Back to blog
Risk ModelMethodologyTravel RiskDuty of Care

What Your Trip's Single Risk Level Actually Means

Part 6 of Inside the Risk Model: how ShadowIQ rolls many individual alerts into one trip-level risk — a high-water mark of what's live and relevant, that comes back down as fast as it went up.

July 19, 2026ShadowIQ Risk Intelligence Team

A coordinator looking at twenty trips doesn't want twenty alert feeds. They want one honest question answered per trip: does this one need my attention right now?

That's what a trip's single risk level is for. Part 6 of Inside the Risk Model is about how ShadowIQ turns many individual alerts — each scored on the four axes — into that one number, and why we made it work the way we did.

A high-water mark, not an average

ShadowIQ's shipped default sets a trip's overall level to reflect the most serious alert that is still active on that trip. It's a high-water mark.

Why not average? Because averaging is dangerous in risk. If a trip has one genuinely serious, live, nearby alert and nine trivial ones, the average is "not much" — and that's exactly the alert you needed to see. Averaging lets real threats hide in a crowd of noise. A high-water mark refuses to let that happen: one serious, live, relevant alert is enough to raise the trip, and no amount of quiet activity can average it away.

The trade-off is that a high-water mark is conservative — it errs toward surfacing. For a duty-of-care decision, that's the right direction to err.

"Active and on this trip" is doing real work

Two qualifiers matter in that sentence, and they connect directly to the earlier posts:

  • Active — resolved, stale, and lapsed alerts (see Part 5) don't hold the trip up. As they ease down, the trip level re-computes.
  • On this trip — the alert must belong to the trip's monitoring picture. The default high-water mark remains deliberately conservative and uses the alert's full severity even when exposure is weak; the dashboard shows exposure separately. An opt-in composite mode can additionally damp weak-exposure alerts and emphasise same-city, in-window events.

So the default trip level answers a conservative question: "what is the most serious alert still live on this trip?" Exposure context then helps a coordinator judge whether it is actually in the group's path.

It comes back down

Because the level is computed live from what's currently active and relevant, it falls as fast as it rises. When the serious alert that raised a trip resolves — or the group leaves the area, or a review clears it — the trip level drops on the next recompute. It's not a ratchet that only goes up.

Changes are notified — asymmetrically

You don't have to watch the dashboard to catch a change. ShadowIQ notifies on trip-level transitions, but deliberately not symmetrically:

  • A rise into High goes out as urgent — a "look now."
  • A step from High down to Medium is a gentle FYI — reassurance that a situation has eased. A direct High-to-Low change does not currently send a transition notification.
  • Small shuffles in the middle don't notify at all, and rapid flip-flopping is damped, so one volatile hour can't spam your team with contradictory messages.

The asymmetry is intentional: escalations deserve urgency, de-escalations deserve a quiet note, and churn deserves silence.

Why it matters to you

The trip level is designed to be trustworthy at a glance: it goes up for the right reason (one real, live, relevant threat), it can't be gamed down by noise, and it comes back to earth as the world does. That's what lets a coordinator triage twenty trips in a minute and trust the ones showing green.

Next in the series: Who gets told, and how fast.