Skip to main content

Alerting

Pavri alerts connect automated threat detection to human investigation. Alerts are designed to be the operator’s starting point when suspicious behavior has already been detected.

Support status

AreaStatusNotes
Alerts list and drill-down into implicated sessionsAvailableReview alerts and the implicated sessions.
Alert rule managementAvailableCreate, update, enable, or disable rules where this capability is enabled for your tenant.
Webhook/Slack-style destinationsAvailable when configuredConfirm the destination and delivery owner for your tenant.
Email deliveryNot availableUse an approved external notification workflow.

Alert triage workflow

Typical operator flow:

  1. Open the alert from the alerts list.
  2. Review severity, threat type, detector context, and policy linkage.
  3. Jump directly to the implicated session and event.
  4. Decide whether the issue is a real threat, a policy gap, or a tuning opportunity.

Pavri intentionally treats the alert as the entry point to investigation, then pivots into sessions, agents, and policies for deeper evidence.

Alert rules

Alert rules control which verdicts generate notifications and where those notifications go.

Current rule authoring supports:

  • creating a rule
  • editing the rule name or routing target
  • enabling or disabling a rule
  • deleting a rule

Rule authoring is available to Admins and Security Analysts. Viewers can review alerts but cannot manage alert-routing configuration.

Operating boundaries

Alert routing has explicit limits:

  • email delivery is not available from the dashboard
  • delivery behavior depends on the configured integration and destination

Use the dashboard alert-rule workflow for operational review and authoring, and verify delivery through the configured destination before relying on it during an incident.