana instructions execute against whatever accounts are passed in. There’s no session or auth token by default. If an instruction doesn’t explicitly require is_signer on the right account, anyone can call it as anyone.
A generic review checks for access control in the web sense, routes, roles, permissions. It won’t know this explicit check is the actual boundary here.