Skip to main content

Operational Exposure

Operational Exposure is the risk rollup — "autonomy danger · governance weakness · blast radius", scored by the Behavry Risk Framework. It answers "where is my biggest exposure right now, and what do I do about it?" Open it from the Governance group in the sidebar (labeled Operational Exposure).

Operational Exposure Operational Exposure — agent risk tiers, AI browser-service risk, and the highest-risk services and users.

Agent risk tiers

The top row buckets every agent by risk — Low / Medium / High / Critical. This is the fleet's exposure at a glance: a growing High or Critical count is where to look first. Expand How risk scores are calculated to see the dimensions that feed a score (autonomy, access, blast radius, drift, and more) — the model is explainable, not a black box. See Risk Scoring for the full framework.

Simulate risk reduction lets you model the effect of a change (tightening a policy, quarantining an agent) before you make it.

AI browser-service exposure

Below the agent tiers, Operational Exposure surfaces the AI browser services in use across the org — the human side of AI risk that the browser extension sees:

  • Headline counts: Browser AI Users, DLP Hits, DLP Blocks, and the Highest-Risk service.
  • The AI Services table ranks each service (ChatGPT, Gemini, Microsoft Copilot, Claude.ai, Perplexity, GitHub Copilot…) by events, users, DLP hits, blocked inputs, and a risk score out of 5.0.
  • Active Users lists the people driving that usage and which services they touch.

This is where "who is pasting sensitive data into which AI tool" becomes concrete and rankable.

A triage routine

  1. Start with the risk tiers — any High/Critical agent is a lead.
  2. Open the agent (via Agents) and read its risk dimensions to see why it scored high.
  3. For browser exposure, sort the AI Services table by risk or blocks, and check the Active Users behind the highest-risk service.
  4. Act — tighten a policy, enroll an ungoverned service (see AI Exposure), or quarantine the agent. Use Simulate risk reduction first to check the impact.
Exposure is relative to blast radius

A high activity agent isn't necessarily high risk. The framework weights blast radius — a quiet agent with broad reach and privileged access outranks a busy one that can only read. Chase the score, not the volume.