List view
Quick Start
Quick Start
User Guide
User Guide
Policies & GuardRails
Policies & GuardRails
Witness Anywhere: Remote Device Security
Witness Anywhere: Remote Device Security
Witness Attack
Witness Attack
Administrator Guide
Administrator Guide
Organizational Behavior GuardRail (Beta)
Organizational Behavior is WitnessAI’s modeled multi-prompt aware Guardrail. The purpose of this Guardrail is to examine an employee’s prompts and score various “meta” behaviors. For example, an employee that may wish to leave the company. When this Guardrail detects these activities, it provides the option to create an Alert in the Witness Console, or push an event to a supported SIEM tool.
Behavioral Alerts
Detection Criteria
If an employee engages with three or more of the defined behavioral queries within a short time frame (e.g., a week), it may indicate the potential for the described risk.
If an employee engages with three or more of the defined behavioral queries within a short time frame (e.g., a week), it may indicate the potential for the described risk.
Burnout Disengagement
Intention
Detect signs of disengagement, low morale, or burnout in employees.
Detection Criteria
If an employee engages with three or more of these queries within a short time frame (e.g., a week), it may indicate potential burnout or disengagement from their role.
Potentially Departing Employee
Intention
Track signs of an employee seeking to reskill or transition to a different career path, either internally or externally.
Track signs of an employee seeking to reskill or transition to a different career path, either internally or externally.
Detection Criteria
Two or more prompts related to learning new skills or transitioning careers over a short period may indicate an intention to change job roles or industries.
Two or more prompts related to learning new skills or transitioning careers over a short period may indicate an intention to change job roles or industries.
Workplace Conflict
Intention
Track potential signs of internal conflict or dissatisfaction with colleagues or management.
Detection Criteria
If an employee asks three or more queries related to conflict resolution, workplace issues, or reporting problems in a short span, this might signal potential internal conflict or growing dissatisfaction.
Track potential signs of internal conflict or dissatisfaction with colleagues or management.
Detection Criteria
If an employee asks three or more queries related to conflict resolution, workplace issues, or reporting problems in a short span, this might signal potential internal conflict or growing dissatisfaction.
External Opportunity Exploration (Side Projects or Freelance)
Intention
Detect whether an employee is exploring side projects, freelancing, or moonlighting opportunities.
Detect whether an employee is exploring side projects, freelancing, or moonlighting opportunities.
Detection Criteria
If an employee interacts with two or more prompts about side projects or freelancing within a few days, it could indicate a divided focus or intention to pursue outside work.
If an employee interacts with two or more prompts about side projects or freelancing within a few days, it could indicate a divided focus or intention to pursue outside work.
Malicious Intent (Fraud or Insider Threats)
Intention
Detect malicious intentions, such as fraud, insider threats, or deliberate harm to the company.
Detection Criteria
One or more high-risk prompts related to fraudulent activities or deliberate harm could signal immediate danger or malicious insider activity.
Detect malicious intentions, such as fraud, insider threats, or deliberate harm to the company.
Detection Criteria
One or more high-risk prompts related to fraudulent activities or deliberate harm could signal immediate danger or malicious insider activity.
Knowledge Hoarding
Intention
Identify when an employee is hoarding or monopolizing knowledge for leverage or improper reasons.
Detection Criteria
Two or more queries related to hiding or withholding information could signal knowledge hoarding or potential misuse of internal resources.
Violation of Company Policies
Intention
Identify potential behaviors indicating that an employee may be attempting to bypass or violate company policies.
Identify potential behaviors indicating that an employee may be attempting to bypass or violate company policies.
Detection Criteria
If two or more of these types of prompts are detected within a certain timeframe, it could signal a potential intention to violate security or company policies.
If two or more of these types of prompts are detected within a certain timeframe, it could signal a potential intention to violate security or company policies.
Using Organizational Behavior Step-by-Step
This section covers details on the Organizational Behavior GuardRail, and how to add it to a Policy. Refer to the Policy Creation page for how to create Policies.
Add a Organizational Behavior GuardRail
After creating a Policy
- Click the Guard Rails tab in the policy editor.
- Select the Organizational Behavior GuardRail from the available options.
- Click the top slide button to enable the GuardRail.
- Click the slide buttons for each Alert you want to enble.
- Save the configuration.
Organizational Behavior GuardRail (Beta)Behavioral AlertsBurnout Disengagement Potentially Departing EmployeeWorkplace ConflictExternal Opportunity Exploration (Side Projects or Freelance)Malicious Intent (Fraud or Insider Threats)Knowledge HoardingViolation of Company PoliciesUsing Organizational Behavior Step-by-StepAdd a Organizational Behavior GuardRail
 Made with Bullet
Made with Bullet