# Risk Events

The **Risk Events** page is the finding-level log: every policy finding across recently analyzed sessions. Open it from **Secure > Risk Events** in the dashboard.

## Access requirements

<Callout type="info">
  Viewing this page requires the `org:admin` scope. Access is included in the [default Admin role](/docs/ai-control-plane/org-admin/roles-and-permissions) but not the Member role.
</Callout>

## Event list

Each finding shows its timestamp, category, severity, rule, session name, user, matched content, and the policy that raised it. The list loads continuously with a running count of findings shown.

Filters narrow the stream:

- **Policy** — including inactive policies, which are labeled and produce a notice
- **Date range**
- **Rule ID** — autocompleted from rules with recent findings
- **User**
- **Unique matches only**
- **Assistant** — including sessions with no assistant

## Redaction and reveal

Matched content is redacted by default. Individual matches can be revealed inline, and a **Reveal all** toggle in the header switches the whole view. Findings from natural-language guardrails open a match dialog with the evaluated content.

## Investigating a finding

Clicking a finding opens the session detail in a risk-focused view — the same transcript panel as [Agent Sessions](/docs/ai-control-plane/observe/agent-sessions), with flagged messages highlighted and unflagged messages dimmed. Each finding also has a copyable share link for handing an investigation to a teammate.
