It's best practice to not leak the existence of a resource by returning 403 when the resource has been found. It's better to just return 404 so that you can't guess ids. The testing tool should either enforce this or make it configurable if it's actually desired.