Bias Proxy List

FieldDescription
senioritySeniority does not inherently indicate whether an activity is malicious or benign. Using it could cause the system to under-scrutinize senior employees or over-scrutinize junior employees, leading to inconsistent threat detection.
departmentDepartment membership often reflects organizational structure rather than security risk. Including it may create assumptions that certain departments are more or less trustworthy, potentially generating biased alerts while missing genuine threats in other areas.
job_titleJob titles can influence expectations about user behavior, but they are not direct indicators of malicious activity. Relying on titles may cause the system to excuse suspicious actions by certain roles or unfairly flag others based on stereotypes rather than observed behavior.
locationGeographic location may be relevant for specific security controls (e.g., impossible travel detection), but as a general risk factor it can introduce bias against users from particular regions. Security decisions should be driven by anomalous behavior relative to a user's normal patterns, not assumptions about where they are located.
nationalityNationality has no intrinsic relationship to malicious intent or security risk. Including it can lead to discriminatory outcomes, increase false positives against certain groups, and create legal, ethical, and compliance concerns without improving threat detection accuracy.