External Connections

OAuth, credentials and external exposure.

Review connected application evidence, credential configuration and externally exposed surfaces without retaining or testing credentials.

OAuth grants requiring review

Retained authorisation evidence, including inactive or frozen-user association when the retained source provides it.

Connected App Evidence Passport

Application identity, governance context, linked findings, observed evidence and explicit gaps.

Credentials and surfaces

Named Credentials, External Credentials, certificates, sites, Experience Cloud and outbound endpoints.

Evidence boundary: an authorisation record does not prove a credential works, and Security Observatory never probes it. External Client App inventory is not claimed; ECA references describe the subscriber-owned self-callout prerequisite and principal context only.