# Per-risk loss exposure

The [FAIR report](../concepts/risk-quantification.md) prices your whole risk
portfolio at once, as a simulated distribution. **Per-risk loss exposure** does
something different: it stores an annual loss exposure (ALE) figure on each
individual risk, so you can rank a single finding by the money it represents,
break the total down by layer or identity type, and see which twenty risks carry
the most exposure.

Both figures describe the same portfolio. They are produced by different
methods, and this page explains what each one is good for — including the cases
where they will not match, which is expected rather than a fault.

## Before you start

- Per-risk pricing is enabled per organization by Axiad. If the widgets and
  panels described below are absent from your dashboard, it is not yet switched
  on for your organization — contact Axiad Support.
- Reading the figures needs no special role. **Recompute** is an administrator
  action.
- Pricing depends on a rate card Axiad maintains centrally. The calibrated
  constants behind your organization's figures aren't published in this
  documentation; for how they're derived for your environment, contact your
  Axiad representative.

## Where the figures appear

| Surface | What it shows |
| --- | --- |
| **ALE (measured)** widget | Your organization's total measured exposure, summed across every open priced risk. |
| **ALE by Layer** widget | The same total split across L1, L2, L3, and Uncategorized. |
| **ALE by Identity Type** widget | The same total split across human, non-human, and AI agent identities. |
| **Top Risks by ALE** widget | The twenty highest-dollar open risks, ranked. |
| **Annualized loss exposure by risk layer** panel on the FAIR report | The layer breakdown alongside the report's simulated percentiles. |
| Identity detail pages | An identity's own contribution to organizational exposure. |

The four widgets are available in [Generative UI](./generative-ui.md)
workspaces. On organizations where per-risk pricing is enabled, the **Executive
View** persona workspace includes them by default.

## Measured, not simulated

This is the single most important distinction on this page.

| | FAIR report percentiles | Per-risk loss exposure |
| --- | --- | --- |
| **Method** | Monte Carlo simulation over the whole portfolio | A deterministic calculation stored on each risk |
| **Output** | A distribution — P10, P50, P90 | One figure per risk, which adds up to a total |
| **Answers** | "What is the shape of our exposure this year?" | "Which of these findings is worth the most to fix?" |
| **Refresh** | When the report is generated | Continuously as risks change, reconciled nightly |

Because they are two methods over the same portfolio, **the measured total and
the simulated median will not be identical**, and neither one is wrong when they
differ. Use the simulated percentiles for framing and budgeting; use the measured
per-risk figures for ranking and drill-down.

> **note**
Where a chart or panel can be fed by either method, Mesh labels it. On the ALE
trend, a caption below the card marks any series drawn from simulated
percentiles rather than the measured per-risk total.

## The total is a floor, not a complete figure

Mesh prices a risk only when its risk type has a researched entry on the rate
card. A risk whose type has **no** entry is left unpriced — it is skipped, never
given a generic default figure.

That is deliberate, and it is the property that makes these numbers defensible.
A generic default applied to a risk type nobody has priced produces a number nobody has
justified, and those numbers are indistinguishable from real ones once they are
on a board slide.

The consequences are worth knowing:

- **An unpriced risk contributes nothing to any total, chart, or ranking.** It
  does not appear in Top Risks by ALE at all — it is absent from the ranking, not
  sorted to the bottom.
- **Quote the measured total as a floor.** It can understate real exposure, and
  it never overstates it by inventing a figure.
- **Unpriced is shown as absent, never as `$0`.** A risk with no price displays
  no figure. If you see a genuine `$0`, that is a measured zero.

If a risk type that matters to you is consistently unpriced, raise it with Axiad
Support — it is a rate-card gap, and adding the entry is a pricing decision Axiad
makes rather than something you configure.

## Reading the layer breakdown

Every priced risk falls into one of four buckets, and the four always add up to
the total.

| Layer | What it covers |
| --- | --- |
| **L1 · Inventory hygiene** | Orphaned, dormant, and unowned inventory. Risks not explicitly classified elsewhere land here. |
| **L2 · Policy compliance** | Risks raised by evaluating an entity against a compliance policy or program. |
| **L3 · Behavioral correlation** | Behavioral and correlation-driven risks, classified explicitly by the engine that produces them. |
| **Uncategorized** | Priced risks whose layer is not set or not recognized. |

Two things about this breakdown surprise people, and both are correct:

- **L3 can read `$0`.** The behavioral layer is populated by an engine that not
  every organization has generating findings yet. An empty L3 beside a populated
  L1 and L2 means "nothing in this layer", not a broken breakdown.
- **Uncategorized is shown, not hidden.** Risks recorded before layer
  classification existed carry no layer. They are displayed in their own bucket
  rather than dropped, so the four bars always reconcile with the headline. If
  they were hidden, the bars would silently sum to less than the total.

A large or growing Uncategorized share is a classification gap, not a pricing
error — the dollars are right, the drill-down under-reports. Contact Axiad
Support if it grows.

