×
Capability levels
How to read the capability map
Colors show how much tenant engineering is required to achieve a capability.
They are maturity signals—not pass/fail grades, certifications, or security verdicts.
L0
Unavailable from tenant space Red · The provider does not expose the capability.
L1
Build and operate it yourself Amber · Possible through custom automation or external tooling.
L2
Managed, with limitations Blue · Provider-managed, but constrained in scope or configurability.
L3
Managed and customizable Green · Provider-managed with tenant-configurable policy or scope.
MIX
Varies by service Purple · The control contains different L0–L3 results across services.
—
Unknown or unscored Grey · Evidence is insufficient, not applicable, or not yet assessed.
Important: higher levels mean less tenant-owned implementation work.
The right target still depends on your threat model, service scope, and required controls.