Alerting
Pavri alerts connect automated threat detection to human investigation. Alerts are designed to be the operator’s starting point when suspicious behavior has already been detected.
Current readiness
| Area | Status | Notes |
|---|---|---|
| Alerts list and drill-down into implicated sessions | Live | This is one of the strongest current product workflows. |
| Alert rule create/edit/delete/toggle | Preview | Fully usable in the dashboard, but currently backed by local/fixture persistence rather than a durable alert-rule backend. |
| Webhook/Slack-style destinations | Preview | Useful for evaluation and operator UX, but not yet positioned as a mature enterprise routing system. |
| Email delivery | Planned | Not yet a complete notification path. |
Alert triage workflow
Typical operator flow:
- Open the alert from the alerts list.
- Review severity, threat type, detector context, and policy linkage.
- Jump directly to the implicated session and event.
- Decide whether the issue is a real threat, a policy gap, or a tuning opportunity.
Pavri intentionally treats the alert as the entry point to investigation, then pivots into sessions, agents, and policies for deeper evidence.
Alert rules
Alert rules control which verdicts generate notifications and where those notifications go.
Current rule authoring supports:
- creating a rule
- editing the rule name or routing target
- enabling or disabling a rule
- deleting a rule
Rule authoring is available to Admins and Security Analysts. Viewers can review alerts but cannot manage alert-routing configuration.
Current product boundaries
The alerting UX is stronger than it was earlier in Phase 4, but it still has explicit limits:
- rule state is not yet treated as a fully durable enterprise control plane
- alert routing remains lighter-weight than the eventual product vision
- email delivery is not yet a finished workflow
Use the dashboard alert-rule workflow for current operational review and authoring, but do not treat it as a finished multi-channel notification platform yet.