Alerting
Pavri alerts connect automated threat detection to human investigation. Alerts are designed to be the operator’s starting point when suspicious behavior has already been detected.
Support status
| Area | Status | Notes |
|---|---|---|
| Alerts list and drill-down into implicated sessions | Available | Review alerts and the implicated sessions. |
| Alert rule management | Available | Create, update, enable, or disable rules where this capability is enabled for your tenant. |
| Webhook/Slack-style destinations | Available when configured | Confirm the destination and delivery owner for your tenant. |
| Email delivery | Not available | Use an approved external notification workflow. |
Alert triage workflow
Typical operator flow:
- Open the alert from the alerts list.
- Review severity, threat type, detector context, and policy linkage.
- Jump directly to the implicated session and event.
- Decide whether the issue is a real threat, a policy gap, or a tuning opportunity.
Pavri intentionally treats the alert as the entry point to investigation, then pivots into sessions, agents, and policies for deeper evidence.
Alert rules
Alert rules control which verdicts generate notifications and where those notifications go.
Current rule authoring supports:
- creating a rule
- editing the rule name or routing target
- enabling or disabling a rule
- deleting a rule
Rule authoring is available to Admins and Security Analysts. Viewers can review alerts but cannot manage alert-routing configuration.
Operating boundaries
Alert routing has explicit limits:
- email delivery is not available from the dashboard
- delivery behavior depends on the configured integration and destination
Use the dashboard alert-rule workflow for operational review and authoring, and verify delivery through the configured destination before relying on it during an incident.