Skip to content
The Citadel mark — a navy rampart forming an open C (concept)

Open Citadel

Open standards for Microsoft security decisions. Because a risk rating you cannot inspect is a risk rating you cannot defend.

An Entra admin is asked to approve an application requesting Mail.Read. Is that risky? Should a directory role be classed as Critical, or merely High?

These questions get answered every day — usually by tooling whose reasoning nobody can inspect, or by tribal knowledge that cannot be defended in an audit. Where a rating exists, the method behind it is almost always invisible.

We publish the method, not just the answer.

Standard Status What it covers
OARS
Open App Risk Standard
draft Rates the risk of applications and the permissions they request in Microsoft Entra ID, using a dual-layer model that scores the application’s trust posture alongside the impact of the permissions it requests.
Entra role tiering planned Classifying Entra directory roles as Critical, High, Medium, or Low with published factors and reasoning.

Open method

Every rating traces to published factors, published weights, and published rationale. If you disagree with a rating, you can see exactly which input to argue about.

Evidence over assertion

Scoring inputs must be programmatically retrievable from authoritative sources. Self-attestation and vendor claims are not inputs.

Machine-readable first

Every standard ships JSON that tools consume directly. A standard only humans can read cannot be enforced consistently, and prose alone has no test suite.

Nobody owns it

The chair rotates every six months, decisions are made in public, and the licence keeps the work open regardless of who maintains it.

Governance →

You do not need to be a maintainer or a security researcher. The most useful thing you can tell us is “I run tenants, and this rating does not match what I see in production.”

Contribute to OARS · Open questions · Discord · GitHub