Watchlists
Focus
Focus
SaaS Security

Watchlists

Table of Contents

Watchlists

Learn about watchlists in Behavior Threats and how risk amplifiers elevate risk scoring for high-priority user groups.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
Watchlists in Behavior Threats® allow you to group and monitor users who represent elevated risk to your organization. By assigning a risk amplifier to each watchlist, you increase the weight applied to a user's risk score, ensuring that high-priority personas receive proportionally higher scrutiny when policy violations occur.
Transition from Legacy Watchlist
If you previously used the legacy watchlist feature, all users from your existing watchlist are automatically migrated to the High Risk Users predefined watchlist in a disabled state with a default risk amplifier of 1. You can enable this watchlist and adjust its settings at any time.
By default, four predefined out-of-the-box watchlists are provided. The platform supports creating a maximum of 6 custom watchlists per tenant.
Predefined Watchlists
Behavior Threats includes the following four predefined watchlists that target common high-risk personas:
  • Departing Users—Employees who have tendered their resignation or are in the process of leaving the organization. These users pose elevated data exfiltration risk.
  • High Exec—Senior executives and leadership whose accounts, if compromised, could cause significant organizational damage.
  • Vendors—Third-party contractors or vendors with time-bound or limited access who may not be subject to the same internal controls as full-time employees.
  • High Risk Users—Users who have previously exhibited risky behavior or have been flagged for investigation.
By default, you have to add users to all the watchlists manually. You can enable or disable any predefined watchlist and modify its status, user list and risk amplifier. However, you cannot delete them.
Custom Watchlists
In addition to the predefined watchlists, you can create a maximum of six custom watchlists tailored to your organization's risk profile. You can create, edit, and delete custom watchlists as needed.
Risk Amplifiers
Each watchlist has a configurable risk amplifier that multiplies the impact of policy violations on the risk scores of users in that group. If a user belongs to multiple watchlists (for example High Exec), only the highest amplifier among those watchlists applies to their score.
To create, edit, or delete watchlists and manage their users, see Manage Watchlists.