Mail.Read.Shared
Low 12.1 / 100 · delegated · Resource-Specific Consent · exchange
The same read capability as Mail.Read, but constrained to explicitly assigned mailboxes through an Application Access Policy rather than reaching whatever the consenting user can see. Permission Breadth and Exfiltration Potential both take their reduced RSC values, which is the model rewarding a deliberate least-privilege choice. This entry exists to demonstrate the RSC adjustment against its unscoped equivalent.
Factor assignments
Section titled “Factor assignments”| Factor | Value | Score | Domain |
|---|---|---|---|
| Data Classification | Confidential | 25 | Data Sensitivity & Leakage |
| Exfiltration Potential | Basic read | 10 (RSC) | Data Sensitivity & Leakage |
| Permission Type | Delegated | 10 | Access Surface & Blast Radius |
| Token Persistence | Short-lived | 10 | Data Sensitivity & Leakage |
| Permission Breadth | Single user or object | 5 (RSC) | Access Surface & Blast Radius |
| Access Policy Modification | None | 0 | Access Surface & Blast Radius |
| App Role Bundles | No bundle | 0 | Identity & Privilege Escalation |
| Impersonation Capability | None | 0 | Identity & Privilege Escalation |
| Legacy API Risk | Modern API | 0 | Compliance & Trust Heuristics |
| Permission Operation | Read | 0 | Access Surface & Blast Radius |
| Privilege Depth | No administrative depth | 0 | Identity & Privilege Escalation |
| Privilege Elevation | None | 0 | Identity & Privilege Escalation |
| User Breadth | One user | 0 | Access Surface & Blast Radius |
How the score is reached
Section titled “How the score is reached”| Domain | Raw | Normalized | Weight | Contribution |
|---|---|---|---|---|
| Identity & Privilege Escalation | 0 / 140 | 0% | 40% | 0 |
| Access Surface & Blast Radius | 15 / 165 | 9.1% | 30% | 2.73 |
| Data Sensitivity & Leakage | 45 / 120 | 37.5% | 25% | 9.38 |
| Compliance & Trust Heuristics | 0 / 40 | 0% | 5% | 0 |
| Composite | 12.1 |
References
Section titled “References”Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard