Understanding Peer Groups

The Peer Groups page lists all groups in your organization in a scrollable panel on the left. Selecting a group displays its details on the right, including member counts, subgroups, and the current Risk Score Multiplier. You can browse and configure any group without leaving the page.

Using the Group List Panel

The left panel lists all peer groups available in your organization. It includes the following controls:

  • All / Custom toggle—switches the list between all groups and custom-only groups.

  • Search groups—filters the list by group name as you type.

  • Create—opens the Create Custom Peer Group modal. See Creating Custom Peer Groups for more information.

Each entry in the list shows the group name, a Custom badge if the group was created in the platform, the member count, and the current Risk Score Multiplier value. The currently selected group is highlighted in the list.

Using the Group Detail Panel

The right panel displays the full detail for the selected group, including three stat cards and sections for subgroups and members.

The header of the detail panel shows the group name, the source badge (for example, Active Directory), and the group description.

The three stat cards are:

  • Members—the total count of entities in the group.

  • Subgroups—the count of direct child groups.

  • Risk Score Multiplier—the current multiplier value with a pencil (edit) icon. See Configuring the Risk Score Multiplier.

For custom groups, a + Add Subgroup button is visible at the top right of the detail panel. See Creating Custom Peer Groups for more information.

Understanding Subgroups

When a group has child groups, a Subgroups section appears below the stat cards. Subgroups are displayed as a two-column grid of clickable cards. Each card shows the subgroup name and member count. Clicking a subgroup card navigates to that subgroup detail in the panel.

Understanding Members

The Members section displays the entities in the group, organized into two tabs. Each tab label includes the current member count, for example, Users (3) and Assets (12).

The Users tab lists identity members along with information about Name, Email, Risk Score, Source, Status, and Groups.

The Assets tab lists asset members along with information about : Hostname, IP Address, Risk Score, Source, Status, and Groups.

Entity names in both tables are clickable links that open the entity detail flyout or full page.

Configuring the Risk Score Multiplier

Both IDP-sourced and custom groups support Risk Score Multiplier configuration. To configure the multiplier for a group, click the edit icon () on the Risk Score Multiplier stat card.

Note: Configuring the multiplier requires the Manage Entities permission. Viewing peer groups and their current multiplier requires View Entities permission or higher. See Managing Roles for more information.

The modal includes a description of the multiplier effect on risk scoring and a slider for setting the value. The slider range is 0.1 to 2.0. Click Save to apply the change, or Cancel to discard it.

Multiplier changes take effect on the next risk calculation cycle for all member entities. All changes are recorded in the audit log.

See Entity Risk Scores for more information on how the multiplier factors into risk calculations.