AW-048

Type: Risk acceptance

Subject: R-03

Decision requested: Accept the residual risk recorded for R-03 - OAuth scope over-grant at consent

Inherent / residual: High / High

Control owner: InfoSec + Google Workspace Admin

Context: Treatment: Accept + monitor - vendor dependency. What we can commit to: We can document exactly what permission was granted and confirm the AI platform's own tool settings prevent the wider capability being used. What remains: Google's app controls work per service, not per individual permission, so we most likely cannot strip one unwanted permission and keep the connector. The narrower boundary is the vendor's product decision, not a setting we hold. Basis for acceptance: Yes - accept a permission grant broader than the capability in use.

No verification items specific to this connector.

Ruling:

Amendment or condition: