Entity Risk Score Override

The Entity Risk Override is a per-entity multiplier that applies a final adjustment to the risk contribution of all detections associated with that entity. It allows administrators to express organizational context that cannot be captured by peer group membership alone — for example, elevating the risk weight for a specific privileged administrator or reducing it for a known-safe automation account.

Note: Setting or changing an override, individually or in bulk, requires the Manage Entities permission. This permission is not limited to Organization Administrators — any role granted it can set overrides. For details, see Managing Roles.

Using Override Range and Defaults

The override range is 0.1 to 2.0 with a precision of two decimal places. The default value for all new entities is 1.0 (neutral). At 1.0, the override has no effect on the calculated risk. Values above 1.0 increase the risk contribution; values below 1.0 reduce it.

The override is applied after the peer group weighted average modifier in the risk formula:

Raw Detection Risk = Base Risk (1–5) × Peer Group Weighted Average Modifier × Entity Override

See Entity Risk Scores for the full formula and worked examples.

Understanding When to Override

Override values above 1.0 are appropriate for entities where the same detection carries higher risk than it would for a typical member of the group. Examples include:

  • Executives and privileged administrators whose accounts are high-value targets.

  • Entities under active investigation where temporary risk elevation is warranted.

Override values below 1.0 are appropriate for entities where expected detection volume or known-safe behavior would otherwise produce misleading scores. Examples include:

  • Approved automation accounts or service accounts with predictable, high-volume activity.

  • Test systems or sandbox environments generating expected detection patterns.

Setting an Override from the Entity Detail Page

Overrides can be set for individual entities from the entity detail page.

To set an override from the entity detail page:

  1. On the left navigation bar, click Entity Management > Entities.

  2. Open the entity detail page for the identity or asset. See Viewing Identity Details or Viewing Asset Details.

  3. Click the Risk Score tab.

  4. In the Entity Risk Override section, adjust the slider to the desired value.

  5. Click Save Override to apply.

The override takes effect on the next risk calculation cycle.

Setting an Override

Overrides can be applied to an entity from the Identities or Assets list, as follows:

  1. On the left navigation bar, click Entity Management > Entities.

  2. Open the entity detail page for the identity or asset.

  3. Click the Risk Score tab.

  4. In the Entity Risk Override section, adjust the slider to the desired value.

  5. Click Save Override to apply.

See Managing Identities and Managing Assets for more information on bulk actions.

Leveraging Audit and History

All override changes are recorded in the History tab of the entity with the previous value, new value, timestamp, and the administrator who made the change. Override changes are immutable audit records and cannot be deleted.

To review the override history for an entity, open the entity detail page and click the History tab. Filter by Actions to show override changes only.

To ensure efficient performance, this tab shows the last seven days of data and the most recent 100 records.