Notification kinds

The twelve notification kinds, when each fires and where it can go.

KindFires whenDefault
alert.criticalA critical alert is writtenInbox, channel
sla.approachingAn alert reaches the approach thresholdInbox
sla.breachedAn alert passes its targetInbox, channel
assignedYou are assigned an alert or caseInbox
mentionedYou are @-mentionedInbox, email
case.updatedA case you own changes stateInbox
response.stagedA playbook staged an actionInbox, channel
response.executedAn automatic action ranInbox, channel
containment.tamperedAn isolated host's firewall state changedInbox, channel
source.stalledA source stopped deliveringInbox, channel
ticketA customer opened or replied to a ticketInbox, email
report.publishedA report was published to a portalCustomer email

Defaults are per analyst under Settings › Notifications; organization routing and mutes are under Settings › Organizations.