Exposure Calculator

What can one person do that you cannot undo?

Every organisation has a small number of actions that cannot be reversed, and more ways to reach them than anyone has counted. This estimates the size of that surface using your own numbers.

Your environment

This calculator estimates authorization exposure: the size of one bad authorization, the number of routes to it, and whether you can prove who did it. Enter your organisation details to see your numbers.

Largest single irreversible action
A transfer, a bulk export, a record disclosure, a destructive change.
Ways that action can be reached
User interface, API, integration, agent, service account, admin console.
Actors who can trigger it
Anyone holding credentials sufficient to perform it — staff, integrations, service accounts, and AI agents.
Share where a human is provably identifiable
Not just that an approval happened — a named person, bound to that action, verifiable later.

Enable JavaScript to use the interactive calculator.

This measures authorization exposure — what can be done irreversibly, by how many actors, and whether you can prove who did it. It does not measure your credential store. Where an action is executed by an agent, an integration, or a service account, there is generally no human to identify at all. Those are not edge cases in most environments; they are the fastest-growing share of consequential actions.