Each entry is a raw signal (variable) that feeds one or more indicators. Definitions are customer-safe and, where the signal originates in Microsoft Graph, link to Microsoft’s own documentation. Follow a term’s Used by links to see which indicators consume it.
- After Hours Volume — Count of emails whose timestamp falls outside configured business hours.
- Attachment Summary — Structured summary of attachment metadata across a user's email activity, covering count, size, and attachment type categories.
- Attachment Type Count — Map of attachment file types (or extensions) to their count, across all emails processed.
- CC Read Ratio — Proportion of CC'd emails that the user has read.
- Cloud Sharing Ratio — Proportion of all attachments that are cloud links (OneDrive / SharePoint reference attachments) rather than file attachments.
- Direct Read Ratio — Proportion of emails addressed directly to the user (To:) that the user has read.
- External Attachment Ratio — Proportion of attachment-bearing sent emails that went to external recipients, out of all attachment-bearing sent emails.
- External Ratio — Proportion of received emails from senders outside the organization's domains.
- Flag Rate — Proportion of received emails the user has flagged for follow-up.
- Junk Open Rate — Proportion of junk emails the user has opened, out of all junk emails processed.
- Junk Restore Rate — Proportion of opened junk emails that the user moved back to their inbox ("restored"), signalling the user believed the message was legitimate.
- Num Attachments Sent External — Count of sent emails that had at least one external recipient and were flagged as having attachments.
- Num Attachments Sent Internal — Count of sent emails where every recipient was internal and the email was flagged as having attachments.
- Num Conversations — Count of distinct email conversation threads (unique conversationId values) in the period.
- Num External — Count of received emails whose sender domain is outside the configured organisation domains.
- Num Flagged — Count of emails the user has flagged for follow-up.
- Num Junk — Total count of emails in the user's Junk Email folder as of the processing date.
- Num Junk Read — Count of junk-folder emails that were opened or read.
- Num Junk Restored To Inbox — Count of junk emails inferred to have been moved back into the inbox by the user.
- Num Junk Unread — Count of junk emails that were present in the junk folder and not opened by the user.
- Num Phish Sim Opened — Count of phishing simulation emails the user opened (marked as read).
- Num Phish Sim Received — Count of emails received that were identified as phishing simulation test messages sent by the organization's security awareness training vendor.
- Num Read — Count of emails in the user's inbox that have been marked as read.
- Num Read CC — Count of emails where the user was in the CC: field that the user has read.
- Num Read Direct — Count of emails where the user was in the To: field that the user has read.
- Num Received — Count of email records treated as received inbox messages for the user in the period.
- Num Received CC — Count of received emails where the user appeared in the CC: field.
- Num Received Direct — Count of received emails where the user appeared in the To: field.
- Num Security Read — Count of security notification emails the user has opened.
- Num Security Received — Count of received emails identified as coming from recognized security senders (security notification domains).
- Num Sent — Count of emails sent by the user in the period.
- Num Sent External — Count of sent emails that had at least one recipient outside the organisation's domains.
- Num Sent Internal — Count of sent emails where every recipient was inside the organisation's domains.
- Num Unread — Count of emails in the user's inbox that have not been marked as read.
- Phish Sim Open Rate — Proportion of phishing simulation emails the user opened, out of all phishing simulation emails received.
- Phish Sim Vendor — Name of the phishing simulation vendor detected from email headers, if any simulation emails were found.
- Read Rate — Proportion of inbox emails the user has read out of all inbox emails (read + unread).
- Reply Latency — Average of positive sent-minus-received time differences (in hours) for records where both timestamps exist.
- Security Read Gap — Difference between how attentive the user is to security emails versus their overall email read rate. Positive = reads security emails more than average; negative = ignores security emails.
- Security Read Rate — Proportion of security notification emails the user has opened.
- Sent External Ratio — Proportion of sent emails that went to at least one recipient outside the organization, out of all sent emails (internal + external).
Security
- Alerts High — Count of high-severity security alerts attributed to this user on the processed date.
- Alerts In Progress — Count of security alerts attributed to this user that are actively being investigated.
- Alerts Informational — Count of informational-severity security alerts attributed to this user on the processed date.
- Alerts Low — Count of low-severity security alerts attributed to this user on the processed date.
- Alerts Medium — Count of medium-severity security alerts attributed to this user on the processed date.
- Alerts New — Count of security alerts attributed to this user that are in "new" (unacknowledged) status.
- Alerts Resolved — Count of security alerts attributed to this user that have been resolved.
- Category List — Sorted list of distinct attack category strings from the security alerts attributed to this user on the processed date.
- Resolution Rate — Proportion of security alerts attributed to this user that have been resolved.
- Total Alerts — Total count of security alerts attributed to this user on the processed date, across all severity levels.
- Unique Categories — Count of distinct attack category types present among the security alerts attributed to this user on the processed date.
- Vendor Providers — Map of alert provider names to the count of alerts they generated for this user on the processed date.
- Weighted Severity Score — Raw numeric sum of severity weights across all security alerts attributed to this user, before normalization. Higher values mean more severe or more numerous alerts.
Overview
- Baseline Delta Direction — How much each indicator's current value has moved relative to that user's own historical baseline, expressed as both an absolute number and a percentage — aggregated across all users and rolled up to min/max/mean statistics at the org or service level.
- Client Side Org Aggregates — Org-level summary statistics computed in the browser from the loaded daily risk timeline — total days loaded, how many were critical or high-risk, the average risk level over the window, and the current trend direction.
- Risk Overview Stat Descriptors — A set of distribution statistics (mean, median, standard deviation, percentiles, etc.) computed across all risk indicator values within a service category or across the whole organisation for a given day or window.
- Risk Persistence — How many distinct calendar days in the loaded window contained at least one critical or high-severity indicator for a given employee — distinguishing a one-off spike from a sustained behavioural pattern.
- Severity Distribution — For each indicator type seen on an employee, a count of how many occurrences fell into each severity bucket (critical / high / medium / low) across the loaded time window.