Anomalous Access

Surface sign-ins from countries each identity hasn't used before.

Security detection

Anomalous Access shows sign-ins and actions from countries outside each identity's established baseline. The backend pre-filters to just the access that falls outside a user's historical country usage, so every row is a potential anomaly. When there's nothing outside baseline, the page shows an all-clear state.

How to use it

  1. Open Settings → Security → Anomalous Access.

  2. Optionally filter by identity email and date range.

  3. Review the highlighted rows — each shows the identity, country, IP, and action.

  4. If the page shows the all-clear state, every sign-in in the window came from a country that identity has used before.

  5. Page through results to review all flagged access.

Tips

  • This is a per-identity behavioral baseline, not a fixed allowlist — it adapts to where each user normally signs in from.

Open Anomalous Access in the app

Jump straight to the feature, or browse the rest of the guides.