A profile of normal communication patterns for an individual identity, built from historical email behaviour. Security tools use the baseline to detect deviations in sender behaviour, tone, timing, recipients, and content that may indicate phishing, account abuse, or fraud.
What Per-User Behavioural Baselines Measure
A per-user behavioural baseline is a reference model of how one identity normally communicates over time. It is built from historical patterns so security systems can flag when sender behaviour, tone, timing, recipients, or content deviate in ways that may warrant review.
This kind of baseline is most useful when the system is trying to separate ordinary variation from suspicious change. It does not prove compromise on its own, but it gives defenders a practical way to spot anomalies that are easy to miss in manual review.
How the Baseline Is Built and Maintained
The value of the baseline depends on what data it can learn from and how stable the user’s communication habits are. A strong baseline usually considers sender cadence, typical recipients, message length, topic patterns, linguistic style, and the time of day an account usually sends mail.
Baselines also need enough history to avoid overfitting to a short or unusual period. If a user changes role, teams, working hours, or communication style, the baseline has to adapt or it will start producing noisy alerts that reduce trust in the detection system.
For identity-related monitoring, this is a classic behavioural signal: the goal is not just to confirm that a message was sent from the right account, but to see whether the account is acting like its normal owner. That is why detection systems often pair behavioural baselines with AI Agent Observability, Audit and Incident Response Guide style logging and attribution concepts when automated actors or delegated actions are involved.
Common Detection Signals and Use Cases
Per-user baselines are commonly used to identify phishing, business email compromise, mailbox abuse, and fraud attempts that arrive through a trusted account. A sudden change in recipients, an unusual request pattern, a new writing style, or abnormal send timing can all be indicators that the account is being misused.
The most important strength of this approach is contextual detection. A message that looks harmless in isolation may stand out sharply when compared with the account’s normal behaviour, especially in environments where attackers try to blend into legitimate communication rather than trigger obvious malware or rule-based alerts.
Because the technique depends on historical patterns, it works best as a detection aid rather than a hard control. Teams still need separate validation for account compromise, fraud review, and escalation decisions when the baseline flags a material deviation.
What Makes the Baseline Reliable
Reliability depends on data quality, coverage, and the quality of the comparison model. A baseline built from sparse, incomplete, or highly transitional data will miss meaningful anomalies or flag too many legitimate messages.
It also depends on scope. A baseline that only watches one signal, such as send time, can miss a broader compromise that preserves timing but changes recipients or language. Conversely, a baseline that watches too many weak signals can become noisy and hard to action.
For that reason, practitioners usually treat the baseline as one layer in a broader detection strategy, not as a standalone verdict engine. It is strongest when combined with mailbox telemetry, authentication context, and incident triage workflows that can confirm whether the behavioural change is benign or suspicious.
Risk and Threat Considerations
Per-user behavioural baselines are valuable precisely because they expose deviations from trusted communication patterns, but that also makes them sensitive to spoofing, account takeover, and low-and-slow abuse. Attackers often try to mimic normal timing and style to stay below the detection threshold, while legitimate changes in user behaviour can create false positives that distract analysts.
Failure mechanism: The baseline becomes unreliable when the historical profile is too thin, too stale, or too narrow to represent real user behaviour, or when an attacker deliberately blends into expected patterns.
Impact: Security teams may miss phishing, fraud, or mailbox abuse, or they may spend time investigating benign behaviour changes and lose confidence in the signal.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Behavioural baselines depend on log review and anomaly analysis to spot unusual account activity. |
| SI-4 — System Monitoring | The term centers on monitoring for anomalous communication behaviour that indicates abuse or compromise. | |
| IA-5 — Authenticator Management | Mailbox abuse and account takeover often hinge on compromised credentials that drive abnormal behaviour. | |
| Recommendation — Correlate message and account activity logs to detect deviations from normal user behaviour. Monitor messaging behaviour for baseline deviations that may indicate compromise or fraud. Harden credential lifecycle controls to reduce the chance that a trusted account becomes the anomaly. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Email-baseline abuse often follows stolen or misused non-human or delegated identities and weak auth paths. |
| Recommendation — Use stronger authentication and abuse detection to reduce account misuse that alters normal behaviour. | ||
| MITRE ATT&CK | T1114 — Email Collection | Behavioural baseline deviations often help detect mailbox abuse and email-based intrusion activity. |
| Recommendation — Detect suspicious mailbox activity patterns that diverge from the user’s normal email behaviour. | ||
Practitioner Guidance
Why practitioners should care: The main operational question is not whether a behavioural baseline can detect anomalies, but whether it produces alerts that are stable enough to trust. Good tuning requires enough history, sensible feature selection, and a clear path for handling legitimate changes in communication behaviour.
Practitioner takeaway: Treat the baseline as a detection and triage aid, not as proof of compromise, and validate it against real user behaviour changes before relying on it operationally.
Related resources from NHI Mgmt Group
- How do you know if per-user Slack connections are actually governed?
- What breaks when AI agents have no behavioural baseline?
- What is the difference between centralized MCP tool optimization and per-user tool filtering?
- Why do cloud database environments become harder to govern when access is managed directly per user?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org