A SOC 2 on file does not justify mail read on a wallpaper app
Most vendor scores are questionnaires wearing a number. They ask about encryption, subprocessors, and whether someone has a SOC 2. They almost never ask whether the product requested gmail.readonly to draw a wallpaper. That is how you end up with a "low risk" vendor holding a refresh token into employee mail.
ScopeMantle scores every grant, not every logo. Four dimensions: Security posture, Privacy practices, Scope Sanity, and Breach History. Forty on Scope Sanity is the default review / auto-revoke threshold. You can change it in governance. You should write down who is allowed to change it.
This page is the rubric, worked examples, and the failure modes I have seen when people treat the number as a moral judgment instead of a queueing rule. It is not a credit score for vendors. It is a way to decide which OAuth grants get a human this week.
The four dimensions
| Dimension | What we look at | What it is not |
|---|---|---|
| Security | Public SOC 2 or similar attestation, known CVEs, admin API exposure, vendor age | A pentest we did not run. We do not invent private reports. |
| Privacy | DPA availability, published subprocessors, residency statements, policy link that actually resolves | A transfer-impact assessment. Counsel still owns that. |
| Scope Sanity | Requested scopes vs category baseline (martech, devtool, AI assistant, warehouse connector) | A ban on mail scopes. CRM mail sync can be sane. A summarizer with admin.directory is not. |
| Breach History | Public disclosures matched to client IDs we already inventory | Prediction of the next zero-day. Tabletop revoke covers that, not the score. |
High Security plus insane scopes still fails the composite. Scope Sanity is heavier for this product on purpose. You bought us to govern OAuth, not to replace your GRC questionnaire tool. See Vanta vs ScopeMantle if someone is trying to make that a bake-off.
1. Security
Inputs are public. If a vendor has a current SOC 2 report they publish, that helps. Known CVEs and a habit of exposing an admin API without SSO drop the number. A ten-year-old CRM usually scores better here than a three-month-old Chrome extension. That is not a character reference. Old vendors get breached too (Drift). Security is one input.
Example: a well-known CRM scores around eighty on Security and thirty-five on Scope Sanity when it suddenly wants mail read it never needed for the original sync. The composite flags review. You do not auto-trust the brand.
2. Privacy
DPA on file, subprocessors listed, residency stated, policy URL that is not a 404. Missing privacy policy is enough to drop Privacy and force attestation even when Security is fine. Cookie banners are relevant only when the same vendor also holds an OAuth grant that contradicts the consent story. Inventory triggers a DPIA conversation. It does not auto-block.
3. Scope Sanity
This is the dimension people actually argue about. We compare requested scopes to a category baseline.
- Martech: contacts and campaign scopes are expected.
admin.directory.user.readonlyis not. - Devtool: repo and issue scopes are expected. Company-wide Drive is not.
- AI assistant: people will request mail and Drive. That scores poorly until someone attests the data flow. Context.ai sat at twenty-eight on this pattern.
- Warehouse connector: warehouse and identity scopes can be plausible. Mail read on an ELT tool needs a written why.
Below forty means scopes sit past a conservative category bar (we describe it internally as beyond the ninety-fifth percentile of that category). Document an exception or revoke. Do not debate the poetry of the number in Slack for three weeks.
Financial services teams sometimes raise the mail-scope trigger so that anything with mail read needs a score of fifty or better before it is tolerated. That is a custom baseline. Write it down. Do not quietly edit production policy on a Friday.
4. Breach History
When Salesloft disclosed, Drift client IDs should have gone critical the same day. The feed is public disclosures, not a private intel product we pretend to have. A match recommends bulk revoke. You still decide whether auto-revoke is on. Zero-day vault theft before disclosure is a tabletop problem, not a scoring problem.
Worked examples
A. Context.ai pattern. Category: AI assistant. Scopes: mail plus Drive. Scope Sanity: twenty-eight. New vendor, no dossier. Platform-engineering owner raises severity. This is the grant you wanted in a weekly digest ninety days before April 2026. Details in the Context.ai breakdown.
B. Sanctioned Salesforce via Okta. High Security, moderate Scope Sanity, attested by RevOps. Stays. You still re-attest on a ninety-day cycle. Permanent "it's Salesforce" exceptions fail samples.
C. Unknown Chrome extension. Low on every dimension. Default is auto-revoke if you enabled it. If you did not, it sits in the queue with a red score. Either way you have a row, not a surprise.
D. Acquisition rename. Privacy policy URL starts redirecting to the acquirer. Client ID is unchanged. Refresh the dossier. Do not create a second vendor row because marketing changed the logo.
How to run scoring without ScopeMantle
- Export grants from Google and Okta. Keep client ID, scopes, owner, user count.
- Assign a category by hand. If you cannot, the category is "unknown" and Scope Sanity starts in the cellar.
- Mark mail, Drive, calendar, and directory scopes as Tier 1 blast radius.
- Look up a public trust page. No page, no Security credit.
