Permissions
Every permission rated against the permission-level model. Each rating shows which factors were assigned, what each contributed, and why — so you can disagree with a specific input rather than with the number.
Low 5 · Medium 4 · High 1 · Critical 1 · 11 rated
| Permission | Type | Score | Tier |
|---|---|---|---|
Application.ReadWrite.All |
application | 81.2 | Critical |
RoleManagement.ReadWrite.Directory |
application | 64.6 | High |
Sites.FullControl.All |
application | 43.3 | Medium |
Directory.Read.All |
application | 37.3 | Medium |
User.Read.All |
application | 37.3 | Medium |
Files.ReadWrite.All |
application | 36.8 | Medium |
Mail.Send |
delegated | 28 | Low |
Mail.Read |
delegated | 14.1 | Low |
Mail.Read.Shared |
delegated, RSC | 12.1 | Low |
offline_access |
delegated | 10.2 | Low |
User.Read |
delegated | 7 | Low |
How a score is reached
Section titled “How a score is reached”Raw factor scores are grouped by risk domain, normalized against the domain’s maximum, weighted by the domain’s share, and summed into a 0–100 composite — the full method is in §4.
| Domain | Weight | Maximum raw |
|---|---|---|
| Identity & Privilege Escalation | 40% | 140 |
| Access Surface & Blast Radius | 30% | 165 |
| Data Sensitivity & Leakage | 25% | 120 |
| Compliance & Trust Heuristics | 5% | 40 |
Using this data
Section titled “Using this data”curl -O https://citadel.ms/oars-permissions.jsonThe dataset and the model are published as versioned JSON on every release. Model · Permissions · Combinations
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard