How to Investigate a Risk Score
An anomaly is a question, not an accusation. A repeatable order of investigation prevents wasted hours and wrong conclusions.
An analyst opens an alert: an entity scored 84. What now? Without a defined sequence, the answer varies by analyst and by day, and the variance shows up as inconsistent outcomes for people.
The order
One. What actually happened? Read the contributing factors, not the score. What did the entity do that the model found unusual? If you cannot state this in a sentence, the enrichment is inadequate and that is the finding.
Two. Is the data trustworthy? Before interpreting behaviour, ask whether the data is real. Did a source backfill? Did a parser change? Is this entity duplicated? A surprising proportion of anomalies dissolve at this step, and checking takes two minutes.
Three. Is there a benign structural explanation? Role change, return from leave, new project, new tool rollout, month-end, a national holiday, an incident the person was responding to. Most of these are available in reference data or a shared calendar.
Four. Is the account compromised? Before treating behaviour as the person's choice, rule out that someone else is using the account. Source addresses, device, authentication method, concurrent sessions, impossible travel. This is the more common explanation and the quicker to check.
Getting this order wrong is how organisations end up investigating a victim.
Five. Is it a shortcut? Someone working around an inadequate process. Common, not malicious, and the finding is about the process.
Six. Only then: is it deliberate and concerning?
What raises concern
None is conclusive alone.
Concealment. Log deletion, renaming, encryption where none is normal, activity timed to avoid observation. Errors are not hidden; this is the strongest single indicator.
Employment context. Notice period, recent role change, a known grievance. Predictive and prejudicial in equal measure — see the entry on enrichment for how to handle it.
Sensitivity of what was touched. Joined against the data inventory.
Breadth. Systematic collection across systems rather than a single action.
Access outside role. No business rationale exists by construction.
Persistence. The same anomaly daily for a week is a behavioural change, not noise.
What does not raise concern
A high score alone. It means unusual.
Unusual hours, for a distributed workforce.
High volume in a role involving high volume. Compare against the entity's own baseline and its peers.
Use of an unsanctioned tool because the sanctioned one is inadequate. That is a finding about your tooling.
Ask the person
The most underused response in this field.
For the large majority of anomalies — error, shortcut, legitimate work nobody recognised — a short, non-accusatory conversation resolves it in minutes, produces a better outcome than an investigation, and frequently reveals a process problem worth fixing.
It requires the question to be genuinely a question. Where the concern is serious, this step is skipped for good reason; it is skipped far more often than it should be.
Documenting the decision
Every triage records what was decided and why, in a fixed category, with the feature vector retained.
Two reasons. Patterns only emerge across time, and an anomaly dismissed three times by three analysts is a pattern nobody saw. And if a case escalates, the earlier decisions form part of the record.
Where it escalates
Define the threshold in advance rather than case by case: evidence suggesting deliberate action, plus either significant volume or high-sensitivity data, plus no benign explanation found.
At that point it stops being triage. It becomes an investigation with authorisation, scope, legal involvement and evidence handling — and the analyst's job is to hand over observations, not conclusions.
A triage template
A fixed structure makes triage faster and makes outcomes consistent between analysts, which is the harder problem.
Observation. One sentence: what the entity did, with numbers, against baseline. Written before any interpretation.
Data check. Sources delivering normally, entity resolution correct, no backfill. Yes or no.
Structural explanations considered. Role change, leave, project, rollout, calendar, incident response. Which were checked and what was found.
Compromise indicators. Source, device, authentication method, concurrency, geography. Checked and result.
Context. Role, employment status, sensitivity of what was touched, prior findings.
Conclusion and category.
Confidence, and what would change it.
Ten minutes to complete, and it produces a record that means something six months later when the entity appears again.
Common false positives
What triage most often finds, which is worth knowing before starting:
Legitimate work nobody recognised — the largest single category by a wide margin.
Process shortcuts around inadequate tooling.
Errors — wrong recipient, wrong folder, wrong system.
Structural explanations available in reference data the analyst did not check.
Data defects.
Compromised accounts, which are the most common genuinely serious finding and are frequently misread as deliberate action by the account owner.
That last point is the reason the compromise check sits before the intent question in the sequence.
Blind spots and assumptions
That the score is evidence. It is a prioritisation signal. In any process with consequences, present observations and baselines, never the number.
That the model saw everything. It saw the features it has, from the sources that were delivering.
That absence of explanation means malice. It frequently means the analyst lacked context that a two-minute conversation would have supplied.
That investigating is free. Every investigation of an innocent person costs trust, and the cost is paid by the whole programme.
More in this section