Risk Amplifier
Focus
Focus
SaaS Security

Risk Amplifier

Table of Contents

Risk Amplifier

Learn how to increase or decrease a user's risk impact using the risk amplifier from the watchlist detail panel.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
Each watchlist in Behavior Threats has a configurable risk amplifier that multiplies the impact of policy violations on the risk scores of users in that watchlist. By adjusting the risk amplifier, you can increase or decrease the risk impact for an entire group of users based on their role or context within your organization.
How Risk Amplifiers Work
The risk amplifier acts as a multiplier on the weighted score contributions from policy violations. A higher amplifier causes each policy violation to contribute more heavily to the user's overall risk score, making it easier to surface threats from high-priority personas during triage.
  • An amplifier greater than 1.0 increases the user's risk impact—policy violations weigh more heavily on their score.
  • An amplifier less than 1.0 reduces the user's risk impact—policy violations weigh less heavily on their score.
  • An amplifier of 1 (default) applies no additional amplification—the user's score is calculated using standard weights only.
Configuring the Risk Amplifier
To configure the risk amplifier for a specific watchlist:
  1. Select Behavior ThreatsUsersWatch ListView All.
  2. Click on the watchlist for which you want to edit the risk amplifier.
  3. In the Watchlist Settings page, modify the risk amplifier as per your need and Save.
Conflict Resolution
A user can belong to multiple watchlists simultaneously. When this occurs, the system automatically applies the risk amplifier from the watchlist with the highest value. This ensures that the most conservative risk posture is always enforced without requiring manual intervention.
Changes to risk amplifier values are recorded in the platform's audit logs for compliance tracking.