- Trends in vulnerabilities, including unused, permanent, outside, or irregular access
- Suggested remediation actions to reduce risk
- A comprehensive view of access grants
- Detailed views of overprovisioned Okta group rules

Assign resource sensitivity
For more precise recommendations, be sure your assets—groups and resources—have appropriate Sensitivity levels. Sensitivity is used, along with access metadata, to determine suggested remediations. Resources are assigned an inferred sensitivity based on their type, but you can manually override a resource’s sensitivity. Find the resource in the Inventory and select the edit icon.


Vulnerability types
See an overview of trends in vulnerabilities in the charts at the top of the Risk Center, and filter by vulnerability in the asset grants table.Permanent access
Access duration, used to calculate permanent access and unused access, is imported from third-party IDPs and apps, and is updated when access is granted through Opal.Outside access
Outside access is any access grant provisioned outside Opal’s approval flow. Note that this refers to provisioned access, not provisioned users—users imported from your IDP are not flagged for outside access.Irregular access
Irregular access is determined by calculating similarity scores for users, based on user attributes, and similarity scores for resources, based on resource types. Opal flags irregular access when access grants are dissimilar to existing access grants.Unused access
Access duration, used to calculate permanent access and unused access, is imported from third-party IDPs and apps, and is updated when access is granted through Opal.Overprovisioned rules
Okta group rules are automatically analyzed and flagged for overprovisioning. Select View rule insights on an Okta group rule in the access grants table for a detailed view on the group rule.The following agent risk types are part of the new Risk Center experience, currently in limited beta. Contact Opal support to enable it for your organization.
No owner
Flags an agent, tracked in your Agent Inventory, whose owning group has no active human member accountable for it.Exceeds owner access
Flags an agent that can access resources its human owner cannot—so the owner can’t vouch for everything the agent reaches.No plausible ownership
Flags an agent whose access has no overlap at all with its owner’s access, making it implausible the owner can vouch for what the agent does.No purpose
Flags an agent with no stated purpose, so there’s nothing to judge its access against.Remediate vulnerabilities
When you select suggested actions, filters are automatically applied to the access grant table for the given asset or vulnerability type. From the table, you can apply the suggested action, revoke access, and view rule insights for Okta group rules. For agent risks, suggested actions also include assigning an owner or setting a purpose. It’s often preferable to convert overprovisioned users to JIT, rather than revoke access, as it is a less jarring experience for end users who might be used to having longstanding access. Dismiss a suggestion to mark the identified vulnerabilities as safe. This prevents the suggestion from appearing for another 6 months.
Remediate in bulk
Select the checkbox on the Access grants table to remediate rows in bulk, then select the Apply Suggested Remediations button. Rows highlighted in yellow—in this example, all users—are marked for access calibration, with the Expires column detailing the change.View rule insights
If you’ve connected to Okta, Opal automatically imports and analyzes Okta group rules to proactively identify overprovisioned groups. In the Vulnerabilities filter, select Overprovisioned rule to view overprovisioned Okta group rules.

Custom monitors
Custom monitors are part of the new Risk Center experience, currently in limited beta. Contact Opal support to enable it for your organization.
- From the Risk Center, select Create risk.
- Name the monitor and set its Severity—High, Medium, or Low.
- Build a query using the same query builder as OpalQuery to define which entities the monitor should flag.
- Preview the entities currently matching your query.
- Save the monitor.
Configure Risk Center ticket propagation
The Risk Center ticketing provider setting is part of the new Risk Center experience, currently in limited beta. Contact Opal support to enable it for your organization.
- Go to Settings > Advanced.
- Turn on Risk Center ticketing provider.
- Choose your ticketing provider and the project, team, workspace, or database to file tickets in.