Skip to main content

Alerting

Pavri alerts connect automated threat detection to human investigation. Alerts are designed to be the operator’s starting point when suspicious behavior has already been detected.

Current readiness

AreaStatusNotes
Alerts list and drill-down into implicated sessionsLiveThis is one of the strongest current product workflows.
Alert rule create/edit/delete/togglePreviewFully usable in the dashboard, but currently backed by local/fixture persistence rather than a durable alert-rule backend.
Webhook/Slack-style destinationsPreviewUseful for evaluation and operator UX, but not yet positioned as a mature enterprise routing system.
Email deliveryPlannedNot yet a complete notification path.

Alert triage workflow

Typical operator flow:

  1. Open the alert from the alerts list.
  2. Review severity, threat type, detector context, and policy linkage.
  3. Jump directly to the implicated session and event.
  4. Decide whether the issue is a real threat, a policy gap, or a tuning opportunity.

Pavri intentionally treats the alert as the entry point to investigation, then pivots into sessions, agents, and policies for deeper evidence.

Alert rules

Alert rules control which verdicts generate notifications and where those notifications go.

Current rule authoring supports:

  • creating a rule
  • editing the rule name or routing target
  • enabling or disabling a rule
  • deleting a rule

Rule authoring is available to Admins and Security Analysts. Viewers can review alerts but cannot manage alert-routing configuration.

Current product boundaries

The alerting UX is stronger than it was earlier in Phase 4, but it still has explicit limits:

  • rule state is not yet treated as a fully durable enterprise control plane
  • alert routing remains lighter-weight than the eventual product vision
  • email delivery is not yet a finished workflow

Use the dashboard alert-rule workflow for current operational review and authoring, but do not treat it as a finished multi-channel notification platform yet.