| metadata | {"author":"github: Raishin","version":"0.1.0","updated":"2026-06-17","category":"compliance","execution_tier":"mutating-runtime","mcp_servers":[],"oauth_scopes":["InformationProtectionPolicy.Read.All","Files.ReadWrite.All (documented least-privileged APPLICATION permission for driveItem assignSensitivityLabel; Graph exposes no per-item application scope for this protected/metered API)"],"run_as_permissions":{"required":["InformationProtectionPolicy.Read.All — to read available sensitivity labels and verify the proposed label ID (application permission, admin-consented)","Files.ReadWrite.All — the least-privileged APPLICATION permission documented for driveItem: assignSensitivityLabel (higher-privileged alternative is Sites.ReadWrite.All; neither Files.ReadWrite without .All nor Sites.Selected is a supported application permission for this API)","Application permission, admin-consented — no delegated/user-context for background agent operations"],"compensating_controls":["Because no per-item application scope exists for this API, constrain the app's effective reach OUTSIDE the Graph permission: app-only access policy / RSC, or a Sites.Selected site-level grant where the tenant supports it, plus this guard's one-item written-approval gate and PREFLIGHT diff"],"denied":["Directory.ReadWrite.All","Sites.FullControl.All","Sites.ReadWrite.All (higher-privileged alternative — Files.ReadWrite.All is the narrower documented permission for this API)","InformationProtectionPolicy.ReadWrite.All (label policy management — not permitted)","LabelPolicyManagement (any scope)","RoleManagement.ReadWrite.Directory","User.ReadWrite.All","Bulk labeling (any operation targeting more than one item)","Label policy changes (any write to label policy resources)","Removing protection that would downgrade classification without explicit approval token"]},"required_egress":["graph.microsoft.com","login.microsoftonline.com"],"requires_credentials":["GRAPH_CLIENT_ID","GRAPH_TENANT_ID"],"output_attestation":{"schema":"sensitivity-label-attestation-v1","signed_with":"idempotency-key","audit_log":"required"},"liveAgentFields":{"execution_tier":"mutating-runtime","single_op":true,"reversible":true,"requires_approval_token":true,"dry_run_preflight":true,"idempotency_key":true,"blast_radius_required":true},"companion_agents":["m365-live-sensitivity-label-apply-guard-agent"]} |