Per-risk loss exposure
The FAIR report prices your whole risk portfolio at once, as a simulated distribution. Per-risk loss exposure does something different: it stores an annual loss exposure (ALE) figure on each individual risk, so you can rank a single finding by the money it represents, break the total down by layer or identity type, and see which twenty risks carry the most exposure.
Both figures describe the same portfolio. They are produced by different methods, and this page explains what each one is good for — including the cases where they will not match, which is expected rather than a fault.
Before you start
- Per-risk pricing is enabled per organization by Axiad. If the widgets and panels described below are absent from your dashboard, it is not yet switched on for your organization — contact Axiad Support.
- Reading the figures needs no special role. Recompute is an administrator action.
- Pricing depends on a rate card Axiad maintains centrally. The calibrated constants behind your organization's figures aren't published in this documentation; for how they're derived for your environment, contact your Axiad representative.
Where the figures appear
| Surface | What it shows |
|---|---|
| ALE (measured) widget | Your organization's total measured exposure, summed across every open priced risk. |
| ALE by Layer widget | The same total split across L1, L2, L3, and Uncategorized. |
| ALE by Identity Type widget | The same total split across human, non-human, and AI agent identities. |
| Top Risks by ALE widget | The twenty highest-dollar open risks, ranked. |
| Annualized loss exposure by risk layer panel on the FAIR report | The layer breakdown alongside the report's simulated percentiles. |
| Identity detail pages | An identity's own contribution to organizational exposure. |
The four widgets are available in Generative UI workspaces. On organizations where per-risk pricing is enabled, the Executive View persona workspace includes them by default.
Measured, not simulated
This is the single most important distinction on this page.
| FAIR report percentiles | Per-risk loss exposure | |
|---|---|---|
| Method | Monte Carlo simulation over the whole portfolio | A deterministic calculation stored on each risk |
| Output | A distribution — P10, P50, P90 | One figure per risk, which adds up to a total |
| Answers | "What is the shape of our exposure this year?" | "Which of these findings is worth the most to fix?" |
| Refresh | When the report is generated | Continuously as risks change, reconciled nightly |
Because they are two methods over the same portfolio, the measured total and the simulated median will not be identical, and neither one is wrong when they differ. Use the simulated percentiles for framing and budgeting; use the measured per-risk figures for ranking and drill-down.
Where a chart or panel can be fed by either method, Mesh labels it. On the ALE trend, a caption below the card marks any series drawn from simulated percentiles rather than the measured per-risk total.
The total is a floor, not a complete figure
Mesh prices a risk only when its risk type has a researched entry on the rate card. A risk whose type has no entry is left unpriced — it is skipped, never given a generic default figure.
That is deliberate, and it is the property that makes these numbers defensible. A generic default applied to a risk type nobody has priced produces a number nobody has justified, and those numbers are indistinguishable from real ones once they are on a board slide.
The consequences are worth knowing:
- An unpriced risk contributes nothing to any total, chart, or ranking. It does not appear in Top Risks by ALE at all — it is absent from the ranking, not sorted to the bottom.
- Quote the measured total as a floor. It can understate real exposure, and it never overstates it by inventing a figure.
- Unpriced is shown as absent, never as
$0. A risk with no price displays no figure. If you see a genuine$0, that is a measured zero.
If a risk type that matters to you is consistently unpriced, raise it with Axiad Support — it is a rate-card gap, and adding the entry is a pricing decision Axiad makes rather than something you configure.
Reading the layer breakdown
Every priced risk falls into one of four buckets, and the four always add up to the total.
| Layer | What it covers |
|---|---|
| L1 · Inventory hygiene | Orphaned, dormant, and unowned inventory. Risks not explicitly classified elsewhere land here. |
| L2 · Policy compliance | Risks raised by evaluating an entity against a compliance policy or program. |
| L3 · Behavioral correlation | Behavioral and correlation-driven risks, classified explicitly by the engine that produces them. |
| Uncategorized | Priced risks whose layer is not set or not recognized. |
Two things about this breakdown surprise people, and both are correct:
- L3 can read
$0. The behavioral layer is populated by an engine that not every organization has generating findings yet. An empty L3 beside a populated L1 and L2 means "nothing in this layer", not a broken breakdown. - Uncategorized is shown, not hidden. Risks recorded before layer classification existed carry no layer. They are displayed in their own bucket rather than dropped, so the four bars always reconcile with the headline. If they were hidden, the bars would silently sum to less than the total.
A large or growing Uncategorized share is a classification gap, not a pricing error — the dollars are right, the drill-down under-reports. Contact Axiad Support if it grows.
