Users Dashboard
Explore the Users tab in Behavior Threats to view risky users, risk score
distribution, watchlist status, and detailed user-level threat data.
| Where Can I Use This? | What Do I Need? |
|
|
Or any of the following licenses that include the Data Security license:
|
The Users tab under Behavior Threats is the
primary interface for monitoring user risk across your organization. It consolidates
risk scores, watchlist membership, and threat incidents into a single view so you can
quickly identify and investigate the users who pose the greatest risk. A time-range
filter at the top of the page (default: Past 30 Days) controls
the data displayed across all panes.
Top 3 Risky Users
The top-left section displays cards for the three users with the highest risk scores.
Each card provides an at-a-glance summary:
- User name—Displayed as a View details link that
opens the User Activity Timeline.
- Risk score—A color-coded circular badge indicating the user's current
score and severity level.
- Watch List—The watchlist(s) the user belongs to, with a count if the user
appears on multiple watchlists.
- Incidents—Total number of threat incidents associated with the user.
- Risk Trend—A directional indicator showing the score change over the
selected time period (for example, "↑ 2 since 1 day ago").
- Status—The user's current account status (Active or Inactive).
Select View Risky Users to navigate to the full list of users
sorted by risk score.
User Risk Score Distribution
The top-right section displays a donut chart showing how your monitored users are
distributed across
risk levels. The center of the chart shows the total number
of monitored users, while the surrounding ring and legend break down the count by
severity band:
- Critical (97–100)
- Very High (90–96)
- High (70–89)
- Medium (50–69)
- Low (0–49)
Watch List Overview
A collapsible section (toggle:
Hide Watch List) displays all
configured
watchlists as horizontal cards. Each card shows:
- Watchlist name—Color-coded label identifying the watchlist.
- Type—A badge indicating whether the watchlist is PREDEFINED
(system-defined) or CUSTOM (created by you).
- User count—Number of users currently on the watchlist.
- Risk
Amplifier—The multiplier applied to risk scores for users on this
watchlist (for example, "Risk x 2" or "Risk x 1.5").
- Users with Incidents—Count of watchlisted users who have active incidents.
Users Table
The main data table lists all monitored users with their current risk posture. Only users
with incidents are listed here. The table includes the following columns:
- Name—The user's display name, rendered as a link that opens the user's activity timeline.
- Watch List—Watchlist(s) the user belongs to.
- Risk Score—The user's current numeric risk score.
- Risk Level—A color-coded badge (Critical, Very High, High, Medium, or Low).
- Department—The user's department from your identity provider.
- Incidents—Total incident count for the user, rendered as a link that open the user's
incident page.
- Last Incident Date—Date of the user's most recent incident.
- Action—An overflow menu with per-user actions. There are two actions you can take on
the specific user: edit the watchlist the user belongs to and reset
the risk score.
Filters
A filter bar above the table lets you narrow results using one or more criteria:
- Search by user name—Free-text search across user display names.
- Situation—Filter by the behavioral situation or detection type that triggered an
incident.
- Watch List—Filter by watchlist membership.
- Risk Level—Filter by severity (Critical, Very High, High, Medium, or Low).
Select Add Filter to apply additional filter criteria, or
select Reset to clear all active filters.
Bulk Actions
When you select one or more rows, the following bulk actions become available:
- Reset
Risk Score—Reset selected users' risk scores back to the ML
baseline.
- Add to Watch List—Add selected users to a watchlist of your choice.
- Remove from Watch List—Remove selected users from a specified watchlist.
Download Users Table
Click on the download button on the far right to download the user details as a CSV
file.