Users Dashboard
Focus
Focus
SaaS Security

Users Dashboard

Table of Contents

Users Dashboard

Explore the Users tab in Behavior Threats to view risky users, risk score distribution, watchlist status, and detailed user-level threat data.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
The Users tab under Behavior Threats is the primary interface for monitoring user risk across your organization. It consolidates risk scores, watchlist membership, and threat incidents into a single view so you can quickly identify and investigate the users who pose the greatest risk. A time-range filter at the top of the page (default: Past 30 Days) controls the data displayed across all panes.
Top 3 Risky Users
The top-left section displays cards for the three users with the highest risk scores. Each card provides an at-a-glance summary:
  • User name—Displayed as a View details link that opens the User Activity Timeline.
  • Risk score—A color-coded circular badge indicating the user's current score and severity level.
  • Watch List—The watchlist(s) the user belongs to, with a count if the user appears on multiple watchlists.
  • Incidents—Total number of threat incidents associated with the user.
  • Risk Trend—A directional indicator showing the score change over the selected time period (for example, "↑ 2 since 1 day ago").
  • Status—The user's current account status (Active or Inactive).
Select View Risky Users to navigate to the full list of users sorted by risk score.
User Risk Score Distribution
The top-right section displays a donut chart showing how your monitored users are distributed across risk levels. The center of the chart shows the total number of monitored users, while the surrounding ring and legend break down the count by severity band:
  • Critical (97–100)
  • Very High (90–96)
  • High (70–89)
  • Medium (50–69)
  • Low (0–49)
Watch List Overview
A collapsible section (toggle: Hide Watch List) displays all configured watchlists as horizontal cards. Each card shows:
  • Watchlist name—Color-coded label identifying the watchlist.
  • Type—A badge indicating whether the watchlist is PREDEFINED (system-defined) or CUSTOM (created by you).
  • User count—Number of users currently on the watchlist.
  • Risk Amplifier—The multiplier applied to risk scores for users on this watchlist (for example, "Risk x 2" or "Risk x 1.5").
  • Users with Incidents—Count of watchlisted users who have active incidents.
Select Add New to create a custom watchlist, or select View All to see the full watchlist management page.
Users Table
The main data table lists all monitored users with their current risk posture. Only users with incidents are listed here. The table includes the following columns:
  • Name—The user's display name, rendered as a link that opens the user's activity timeline.
  • Watch List—Watchlist(s) the user belongs to.
  • Risk Score—The user's current numeric risk score.
  • Risk Level—A color-coded badge (Critical, Very High, High, Medium, or Low).
  • Department—The user's department from your identity provider.
  • Incidents—Total incident count for the user, rendered as a link that open the user's incident page.
  • Last Incident Date—Date of the user's most recent incident.
  • Action—An overflow menu with per-user actions. There are two actions you can take on the specific user: edit the watchlist the user belongs to and reset the risk score.
Filters
A filter bar above the table lets you narrow results using one or more criteria:
  • Search by user name—Free-text search across user display names.
  • Situation—Filter by the behavioral situation or detection type that triggered an incident.
  • Watch List—Filter by watchlist membership.
  • Risk Level—Filter by severity (Critical, Very High, High, Medium, or Low).
Select Add Filter to apply additional filter criteria, or select Reset to clear all active filters.
Bulk Actions
When you select one or more rows, the following bulk actions become available:
  • Reset Risk Score—Reset selected users' risk scores back to the ML baseline.
  • Add to Watch List—Add selected users to a watchlist of your choice.
  • Remove from Watch List—Remove selected users from a specified watchlist.
Download Users Table
Click on the download button on the far right to download the user details as a CSV file.