Skip to content
Platform Status

Secure

Risk Events

The Risk Events page is the finding-level log: every policy finding across recently analyzed sessions. Open it from Secure > Risk Events in the dashboard.

Viewing this page requires the org:admin scope. Access is included in the default Admin role but not the Member role.

Each finding shows its timestamp, category, severity, rule, session name, user, matched content, and the policy that raised it. The list loads continuously with a running count of findings shown.

Filters narrow the stream:

  • Policy — including inactive policies, which are labeled and produce a notice
  • Date range
  • Rule ID — autocompleted from rules with recent findings
  • User
  • Unique matches only
  • Assistant — including sessions with no assistant

Matched content is redacted by default. Individual matches can be revealed inline, and a Reveal all toggle in the header switches the whole view. Findings from natural-language guardrails open a match dialog with the evaluated content.

Clicking a finding opens the session detail in a risk-focused view — the same transcript panel as Agent Sessions, with flagged messages highlighted and unflagged messages dimmed. Each finding also has a copyable share link for handing an investigation to a teammate.