Alerts

100 %
inside your org
0
outbound data by default
71/255
controls self-assessed
10 min
to install

The French text governs. This page is the English version of Alertes FR.

25 capabilities, a good part of which exist for a single reason: not to drown you. A detection tool that sends five alerts for one incident ends up as an inbox rule, and detects nothing any more. What the Discovery offer opens among them: 3.

25
capabilities in this family
3
active on installation day, on the Discovery offer
Discovery
entry tier of the family

What this family measures

Emitting. Two channels stay inside your org and are open from the Discovery offer: the platform event and the custom notification. E-mail comes at the Small business tier. The finding detail inside the platform event, however, is closed by default: a Pub/Sub subscriber receives the whole payload whatever its own permissions, so the delivered event carries coordinates only — a subscriber wanting the detail re-reads the finding under its own rights.

Not drowning. Deduplication, grouping, flapping suppression when a finding opens and closes in a loop, burst correlation, quiet hours per recipient group in that group's own timezone, and maintenance windows. Routing, escalating, accounting: a single rule that replaces the siloed channels, escalation chains triggered by the age of an unacknowledged finding, inbound acknowledgement, history, and the analytics measuring your mean time to acknowledge and your ignore rate.

External channels — Slack, Teams, PagerDuty, webhook — sit at the Mid-market tier, go to a destination you choose with your credentials, and are closed at delivery. Chatter, for its part, never leaves the org.

The 25 capabilities, one by one

Capabilities of the family, their minimum offer and their state at install.
CapabilityMinimum offerAt install
Emitting
AlertsAlertingDiscoveryOpen
Platform Event alertsAlert_PlatformEventDiscovery, display tier: nothing to toggle, the offer is enough
Custom-notification alertsAlert_CustomNotificationDiscovery, display tier: nothing to toggle, the offer is enough
Finding detail inside Platform Event alertsAlert_Event_Detail · closed by default: the event carries coordinates only, never the finding proseDiscoveryClosed
E-mail alertsAlert_EmailSmall business, display tier: nothing to toggle, the offer is enough
Not drowning the reader
Alert deduplicationAlert_DeduplicationSmall businessOpen
Alert groupingAlert_GroupingSmall businessClosed
Alert flapping suppressionAlert_Flap_SuppressionSmall businessClosed
Incident-burst correlationCorrelation_BurstSmall businessClosed
Quiet hoursQuiet_HoursSmall businessClosed
Maintenance windowsMaintenance_WindowsSmall businessClosed
Routing, escalating, accounting
Alert routingAlert_RoutingSmall businessClosed
Alert escalationAlert_EscalationSmall businessOpen
Alert escalation chainsAlert_Escalation_ChainsSmall businessClosed
Inbound acknowledgementInbound_AckSmall businessClosed
Alert historyAlert_HistorySmall businessOpen
Alert analyticsAlert_AnalyticsSmall businessClosed
Incidents
Incident managementIncident_ManagementSmall businessClosed
Incident drill (rehearsal)Incident_Drill · dry rehearsal: the escalation chain is resolved end to end, with zero send and zero outbound flowSmall businessClosed
Incident drill in live modeIncident_Drill_Live · closed at install; it requires its own gate, management authority and a typed confirmation phraseMid-marketClosed
External channels
External alert channels (Slack, Teams, PagerDuty, webhook)Channel_Slack · outbound flow to a destination you choose, with your credentialsMid-marketClosed
Teams alert channelChannel_Teams · outbound flow to a destination you choose, with your credentialsMid-marketClosed
PagerDuty alert channelChannel_PagerDuty · outbound flow to a destination you choose, with your credentialsMid-marketClosed
Webhook alert channelChannel_Webhook · outbound flow to a destination you choose, with your credentialsMid-marketClosed
Chatter alert channelChannel_Chatter · stays inside your org: Chatter is not an outbound flow. Off at install, until you designate the feed to post toSmall businessClosed

display tier: nothing to toggle, the offer is enough

Source: read from the package code at the moment this page is built — FeatureGate.FEATURE_TIER for the offer, FeatureGate.CODE_DEFAULTS for the state at install. The label is the one exception: the in-org feature editor is French only, so the English wording in this column was written for this site. Its French counterpart, on /produit/, is the exact string your administrator reads, and the site build fails if the two lists move apart. “Closed” does not mean absent: the capability is shipped, it is waiting for a human to open it inside the org — and a capability whose implementation nothing in the package can reach appears on none of these pages: the build drops it instead of selling it.

What this family does not do

Is this family in your offer? The grid says so line by line.

See the pricing grid Back to the seven families