Business

SaaS Risk Heatmap

A SaaS risk heatmap scores every application in your stack on two axes, how sensitive the data it holds is and how far a compromised account or OAuth grant would reach, then plots them so the ones that need SSO, MFA and offboarding automation first are obvious.

Last reviewed by the Radiatus Cloud team

Want this done for your business?

Radiatus delivers cloud, security & automation for growing teams.

Book a free consult

The two axes

Data criticality is what the app holds: source code, customer records, payroll, or lunch orders. Access scope is blast radius: what else an attacker reaches after compromising one account or one integration token. Google Workspace scores five on both because it is usually the identity provider, so control of one admin account resets the password on every other app. The score is the product of the two, from 1 to 25, banded as Low under 6, Medium to 9, High to 15 and Critical from 16.

Why the pre-filled scores look the way they do

  • GitHub: secrets committed to repositories and long-lived personal access tokens that skip MFA entirely.
  • Salesforce: report exports and connected apps with API access; guest and community sharing rules are misconfigured often enough to have a name, the Ghost Sites problem.
  • Slack: credentials and customer data pasted into channels, retained indefinitely and searchable by every member.
  • Jira and Notion: unfixed vulnerabilities and runbooks written in plain language, one public-link toggle away from the internet.

Adding your own applications

Use the extra row to add anything not listed, with your own criticality and scope from 1 to 5. Be honest about scope: a payroll provider holds critical data but usually scores 2 on reach because it integrates with little else. A password manager or an SSO provider is the reverse case and should be 5 on scope regardless of what it stores.

What to do with the ranking

Everything scoring 10 or more should be behind single sign-on with MFA enforced, should have SCIM or an equivalent so that leavers are deprovisioned automatically, and should have its OAuth grants reviewed quarterly. Everything Critical also needs an admin-count audit; more than a handful of global admins on the identity provider is the single most common finding in SaaS security reviews. The heatmap is a prioritisation device, not an assessment, and it runs entirely in the browser with nothing saved.

Related tools

Frequently Asked Questions

Why does Google Workspace rank above GitHub when GitHub holds our code?

Because Workspace is the identity provider. Compromise it and the attacker can reset the GitHub password too. Identity systems always score maximum on access scope.

How is the score calculated?

Data criticality multiplied by access scope, each from 1 to 5, giving 1 to 25. Bands are Low below 6, Medium 6 to 9, High 10 to 15, Critical 16 and above.

Is this a replacement for a vendor risk assessment?

No. It ranks which vendors to assess first. A proper assessment looks at the vendor's own controls, certifications and contract terms; the heatmap only looks at your exposure to them.

What is an OAuth grant and why does it matter here?

When a user clicks Allow on a third-party app that wants access to their Google or Slack account, that app receives a token that keeps working after the user changes their password. Unreviewed grants are a quiet way for data to leave.

Is my app list stored anywhere?

No. Selections and custom entries live in the page and are gone on reload.

Privacy & Security

Generated locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.