OAuth grants requiring review
Retained authorisation evidence, including inactive or frozen-user association when the retained source provides it.
External Connections
Review connected application evidence, credential configuration and externally exposed surfaces without retaining or testing credentials.
Retained authorisation evidence, including inactive or frozen-user association when the retained source provides it.
Application identity, governance context, linked findings, observed evidence and explicit gaps.
Named Credentials, External Credentials, certificates, sites, Experience Cloud and outbound endpoints.
Evidence boundary: an authorisation record does not prove a credential works, and Security Observatory never probes it. External Client App inventory is not claimed; ECA references describe the subscriber-owned self-callout prerequisite and principal context only.