Open method
Every rating traces to published factors, published weights, and published rationale. If you disagree with a rating, you can see exactly which input to argue about.
An Entra admin is asked to approve an application requesting Mail.Read. Is that
risky? Should a directory role be classed as Critical, or merely High?
These questions get answered every day — usually by tooling whose reasoning nobody can inspect, or by tribal knowledge that cannot be defended in an audit. Where a rating exists, the method behind it is almost always invisible.
We publish the method, not just the answer.
| Standard | Status | What it covers |
|---|---|---|
| OARS Open App Risk Standard |
draft | Rates the risk of applications and the permissions they request in Microsoft Entra ID, using a dual-layer model that scores the application’s trust posture alongside the impact of the permissions it requests. |
| Entra role tiering | planned | Classifying Entra directory roles as Critical, High, Medium, or Low with published factors and reasoning. |
Open method
Every rating traces to published factors, published weights, and published rationale. If you disagree with a rating, you can see exactly which input to argue about.
Evidence over assertion
Scoring inputs must be programmatically retrievable from authoritative sources. Self-attestation and vendor claims are not inputs.
Machine-readable first
Every standard ships JSON that tools consume directly. A standard only humans can read cannot be enforced consistently, and prose alone has no test suite.
Nobody owns it
The chair rotates every six months, decisions are made in public, and the licence keeps the work open regardless of who maintains it.
You do not need to be a maintainer or a security researcher. The most useful thing you can tell us is “I run tenants, and this rating does not match what I see in production.”
An Open Citadel project ·GitHub ·Code of Conduct