User Risk Scoring
Focus
Focus
SaaS Security

User Risk Scoring

Table of Contents

User Risk Scoring

Learn how Behavior Threats calculates user risk scores from a transparent, fully explainable model driven entirely by admin-configured weights.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
Behavior Threats® uses a transparent, fully explainable risk scoring model that gives you complete control over how each user's risk score is calculated. We start with default weights assigned to each policy, count of policy breach, thresholds measured by ML policies, and the risk amplifier for the user (default is 1). Behavior Threats compiles the risk score directly from these admin-configured weights, ensuring you always understand exactly why a user was flagged.
How Weights Work
The scoring model is based on configurable admin controls for impacting risk scores. As an admin, you can stack rank the policies by changing the default weights for each policy. Higher the weight, higher the impact to risk score. You can also add users to a watchlist and change the risk amplifier of the watchlist. Higher the risk amplifier, higher the risk score for that user.
The Users Tab Dashboard
The Users tab dashboard displays a risk breakdown for each user, including their overall score, severity level, incident count, and watchlist membership. You can filter the list by risk level, policy type, or watchlist to focus your investigation on the most critical users. The top risky users are prominently displayed for immediate triage.
Severity-to-Score Mapping
The platform maps calculated risk scores to severity levels using the following ranges:
Risk LevelScore RangeDescription
Very Low0–40Minimal risk; user behavior is within normal parameters.
Low41–60Slight elevation; minor anomalies detected but unlikely to indicate a threat.
Medium61–80Moderate risk; multiple policy violations warrant investigation.
High81–90Elevated risk; significant policy violations indicate potential insider threat activity.
Critical91–100Severe risk; immediate investigation and remediation recommended.
Smart Decay Logic
To ensure that stale data does not trigger false positives, the platform applies time-based decay to incident weights. Incidents are bucketed by recency, with more recent incidents contributing more heavily to the overall score.
  • Each incident contributes to your risk score based on its severity and the associated policy weight.
  • Over time, the contribution of each incident decays; that is, older incidents have progressively less influence on your current score.
  • The decay follows an exponential curve: an incident's influence reduces by approximately half every 30 days.
  • If no new incidents occur, a user's score gradually returns to the baseline score of 5.
Key Behaviors of Smart Decay Logic
  • Recent incidents have the strongest impact on the score.
  • Older incidents (for example, 60+ days) contribute very little to the score.
  • New incidents increase the score immediately based on their severity.
  • If an admin performs a manual score reset, all prior incidents stop contributing and the score starts fresh from that point.
The risk score range is 5 (baseline, no risk) to 100 (maximum risk). Every day the decay factor will decrease, it will not be same. This decay logic ensures that your risk scores always reflect the current threat landscape rather than accumulating historical noise.
Risk Amplifiers from Watchlists
If a user belongs to a watchlist, their risk amplifier multiplies the impact of policy violations on their score. This contextual amplification ensures that high-priority personas (departing employees, executives, vendors) receive proportionally higher scrutiny.
To understand how individual policy violations contribute to a user's score over time, see User Activity Timeline. To reset a user's score back to the baseline, see Reset a User Risk Score.