Skip to main content

UX Details: Overview page (Authority Prioritization)

Document date: 2026-02-27

This page maps to Step 1: Authority Prioritization (The “I Didn’t Know This Was Running” Layer)

Task

Modify to:

  • Functional cluster name (not attribute-based)
CurrentCluster Title
Orphaned + SensitiveUnowned Sensitive Access
Orphaned + Sensitive + LLMUnowned Sensitive Access with LLM
Unbound + SensitiveUnbound Sensitive Access
LLM EgressLLM Data Egress
Orphaned + External EgressUnowned External Egress
Dormant + ExternalDormant External Access
  • 5-second verdict sentence (execution-determined). The verdict summarizes observed activity, not telemetry details. Format:

<N> autonomous identities accessed <scope> <X> times in the last 30 days.

If a governance failure exists, append a short clause: — <governance condition>.

Examples:

Unowned Sensitive Access

13 autonomous identities accessed sensitive systems 681 times in the last 30 days — none have an assigned owner.

Unowned Sensitive Access with LLM

6 autonomous identities sent sensitive data to an LLM 142 times in the last 30 days — none have an assigned owner.

Unbound Sensitive Access

9 autonomous identities accessed sensitive systems 214 times in the last 30 days without a bound automation.

LLM Data Egress

4 autonomous identities sent data to LLM endpoints 87 times in the last 30 days.

Unowned External Egress

5 autonomous identities sent data outside the organization 63 times in the last 30 days — none have an assigned owner.

Dormant External Access

3 autonomous identities retain external access but have not executed in the last 30 days.

  • Risk badge (clear, deterministic)

Critical

Sensitive domain + active execution + governance failure

High

Sensitive domain + active execution

Moderate

Governance failure but limited or no execution

Low

Dormant authority

  • Keep paths + execution count

Remove:

  • Attribute-style framing as primary label
  • Anything that feels like a filter category instead of a threat definition

This page becomes: “Which autonomous authority is actively unstable?”