What this page does and does not say
Coverage is what a real tenant has established about each capability. It is not a score and not a percentage: the Engine publishes neither, and a number computed here would be this site inventing a governance conclusion. A capability proved offline and never run against a tenant has been proved to behave as somebody believed the API behaves, which is a different claim from having read one.
A state here does not mean the collector ran without an error. A real acquisition proves the acquisition path and proves nothing about whether the fields mean what the Engine says they mean: a value can arrive from a real tenant and still be summed into a figure that means nothing, or change its JSON type with how much the collector found. So the Engine publishes a second thing beside the state, per capability — whether the representation was checked, the second authoritative surface for the claim if one exists, and where that comparison stands.
A second surface is not another client reading the same property. A cmdlet wrapping a REST call, an administration portal rendering a value, and a surface documented as followinga setting are consumers of one authority, and their agreement establishes nothing. Where the vendor exposes only one, that is recorded and the limitation stays.
| Capability | State | Least privilege | Rules that would answer unknown |
|---|---|---|---|
activity | live-validated | SPO-ACTIVITY-001 | |
agents | live-validated | Sites.Read.All | none |
classification | live-validated | Sites.Read.All | SPO-CLASS-001 SPO-CLASS-002 SPO-CLASS-003 SPO-CLASS-004 |
conditional-access | provider live-validated, slice not live-validated | Policy.Read.All | CA-STATE-001 |
customization | not live-validated | Sites.Read.All | SPO-SCRIPT-001 |
licensing | partially live-validated, assignment, report identifiability and one usage report were observed against a real directory; the report returned rows and named nobody, and dependency evidence is collected by nothing | Organization.Read.All, User.Read.All, Reports.Read.All, ReportSettings.Read.All | none |
modernity | live-validated | Sites.Read.All | SPO-MODERN-001 SPO-MODERN-003 SPO-MODERN-004 |
owners | live-validated | Sites.Read.All | SPO-SITE-001 SPO-SITE-002 |
permissions | live-validated | Sites.Read.All | SPO-LIST-001 SPO-LIST-002 SPO-LIST-003 |
sharing | live-validated | SPO-SHARE-001 SPO-SHARE-002 SPO-SHARE-005 | |
sites | live-validated | SPO-SITE-003 | |
spfx | negative path validated, both scopes observed: a tenant catalog of ten solutions and a site catalog of one. No solution in either was behind its catalog version, so the finding branch has not been produced by a real catalog | Sites.Read.All | SPO-SPFX-001 |
tenant-sharing | live-validated | SPO-SHARE-003 SPO-SHARE-004 |
Reading the states
- fully live-validated
- Both a successful read and a refusal have been observed against a real tenant.
- live-validated
- A real read produced real evidence.
- negative path validated
- A typed refusal was observed and no successful read. The collector behaves correctly when it is denied; what it returns when permitted is not established.
- not live-validated
- Offline tests only. No rule should rest on this alone.
Generated from capability-manifest/1.0.0 at1.0.0b8@2d4f5db76f21, contract1.0.0b8. Every fact on this page is the Engine's; this site publishes it and does not maintain it.