Identity risk you can read,
tune, and act on.
Every user, app, and entitlement carries an explainable risk score — built from posture and behavior, enforced at sign-in and in governance. No black boxes: every number decomposes into the factors and events behind it.
- Explainable, configurable scoring
- Posture + behavior in one engine
- A–F Identity Security Grade
One risk model, from sign-in to certification.
Auth-time risk engines and governance risk engines are usually separate products. Monosign is both the IdP and the IGA — so one score drives both decisions.
Score anything, explain everything
Users, apps, roles, groups, entitlements — every object carries a configurable score that rolls up into composite risk. And every score decomposes into the factors that produced it.
- Configurable 0–1000 base score + multiplier per object type
- Composite risk per user, application, and entitlement
- Factor-contribution breakdown, drill-down to events
- Base-score suggestions from real access power (blast radius)
Posture and behavior, one engine
The industry splits identity risk into two products — posture (ISPM) and behavior (UEBA). Monosign scores both in the same model.
- Posture factors: MFA gaps, dormant accounts, password age, orphans
- Behavioral catalog: impossible travel, new device, brute force, off-hours
- Cold-start caution for accounts without a baseline
- User-reported "this wasn’t me" feeds the model
Risk that acts at sign-in
Scores are policy conditions, not dashboard decoration. Risk adds friction where it belongs — and never removes an auth factor, in line with NIST SP 800-63-4.
- Step-up MFA, block, shorten session, or terminate all sessions
- Route risky requests to approval workflows
- Self-remediation: completing MFA clears active risk
- Admin dispositions with reasons, exceptions, and audit
Risk that governs access
The same scores drive governance: outliers get flagged, stale access gets surfaced, low-risk reviews approve themselves, and leadership gets a grade.
- Peer-group outlier detection against least-privilege drift
- Access dormancy: unused entitlements flagged on a clock
- Risk-based auto-certify keeps humans on the risky rows
- Identity Security Grade: an A–F report card for the board
From default scores to a board-level grade.
Tune the model
Set base scores and multipliers per object type — or accept suggested scores computed from real access power.
Wire the policy
Use risk level as a condition: step-up MFA, block, reauthenticate, or route to approval — per app, per tier.
Watch the grade
Dashboards track risky users, remediation times, and trends; the A–F grade lands on the board agenda as a PDF.
Related Monofor capabilities.
Kimlikleri doğru şekilde
yönetmeye hazır mısınız?
Beş dakikadan kısa sürede tam donanımlı bir deneme ortamı kurun. Kredi kartı yok, satış engeli yok.