Skip to main content
Alerts are Ultra Hub’s notifications. They gather the high-signal events from across your organization into one prioritized list, so you don’t have to reconstruct what happened by reading the audit log. Open it from Alerts in the Hub sidebar, or go directly to /alerts.
Alerts are off until you switch them on. A new organization raises no alerts at all. Nothing is missing from the feed and nothing is broken: no alert source is enabled yet. Turn on the sources you want from Configuration, below.

Alert Sources

Three sources can raise alerts. The Type column tells you which one produced a given alert, and each is switched on independently.

Guardrail alerts

Guardrail alerts cover what a guardrail actually did: blocked a request, redacted a response, or, in Monitor mode, allowed the request and recorded the match. The alert names the tool or connector involved. Alerting keys off the outcome Ultra recorded, not the mode you configured. A guardrail set to Block that let a call through recorded an allow, so it raises nothing.
Monitor-mode guardrails do raise alerts, letting you watch the guardrail’s real-world behavior before you set it to Block. See Enforcement modes.

Governance alerts

Governance alerts cover blocked attempts to reach a connector your governance policy does not permit. The alert names the blocked connector.

Anomaly alerts

Every anomaly finding carries a risk score between 0 and 1, shown on the finding itself. A finding scoring 0.6 or above raises an alert, so something worth acting on reaches the same feed as your enforcement events instead of waiting to be noticed on the Anomalies page. Findings below 0.6 are still detected, still recorded, and still shown in full on the Anomalies page with their scores — they just don’t raise an alert. The threshold is fixed and the same for every organization, so a score you see on a finding tells you directly whether it alerted. Where a finding names exactly one resolvable user, the alert’s context is that person. Otherwise it is recorded as organization-wide. Every enforcement event is recorded in the audit log whether or not it raises an alert. To send alerts outside Ultra Hub, route them to Slack or export them to your SIEM.

Configuration

Owners and admins choose what raises an alert from Configuration in the Alerts page header. You can turn alerts on or off for:
  • Each guardrail
  • Each governance block
  • Anomaly detection
These settings change notifications only. Turning off a guardrail’s alerts does not stop it from monitoring, blocking, or redacting.

Test Alerts

A test alert shows what a source produces, or confirms an integration is receiving alerts, without waiting for a real event. Owners and admins can click Test on any row in Configuration, then Send test. The test appears in the feed titled Test: followed by the source’s name. It works even when the source is switched off, and it doesn’t create traffic, traces, or audit events. To remove a test alert, open it and click Delete test alert. This removes it from Ultra only; a copy already sent to an integration stays there.

Severity

Ultra assigns severity, so an alert means the same thing across every organization.

The Alerts Page

Read state is per person. A teammate opening an alert doesn’t clear it for you, and the unread count in the sidebar reflects only what you haven’t opened. Opening an alert adds ?alert=<id> to the URL, so you can share a specific alert with a teammate.

Exporting

Export the feed as CSV or JSON. With nothing selected, the export covers the whole feed as currently filtered, not just the page you’re looking at. With rows selected, it covers exactly those rows. Exports leave out read state, trigger details, and request context.

Permissions

See RBAC for the full permission matrix.

Scope

Alerts are organization-scoped: every member can see every alert, regardless of workspace membership. The workspace and device filters in the Hub header narrow the feed, its export, and Mark all read. Alerts that belong to no workspace or device, such as anomaly alerts, stay visible under any selection.