# Security Operations

The identity risk cluster, your top findings, the identity exposure breakdown,
and an inventory of the autonomous AI agents operating in your tenant.

![The Security Operations view composed on a live tenant — top findings, top 10 identity risks, NHIs by type, agentic AI inventory, and the identity risk cluster](/img/generative-ui/view-security-operations.png)

## Top findings

*Which single fix retires the most risk?*

Ranked by how many identities are affected, so it surfaces systemic hygiene
problems over one-off outliers. Selecting a finding opens its drill-down —
evidence, affected identities, and remediation steps.

![The top findings widget](/img/generative-ui/widget-top-findings.png)

## Top 10 riskiest identities

*Who, by name?*

People, machine accounts, and certificates in one list, so nothing hides behind
a category. Selecting an identity opens its blast-radius drill-down.

![The top 10 riskiest identities widget](/img/generative-ui/widget-top-10-riskiest-identities.png)

## Non-human identities by type

*How many machine accounts do we really have?*

Usually more than people expect. Pair it with the agent inventory.

![The non-human identities by type widget](/img/generative-ui/widget-nhi-by-type.png)

## Agentic AI inventory

*What AI agents are running, and what can they touch?*

The tool surface column matters most — it is what the agent can act on.
Autonomy tells you whether a human approves first.

![The agentic AI inventory widget](/img/generative-ui/widget-agentic-ai-inventory.png)

## Identity risk cluster

*What am I not seeing?*

The one to open when you don't yet know what you're looking for. Tight groups
of large bubbles are concentrations worth a look.

![The identity risk cluster widget](/img/generative-ui/widget-identity-risk-cluster.png)

## Top kill chain

The kill-chain flow panel is temporarily unavailable while it is reworked — it
is coming back in a future release.
