Skip to main content

Key Risk Indicators (KRIs)

KRIs are metrics that quantify your privileged access risk posture. Each KRI measures a specific aspect of risk and uses RAG (Red/Amber/Green) thresholds to indicate severity.

KRI Overview

Navigate to KRIs to see all current indicator values.

KRI Trends

Each KRI card shows:

ElementDescription
NameWhat is being measured
Current ValueLatest count or percentage
RAG StatusGreen (within tolerance), Amber (warning), or Red (critical)
ChangeIncrease or decrease since the last snapshot

Built-in KRIs

KRIDescriptionCommunity
Privileged Without OwnerPrivileged accounts not linked to an identityYes
Unlinked AccountsAll accounts (privileged or not) without an identityYes
Not in PAM ToolPrivileged accounts not found in your PAM tool inventoryYes
Standing PrivilegesAlways-on privileged access (not just-in-time)Yes
Shared Privileged AccountsAccounts used by more than one personPro+
All Privileged AccountsTotal count of privileged accountsPro+
System CoveragePercentage of systems successfully scanned recentlyPro+
Entitlement DistributionConcentration of high-privilege entitlementsPro+

KRI Definitions

Navigate to KRIs and view the definitions to see or edit the configuration for each KRI.

Each definition has:

FieldDescription
CodeUnique identifier (e.g., PRIVILEGED_WITHOUT_OWNER)
NameDisplay name
DescriptionWhat the KRI measures and why it matters
Green ThresholdValues at or below this are healthy
Amber ThresholdValues between Green and Red are a warning
Red ThresholdValues at or above this are critical
EnabledWhether the KRI is active
note

Thresholds are inclusive. For example, if Green = 5, Amber = 15, and Red = 16, then a value of 5 is Green, 15 is Amber, and 16 is Red.

Editing Thresholds

  1. Click on a KRI definition
  2. Adjust the Green, Amber, and Red threshold values
  3. Click Save

Threshold changes take effect immediately on the dashboard and KRI pages.

KRI Snapshots

Requires Pro or Enterprise edition.

Snapshots capture a point-in-time record of all KRI values. They are used to build trend charts and track progress over time.

Automatic Snapshots

A snapshot is taken automatically each time a scan completes.

Manual Snapshots

  1. Navigate to KRIs > Snapshots
  2. Click Take Snapshot

Viewing Snapshots

The snapshots page shows a table of all historical snapshots with their timestamp and KRI values. Click a snapshot to see its full breakdown.

Requires Pro or Enterprise edition.

Navigate to KRIs > Trends to view KRI values over time as a chart.

  • Select one or more KRIs to display
  • Choose a time range
  • The chart background uses RAG colouring to show threshold bands

This makes it easy to spot whether your risk posture is improving or deteriorating.

KRI Exceptions

Requires Enterprise edition.

Exceptions allow you to formally acknowledge and exclude specific accounts from KRI calculations. This is useful for accounts that have been reviewed and accepted as a known risk.

Creating an Exception

  1. Navigate to KRIs > Exceptions
  2. Click Add Exception
  3. Fill in:
FieldRequiredDescription
KRIYesWhich KRI this exception applies to
AccountYesThe account being excepted
ReasonYesJustification for the exception
ApproverYesWho approved this exception
Expiry DateNoWhen the exception expires (must be re-approved after this date)
  1. Click Save

Managing Exceptions

  • Expired exceptions are highlighted in amber and should be reviewed and either renewed or removed
  • Delete an exception to bring the account back into KRI calculations
  • All exception changes are recorded in the audit log