Secure · Risk Events
Risk Events
Review individual policy findings across analyzed agent sessions, with redacted matches and full-session investigation.
The Risk Events page is the finding-level log: every policy finding across recently analyzed sessions, one row per finding. Open it from Secure > Risk Events in the dashboard.
Where Watchdog clusters findings into ranked signals for triage, Risk Events lists the raw findings themselves — useful for auditing individual matches, tracking down a specific rule or user, or handing a single finding to a teammate.
Access requirements
Section titled “Access requirements”Viewing this page requires the org:admin scope. Access is included in the default Admin role but not the Member role.
Event list
Section titled “Event list”Each finding shows its timestamp, category, severity, rule, session name, user, matched content, and the guardrail policy that raised it. The list loads continuously with a running count of findings shown.
Filters narrow the stream. Policy and Date range are always visible, and the rest live behind More filters:
- Policy — including inactive policies, which are labeled and produce a notice
- Date range
- Rule ID — matches rule IDs containing the entered text
- User
- Unique matches only
- Assistant — including sessions with no assistant
Redaction and reveal
Section titled “Redaction and reveal”Matched content is redacted by default. Individual matches can be revealed inline, and a Reveal all toggle in the header switches the whole view. Findings from natural-language guardrails open a match dialog with the evaluated content.
Investigating a finding
Section titled “Investigating a finding”Clicking a finding opens the session detail in a risk-focused view — the same transcript panel as Agent Sessions, with flagged messages highlighted and unflagged messages dimmed. Each finding also has a copyable share link for handing an investigation to a teammate.