How to read this board
IAM Risk is what your identity system predicts from a job title and the permissions attached to it. It is set at provisioning and revisited on a review cycle. It never sees behaviour.
Zendata Behavioral Risk is what the identity actually did. Every action is scored 0–100 as it happens — what data it touched, whether personal information was involved, whether the caller still behaves like itself, whether it stayed inside its boundary. An identity's score is the highest single action it took, raised to a floor if it crossed a boundary, read personal data on a restricted system, or tripped the takeover detector.
The gap between them is the finding. On the chart, the dashed line is where the two agree. A point sitting on it is behaving exactly as provisioned. A point floating above it is doing more than its permissions ever predicted — and no permissions review can catch that, because on paper nothing is wrong.