Reading the identity-type breakdown
| Bucket | What it covers |
|---|---|
| Human | Risks on identities belonging to people. |
| Non-human | Risks on service accounts, workloads, and other machine identities. |
| AI agent | Risks on agentic identities. |
| Unknown | Priced risks whose identity could not be resolved. |
Unknown is a deliberate fourth bucket rather than being folded into non-human. Growth in Unknown means risks have stopped resolving to identities — a signal worth investigating, and one that folding it into another bucket would hide.
The range beside each figure
Each priced risk carries a low and a high figure alongside its main estimate.
Read this as a range, not as a confidence interval. It is built by combining the low ends of the underlying factors and then the high ends, which produces a deliberately wide span — wider than the P10-to-P90 band the FAIR report shows for the same portfolio, and wider again once ranges are summed across many risks. The two bands mean different things and are not comparable to each other.
How current the figures are
- The organization total and every breakdown are live. They reflect the risks currently open, and update as risks are raised and resolved.
- The trend chart of daily snapshots can be up to a day behind. It is built from a nightly export, which is the correct granularity for a chart of daily points and the same latency the FAIR snapshots beside it have always had.
- Figures are reconciled nightly. As a large batch of new data arrives, an individual risk is priced with the information available at that moment. An overnight pass re-derives every figure across the whole organization, which is when the totals become exactly consistent.
During a large ingestion — an onboarding, a new connector, an acquisition — an established organization can see its measured total run high until the next overnight reconciliation brings it back to the exact figure. A brand-new organization is protected differently: pricing is deferred until the first full pass, so its first figure is correct rather than inflated. In that window, risks show no exposure figure at all rather than a provisional one.
Recompute exposure (administrators)
Administrators can force a re-pricing of the organization from the current rate card, rather than waiting for the overnight pass.
- Go to Recompute ALE in the admin area.
- Select Recompute. The job runs in the background and reports when it finishes.
- Read the result counts:
| Count | What it means |
|---|---|
| Scanned | Risks examined. |
| Updated | Risks whose figure changed. |
| Cleared (unpriced) | Risks whose price was removed because their type no longer has a rate-card entry. |
| Skipped (no constants) | Risks left unpriced because their type has no entry. A steady non-zero count here is a rate-card gap. |
Recompute is safe to repeat — running it twice changes nothing the second time.
Use it after Axiad tells you the rate card has changed, or if a figure looks stale. Routine drift needs no action: the overnight pass heals it.
When pricing is first enabled, your reported figures will move
The first time per-risk pricing is enabled for your organization, your reported exposure changes, and it may go down, possibly by a lot.
That is a correction, not a loss of data. Previously, a risk type with no researched entry could still receive a generic figure. Those risks are now either priced from their own researched entry or left unpriced — and for some risk types the researched figure is substantially lower than the generic one it replaces.
Axiad provides the expected change for your organization ahead of the switch. If a figure moves and you were not expecting it, contact your Axiad representative before drawing conclusions from the new number: the direction of the move on its own does not tell you which mechanism caused it.
Troubleshooting
| Symptom | Cause | Resolution |
|---|---|---|
| No ALE widgets or panel anywhere in the dashboard | Per-risk pricing is not enabled for your organization. | Contact Axiad Support. |
| Measured total does not match the FAIR report's P50 | Expected — a deterministic sum and a simulated median are different quantities. | No action. Use percentiles for framing, measured figures for ranking. |
| A risk you care about is missing from Top Risks by ALE | Its risk type has no rate-card entry, so it is unpriced and absent from the ranking. | Contact Axiad Support to raise the rate-card gap. |
| The panel warns that pricing is still in progress | Part of the portfolio is priced and part is not, so the total covers only part of it. | Wait for the overnight pass, or ask an administrator to run Recompute ALE. |
L3 reads $0 beside a populated L1 and L2 | The behavioral layer has no findings for your organization. | No action. This is a measured zero, not a fault. |
| Uncategorized is large or growing | Risks are not being classified into a layer. | Contact Axiad Support. The total is still correct; the breakdown under-reports. |
| Total dropped sharply with no remediation | Pricing was enabled or the rate card changed. | Contact your Axiad representative for the expected-change figures for your organization. |
| Trend chart's newest point looks a day old | The daily series comes from a nightly export. | Expected. The organization total on the widgets is live. |
| An identity's history restarts on the trend | The identity was merged with another, which re-anchors its history from that day. | Expected. The earlier series is not deleted; a new one begins beside it. |
Related
- Risk quantification — the FAIR methodology, the factor decomposition, and the Monte Carlo simulation.
- Reports, exports, and data retrieval — generating and consuming FAIR reports.
- Risk scoring — the 1–100 ranking that sits alongside the dollar figure.
- Quantify risk in dollars — the use case these figures serve.
- Generative UI — the workspaces the ALE widgets appear in.