New
Risk Scoring Reference

How ThreatLynx calculates and explains application risk scores

This reference documents the ThreatLynx risk scoring methodology — how composite scores are derived, what each dimension measures, and how governance decisions influence the result. Intended for security teams, auditors, governance reviewers, and procurement due diligence.

Rules-basedFully explainableNo black-box AIAudit-friendly

ThreatLynx provides explainable governance and risk visibility support. Scores are rules-based indicators designed to assist review workflows — not definitive security assessments, compliance certifications, or legal determinations.

Composite scoring model

Every application receives a score from 0–100 calculated across seven additive dimensions. Each dimension is documented and traceable — no opaque weighting, no hidden model.

Score bands — prioritisation tiers
75 – 100Critical

Immediate governance review. High-sensitivity scopes, broad user exposure, or multiple elevated factors. Escalate to security team.

50 – 74High

Prioritise for governance cycle. Significant data access with limited oversight. Review and document before next reporting period.

25 – 49Medium

Schedule for periodic review. Some risk indicators present. Suitable for batched governance cycles.

0 – 24Low

Lower risk profile. Narrow scopes, limited exposure, or governance review documented and on record.

Score composition

Scores are additive across seven dimensions. Maximum total is 100. Each dimension is capped.

max 30 pts

Permission sensitivity

max 20 pts

Data breadth

max 15 pts

User exposure

max 15 pts

AI / agent exposure

max 10 pts

Vendor posture

max 15 pts

Governance status

max 10 pts

Compliance indicators

composite

0–100

Additive score

Core risk dimensions

Each dimension is independently scored and documented. Any application's score can be traced factor by factor — suitable for audit evidence and governance review.

Permission sensitivity

The type of OAuth scopes granted carries the highest individual weight. Mail write, directory admin, and file delete permissions represent materially different risk levels than profile or calendar read.

Data exposure breadth

An application granted access across multiple sensitive data categories (mail + files + directory) scores higher than one with a narrow, single-purpose scope. Blast radius potential is a primary input.

User exposure count

Organisational exposure scales with authorisation breadth. The same scope granted across a department or domain-wide carries higher risk than one held by a single user or service account.

Vendor posture indicators

Vendor jurisdiction, registration country, and known classification patterns contribute to the score. Applications incorporated outside Australia may raise data sovereignty considerations.

Governance status

Unreviewed applications score higher than those with a documented governance decision. Approving, restricting, or blocking an application updates its active score — governance action is recognised.

AI and agent exposure

Applications identified as AI-powered tools, autonomous agents, or MCP-connected systems receive additional weighting. These categories commonly process sensitive data to deliver functionality.

Dimension weights reflect the relative organisational impact of each factor in typical Australian enterprise environments. Weights are reviewed periodically. Custom threshold configurations are available for enterprise plans.

OAuth permission sensitivity

Permission sensitivity is the highest-weight dimension — carrying up to 30 points of the composite score. Scope categories are classified by the potential data impact of misuse or compromise.

CategoryExample scopesSensitivityNotes
Directory / AdminAdmin SDK, Directory API, User account managementCriticalRarely required by legitimate third-party SaaS tools. Grants broad read/write access to user accounts, groups, and domain settings.
Mail — write / send / deleteGmail send, modify, delete; Exchange mail writeHighPermits sending email as users, modifying or deleting message content. Common in productivity and AI assistant tools.
Files — write / deleteDrive file write, SharePoint files write, OneDrive deleteHighAllows creating, modifying, or deleting documents and spreadsheets. Significant data destruction risk if abused.
Mail — readGmail readonly, Mail.Read, IMAP accessMedium–HighPassive read access to all email content. Frequently granted by AI writing assistants, calendar tools, and CRM integrations.
Files — readDrive readonly, Files.Read, SharePoint readMediumRead access to documents and spreadsheets. Risk depends on the sensitivity of content held in the workspace.
CalendarCalendar events read/write, Bookings accessMediumScheduling and meeting data. Contains attendee information and meeting context. Lower direct risk than mail or file access.
ContactsPeople API read, Contacts.ReadLow–MediumAccess to organisational contact lists. Relevant for identifying data subject exposure under the Privacy Act 1988.
Profile / openidBasic profile, email, openid, User.ReadLowIdentity and sign-in scopes only. Minimal data access beyond name, email address, and profile image.

Persistent and offline access scopes

Applications granted offline_access or access_type=offline retain refresh tokens that allow continued API access without user re-authorisation. This persistence factor is applied as an additive modifier on top of the underlying scope sensitivity score, reflecting the extended window of potential exposure.

AI and agent exposure indicators

Applications with indicators of AI capability, autonomous operation, or non-human identity receive additional weighting. Detection is metadata-based and confidence-graded — not content inspection.

Indicator typeDetection signalConfidenceWeight
AI vendor patternApplication name, client ID, or vendor domain matches a known AI/LLM vendor pattern.High+12 pts
Sensitive scope + AI vendorAI vendor classification confirmed AND access to mail, files, or directory scopes.High+20 pts
Broad persistent accessApplication holds multiple sensitive scopes without a specific single-user owner (service-level pattern).Medium+10 pts
MCP-connected indicatorClient metadata or vendor pattern matches known MCP-connected system characteristics.Medium+12 pts
Automation workflow patternVendor classification as workflow automation platform (e.g. Zapier, Make) with multi-scope access.Medium+8 pts
Service principal (M365)Application registered as a service principal or enterprise application in Entra ID.High (M365)+10 pts

Agent identity detection is metadata-driven, not endpoint-based. ThreatLynx does not monitor employee behaviour, inspect message content, or log user activity. Detection signals are governance readiness indicators — review by application or security owners is recommended before any formal classification.

