Skip to content

Document Entity Risks rename, user identity grouping, and rollup notifications - #40114

Merged
jenny-park-dd merged 19 commits into
masterfrom
jenny.park/entity-risks-user-identity-rollup
Oct 7, 2026
Merged

jenny-park-dd merged 19 commits into
masterfrom
jenny.park/entity-risks-user-identity-rollup

Conversation

@jenny-park-dd

@jenny-park-dd jenny-park-dd commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

What does this PR do? What is the motivation?

Renames Risk Insights to Entity Risks across the Cloud SIEM documentation, and documents two additions to the feature. The existing page structure is preserved; apart from the rename, the changes are additive.

Risk grouped by user identity — a new section under Explore Entity Risks describing how user identities sync from an identity provider (Okta, Google Workspace, or Microsoft Entra ID) through the Entity Pack, how a user identity's risk score is the sum of the scores of the entities resolved to it, and how to expand a user identity row to investigate those entities. Includes a note that only unambiguously resolved entities are grouped, so the same person can still appear more than once.

User identity notifications — a new Group risk by step in the notification flow, plus a new "Notify on rolled-up user identity risk" section covering user attribute matching, conditions evaluated against the rolled-up score, threshold-crossing behavior, person-centric message content, and the link into User Inventory.

Also:

  • Adds a note that Entity Risks was previously known as Risk Insights.
  • Renames the left-nav entry in the English and Korean menus. The Spanish, French, and Japanese menus translate this entry, so they are left for localization.
  • Updates the Entity Risks explorer and settings links to their new routes.
  • Presents the Entity Pack as a recommended part of setup rather than optional, and says what configuring it changes.
  • Notes that the existing entity severity thresholds also apply to a user identity's rolled-up risk score, and generalizes that table's column header accordingly.
  • Expands the entity filtering list in the Overview to match the available filters.

Merge readiness

  • Ready for merge

AI assistance

Drafted with Claude Code from the feature specification, then reviewed against the product UI.

Additional notes

Opening as a draft for product-team review before docs-team review.

  • UI strings and both app routes have been verified against the product.
  • Screenshots on both pages were replaced with current captures, and alt text was added where it was missing. The new Risk grouped by user identity section has no screenshot of its own yet.
  • Entity Risks is not in the Datadog.headings exceptions list in DataDog/datadog-vale, so the three headings containing the new product name raise sentence-case warnings. Adding the term there would clear them, and would apply to any future page using the name. Vale otherwise reports no errors.

Rename Risk Insights to Entity Risks across the Cloud SIEM docs, and update the
app link to the new route.

Add a "Risk grouped by user identity" section covering identity provider sync
through the Entity Pack, the rolled-up risk score, and expanding a user identity
row to investigate the entities beneath it.

Add a "Group risk by" step to the notification flow, and a "Notify on rolled-up
user identity risk" section describing user attribute matching, conditions
evaluated against the rolled-up score, threshold-crossing behavior, message
content, and the User Inventory link.

Note that the existing entity severity thresholds also apply to a user
identity's rolled-up risk score.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@jenny-park-dd jenny-park-dd added the WORK IN PROGRESS No review needed, it's a wip ;) label Sep 21, 2026
jenny-park-dd and others added 2 commits September 30, 2026 10:31
Add a note to the Overview stating that Entity Risks was previously known as
Risk Insights, so readers arriving from older links or search results can
confirm they are on the right page.

Rename the left-nav entry from Risk Insights to Entity Risks in the English and
Korean menus. The Spanish, French, and Japanese menus translate this entry, so
they are left for localization rather than renamed here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-actions github-actions Bot added the Architecture Everything related to the Doc backend label Sep 30, 2026
jenny-park-dd and others added 4 commits September 30, 2026 13:50
Move the Entity Pack from an optional prerequisite to a recommended one, and
say what configuring it changes: entities resolve into a single user identity
with a rolled-up risk score, and user identity notifications become available.
Note the consequence of skipping it, so the choice is clear.

