Reading the Insights screen
What the headline numbers, outcomes, and breakdowns on Insights mean, and which limits the screen has on purpose.
Insights
Monitor sensitive-data detections across your team
The Insights screen (under Realtime Privacy) shows the sensitive-data detections across your team: how many, where, which types, and what happened to them. Everything is a count; message text appears nowhere.
Insights in the dashboardHeadline numbers, outcomes, and breakdowns per app and per data type, for the period you pick.Period and filters
The Period button sets the window for the whole page. Pick a preset (from Last 7 days up to Last year) or click a start and end date in the calendar. Days older than the 24-month retention window cannot be picked; the calendar says "Data from before (date) is not kept."
Next to it sits the Filters button, with three fields that apply to every card at once:
| Filter | Options |
|---|---|
| Platform | All platforms, or one app (with web or desktop where both exist) |
| Entity type | All entity types, or one type |
| Level | All levels, Standard, or Critical |
Active filters show as badges next to the button; Clear all resets them.
The headline numbers
Four cards sit at the top, each compared against the previous period:
- Detections: the total for the chosen period.
- Critical detections: the Critical share, with its percentage of the total.
- Adjusted before sending: detections the user masked, replaced, or removed before sending.
- Critical sent despite warning: critical detections that were not adjusted and still went out. This is the number to manage: here, something genuinely sensitive left the building.
Detections over time
The chart shows detections per day, split into Standard and Critical, as bars or a line. Use it to see whether training, policy, or a profile change lands: detections should drop, or the adjusted share should rise.
Outcomes
The Outcomes card spreads every detection in the window across one 100% bar:
| Segment | Meaning (as the screen puts it) |
|---|---|
| Replaced | Swapped for safe placeholder text |
| Masked | Hidden behind ●●● |
| Removed | Deleted from the message |
| Sent despite warning | Detected but sent without changes |
| No action recorded | Left in place, or predates outcome tracking; not known to have been sent |
The first three add up to the headline "adjusted before sending". The gray segment deliberately carries no judgment: it includes history from before outcomes were tracked.
Detections by platform
Per app you see the detection count, how many were critical, and what share was adjusted before sending. Apps that exist in both the browser and the desktop app appear separately, labelled web or desktop. Click a row to filter the whole page on that platform.
Detected entity types
The same breakdown, per data type, with critical types first. A click filters the whole page here too. Financial data and credential-like types tend to be low in volume but high in risk, so do not read only the tallest bar.
Departments
If your organisation has switched on Department insights (Organisation → Organisation settings), a Departments card sits at the bottom: critical detections per person for each department, alongside how many of those happened in non-allowed AI tools. Numbers are normalised per person, so a big department does not automatically look worse than a small one. Click a department to filter the whole page; a department filter then also appears next to the period control.
What is and is not on this screen
Insights counts metadata: data type, level, app, timestamp, and the action taken. The typed text is never stored, and the dashboard has no per-employee view; everything you see is a group total.
The counting is on or off per organisation: the Team insights switch under Organisation settings. With it off, the clients send no detection events and this screen stays empty.