User Activity Timeline
Focus
Focus
SaaS Security

User Activity Timeline

Table of Contents

User Activity Timeline

Learn how the user activity timeline displays policy violations with their risk impact percentages to explain how a user's risk score changed over time.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
The user activity timeline provides a chronological view of all policy violations that contributed to a user's current risk score. Events are aggregated by policy and displayed in order of recency for the last 90 days by default. This view allows you to understand exactly why a user's risk score changed by examining the specific policy violations, their impact, and how they accumulate over time.
The following walk through uses the user Mark Nelson to illustrate how you can investigate a high-risk user through the activity timeline.
Risk Level Meter
At the top-left of the user detail page, a semicircular gauge displays the user's current risk score and severity level. Mark Nelson's gauge shows a score of 86 (High), color-coded in red. Below the gauge, a risk trend indicator shows the direction and magnitude of the most recent score change (for example, "↑ 1 since 1 day ago"), and a Reset link allows you to reset the user's risk score back to the ML baseline.
User Attributes
A horizontal metadata bar adjacent to the risk meter displays the user's identity attributes pulled from your directory services: Email, Title, Department, Last Activity, Location, Manager, Active Directory Account, Active Directory Group(s), and Cloud Dynamic User Group(s).
Manage CDUG
The Manage CDUG link opens the Dynamic User Group management interface. When you create a CDUG with a defined criteria, users will be automatically added/removed from the group based on that criteria.
Risk Score Trend for Past 90 Days
An area chart below the user attributes shows how the user's risk score evolved over the selected time period. The chart uses color-coded bands to indicate severity thresholds—green for the low-risk zone (0–49), transitioning through yellow and orange for medium and high, up to red for critical scores. For Mark Nelson, the trend shows an initial low-risk period, a sharp spike as policy violations accumulated, a brief decline, and then a sustained climb back to 86 as new violations continued to trigger.
A Past 90 Days drop-down in the top-right corner of the chart lets you adjust the time window to focus on specific periods of interest.
User Event Timeline
The timeline section lists every policy violation that contributed to the user's current score, ordered chronologically (from bottom to top). Each event displays:
  • Date and Timestamp—The UTC time when the violation was detected (for example, "2024-05-01 12:00 AM UTC").
  • Severity Icon—A color-coded square indicating the severity of the event.
  • Policy Name—A clickable link identifying the triggered rule (for example, "High Frequency Activity" or "Data Transfer Spike").
  • Detection Description—A brief description of what the policy detects (for example, "Detect spike in User Activity" or "Detect spike in Data Downloads or Uploads").
  • Severity Level—The severity assigned to this violation (Medium, High, or Critical).
  • Risk Contribution—The percentage this event contributed to the user's overall risk score (for example, "+5.77%" or "+10.03%").
Sample Use Case: How Risk Contribution Builds Over Time
Mark Nelson's timeline demonstrates how incremental policy violations compound into a high risk score. Each event adds a percentage to the overall score based on the policy weight you configured and the severity of the violation. Reading the timeline from earliest to most recent, you can trace the escalation pattern:
DatePolicy ViolatedDetection RuleSeverityRisk Contribution
2026-04-23High Frequency ActivityDetect spike in User ActivityCritical+3.51%
2026-04-25Sustained Bulk Activity BurstDetect bulk User ActivityHigh+1.84%
2026-04-25Data Transfer SpikeDetect spike in Data Downloads or UploadsMedium+2.57%
2026-04-25Abnormal Hours ActivityDetect Abnormal User Activity HoursCritical+1.47%
2026-04-25Unusual Geo-AccessDetect Abnormal Location AccessCritical+2.21%
2026-04-25Off-Hours App Usage SpikeDetect spike in Application UsageHigh+1.47%
2026-04-25Failed Logins SpikeDetect spike in failed loginsMedium+2.57%
2026-04-25Off-Hours App Usage SpikeDetect spike in Application UsageHigh+1.47%
2026-04-28Off-Hours App Usage SpikeDetect spike in Application UsageCritical+1.58%
2026-04-28Abnormal Hours ActivityDetect Abnormal User Activity HoursHigh+1.58%
2026-04-29Sensitive Data AccessDetect User Unusual Accesses to Sensitive DataHigh+4.03%
2026-04-29High Frequency ActivityDetect spike in User ActivityMedium+4.03%
2026-05-02Data Transfer SpikeDetect spike in Data Downloads or UploadsCritical+3.02%
2026-05-02High Frequency ActivityDetect spike in User ActivityCritical+4.32%
2026-05-02Unusual Geo-AccessDetect Abnormal Location AccessHigh+2.59%
2026-05-04High Frequency ActivityDetect spike in User ActivityHigh+4.52%
2026-05-04Data Transfer SpikeDetect spike in Data Downloads or UploadsHigh+3.17%
2026-05-04Bulk Data TransferDetect bulk Data Downloads or UploadsMedium+7.08%
The total risk contribution across all 18 violations over this 12-day period amounts to +53.03%.
The platform computes each contribution by calculating the policy's weight relative to the total weighted score before normalization. As new incidents are created, these percentages adjust dynamically, reflecting the decay logic applied to older events—recent violations carry full weight, while incidents older than 7 days receive progressively reduced impact.
Filters
Two dropdown filters at the top-right of the timeline section help you focus your investigation:
  • Policy—Filter events by a specific policy name to isolate a single detection type (for example, show only Data Transfer Spike events).
  • Severity—Filter events by severity level (Medium, High, or Critical) to focus on the most impactful violations first.
View All Incidents
The View All Incidents link at the top of the timeline section opens the full incidents investigation page filtered to this specific user. This gives you access to additional incident metadata and export options.