Every identity in VeraID carries a dynamic risk score ranging from 0 to 100. This score is continuously recalculated based on behavioral signals, credential hygiene, access patterns, and policy compliance. Risk scores drive automated responses such as step-up verification, access restrictions, suspension, and alerting.
How Risk Scoring Works
VeraID evaluates each identity against a set of weighted risk factors. When a factor’s conditions are met, its weight is added to the identity’s score. The final score is capped at 100 and rounded to the nearest integer.
Risk scores are recalculated:
After every authenticated action
On a scheduled basis (every 15 minutes for active identities)
When credential, policy, or ownership changes occur
When anomaly detection triggers fire
Risk Levels
Scores map to four risk levels that determine the severity of automated responses and dashboard indicators.
The following nine factors apply to all identity types. Each factor has a weight (the number of points added to the score) and a trigger condition.
Failed Authentication Attempts
Weight
+25
Trigger
10 or more failed authentication attempts within a 30-day window
Rationale
Repeated failures may indicate a credential stuffing attack, brute-force attempt, or misconfigured client
Policy Violations
Weight
+25
Trigger
10 or more denied policy evaluations within 7 days
Rationale
Frequent policy denials suggest the identity is attempting unauthorized actions or has drifted from its intended scope
Geographic Anomaly
Weight
+20
Trigger
Authentication from an IP address in a geographic region not previously associated with this identity
Rationale
Unexpected geographic shifts may indicate credential theft or proxy-based access from an unauthorized location
Dormant Reactivation
Weight
+20
Trigger
Identity inactive for 30 or more days, followed by 10 or more actions within 24 hours
Rationale
A sudden burst of activity from a long-dormant identity is a strong indicator of compromise
Unusual Request Rate
Weight
+20
Trigger
Request rate exceeds 3x the identity’s rolling 30-day average
Rationale
Traffic spikes well above baseline may indicate automated abuse, data exfiltration, or a compromised credential
Credential Not Rotated
Weight
+15
Trigger
Any associated credential has not been rotated in 90 or more days
Rationale
Long-lived credentials increase the window of exposure if compromised; regular rotation is an industry best practice
Unusual Access Hours
Weight
+15
Trigger
50% or more of requests occur during off-hours (10:00 PM – 6:00 AM in the identity’s configured timezone)
Rationale
While some automation legitimately runs overnight, a shift toward off-hours access can indicate unauthorized use
Expiring Credential
Weight
+10
Trigger
Any associated credential expires within 7 days
Rationale
Impending expiration increases operational risk; teams should be alerted to rotate before an outage occurs
Excessive Permissions
Weight
+10
Trigger
Identity has more policy bindings than the 90th percentile for its type
Rationale
Over-permissioned identities expand the blast radius if compromised; least-privilege principles should be enforced
AI Agent-Specific Risk Factors
Identities of type AI_AGENT are evaluated against five additional risk factors that address the unique threat surface of autonomous AI systems.
Prompt Injection Detected
Weight
+30
Trigger
VeraID’s prompt injection detection system identifies a potential injection attempt in the agent’s input or output
Rationale
Prompt injection is a critical threat to AI agents; a detected attempt may indicate an active attack on the agent’s decision-making process
Capability Abuse
Weight
+25
Trigger
5 or more denied capability requests (MCP tool calls, API actions outside allowed scope)
Rationale
Repeated attempts to use unauthorized capabilities suggest the agent has been manipulated or is behaving outside its intended parameters
Budget Exceeded
Weight
+20
Trigger
Agent has consumed more than 80% of its configured budget for the current period
Rationale
Runaway spending may indicate an infinite loop, prompt injection causing excessive API calls, or unauthorized task escalation
Unusual Model Usage
Weight
+15
Trigger
Agent has used 3 or more different AI models within a single evaluation period
Rationale
Unexpected model switching may indicate an attacker probing for vulnerabilities across model providers or attempting to bypass model-specific safety controls
High Cost Rate
Weight
+15
Trigger
Current daily spending rate exceeds 2x the identity’s rolling daily average
Rationale
A sudden increase in cost rate — independent of total budget consumption — signals anomalous behavior that warrants investigation
Risk Factor Summary
The table below provides a complete reference of all risk factors sorted by weight.
Factor
Weight
Category
Trigger Summary
Prompt Injection Detected
+30
AI Agent
Injection attempt detected
Failed Authentication
+25
Standard
10+ failures in 30 days
Policy Violations
+25
Standard
10+ denied evaluations in 7 days
Capability Abuse
+25
AI Agent
5+ denied capability requests
Geographic Anomaly
+20
Standard
Request from new geographic region
Dormant Reactivation
+20
Standard
30+ days inactive, then 10+ actions in 24h
Unusual Request Rate
+20
Standard
3x above 30-day average
Budget Exceeded
+20
AI Agent
>80% of budget consumed
Credential Not Rotated
+15
Standard
90+ days without rotation
Unusual Access Hours
+15
Standard
50%+ requests during 10 PM – 6 AM
Unusual Model Usage
+15
AI Agent
3+ models used in one period
High Cost Rate
+15
AI Agent
2x above daily spending average
Expiring Credential
+10
Standard
Credential expires within 7 days
Excessive Permissions
+10
Standard
Permissions above 90th percentile
Viewing Risk Scores
Dashboard
The VeraID dashboard displays risk scores with color-coded indicators on the identity list view, identity detail page, and the risk analytics overview. Identities in the High or Critical range are surfaced in the priority queue on the dashboard home page.
API
Retrieve an identity’s current risk score as part of the identity object: