User Activity Timeline
Learn how the user activity timeline displays policy violations with their risk
impact percentages to explain how a user's risk score changed over time.
| Where Can I Use This? | What Do I Need? |
|
|
Or any of the following licenses that include the Data Security license:
|
The user activity timeline provides a chronological view of all policy violations that
contributed to a user's current risk score. Events are aggregated by policy and displayed
in order of recency for the last 90 days by default. This view allows you to understand
exactly why a user's risk score changed by examining the specific policy violations,
their impact, and how they accumulate over time.
The following walk through uses the user Mark Nelson to illustrate how you can
investigate a high-risk user through the activity timeline.
Risk Level Meter
At the top-left of the user detail page, a semicircular gauge displays the user's
current risk score and severity level. Mark Nelson's gauge shows a score of 86 (High),
color-coded in red. Below the gauge, a risk trend indicator shows the direction and
magnitude of the most recent score change (for example, "↑ 1 since 1 day ago"), and a
Reset link allows you to
reset the
user's risk score back to the ML baseline.
User Attributes
A horizontal metadata bar adjacent to the risk meter displays the user's identity
attributes pulled from your directory services: Email, Title, Department, Last Activity,
Location, Manager, Active Directory Account, Active Directory Group(s), and Cloud
Dynamic User Group(s).
Manage CDUG
The
Manage CDUG link opens the
Dynamic User Group management
interface. When you create a CDUG with a defined criteria, users will be automatically
added/removed from the group based on that criteria.
Risk Score Trend for Past 90 Days
An area chart below the user attributes shows how the user's risk score evolved over
the selected time period. The chart uses color-coded bands to indicate severity
thresholds—green for the low-risk zone (0–49), transitioning through yellow and orange
for medium and high, up to red for critical scores. For Mark Nelson, the trend shows
an initial low-risk period, a sharp spike as policy violations accumulated, a brief
decline, and then a sustained climb back to 86 as new violations continued to
trigger.
A Past 90 Days drop-down in the top-right corner of the chart lets
you adjust the time window to focus on specific periods of interest.
User Event Timeline
The timeline section lists every policy violation that contributed to the user's current
score, ordered chronologically (from bottom to top). Each event displays:
- Date and Timestamp—The UTC time when the violation was detected (for example,
"2024-05-01 12:00 AM UTC").
- Severity Icon—A color-coded square indicating the severity of the event.
- Policy Name—A clickable link identifying the triggered rule (for example, "High
Frequency Activity" or "Data Transfer Spike").
- Detection Description—A brief description of what the policy detects (for example,
"Detect spike in User Activity" or "Detect spike in Data Downloads or
Uploads").
- Severity Level—The severity assigned to this violation (Medium, High, or
Critical).
- Risk Contribution—The percentage this event contributed to the user's overall risk
score (for example, "+5.77%" or "+10.03%").
Sample Use Case: How Risk Contribution Builds Over Time
Mark Nelson's timeline demonstrates how incremental policy violations compound into a
high risk score. Each event adds a percentage to the overall score based on the policy
weight you configured and the severity of the violation. Reading the timeline from
earliest to most recent, you can trace the escalation pattern:
| Date | Policy Violated | Detection Rule | Severity | Risk Contribution |
| 2026-04-23 | High Frequency Activity | Detect spike in User Activity | Critical | +3.51% |
| 2026-04-25 | Sustained Bulk Activity Burst | Detect bulk User Activity | High | +1.84% |
| 2026-04-25 | Data Transfer Spike | Detect spike in Data Downloads or Uploads | Medium | +2.57% |
| 2026-04-25 | Abnormal Hours Activity | Detect Abnormal User Activity Hours | Critical | +1.47% |
| 2026-04-25 | Unusual Geo-Access | Detect Abnormal Location Access | Critical | +2.21% |
| 2026-04-25 | Off-Hours App Usage Spike | Detect spike in Application Usage | High | +1.47% |
| 2026-04-25 | Failed Logins Spike | Detect spike in failed logins | Medium | +2.57% |
| 2026-04-25 | Off-Hours App Usage Spike | Detect spike in Application Usage | High | +1.47% |
| 2026-04-28 | Off-Hours App Usage Spike | Detect spike in Application Usage | Critical | +1.58% |
| 2026-04-28 | Abnormal Hours Activity | Detect Abnormal User Activity Hours | High | +1.58% |
| 2026-04-29 | Sensitive Data Access | Detect User Unusual Accesses to Sensitive Data | High | +4.03% |
| 2026-04-29 | High Frequency Activity | Detect spike in User Activity | Medium | +4.03% |
| 2026-05-02 | Data Transfer Spike | Detect spike in Data Downloads or Uploads | Critical | +3.02% |
| 2026-05-02 | High Frequency Activity | Detect spike in User Activity | Critical | +4.32% |
| 2026-05-02 | Unusual Geo-Access | Detect Abnormal Location Access | High | +2.59% |
| 2026-05-04 | High Frequency Activity | Detect spike in User Activity | High | +4.52% |
| 2026-05-04 | Data Transfer Spike | Detect spike in Data Downloads or Uploads | High | +3.17% |
| 2026-05-04 | Bulk Data Transfer | Detect bulk Data Downloads or Uploads | Medium | +7.08% |
The total risk contribution across all 18 violations over this 12-day period amounts to
+53.03%.
The platform computes each contribution by calculating the policy's weight relative to
the total weighted score before normalization. As new incidents are created, these
percentages adjust dynamically, reflecting the
decay logic applied to older
events—recent violations carry full weight, while incidents older than 7 days
receive progressively reduced impact.
Filters
Two dropdown filters at the top-right of the timeline section help you focus your
investigation:
- Policy—Filter events by a specific policy name to isolate a single
detection type (for example, show only Data Transfer Spike events).
- Severity—Filter events by severity level (Medium, High, or Critical) to
focus on the most impactful violations first.
View All Incidents
The
View All Incidents link at the top of the timeline section
opens the full
incidents investigation page filtered to this specific user.
This gives you access to additional incident metadata and export options.