How ThreatLynx calculates and explains application risk scores
This reference documents the ThreatLynx risk scoring methodology — how composite scores are derived, what each dimension measures, and how governance decisions influence the result. Intended for security teams, auditors, governance reviewers, and procurement due diligence.
ThreatLynx provides explainable governance and risk visibility support. Scores are rules-based indicators designed to assist review workflows — not definitive security assessments, compliance certifications, or legal determinations.
Composite scoring model
Every application receives a score from 0–100 calculated across seven additive dimensions. Each dimension is documented and traceable — no opaque weighting, no hidden model.
Immediate governance review. High-sensitivity scopes, broad user exposure, or multiple elevated factors. Escalate to security team.
Prioritise for governance cycle. Significant data access with limited oversight. Review and document before next reporting period.
Schedule for periodic review. Some risk indicators present. Suitable for batched governance cycles.
Lower risk profile. Narrow scopes, limited exposure, or governance review documented and on record.
Score composition
Scores are additive across seven dimensions. Maximum total is 100. Each dimension is capped.
Permission sensitivity
Data breadth
User exposure
AI / agent exposure
Vendor posture
Governance status
Compliance indicators
0–100
Additive score
Core risk dimensions
Each dimension is independently scored and documented. Any application's score can be traced factor by factor — suitable for audit evidence and governance review.
Dimension weights reflect the relative organisational impact of each factor in typical Australian enterprise environments. Weights are reviewed periodically. Custom threshold configurations are available for enterprise plans.
OAuth permission sensitivity
Permission sensitivity is the highest-weight dimension — carrying up to 30 points of the composite score. Scope categories are classified by the potential data impact of misuse or compromise.
| Category | Example scopes | Sensitivity | Notes |
|---|---|---|---|
| Directory / Admin | Admin SDK, Directory API, User account management | Critical | Rarely required by legitimate third-party SaaS tools. Grants broad read/write access to user accounts, groups, and domain settings. |
| Mail — write / send / delete | Gmail send, modify, delete; Exchange mail write | High | Permits sending email as users, modifying or deleting message content. Common in productivity and AI assistant tools. |
| Files — write / delete | Drive file write, SharePoint files write, OneDrive delete | High | Allows creating, modifying, or deleting documents and spreadsheets. Significant data destruction risk if abused. |
| Mail — read | Gmail readonly, Mail.Read, IMAP access | Medium–High | Passive read access to all email content. Frequently granted by AI writing assistants, calendar tools, and CRM integrations. |
| Files — read | Drive readonly, Files.Read, SharePoint read | Medium | Read access to documents and spreadsheets. Risk depends on the sensitivity of content held in the workspace. |
| Calendar | Calendar events read/write, Bookings access | Medium | Scheduling and meeting data. Contains attendee information and meeting context. Lower direct risk than mail or file access. |
| Contacts | People API read, Contacts.Read | Low–Medium | Access to organisational contact lists. Relevant for identifying data subject exposure under the Privacy Act 1988. |
| Profile / openid | Basic profile, email, openid, User.Read | Low | Identity and sign-in scopes only. Minimal data access beyond name, email address, and profile image. |
Persistent and offline access scopes
Applications granted offline_access or access_type=offline retain refresh tokens that allow continued API access without user re-authorisation. This persistence factor is applied as an additive modifier on top of the underlying scope sensitivity score, reflecting the extended window of potential exposure.
AI and agent exposure indicators
Applications with indicators of AI capability, autonomous operation, or non-human identity receive additional weighting. Detection is metadata-based and confidence-graded — not content inspection.
| Indicator type | Detection signal | Confidence | Weight |
|---|---|---|---|
| AI vendor pattern | Application name, client ID, or vendor domain matches a known AI/LLM vendor pattern. | High | +12 pts |
| Sensitive scope + AI vendor | AI vendor classification confirmed AND access to mail, files, or directory scopes. | High | +20 pts |
| Broad persistent access | Application holds multiple sensitive scopes without a specific single-user owner (service-level pattern). | Medium | +10 pts |
| MCP-connected indicator | Client metadata or vendor pattern matches known MCP-connected system characteristics. | Medium | +12 pts |
| Automation workflow pattern | Vendor classification as workflow automation platform (e.g. Zapier, Make) with multi-scope access. | Medium | +8 pts |
| Service principal (M365) | Application registered as a service principal or enterprise application in Entra ID. | High (M365) | +10 pts |
Agent identity detection is metadata-driven, not endpoint-based. ThreatLynx does not monitor employee behaviour, inspect message content, or log user activity. Detection signals are governance readiness indicators — review by application or security owners is recommended before any formal classification.
Governance influence on scores
Governance decisions affect the composite score. Taking documented action reduces ungoverned risk weighting. This creates a direct incentive for active governance — the score reflects your team's posture.
