A score you can argue with
Risk scoring is only useful if the person reading it can explain it to someone else. Every OAuthRadar score decomposes into named factors with published weights.
01 · DISCOVER
What lands in the inventory
Everything holding a third-party token, not only the accounts a directory export would show.
People
Every account in the directory, including those who left and whose grants outlived them.
Shared mailboxes
The addresses nobody owns and everybody uses. Historically the least reviewed and the most connected.
Service accounts
Non-human identities, which outnumber people in most estates by an order of magnitude.
02 · SCORE
The five factors
Weights are fixed and published. A score never moves because we changed our mind quietly.
Scope severity
What the grant can reach. Full mailbox read scores higher than calendar free-busy.
Data exposure
How much of the estate the subject can see. An admin account carries more than a contractor.
Vendor posture
Whether the vendor publishes a security page, holds certifications, and has a disclosed breach history.
Usage recency
A grant unused for 90 days is a standing risk with no operational benefit.
Subject privilege
Whether the account holding the grant is an administrator, a shared mailbox, or a service account.
02 · BANDS
What the score resolves to
The band is what an operator reads first. Colour is never the only encoding, so every band carries a glyph and a word alongside it.
Narrow scopes, recent use, known vendor. Reviewed quarterly.
Broad read access or an unfamiliar vendor. Worth a look this month.
Write access, or read access to a privileged mailbox. Alerts by default.
Admin-equivalent reach. Alerts immediately and sorts to the top of the list.
A score is worth what you do with it
Everything above is measurement. The next two stages are what change your exposure.
03 · ALERT
Told once, on the channel you already watch
A rule is a band threshold, a channel and a destination. Nothing more to configure.
One notice per grant
A grant that crosses a threshold alerts once. Re-scoring inside the same band stays silent, because an alerting tool that repeats itself gets muted.
Signed webhooks
HMAC-SHA256 over the raw body, secret shown once at creation, delivery log with a manual retry.
Allowlist what you accept
A grant you have reviewed and kept stops alerting, with your name and the date on the decision.
04 · REVOKE
The one thing we write
Revocation is irreversible for the user whose grant it was, so it is the only action that asks twice.
Killed at the provider
The token is deleted at Google Workspace. otter.ai loses access immediately and any automation using it stops. This cannot be undone. The app must be authorised again by a user to return.
Confirmed by name
The dialog states the application, the subject and what stops working. You type nothing, but you confirm the object.
On the record
Who, what, when, and the provider acknowledgement, in an audit log you can export.
See these bands on your own tenant
Connect one provider read-only and the first scan returns a scored inventory in about two minutes.