Every AI risk, scored by what it can reach.
The risk register lists every flagged and unreviewed AI agent, MCP server, package, and personal-account coding session. Each one carries a severity, a risk score that counts what it can reach on the graph, its owner if it has one, and a due date.
Risks across Acme Corp's AI estate
6 risks, sorted by severity and risk score; 4 have no owner.
- Reason
- Flagged AI agent with no owner
- Risk score
- 92 · reaches 2 nodes in 1 hop
- Can reach
- mcp-postgres-prod,openai 1.51.0
- Assigned to
- Priya Raman@payments
- Due
- Sep 30
- Ticket
- PAY-418
On Acme Corp's map, eng-ws-14 runs shadow-summarizer, and shadow-summarizer can reach mcp-postgres-prod (1) and openai 1.51.0 (2). What it can reach counts toward its risk score, 92, the highest in the register.
The risk score counts what a risk can reach
Octic scores each risk by how likely it is to cause harm and what it can reach on the graph: the MCP servers an AI agent connects to, the packages it uses, and what those reach in turn.
A flagged AI agent wired into a production database scores above an unreviewed one that reads local files. The register sorts by severity, then by risk score.
- A risk score weighs how likely a risk is and what it can reach on the graph.
- shadow-summarizer, flagged AI agent with no owner, can reach mcp-postgres-prod and openai 1.51.0. Risk score 92. Severity Critical, rank 1 of 6.
- invoice-extractor, aI agent awaiting review, can reach OpenAI API and mcp-filesystem. Risk score 56. Severity Medium, rank 4 of 6.
Each can reach 2 nodes. shadow-summarizer is flagged and one of them is a production database, so it scores 92 to invoice-extractor's 56 and ranks first.
Every risk has an owner, or shows it has none
Each risk carries the owner Trust derived for it. When nobody owns an AI agent, MCP server, or package, the register says so, and the gap in ownership shows on the risk itself.
Sort the register by severity, status, assignee, or due date, and export it as CSV.
- shadow-summarizer, AI Agent. Flagged. No owner found.
- mcp-postgres-prod, MCP Server. Flagged. No owner found.
- Codex, Software Application. Flagged. No owner found.
- invoice-extractor, AI Agent. Unreviewed. Owner @finance-ops.
- openai 1.51.0, Software Package. Unreviewed. No owner found.
- mcp-filesystem, MCP Server. Unreviewed. Owner @platform.
- invoice-extractor connects to mcp-filesystem.
- shadow-summarizer connects to mcp-postgres-prod.
- shadow-summarizer uses openai 1.51.0.
2 of 6 risks have an owner; the other 4 have none.
Each finding gets an assignee, a due date, and a history
A finding is assigned to a person and gets a due date from its SLA. Add a ticket reference to tie it to the work in your tracker.
Every change to the finding lands in its history, with who made it and when.
- shadow-summarizer, AI Agent. Flagged. Rank 1 in the register. No owner found.
- Flagged AI agent, Finding. Severity Critical. Status Open. Due Sep 30. Ticket PAY-418.
- Priya Raman, Person. Team @payments.
- shadow-summarizer has finding Flagged AI agent.
- Flagged AI agent assigned to Priya Raman.
History
- 09:12:21Finding openedby Octic
- 09:26:10Assigned to Priya Ramanby Lena Okafor
- 09:41:52Ticket PAY-418 linkedby Priya Raman
Where this sits in Trust
The policy engine decides what is approved. The risk register tracks everything that isn’t, scored by what it can reach, with an owner, a due date, and a history.
Back to TrustFind the risk that reaches the most
Install a sensor on a Linux or Windows host and connect your APIs. Every flagged and unreviewed AI agent, MCP server, and package lands in the register with its severity, its owner, and a due date.