Permission Drift Score by Actor(5.3.10)

Visual
Where to find it:CompliancePermission drift
Ent Standard
Open in dashboard

Rather than requiring a compliance investigator to correlate three separate signals per actor by hand, this table aggregates them into a single score. Actors with high scores have exhibited multiple access-expansion and accountability-bypass patterns simultaneously — making them the highest priority for investigation.

What you can conclude

  • Actors with scores above 70 are flagged as high risk — multiple concurrent signals suggest a pattern, not a coincidence.
  • Actors in the 40–69 range warrant monitoring — one or two signals are present but not yet at an escalation threshold.
  • Actors below 40 have a low combined score, though one signal on its own can still be present.

How this chart works

Ranked table showing actors with a composite permission drift score (0 to 100), built from three signals measured per actor per week: reporter changes, the number of distinct projects the actor was active in, and their self-assignment rate. Color-coded: red (70 or above), amber (40 to 69), green (below 40).

The self-assignment term uses the same definition as the Self-Assignment Rate by Project chart on this page: self-assignments divided by assignee changes, not by overall edit volume. That rate is shown in the table next to the number of assignee changes it was measured over, so a rate resting on two changes can be told apart from one resting on ninety. An actor who made no assignee changes at all in the week shows a blank rate and contributes nothing to this term; the rest of their score still reflects the other two signals. The self-assignment term only enters the score once the actor made at least five assignee changes in the week; below that the rate is still shown, contributes nothing, and the table says whether it was scored. Use the date and project filters to focus on specific periods. Each actor carries the type of account Jira reports for it: person, app, customer, unknown when Jira returned no type, or erased.