Monosign · Security Score

Identity risk you can read,
tune, and act on.

Every user, app, and entitlement carries an explainable risk score, built from posture and behavior, enforced at sign-in and in governance. No black boxes: every number decomposes into the factors and events behind it.

  • Explainable, configurable scoring
  • Posture + behavior in one engine
  • A-F Identity Security Grade
What you get

One risk model, from sign-in to certification.

Auth-time risk engines and governance risk engines are usually separate products. Monosign is both the IdP and the IGA, so one score drives both decisions.

Score anything, explain everything

Users, apps, roles, groups, entitlements: every object carries a configurable score that rolls up into composite risk. And every score decomposes into the factors that produced it.

  • Configurable 0-1000 base score + multiplier per object type
  • Composite risk per user, application, and entitlement
  • Factor-contribution breakdown, drill-down to events
  • Base-score suggestions from real access power (blast radius)

Posture and behavior, one engine

The industry splits identity risk into two products: posture (ISPM) and behavior (UEBA). Monosign scores both in the same model.

  • Posture factors: MFA gaps, dormant accounts, password age, orphans
  • Behavioral catalog: impossible travel, new device, brute force, off-hours
  • Cold-start caution for accounts without a baseline
  • User-reported "this wasn’t me" feeds the model

Risk that acts at sign-in

Scores are policy conditions, not dashboard decoration. Risk adds friction where it belongs, and never removes an auth factor, in line with NIST SP 800-63-4.

  • Step-up MFA, block, shorten session, or terminate all sessions
  • Route risky requests to approval workflows
  • Self-remediation: completing MFA clears active risk
  • Admin dispositions with reasons, exceptions, and audit

Risk that governs access

The same scores drive governance: outliers get flagged, stale access gets surfaced, low-risk reviews approve themselves, and leadership gets a grade.

  • Peer-group outlier detection against least-privilege drift
  • Access dormancy: unused entitlements flagged on a clock
  • Risk-based auto-certify keeps humans on the risky rows
  • Identity Security Grade: an A-F report card for the board
How it works

From default scores to a board-level grade.

01

Tune the model

Set base scores and multipliers per object type, or accept suggested scores computed from real access power.

02

Wire the policy

Use risk level as a condition: step-up MFA, block, reauthenticate, or route to approval, per app, per tier.

03

Watch the grade

Dashboards track risky users, remediation times, and trends; the A-F grade lands on the board agenda as a PDF.

Kimlikleri doğru şekilde
yönetmeye hazır mısınız?

Beş dakikadan kısa sürede tam donanımlı bir deneme ortamı kurun. Kredi kartı yok, satış engeli yok.