Entity Analytics
The analysis of behaviour and relationships across all entities in an environment, human and non-human, to establish what normal looks like and surface deviations from it. An entity is any actor with an identity: an employee, a contractor, a service account, an API key, a workload, or an AI agent.
Entity analytics is the broader successor to user and entity behaviour analytics (UEBA). The shift matters because in most environments non-human identities now outnumber human ones by a wide margin, and a model trained only on employee login patterns cannot reason about a service account that suddenly queries a new database or an AI agent invoking a tool it has never used. Where UEBA asked whether this user is behaving unusually, entity analytics asks the same of every principal and, critically, of the relationships between them.
In practice the capability appears inside ITDR platforms and identity security posture tooling rather than as a standalone product category. Evaluate it on three things: which entity types are actually modelled, whether relationships between entities are represented or only individual behaviour, and how the baseline handles legitimate change such as a deployment or a seasonal workload.
See also: ITDR, non-human identity, identity threat detection platforms
Related on Start with Identity
- GlossaryABAC
Attribute-Based Access Control. Access decisions are made by evaluating attributes of the subject, resource, action, and environment against policy. Flexible bu
- GlossaryAccess Certification
Periodic review of who has access to what, with managers or resource owners attesting that access is still appropriate. A regulatory requirement in many industr
- GlossaryAccess Token
A short-lived credential a client presents to a resource server to access protected data. Access tokens are typically opaque or JWT-formatted, with lifetimes me
- ArticleTop 6 Identity Analytics Platforms for Detecting Insider Threats in 2026
Compare the top 6 identity analytics platforms, Gurucul, Securonix, Exabeam, LogRhythm, Microsoft Sentinel, and Splunk UBA, to detect identity-based threats, in