What is the best practice to debug insufficient privileges on a non admin/server token?

As non admin/server token don’t return any dbg() or else information about ABAC functions etc. I wonder what is the best practice to debug non admin/server roles?

At the beginning it was possible to guess the solutions somehow, but with growing complexity this grows completely over my head, so having there a solution for this would be a true lifesaver.