Manual

The Dashboard

The dashboard is your abuse operations center: monitor user behavior, investigate suspicious activity, and manage escalations from a single interface. Everything you need to understand the health of your user base is here.

Home Page

The home page shows key metrics at a glance. Four stat cards show total tracked identities, identities active in the last 24 hours, identities scored in the last 24 hours, and total events in the last 24 hours. These numbers tell you how much activity Dregs is processing and how fresh your scoring data is.

Below the stats, score distribution charts show how your user base breaks down across all four scoring dimensions: Humanity, Authenticity, Uniqueness, and Behavior. A healthy user base clusters toward high scores. A growing tail of low scores in any dimension tells you where to focus your attention.

The recently active identities table rounds out the home page, showing the most recently active users. Each row shows the identity, its scores, and when it was last seen: a quick way to spot-check activity without running a search.

Identities

You'll spend the most time on the Identities page during investigations. It lists every tracked user with their scores visible at a glance. Browse the full list, or narrow it with search and filters to find exactly who you're looking for.

Each identity in the list shows a compact summary: the user identifier, display name and email if available, and the four dimension scores as colored indicators. Sort by any score dimension to surface the most suspicious users first.

Clicking an identity opens the full detail view, organized into several sections:

  • Overview: the identity's scores, badges, and key metadata at a glance.
  • Scores and observations: a breakdown of every analyzer's output for this identity, showing exactly why each score is what it is. Each observation includes a confidence level and a plain-language explanation.
  • Devices: every device this identity has used, with fingerprint details, IP addresses, and geolocation. Critical for understanding whether one person uses multiple devices or multiple accounts share one device.
  • Related identities: other users linked to this identity through shared devices, similar names, similar emails, or overlapping behavior patterns. This is where you uncover duplicate accounts and coordinated abuse.
  • Events: the full event history for this identity, showing every tracked action in chronological order.
  • Reviews: LLM-powered identity reviews that provide a narrative assessment of the user's risk profile.

Groups

The Groups page lists the organizations, companies, teams, or workspaces your identities belong to, as reported by your tracking calls. Each row shows the group's ID, name, type, how many identities belong to it, and when it was first and last seen. Open a group to see its data fields, its member identities, and its recent events. For how to send groups, see Groups.

Devices

The Devices page lists every fingerprinted device Dregs has seen. Each entry shows the device fingerprint, IP address, geolocation (city and country), user agent, and which identities have used it.

Devices are a key investigative tool. A single device associated with multiple identities is a strong signal of duplicate accounts: someone signed up repeatedly with different email addresses on the same machine. The device detail view shows this mapping clearly.

For more on how fingerprinting works, see Devices.

Events

The Events page is your live activity stream. Every tracked action (page views, form submissions, custom events) appears here in reverse chronological order. Go here to understand exactly what a user did and when.

Filter by event type, identity, device fingerprint, or free text to narrow the list to the activity you care about. Click any event to see the full payload, including all tracked data fields. For incident investigations, the Events page is indispensable: it gives you a precise timeline of every action a suspicious user took.

Escalations

The Escalations page is your review queue. Summary cards at the top show counts of open, acknowledged, and closed escalations, so you can gauge the current workload at a glance.

Below the summary, the escalation list shows each escalation with its severity, the identity that triggered it, and the rule it matched. Filter by status, severity, or identity to focus on what matters most. As you investigate, acknowledge escalations to signal that someone is looking at them, and close them once the issue is resolved or found to be benign.

For details on configuring the rules that generate escalations, see Escalations.

Search and Filtering

The Events, Identities, and Devices pages share a unified search bar that supports both free text and structured filters. Start typing to search, or use key:value syntax for precise filtering.

Some examples:

  • humanity:0-50: identities with a Humanity score between 0 and 50
  • identity:user@example.com: events or devices associated with a specific identity
  • authenticity:0-30 behavior:0-30: identities that score low on both Authenticity and Behavior
  • Plain text without a prefix searches across relevant fields for the current page

Score range filters save you a lot of scrolling. Instead of paging through hundreds of identities, you can instantly surface users in a specific risk band: for example, everyone with a Uniqueness score below 25.

Settings

The Settings page controls how Dregs operates for your account. Its tabs, in order:

  • Team: team info, invite members, choose who is an administrator, view pending invitations
  • Billing: your plan, usage, and subscription
  • Credentials: manage API key pairs, allowed origins, and enable/disable status
  • AI Agents: connect AI agents to your account over MCP
  • Datasets: create and manage custom lookup tables for scoring enrichment
  • Mappings: map your own field names to the canonical fields Dregs scores on
  • Badges: define badge rules that automatically label identities based on score thresholds
  • Escalations: configure escalation rules and choose which notification channels each one notifies
  • Notifications: set up the email, Slack, and webhook channels that escalations deliver to

Every team member can view every tab, but only administrators can create, edit, or delete anything in them. See Team Management for details on roles and permissions.

The dashboard updates automatically. Pages that show live data refresh periodically in the background, so you don't need to reload to see the latest activity.