Radar
Radar scores your AI security posture across five categories. Each category contains several KPIs (key performance indicators). Willow compares each KPI against two values. The first is your target, the value you want to reach. The second is the typical value, which is what an organization like yours usually shows before it starts an AI-security program.
To open Radar, go to Security > Radar.
Posture by category
The overview opens on a five-axis chart. The solid shape shows your current scores. The dashed ring shows your targets. The ring at the top right shows your overall score, together with a rating word such as Weak.
To open a category, select its axis on the chart or its card in the Categories list on the right.

The first time Radar runs, and after every Refresh, it calculates every score again. While it does, three things happen. The chart shows the message Measuring every KPI against your own inventory before anything is scored. The score ring counts up through N of 38. Each category card shows a count such as 0/7 KPIs and a Queued label until Radar reaches that category.
Wait for the count to finish before you read any score.
Each card shows the category score and how many of its KPIs are off target, for example 3 of 7 KPIs off target · 2 unmeasured. The of 7 counts only the KPIs Willow could measure. Unmeasured KPIs are listed separately and are not included in that total.
Below the chart, Start here lists the specific items that caused the lowest-scoring KPIs. Use it to begin work without reading all five category pages.
How the score works
Select the info icon next to Overall for the summary in the product. Radar calculates scores at three levels:
| Level | Calculation |
|---|---|
| KPI | Willow gives each KPI a score from 0 to 100, based on how far the current value has moved from the typical value toward the target. A current value equal to the target scores 100. A current value equal to the typical value scores 0. |
| Category | The weighted average of its measured KPIs. |
| Overall | The plain average of the five category scores. All five count the same, so no one category can decide the overall score on its own. |
Willow excludes KPIs it cannot measure. It does not count them as passing. A KPI is unmeasured when Willow does not yet have the data it needs. This usually happens because the scan agent or the browser extension has not sent any data yet. Unmeasured rows show – for the current value and n/a for the score.
Targets are not always zero. Four KPIs have a different target:
- Share of AI tool calls flowing through the gateway targets 90%.
- Prompt-injection detection coverage targets 100%.
- Audit log retention targets 180 days.
- Tool calls blocked by a guard targets 1%. An organization that blocks nothing at all usually has no guards configured, rather than no threats to block.
Read a KPI row
Every category page is a table of KPI rows with four columns:
| Column | Meaning |
|---|---|
| Current | What Willow measures today. |
| Target | The value you are aiming for. |
| Typical | The value an organization like yours usually shows before it starts an AI-security program. Willow writes this value with a ~ because it is a general reference point, not a measurement of your own organization. |
| Score | The KPI's 0–100 score. |
Under the KPI name, the row shows three things: a one-line description, an example list of the items Willow counted (with +N more if the list is longer), and the compliance frameworks the KPI maps to.

Two qualifiers can appear beside a KPI name:
approximate— the number is an estimate rather than an exact count.Partial coverage— Willow measures this KPI from device scans, so it covers only the devices that report to the scan agent. Fix Employees with no scanned device in Shadow AI first. Until you do, this KPI covers only part of your organization.
Work a KPI
Select a row to open its detail panel:
- Current / Target / Typical, with a Progress from typical to target bar showing the KPI's score out of 100.
- Why it matters — the security risk this KPI measures.
- How to improve it — numbered steps to follow. Below the steps are a button that opens the Willow page where you make the change, and a Docs link to the reference page for that change.
- Framework mapping — the specific controls the KPI maps to, for example
OWASP NHI NHI5 Overprivileged NHIorNIST CSF PR.AA-05. You can also use each mapping as audit evidence for an ISO 42001 or EU AI Act audit. - What is counted — the full list of items Willow counted for this KPI. Select Full screen when the list is long.

Select Refresh at the top right of the overview or of any category page to re-run the checks.
Compliance frameworks
KPIs map to controls in the following frameworks. The tags on each row link out to the source.
| Framework | Used for |
|---|---|
| NIST CSF | Access control, detection, and response. |
| NIST AI RMF | AI inventory, governance, and measurement. |
| NIST GenAI Profile | Generative-AI data privacy. |
| OWASP LLM | The LLM Top 10 — prompt injection, sensitive information disclosure, excessive agency, supply chain. |
| OWASP NHI | Non-human identity risks — overprivileged credentials, secret leakage, long-lived secrets. |
| OWASP AST10 | Agent skill risks — malicious skills, over-privileged skills, update drift, untrusted external instructions. |
| MITRE ATLAS | Adversarial techniques against AI systems. |
| MCP Spec | Risks named in the Model Context Protocol (MCP) specification: tool poisoning, where a tool description manipulates the agent, and the confused deputy problem, where an attacker uses a trusted component's permissions to act on its behalf. |
| EU AI Act | Human oversight, deployer obligations, log keeping, serious incident reporting. |
| ISO 42001 | AI management system controls. |
| ISO 27001 | Information security controls. |
| SANS | Access control, monitoring, and inference security guidance. |
| Gartner TRiSM | AI trust, risk, and security management layers. |
A Practitioner tag marks a KPI based on accepted industry practice rather than on a control published in a named framework.
Categories
| Category | Covers |
|---|---|
| Identity & Access | How AI tools and agents authenticate, who owns them, and whether their credentials are short-lived and scoped. |
| Shadow AI | AI tools, MCP servers, and accounts used without approval, and how much of your AI traffic Willow can see. |
| Data Exposure | Secrets, personal data, and source code reaching AI tools, and whether anything inspects prompts and responses. |
| Agents & MCP | What autonomous agents are allowed to do, how much of that permission they actually use, and who must approve the actions that can cause damage. |
| Monitoring & Incidents | Whether your AI activity reaches your SIEM (security information and event management system), how long you keep the logs, and how quickly your team reviews alerts. |
Identity & Access
Radar KPIs for how AI tools and agents authenticate, who owns them, and whether their credentials are short-lived and scoped.
Shadow AI
Radar KPIs for AI tools, MCP servers, skills, and accounts in use without approval, and how much of that traffic you can see.
Data Exposure
Radar KPIs for secrets, personal data, and source code reaching AI tools, and whether anything inspects prompts and responses.
Agents & MCP
Radar KPIs for what autonomous agents are allowed to do, how much of that permission they use, and who approves the dangerous parts.
Monitoring & Incidents
Radar KPIs for whether AI activity reaches your SIEM, how long you keep the logs, and how quickly your team reviews alerts.