Help Center / Risk Analysis / Understanding Results

Understanding Results

Results Table

Results are displayed in a table with the following information:

ColumnDescription
User/RoleAffected user or role name
Risk IDRisk identifier (e.g., F001)
Risk DescriptionHuman-readable risk name
Risk LevelSeverity as defined by the ruleset, commonly Critical, High, Medium, Low
Risk TypeType as defined by the ruleset, commonly Segregation of Duties, Critical Action, Critical Permission
FunctionBusiness function(s) involved
ActionTransaction codes providing the access
RoleRole(s) granting the access
Composite RoleParent composite role (if applicable)
Business ProcessBusiness process category
DepartmentHR department of the user, when HR data is loaded
HR FunctionHR function of the user, when HR data is loaded
LocationHR location of the user, when HR data is loaded

Every column has a filter, so a result can be narrowed further after the analysis has run. Scoping before the run is still preferable for large systems, because it keeps the analysis and the report small. See Scoping Your Analysis.

Risk level and risk type are not fixed lists. Both carry through verbatim from the loaded ruleset, and the filter options offered here are built from the distinct values found in it. Two reports produced against different rulesets are only comparable on severity if those rulesets agree on the vocabulary.

Result Tabs

TabContent
InfoThe criteria the analysis was run with
Summary reportOne row per user and risk
Detailed reportThe roles, actions and authorizations behind each conflict
RemediationRecommendations for resolving the risks, see Generating Recommendations
Did-doExecution data for the access involved, when Did do was enabled. See Did-Do Analysis

The table on screen is a view onto the exported files. For the exact column layout of what gets written to disk, which differs between users and roles mode, see Report Types.

Updated on: 2026-08-02

« Back to Risk Analysis