Secure
Risk Events
The Risk Events page is the finding-level log: every policy finding across recently analyzed sessions. Open it from Secure > Risk Events in the dashboard.
Access requirements
Section titled “Access requirements”Viewing this page requires the org:admin scope. Access is included in the default Admin role but not the Member role.
Event list
Section titled “Event list”Each finding shows its timestamp, category, severity, rule, session name, user, matched content, and the policy that raised it. The list loads continuously with a running count of findings shown.
Filters narrow the stream:
- Policy — including inactive policies, which are labeled and produce a notice
- Date range
- Rule ID — autocompleted from rules with recent findings
- User
- Unique matches only
- Assistant — including sessions with no assistant
Redaction and reveal
Section titled “Redaction and reveal”Matched content is redacted by default. Individual matches can be revealed inline, and a Reveal all toggle in the header switches the whole view. Findings from natural-language guardrails open a match dialog with the evaluated content.
Investigating a finding
Section titled “Investigating a finding”Clicking a finding opens the session detail in a risk-focused view — the same transcript panel as Agent Sessions, with flagged messages highlighted and unflagged messages dimmed. Each finding also has a copyable share link for handing an investigation to a teammate.