The inbox
The bell in the top bar is an inbox of what the platform raised for you and for the organizations in your scope. Each notification links to the alert, case, ticket or host it is about. Notifications opens the full list with a Delivery view showing what was sent, where, and whether it succeeded.
Kinds
| Kind | Raised when |
|---|---|
| Alert critical | A critical alert is written. |
| SLA approaching | An alert reaches the approach threshold. |
| SLA breached | An alert passes its target. |
| Assigned to you | Someone assigns you an alert or case. |
| Mentioned | Someone @-mentions you in a note or the war room. |
| Case update | A case you own changes state. |
| Response staged | A playbook has staged an action awaiting confirmation. |
| Response executed | An automatic action ran. |
| Containment tampered | An isolated host's firewall state changed unexpectedly. |
| Source stalled | A connector or sender stopped delivering. |
| Ticket | A customer opened or replied to a ticket. |
| Report published | A report was published to a portal. |
Preferences
Settings › Notifications lets each analyst choose which kinds reach the inbox, email or a channel, and quiet hours. An organization's mute in Settings › Organizations wins over any individual choice.
Organization routing
Per organization, admins set extra recipients on the operator side, the customer recipients for portal notifications, muted kinds and the customer's quiet hours.
Channels
Email, Slack, Microsoft Teams, Discord and webhooks are configured as egress integrations and can be selected per kind. See Egress.