Exposure scoring

A defensible score for every site

No more guessing which sites are risky. Each one gets a 0-100 exposure score built from weighted factors - with the breakdown shown, so you can defend the number to auditors and site owners alike.

  • Sharing & anonymous links - unexpiring 'anyone with the link' sharing is the dominant driver, and it's caught.
  • External & guest access - access that has drifted beyond its original project scope is surfaced.
  • Dormancy - stale sites that are still broadly shared score higher, not lower.
  • Levels & drill-down - filter by critical, high, or a single factor to focus the work.
app.princetonsentinel.com/dashboard/data-risk
Data risk page with exposure gauge, risk-level counts, factor contribution chart, and AI summary
AI executive summary

The 'so what' written for you

A gauge is nice; a paragraph a CISO can forward is better. Sentinel writes a plain-language summary of where exposure concentrates and which fixes remove the most risk.

  • Portfolio narrative - what's exposed across the tenant and why it matters, in plain English.
  • Prioritized recommendations - the highest-impact fixes, ordered - not a wall of raw findings.
  • Grounded in your data - generated from your actual scores, inside your own environment.
app.princetonsentinel.com/dashboard/risk
Risk hub with data-risk and agent-risk gauges and AI-written summaries
Remediation

From a finding to a fix, with a trail

Insight that you can't act on is just anxiety. Sentinel connects each finding to the sharing view and the revoke workflow, and records what was done.

  • One-click revoke - remove anonymous or external links from the site that surfaced them.
  • Admin-approved - state-changing actions require an admin - nothing happens automatically.
  • Full audit log - every revoke is captured with actor, target, and timestamp, and exportable.
app.princetonsentinel.com/dashboard/sharing
Sharing posture page used to review and revoke over-broad links
The workflow

From findings to fixes

Detection is only useful if it ends in a remediated, audited environment.

01

Detect

Every site is scored from real sharing and access signals - no sampling, no manual review.

02

Prioritize

Risk levels and factor breakdowns push the highest-exposure sites to the top of the queue.

03

Remediate

Revoke anonymous or external links straight from the finding - always with admin approval.

04

Audit

Every revoke is logged with actor, target, and time, and re-scored on the next run.

What signals go into a site's exposure score?

Sharing scope (how broadly links are shared), anonymous links without expiration, external and guest access, dormancy, and sensitivity signals. Each factor is weighted and combined into a 0–100 score with a risk level, and the full factor breakdown is shown so the number is never a black box.

Does scoring or remediation change anything without approval?

No. Scoring is entirely read-only. Revoking a link is an explicit, admin-initiated action - Sentinel never removes access on its own - and every action is written to an audit log.

How fresh are the scores?

Scoring runs on a schedule you control, against the inventory the ingestion job has synced from Microsoft Graph. After you remediate, the affected sites are re-scored on the next run so the queue reflects reality.

What are the AI summaries, and where does that run?

On top of the deterministic numeric score, an optional AI layer writes a plain-language executive summary and prioritized recommendations. It runs inside your own cloud environment; the score itself never depends on it.

Find your riskiest sites this week

In the demo we'll score a tenant that looks like yours and walk the exact path from a high-risk finding to a logged, remediated fix.

Request a demo