Every "Sign in with Google" or "Connect to Slack" button grants a third-party app an OAuth scope — and those grants pile up quietly for years, long after anyone remembers approving them. This simulator renders the connected apps around an identity-provider hub on a 2D risk radar, with each app's scopes shown as small orbiting read/write/admin tokens whose color marks the grant level. A staleness-weighted risk score pushes high-privilege, long-unused apps further from the trusted core, an adjustable admin-scope weight and staleness horizon let you see how policy choices reshape the whole radar, and two remediation controls — enforce least privilege and revoke — let you act on what the radar shows, exactly the triage a SaaS Security Posture Management (SSPM) console performs against configuration drift and shadow-app sprawl.