Radar
Radar is a unified feed of risks and warnings across your systems, scored and actionable, so you can fix or track every issue in one place. Open it from Security > Radar.
Radar is a beta feature. If you don't see it in the sidebar, enable Radar under Settings > Beta Features. To request access to beta features, contact Willow.

Security score
The top of the page shows an overall Security Score from 0 to 100 with a band label (for example, Critical). It summarizes how many action items are open and how severe they are, so the score rises as you resolve items.
Alongside it, the header shows:
- Action Items totals: Total, Open, Resolved, and Ignored.
- Last 7 Days activity: Tool Calls, Users, Success rate, and Avg/User.
Categories
The left panel groups action items into categories, each with its own score and a count of open items. Select a category to filter the action items list to it. Each category has its own reference page below:
| Category | Covers |
|---|---|
| Permissions & Access | Access policies, token management, and authorization. |
| Integrations & MCPs | MCP servers, tools, connectors, and third-party integrations. |
| Compliance & Logging | Audit logging, log sync, and regulatory compliance. |
| Identity & SSO | Authentication, SSO enforcement, and user identity controls. |
| AI Agents | Background agents, sub-agents, and autonomous AI governance. |
| Data Protection | Guards, guardrails, secrets, and content filtering. |
Work an action item
The Action Items list shows every open item, each with a severity icon, a title, and a category tag. Per item you can:
- Fix: open the guided fix flow for that item in Willow.
- Docs: open the documentation for that item (the per-category reference pages below).
- Use the clock menu to defer the item (snooze or ignore it).
Use Search items to filter the list, and toggle Show resolved to include items you have already resolved. Select Refresh at the top right to re-run the checks.
Action items reference
Each action item Radar can raise is documented on its category page. Every item describes the problem, why it is a risk, a concrete example of what can go wrong, and the step-by-step fix in Willow.
Identity & SSO
Radar action items for authentication, SSO enforcement, and user identity controls.
Permissions & Access
Radar action items for access policies, token management, and authorization.
Integrations & MCPs
Radar action items for MCP servers, tools, connectors, and third-party integrations.
Compliance & Logging
Radar action items for audit logging, log sync, and regulatory compliance.
AI Agents
Radar action items for background agents, sub-agents, and autonomous AI governance.
Data Protection
Radar action items for guards, guardrails, secrets, and content filtering.
Event-generated items
Some radar items are produced by runtime signals or integrations rather than the static checks above. Each one carries its own context and is not part of the per-category catalog.
- The signal indicates something concrete happened (for example, a guard breach, an unusual sign-in, or a failed rotation).
- The item stays open until somebody acknowledges and addresses it.
To work one:
- Read the item's title, description, and detail carefully.
- Select the Fix action if one is provided, it points to the relevant page in Willow.
- Add notes describing what you did and assign follow-up to the right owner.
- Resolve the item only after the underlying signal has been addressed, so it does not auto-reopen on the next evaluation.