> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/documentation/insight/reporting/user-based-risk-report.md).

# User-Based Risk Report

The **User-Based Risk Report** provides a focused view of user-specific incidents, highlighting individuals who may be bypassing policies or engaging in risky behaviour. It helps security teams identify high-risk users, understand their activities and incident patterns, and take timely actions to reduce potential threats across the organisation.

Clicking on an item in the report takes you to the INSIGHT dashboard for deeper investigation. You need to log in to the GuardWare Management Console to access the dashboard. You can customise the report to suit your requirements by choosing what data and users to include, how it is displayed, and how frequently it is sent.&#x20;

## Configure User-Based Risk Report

1. Navigate to ***INSIGHT > User-Based Risk***.
2. ​Click **Configure User-Based Risk Report**.<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FQmYmNjL2oGvX4IITHpsr%2FConfigure%20User-based%20report%20button.png?alt=media&amp;token=65143b45-bb3f-477e-b052-d0cebe84921d" alt=""><figcaption></figcaption></figure>
3. ​In **General**:
   1. ​Enter the email subject.
   2. In **CC**, add valid email addresses for additional recipients, if needed. Separate multiple email addresses with commas.
   3. ​In **Email Start Date**, select the date when the first report will be sent.
   4. ​Enable the **Status.** The report will only be generated if the status is enabled.
   5. ​In **Frequency**, choose how often the report is sent.

      <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FE5491Q0H2ZvNpejo23oP%2FCreate%20User-based%20-%20General.png?alt=media&amp;token=708d9dc4-9ea7-4f15-83a7-2a99ed9043b0" alt=""><figcaption></figcaption></figure>
   6. ​Click **Next**.
4. ​In **Select Users**, search and select the users whose risk activities you want to track in the report and click **Continue**. Only activities related to selected users will be included.<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2F5oOgnqoHGS5FPorc3eCc%2FCreate%20User-based%20-%20Select%20users.png?alt=media&amp;token=1ba9e729-a134-4afa-b794-5e4a3168d7e9" alt=""><figcaption></figcaption></figure>
5. In Select data types, click **Add data types** and select the data types to monitor for this report
6. Click **Continue.**
7. In **Select Risks**, select and configure the risks to include in the report. To configure a risk:
   1. Select a risk from the list and select the **Incident Threshold** and **Data Type Occurrence** **Threshold**.
      1. In **Incident Threshold**, define how many times an incident must occur before the User-based risk report is generated. If the threshold is set to **3**, the report is generated only after an incident matching the selected data type occurs **three times**. If it occurs once or twice, it is recorded, but the report is not generated.
      2. In **Data Type Occurrence** **Threshold**, define how many times the selected data type must appear in a document before it is considered an incident, and the report is triggered.\
         \
         *`Example: For`` `**`Sensitive Files Uploaded to Generative AI Applications`**`, if the selected data type is`` `**`Visa Card Global`**` ``and the`*` `**`Incident Threshold`**` ``is set to 3 files and`` `**`Data Type Occurrence Threshold`**` ``is set to 5, the report is generated only if the uploaded file contains at least 5`` `*`Visa card matches and at least 3 such files (containing at least`*` ``5`` `*`Visa card matches) are uploaded to the AI application.`*&#x20;
      3. For risks associated with time-based activities, the **Duration Threshold** option is displayed in the configuration. Use this setting to define the minimum duration an activity must last before it is considered an incident.

         \
         *`Example: If the selected risk type is Time spent on Generative AI websites and the Duration Threshold is set to 10 minutes or more, a report is generated when a user browses Generative AI websites for 10 minutes or longer.`* \ <br>

         <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FaFvmsMsS2B1frToeNItC%2Fimage.png?alt=media&amp;token=e628486a-2741-4d37-838b-931099279493" alt=""><figcaption></figcaption></figure>

   2. Click **Edit** to customise further.&#x20;

   3. In the **first text editor**, add context and information to help recipients understand the risk. Define the overall alert message displayed at the beginning of the report.<br>

      **Example:** <br>

      ```
      {{numUsers}} user(s) uploaded {{count}} file(s) containing sensitive data to AI applications.
      ```

      \
      In the generated report, this will appear as:

      > 1 user(s) uploaded 21 file(s) containing sensitive data to AI applications.

   4. In the **second text editor (User-level template)**, add the detailed information displayed for each affected user. It can include the user name, number of files, AI applications involved, and the names of uploaded files.<br>

      **Example:**<br>

      ```
      {{user}} - {{count}} file(s).
      AI applications include: {{apps}}.
      Files include: {{files}}
      ```

      \
      In the generated report, this will appear as:<br>

      > JOHNDOE - 21 file(s).\
      > AI applications include: CHATGPT.EXE and CLAUDE.EXE.\
      > Files include: codex.json, icon.png, browser.png, and 16 more.

      \
      ![](https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FpUwSQLoj2Jy2ZksJeFAp%2Fimage.png?alt=media\&token=8b86abc2-6311-46d1-aafa-c42f69a64ec2)<br>

   5. Click **Save Configuration**, then click **Continue**.
8. In **Customise**, customise the appearance and content of the email report.
   1. In **Cover Image**, upload an image in PNG, JPG, or GIF format, up to 5 MB, to personalise the report.
   2. In **Introductory Message**, add or edit the content that will appear at the top of the email.&#x20;
   3. In **Footer Template**, add or edit the footer content displayed at the bottom of the email report.
   4. In **Privacy Template**, add or edit the privacy statement or disclaimer included at the bottom of the email report.<br>

      <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FVy4ZJ9iXDTdTOLcJC4G7%2FCreate%20User-based%20-%20Customise.png?alt=media&amp;token=dcfd6775-a3f3-4fb9-917f-7be0701dfb85" alt=""><figcaption></figcaption></figure>
9. After completing all steps, click **Save**. The report will be generated and sent based on the defined criteria and schedule.
10. You can also send a test email to a specified email address to preview how the report appears to recipients. To send a test email:
    1. In **Email to**, select or add the email address.
    2. Click **Send Test Email**.<br>

       <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FBnBMBFT2gaek0HN6sYkj%2FCreate%20SASI%20-%20Send%20test%20email.png?alt=media&amp;token=7f14ae4a-4d41-4b5f-9c33-cf32fff04899" alt=""><figcaption></figcaption></figure>

## View User-Based Risk Report Details

You can view the User-Based Risk Report email that was sent to users.

1. Navigate to ***INSIGHT > User-Based Risk***.
2. Click **View Details** in the **ACTION** column.<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FYqf3SETX3iVyai46VgmQ%2FView%20User-based%20report.png?alt=media&amp;token=e00f42bf-c43b-49fe-a377-a4986d00a131" alt=""><figcaption></figcaption></figure>
3. In the **ACTION** column, click **View Email**.<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FdrFKijP6CDy8KowxjT1p%2FView%20email%20User-based%20report.png?alt=media&amp;token=e1415db7-1a39-4880-b8b8-bfa6f825a0f1" alt=""><figcaption></figcaption></figure>

## Edit User-Based Risk Report

1. Navigate to ***INSIGHT > User-Based Risk***.
2. Click **Edit Report** in the **ACTION** column.<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FIW3W0uhoNBBuzaAckBAC%2FEdit%20User-based%20report.png?alt=media&amp;token=e8cd2a2a-89f5-4f41-bc75-930e45e1776d" alt=""><figcaption></figcaption></figure>
3. Update the necessary information and click **Update Report**.

## Delete User-Based Risk Report

1. Navigate to ***INSIGHT > User-Based Risk***.
2. Click the **Delete** icon in the **ACTION** column.<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FHJMBYoR9cEJfIFeCvGHU%2FDelete%20User-based%20report.png?alt=media&amp;token=b871f893-d7cb-4c8b-8ba8-a9e94afa0c78" alt=""><figcaption></figcaption></figure>
3. Click **Yes, delete** in the confirmation box.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/documentation/insight/reporting/user-based-risk-report.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