## Reading the identity-type breakdown

| Bucket | What it covers |
| --- | --- |
| **Human** | Risks on identities belonging to people. |
| **Non-human** | Risks on service accounts, workloads, and other machine identities. |
| **AI agent** | Risks on agentic identities. |
| **Unknown** | Priced risks whose identity could not be resolved. |

**Unknown** is a deliberate fourth bucket rather than being folded into
non-human. Growth in Unknown means risks have stopped resolving to identities —
a signal worth investigating, and one that folding it into another bucket would
hide.

## The range beside each figure

Each priced risk carries a low and a high figure alongside its main estimate.

Read this as a **range**, not as a confidence interval. It is built by combining
the low ends of the underlying factors and then the high ends, which produces a
deliberately wide span — wider than the P10-to-P90 band the FAIR report shows for
the same portfolio, and wider again once ranges are summed across many risks.
The two bands mean different things and are not comparable to each other.

## How current the figures are

- **The organization total and every breakdown are live.** They reflect the
  risks currently open, and update as risks are raised and resolved.
- **The trend chart of daily snapshots can be up to a day behind.** It is built
  from a nightly export, which is the correct granularity for a chart of daily
  points and the same latency the FAIR snapshots beside it have always had.
- **Figures are reconciled nightly.** As a large batch of new data arrives, an
  individual risk is priced with the information available at that moment. An
  overnight pass re-derives every figure across the whole organization, which is
  when the totals become exactly consistent.

> **note**
During a large ingestion — an onboarding, a new connector, an acquisition — an
established organization can see its measured total run high until the next
overnight reconciliation brings it back to the exact figure. A brand-new
organization is protected differently: pricing is deferred until the first full
pass, so its first figure is correct rather than inflated. In that window, risks
show no exposure figure at all rather than a provisional one.

## Recompute exposure (administrators)

Administrators can force a re-pricing of the organization from the current rate
card, rather than waiting for the overnight pass.

1. Go to **Recompute ALE** in the admin area.
2. Select **Recompute**. The job runs in the background and reports when it
   finishes.
3. Read the result counts:

| Count | What it means |
| --- | --- |
| **Scanned** | Risks examined. |
| **Updated** | Risks whose figure changed. |
| **Cleared (unpriced)** | Risks whose price was removed because their type no longer has a rate-card entry. |
| **Skipped (no constants)** | Risks left unpriced because their type has no entry. A steady non-zero count here is a rate-card gap. |

Recompute is safe to repeat — running it twice changes nothing the second time.

Use it after Axiad tells you the rate card has changed, or if a figure looks
stale. Routine drift needs no action: the overnight pass heals it.

## When pricing is first enabled, your reported figures will move

The first time per-risk pricing is enabled for your organization, **your
reported exposure changes**, and it may go **down**, possibly by a lot.

That is a correction, not a loss of data. Previously, a risk type with no
researched entry could still receive a generic figure. Those risks are now
either priced from their own researched entry or left unpriced — and for some
risk types the researched figure is substantially lower than the generic one it
replaces.

Axiad provides the expected change for your organization ahead of the switch.
If a figure moves and you were not expecting it, contact your Axiad
representative before drawing conclusions from the new number: the direction of
the move on its own does not tell you which mechanism caused it.

## Troubleshooting

| Symptom | Cause | Resolution |
| --- | --- | --- |
| No ALE widgets or panel anywhere in the dashboard | Per-risk pricing is not enabled for your organization. | Contact Axiad Support. |
| Measured total does not match the FAIR report's P50 | Expected — a deterministic sum and a simulated median are different quantities. | No action. Use percentiles for framing, measured figures for ranking. |
| A risk you care about is missing from Top Risks by ALE | Its risk type has no rate-card entry, so it is unpriced and absent from the ranking. | Contact Axiad Support to raise the rate-card gap. |
| The panel warns that pricing is still in progress | Part of the portfolio is priced and part is not, so the total covers only part of it. | Wait for the overnight pass, or ask an administrator to run **Recompute ALE**. |
| L3 reads `$0` beside a populated L1 and L2 | The behavioral layer has no findings for your organization. | No action. This is a measured zero, not a fault. |
| Uncategorized is large or growing | Risks are not being classified into a layer. | Contact Axiad Support. The total is still correct; the breakdown under-reports. |
| Total dropped sharply with no remediation | Pricing was enabled or the rate card changed. | Contact your Axiad representative for the expected-change figures for your organization. |
| Trend chart's newest point looks a day old | The daily series comes from a nightly export. | Expected. The organization total on the widgets is live. |
| An identity's history restarts on the trend | The identity was merged with another, which re-anchors its history from that day. | Expected. The earlier series is not deleted; a new one begins beside it. |

## Related

- [Risk quantification](../concepts/risk-quantification.md) — the FAIR
  methodology, the factor decomposition, and the Monte Carlo simulation.
- [Reports, exports, and data retrieval](./reports-and-exports.md#fair-quantitative-risk-reporting) —
  generating and consuming FAIR reports.
- [Risk scoring](../concepts/risk-scoring.md) — the 1–100 ranking that sits
  alongside the dollar figure.
- [Quantify risk in dollars](../use-cases/quantify-risk-in-dollars.md) — the use
  case these figures serve.
- [Generative UI](./generative-ui.md) — the workspaces the ALE widgets appear in.