Add the user identity view to the Overview capability list, and widen the
notifications entry to cover alerting on people as well as entities.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Use the singular "Create a new Entity Risk notification" for the page name, to
match the product. Point the settings reference at
/security/configuration/siem/entity-risks, which moved with the rename.

Document the score scales the two groupings use, since that is what determines
a workable threshold: individual entity scores typically range from 0 to 500,
while rolled-up user identity scores are unbounded.

Split several long sentences and avoid "Create a new" per the style guide.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Remove the statement that individual entity scores typically range from 0 to
500, which does not reliably hold, and the claim that rolled-up scores need
higher thresholds. Each option now describes only what the rule measures.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The previous screenshot dated from June 2025 and no longer matched the product:
it carried a Risk Insights promotional banner, an older navigation bar, the
singular filter labels, an entity count instead of a risk count, and the former
column names. It also predated grouping, so it could not show a user identity
row.

Update the alt text to describe the grouped view the new capture shows.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-actions github-actions Bot added the Images Images are added/removed with this PR label Oct 4, 2026
jenny-park-dd and others added 5 commits October 3, 2026 20:40
The previous screenshot showed the section header "What contributes to the
score?", which the page text no longer uses, and did not show the
View All Related Signals control the text refers to. The new capture shows the
Risk Contributors tab and section, so the text and the image agree again.

Update the alt text to name the two sections the surrounding text describes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The entity side panel no longer has a Next steps section. Triage state,
assignment, security cases, incidents, and suppressions are now inline actions
in the Risk Contributors section, so describe them there and list them.

Remove the accompanying screenshot, which showed the Next steps panel. The
image file itself is kept, because the Spanish translation still references it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The previous capture titled the panel "Risk Insights" and labelled its link
"View Risk Insights", which contradicted the renamed section heading. The new
capture shows the renamed panel.

Add alt text, which was previously empty.

Keep the old image file, because the Spanish translation still references it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Pre-existing style error on a line this branch already touches.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@jenny-park-dd
jenny-park-dd marked this pull request as ready for review October 5, 2026 19:43
@jenny-park-dd
jenny-park-dd requested a review from a team as a code owner October 5, 2026 19:43
@jnhunsberger

Copy link
Copy Markdown
Contributor

@jenny-park-dd These updates look good to me. Thank you for putting them together.

@janine-c janine-c left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks fantastic! Just a couple small writing things I noticed that we can easily address in a future PR if we need to push this sooner 🙂

@jnhunsberger

Copy link
Copy Markdown
Contributor

Thanks @janine-c These changes look good to me. @jenny-park-dd do they look good to you?

jenny-park-dd and others added 7 commits October 6, 2026 21:16
…ities_and_risk_scoring.md

Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
…ities_and_risk_scoring.md

Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
…ities_and_risk_scoring.md

Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
…ities_and_risk_scoring.md

Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
…ities_and_risk_scoring.md

Co-authored-by: Janine Chan <64388808+janine-c@users.noreply.github.com>
Point the Entity Pack references at the new Entity Packs page rather than at
Content Packs, and add it to further reading, reciprocating the link that page
already has to this one. Keep the Content Packs pointer in the prerequisite,
since that is still where an Entity Pack is configured.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@jenny-park-dd
jenny-park-dd requested a review from janine-c October 7, 2026 01:27
@jenny-park-dd

Copy link
Copy Markdown
Contributor Author

Yes, they look good to me - accepted all edits and added a link to the Entity Packs page. Thanks!

@jenny-park-dd jenny-park-dd removed the WORK IN PROGRESS No review needed, it's a wip ;) label Oct 7, 2026

@janine-c janine-c left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks awesome, thanks, Jenny!

@jenny-park-dd
jenny-park-dd merged commit 0056f6b into master Oct 7, 2026
32 of 33 checks passed
@jenny-park-dd
jenny-park-dd deleted the jenny.park/entity-risks-user-identity-rollup branch October 7, 2026 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Architecture Everything related to the Doc backend Images Images are added/removed with this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants