Skip to content

Permissions

Every permission rated against the permission-level model. Each rating shows which factors were assigned, what each contributed, and why — so you can disagree with a specific input rather than with the number.

Low 5 · Medium 4 · High 1 · Critical 1 · 11 rated

Permission Type Score Tier
Application.ReadWrite.All application 81.2 Critical
RoleManagement.ReadWrite.Directory application 64.6 High
Sites.FullControl.All application 43.3 Medium
Directory.Read.All application 37.3 Medium
User.Read.All application 37.3 Medium
Files.ReadWrite.All application 36.8 Medium
Mail.Send delegated 28 Low
Mail.Read delegated 14.1 Low
Mail.Read.Shared delegated, RSC 12.1 Low
offline_access delegated 10.2 Low
User.Read delegated 7 Low

Raw factor scores are grouped by risk domain, normalized against the domain’s maximum, weighted by the domain’s share, and summed into a 0–100 composite — the full method is in §4.

Domain Weight Maximum raw
Identity & Privilege Escalation 40% 140
Access Surface & Blast Radius 30% 165
Data Sensitivity & Leakage 25% 120
Compliance & Trust Heuristics 5% 40
Terminal window
curl -O https://citadel.ms/oars-permissions.json

The dataset and the model are published as versioned JSON on every release. Model · Permissions · Combinations

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard