Monosign · Security Score

Identity risk you can read,
tune, and act on.

Every user, app, and entitlement carries an explainable risk score — built from posture and behavior, enforced at sign-in and in governance. No black boxes: every number decomposes into the factors and events behind it.

  • Explainable, configurable scoring
  • Posture + behavior in one engine
  • A–F Identity Security Grade
What you get

One risk model, from sign-in to certification.

Auth-time risk engines and governance risk engines are usually separate products. Monosign is both the IdP and the IGA — so one score drives both decisions.

Score anything, explain everything

Users, apps, roles, groups, entitlements — every object carries a configurable score that rolls up into composite risk. And every score decomposes into the factors that produced it.

  • Configurable 0–1000 base score + multiplier per object type
  • Composite risk per user, application, and entitlement
  • Factor-contribution breakdown, drill-down to events
  • Base-score suggestions from real access power (blast radius)

Posture and behavior, one engine

The industry splits identity risk into two products — posture (ISPM) and behavior (UEBA). Monosign scores both in the same model.

  • Posture factors: MFA gaps, dormant accounts, password age, orphans
  • Behavioral catalog: impossible travel, new device, brute force, off-hours
  • Cold-start caution for accounts without a baseline
  • User-reported "this wasn’t me" feeds the model

Risk that acts at sign-in

Scores are policy conditions, not dashboard decoration. Risk adds friction where it belongs — and never removes an auth factor, in line with NIST SP 800-63-4.

  • Step-up MFA, block, shorten session, or terminate all sessions
  • Route risky requests to approval workflows
  • Self-remediation: completing MFA clears active risk
  • Admin dispositions with reasons, exceptions, and audit

Risk that governs access

The same scores drive governance: outliers get flagged, stale access gets surfaced, low-risk reviews approve themselves, and leadership gets a grade.

  • Peer-group outlier detection against least-privilege drift
  • Access dormancy: unused entitlements flagged on a clock
  • Risk-based auto-certify keeps humans on the risky rows
  • Identity Security Grade: an A–F report card for the board
How it works

From default scores to a board-level grade.

01

Tune the model

Set base scores and multipliers per object type — or accept suggested scores computed from real access power.

02

Wire the policy

Use risk level as a condition: step-up MFA, block, reauthenticate, or route to approval — per app, per tier.

03

Watch the grade

Dashboards track risky users, remediation times, and trends; the A–F grade lands on the board agenda as a PDF.

Ready to start managing
identities the right way?

Spin up a fully-loaded trial tenant in under five minutes. No credit card. No sales gate.