Alerts
Rules that watch one number on a dashboard, checked every 15 minutes with no AI, and a fixed severity ladder that decides who hears about it.
An alert rule watches one number on a dashboard and compares it with a threshold: failed syncs above 10, refund rate up more than 40% against the previous period. When the number breaches for the number of checks in a row you chose, the rule fires and the severity decides who is told.
A check is the dashboard's saved query, run again, and a plain comparison. No model is involved and a check costs nothing. AI is used once, when Triagic suggests a rule.
Alerts live on the desktop app's Alerts page. The Alerts row in the sidebar counts firing high and critical alerts, and a chart with an open alert shows a dot that links to it.
What a rule watches
A rule watches one chart or KPI on one dashboard, over a 7, 30 or 90 day range:
- a KPI: its value
- a line or bar chart: the latest point of one series
- a table: how many rows it returned
It compares that number with is above, is at or above, is below or is at or below a threshold. A KPI that compares with the previous period can also use rises more than (%) or falls more than (%).
Checks in a row is 1 to 4. With 2, the number has to breach on two checks 15 minutes apart before the rule fires, so one odd reading does not page anyone.
Making rules
Anyone who can open a dashboard can make rules on it. Rules are yours: teammates do not see them in their app.
Ask for suggestions
Suggest alerts on a dashboard reads its charts and your current numbers and proposes up to 6 rules, each with a severity and a one-line reason that names the numbers it is based on. Table rows are never sent to the model, only how many there are. The button shows the price of the one AI call before you press it.
To ask for one rule on one chart, press Alert in the chart's header and say when you want to hear about it, for example "Page me if failed syncs go over 10". Write rule is one priced AI call, and the rule opens in the editor.
Review and save
Nothing is saved until you press Save. Untick a suggestion you don't want, and pick who else hears about each rule: Only me, or a team. Saving is free.
Editing a rule by hand is free. Edit on the Rules tab changes the name, the chart, the comparison, the threshold, the checks in a row, the severity and the team. Changing the chart, the condition or the severity, or turning the rule off, resolves its open alert; if the number is still bad, the rule fires again under the new definition. A rename or a team change leaves the alert open, so nobody is paged twice.
Who hears about it
The severity alone decides. The ladder is fixed and has no settings:
| Severity | Bell | OS notification and tone | Slack | Repeats until acknowledged | |
|---|---|---|---|---|---|
| Low | Yes | No | Daily digest | No | No |
| Medium | Yes | Yes | No | No | No |
| High | Yes | Yes | Yes | No | No |
| Critical | Yes | Yes | Yes | Yes | Every 15 min, up to 8 times |
- Bell, notification and tone go to the rule's owner only, on the desktop that checks the rule. With the window open, the sound and desktop notification follow your Settings. A critical notification stays on screen until you dismiss it, and each repeat shows again.
- Email goes to the owner and to every member of the rule's team who has an email address. High and critical email at once. Low alerts go into one digest email a day, sent after 09:00 desktop time and listing the low alerts of the last 24 hours; no digest is sent when there were none. Email needs your organization's email to be set up; the Alerts page says so when it isn't.
- Slack: critical alerts post to the Slack channel set on the Alerts page.
The team list offers the teams you belong to. Org admins can pick any team in the organization.
When the app is idle-locked, checks keep running and medium and higher alerts still show an OS notification. See Idle lock.
The Slack channel
Set it under Slack channel for critical alerts at the bottom of the Alerts page.
Use the channel ID (like C0123ABCD), not its name. Only an org admin can change it,
and Slack must be connected under Integrations. The page says when it isn't.
If an email or Slack post fails, the reason is saved on the alert and shown under it. It never stops the check or the other channels.
Acknowledging and resolving
An alert starts on the Firing tab.
- Acknowledge says someone is on it and moves it to Acknowledged. For a critical alert, this stops the repeats.
- Resolve closes it by hand. If the number is still bad, the rule fires again only after its checks in a row breach again.
- An alert resolves on its own when a check sees the number back within the threshold. The bell gets a resolve notice, and so does everyone who got its email or Slack post.
On a cloud-managed install, high and critical emails carry an Acknowledge link. A teammate opens it, signs in to the portal and acknowledges there, which stops the repeat pages for everyone. The owner's desktop picks that up before its next repeat and when the Alerts page opens. If the cloud can't be reached, the email goes out without the link and the alert can still be acknowledged in the app.
Deleting a rule resolves its open alert. Deleting a chart marks its rules Widget deleted, and deleting a dashboard removes its rules.
The Alerts page
| Tab | What it shows |
|---|---|
| Firing | Open alerts nobody has acknowledged, with the value, the threshold, when it opened and how many times it repeated. |
| Acknowledged | Who acknowledged each one, and when. |
| Resolved | Who resolved each one, or Resolved on its own. |
| Rules | Your rules: dashboard, condition, team, state, last value and last checked. Turn a rule off or on, edit it, or delete it. |
A rule's state is one of OK, Breached, waiting for more checks, Firing, Not checked yet or no number and Widget deleted. When a source is down or returns no number, nothing opens or resolves. After an hour without a number, the bell says Can't check with the reason.
Below the tabs, Who hears about it shows the ladder above.
Where checks run
Rules are checked on the rule owner's desktop, over the owner's own connections, every 15 minutes while the app is running. A check and an open dashboard share the same 15-minute cache, so no source is queried twice.
Checks need the owner's app running
On macOS, closing the window keeps the app running and checking. Quitting the app, or the machine going to sleep, stops checks for that owner's rules until it is back. On Windows and Linux, closing the window quits the app. Last checked on the Rules tab shows when each rule last ran.
Limits
- 50 rules per owner.
- One check every 15 minutes.
- Critical repeats at most 8 times, every 15 minutes (two hours).
- Up to 6 rules per Suggest alerts.
- Rule names up to 80 characters.
- A row count threshold must be below 500, the most rows a table returns.