Skip to content

Signal Glossary

Definitions of the raw signals (variables) that feed the Praxis Navigator analytics indicators, including their Microsoft Graph source.

Updated View as Markdown

Each entry is a raw signal (variable) that feeds one or more indicators. Definitions are customer-safe and, where the signal originates in Microsoft Graph, link to Microsoft’s own documentation. Follow a term’s Used by links to see which indicators consume it.

Email

  • After Hours Volume — Count of emails whose timestamp falls outside configured business hours.
  • Attachment Summary — Structured summary of attachment metadata across a user's email activity, covering count, size, and attachment type categories.
  • Attachment Type Count — Map of attachment file types (or extensions) to their count, across all emails processed.
  • CC Read Ratio — Proportion of CC'd emails that the user has read.
  • Cloud Sharing Ratio — Proportion of all attachments that are cloud links (OneDrive / SharePoint reference attachments) rather than file attachments.
  • Direct Read Ratio — Proportion of emails addressed directly to the user (To:) that the user has read.
  • External Attachment Ratio — Proportion of attachment-bearing sent emails that went to external recipients, out of all attachment-bearing sent emails.
  • External Ratio — Proportion of received emails from senders outside the organization's domains.
  • Flag Rate — Proportion of received emails the user has flagged for follow-up.
  • Junk Open Rate — Proportion of junk emails the user has opened, out of all junk emails processed.
  • Junk Restore Rate — Proportion of opened junk emails that the user moved back to their inbox ("restored"), signalling the user believed the message was legitimate.
  • Num Attachments Sent External — Count of sent emails that had at least one external recipient and were flagged as having attachments.
  • Num Attachments Sent Internal — Count of sent emails where every recipient was internal and the email was flagged as having attachments.
  • Num Conversations — Count of distinct email conversation threads (unique conversationId values) in the period.
  • Num External — Count of received emails whose sender domain is outside the configured organisation domains.
  • Num Flagged — Count of emails the user has flagged for follow-up.
  • Num Junk — Total count of emails in the user's Junk Email folder as of the processing date.
  • Num Junk Read — Count of junk-folder emails that were opened or read.
  • Num Junk Restored To Inbox — Count of junk emails inferred to have been moved back into the inbox by the user.
  • Num Junk Unread — Count of junk emails that were present in the junk folder and not opened by the user.
  • Num Phish Sim Opened — Count of phishing simulation emails the user opened (marked as read).
  • Num Phish Sim Received — Count of emails received that were identified as phishing simulation test messages sent by the organization's security awareness training vendor.
  • Num Read — Count of emails in the user's inbox that have been marked as read.
  • Num Read CC — Count of emails where the user was in the CC: field that the user has read.
  • Num Read Direct — Count of emails where the user was in the To: field that the user has read.
  • Num Received — Count of email records treated as received inbox messages for the user in the period.
  • Num Received CC — Count of received emails where the user appeared in the CC: field.
  • Num Received Direct — Count of received emails where the user appeared in the To: field.
  • Num Security Read — Count of security notification emails the user has opened.
  • Num Security Received — Count of received emails identified as coming from recognized security senders (security notification domains).
  • Num Sent — Count of emails sent by the user in the period.
  • Num Sent External — Count of sent emails that had at least one recipient outside the organisation's domains.
  • Num Sent Internal — Count of sent emails where every recipient was inside the organisation's domains.
  • Num Unread — Count of emails in the user's inbox that have not been marked as read.
  • Phish Sim Open Rate — Proportion of phishing simulation emails the user opened, out of all phishing simulation emails received.
  • Phish Sim Vendor — Name of the phishing simulation vendor detected from email headers, if any simulation emails were found.
  • Read Rate — Proportion of inbox emails the user has read out of all inbox emails (read + unread).
  • Reply Latency — Average of positive sent-minus-received time differences (in hours) for records where both timestamps exist.
  • Security Read Gap — Difference between how attentive the user is to security emails versus their overall email read rate. Positive = reads security emails more than average; negative = ignores security emails.
  • Security Read Rate — Proportion of security notification emails the user has opened.
  • Sent External Ratio — Proportion of sent emails that went to at least one recipient outside the organization, out of all sent emails (internal + external).

Security

  • Alerts High — Count of high-severity security alerts attributed to this user on the processed date.
  • Alerts In Progress — Count of security alerts attributed to this user that are actively being investigated.
  • Alerts Informational — Count of informational-severity security alerts attributed to this user on the processed date.
  • Alerts Low — Count of low-severity security alerts attributed to this user on the processed date.
  • Alerts Medium — Count of medium-severity security alerts attributed to this user on the processed date.
  • Alerts New — Count of security alerts attributed to this user that are in "new" (unacknowledged) status.
  • Alerts Resolved — Count of security alerts attributed to this user that have been resolved.
  • Category List — Sorted list of distinct attack category strings from the security alerts attributed to this user on the processed date.
  • Resolution Rate — Proportion of security alerts attributed to this user that have been resolved.
  • Total Alerts — Total count of security alerts attributed to this user on the processed date, across all severity levels.
  • Unique Categories — Count of distinct attack category types present among the security alerts attributed to this user on the processed date.
  • Vendor Providers — Map of alert provider names to the count of alerts they generated for this user on the processed date.
  • Weighted Severity Score — Raw numeric sum of severity weights across all security alerts attributed to this user, before normalization. Higher values mean more severe or more numerous alerts.

Overview

  • Baseline Delta Direction — How much each indicator's current value has moved relative to that user's own historical baseline, expressed as both an absolute number and a percentage — aggregated across all users and rolled up to min/max/mean statistics at the org or service level.
  • Client Side Org Aggregates — Org-level summary statistics computed in the browser from the loaded daily risk timeline — total days loaded, how many were critical or high-risk, the average risk level over the window, and the current trend direction.
  • Risk Overview Stat Descriptors — A set of distribution statistics (mean, median, standard deviation, percentiles, etc.) computed across all risk indicator values within a service category or across the whole organisation for a given day or window.
  • Risk Persistence — How many distinct calendar days in the loaded window contained at least one critical or high-severity indicator for a given employee — distinguishing a one-off spike from a sustained behavioural pattern.
  • Severity Distribution — For each indicator type seen on an employee, a count of how many occurrences fell into each severity bucket (critical / high / medium / low) across the loaded time window.
Navigation

Type to search…

↑↓ navigate↵ selectEsc close