The analytics knowledge base explains every indicator and composite Praxis Navigator reports, what each one can and cannot tell you, and the raw signals they are built from. Indicators and composites are pages; the underlying variables live in the signal glossary.
Overview
- Department Risk AggregationA ranked list of departments sorted by their average risk level over a time window, showing how risk is distributed across the organisation's teams.
- Overall Risk CompositeA single 0–100 risk number for one employee that represents their overall risk level for a given day, combining all indicators from all service categories with extra weight given to the most severe events.
- After Hours ActivityMeasures how much of a user's email activity happens outside normal working hours, compared with their own typical recent pattern.
- Attachment RiskWhether the user's attachment patterns include security-sensitive file types, unusually high attachment volume, or unusually large average attachment size.
- Behavior ConsistencyHow much this user's directly observable email behaviours have shifted from their personal 30-day norm, expressed as an average % deviation across four dimensions.
- Cloud Sharing BehaviorWhether the user's email attachment activity relies heavily on OneDrive / SharePoint cloud links, and whether that pattern has changed unusually from their recent baseline.
- Email ActivityA contextual summary of how actively this user is engaging with their inbox (read rate) and how much outbound email activity they are generating (sent volume). This is a descriptive signal, not a direct risk indicator.
- Email Attention MetricsWhat proportion of emails addressed directly to the user (and CC'd emails) the user has read.
- Email DisciplineA simple summary of whether the user tends to read their email and use message flagging, expressed as an inbox management signal.
- Email ServiceA single summary score for email-related risk, emphasising the most extreme underlying email indicator for this user on this day.
- External Communication RiskHow much of the user's received email is from external senders, and whether that proportion is unusually high relative to their own recent baseline.
- Flag BehaviorWhether this user's flagging behaviour is anomalously high or low relative to their own 30-day baseline. Flagging is treated as an attentiveness proxy — it requires the user to actively interact with a message.
- Junk Email BehaviorWhether the user opens junk email and whether they restore junk messages back into the inbox, framed as a security-awareness signal.
- Phishing AwarenessWhether the user opens phishing simulation emails sent as part of a security awareness training programme. A user who opens simulations scores higher risk.
- Received Volume AnomalyFlags when a user receives an unusually high or low number of emails compared with their own typical recent pattern. This is context, not a risk in itself.
- Security Email AttentionWhether the user reads security-related emails proportionally to how they read general mail. A user who ignores security emails relative to their normal reading habits scores higher risk.
- Sent External RiskWhat proportion of the user's sent email and sent attachments go to external recipients, and whether that pattern is unusually high relative to their own recent baseline.
- Sent Volume AnomalyFlags when a user sends an unusually high or low number of emails compared with their own typical recent pattern.
- Temporal Behavior AnomalyWhether the user's recent email timing — such as after-hours activity or reply speed — differs unusually from their own recent pattern.
- Volume AnomalyWhether this user's sending or receiving volume is unusually high or low relative to their own recent history.
Identity
- Account Change VelocityHow many attribute changes have occurred on this account recently, with extra weight on new and deleted accounts.
- Account Hygiene ScoreA composite score reflecting the state of a user's account across key hygiene dimensions: whether the account is disabled, unlicensed, a guest, lacks department or title, or is newly created.
- Guest Domain RiskFor guest accounts, a fixed risk score based on the classification of their email domain; member accounts score 0.
- Hygiene Health RollupA percentage showing what share of users in a group — Employees, External guests, or all users combined — have no active identity hygiene issues flagged against them.
- IdentityA summary of account hygiene and identity governance risk signals for this user, with extra emphasis on the riskiest underlying identity issue.
- License Gap RiskA risk score reflecting whether this account lacks Microsoft licences, weighted by how long the account has existed without them.
- Special Account RiskWhether this account has special characteristics — breakglass, admin-titled but unlicensed — that carry elevated governance risk.
Security Posture
- Defender Email CoverageWhether the customer's tenant has Microsoft Defender for Office 365 email threat analysis active and accessible.
- Defender Identity CoverageWhether the customer's tenant has Microsoft Defender for Identity active and accessible.
- Defender Incident CoverageWhether the customer's tenant has Microsoft Defender incident management active and accessible.
- Defender XDR CoverageWhether the customer's tenant has Microsoft Defender XDR (threat detection and response) active and accessible.
- Security PostureWhether the customer's tenant has the key Microsoft Defender security services provisioned and active, expressed as a single coverage gap score. Higher score = more coverage gaps.