Identify risky and sensitive users | Entitle Pathfinder

A workflow for Entitle and Identity Security Insights

An identity with too much access is one of the easiest ways for an attacker to move through your environment. Risk and sensitivity scores show you which users hold dangerous access before someone abuses it. This workflow shows you how to find those users in Entitle and review the detections behind their scores in Identity Security Insights.

Scope of this guide

This workflow covers finding risky and sensitive users in the Permissions page in Entitle on the Pathfinder platform, and opening a detection in Identity Security Insights to see the full detail.

Prerequisites

  • Your organization has a license for both Entitle and Identity Security Insights on the Pathfinder platform.
  • The Identity Security Insights integration is set up, so Entitle receives detection and privilege data.
  • You can sign in to Entitle and open the Permissions page.

Risk and sensitivity tiers

Entitle shows a risk label and a sensitivity label on each user. The labels come from the data that Insights collects.

LabelWhat it means
Risk: RiskyThe user has at least one open security detection in Insights at critical (4) or high (3) severity.
Risk: CautionThe user's highest open security detection in Insights is moderate (2) or low (1) severity.
Sensitivity: HighThe highest privilege level across the user's accounts is highest (4) or high (3).
Sensitivity: MediumThe highest privilege level across the user's accounts is moderate (2) or low (1).

Steps

Step 1: Review risk and sensitivity in the graph view

  1. Sign in to Entitle and navigate to Permissions.

  2. Select a risk or sensitivity tier to see the users in that tier. Entitle displays up to 250 users at a time, so filter the graph to narrow your search.

    The Permissions graph with risk and sensitivity tiers

  3. Hover over the risk and sensitivity indicators on a user to see the details.

    Risk and sensitivity details on hover

Step 2: Open the detail in Insights

  1. Select a risk detection to review it in Insights.

  2. Select the sensitivity indicator to open the identity's profile in Insights.

    Selecting a detection to open it in Insights

Step 3: Filter the table view

Use the table view when you want a filtered list of users rather than a graph.

  1. In Entitle, navigate to Permissions, then select Table and Filter.

    The Permissions table view

  2. Select User risk or User sensitivity, then complete the filter expression.

    Filtering the table by user risk or user sensitivity

Verify the results

Confirm that the Permissions page shows a risk or sensitivity label on the users you filtered for. Confirm that selecting a risk detection opens the matching detection in Insights. If no labels appear on any user, check that the Insights integration is connected.

Next steps

  • Review the access that a risky user holds, then remove what they no longer need.
  • Run an access review for the resources that your sensitive users can reach.

Did this page help you?

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.