Skip to main contentWhat is Insider Threat Policy?
Insider threat policies detect data exfiltration, unauthorized access, policy violations, suspicious behavior, and insider risk indicators.
Available Variants
InsiderThreatBlockPolicy: Pattern detection with blocking
InsiderThreatBlockPolicy_LLM: LLM-powered block messages
InsiderThreatBlockPolicy_LLM_Finder: LLM detection for better accuracy
InsiderThreatAnonymizePolicy: Anonymizes threat indicators
InsiderThreatReplacePolicy: Replaces with placeholder
InsiderThreatRaiseExceptionPolicy: Raises DisallowedOperation exception
InsiderThreatRaiseExceptionPolicy_LLM: LLM-generated exception messages