t = 0.0s
drag to rotate ring
risk score scope — dashed line = threshold

Consent Phishing & OAuth Grant Risk Ring (2D)

OAuth apps arrive continuously around a central identity hub, each carrying a hidden mix of risky scope requests, unverified-publisher signals, and request-velocity anomalies. A live risk model scores every grant, flags the risky ones into step-up authentication, and — with automated response enabled — resolves them into a clean revoke or a cleared false positive without waiting on a human. This 2D view lays the grants on a draggable ring around the hub and adds a scrolling risk-score scope beneath it, so you can watch each app's score cross the threshold line in real time. Tune the risk threshold, the share of genuinely malicious apps, and the arrival rate to see the same precision/recall trade-off every real identity threat detection and response (ITDR) pipeline has to make, with detection rate and mean time-to-revoke tracked live.