Skip to main content

Radar

Radar scores your AI security posture across five categories. Each category contains several KPIs (key performance indicators). Willow compares each KPI against two values. The first is your target, the value you want to reach. The second is the typical value, which is what an organization like yours usually shows before it starts an AI-security program.

To open Radar, go to Security > Radar.

Posture by category

The overview opens on a five-axis chart. The solid shape shows your current scores. The dashed ring shows your targets. The ring at the top right shows your overall score, together with a rating word such as Weak.

To open a category, select its axis on the chart or its card in the Categories list on the right.

The Radar overview: a five-axis posture chart with a dashed target ring, an overall score ring reading 45 and the band Weak, and a Categories list showing Identity & Access, Shadow AI, Data Exposure, Agents & MCP, and Monitoring & Incidents with their scores and off-target counts

The first time Radar runs, and after every Refresh, it calculates every score again. While it does, three things happen. The chart shows the message Measuring every KPI against your own inventory before anything is scored. The score ring counts up through N of 38. Each category card shows a count such as 0/7 KPIs and a Queued label until Radar reaches that category.

Wait for the count to finish before you read any score.

Each card shows the category score and how many of its KPIs are off target, for example 3 of 7 KPIs off target · 2 unmeasured. The of 7 counts only the KPIs Willow could measure. Unmeasured KPIs are listed separately and are not included in that total.

Below the chart, Start here lists the specific items that caused the lowest-scoring KPIs. Use it to begin work without reading all five category pages.

How the score works

Select the info icon next to Overall for the summary in the product. Radar calculates scores at three levels:

LevelCalculation
KPIWillow gives each KPI a score from 0 to 100, based on how far the current value has moved from the typical value toward the target. A current value equal to the target scores 100. A current value equal to the typical value scores 0.
CategoryThe weighted average of its measured KPIs.
OverallThe plain average of the five category scores. All five count the same, so no one category can decide the overall score on its own.

Willow excludes KPIs it cannot measure. It does not count them as passing. A KPI is unmeasured when Willow does not yet have the data it needs. This usually happens because the scan agent or the browser extension has not sent any data yet. Unmeasured rows show for the current value and n/a for the score.

Targets are not always zero. Four KPIs have a different target:

  • Share of AI tool calls flowing through the gateway targets 90%.
  • Prompt-injection detection coverage targets 100%.
  • Audit log retention targets 180 days.
  • Tool calls blocked by a guard targets 1%. An organization that blocks nothing at all usually has no guards configured, rather than no threats to block.

Read a KPI row

Every category page is a table of KPI rows with four columns:

ColumnMeaning
CurrentWhat Willow measures today.
TargetThe value you are aiming for.
TypicalThe value an organization like yours usually shows before it starts an AI-security program. Willow writes this value with a ~ because it is a general reference point, not a measurement of your own organization.
ScoreThe KPI's 0–100 score.

Under the KPI name, the row shows three things: a one-line description, an example list of the items Willow counted (with +N more if the list is longer), and the compliance frameworks the KPI maps to.

The Identity & Access category page: a header with the category score, counts of KPIs off target, on target, and unmeasured, above a KPI table with Current, Target, Typical, and Score columns

Two qualifiers can appear beside a KPI name:

  • approximate — the number is an estimate rather than an exact count.
  • Partial coverage — Willow measures this KPI from device scans, so it covers only the devices that report to the scan agent. Fix Employees with no scanned device in Shadow AI first. Until you do, this KPI covers only part of your organization.

Work a KPI

Select a row to open its detail panel:

  1. Current / Target / Typical, with a Progress from typical to target bar showing the KPI's score out of 100.
  2. Why it matters — the security risk this KPI measures.
  3. How to improve it — numbered steps to follow. Below the steps are a button that opens the Willow page where you make the change, and a Docs link to the reference page for that change.
  4. Framework mapping — the specific controls the KPI maps to, for example OWASP NHI NHI5 Overprivileged NHI or NIST CSF PR.AA-05. You can also use each mapping as audit evidence for an ISO 42001 or EU AI Act audit.
  5. What is counted — the full list of items Willow counted for this KPI. Select Full screen when the list is long.
A Radar KPI detail panel showing Current, Target, and Typical values, a Progress from typical to target bar, Why it matters, numbered How to improve it steps with an action button and Docs link, Framework mapping tags, and the What is counted list

Select Refresh at the top right of the overview or of any category page to re-run the checks.

Compliance frameworks

KPIs map to controls in the following frameworks. The tags on each row link out to the source.

FrameworkUsed for
NIST CSFAccess control, detection, and response.
NIST AI RMFAI inventory, governance, and measurement.
NIST GenAI ProfileGenerative-AI data privacy.
OWASP LLMThe LLM Top 10 — prompt injection, sensitive information disclosure, excessive agency, supply chain.
OWASP NHINon-human identity risks — overprivileged credentials, secret leakage, long-lived secrets.
OWASP AST10Agent skill risks — malicious skills, over-privileged skills, update drift, untrusted external instructions.
MITRE ATLASAdversarial techniques against AI systems.
MCP SpecRisks named in the Model Context Protocol (MCP) specification: tool poisoning, where a tool description manipulates the agent, and the confused deputy problem, where an attacker uses a trusted component's permissions to act on its behalf.
EU AI ActHuman oversight, deployer obligations, log keeping, serious incident reporting.
ISO 42001AI management system controls.
ISO 27001Information security controls.
SANSAccess control, monitoring, and inference security guidance.
Gartner TRiSMAI trust, risk, and security management layers.

A Practitioner tag marks a KPI based on accepted industry practice rather than on a control published in a named framework.

Categories

CategoryCovers
Identity & AccessHow AI tools and agents authenticate, who owns them, and whether their credentials are short-lived and scoped.
Shadow AIAI tools, MCP servers, and accounts used without approval, and how much of your AI traffic Willow can see.
Data ExposureSecrets, personal data, and source code reaching AI tools, and whether anything inspects prompts and responses.
Agents & MCPWhat autonomous agents are allowed to do, how much of that permission they actually use, and who must approve the actions that can cause damage.
Monitoring & IncidentsWhether your AI activity reaches your SIEM (security information and event management system), how long you keep the logs, and how quickly your team reviews alerts.