Governance influence on scores

Governance decisions affect the composite score. Taking documented action reduces ungoverned risk weighting. This creates a direct incentive for active governance — the score reflects your team's posture.

Ungoverned+15 pts

No governance decision has been recorded. Highest additive modifier. Default state for newly discovered applications.

Under Review+8 pts

Review has been initiated but no outcome has been documented. Review without decision still carries elevated weighting.

Restricted±0 pts

A restriction has been applied. Score reflects the underlying risk factors only — governance action is neutral, not rewarded above base.

Approved−10 pts

Application has been reviewed and approved with documented rationale. Score is reduced to reflect active governance posture.

BlockedFlagged

Block decision recorded. Application is flagged for remediation. Score is maintained for audit visibility — block does not clear risk.

Exception Granted−5 pts

Exception has been granted with documented rationale and review date. Partial reduction applied for documented decision with expiry.

Owner assignment

Applications without an assigned business owner carry a small additive penalty, reflecting unresolved accountability. Assigning an owner is treated as a governance maturity signal.

Review date and overdue status

Applications with an overdue scheduled review receive a stale-governance modifier. Review dates can be set per application — scheduled review discipline is reflected in the score.

Compliance framework influence

Risk score dimensions map to Australian and international governance frameworks. Scores can be used as structured evidence in governance review cycles — not as certification.

ASD Essential Eight — Application Control

Readiness visibility only

Ungoverned applications with elevated scopes contribute to unresolved findings relevant to Application Control maturity.

APRA CPS 234 — Third-party Risk

Governance evidence support

Risk scores and governance decisions provide structured evidence for third-party information security capability assessments and information asset registers.

Privacy Act 1988 — APP 11

Identification support only

Applications with access to personal information (mail, contacts, directory) are surfaced and scored, supporting APP 11 reasonable-steps obligations.

ISO/IEC 27001:2022 — A.8 / A.9

Partial coverage

Application inventory and access-control records support Annex A controls for asset management and access review cycles.

Compliance framework references are informational. ThreatLynx does not provide legal advice, compliance certification, or guaranteed compliance outcomes. Risk scores are rules-based governance indicators, not regulatory determinations. Consult qualified legal, compliance, and security advisors for specific obligations.

Confidence and limitations

Understanding score limitations is essential for correct governance use. These constraints apply to all ThreatLynx deployments.

01

Scores are indicators, not verdicts

Risk scores are designed to prioritise governance review workflows. They are additive, rules-based assessments of available OAuth metadata — not comprehensive security assessments, audit opinions, or definitive risk determinations.

02

Score accuracy depends on metadata completeness

If vendor registration data, scope strings, or OAuth client metadata are incomplete or unavailable, the resulting score will reflect what was available at the time of sync, not the full risk profile.

03

Microsoft 365 scoring depends on Graph metadata

M365 scope depth, service principal detection, and permission data fidelity depend on the metadata returned by Microsoft Graph. Scores derived from M365 data reflect what was available at the time of sync.

04

AI and agent detection is confidence-based

AI tool and agent identity classification is based on metadata heuristics — not content inspection or API call monitoring. Some AI-powered tools may not be classified, and non-AI tools may occasionally match classification patterns.

05

Governance action requires human review

ThreatLynx does not automatically revoke, restrict, or block applications. Governance actions are recorded but must be executed by an administrator in the workspace admin console.

06

Scores reflect snapshot state

Scores are recalculated at each sync. Between syncs, a new high-risk OAuth grant may not yet be reflected. For time-sensitive environments, more frequent syncs are recommended.

Worked example scoring breakdown

An illustrative example showing how a composite score is assembled across scoring dimensions. All values are hypothetical and for reference only.

Hypothetical application

AI Writing Assistant Pro

AI productivity tool · Gmail + Drive access · 38 users · Vendor incorporated in USA · No governance decision on record

80
High risk
Score factor breakdown

Mail — read scope

Active gmail.readonly scope — highest-weight single scope.

18 / 25 pts

+18

Files — read scope

Drive readonly scope — significant data exposure category.

12 / 25 pts

+12

Scope breadth (2 domains)

Access spans mail AND files — combined breadth multiplier.

10 / 20 pts

+10

AI vendor classification

Vendor matched known AI productivity tool pattern.

12 / 15 pts

+12

User exposure (38 users)

Broad departmental authorisation — above single-user baseline.

9 / 15 pts

+9

Governance: Ungoverned

No review decision on record — full governance penalty applied.

15 / 15 pts

+15

Vendor jurisdiction

Vendor incorporated outside Australia — data sovereignty factor.

4 / 5 pts

+4

Composite risk score

Sum of all applicable factors

80High

Recommended governance action

Assign a business owner and initiate a governance review. Document the approved use case and data access rationale. If mail and file access cannot be justified by business function, consider requesting a restricted scope version of the integration or moving to block. Documenting a governance decision will reduce the score by up to 25 points.

This example is illustrative only. Actual scores depend on the specific OAuth scopes, vendor metadata, user counts, and governance records for each application in your environment.

See risk scoring on your workspace data

Request a guided walkthrough to explore how ThreatLynx scores the applications connected to your Google Workspace or Microsoft 365 environment.