Back to all guides
Custom Alert Rules
Create advanced alerting rules for specific scenarios.
Overview
Create custom alert rules to get notified about specific conditions that matter to your organisation.
Step 1: Create Alert Rule
- Navigate to Alerts → Alert Rules
- Click "Create Rule"
- Name your alert rule
- Set severity level
Step 2: Define Conditions
Set trigger conditions:
- Issue severity equals or exceeds threshold
- Issue count exceeds number in time period
- Security score drops below threshold
- Specific issue type is detected
- User activity matches pattern
Step 3: Configure Filters
- Filter by integration or service
- Filter by user or group
- Filter by issue category
- Add custom tag filters
Step 4: Set Actions
Configure what happens when triggered:
- Send email notification
- Send Slack message
- Trigger webhook
- Create ticket in ITSM tool
- Execute automated response
Step 5: Configure Timing
- Set evaluation frequency
- Configure alert cooldown period
- Set active hours (optional)
- Enable or disable the rule
Example Rules
- Alert when any critical issue is detected
- Alert when 5+ high issues in 1 hour
- Alert when admin role is assigned
- Alert when security score drops 10+ points
- Alert on external sharing rule creation