Alerts
- 100 %
- inside your org
- 0
- outbound data by default
- 71/255
- controls self-assessed
- 10 min
- to install
The French text governs. This page is the English version of Alertes FR.
25 capabilities, a good part of which exist for a single reason: not to drown you. A detection tool that sends five alerts for one incident ends up as an inbox rule, and detects nothing any more. What the Discovery offer opens among them: 3.
- 25
- capabilities in this family
- 3
- active on installation day, on the Discovery offer
- Discovery
- entry tier of the family
What this family measures
Emitting. Two channels stay inside your org and are open from the Discovery offer: the platform event and the custom notification. E-mail comes at the Small business tier. The finding detail inside the platform event, however, is closed by default: a Pub/Sub subscriber receives the whole payload whatever its own permissions, so the delivered event carries coordinates only — a subscriber wanting the detail re-reads the finding under its own rights.
Not drowning. Deduplication, grouping, flapping suppression when a finding opens and closes in a loop, burst correlation, quiet hours per recipient group in that group's own timezone, and maintenance windows. Routing, escalating, accounting: a single rule that replaces the siloed channels, escalation chains triggered by the age of an unacknowledged finding, inbound acknowledgement, history, and the analytics measuring your mean time to acknowledge and your ignore rate.
External channels — Slack, Teams, PagerDuty, webhook — sit at the Mid-market tier, go to a destination you choose with your credentials, and are closed at delivery. Chatter, for its part, never leaves the org.
The 25 capabilities, one by one
| Capability | Minimum offer | At install |
|---|---|---|
| Emitting | ||
AlertsAlerting | Discovery | Open |
Platform Event alertsAlert_PlatformEvent | Discovery | —, display tier: nothing to toggle, the offer is enough |
Custom-notification alertsAlert_CustomNotification | Discovery | —, display tier: nothing to toggle, the offer is enough |
Finding detail inside Platform Event alertsAlert_Event_Detail · closed by default: the event carries coordinates only, never the finding prose | Discovery | Closed |
E-mail alertsAlert_Email | Small business | —, display tier: nothing to toggle, the offer is enough |
| Not drowning the reader | ||
Alert deduplicationAlert_Deduplication | Small business | Open |
Alert groupingAlert_Grouping | Small business | Closed |
Alert flapping suppressionAlert_Flap_Suppression | Small business | Closed |
Incident-burst correlationCorrelation_Burst | Small business | Closed |
Quiet hoursQuiet_Hours | Small business | Closed |
Maintenance windowsMaintenance_Windows | Small business | Closed |
| Routing, escalating, accounting | ||
Alert routingAlert_Routing | Small business | Closed |
Alert escalationAlert_Escalation | Small business | Open |
Alert escalation chainsAlert_Escalation_Chains | Small business | Closed |
Inbound acknowledgementInbound_Ack | Small business | Closed |
Alert historyAlert_History | Small business | Open |
Alert analyticsAlert_Analytics | Small business | Closed |
| Incidents | ||
Incident managementIncident_Management | Small business | Closed |
Incident drill (rehearsal)Incident_Drill · dry rehearsal: the escalation chain is resolved end to end, with zero send and zero outbound flow | Small business | Closed |
Incident drill in live modeIncident_Drill_Live · closed at install; it requires its own gate, management authority and a typed confirmation phrase | Mid-market | Closed |
| External channels | ||
External alert channels (Slack, Teams, PagerDuty, webhook)Channel_Slack · outbound flow to a destination you choose, with your credentials | Mid-market | Closed |
Teams alert channelChannel_Teams · outbound flow to a destination you choose, with your credentials | Mid-market | Closed |
PagerDuty alert channelChannel_PagerDuty · outbound flow to a destination you choose, with your credentials | Mid-market | Closed |
Webhook alert channelChannel_Webhook · outbound flow to a destination you choose, with your credentials | Mid-market | Closed |
Chatter alert channelChannel_Chatter · stays inside your org: Chatter is not an outbound flow. Off at install, until you designate the feed to post to | Small business | Closed |
— display tier: nothing to toggle, the offer is enough
Source: read from the package code at the moment this page is built — FeatureGate.FEATURE_TIER for the offer, FeatureGate.CODE_DEFAULTS for the state at install. The label is the one exception: the in-org feature editor is French only, so the English wording in this column was written for this site. Its French counterpart, on /produit/, is the exact string your administrator reads, and the site build fails if the two lists move apart. “Closed” does not mean absent: the capability is shipped, it is waiting for a human to open it inside the org — and a capability whose implementation nothing in the package can reach appears on none of these pages: the build drops it instead of selling it.
What this family does not do
- No alert triggers an action inside your org. An escalation warns a human; it does not close the access it reports.
- No external channel is open at delivery. Each is enabled separately, inside the org, by an administrator.
- We call nobody. No phone on-call: PagerDuty does it better, and that is exactly why the channel exists.
- Correlation groups, it does not diagnose. It says “these five findings move together”, not “here is the cause”.
The other families
Is this family in your offer? The grid says so line by line.
See the pricing grid Back to the seven families