What this page does and does not say

Coverage is what a real tenant has established about each capability. It is not a score and not a percentage: the Engine publishes neither, and a number computed here would be this site inventing a governance conclusion. A capability proved offline and never run against a tenant has been proved to behave as somebody believed the API behaves, which is a different claim from having read one.

Live validation state per capability, and the rules that depend on it
CapabilityStateLeast privilegeRules that would answer unknown
activitylive-validatedSPO-ACTIVITY-001
agentslive-validatednone
classificationlive-validatedSPO-CLASS-001 SPO-CLASS-002 SPO-CLASS-003 SPO-CLASS-004
conditional-accessprovider live-validated, slice not live-validatedPolicy.Read.Allnone
modernitylive-validatedSPO-MODERN-001 SPO-MODERN-003 SPO-MODERN-004
ownerslive-validatedSPO-SITE-001 SPO-SITE-002
permissionslive-validatedSPO-LIST-001
sharinglive-validatedSPO-SHARE-001 SPO-SHARE-002 SPO-SHARE-005
sitesfully live-validatedAllSites.FullControlSPO-SITE-003
spfxnegative path validatedSPO-SPFX-001
tenant-sharinglive-validatedSPO-SHARE-003 SPO-SHARE-004

Reading the states

fully live-validated
Both a successful read and a refusal have been observed against a real tenant.
live-validated
A real read produced real evidence.
negative path validated
A typed refusal was observed and no successful read. The collector behaves correctly when it is denied; what it returns when permitted is not established.
not live-validated
Offline tests only. No rule should rest on this alone.

Generated from capability-manifest/1.0.0 at1.0.0b6@b4bf9c325233, contract1.0.0b6. Every fact on this page is the Engine's; this site publishes it and does not maintain it.