Skip to main content

Risk Scoring

Every agent in Behavry has a dynamic risk score that reflects its observed behavior. The score drives automatic policy tightening, escalation logic, and alerting thresholds.

Behavry Risk Framework

The score is a weighted composite across six dimensions, each normalized to 0–100:

DimensionWeightWhat it measures
Policy denial rate25%Fraction of tool calls blocked by policy
Anomaly frequency20%How often the agent triggers behavioral anomalies
Data volume15%Total data accessed relative to peer baseline
New resource access15%Rate of first-ever accesses to new paths/servers
Session behavior15%Session length and tool-call pattern vs baseline
Escalation outcomes10%Denied escalations as a fraction of total escalations

Risk tiers

TierScoreEscalation timeoutRecommended action
Low0–2524 hoursStandard operation
Medium26–504 hoursMonitor trends
High51–7530 minutesReview recent activity
Critical76–1005 minutesConsider suspension

How scores change

Scores are recomputed continuously. Positive signals (consistent allowed actions, low denial rate, no new anomalies) reduce the score over time. Negative signals raise it immediately.

The risk tier feeds back into OPA policy — a high-tier agent automatically faces stricter rules without any policy edit.

Behavioral Monitor
Alerts & Escalations