What this page does and does not say
Coverage is what a real tenant has established about each capability. It is not a score and not a percentage: the Engine publishes neither, and a number computed here would be this site inventing a governance conclusion. A capability proved offline and never run against a tenant has been proved to behave as somebody believed the API behaves, which is a different claim from having read one.
| Capability | State | Least privilege | Rules that would answer unknown |
|---|---|---|---|
activity | live-validated | SPO-ACTIVITY-001 | |
agents | live-validated | none | |
classification | live-validated | SPO-CLASS-001 SPO-CLASS-002 SPO-CLASS-003 SPO-CLASS-004 | |
conditional-access | provider live-validated, slice not live-validated | Policy.Read.All | none |
modernity | live-validated | SPO-MODERN-001 SPO-MODERN-003 SPO-MODERN-004 | |
owners | live-validated | SPO-SITE-001 SPO-SITE-002 | |
permissions | live-validated | SPO-LIST-001 | |
sharing | live-validated | SPO-SHARE-001 SPO-SHARE-002 SPO-SHARE-005 | |
sites | fully live-validated | AllSites.FullControl | SPO-SITE-003 |
spfx | negative path validated | SPO-SPFX-001 | |
tenant-sharing | live-validated | SPO-SHARE-003 SPO-SHARE-004 |
Reading the states
- fully live-validated
- Both a successful read and a refusal have been observed against a real tenant.
- live-validated
- A real read produced real evidence.
- negative path validated
- A typed refusal was observed and no successful read. The collector behaves correctly when it is denied; what it returns when permitted is not established.
- not live-validated
- Offline tests only. No rule should rest on this alone.
Generated from capability-manifest/1.0.0 at1.0.0b6@b4bf9c325233, contract1.0.0b6. Every fact on this page is the Engine's; this site publishes it and does not maintain it.