What are Signals?
Signals is the first layer in the Human Risk Intelligence closed loop. Every risk calculation, training assignment, and intervention starts with a signal.
Signals are the data points Moxso collects about your employees and their environment. They're the starting point for everything the Human Risk Intelligence engine does. Without signals, there's no risk picture, no training assignment, and no intervention.
How signals work
Moxso collects signals continuously from three sources: your employees' behavior, your organization's context, and active threats in your industry and country. Every signal is fed into the Intelligence layer, where it's classified, weighted, and turned into a risk calculation.
Signals don't trigger actions on their own. A single event, such as an employee clicking a link, is only meaningful when the Intelligence layer puts it in context. That context includes who the employee is, what they have access to, and what's currently happening in the outside world.
You can see behavioral signals recorded for your organization under Human risk intelligence > Signals. Each entry shows the signal type, its sentiment, the employee it relates to, and when it was recorded. You can filter by employee, group, signal type, severity, sentiment, risk matrix, and date.
Clicking on an individual signal opens a detail panel showing the employee's role and access level, the signal type, sentiment, and severity, and the Risk Framework categories associated with it. Where applicable, it also shows a preview of the content that triggered the signal.
The three signal sources
Human behavior
Human behavior signals come from how your employees interact with security-related events and systems. Moxso monitors these continuously across your organization.
The full list of behavioral signals is:
|
Signal |
Sentiment |
|
Assigned training completed |
Positive |
|
Assigned training completed on time |
Positive |
|
Breach found |
Negative |
|
Completed optional training |
Positive |
|
Email simulation clicked |
Negative |
|
Email simulation credentials submitted |
Negative |
|
Email simulation delivered |
Neutral |
|
Email simulation reported |
Positive |
|
Email simulation reported without clicking |
Positive |
|
Multiple choice question answered correctly |
Positive |
|
Multiple choice question answered incorrectly |
Negative |
|
Opened real phishing email |
Negative |
|
Participates in cybersecurity initiatives |
Positive |
|
Post-deadline completion |
Negative |
|
Repeatedly answered phishing quizzes correctly |
Positive |
|
Repeatedly answered phishing quizzes incorrectly |
Negative |
|
Reported real phishing email |
Positive |
|
Reports legitimate emails as phishing emails |
Negative |
|
SMS simulation clicked |
Negative |
|
SMS simulation delivered |
Neutral |
|
Targeted in real phishing emails |
Neutral |
|
Threat reported |
Positive |
|
Training video watched |
Positive |
Each signal is classified by severity (Critical, High, Medium, Low, or Neutral) and by sentiment (Positive, Negative, or Neutral). Severity reflects how serious the behavior is. Sentiment reflects whether the behavior moves risk up or down: a phishing simulation failure is Negative, while reporting a real phishing email is Positive.
Signals are also weighted against a risk matrix that combines two dimensions: impact (High, Medium, or Low) and likelihood (Very likely, Somewhat likely, or Very unlikely). A signal that is both high impact and very likely carries significantly more weight than one that is low impact and very unlikely. This weighting happens automatically in the Intelligence layer and feeds directly into each employee's risk profile.
Organizational context
Organizational context tells Moxso who each employee is within your organization. Unlike behavioral signals, this isn't event-based. It's a continuous background input that shapes how every other signal is interpreted, and what allows the Intelligence layer to treat a risky action by a high-privilege user differently from the same action by someone with limited access.
Organizational context includes three inputs.
1) Organizational role is a standardized Moxso role that reflects the type of work an employee does, independent of their job title. Because roles are standardized, Moxso can compare risk consistently across departments and companies. The available roles are:
Administration, Customer support success, Data analytics, Education training, Engineering development, Executive leadership, Facilities services, Finance, Human resources, IT systems, Legal compliance, Management team leadership, Marketing communications, Operations, Product design, Project program management, Quality process, Research science, Sales, Security, and Supply chain logistics.
Moxso can automatically assign an organizational role to employees that don't already have one, based on their department and group data. This requires the employee data enrichment setting to be enabled in your workspace settings. The process runs once per day and existing roles are never overwritten automatically. Read more about organizational roles in this article: What are organizational roles?
2) Access level and responsibility tier are mapped to a risk weighting between 1 and 10. An employee with high system access and broad organizational responsibility carries a higher baseline risk weight than someone with limited access, which means the same behavioral signal can result in a different risk calculation depending on who triggered it.
3) Compliance requirements that apply to the employee. This data comes from your active directory integration, typically Microsoft Entra ID or Google Workspace.
External threats
External threat data comes from OSINT (open-source intelligence), which continuously monitors open sources for threats relevant to your organization. This includes active attacks in your industry and country, and data breaches that may affect your employees.
You can see what Moxso is currently tracking in Human risk intelligence > OSINT.
What happens after a signal is collected
Every signal is passed to the Intelligence layer, where it's classified against the Moxso Risk Framework and weighted based on your organization's context and training strategy. The resulting risk calculation is then passed to the Action layer, which determines the appropriate response.

