Type: Risk acceptance
Subject: R-03
Decision requested: Accept the residual risk recorded for R-03 - OAuth scope over-grant at consent
Inherent / residual: High / High
Control owner: InfoSec + Google Workspace Admin
Context: Treatment: Accept + monitor - vendor dependency. What we can commit to: We can document exactly what permission was granted and confirm the AI platform's own tool settings prevent the wider capability being used. What remains: Google's app controls work per service, not per individual permission, so we most likely cannot strip one unwanted permission and keep the connector. The narrower boundary is the vendor's product decision, not a setting we hold. Basis for acceptance: Yes - accept a permission grant broader than the capability in use.
No verification items specific to this connector.
Ruling:
Amendment or condition: