In scope today
A question is counted here only when the capability that supplies its evidence has read a real tenant. Implemented is not established: a collector proved only by offline tests has been proved to behave as somebody believed the API behaves, and a collector proved only by being refused has proved nothing about what it returns when it is permitted.
| Workload | Questions established |
|---|---|
sharepoint | 17 |
17 questions currently satisfy the publication criteria at 1.0.0b6@b4bf9c325233.
The number never appears without the criterion. A count detached from what it counts becomes a score, and a score is the one thing this product does not publish.
The publication criteria
A question appears above only when all of these hold. The page is derived from the evidence chain, so it is not possible to publish a question that does not satisfy them: this page is a check on the product, not a description of it.
- the rule declares its criteria, and the basis type is published;
- the evidence it requires is declared;
- the capability supplying that evidence has a positive live read against a real tenant;
- a denial, an unsupported surface or an absent licence does not collapse into an empty estate;
- the answer is reproducible from the evidence;
- the limitations are published, including what a pass leaves unresolved;
- a third party can verify the assessment without pH7x Systems;
- the sources the rule rests on are identified.
Criteria 1, 2, 3, 6 and 8 are read from the manifest for every question on this page. Criteria 4, 5 and 7 hold by construction and are proved by the Engine's own gates rather than re-checked here: stated so that nobody reads this list as eight independent measurements.
Implemented, and not counted
These exist in the product and are excluded from the number above. The reason is the Engine's own sentence, not ours.
conditional-access: provider live-validated, slice not live-validatedspfx: negative path validatedSPO-LIST-002: no capability with a proven live read supplies its evidenceSPO-LIST-003: no capability with a proven live read supplies its evidenceSPO-SPFX-001: no capability with a proven live read supplies its evidence
Not covered
We publish no governance questions for these, and nothing here is a commitment to add them.
Exchange · Teams · Intune · Purview · Defender
How outcomes are worded
The Engine's contract values are the authority. This site translates them for reading and never redefines one; the table is published so a reader can always recover the value behind the wording.
| Contract value | Public wording |
|---|---|
pass | established |
fail | departure from the stated criteria |
unknown | could not be established |
not-applicable | not applicable |
invalid-evidence | evidence not usable |
Reading "could not be established"
This is not a failure. It means the available evidence does not support a conclusion.
A tool that answers it is refusing to invent an answer. On some collectors it is the most common outcome, and that is the product working: a run that returned green everywhere would be the result worth distrusting. It is also the answer with the most information in it, because it names what would have to be read to decide.
What is not established about continuity
Individual assessments are tamper-evident. Complete continuity across multiple assessments is not established.
A digest detects alteration. It does not detect omission: it proves a document was not changed, and it cannot prove that none was removed. Those are different guarantees, and the difference is stated here rather than left for somebody to discover.
Generated from capability-manifest/1.0.0 at1.0.0b6@b4bf9c325233, contract1.0.0b6. Every fact on this page is the Engine's; this site publishes it and does not maintain it.