No governance decision has been recorded. Highest additive modifier. Default state for newly discovered applications.
Review has been initiated but no outcome has been documented. Review without decision still carries elevated weighting.
A restriction has been applied. Score reflects the underlying risk factors only — governance action is neutral, not rewarded above base.
Application has been reviewed and approved with documented rationale. Score is reduced to reflect active governance posture.
Block decision recorded. Application is flagged for remediation. Score is maintained for audit visibility — block does not clear risk.
Exception has been granted with documented rationale and review date. Partial reduction applied for documented decision with expiry.
Owner assignment
Applications without an assigned business owner carry a small additive penalty, reflecting unresolved accountability. Assigning an owner is treated as a governance maturity signal.
Review date and overdue status
Applications with an overdue scheduled review receive a stale-governance modifier. Review dates can be set per application — scheduled review discipline is reflected in the score.
Compliance framework influence
Risk score dimensions map to Australian and international governance frameworks. Scores can be used as structured evidence in governance review cycles — not as certification.
ASD Essential Eight — Application Control
Readiness visibility onlyUngoverned applications with elevated scopes contribute to unresolved findings relevant to Application Control maturity.
APRA CPS 234 — Third-party Risk
Governance evidence supportRisk scores and governance decisions provide structured evidence for third-party information security capability assessments and information asset registers.
Privacy Act 1988 — APP 11
Identification support onlyApplications with access to personal information (mail, contacts, directory) are surfaced and scored, supporting APP 11 reasonable-steps obligations.
ISO/IEC 27001:2022 — A.8 / A.9
Partial coverageApplication inventory and access-control records support Annex A controls for asset management and access review cycles.
Compliance framework references are informational. ThreatLynx does not provide legal advice, compliance certification, or guaranteed compliance outcomes. Risk scores are rules-based governance indicators, not regulatory determinations. Consult qualified legal, compliance, and security advisors for specific obligations.
Confidence and limitations
Understanding score limitations is essential for correct governance use. These constraints apply to all ThreatLynx deployments.
Scores are indicators, not verdicts
Risk scores are designed to prioritise governance review workflows. They are additive, rules-based assessments of available OAuth metadata — not comprehensive security assessments, audit opinions, or definitive risk determinations.
Score accuracy depends on metadata completeness
If vendor registration data, scope strings, or OAuth client metadata are incomplete or unavailable, the resulting score will reflect what was available at the time of sync, not the full risk profile.
Microsoft 365 scoring depends on Graph metadata
M365 scope depth, service principal detection, and permission data fidelity depend on the metadata returned by Microsoft Graph. Scores derived from M365 data reflect what was available at the time of sync.
AI and agent detection is confidence-based
AI tool and agent identity classification is based on metadata heuristics — not content inspection or API call monitoring. Some AI-powered tools may not be classified, and non-AI tools may occasionally match classification patterns.
Governance action requires human review
ThreatLynx does not automatically revoke, restrict, or block applications. Governance actions are recorded but must be executed by an administrator in the workspace admin console.
Scores reflect snapshot state
Scores are recalculated at each sync. Between syncs, a new high-risk OAuth grant may not yet be reflected. For time-sensitive environments, more frequent syncs are recommended.
Worked example scoring breakdown
An illustrative example showing how a composite score is assembled across scoring dimensions. All values are hypothetical and for reference only.
Hypothetical application
AI Writing Assistant Pro
AI productivity tool · Gmail + Drive access · 38 users · Vendor incorporated in USA · No governance decision on record
Mail — read scope
Active gmail.readonly scope — highest-weight single scope.
18 / 25 pts
Files — read scope
Drive readonly scope — significant data exposure category.
12 / 25 pts
Scope breadth (2 domains)
Access spans mail AND files — combined breadth multiplier.
10 / 20 pts
AI vendor classification
Vendor matched known AI productivity tool pattern.
12 / 15 pts
User exposure (38 users)
Broad departmental authorisation — above single-user baseline.
9 / 15 pts
Governance: Ungoverned
No review decision on record — full governance penalty applied.
15 / 15 pts
Vendor jurisdiction
Vendor incorporated outside Australia — data sovereignty factor.
4 / 5 pts
Composite risk score
Sum of all applicable factors
Recommended governance action
Assign a business owner and initiate a governance review. Document the approved use case and data access rationale. If mail and file access cannot be justified by business function, consider requesting a restricted scope version of the integration or moving to block. Documenting a governance decision will reduce the score by up to 25 points.
This example is illustrative only. Actual scores depend on the specific OAuth scopes, vendor metadata, user counts, and governance records for each application in your environment.
See risk scoring on your workspace data
Request a guided walkthrough to explore how ThreatLynx scores the applications connected to your Google Workspace or Microsoft 365 environment.