"This access is risky" isn't a decision anyone can actually act on. "This access is risky because nobody else in this role holds it, and this person has been denied for similar requests twice before" is. The difference between the two is context, and contextual risk insight is specifically about surfacing that surrounding information directly at the moment someone's actually making a governance call, not as a separate report they'd have to go dig up first.
A risk score on its own requires the person looking at it to already know what "normal" looks like for comparison, which is exactly the institutional knowledge that isn't consistently available to whoever happens to be approving a request or reviewing an access certification that day. Contextual risk insight closes that gap by injecting the surrounding facts directly into the decision moment itself.
Zluri surfaces context in five distinct forms, each answering a different question:

This piece covers each one, and where it actually shows up.
Peer Context: Is This Normal for Someone in This Position
This is the same underlying principle showing up at two different governance moments, worth recognizing as one pattern rather than two unrelated features.
At the point of request, Approver Insights' Peer Insights show what percentage of people holding the same job title already use the requested application, at what access level, and the historical approval rate for similar requests, flagged specifically when that peer approval rate is zero.
At the point of review, Access Reviews' peer-comparison insight flags an access level as an outlier relative to what current department or role peers actually hold.
Both are answering the identical underlying question, does this look like what similarly situated people actually have, just asked at two different points in an identity's lifecycle: once before access is granted, once periodically afterward to confirm it's still consistent with the pattern.
Historical Context: Has This Identity Asked for This Before
A separate, complementary form of context looks at the requester's own pattern rather than their peers'.
User Insights show how many times a specific identity has requested a specific application over the past year, their own historical approval rate, and the outcome and decision-maker of their most recent request.
This matters distinctly from peer context. Someone who's requested and been denied the same access repeatedly represents a different situation than a first-time request, even if their peer group's overall approval rate for that access looks perfectly normal.
Combination Context: What Else Does This Identity Already Hold
This is the most extreme form of context-dependence in the whole model, since it can change a grant's risk entirely based on facts that have nothing to do with the grant itself.
Access Insights within Approver Insights flag whether a requested permission is standard or privileged. The deeper combination context comes from Segregation of Duties evaluation, where the exact same request that would be entirely appropriate on its own becomes a genuine conflict the moment it's evaluated against everything else the requesting identity already holds.
A risk assessment that only looks at the grant in isolation, with no context about the requester's existing access, misses this category of risk entirely, since nothing about the individual request looks wrong.
Organizational Status Context: What This Target Actually Means Right Now
The identical risk score means something genuinely different depending on the current governance status of what's being accessed. This is context about the target rather than the requester.
The recommended-action matrix pairs a risk level directly with an application's authorization status, Restricted, Managed, or Needs Review, to produce a different required response for the same underlying risk number. A high-risk score on an application the organization has already decided to block calls for a different action than the identical score on an application it's actively relying on and trying to secure further.
Environmental Context: Has Anything About the Target Changed
Context isn't only about the requester and their peers. It includes facts about the application itself that shift independently of any specific access decision.
The broader risk score's four inputs, scope sensitivity, compliance certification coverage, third-party security ratings, and active breach monitoring, mean an application's risk context can change entirely between one access decision and the next. A certification lapsing or a breach being disclosed shifts the surrounding context for every subsequent decision involving that application, regardless of anything about the specific person requesting access at that moment.
Rolling Multiple Contexts Into One Interpretable Signal
The actual point of contextual insight is turning several separate facts into one thing a person can act on quickly.
Approver Insights' summary status is exactly this synthesis:

Rather than requiring an approver to manually weigh peer approval rates, the requester's own history, and whether the access is privileged as three separate data points, the summary status does that weighing directly and presents a single, interpreted judgment, with the underlying detail still available for anyone who wants to look closer.
This is the difference between data and insight in practice. Data is the individual facts. Insight is what those facts add up to once someone's actually done the work of interpreting them together.
Why Contextual Insight Beats a Bare Score
The actual argument for building governance decisions around contextual insight rather than a flat risk number is that a bare score assumes the decision-maker already has the baseline knowledge to interpret it: what's normal, what this person's history looks like, what else they hold. That knowledge is rarely consistently available to whoever happens to be reviewing a specific request or certification that day.
Supplying that context directly, at the exact moment a decision is being made, is what actually makes fast, confident governance possible without depending on institutional memory that inevitably varies from one reviewer to the next.
Frequently Asked Questions
Is contextual risk insight the same thing as a risk score?
Related but distinct. A risk score is a number. Contextual insight is the surrounding information, peer comparison, request history, combination risk, target status, that explains what that number actually means and what to do about it, surfaced directly at the moment of a governance decision rather than left for someone to interpret on their own.
Why does the same peer-comparison logic show up in both access requests and access reviews?
Because it's answering the same underlying question, does this access look consistent with what similarly situated people actually hold, at two different points in an identity's lifecycle. Request-time peer context informs whether to grant access in the first place; review-time peer context confirms whether it's remained consistent with that pattern afterward.
Can an access request look completely reasonable on its own and still be risky in context?
Yes, specifically when it combines with something the requesting identity already holds into a toxic combination. This is exactly why combination context, evaluated through Segregation of Duties, matters as its own distinct category, a risk that's invisible when a request is assessed in isolation but becomes obvious once evaluated against the requester's full existing access.
Why does a summary status like "Review Carefully" matter more than showing all the underlying data points separately?
Because it does the interpretive work of weighing multiple contextual signals together, rather than requiring every reviewer to manually synthesize peer data, history, and access type into a judgment themselves each time. The underlying detail stays available for anyone who wants it, but the summary status turns that detail into something actionable at a glance.
