- Search the vendor name plus "breach" for the last twenty-four months. Record the date you searched.
- Score Scope Sanity 0-100 using a written rubric (example: start at 80, minus 20 per extra sensitive scope beyond the category default, minus 30 if the vendor is unknown).
- Queue everything under forty for a human this week. Ninety-day expiry on any keep decision.
That procedure works for a one-time review. It falls apart when marketing installs four tools before Friday. ScopeMantle runs it on every sync. Same rubric, less heroics.
Overrides, expiry, and who signs
Leadership should sign off before you enable auto-revoke below forty. Security and privacy will disagree about a legitimate AI tool. A forty-eight-hour fast-track attestation is how you avoid shadow reconnect on personal Gmail.
Manual override defaults to ninety days. Permanent exceptions are how CC9.2 findings are born. Name the business sponsor. Marketing owns martech. Engineering owns devtools. If a title in infra or platform engineering owns a high-scope grant, raise severity even when the vendor looks fine.
What to tell an auditor
Show the rubric (this page, plus your threshold). Show a dated export of scores. Show attestation records with expiry. Show one revoke that followed a score, with timestamp. Say the dimensions are public-signal plus scope math, not a private rating agency. Do not claim we hold a SOC 2 we have not published. Do not claim HIPAA. Map the control to CC9.2 identification and monitoring in the compliance map.
Failure modes
- Treating Security as a veto. A SOC 2 does not bless
admin.directoryon a new AI toy. - Tuning the threshold to 15 so nothing ever queues. That is turning the control off.
- Letting scores drift after M&A without a dossier refresh.
- Ignoring Breach History because "we already revoked last year." People reconnect for the next campaign.
- Using the score in a customer-facing claim we cannot support. We do not publish fake customer counts. Neither should you launder our number into one.
How ScopeMantle fits
Inventory from read-only Google Workspace and Okta connectors. Score on every sync. Governance holds the attestation trail. DSAR uses the same vendor list. Optional event stream for SIEM. HRIS-linked owners. Stale grants over ninety days show up in the weekly digest and the board export.
Standard pricing is $5 per employee per month annual or $6 monthly. No seat minimum. Custom at 500+. Thirty-day trial via /demo. Entra is Beta. HIPAA is not attested. No BAA.
Category baselines you can copy into a wiki
These are operator defaults, not science. Change them in writing.
- Calendar / scheduling: calendar scopes expected. Mail read unexpected. Directory unexpected.
- Note-taking / docs: Drive file-level can be sane. Domain-wide Drive plus mail is not.
- Inbox helper / AI summarizer: start them in the penalty box. Attest the retention and training-data story before you tolerate mail read.
- CRM / MAP: contacts expected. Mail send may be expected. Org-wide directory is a separate ticket.
- Support / success: ticket and contact objects expected. Warehouse dump scopes are a category miss.
- Devtools: repo and CI expected. Employee mail is not a debugger feature.
Publish the list. When marketing argues, you argue the category, not your mood. ScopeMantle automates the comparison. The wiki is what you show an auditor when they ask who decided forty was the line.
Composite vs queue
People will ask for a single 0-100 they can sort. Fine. Use it to order the queue. Do not use it as a pass/fail without looking at Scope Sanity. A 72 composite with a 31 Sanity is still a revoke candidate. A 44 composite with a 70 Sanity and a missing privacy policy is an attestation, not an emergency.
Breach History can jump a row to the front of the queue the same day. That jump should page someone. It should not wait for the Friday digest.
What to do this week
- Write a ten-line Scope Sanity rubric and put it in the wiki. Include
gmail.readonlyas Tier 1 mail content. - Score your top twenty grants by user count. You will find at least one wallpaper-class row if the org is mid-size.
- Decide the auto-revoke threshold in a 45-minute meeting with security and privacy. Record the decision.
- Set ninety-day expiry on every current exception. Permanent rows get a sponsor or they get revoked.
- Read the supply-chain playbook so Breach History is not an abstract fourth column.
Stale grants over ninety days belong in the weekly digest even when the score is mediocre. Age is its own smell. Event stream (optional) can emit score changes for SIEM correlation. Do not build a SOC use case that pages on every new calendar scope. Page on Breach History and on admin.directory from an unknown publisher. HRIS-linked owners elevate infra and platform-engineering titles even when the vendor looks boring. A low-scope tool on a production engineer is still a path into mail that resets production credentials.
Field guide: the 45-minute threshold meeting
Security and privacy in a room. Write the category baselines. Pick forty or write a custom mail-scope bar. Decide auto-revoke yes or no. Name the 48-hour fast track. Ninety-day expiry on exceptions. Change ticket. Then score twenty grants by hand so people see the queue. $5 / $6, no seat min. Scoring.
Composite score orders the queue. Scope Sanity still decides revoke. Breach History still pages. Ninety-day expiry still applies to exceptions. Do not tune the threshold to fifteen so nothing queues. That is turning the control off.