Risk scoring
Explainable risk scoring for AI agents
A score is useful when people can see what moved it. Roxea turns declared permissions and control gaps into findings that remain readable for technical and business teams.
The problem: a risk label without reasons changes nothing
Calling an agent “high risk” is not enough. The owner needs to know whether the issue is broad inbox access, payment capability, missing approval or weak logging.
Roxea keeps the raw inputs and findings visible so teams can challenge an assumption and choose a specific response.
How risk scoring works in Roxea
The assessment uses the agent’s declared tools, permissions, autonomy and safeguards. It produces a current score, a level and a list of findings with practical recommendations.
- Review sensitive read and write permissions.
- Identify external, financial and destructive actions.
- Account for human approval and operational controls.
- Keep the raw score unchanged when a risk is accepted.
- Use score history on Pro and Business to review change over time.
Example: the same tool, different risk
Two agents use GitHub. One reads public issues to draft a summary. The other can modify private repositories and merge pull requests without approval. The tool name is the same; the access and controls produce a different finding.
FAQ
Questions people ask before a review
See the reasons behind an agent’s risk level.
Record its real access and turn each finding into a decision or action.