What this page does and does not say

Coverage is what a real tenant has established about each capability. It is not a score and not a percentage: the Engine publishes neither, and a number computed here would be this site inventing a governance conclusion. A capability proved offline and never run against a tenant has been proved to behave as somebody believed the API behaves, which is a different claim from having read one.

A state here does not mean the collector ran without an error. A real acquisition proves the acquisition path and proves nothing about whether the fields mean what the Engine says they mean: a value can arrive from a real tenant and still be summed into a figure that means nothing, or change its JSON type with how much the collector found. So the Engine publishes a second thing beside the state, per capability — whether the representation was checked, the second authoritative surface for the claim if one exists, and where that comparison stands.

A second surface is not another client reading the same property. A cmdlet wrapping a REST call, an administration portal rendering a value, and a surface documented as followinga setting are consumers of one authority, and their agreement establishes nothing. Where the vendor exposes only one, that is recorded and the limitation stays.

Live validation state per capability, and the rules that depend on it
CapabilityStateLeast privilegeRules that would answer unknown
activitylive-validatedSPO-ACTIVITY-001
agentslive-validatedSites.Read.Allnone
classificationlive-validatedSites.Read.AllSPO-CLASS-001 SPO-CLASS-002 SPO-CLASS-003 SPO-CLASS-004
conditional-accessprovider live-validated, slice not live-validatedPolicy.Read.AllCA-STATE-001
customizationnot live-validatedSites.Read.AllSPO-SCRIPT-001
licensingpartially live-validated, assignment, report identifiability and one usage report were observed against a real directory; the report returned rows and named nobody, and dependency evidence is collected by nothingOrganization.Read.All, User.Read.All, Reports.Read.All, ReportSettings.Read.Allnone
modernitylive-validatedSites.Read.AllSPO-MODERN-001 SPO-MODERN-003 SPO-MODERN-004
ownerslive-validatedSites.Read.AllSPO-SITE-001 SPO-SITE-002
permissionslive-validatedSites.Read.AllSPO-LIST-001 SPO-LIST-002 SPO-LIST-003
sharinglive-validatedSPO-SHARE-001 SPO-SHARE-002 SPO-SHARE-005
siteslive-validatedSPO-SITE-003
spfxnegative path validated, both scopes observed: a tenant catalog of ten solutions and a site catalog of one. No solution in either was behind its catalog version, so the finding branch has not been produced by a real catalogSites.Read.AllSPO-SPFX-001
tenant-sharinglive-validatedSPO-SHARE-003 SPO-SHARE-004

Reading the states

fully live-validated
Both a successful read and a refusal have been observed against a real tenant.
live-validated
A real read produced real evidence.
negative path validated
A typed refusal was observed and no successful read. The collector behaves correctly when it is denied; what it returns when permitted is not established.
not live-validated
Offline tests only. No rule should rest on this alone.

Generated from capability-manifest/1.0.0 at1.0.0b8@2d4f5db76f21, contract1.0.0b8. Every fact on this page is the Engine's; this site publishes it and does not maintain it.