Risk combines what a tool is (vendor posture from the catalog) with how it's actually used in your organization: which data classes it touches, how many users, what departments, what the enforcement history looks like. Two companies using the same tool can — correctly — score it differently.
Scores move as reality moves: a tool that starts touching customer PII climbs, a retired tool decays, an agent that trips policy repeatedly gets hotter. Prioritization stays honest without anyone re-running a review.
Click any score and it splits into its factors — the data classes involved, the usage volume, the vendor posture inputs — so the conversation with a skeptical stakeholder is about evidence, and the artifact you show an auditor explains itself.
Weights are adjustable — a healthcare deployment can weight PHI exposure higher than a fintech weights source code, and the decomposition shows the effect.
Yes — thresholds drive policy, so tools crossing a risk line automatically pick up stricter rules pending review.
Factors are visible and correctable — misclassified usage can be recategorized, and the score recomputes with the correction logged.
Yes — agents score on the same dimensions plus action patterns: tool scopes used, destinations reached, and enforcement history.