Identity Risk Calculator
Score a single identity โ a human user, a service account, or an AI agent โ from 0โ100 across the factors that actually drive account-takeover risk: blast radius, authentication strength, exposure, governance and monitoring. Nothing is uploaded; the math runs in your browser.
How much damage this person can do if the account is taken over.
A well-governed identity. Keep the controls current and re-score when scope or access changes.
How to read it. This is a fast, transparent triage score, not a substitute for your IdP's live risk engine. Use it to compare identities, justify where to spend hardening effort first, and to make the "why is this account risky?" conversation concrete.
Bring the score down by cutting blast radius (least privilege), moving to phishing-resistant authentication, restricting to managed devices, and putting monitoring on the identities that can do the most damage. Read the high-risk user checklist and the FIDO2 guide.
FAQ
What does the Identity Risk Calculator do?
It scores a single identity from 0 to 100 based on the factors that drive account-takeover and misuse risk โ privilege / blast radius, authentication strength, network exposure, credential handling, governance and monitoring โ and bands it Low, Moderate, High or Critical. It works for human users, service accounts, and agentic (AI) identities, each with a tailored set of factors.
Why score service accounts and AI agents separately?
Non-human identities now outnumber human ones and fail differently. A service account's risk is dominated by long-lived secrets, orphaned ownership and over-permissioning; an AI agent's risk is dominated by autonomy, tool/shell access, prompt-injection exposure and whether it runs under its own governed identity. The calculator uses factor sets tuned to each.
Is my data uploaded anywhere?
No. The calculation is pure client-side math in your browser. Nothing you select is sent to a server.
Does this replace my identity provider's risk engine?
No. Live IdP risk (Entra ID Protection, Okta ThreatInsight, etc.) uses real signals like impossible travel and leaked credentials. This tool is a fast, transparent triage score to compare identities, prioritise hardening, and make the "why is this account risky?" conversation concrete.
How do I lower an identity's score?
Cut blast radius with least privilege, move to phishing-resistant authentication (FIDO2/passkeys), restrict logins to managed devices, replace long-lived secrets with short-lived tokens or managed identities, assign an owner and lifecycle, and put logging and alerting on the identities that can do the most damage.