Reference
Reference
The generated transparency reference - every one of the 885 checks Watchtower ships and every permission it requests, derived from the product source and kept in sync by CI.
This reference is generated directly from the product source and verified in CI, so it can never drift from what the software actually does. Two views, from opposite directions:
- Check catalog - every one of the 885 built-in checks, grouped by product family, with its stable slug, severity, what it verifies, why that matters, and the exact tenant access its evaluation reads.
- Permissions we request - every permission the app registration asks for at admin consent, what each one reads, and how many checks depend on it - the same mapping from the consent side.