> For the complete documentation index, see [llms.txt](https://docs.facephi.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.facephi.com/docs.facephi-en/products/facephi-intelligence-platform/modulos/behaviour.md).

# Behaviour

Behaviour allows you to analyze the activity recorded during sessions to identify signals related to the device, network, location, and user behavior.

The information and features available depend on the services contracted by your organization.

### What you can do

From Behaviour, you can:

* Consult the sessions recorded in FIP.
* Identify devices, networks, or behaviors that may require attention.
* Analyze the smart signals detected during a session.
* Consult information about devices, connections, and locations.
* Review the recorded events chronologically.
* Access the related identity to expand the investigation.
* Analyze alerts and risk levels when Behavioral Detection System is available.

{% hint style="info" %}
An isolated signal does not confirm that fraud exists. Interpret it together with the rest of the information available about the session and the identity.
{% endhint %}

### Available systems

Behaviour can include one or both systems, depending on the services contracted by your organization.

<figure><img src="/files/1410c29aef6365ea4f4d20bdae0a3331560bbc7d" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
You may only have access to one of these systems. Their availability depends on the contracted services and the permissions associated with your user.
{% endhint %}

### Main concepts

#### Session

A session groups the activity recorded during a user's interaction with the service.

It can contain one or more operations, as well as the signals, alerts, rules, and events detected during its course.

#### Smart signal

A smart signal is data detected during the session that provides context about the device, network, location, or user behavior.

Its detection does not necessarily imply that fraud exists. It must be analyzed together with the rest of the available information.

#### Alert

An alert indicates that a condition has been detected that may require attention or a more detailed review.

Alerts are available when the configuration and contracted services allow the session risk to be assessed.

#### Risk level

The risk level or score helps prioritize sessions that may need review.

It should not be used on its own to make a decision. Always review the associated signals, alerts, and evidence.

***

### How it relates to other modules

Behaviour connects the activity recorded during a session with other elements of FIP.

From the details of a session, you can access the related identity, consult other interactions associated with the same user, and review the linked operations when available.

This connection allows you to expand the investigation without losing the session context.

***

### Start here

Select the documentation corresponding to the system available for your organization:

* [**Device Intelligence System**](/docs.facephi-en/products/facephi-intelligence-platform/modulos/behaviour/device-intelligence-system.md), to analyze devices, networks, and technical context.
* [**Behavioral Detection System**](/docs.facephi-en/products/facephi-intelligence-platform/modulos/behaviour/behavioral-detection-system.md), to analyze behavior, alerts, and advanced risk.
