Skip to content

Permissions

Every permission rated against the permission-level model. Each rating shows which factors were assigned, what each contributed, and why — so you can disagree with a specific input rather than with the number.

Low 5 · Medium 4 · High 1 · Critical 1 · 11 rated

Permission Type Score Tier
Application.ReadWrite.All application 81.2 Critical
RoleManagement.ReadWrite.Directory application 64.6 High
Sites.FullControl.All application 43.3 Medium
Directory.Read.All application 37.3 Medium
User.Read.All application 37.3 Medium
Files.ReadWrite.All application 36.8 Medium
Mail.Send delegated 28 Low
Mail.Read delegated 14.1 Low
Mail.Read.Shared delegated, RSC 12.1 Low
offline_access delegated 10.2 Low
User.Read delegated 7 Low

Raw factor scores are grouped by risk domain, normalized against the domain’s maximum, weighted by the domain’s share, and summed into a 0–100 composite — the full method is in §4.

Domain Weight Maximum raw
Identity & Privilege Escalation 40% 140
Access Surface & Blast Radius 30% 165
Data Sensitivity & Leakage 25% 120
Compliance & Trust Heuristics 5% 40
Terminal window
curl -O https://open-citadel.org/oars-permissions.json

Model · Permissions · Combinations

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary. Specification and dataset licensed CC BY 4.0; tooling licensed MIT. © 2026 Khurram Chaudhary and the Open Citadel contributors.

An Open Citadel project ·GitHub ·Cite this standard · Code of Conduct