Mass Assignment

Mass Assignment, fillable, and guarded

create(), fill(), update() and new Product([...]) assign whole arrays, usually request input, so Eloquent lets through only the columns you list. With no list a model is fully guarded: the bare Product rejected create() with MassAssignmentException: Add [sku] to fillable property to allow mass assignment on [App\Models\Product]. The configured one lists six columns in #[Fillable([...])] (or the older protected $fillable), and drops anything else silently:

What the fillable list lets throughSQL
use App\Models\Product;
use Illuminate\Database\Eloquent\Model;
$input = ['sku' => 'BK-GO-01', 'title' => 'Go for PHP Developers', 'id' => 1, 'stock' => 3];
echo json_encode((new Product($input))->getAttributes()), "\n";
Model::preventSilentlyDiscardingAttributes();
new Product($input);
Output
{"sku":"BK-GO-01","title":"Go for PHP Developers","stock":3}
   Illuminate\Database\Eloquent\MassAssignmentException  Add fillable property [id] to allow
mass assignment on [App\Models\Product].

The injected id vanished; without the list, a form field named id or is_admin would write what it likes. Model::preventSilentlyDiscardingAttributes($this->app->isLocal()) in AppServiceProvider::boot() makes a typo in the list fail loudly in development only. #[Guarded(['id'])] inverts the list; #[Unguarded] ($guarded = []) turns it off, safe only when every write passes validated data (Validating Inside a Controller). forceFill() bypasses it for trusted values.