Skip to content
Platform Status

Secure

Risk Overview

The Risk Overview page summarizes risk analysis across agent sessions for the selected time range. Open it from Secure > Risk Overview in the dashboard.

Viewing this page requires the org:admin scope. Access is included in the default Admin role but not the Member role.

Four cards summarize policy activity:

  • Events Scanned — session events analyzed by active policies
  • Findings — policy findings raised
  • Flagged Sessions — sessions containing at least one finding
  • Active Policies — policies currently scanning

The time range picker supports presets from 15 minutes to 30 days, custom ranges, and drag-to-zoom directly on charts.

The Policy Activity section ranks where risk concentrates:

  • Top Risk Events by Category — which detector categories fire most
  • Top Risk Events by Rule — the specific rules behind findings
  • Users with Most Findings — members whose sessions trigger findings

Each list links to a full view, and drill-down pages break findings down by user, category, and rule. A Risk Events over Time chart shows the trend for the selected range.

Two shortcuts jump into investigation: View Sessions with Risk opens Agent Sessions filtered to flagged sessions, and View All Events opens Risk Events.

With no active policies and no scan history, the page prompts to create a first policy with a Manage Policies button. If policies exist but all are disabled, a banner calls that out.