Repository navigation
Document Entity Risks rename, user identity grouping, and rollup notifications - #40114
Merged
jenny-park-dd merged 19 commits intoOct 7, 2026
Merged
Conversation
Rename Risk Insights to Entity Risks across the Cloud SIEM docs, and update the app link to the new route. Add a "Risk grouped by user identity" section covering identity provider sync through the Entity Pack, the rolled-up risk score, and expanding a user identity row to investigate the entities beneath it. Add a "Group risk by" step to the notification flow, and a "Notify on rolled-up user identity risk" section describing user attribute matching, conditions evaluated against the rolled-up score, threshold-crossing behavior, message content, and the User Inventory link. Note that the existing entity severity thresholds also apply to a user identity's rolled-up risk score. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Contributor
Add a note to the Overview stating that Entity Risks was previously known as Risk Insights, so readers arriving from older links or search results can confirm they are on the right page. Rename the left-nav entry from Risk Insights to Entity Risks in the English and Korean menus. The Spanish, French, and Japanese menus translate this entry, so they are left for localization rather than renamed here. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Move the Entity Pack from an optional prerequisite to a recommended one, and say what configuring it changes: entities resolve into a single user identity with a rolled-up risk score, and user identity notifications become available. Note the consequence of skipping it, so the choice is clear. Add the user identity view to the Overview capability list, and widen the notifications entry to cover alerting on people as well as entities. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Use the singular "Create a new Entity Risk notification" for the page name, to match the product. Point the settings reference at /security/configuration/siem/entity-risks, which moved with the rename. Document the score scales the two groupings use, since that is what determines a workable threshold: individual entity scores typically range from 0 to 500, while rolled-up user identity scores are unbounded. Split several long sentences and avoid "Create a new" per the style guide. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Remove the statement that individual entity scores typically range from 0 to 500, which does not reliably hold, and the claim that rolled-up scores need higher thresholds. Each option now describes only what the rule measures. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The previous screenshot dated from June 2025 and no longer matched the product: it carried a Risk Insights promotional banner, an older navigation bar, the singular filter labels, an entity count instead of a risk count, and the former column names. It also predated grouping, so it could not show a user identity row. Update the alt text to describe the grouped view the new capture shows. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The previous screenshot showed the section header "What contributes to the score?", which the page text no longer uses, and did not show the View All Related Signals control the text refers to. The new capture shows the Risk Contributors tab and section, so the text and the image agree again. Update the alt text to name the two sections the surrounding text describes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The entity side panel no longer has a Next steps section. Triage state, assignment, security cases, incidents, and suppressions are now inline actions in the Risk Contributors section, so describe them there and list them. Remove the accompanying screenshot, which showed the Next steps panel. The image file itself is kept, because the Spanish translation still references it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The previous capture titled the panel "Risk Insights" and labelled its link "View Risk Insights", which contradicted the renamed section heading. The new capture shows the renamed panel. Add alt text, which was previously empty. Keep the old image file, because the Spanish translation still references it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Pre-existing style error on a line this branch already touches. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
jenny-park-dd
marked this pull request as ready for review
October 5, 2026 19:43
Contributor
|
@jenny-park-dd These updates look good to me. Thank you for putting them together. |
janine-c
approved these changes
Oct 6, 2026
janine-c
left a comment
Collaborator
There was a problem hiding this comment.
This looks fantastic! Just a couple small writing things I noticed that we can easily address in a future PR if we need to push this sooner 🙂
Contributor
|
Thanks @janine-c These changes look good to me. @jenny-park-dd do they look good to you? |
…ities_and_risk_scoring.md Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
…ities_and_risk_scoring.md Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
…ities_and_risk_scoring.md Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
…ities_and_risk_scoring.md Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
…ities_and_risk_scoring.md Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
Point the Entity Pack references at the new Entity Packs page rather than at Content Packs, and add it to further reading, reciprocating the link that page already has to this one. Keep the Content Packs pointer in the prerequisite, since that is still where an Entity Pack is configured. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Contributor
Author
|
Yes, they look good to me - accepted all edits and added a link to the Entity Packs page. Thanks! |
janine-c
approved these changes
Oct 7, 2026
janine-c
left a comment
Collaborator
There was a problem hiding this comment.
Looks awesome, thanks, Jenny!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do? What is the motivation?
Renames Risk Insights to Entity Risks across the Cloud SIEM documentation, and documents two additions to the feature. The existing page structure is preserved; apart from the rename, the changes are additive.
Risk grouped by user identity — a new section under Explore Entity Risks describing how user identities sync from an identity provider (Okta, Google Workspace, or Microsoft Entra ID) through the Entity Pack, how a user identity's risk score is the sum of the scores of the entities resolved to it, and how to expand a user identity row to investigate those entities. Includes a note that only unambiguously resolved entities are grouped, so the same person can still appear more than once.
User identity notifications — a new
Group risk bystep in the notification flow, plus a new "Notify on rolled-up user identity risk" section covering user attribute matching, conditions evaluated against the rolled-up score, threshold-crossing behavior, person-centric message content, and the link into User Inventory.Also:
Merge readiness
AI assistance
Drafted with Claude Code from the feature specification, then reviewed against the product UI.
Additional notes
Opening as a draft for product-team review before docs-team review.
Risk grouped by user identitysection has no screenshot of its own yet.Entity Risksis not in theDatadog.headingsexceptions list inDataDog/datadog-vale, so the three headings containing the new product name raise sentence-case warnings. Adding the term there would clear them, and would apply to any future page using the name. Vale otherwise reports no errors.