New Actor Burst Detection(5.3.6)

Visual
Where to find it:CompliancePermission drift
Ent Standard
Open in dashboard

When a new actor appears in the system, their initial activity level tells you something important. A new team member with a moderate first-week activity level is onboarding normally. A new actor with an extremely high first-week activity level, far above the norm for new accounts, may indicate account takeover, improper access provisioning, or an app account that has been given broad access.

What you can conclude

  • For a new actor flagged as a burst (at or above the burst threshold set by people's debuts), a reviewer could ask how the account was provisioned and whether its first-week activity matches the access it was meant to have.
  • A normal-looking debut activity level, even for a new actor, is not a concern.
  • Multiple burst actors appearing in the same short period may indicate a systematic access provisioning issue.

How this chart works

Horizontal bar chart showing actors who appeared for the first time in the period, ranked by their debut week activity level. The burst threshold is the mean debut-week count of people's accounts in the selected range plus 2 standard deviations; the chart draws no line for it, and an actor at or above it is flagged in red. Debuts by apps, service-desk customers, erased accounts and accounts Jira returned no type for are compared with the threshold but do not move it, so a busy app setting up neither raises it over a person's burst nor lowers it. The threshold needs at least three people's debuts that differ: with fewer than three people in the range, or when every person debuts with the same count (a standard deviation of 0), no threshold is set and no actor is flagged, and the Burst actors figure shows "—" rather than 0, because no burst could be measured, which is not the same as none found. Each actor carries the type of account Jira reports for it (person, app, customer, unknown when Jira returned no type, or erased), so people's debuts are counted apart from apps and service-desk customers, and an account Jira returned no type for is shown as unknown, never as a person.