| Kind | Fires when | Default |
|---|---|---|
| alert.critical | A critical alert is written | Inbox, channel |
| sla.approaching | An alert reaches the approach threshold | Inbox |
| sla.breached | An alert passes its target | Inbox, channel |
| assigned | You are assigned an alert or case | Inbox |
| mentioned | You are @-mentioned | Inbox, email |
| case.updated | A case you own changes state | Inbox |
| response.staged | A playbook staged an action | Inbox, channel |
| response.executed | An automatic action ran | Inbox, channel |
| containment.tampered | An isolated host's firewall state changed | Inbox, channel |
| source.stalled | A source stopped delivering | Inbox, channel |
| ticket | A customer opened or replied to a ticket | Inbox, email |
| report.published | A report was published to a portal | Customer email |
Defaults are per analyst under Settings › Notifications; organization routing and mutes are under Settings › Organizations.