The Standard
Open App Risk Standard (OARS) Version 0.1.0-draft · Status: Draft · Not yet ratified
| Founding author | Khurram Chaudhary (@kuddyc) |
| Founding spec editor | Khurram Chaudhary (@kuddyc) |
| Derived from | Graph Consent Risk Framework, Khurram Chaudhary, 2026 |
| Licence | CC BY 4.0 |
| Project | Citadel Project |
What this standard does
Section titled “What this standard does”Microsoft Entra ID permissions are commonly rated using a static risk tier — Low, Medium, High, or Critical — based on generalized assumptions about individual scopes. While this offers a rough measure of permission sensitivity, it lacks transparency and fails to account for contextual risk. Critically, it evaluates permissions in isolation, without factoring in the application requesting them.
OARS closes that gap with a dual-layer model: it scores the application’s own trust posture and the impact of the permissions it requests, then combines the two into a consent decision. The same permission can warrant very different handling depending on who is asking.
Every input is derived from authoritative, programmatically retrievable sources. No manual attestation or self-reported values are used.
Sections
Section titled “Sections”| Section | Contents |
|---|---|
| 1. Overview | The dual-layer model and the risk domains |
| 2. Application-Level Risk Factors | Factors describing the app’s own posture |
| 3. Permission-Level Risk Factors | Factors describing what a scope enables, including RSC |
| 4. Scoring and Tiers | Normalization, weighting, and tier mapping |
| 5. From Tiers to Enforcement | Turning two tiers into a consent decision |
| 6. Worked Examples | Two end-to-end scored scenarios |
Status of this document
Section titled “Status of this document”This is a draft published for open review. It has not been ratified and should not yet be treated as stable. The model, factors, and scoring values are open to change through the process described in GOVERNANCE.md.
Comments, corrections, and proposals are welcome as issues or discussions.
The Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary. Licensed CC BY 4.0.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard